Quantcast
Channel: Q&A related to Splunk for Palo Alto Networks
Viewing all articles
Browse latest Browse all 121

Installing Splunk for Palo Alto on a cluster

$
0
0

I have a V6 cluster with a Master Node, 5 Indexers, and a Search Head Pool with 3 Search Heads and 2 forwarders that receive all the data. The PAN logs come in on UDP 11112.

The simple installation instructions say

  1. Unpack the tar ball into $SPLUNK_HOME/etc/apps
  2. Restart Splunk

I figured this out so I'm just updating the steps. I'm going to run through this again to verify but I'm pretty sure I've got everything. YMMV

  1. Install on Master Node, restart and configure.
  2. Move/copy /opt/splunk/etc/apps/SplunkforPaloAltoNetworks to /opt/splunk/etc/master-apps/SplunkforPaloAltoNetworks
  3. Use Master Node to deploy the app to indexers.
  4. Install on Search Heads. Make sure it goes to the Search Head Pool NFS mount /NFS-SH/etc/apps.
  5. Install on forwarders so the props and translations take affect.

Viewing all articles
Browse latest Browse all 121

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>