New

The executive guide to generative AI

Read more
Loading

Palo Alto Network Integration

Version 5.2.1 (View all)
Compatible Kibana version(s) 8.7.1 or higher
9.0.0 or higher
Supported Serverless project types
What's this?
Security
Observability
Subscription level
What's this?
Basic
Level of support
What's this?
Elastic

This integration is for Palo Alto Networks PAN-OS firewall monitoring logs received over Syslog or read from a file. It currently supports messages of GlobalProtect, HIP Match, Threat, Traffic, User-ID, Authentication, Config, Correlated Events, Decryption, GTP, IP-Tag, SCTP, System and Tunnel Inspection types.

  • This integration supports PAN-OS versions 8.1 to 11.0, but limited compatibility is expected for earlier versions.

  • This integration supports logs of GlobalProtect for PAN-OS version 9.1.3 or above.

  • This integration supports logs of User-ID for PAN-OS version 8.1 or above.

  • This integration supports logs of Tunnel Inspection for PAN-OS version 9.1 or above.

  • This integration supports logs of configuration changes with and without details about the changed configuration(before-change-detail and after-change-detail). Please read Note for more details.

  • This module has been tested with logs generated by devices running PAN-OS versions 7.1 to 11.0.

To configure syslog monitoring, please follow the steps mentioned in the Configure Syslog Monitoring.

  • If events are getting truncated, then increase max_message_size option for TCP and UDP input type.

    • It can be found under Advanced Options and can be configured as per requirements. The default value of max_message_size is set to 50KiB.
  • If the TCP input is used, it is recommended that PAN-OS is configured to send syslog messages using the IETF (RFC 5424) format. In addition, RFC 6587 framing (Octet Counting) will be enabled by default on the TCP input.

  • If you want to see the configuration before and after the change(fields before-change-detail and after-change-detail) in the config-log, please use the following custom log format in the syslog server profile: 1,$receive_time,$serial,$type,$subtype,2561,$time_generated,$host,$vsys,$cmd,$admin,$client,$result,$path,$before-change-detail,$after-change-detail,$seqno,$actionflags,$dg_hier_level_1,$dg_hier_level_2,$dg_hier_level_3,$dg_hier_level_4,$vsys_name,$device_name,$dg_id,$comment,0,$high_res_timestamp

This is the panos data stream.