<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk and Palo Alto Networks Integration in AWS: Log Data Discrepancies in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/splunk-and-palo-alto-networks-integration-in-aws-log-data/m-p/555221#M1970</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Check the parsing and indexing configuration in Splunk. Splunk uses regular expressions and configurations to extract and index data. Ensure that your Splunk configuration aligns with the log format used by Palo Alto Networks devices. Misconfigured or incomplete parsing rules could lead to discrepancies.&amp;nbsp;Timestamps are crucial for accurate log analysis. Ensure that the timestamps in your log data are correctly parsed and indexed in Splunk. If the timestamps are mismatched or not aligned properly, it can lead to discrepancies between the PAN-OS console and Splunk.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;&lt;A href="https://www.paybyplatema.ltd/" target="_self"&gt;&lt;FONT color="#FFFFFF"&gt;PaybyPlateMa Invoice&lt;/FONT&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 25 Aug 2023 04:31:42 GMT</pubDate>
    <dc:creator>uthhab2</dc:creator>
    <dc:date>2023-08-25T04:31:42Z</dc:date>
    <item>
      <title>Splunk and Palo Alto Networks Integration in AWS: Log Data Discrepancies</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/splunk-and-palo-alto-networks-integration-in-aws-log-data/m-p/554802#M1961</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Recently, in our organization, we undertook the task of integrating Splunk with our existing Palo Alto Networks infrastructure within our AWS environment. The integration process was fairly smooth, and we were eager to begin monitoring and analyzing our network logs using Splunk's capabilities.&lt;/P&gt;
&lt;P&gt;However, as we started to deep dive into the log data, we noticed certain discrepancies. Some log entries, when visualized in Splunk, appear differently than when they're viewed directly in the PAN-OS console. This has raised concerns about the accuracy and consistency of the data we're analyzing.&lt;/P&gt;
&lt;P&gt;I wanted to reach out and see if anyone in this community has faced a similar issue. Specifically:&lt;/P&gt;
&lt;P data-unlink="true"&gt;Have you observed any discrepancies in log data between the PAN-OS&amp;nbsp; and Splunk&amp;nbsp; console in your integrations?&lt;BR /&gt;If so, what measures did you take to address or troubleshoot the problem?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 08:23:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/splunk-and-palo-alto-networks-integration-in-aws-log-data/m-p/554802#M1961</guid>
      <dc:creator>miasmith500</dc:creator>
      <dc:date>2023-08-23T08:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk and Palo Alto Networks Integration in AWS: Log Data Discrepancies</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/splunk-and-palo-alto-networks-integration-in-aws-log-data/m-p/555002#M1967</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Yes, discrepancies between log data in Palo Alto Networks (PAN-OS) and Splunk integrations can occur due to parsing, timestamps, and data processing differences.&amp;nbsp;Verify data integrity and consistent log generation. Review parsing and indexing settings in Splunk to match log format. Ensure timestamp consistency and timezones. Manually compare raw log entries in both systems. Consult documentation, support, and experts if discrepancies persist.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 07:01:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/splunk-and-palo-alto-networks-integration-in-aws-log-data/m-p/555002#M1967</guid>
      <dc:creator>uthhab2</dc:creator>
      <dc:date>2023-08-24T07:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk and Palo Alto Networks Integration in AWS: Log Data Discrepancies</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/splunk-and-palo-alto-networks-integration-in-aws-log-data/m-p/555221#M1970</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Check the parsing and indexing configuration in Splunk. Splunk uses regular expressions and configurations to extract and index data. Ensure that your Splunk configuration aligns with the log format used by Palo Alto Networks devices. Misconfigured or incomplete parsing rules could lead to discrepancies.&amp;nbsp;Timestamps are crucial for accurate log analysis. Ensure that the timestamps in your log data are correctly parsed and indexed in Splunk. If the timestamps are mismatched or not aligned properly, it can lead to discrepancies between the PAN-OS console and Splunk.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;&lt;A href="https://www.paybyplatema.ltd/" target="_self"&gt;&lt;FONT color="#FFFFFF"&gt;PaybyPlateMa Invoice&lt;/FONT&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 04:31:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/splunk-and-palo-alto-networks-integration-in-aws-log-data/m-p/555221#M1970</guid>
      <dc:creator>uthhab2</dc:creator>
      <dc:date>2023-08-25T04:31:42Z</dc:date>
    </item>
  </channel>
</rss>

