All Apps and Add-ons

Splunk for Palo Alto Networks app blank when Splunk shows traffic

blarney
Engager

Splunk 6.1.1 build 207789 running on Ubuntu 14.04
PAN appliance logs show successful connection to syslog server.
Using defaults on PAN syslog settings.

Logs are seen with comma delimiters in straight Splunk. However, there is nothing showing up in Splunk for Palo Alto Networks.

Guidance or advise appreciated

Tags (2)
0 Karma
1 Solution

okrabbe_splunk
Splunk Employee
Splunk Employee

The sourcetype for the logs needs to be pan_log and the index should be pan_logs.

The app docs describe this in more detail:

http://apps.splunk.com/app/491/

View solution in original post

0 Karma

okrabbe_splunk
Splunk Employee
Splunk Employee

No problem! Glad you got it working. I posted the comment as an answer so please accept the answer for posterities sake 🙂

0 Karma

okrabbe_splunk
Splunk Employee
Splunk Employee

The sourcetype for the logs needs to be pan_log and the index should be pan_logs.

The app docs describe this in more detail:

http://apps.splunk.com/app/491/

0 Karma

blarney
Engager

thanks, okrabbe_splunk. My misunderstanding of how splunk works with the splunk for palo alto networks app has been cleared up. It is one or the other and not splunk for palo alto networks on top of splunk. had the source type set as pan_log. Was using the default index though. Changing to pan_logs allowed for event support / different index.
http://docs.splunk.com/Documentation/Splunk/6.1.1/Data/Monitornetworkports
Thanks for the pointer.

0 Karma

okrabbe_splunk
Splunk Employee
Splunk Employee

What is the sourcetype and index for the PAN logs? The sourcetype for the logs needs to be pan_log and the index should be pan_logs.

The app docs describe this in more detail: http://apps.splunk.com/app/491/

Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...