{"repo":"criblpacks/cribl-palo-alto-networks","free":true,"listed":false,"github":"https://github.com/criblpacks/cribl-palo-alto-networks","clone":"git clone https://github.com/criblpacks/cribl-palo-alto-networks.git","description":"Process, reduce, and transform Palo Alto Networks Firewall logs.","language":"Python","stars":19,"topics":["network","stream-processing","palo-alto-networks","palo-alto","logstream","observability","pipelines","data","logs"],"license":"Apache-2.0","category":"data-pipelines","readme_excerpt":"Cribl Pack for Palo Alto Networks Firewalls ---- The Cribl Pack for Palo Alto Networks Firewalls processes events with the following goals in mind: 1. Events are received via syslog directly from Palo Alto firewalls 1. Add Splunk metadata to events (e.g. index, source, sourcetype, host) 2. Reduction of events by trimming the Syslog header and removing unnecessary fields such as \"future use\" and \"time\" fields. You should expect to see 15-30% reduction in the size of your Palo Alto Firewall log data. Installation --- 1. Install this pack from the Cribl Pack Dispensary, use the Git clone feature inside Cribl Stream, or download the most recent .crbl file from the repo releases page. 2. Create a Route with a filter for your Palo Alto Firewall events. A sample filter to match all events: 3. Select the cribl-palo-alto-networks pack as the pipeline. 4. Configure the Global Variable ( pan default index ) inside the Pack with the appropriate Splunk index for your Palo Alto logs. By default, the index field will be set to pan logs . Configure Device Information This pack assumes firewalls currently use UTC/GMT for their time zone configuration. If any device uses a local time zone, please configure an entry in the device info.csv lookup file (located in the pack's Knowledge content) to adjust timestamps with the timezone of the firewall. The timezone acts as the offset to adjust the timestamp of the event to UTC with the Auto Timestamp function. The lookup file expects data in two colu","default_branch":null,"files":null,"tree":[],"storefront":"/r/criblpacks","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/criblpacks/cribl-palo-alto-networks/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}