We are ingesting the firewall data from the panorama and GP cloud service logs from Cortex and ingesting the data to the same index pan_logs with sourcetype=pan:log.
The logs from panorama are getting parsed properly, however, the data from the cortex data lake for global protect cloud service is not getting parsed. Does the Palo Alto Networks for Splunk add-on support data coming from Cortex? Any suggestions to make this work?
I'm also curious about this.
I am trying to get data from cortex data lake to our Splunk hosted on prem. We getting the logs but it’s garbage characters.
splunk is not able to open ssl input. Can you share splunk side config to make this work?
what were the parameters on inputs.conf and what third party CA you user and created pem files?
any help would be appreciated
I don't think Cortex Data Lake supports SSL (assuming you mean https). It does support syslog over TLS though.
In case anyone else lands here, it appears Cortex Data Lake now supports forwarding directly to Splunk via HTTP Event Collector (HEC).
https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-start...