All Apps and Add-ons

Palo Alto Networks Add-on: Can we receive TCP data on Port 80 from Panorama?

phularah
Communicator

I want my Splunk Heavy Forwarder to receive TCP data on port 80 using Panorama. I have installed Palo Alto Networks add-on for Splunk on said Heavy Forwarder. Am I required to make any specific configurations in the add-on? I am not interested in using Wildfire, Aperture etc. I am only interested in getting firewall data in my Splunk indexer. Firewalls are already configured to store data in Panorama. Total no. of firewalls is 6 in number.

I have created a TCP data input in my heavy forwarder for that. I have also asked the security team to create a profile for Http(s) server (which will be Splunk) on Panorama.

Do I need to follow any more steps? Any ideas or suggestions? @btorresgil, @adonio, @panguy

0 Karma
1 Solution

phularah
Communicator

I integrated Palo Alto with Splunk a few days back. I used port 514 instead. I made a data input in Splunk on port 514 and asked Security team to send data from Panorama to the data input. Everything works fine.

View solution in original post

0 Karma

phularah
Communicator

I integrated Palo Alto with Splunk a few days back. I used port 514 instead. I made a data input in Splunk on port 514 and asked Security team to send data from Panorama to the data input. Everything works fine.

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...