Skip to content

Release history for the Splunk Add-on for Palo Alto Networks

Version 3.2.1 is the latest version of the Splunk Add-on for Palo Alto Networks. See Release Notes for the latest updates.

Version 3.2.0

Version 3.2.0 of the Splunk Add-on for Palo Alto Networks was released . It was tested with the following software, CIM versions, and platforms:

Component Description
Splunk platform versions 9.1.x, 9.2.x, 9.3.x, 9.4.x, 10.0.x, 10.1.x, 10.2.x, 10.3.x, 10.4.x
CIM 5.x
Platforms Platform independent
Vendor Products Cortex XDR, Device Security (former IoT Security), NGFW, Strata Logging Service, PAN-OS, Data Security

New features

Version 3.2.0 of the Splunk Add-on for Palo Alto Networks has the following new features:

  • Added SPL2 content for the pan:traffic, pan:threat, and pan:traffic:cloud sourcetypes.

To learn more about SPL2, see What is SPL2?.

Updates to the SPL2 modules

This release contains the following changes to the SPL2 modules:

  • Added field-extraction modules for the pan:traffic, pan:threat, and pan:traffic:cloud sourcetypes.

Note

After you install or upgrade the Splunk Add-on for Palo Alto Networks, SPL2 modules can take a short time to appear in the product experience while they are compiled.

For more information on SPL2 modules for this release, see the Modules section. For a general introduction to SPL2, see What is SPL2?.

Fixed issues

Version 3.2.0 of the Splunk Add-on for Palo Alto Networks contains the following fixed issues, if any.

Known issues

Version 3.2.0 of the Splunk Add-on for Palo Alto Networks contains the following known issues, if any.

Third-party software attributions

No new third-party software attributions were added for this release.

Version 3.1.0

Version 3.1.0 of the Splunk Add-on for Palo Alto Networks was released on May 22, 2026. It was tested with the following software, CIM versions, and platforms:

Component Description
Splunk platform versions 9.1.x, 9.2.x, 9.3.x, 9.4.x, 10.0.x, 10.1.x, 10.2.x, 10.3.x, 10.4.x
CIM 5.x
Platforms Platform independent
Vendor Products Cortex XDR, Device Security (former IoT Security), NGFW, Strata Logging Service, PAN-OS, Data Security

New features

Version 3.1.0 of the Splunk Add-on for Palo Alto Networks has the following new features:

  • Added Collect Alerts checkbox to the Cortex XDR modular input. Alerts are fetched via the get_alerts_multi_events API with pagination and rate-limit handling, and indexed as sourcetype pan:xdr:alert.
  • Added Collect Endpoints checkbox to the Cortex XDR modular input. All endpoints are fetched with pagination and indexed as sourcetype pan:xdr:endpoint.
  • Full CIM mappings for pan:xdr:alertIntrusion Detection (IDS_Attacks host-based).
  • Full CIM mappings for pan:xdr:endpointInventory datamodel.
  • Checkpoint mechanism for alert and endpoint inputs to track last-fetched position across restarts.

Fixed issues

Version 3.1.0 of the Splunk Add-on for Palo Alto Networks contains the following fixed issues, if any.

Known issues

Version 3.1.0 of the Splunk Add-on for Palo Alto Networks contains the following known issues, if any.

Third-party software attributions

Third-party software attributions for the Splunk Add-on for Palo Alto Networks

Version 3.0.1

Version 3.0.1 of the Splunk Add-on for Palo Alto Networks was released on Mar 31, 2026. It was tested with the following software, CIM versions, and platforms:

Component Description
Splunk platform versions 9.1.x, 9.2.x, 9.3.x, 9.4.x
CIM 5.x
Platforms Platform independent
Vendor Products Cortex XDR, Device Security (former IoT Security), NGFW, Strata Logging Service, PAN-OS, Data Security

Fixed issues

Version 3.0.1 of the Splunk Add-on for Palo Alto Networks contains the following fixed issues, if any.

Known issues

Version 3.0.1 of the Splunk Add-on for Palo Alto Networks contains the following known issues, if any.

Third-party software attributions

Third-party software attributions for the Splunk Add-on for Palo Alto Networks

Version 3.0.0

Version 3.0.0 of the Splunk Add-on for Palo Alto Networks was released on Nov 05, 2025. It was tested with the following software, CIM versions, and platforms:

Component Description
Splunk platform versions 9.1.x, 9.2.x, 9.3.x, 9.4.x
CIM 5.x
Platforms Platform independent
Vendor Products Cortex XDR, IoT Security, NGFW, Strata Logging Service, PAN-OS, Data Security

New features

  • Added new endpoints support in Cortex XDR input to collect management audit logs. Introduced a new sourcetype: pan:xdr:audit and pan:xdr:mgmt:audit.
  • Added compatibility with the default log formats of the latest product version 11.0.
  • Enhance lookup to extract few new fields — block-override, override, override-lockout, random-drop, and syncookie-sent.
  • Added CIM support for new sourcetypes pan:userid and pan:hipmatch.
  • The Account field in Cortex XDR inputs now also supports numeric values within the XDR tenant.

