Quantcast
Channel: Q&A related to Splunk for Palo Alto Networks
Viewing all articles
Browse latest Browse all 121

Index Config for Palo Alto App

$
0
0

The documentation indicates that the default index is pan_logs; however, the default config files have pan_index as the default index. Please clarify which is correct.


To get the firewall data into Splunk

IMPORTANT: When you configure the input port, you must set the sourcetype of the firewall data to pan__log and the index to pan__logs. This can be done from the Web UI or the CLI. Then, configure the firewall to set traffic to Splunk.


Viewing all articles
Browse latest Browse all 121

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>