<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Certain logs not sending to Splunk in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/certain-logs-not-sending-to-splunk/m-p/1261155#M126835</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/225107"&gt;@Fariq_Zaidi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How do you have your log forwarding profile configured? Do you have your log types set to All Logs for URL, Wildfire, and Tunnel?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For URL you also want to make sure that&amp;nbsp;URL Filtering profile uses an action such as &lt;STRONG data-end="271" data-start="262"&gt;alert&lt;/STRONG&gt;, &lt;STRONG data-end="282" data-start="273"&gt;block&lt;/STRONG&gt;, or &lt;STRONG data-end="299" data-start="287"&gt;continue&lt;/STRONG&gt; for the categories you want logged. Categories set to &lt;STRONG data-end="363" data-start="354"&gt;allow&lt;/STRONG&gt; may not generate a URL log.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the Tunnel logs, please confirm whether Tunnel Content Inspection is configured under &lt;STRONG data-end="2065" data-start="2033"&gt;Policies &amp;gt; Tunnel Inspection&lt;/STRONG&gt; and whether logs are generated locally under &lt;STRONG data-end="2149" data-start="2111"&gt;Monitor &amp;gt; Logs &amp;gt; Tunnel Inspection&lt;/STRONG&gt;. This log type applies to supported cleartext tunnels passing through the firewall and is separate from standard IPsec VPN status events. If you are looking for standard IPsec VPN events such as tunnel status, negotiation, or tunnel-monitor messages, those are typically found in the &lt;STRONG data-end="585" data-start="570"&gt;System logs. &lt;/STRONG&gt;So you should be covered there.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you go to&lt;STRONG&gt; Monitor &amp;gt; Logs &amp;gt; Wildfire&lt;/STRONG&gt; , do you see logs generated there during the time frame of when you were monitoring Splunk?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 06 Aug 2026 03:38:23 GMT</pubDate>
    <dc:creator>JayGolf</dc:creator>
    <dc:date>2026-08-06T03:38:23Z</dc:date>
    <item>
      <title>Certain logs not sending to Splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certain-logs-not-sending-to-splunk/m-p/1261139#M126834</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PA 1410&lt;BR /&gt;PAN-OS&amp;nbsp;&lt;SPAN&gt;11.1.13-h9&lt;/SPAN&gt;&lt;BR /&gt;license valid&amp;nbsp;&lt;BR /&gt;&lt;SPAN&gt;Advanced URL Filtering&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Advanced WildFire License&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just recently i have configure Log forwarding to our Splunk. We follow this document&amp;nbsp;&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGwCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGwCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the splunk is successfully receive&amp;nbsp;&lt;SPAN&gt;Traffic, Threat, System, GlobalProtect, and Config logs. But we missing the URL, wildlfire and tunnel logs&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can advise how to check further.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2026 01:58:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certain-logs-not-sending-to-splunk/m-p/1261139#M126834</guid>
      <dc:creator>Fariq_Zaidi</dc:creator>
      <dc:date>2026-08-06T01:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: Certain logs not sending to Splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certain-logs-not-sending-to-splunk/m-p/1261155#M126835</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/225107"&gt;@Fariq_Zaidi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How do you have your log forwarding profile configured? Do you have your log types set to All Logs for URL, Wildfire, and Tunnel?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For URL you also want to make sure that&amp;nbsp;URL Filtering profile uses an action such as &lt;STRONG data-end="271" data-start="262"&gt;alert&lt;/STRONG&gt;, &lt;STRONG data-end="282" data-start="273"&gt;block&lt;/STRONG&gt;, or &lt;STRONG data-end="299" data-start="287"&gt;continue&lt;/STRONG&gt; for the categories you want logged. Categories set to &lt;STRONG data-end="363" data-start="354"&gt;allow&lt;/STRONG&gt; may not generate a URL log.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the Tunnel logs, please confirm whether Tunnel Content Inspection is configured under &lt;STRONG data-end="2065" data-start="2033"&gt;Policies &amp;gt; Tunnel Inspection&lt;/STRONG&gt; and whether logs are generated locally under &lt;STRONG data-end="2149" data-start="2111"&gt;Monitor &amp;gt; Logs &amp;gt; Tunnel Inspection&lt;/STRONG&gt;. This log type applies to supported cleartext tunnels passing through the firewall and is separate from standard IPsec VPN status events. If you are looking for standard IPsec VPN events such as tunnel status, negotiation, or tunnel-monitor messages, those are typically found in the &lt;STRONG data-end="585" data-start="570"&gt;System logs. &lt;/STRONG&gt;So you should be covered there.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you go to&lt;STRONG&gt; Monitor &amp;gt; Logs &amp;gt; Wildfire&lt;/STRONG&gt; , do you see logs generated there during the time frame of when you were monitoring Splunk?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2026 03:38:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certain-logs-not-sending-to-splunk/m-p/1261155#M126835</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2026-08-06T03:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: Certain logs not sending to Splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/certain-logs-not-sending-to-splunk/m-p/1261160#M126837</link>
      <description>&lt;P&gt;Hi Jay&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for the feedback , see my answered below&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Do you have your log types set to All Logs for URL, Wildfire, and Tunnel?&amp;nbsp; - Yes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;For the URL we have setup correctly as we can see the URL logs in firewall&lt;/P&gt;
&lt;P&gt;For Tunnel inspection, we not configure under policy-&amp;gt; tunnel inspection .&amp;nbsp; so no logs seen in firewall (this is confirm)&lt;BR /&gt;For Wildfire -&amp;gt; yes we can see the logs generated&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="URL log.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/72207iCA4FD14022B57AD9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="URL log.png" alt="URL log.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Wildfire log.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/72208iC59F9B4DA6AE6AEF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Wildfire log.png" alt="Wildfire log.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;  &lt;BR /&gt;thank you&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2026 04:01:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/certain-logs-not-sending-to-splunk/m-p/1261160#M126837</guid>
      <dc:creator>Fariq_Zaidi</dc:creator>
      <dc:date>2026-08-06T04:01:20Z</dc:date>
    </item>
  </channel>
</rss>

