Loading

Palo Alto Network Integration

<div class="condensed-table">
| | |
| --- | --- |
| Version | 4.2.0 (View all) |
| Compatible Kibana version(s) | 8.7.1 or higher |
| Supported Serverless project types
What’s this? | Security
Observability |
| Subscription level
What’s this? | Basic |
| Level of support
What’s this? | Elastic |

</div>
This integration is for Palo Alto Networks PAN-OS firewall monitoring logs received over Syslog or read from a file. It currently supports messages of GlobalProtect, HIP Match, Threat, Traffic, User-ID, Authentication, Config, Correlated Events, Decryption, GTP, IP-Tag, SCTP, System and Tunnel Inspection types.

  • This integration supports PAN-OS versions 8.1 to 11.0, but limited compatibility is expected for earlier versions.
  • This integration supports logs of GlobalProtect for PAN-OS version 9.1.3 or above.
  • This integration supports logs of User-ID for PAN-OS version 8.1 or above.
  • This integration supports logs of Tunnel Inspection for PAN-OS version 9.1 or above.
  • This integration supports logs of configuration changes with and without details about the changed configuration(before-change-detail and after-change-detail). Please read Note for more details.
  • This module has been tested with logs generated by devices running PAN-OS versions 7.1 to 11.0.

To configure syslog monitoring, please follow the steps mentioned in the Configure Syslog Monitoring.

  • If events are getting truncated, then increase max_message_size option for TCP and UDP input type.

    • It can be found under Advanced Options and can be configured as per requirements. The default value of max_message_size is set to 50KiB.
  • If the TCP input is used, it is recommended that PAN-OS is configured to send syslog messages using the IETF (RFC 5424) format. In addition, RFC 6587 framing (Octet Counting) will be enabled by default on the TCP input.

  • If you want to see the configuration before and after the change(fields before-change-detail and after-change-detail) in the config-log, please use the following custom log format in the syslog server profile: 1,$receive_time,$serial,$type,$subtype,2561,$time_generated,$host,$vsys,$cmd,$admin,$client,$result,$path,$before-change-detail,$after-change-detail,$seqno,$actionflags,$dg_hier_level_1,$dg_hier_level_2,$dg_hier_level_3,$dg_hier_level_4,$vsys_name,$device_name,$dg_id,$comment,0,$high_res_timestamp

This is the panos data stream.