<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Data Filtering / URL Logs into Splunk in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/data-filtering-url-logs-into-splunk/m-p/2768#M2064</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the Palo Alto App working for the Threat/Traffic Logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, I would like to do the same for the Data Filtering / URL Logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if it is and how to do it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 13 Mar 2012 22:09:40 GMT</pubDate>
    <dc:creator>ikinnexi</dc:creator>
    <dc:date>2012-03-13T22:09:40Z</dc:date>
    <item>
      <title>Data Filtering / URL Logs into Splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/data-filtering-url-logs-into-splunk/m-p/2768#M2064</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the Palo Alto App working for the Threat/Traffic Logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, I would like to do the same for the Data Filtering / URL Logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if it is and how to do it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Mar 2012 22:09:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/data-filtering-url-logs-into-splunk/m-p/2768#M2064</guid>
      <dc:creator>ikinnexi</dc:creator>
      <dc:date>2012-03-13T22:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: Data Filtering / URL Logs into Splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/data-filtering-url-logs-into-splunk/m-p/2769#M2065</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I have URL --&amp;gt; Splunk running. Use the log forwarding option in the security rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.) Create URL profile with all cat. set to alert&lt;/P&gt;&lt;P&gt;2.) Create Syslog Server Profile for Splunk&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="2708" alt="13-03-2012 23-55-17.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/2708_13-03-2012 23-55-17.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3.) Create Log forwarding Profile&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="2709" alt="13-03-2012 23-58-03.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/2709_13-03-2012 23-58-03.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3.) Attach the URL alert profile to the appropriate security rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4.) Attach the log forwarding profile to the appropriate security rule (Options)&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="2710" alt="13-03-2012 23-59-11.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/2710_13-03-2012 23-59-11.png" /&gt;&lt;/P&gt;&lt;P&gt;done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not tested Data Filtering alerts into Splunk.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roland&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Mar 2012 23:01:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/data-filtering-url-logs-into-splunk/m-p/2769#M2065</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2012-03-13T23:01:29Z</dc:date>
    </item>
    <item>
      <title>Re: Data Filtering / URL Logs into Splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/data-filtering-url-logs-into-splunk/m-p/2770#M2066</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did exactly what you described and I still don't see URL or Data Filtering stuff in my Splunk. I'm running Splunk for Palo Alto Networks 3.0 and Splunk version 5.0.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you have to do anything special in Splunk to get this data to show up?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 11:42:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/data-filtering-url-logs-into-splunk/m-p/2770#M2066</guid>
      <dc:creator>jwolach</dc:creator>
      <dc:date>2013-04-24T11:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: Data Filtering / URL Logs into Splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/data-filtering-url-logs-into-splunk/m-p/2771#M2067</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ahh... I just figured it out. My log forwarding profile was only forwarding Medium to High Severity levels. When I enabled Low &amp;amp; Informational the URL data started showing up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 11:43:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/data-filtering-url-logs-into-splunk/m-p/2771#M2067</guid>
      <dc:creator>jwolach</dc:creator>
      <dc:date>2013-04-24T11:43:58Z</dc:date>
    </item>
  </channel>
</rss>

