<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk For Palo Alto configuration in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/splunk-for-palo-alto-configuration/m-p/40#M33</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;﻿﻿﻿Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;When trying to create the log forwarding profile as you have explained to me, i noticed that we can associate only Threat and Traffig logs and there is no Configuration and System log, i've attached a picture to explain more the problem. Is there any other configuration to do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;Thanks&lt;/P&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;Nicolas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 02 Aug 2011 07:20:19 GMT</pubDate>
    <dc:creator>nmarchal</dc:creator>
    <dc:date>2011-08-02T07:20:19Z</dc:date>
    <item>
      <title>Splunk For Palo Alto configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/splunk-for-palo-alto-configuration/m-p/38#M31</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using Splunk as a tool to collect and correlate logs coming from my PAN, i am trynig to configure splunkforPaloAlto Application under Splunk but i don't see the 4 types of log files (Threat, traffic, System and configuration), i'am seeing only the traffic log, i am following the configuration guide to configure this application but i can't see all the log files. I am asking if is there any psecial configuration to implement with my PAN to receive all the logs in the Splunk.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Nicolas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jul 2011 08:36:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/splunk-for-palo-alto-configuration/m-p/38#M31</guid>
      <dc:creator>nmarchal</dc:creator>
      <dc:date>2011-07-28T08:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk For Palo Alto configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/splunk-for-palo-alto-configuration/m-p/39#M32</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to create a log-forwarding-profile where you specify that the traffic logs AND all of the threat logs need to be forwarded by syslog.&lt;/P&gt;&lt;P&gt;The you should apply this profile to all your firewall rules.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jul 2011 13:45:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/splunk-for-palo-alto-configuration/m-p/39#M32</guid>
      <dc:creator>Bart_Jocque</dc:creator>
      <dc:date>2011-07-28T13:45:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk For Palo Alto configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/splunk-for-palo-alto-configuration/m-p/40#M33</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;﻿﻿﻿Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;When trying to create the log forwarding profile as you have explained to me, i noticed that we can associate only Threat and Traffig logs and there is no Configuration and System log, i've attached a picture to explain more the problem. Is there any other configuration to do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;Thanks&lt;/P&gt;&lt;P style="margin-top:0pt;margin-right:0pt;margin-bottom:0pt;margin-left:0pt;padding-top:0pt;padding-right:0pt;padding-bottom:0pt;padding-left:0pt"&gt;Nicolas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Aug 2011 07:20:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/splunk-for-palo-alto-configuration/m-p/40#M33</guid>
      <dc:creator>nmarchal</dc:creator>
      <dc:date>2011-08-02T07:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk For Palo Alto configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/splunk-for-palo-alto-configuration/m-p/41#M34</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;you can find System &amp;amp; Config log settings under Device tab (Log Settings).&lt;/P&gt;&lt;P&gt;There you can decide where to send your system and config logs.&lt;/P&gt;&lt;P&gt;Bye&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Aug 2011 12:24:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/splunk-for-palo-alto-configuration/m-p/41#M34</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-08-02T12:24:02Z</dc:date>
    </item>
  </channel>
</rss>

