All Apps and Add-ons

Can Splunk for Palo Alto Networks app index data on my network without WildFire?

ctheidea
Engager

Sorry I'm Splunk newbie.

I have Palo Alto Logs into Splunk (realtime).

I'm installed Splunk for Palo Alto Networks and Config without WildFire Config.

Can I use this app without WildFire. ( I mean Splunk for Pal Alto Network can index data from Palo Alto Networks without WildFire? )

Sorry my English, I'm learning 🙂

Thankyou

1 Solution

barakreeves
Splunk Employee
Splunk Employee

You do not need a WildFire account to get good value out of the PaloAlto Network app for Splunk. The app will work great without the subscription. Remember, at anytime, you can correlate PaloAlto Network data with any other data source, such as AD or Windows security EventLogs by going into search and type: index=pan_logs OR index=msad

Happy Splunking,
Barak

View solution in original post

barakreeves
Splunk Employee
Splunk Employee

You do not need a WildFire account to get good value out of the PaloAlto Network app for Splunk. The app will work great without the subscription. Remember, at anytime, you can correlate PaloAlto Network data with any other data source, such as AD or Windows security EventLogs by going into search and type: index=pan_logs OR index=msad

Happy Splunking,
Barak

ctheidea
Engager

Thank you for advice 🙂

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...