Quantcast
Channel: Q&A related to Splunk for Palo Alto Networks
Viewing all articles
Browse latest Browse all 121

How to Deploy Palo Alto Apps under Forwarder and Indexer environment

$
0
0

Hi,

I follow the instruction to set up the data input config in inputs.conf of Forwarder server and install the Palo Alto Apps in Indexer server.

I found the Indexer can receive the log successfully but it cannot extract field from log. The search inspector show the follow message in Traffic dashboard: None | tstats sum(bytes_sent) AS sumSent sum(bytes_received) AS sumReceived FROM pan_traffic where log_subtype=end groupby _time span=5m | timechart span=5m values("sumReceived") AS "Bytes Received" values("sumSent") AS "Bytes Sent"

It seems the problem caused by props.conf and transforms.conf is not applied.

Do you know any additional config is required if deploy on Forwarder and Indexer environment?

Thanks


Viewing all articles
Browse latest Browse all 121

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>