Certain logs not sending to Splunk

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Certain logs not sending to Splunk

L3 Networker

Hi All,

 

PA 1410
PAN-OS 11.1.13-h9
license valid 
Advanced URL Filtering

Advanced WildFire License

 

Just recently i have configure Log forwarding to our Splunk. We follow this document 
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGwCAK

 

the splunk is successfully receive Traffic, Threat, System, GlobalProtect, and Config logs. But we missing the URL, wildlfire and tunnel logs

 

can advise how to check further.

 

Thank you

 

 

 

1 REPLY 1

Community Team Member

Hi @Fariq_Zaidi ,

 

How do you have your log forwarding profile configured? Do you have your log types set to All Logs for URL, Wildfire, and Tunnel?

 

For URL you also want to make sure that URL Filtering profile uses an action such as alert, block, or continue for the categories you want logged. Categories set to allow may not generate a URL log.

 

For the Tunnel logs, please confirm whether Tunnel Content Inspection is configured under Policies > Tunnel Inspection and whether logs are generated locally under Monitor > Logs > Tunnel Inspection. This log type applies to supported cleartext tunnels passing through the firewall and is separate from standard IPsec VPN status events. If you are looking for standard IPsec VPN events such as tunnel status, negotiation, or tunnel-monitor messages, those are typically found in the System logs. So you should be covered there. 

 

If you go to Monitor > Logs > Wildfire , do you see logs generated there during the time frame of when you were monitoring Splunk? 

 

 

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 22 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!