PaloAltoNetworks/Splunk_TA_paloalto

Logs are not parsing as expected.

Closed this issue · 1 comments

I have installed TA on my HF,Indexer and SH. Logs are not parsing as expected, I cannot see any src_ip/dst_ip etc on my fields. And my logs looks like this :

image

I got my sourcetypes segregated properly. But fields are not parsed as expected.

Closing this as we have determined this to not be an issue with our Add-on. We will continue to support you through the email thread.