Authors: Brian Torres-Gil and Paul Nguyen - Palo Alto Networks
Upgrading from 4.x to 5.x? Use the Upgrade Guide:
Installation and Getting Started: http://pansplunk.readthedocs.io/en/latest/getting_started.html
Release Notes: http://pansplunk.readthedocs.io/en/latest/release_notes.html
* Endpoint Operations Dashboard
* Endpoint Security Dashboard
* Endpoint Dashboard support new Traps 3.4 fields
* Support for AutoFocus Remote Search via External Search Handler
* Support for Firewall Log Link via External Search Handler
* Improved AutoFocus cross launch
- Changes made to meet new certification requirements
- GlobalProtect Dashboard
- Other updates are in the Add-on (https://splunkbase.splunk.com/app/2757)
Important App Upgrade Notes
- App 5.3.x requires Add-on 3.7.x
- The App setup screen has moved to the Add-on. If you has previous set firewall credentials or a WildFire API key in the App setup screen, you’ll need to set them in the Add-on setup screen. See Step 2: Initial Setup in the Getting Started Guide.
- Datamodel acceleration might rebuild itself after installation due to updated constraints
- Eventtype pan_threat no longer includes these log_subtypes: url, data, file, and wildfire. You might need to update custom searches or panels you created that leverage the pan_threat eventtype. There are new eventtypes for each of the removed log_subtypes: pan_url, pan_data, pan_file, and pan_wildfire.
* App Certified by Splunk
Note: As a certification requirement, this version drops support for Splunk 6.1 and earlier, and removes deprecated commands (**panblock** and **panupdate**). If you are using Splunk 6.1, please upgrade Splunk to 6.2 or higher before upgrading this App. If you are using panblock or panupdate, please use pantag and panuserupdate instead before upgrading this App.
Splunk's App Certification program uses a specific set of criteria to evaluate the level of quality, usability and security your app offers to its users. In addition, we evaluate the documentation and support you offer to your app's users.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 50GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.