Skip to main content
Splunk Add-on for Palo Alto Networks app icon

Splunk Add-on for Palo Alto Networks

Collects and normalizes security and network telemetry from Palo Alto Networks devices (firewalls, Panorama, Cortex XDR, IoT Security, Data Security) with CIM-compliant field extractions and modular inputs.Built by Splunk LLC
splunk product badge

Default Version 3.2.2

July 30, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2

CIM Version: 5.x

Rating
0
(0)

Log in to rate this app

Support
Splunk Supported

The Splunk Add-on for Palo Alto Networks collects and normalizes security and network telemetry from Palo Alto Networks devices, including firewalls, Panorama, Cortex XDR, IoT Security, and Data Security. It provides field extractions and maps events to Common Information Model (CIM) domains including Authentication, Network Traffic, Malware, Intrusion Detection, and Change. The add-on supports modular inputs for Cortex XDR incidents, IoT Security alerts, and Data Security incidents. It includes a custom search command (pancontentpack) for retrieving ContentPack threat intelligence, an alert action for dynamically tagging addresses and user groups on Palo Alto firewalls, and saved searches for creating notable events from Cortex XDR incidents. The add-on normalizes data from over 25 source types covering firewall traffic, threat logs, system events, GlobalProtect VPN, decryption logs, configuration changes, correlation events, IoT alerts and vulnerabilities, Data Security incidents, and Cortex XDR incident details. It uses KV store for device lookups and checkpointing to ensure reliable data collection across distributed Splunk deployments.