<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XSIAM logs from Palo Alto Firewall using syslog in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/xsiam-logs-from-palo-alto-firewall-using-syslog/m-p/1262840#M473</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/710084109"&gt;@bridgetlitt&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="198" data-start="0"&gt;-Cortex XSIAM’s standard &lt;STRONG data-end="48" data-start="24"&gt;CEF/Syslog ingestion&lt;/STRONG&gt; officially supports only four NGFW log types: &lt;STRONG data-end="134" data-start="95"&gt;Traffic, Threat, URL, and File Data&lt;/STRONG&gt;. These are automatically parsed into their respective datasets.&lt;/P&gt;
&lt;P data-end="198" data-start="0"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="371" data-start="200"&gt;-Other logs such as &lt;STRONG data-end="281" data-start="219"&gt;System, Authentication, GlobalProtect, Tunnel, and User-ID&lt;/STRONG&gt; are not officially supported through the standard CEF method and may not parse correctly.&lt;/P&gt;
&lt;P data-end="371" data-start="200"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="541" data-start="373"&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; For collecting the full range of NGFW logs, &lt;STRONG data-end="450" data-start="417"&gt;CLCS / Strata Logging Service&lt;/STRONG&gt; is the recommended approach, as it provides native parsing for these additional log types.Also, avoid using &lt;STRONG data-end="574" data-start="561"&gt;PANW/PALO&lt;/STRONG&gt; as the vendor or &lt;STRONG data-end="604" data-start="592"&gt;NGFW_CEF&lt;/STRONG&gt; as the product for unsupported log types, as these are reserved for the built-in parser.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;------------------------------------&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Through CLCS, XSIAM natively supports and parses a broader spectrum of NGFW/Panorama log types into dedicated datasets, including:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;System Logs&lt;/STRONG&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;panw_ngfw_system_raw&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Authentication Logs&lt;/STRONG&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;panw_ngfw_auth_raw&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;GlobalProtect Logs&lt;/STRONG&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;panw_ngfw_globalprotect_raw&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;HIP Match Logs&lt;/STRONG&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;panw_ngfw_hipmatch_raw&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;User-ID Logs&lt;/STRONG&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;panw_ngfw_userid_raw&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Traffic, Threat, URL, and File Data Logs&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
    <pubDate>Wed, 26 Aug 2026 01:59:19 GMT</pubDate>
    <dc:creator>susekar</dc:creator>
    <dc:date>2026-08-26T01:59:19Z</dc:date>
    <item>
      <title>XSIAM logs from Palo Alto Firewall using syslog</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/xsiam-logs-from-palo-alto-firewall-using-syslog/m-p/1262480#M468</link>
      <description>&lt;P&gt;&lt;A href="https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/next-generation-firewall/ingest-next-generation-firewall-logs-using-the-syslog-collector" target="_blank"&gt;https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/next-generation-firewall/ingest-next-generation-firewall-logs-using-the-syslog-collector&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Why does the official guide only highlight Custom Formats for Traffic, Threat, URL, and File data logs? What about other NGFW/panorama log types, such as System logs where can I find the format for those?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does Cortex XSIAM fail to parse remaining CEF logs properly, or does this mean other log categories are unsupported?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XSIAM" id="Cortex_XSIAM"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="NGFW" id="NGFW"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2026 05:33:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/xsiam-logs-from-palo-alto-firewall-using-syslog/m-p/1262480#M468</guid>
      <dc:creator>bridgetlitt</dc:creator>
      <dc:date>2026-08-21T05:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: XSIAM logs from Palo Alto Firewall using syslog</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/xsiam-logs-from-palo-alto-firewall-using-syslog/m-p/1262840#M473</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/710084109"&gt;@bridgetlitt&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="198" data-start="0"&gt;-Cortex XSIAM’s standard &lt;STRONG data-end="48" data-start="24"&gt;CEF/Syslog ingestion&lt;/STRONG&gt; officially supports only four NGFW log types: &lt;STRONG data-end="134" data-start="95"&gt;Traffic, Threat, URL, and File Data&lt;/STRONG&gt;. These are automatically parsed into their respective datasets.&lt;/P&gt;
&lt;P data-end="198" data-start="0"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="371" data-start="200"&gt;-Other logs such as &lt;STRONG data-end="281" data-start="219"&gt;System, Authentication, GlobalProtect, Tunnel, and User-ID&lt;/STRONG&gt; are not officially supported through the standard CEF method and may not parse correctly.&lt;/P&gt;
&lt;P data-end="371" data-start="200"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="541" data-start="373"&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; For collecting the full range of NGFW logs, &lt;STRONG data-end="450" data-start="417"&gt;CLCS / Strata Logging Service&lt;/STRONG&gt; is the recommended approach, as it provides native parsing for these additional log types.Also, avoid using &lt;STRONG data-end="574" data-start="561"&gt;PANW/PALO&lt;/STRONG&gt; as the vendor or &lt;STRONG data-end="604" data-start="592"&gt;NGFW_CEF&lt;/STRONG&gt; as the product for unsupported log types, as these are reserved for the built-in parser.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;------------------------------------&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Through CLCS, XSIAM natively supports and parses a broader spectrum of NGFW/Panorama log types into dedicated datasets, including:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;System Logs&lt;/STRONG&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;panw_ngfw_system_raw&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Authentication Logs&lt;/STRONG&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;panw_ngfw_auth_raw&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;GlobalProtect Logs&lt;/STRONG&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;panw_ngfw_globalprotect_raw&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;HIP Match Logs&lt;/STRONG&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;panw_ngfw_hipmatch_raw&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;User-ID Logs&lt;/STRONG&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;panw_ngfw_userid_raw&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Traffic, Threat, URL, and File Data Logs&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2026 01:59:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/xsiam-logs-from-palo-alto-firewall-using-syslog/m-p/1262840#M473</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-08-26T01:59:19Z</dc:date>
    </item>
  </channel>
</rss>

