All Apps and Add-ons

Can Splunk for Palo Alto Networks app index data on my network without WildFire?

ctheidea
Engager

Sorry I'm Splunk newbie.

I have Palo Alto Logs into Splunk (realtime).

I'm installed Splunk for Palo Alto Networks and Config without WildFire Config.

Can I use this app without WildFire. ( I mean Splunk for Pal Alto Network can index data from Palo Alto Networks without WildFire? )

Sorry my English, I'm learning 🙂

Thankyou

1 Solution

barakreeves
Splunk Employee
Splunk Employee

You do not need a WildFire account to get good value out of the PaloAlto Network app for Splunk. The app will work great without the subscription. Remember, at anytime, you can correlate PaloAlto Network data with any other data source, such as AD or Windows security EventLogs by going into search and type: index=pan_logs OR index=msad

Happy Splunking,
Barak

View solution in original post

barakreeves
Splunk Employee
Splunk Employee

You do not need a WildFire account to get good value out of the PaloAlto Network app for Splunk. The app will work great without the subscription. Remember, at anytime, you can correlate PaloAlto Network data with any other data source, such as AD or Windows security EventLogs by going into search and type: index=pan_logs OR index=msad

Happy Splunking,
Barak

ctheidea
Engager

Thank you for advice 🙂

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...