<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Palo Alto Networks App for QRadar Troubleshooting Guide in App for QRadar Articles</title>
    <link>https://live.paloaltonetworks.com/t5/app-for-qradar-articles/palo-alto-networks-app-for-qradar-troubleshooting-guide/ta-p/245380</link>
    <description>&lt;H2 id="panels-are-not-showing-any-data" class="code-line" style="font-weight: normal; position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="2"&gt;&lt;FONT color="#000000"&gt;Panels are not showing any data&lt;/FONT&gt;&lt;/H2&gt;
&lt;HR /&gt;
&lt;H3 class="code-line  " style="font-weight: normal; position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="4"&gt;&amp;nbsp;&lt;/H3&gt;
&lt;H3 id="check-to-see-if-logs-are-being-forwarded-properly" class="code-line  " style="font-weight: normal; position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="4"&gt;&lt;FONT color="#000000"&gt;1. Check to see if logs are being forwarded properly&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Confirm you are receiving LEEF log format in QRadar, navigate to the “Log Activity” tab of QRadar and create an advanced search:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;PRE&gt;&lt;FONT color="#000000"&gt;SELECT UTF8(payload) FROM events WHERE devicetype=206&lt;/FONT&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="12"&gt;&lt;FONT color="#000000"&gt;No Results&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="14"&gt;&lt;FONT color="#000000"&gt;Check log forwarding configurations in the Firewall/Panorama. Refer to the getting started guide on how to setup log forwarding from the Firewall/Panorama.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="14"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="16"&gt;&lt;FONT color="#000000"&gt;Results&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="18"&gt;&lt;FONT color="#000000"&gt;Double check that the log contains the word&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE style="color: var(--vscode-textpreformat-foreground); font-family: Menlo, Monaco, Consolas, 'Droid Sans Mono', 'Courier New', monospace, 'Droid Sans Fallback'; font-size: 14px; line-height: 19px;"&gt;LEEF&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in the payload.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="20"&gt;&lt;FONT color="#000000"&gt;If&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE style="color: var(--vscode-textpreformat-foreground); font-family: Menlo, Monaco, Consolas, 'Droid Sans Mono', 'Courier New', monospace, 'Droid Sans Fallback'; font-size: 14px; line-height: 19px;"&gt;LEEF&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;does not exist in the payload then you have setup log forwarding with standard log format. By default QRadar expects logs to be in LEEF format. Refer to the getting started guide on how to send logs in LEEF format.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="20"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;A title="Creating a Syslog destination on your Palo Alto PA Series device | IBM" href="https://www.ibm.com/support/knowledgecenter/en/SS42VS_DSM/t_dsm_guide_palo_alto_syslog_dest.html?cp=SS42VS_7.3.0" target="_blank" rel="noopener"&gt;LEEF Log Forwarding Guide&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="20"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#FF9900"&gt;&lt;STRONG&gt;NOTE: &lt;/STRONG&gt;&lt;FONT color="#000000"&gt;M&lt;/FONT&gt;&lt;FONT color="#000000"&gt;ake sure you are using LEEF format for PAN-OS v7.0-v8.0+&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&amp;nbsp;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="26"&gt;&lt;FONT color="#000000"&gt;If LEEF exist in the payload, then there may be an issue with the custom properties. &lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="26"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="26"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3 id="check-that-custom-properties-are-correct" class="code-line" style="font-weight: normal; position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="28"&gt;&lt;FONT color="#000000"&gt;2. Check that custom properties are correct&lt;/FONT&gt;&lt;/H3&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="30"&gt;&lt;FONT color="#000000"&gt;Confirm each field is being parsed by running this search in the "Log Activity" tab of QRadar.&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="30"&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="30"&gt;&lt;FONT face="courier new,courier" color="#000000"&gt;SELECT "PANW-type", "PANW-subtype", "PANW-category", "PANW-filename", "PANW-threatid", "PANW-vendor-action" from events WHERE "PANW-type"='THREAT'&lt;/FONT&gt;&lt;/PRE&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="30"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="30"&gt;&lt;FONT color="#000000"&gt;The columned returned should have values in them. If you are receiving "NA" in the column then there is an issue with the parser.