All Apps and Add-ons

How to have “Splunk for Palo Alto Networks” read from the default index?

jeffa
Path Finder

According to the setup documentation, the input for Splunk for Palo Alto Networks should write to the pan_logs index, however, I would prefer that it write to the default index. My hope is that making this change is as easy as updating the `pan_index` macro to point to the default index rather than pan_logs, but are there any other considerations?

0 Karma
1 Solution

jeffa
Path Finder

I did some experimentation with this and found that pointing the pan_index macro at the default index did allow me to view logs and dashboards from logs stored in the default index instead of the pan_logs index. However, the app author has stated that “Though keep in mind that this isn't really a supported configuration…” and that the configuration may cause issues w/ future releases.

The reason I originally asked the question is that up till now, I have used the index size limit of the default index to control disk utilization. Rather than putting the Palo Alto logs in the default index, the better answer was to implement “Volume settings” (indexes.conf) and place the default index, pan_logs index (and any other index that I want to control) into the same “volume”.

View solution in original post

0 Karma

jeffa
Path Finder

I did some experimentation with this and found that pointing the pan_index macro at the default index did allow me to view logs and dashboards from logs stored in the default index instead of the pan_logs index. However, the app author has stated that “Though keep in mind that this isn't really a supported configuration…” and that the configuration may cause issues w/ future releases.

The reason I originally asked the question is that up till now, I have used the index size limit of the default index to control disk utilization. Rather than putting the Palo Alto logs in the default index, the better answer was to implement “Volume settings” (indexes.conf) and place the default index, pan_logs index (and any other index that I want to control) into the same “volume”.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...