All Apps and Add-ons

Palo Alto Networks App for Splunk: Does the app not support firewall logs sending data in CEF format?

cosmin_rautoiu
New Member

Hello,

We configured one of the firewalls to send the data in CEF format. Now I cannot see this firewall anymore in Palo Alto Networks tab as it is being recognized as Endpoint Security Manager (ESM). Should I assume that the app doesn't support firewall logs in CEF?

Splunk 6.5.1, latest Palo Alto Networks App for Splunk and Palo Alto Networks Add-on for Splunk.

Thanks!

0 Karma

jstoner_splunk
Splunk Employee
Splunk Employee

The newer version of Splunk's CEF App will rely on the data models to extract data. Based on that, you will need to use the wizard based on the Network Traffic data model to get the data out for PAN. If you want to constrain to just PAN and not other data in the network traffic data model, clone the network traffic data model and add a constraint to isolate on the PAN. The search will be generated and the output.conf file will need to be deployed to the indexers. The mapping in the CEF app will allow you to place specific values into CEF fields.

0 Karma

kchamplin_splun
Splunk Employee
Splunk Employee

Currently the Palo Alto Add-On only supports CEF for ESM logs. If you look at the transforms.conf file of the add-on you will see the following stanza for endpoint logs.
[pan_endpoint]
DEST_KEY = MetaData:Sourcetype
REGEX = ^[^|,]+ CEF:0|
FORMAT = sourcetype::pan:endpoint
For the other sourcetypes, you'll find a different set of regexs for setting the different sourcetypes from the standard Palo Alto Networks logs.
Ultimately I think not sending the firewall logs in CEF format results in an overall better experience. Other than getting the dashboards to populate, you'll get Splunk Common Information model mapped fields and other benefits.

0 Karma

panguy
Contributor

The app doesn't support CEF format logs from the Firewall.

cosmin_rautoiu
New Member

Hello kchamplin,

Yes, we need to feed ArcSight too, that's why CEF was chosen.

0 Karma

cosmin_rautoiu
New Member

Thanks for the fast reply. Any idea if this will be implemented in the future? I mean, if the fw supports CEF format the app should also supports it, right?

0 Karma

kchamplin_splun
Splunk Employee
Splunk Employee

Hello @cosmin.rautoiu what is your use-case regarding CEF - do you need to send CEF formatted data back out from Splunk to other devices? Or is CEF just a general preference?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...