The Splunk Add-on for Palo Alto Networks collects and normalizes security and network telemetry from Palo Alto Networks devices, including firewalls, Panorama, Cortex XDR, IoT Security, and Data Security. It provides field extractions and maps events to Common Information Model (CIM) domains including Authentication, Network Traffic, Malware, Intrusion Detection, and Change. The add-on supports modular inputs for Cortex XDR incidents, IoT Security alerts, and Data Security incidents. It includes a custom search command (pancontentpack) for retrieving ContentPack threat intelligence, an alert action for dynamically tagging addresses and user groups on Palo Alto firewalls, and saved searches for creating notable events from Cortex XDR incidents. The add-on normalizes data from over 25 source types covering firewall traffic, threat logs, system events, GlobalProtect VPN, decryption logs, configuration changes, correlation events, IoT alerts and vulnerabilities, Data Security incidents, and Cortex XDR incident details. It uses KV store for device lookups and checkpointing to ensure reliable data collection across distributed Splunk deployments.