Skip to main content
This information is for Palo Alto Networks Telemetry Pipeline, which is a standalone product separate from Palo Alto Networks Cortex XCOR.
You can use the Splunk UF source plugin (name: tcp, alias: Splunk_UF) to ingest data from your Splunk Universal Forwarder instances into a telemetry pipeline. This is a push-based source plugin.

Supported telemetry types

The Splunk UF source plugin for Palo Alto Networks Telemetry Pipeline supports these telemetry types:

Configuration parameters

Use the parameters in this section to configure the Splunk UF source plugin. The Palo Alto Networks Telemetry Pipeline web interface uses the items in the Name column to describe these parameters. Pipeline configuration files use the items in the Key column as YAML keys.

Required

Advanced

Security and TLS

Splunk Universal Forwarder configuration