• 521,421 Members
  • 799 Online
  • 1,129,088 Posts
  • 19,454 Solutions
  • 53,109 Likes

Welcome to Palo Alto Networks LIVEcommunity

Find answers, share solutions, and connect with peers and thought leaders from around the world.
New to LIVEcommunity? Check out our Welcome Guide.

Community Activity

Retrieve AIOps telemetry metrics via API

Anybody knows if this is possible or have code example? We have onprem Panorama managed firewalls sending telemetry data to cloud. In SCM web gui can see these under Insights => NGFW => Status and Monitoring. Now we want to utilize the collected metrics in some automation. For this we would need to retrieve the data somehow via api. ...

Anon1 by L4 Transporter
  • 51 Views
  • 1 replies
  • 0 Likes

What OS version is recommended for a Palo Alto 3410

Hello team, What OS version is recommended for a Palo Alto 3410, does not have a licence yet.Firewall is only doing basic security rules (no user-id / app id / security profiles) and basic routing.Currently it is on 11.1.4-h7.Could you please suggest if this OS is ok or need to upgrade to which version and reason for choosing that version please...

Network Security for the Frontier AI Era: Introducing PAN-OS 12.2 Ceres

5 min read

Palo Alto Networks has released PAN-OS 12.2 Ceres, marking the next major evolution in enterprise cyber prevention engineered to drastically reduce attack surfaces, disrupt threats, and stop advanced attacks. As cyber adversaries rapidly adopt AI automation, modern organizations face an overwhelming volume of direct-to-IP attacks, polymorphic ma...

Screenshot 2026-08-14 at 8.42.33 AM.png
Screenshot 2026-08-14 at 8.43.35 AM.png
JayGolf by Community Team Member
  • 76 Views
  • 0 replies
  • 1 Likes

Portal Sync Issue - Credit Pool Expired status for Active Eval E609278

Hello Support Team, My Eval Request E609278 was confirmed active until 09/10/2026 by the NextWave team. However, on my CSP portal (Account ID: 64687609), my Credit Pool ID 1279246520 is still showing as expired (07-10-2026) and the button "Create Deployment Profile" remains greyed out / disabled. Could you please refresh/sync my CSP account lice...

User-id mapping domain name issue

Hi everyone, I recently set up GP user-id mapping in our network. It's showing domain.local\username in the logs. I was also told to set up User-ID mapping using the windows agent as well since our users would need to disconnect from GP occasionally. The logs that we get from the windows agent is domain\username. Issue now is that when we se...

Specifications for Device Telemetry

Please let me know if you have any information. Regarding device telemetry, there was a report last year that it would be automated starting with releases from 10.2.17 onward. My understanding is that it will be enabled automatically and cannot be turned on or off.https://docs.paloaltonetworks.com/ngfw/administration/device-telemetry/device-te...

n-tomo by L2 Linker
  • 39 Views
  • 0 replies
  • 0 Likes

Does the GlobalProtect Credential Provider CLSID change between versions?

Hi all, We are considering using the Windows GPO “Assign a default credential provider” so that GlobalProtect is selected by default even on the “Other user” sign-in screen. It looks like we need to specify the CLSID (GUID) of the GlobalProtect Credential Provider in the GPO. I would like to confirm: 1. Is the GlobalProtect Credential Prov...

False positive submission - Generic.ml - Trauma Zer0 Disclosure v5.5.1.5

Hello Palo Alto Networks Threat Research Team, We are requesting a false-positive review and WildFire verdict reconsideration for a legitimate, digitally signed corporate application currently detected by Palo Alto Networks on VirusTotal as: Generic.ml File information: File name: Agent_Win_Disclosure.exeProduct: Trauma Zer0File version: 5.5.1.5...

Starlink DHCP Route Injection dropping if DHCP expires briefly

This is a remote location with a Starlink connected directly into a Palo Alto 510. We have another backup satellite connection provider which should be used for emergency / comms only when Starlink goes offline. Starlink renews its DHCP lease every 5 minutes. Normally, this works fine, and gets renewed successfully without interruption. Once...

GlobalProtect Silent Install

We are currently in the stages of switching over our equipment to palo alto. In preparation, we are installing the global protect app on all machines ahead of the migration. I've got a silent install setup, but once it completes, I get a connection failed message. I'm wondering if there's any way to suppress this message since it will fail until...

Sending case to a third party tickiting system

Hello, i hope you re doing well i want to know the steps to send cases when there generated to our third party tickiting system , how to do it via API or weebhook. can someone already worked on a similare case share with me all the steps and configuration required. thanks in advance Cortex XDR

Firewall SSH, the login succeeds with TACACS Account, but there is an issue that closes the session immediately.

Hello, everyone. Firewall has OS of 10.2.4-H2. When TACACS account to connect to Firewall SSH, the login succeeds, but there is an issue that closes the session immediately. In Firewall System-log, authentication and authorization were successful and it was confirmed that the Superuser role was granted.. However, a "create-admin-acct-err...

hbshin by L2 Linker
  • 2810 Views
  • 4 replies
  • 0 Likes

Palo Alto with Azure Issue

We are having weird issue going on that we can't resolve. I would appreciate if someone can help me in this. On prem palo is connected to ISP WAN switch that has direct internet connection no other device between these two. We have on prem new Palo Alto with all configuration pulled from Azure Panorama over SD-WAN tunnel that is on on prem ...

Upcoming Fuel Events

Top Contributors