Quantcast
Channel: Q&A related to Splunk for Palo Alto Networks
Viewing all articles
Browse latest Browse all 121

Index Config for Palo Alto App

$
0
0

The documentation indicates that the default index is pan_logs; however, the default config files have pan_index as the default index. Please clarify which is correct.


To get the firewall data into Splunk

IMPORTANT: When you configure the input port, you must set the sourcetype of the firewall data to pan__log and the index to pan__logs. This can be done from the Web UI or the CLI. Then, configure the firewall to set traffic to Splunk.


Viewing all articles
Browse latest Browse all 121

Latest Images

Trending Articles



Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>