&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="30"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="32"&gt;&lt;FONT color="#000000"&gt;Navigate to the admin panel and click on&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;CODE style="color: var(--vscode-textpreformat-foreground); font-family: Menlo, Monaco, Consolas, 'Droid Sans Mono', 'Courier New', monospace, 'Droid Sans Fallback'; font-size: 14px; line-height: 19px;"&gt;Extensions" and c&lt;/CODE&gt;onfirm that the "Palo Alto Networks&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE style="color: var(--vscode-textpreformat-foreground); font-family: Menlo, Monaco, Consolas, 'Droid Sans Mono', 'Courier New', monospace, 'Droid Sans Fallback'; font-size: 14px; line-height: 19px;"&gt;LEEF to Standard log" extension&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;NOT&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;installed.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="34"&gt;&lt;FONT color="#000000"&gt;This extension is only required if if logs are being sent in the standard log format. This format is not recommended by QRadar. The recommended log format is LEEF. &lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="34"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="36"&gt;&lt;FONT color="#000000"&gt;LEEF to standard log extension was installed&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="38"&gt;&lt;FONT color="#000000"&gt;Uninstall both the App and the extension. Then reinstall only the Palo Alto Networks QRadar App.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;LEEF logs are being sent but still receiving "NA" in the columns&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;You may have setup the older LEEF log format on the Firewall/Panorama. In this case please review the LEEF Log Forwarding Guide and make sure you are using PAN-OS v7.0 - v8.0+ format in the log forwarding profile.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&lt;A title="Creating a Syslog destination on your Palo Alto PA Series device | IBM" href="https://www.ibm.com/support/knowledgecenter/en/SS42VS_DSM/t_dsm_guide_palo_alto_syslog_dest.html?cp=SS42VS_7.3.0" target="_blank" rel="noopener"&gt;LEEF Log Forwarding Guide&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="20"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#FF9900"&gt;&lt;STRONG&gt;NOTE: &lt;/STRONG&gt;&lt;FONT color="#000000"&gt;Make sure you are using LEEF format for PAN-OS v7.0-v8.0+&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="20"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="20"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#FF9900"&gt;&lt;FONT color="#000000"&gt;For further support please contact qradar@paloaltonetworks.com&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 26 Aug 2019 19:41:53 GMT</pubDate>
    <dc:creator>panguyen</dc:creator>
    <dc:date>2019-08-26T19:41:53Z</dc:date>
    <item>
      <title>Palo Alto Networks App for QRadar Troubleshooting Guide</title>
      <link>https://live.paloaltonetworks.com/t5/app-for-qradar-articles/palo-alto-networks-app-for-qradar-troubleshooting-guide/ta-p/245380</link>
      <description>&lt;H2 id="panels-are-not-showing-any-data" class="code-line" style="font-weight: normal; position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="2"&gt;&lt;FONT color="#000000"&gt;Panels are not showing any data&lt;/FONT&gt;&lt;/H2&gt;
&lt;HR /&gt;
&lt;H3 class="code-line  " style="font-weight: normal; position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="4"&gt;&amp;nbsp;&lt;/H3&gt;
&lt;H3 id="check-to-see-if-logs-are-being-forwarded-properly" class="code-line  " style="font-weight: normal; position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="4"&gt;&lt;FONT color="#000000"&gt;1. Check to see if logs are being forwarded properly&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Confirm you are receiving LEEF log format in QRadar, navigate to the “Log Activity” tab of QRadar and create an advanced search:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;PRE&gt;&lt;FONT color="#000000"&gt;SELECT UTF8(payload) FROM events WHERE devicetype=206&lt;/FONT&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="12"&gt;&lt;FONT color="#000000"&gt;No Results&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="14"&gt;&lt;FONT color="#000000"&gt;Check log forwarding configurations in the Firewall/Panorama. Refer to the getting started guide on how to setup log forwarding from the Firewall/Panorama.