All Apps and Add-ons

Splunk and Palo Alto Cortex Data Lake: Data for global protect cloud service is not getting parsed.

shirishkamat84
Path Finder

We are ingesting the firewall data from the panorama and GP cloud service logs from Cortex and ingesting the data to the same index pan_logs with sourcetype=pan:log.

The logs from panorama are getting parsed properly, however, the data from the cortex data lake for global protect cloud service is not getting parsed. Does the Palo Alto Networks for Splunk add-on support data coming from Cortex? Any suggestions to make this work?

Labels (1)

swebb07g
Path Finder

I'm also curious about this.

0 Karma

hiren53
New Member

I am trying to get data from cortex data lake to our Splunk hosted on prem. We getting the logs but it’s garbage characters.

splunk is not able to open ssl input. Can you share splunk side config to make this work?

what were the parameters on inputs.conf and what third party CA you user and created pem files?

 

any help would be appreciated 

0 Karma

swebb07g
Path Finder

I don't think Cortex Data Lake supports SSL (assuming you mean https). It does support syslog over TLS though.

0 Karma

swebb07g
Path Finder

In case anyone else lands here, it appears Cortex Data Lake now supports forwarding directly to Splunk  via HTTP Event Collector (HEC).

https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-start...

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...