<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ingest Palo Alto logs to SIEM tool (Splunk) using Eventhub in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/ingest-palo-alto-logs-to-siem-tool-splunk-using-eventhub/m-p/590729#M2202</link>
    <description>&lt;DIV class="flex flex-grow flex-col max-w-full"&gt;
&lt;DIV class="min-h-[20px] text-message flex flex-col items-start whitespace-pre-wrap break-words [.text-message+&amp;amp;]:mt-5 juice:w-full juice:items-end overflow-x-auto gap-2" dir="auto" data-message-author-role="assistant" data-message-id="f9d800fb-d089-40fd-86cc-ad75f3d4c005"&gt;
&lt;DIV class="flex w-full flex-col gap-1 juice:empty:hidden juice:first:pt-[3px]"&gt;
&lt;DIV class="markdown prose w-full break-words dark:prose-invert light"&gt;
&lt;P&gt;To route Palo Alto firewall logs to Splunk via Azure Event Hub, configure the firewall to send logs to an Azure Function or Logic App, which forwards them to Event Hub. Install the Splunk Add-on for Microsoft Cloud Services and configure it to ingest logs from Event Hub, enabling efficient log management and analysis in Splunk.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="mt-1 flex gap-3 empty:hidden juice:-ml-3"&gt;
&lt;DIV class="items-center justify-start rounded-xl p-1 flex"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Fri, 28 Jun 2024 19:01:58 GMT</pubDate>
    <dc:creator>KateWinslet1</dc:creator>
    <dc:date>2024-06-28T19:01:58Z</dc:date>
    <item>
      <title>Ingest Palo Alto logs to SIEM tool (Splunk) using Eventhub</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/ingest-palo-alto-logs-to-siem-tool-splunk-using-eventhub/m-p/589234#M2186</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We're looking into some sort of cloud-based solution to route our Palo Alto firewall logs to across our customer base. I was intrigued by the Event Hubs (&lt;/SPAN&gt;&lt;A class="relative pointer-events-auto a
  
  
  
  
  hover:underline
  " href="https://azure.microsoft.com/en-us/products/event-hubs/" target="_blank" rel="noopener nofollow ugc"&gt;https://azure.microsoft.com/en-us/products/event-hubs/&lt;/A&gt;&lt;SPAN&gt;) solution as a way to push logs to it and then ingest them from there into our SIEM (Splunk). Is there a way, we can directly push logs from Palo Alto VM-series firewalls in Azure to Eventhub and then ingest it to Splunk from there? I have tried to search for documentation around it but nothing of help as such. Can someone please help me here? We need to setup something like this (attached in screenshot).&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/160461"&gt;@lmori&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;#PaloAlto #Logging #EventHub #SEIM #Splunk&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Do I need to setup AKS with fluentd in between firewalls and Eventhub before pushing the logs to Eventhub?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 08:01:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/ingest-palo-alto-logs-to-siem-tool-splunk-using-eventhub/m-p/589234#M2186</guid>
      <dc:creator>BilalMohd</dc:creator>
      <dc:date>2024-06-11T08:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Palo Alto logs to SIEM tool (Splunk) using Eventhub</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/ingest-palo-alto-logs-to-siem-tool-splunk-using-eventhub/m-p/589374#M2187</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Not familiar with either Splunk or EventHub, however the Palo Alto can send its syslog's to any destination. If Eventhub can accept syslogs, then I cant see why it wont send there. You can also send the logs to several destinations, ie EventHub and Splunk from the PAN. Not sure what the end goal is to sent ot both.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2024 14:42:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/ingest-palo-alto-logs-to-siem-tool-splunk-using-eventhub/m-p/589374#M2187</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-06-12T14:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Palo Alto logs to SIEM tool (Splunk) using Eventhub</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/ingest-palo-alto-logs-to-siem-tool-splunk-using-eventhub/m-p/589673#M2188</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/292033"&gt;@BilalMohd&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on documentation Azure Event Hubs supports streaming of incoming data with HTTPS. Palo Alto supports log forwarding from Firewalls over HTTPS:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/forward-logs-to-an-https-destination" target="_self"&gt;Forward Logs to an HTTP/S Destination&lt;/A&gt;. The part to send logs from Azure Event Hubs is tricky. I came across this blog post:&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/How-to-send-data-to-Splunk-from-Azure-Event-Hub/td-p/618022" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/How-to-send-data-to-Splunk-from-Azure-Event-Hub/td-p/618022&lt;/A&gt;&amp;nbsp;which indicates this might be possible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 02:26:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/ingest-palo-alto-logs-to-siem-tool-splunk-using-eventhub/m-p/589673#M2188</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-06-17T02:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Palo Alto logs to SIEM tool (Splunk) using Eventhub</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/ingest-palo-alto-logs-to-siem-tool-splunk-using-eventhub/m-p/590729#M2202</link>
      <description>&lt;DIV class="flex flex-grow flex-col max-w-full"&gt;
&lt;DIV class="min-h-[20px] text-message flex flex-col items-start whitespace-pre-wrap break-words [.text-message+&amp;amp;]:mt-5 juice:w-full juice:items-end overflow-x-auto gap-2" dir="auto" data-message-author-role="assistant" data-message-id="f9d800fb-d089-40fd-86cc-ad75f3d4c005"&gt;
&lt;DIV class="flex w-full flex-col gap-1 juice:empty:hidden juice:first:pt-[3px]"&gt;
&lt;DIV class="markdown prose w-full break-words dark:prose-invert light"&gt;
&lt;P&gt;To route Palo Alto firewall logs to Splunk via Azure Event Hub, configure the firewall to send logs to an Azure Function or Logic App, which forwards them to Event Hub. Install the Splunk Add-on for Microsoft Cloud Services and configure it to ingest logs from Event Hub, enabling efficient log management and analysis in Splunk.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="mt-1 flex gap-3 empty:hidden juice:-ml-3"&gt;
&lt;DIV class="items-center justify-start rounded-xl p-1 flex"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 28 Jun 2024 19:01:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/ingest-palo-alto-logs-to-siem-tool-splunk-using-eventhub/m-p/590729#M2202</guid>
      <dc:creator>KateWinslet1</dc:creator>
      <dc:date>2024-06-28T19:01:58Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Palo Alto logs to SIEM tool (Splunk) using Eventhub</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/ingest-palo-alto-logs-to-siem-tool-splunk-using-eventhub/m-p/615445#M2291</link>
      <description>&lt;P&gt;Configure Palo Alto to send logs to Azure Event Hub via an Azure Function or Logic App. Then, install the Splunk Add-on for Microsoft Cloud Services to ingest logs from Event Hub for efficient analysis in Splunk.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 13:39:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/ingest-palo-alto-logs-to-siem-tool-splunk-using-eventhub/m-p/615445#M2291</guid>
      <dc:creator>BrettLee1</dc:creator>
      <dc:date>2024-10-28T13:39:32Z</dc:date>
    </item>
  </channel>
</rss>

