Configure Splunk to collect data from Paloalto!
Bit-Lab
0:00 / 0:00
Configure Splunk to collect data from Paloalto!
3 144 просмотра · 2 года назад
Bit-Lab
236 подписчиков
3 144 просмотра · 2 года назад
Configure Log forwarding profile on Paloalto firewall and apply it to the Security Policy Rule to send logs to Splunk via Syslog.
#splunk #paloaltofirewall #pcnsa #pcnse
0:00 - Intro
01:01 - Topology
01:23 - Download/Install Splunk
02:28 - Install Paloalto App/Add-on for Splunk
03:02 - Configure Data Input
04:18 - Configure Server Profile
04:45 - Configure Log Forwarding
05:26 - Service route configuration
06:16 - Apply log Forwarding
06:48 - Test
07:07 - Checking Splunk logs
07:30 - Extract new fields
09:09 - Adding colore code
10:18 - Events search
11:18 - Troubleshooting
12:57 - Thank You!
Download Splunk Enterprise:
https://www.splunk.com/en_us/download...
Event type coloring configuration file:
https://community.splunk.com/t5/Dashb...
Splunk folder location:
C:\Program Files\Splunk\etc\system\local
My LinkedIn:
/ hamza-al-sammarai-276856206
Atea website: https://atea.com/