All Apps and Add-ons

How to have “Splunk for Palo Alto Networks” read from the default index?

jeffa
Path Finder

According to the setup documentation, the input for Splunk for Palo Alto Networks should write to the pan_logs index, however, I would prefer that it write to the default index. My hope is that making this change is as easy as updating the `pan_index` macro to point to the default index rather than pan_logs, but are there any other considerations?

0 Karma
1 Solution

jeffa
Path Finder

I did some experimentation with this and found that pointing the pan_index macro at the default index did allow me to view logs and dashboards from logs stored in the default index instead of the pan_logs index. However, the app author has stated that “Though keep in mind that this isn't really a supported configuration…” and that the configuration may cause issues w/ future releases.

The reason I originally asked the question is that up till now, I have used the index size limit of the default index to control disk utilization. Rather than putting the Palo Alto logs in the default index, the better answer was to implement “Volume settings” (indexes.conf) and place the default index, pan_logs index (and any other index that I want to control) into the same “volume”.

View solution in original post

0 Karma

jeffa
Path Finder

I did some experimentation with this and found that pointing the pan_index macro at the default index did allow me to view logs and dashboards from logs stored in the default index instead of the pan_logs index. However, the app author has stated that “Though keep in mind that this isn't really a supported configuration…” and that the configuration may cause issues w/ future releases.

The reason I originally asked the question is that up till now, I have used the index size limit of the default index to control disk utilization. Rather than putting the Palo Alto logs in the default index, the better answer was to implement “Volume settings” (indexes.conf) and place the default index, pan_logs index (and any other index that I want to control) into the same “volume”.

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...