I have installed the Palo Alto App and add-on and i have also pointed a firewall to Splunk.
I can see traffic, threat logs ETC under search but cannot see anything in the App.
sourcetype is being seen correctly such as:
sourcetype=pan:traffic
sourcetype=pan:threat
What am i doing wrong or not doing!
↧