- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-05-2026 06:58 PM
Hi All,
PA 1410
PAN-OS 11.1.13-h9
license valid
Advanced URL Filtering
Advanced WildFire License
Just recently i have configure Log forwarding to our Splunk. We follow this document
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGwCAK
the splunk is successfully receive Traffic, Threat, System, GlobalProtect, and Config logs. But we missing the URL, wildlfire and tunnel logs
can advise how to check further.
Thank you
08-05-2026 08:38 PM
Hi @Fariq_Zaidi ,
How do you have your log forwarding profile configured? Do you have your log types set to All Logs for URL, Wildfire, and Tunnel?
For URL you also want to make sure that URL Filtering profile uses an action such as alert, block, or continue for the categories you want logged. Categories set to allow may not generate a URL log.
For the Tunnel logs, please confirm whether Tunnel Content Inspection is configured under Policies > Tunnel Inspection and whether logs are generated locally under Monitor > Logs > Tunnel Inspection. This log type applies to supported cleartext tunnels passing through the firewall and is separate from standard IPsec VPN status events. If you are looking for standard IPsec VPN events such as tunnel status, negotiation, or tunnel-monitor messages, those are typically found in the System logs. So you should be covered there.
If you go to Monitor > Logs > Wildfire , do you see logs generated there during the time frame of when you were monitoring Splunk?
08-05-2026 09:01 PM
Hi Jay
thank you for the feedback , see my answered below
Do you have your log types set to All Logs for URL, Wildfire, and Tunnel? - Yes
For the URL we have setup correctly as we can see the URL logs in firewall
For Tunnel inspection, we not configure under policy-> tunnel inspection . so no logs seen in firewall (this is confirm)
For Wildfire -> yes we can see the logs generated
thank you
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

