Loading

Palo Alto Networks Integration

<div class="condensed-table">
| | |
| --- | --- |
| Version | 0.1.1 [beta] (View all) |
| Compatible Kibana version(s) | 8.15.2 or higher |
| Supported Serverless project types
What’s this? | Security
Observability |
| Subscription level
What’s this? | Basic |
| Level of support
What’s this? | Elastic |

</div>
This integration periodically fetches metrics from Palo Alto Networks firewalls and management systems.

The integration uses the Pango library to collect metrics from Palo Alto Networks firewalls.

This integration is designed to work with a single firewall at a time. Support for multiple firewalls within one integration policy is not available and has not been tested with Panorama. To collect metrics from multiple firewalls, create a separate integration policy for each firewall, specifying the respective host IP and API key.

The interfaces dataset collects detailed network interface statistics from Palo Alto Networks firewalls. It provides information about interface status, traffic throughput, packet counts, error rates, and configuration details, including physical, logical, and high-availability (HA) interfaces.

The fields reported are:

ECS Field Reference

Please refer to the following document for detailed information on ECS fields.

The routing dataset gathers comprehensive routing information from Palo Alto Networks devices. It includes details about routing protocols (with a focus on BGP), static and dynamic routes, next hops, AS numbers, and peer states. This dataset provides insights into the device’s routing table and its interactions with other network devices.

The fields reported are:

ECS Field Reference

Please refer to the following document for detailed information on ECS fields.

The system dataset collects a wide range of system-level metrics from Palo Alto Networks firewalls. This includes CPU usage, memory utilization, disk space, load averages, and process statistics. It also provides information about system uptime, licensed features, file system usage, and hardware component status (such as fans, thermal sensors, and power supplies).

The fields reported are:

ECS Field Reference

Please refer to the following document for detailed information on ECS fields.

The vpn dataset gathers detailed Virtual Private Network (VPN) statistics from Palo Alto Networks devices. It covers both GlobalProtect and IPsec VPN technologies, providing information about active VPN sessions, user connections, tunnel status, encryption details, and performance metrics. This dataset offers insights into VPN usage, security, and performance.

The fields reported are:

ECS Field Reference

Please refer to the following document for detailed information on ECS fields.