Breaking Changes

  • Modified the data model for security detections to align with ESCU content.
  • Renamed following sourcetypes as per standard practices:
    • pan:xdr_incident renamed to pan:xdr:incident
    • pan:firewall_cloud renamed to pan:firewall:cloud
  • Added sourcetype routing for pan:firewall_cloud events based on the LogType field, similar to the routing used for syslog events (for example,pan:firewall_cloud with LogType “traffic”, the sourcetype would be pan:traffic:cloud)

Fixed issues

Version 3.0.0 of the Splunk Add-on for Palo Alto Networks contains the following known issues, if any.

Known issues

Version 3.0.0 of the Splunk Add-on for Palo Alto Networks contains the following known issues, if any.

Third-party software attributions

Third-party software attributions for the Splunk Add-on for Palo Alto Networks

Version 2.0.2

Version 2.0.2 of the Splunk Add-on for Palo Alto Networks was released on Sep 1, 2025. It was tested with the following software, CIM versions, and platforms:

Splunk platform versions 9.1.x, 9.2.x, 9.3.x, 9.4.x
CIM 5.x
Platforms Platform independent
Vendor Products Cortex XDR, IoT Security, NGFW, Strata Logging Service, PAN-OS, Data Security

Fixed issues

Version 2.0.2 of the Splunk Add-on for Palo Alto Networks contains the following known issues, if any.

Known issues

Version 2.0.2 of the Splunk Add-on for Palo Alto Networks contains the following known issues, if any.

Third-party software attributions

Third-party software attributions for the Splunk Add-on for Palo Alto Networks

Version 2.0.1

Version 2.0.1 of the Splunk Add-on for Palo Alto Networks was released on May 23, 2025. It was tested with the following software, CIM versions, and platforms.

Splunk platform versions 9.1.x, 9.2.x
CIM 5.x
Platforms Platform independent
Vendor Products Cortex XDR, IoT Security, NGFW, Strata Logging Service, PAN-OS

Fixed issues

Version 2.0.1 of the Splunk Add-on for Palo Alto Networks contains the following fixed issues, if any.

Known issues

Version 2.0.1 of the Splunk Add-on for Palo Alto Networks contains the following known issues, if any.

Third-party software attributions

Third-party software attributions for the Splunk Add-on for Palo Alto Networks

Version 2.0.0

Component Description
Splunk platform versions 9.1.x, 9.2.x, 9.3.x, 9.4.x
CIM 5.x
Platforms Platform independent
Vendor Products Cortex XDR, IoT Security, NGFW, Strata Logging Service, PAN-OS, Data Security

New features

  • New modular input “Data Security”
  • New events for CIM normalization
  • Alert action for tagging IPs and users
  • Custom search command to update lookup tables
  • FedRAMP certification

Known issues

Version 2.0.0 of the Splunk Add-on for Palo Alto Networks contains the following known issues, if any.

Third-party software attributions

Third-party software attributions for the Splunk Add-on for Palo Alto Networks

Version 1.0.1

Version 1.0.1 of the Splunk Add-on for Palo Alto Networks was released on November 12, 2024. It was tested with the following software, CIM versions, and platforms:

Component Description
Splunk platform versions 9.1.x, 9.2.x
CIM 5.x
Platforms Platform independent
Vendor Products Cortex XDR, IoT Security, NGFW, Strata Logging Service, PAN-OS

Fixed issues

Version 1.0.1 of the Splunk Add-on for Palo Alto Networks contains the following fixed issues, if any.

Known issues

Version 1.0.1 of the Splunk Add-on for Palo Alto Networks contains the following known issues, if any.

Third-party software attributions

Third-party software attributions for the Splunk Add-on for Palo Alto Networks

Version 1.0.0

Version 1.0.0 of the Splunk Add-on for Palo Alto Networks was released on October 2, 2024. It was tested with the following software, CIM versions, and platforms:

Component Description
Splunk platform versions 9.1, 9.2
CIM 5.x
Platforms Platform independent
Vendor Products Cortex XDR, IoT Security, NGFW, Strata Logging Service, PAN-OS

New features

Version 1.0.0 of the Splunk Add-on for Palo Alto Networks has the following new features:

  • Modular inputs for IoT Security & Cortex XDR
  • Monitoring Dashboard
  • CIM normalization for supported vendor products

Third-party software attributions

Third-party software attributions for the Splunk Add-on for Palo Alto Networks for v1.0.0