This information is for Palo Alto Networks Telemetry Pipeline, which is a standalone
product separate from Palo Alto Networks Cortex XCOR.
The Splunk HEC source plugin
(name: splunk, alias: splunk_hec) lets you ingest log data from the Splunk
HTTP Event Collector into a telemetry pipeline.
This is a
push-based
source plugin.
Supported telemetry types
The Splunk HEC source plugin for Palo Alto Networks Telemetry Pipeline supports these telemetry types:
Configuration parameters
Use the parameters in this section to configure the Splunk HEC source plugin. The
Palo Alto Networks Telemetry Pipeline web interface uses the items in the Name column to
describe these parameters. Pipeline configuration files
use the items in the Key column as YAML keys.
General
Security and TLS
Advanced