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="14"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="16"&gt;&lt;FONT color="#000000"&gt;Results&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="18"&gt;&lt;FONT color="#000000"&gt;Double check that the log contains the word&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE style="color: var(--vscode-textpreformat-foreground); font-family: Menlo, Monaco, Consolas, 'Droid Sans Mono', 'Courier New', monospace, 'Droid Sans Fallback'; font-size: 14px; line-height: 19px;"&gt;LEEF&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in the payload.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="20"&gt;&lt;FONT color="#000000"&gt;If&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE style="color: var(--vscode-textpreformat-foreground); font-family: Menlo, Monaco, Consolas, 'Droid Sans Mono', 'Courier New', monospace, 'Droid Sans Fallback'; font-size: 14px; line-height: 19px;"&gt;LEEF&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;does not exist in the payload then you have setup log forwarding with standard log format. By default QRadar expects logs to be in LEEF format. Refer to the getting started guide on how to send logs in LEEF format.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="20"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;A title="Creating a Syslog destination on your Palo Alto PA Series device | IBM" href="https://www.ibm.com/support/knowledgecenter/en/SS42VS_DSM/t_dsm_guide_palo_alto_syslog_dest.html?cp=SS42VS_7.3.0" target="_blank" rel="noopener"&gt;LEEF Log Forwarding Guide&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="20"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#FF9900"&gt;&lt;STRONG&gt;NOTE: &lt;/STRONG&gt;&lt;FONT color="#000000"&gt;M&lt;/FONT&gt;&lt;FONT color="#000000"&gt;ake sure you are using LEEF format for PAN-OS v7.0-v8.0+&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&amp;nbsp;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="26"&gt;&lt;FONT color="#000000"&gt;If LEEF exist in the payload, then there may be an issue with the custom properties. &lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="26"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="26"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3 id="check-that-custom-properties-are-correct" class="code-line" style="font-weight: normal; position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="28"&gt;&lt;FONT color="#000000"&gt;2. Check that custom properties are correct&lt;/FONT&gt;&lt;/H3&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="30"&gt;&lt;FONT color="#000000"&gt;Confirm each field is being parsed by running this search in the "Log Activity" tab of QRadar.&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="30"&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="30"&gt;&lt;FONT face="courier new,courier" color="#000000"&gt;SELECT "PANW-type", "PANW-subtype", "PANW-category", "PANW-filename", "PANW-threatid", "PANW-vendor-action" from events WHERE "PANW-type"='THREAT'&lt;/FONT&gt;&lt;/PRE&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="30"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="30"&gt;&lt;FONT color="#000000"&gt;The columned returned should have values in them. If you are receiving "NA" in the column then there is an issue with the parser.&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="30"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="32"&gt;&lt;FONT color="#000000"&gt;Navigate to the admin panel and click on&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;CODE style="color: var(--vscode-textpreformat-foreground); font-family: Menlo, Monaco, Consolas, 'Droid Sans Mono', 'Courier New', monospace, 'Droid Sans Fallback'; font-size: 14px; line-height: 19px;"&gt;Extensions" and c&lt;/CODE&gt;onfirm that the "Palo Alto Networks&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE style="color: var(--vscode-textpreformat-foreground); font-family: Menlo, Monaco, Consolas, 'Droid Sans Mono', 'Courier New', monospace, 'Droid Sans Fallback'; font-size: 14px; line-height: 19px;"&gt;LEEF to Standard log" extension&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;NOT&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;installed.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="34"&gt;&lt;FONT color="#000000"&gt;This extension is only required if if logs are being sent in the standard log format. This format is not recommended by QRadar. The recommended log format is LEEF. &lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="34"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="36"&gt;&lt;FONT color="#000000"&gt;LEEF to standard log extension was installed&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="38"&gt;&lt;FONT color="#000000"&gt;Uninstall both the App and the extension. Then reinstall only the Palo Alto Networks QRadar App.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;LEEF logs are being sent but still receiving "NA" in the columns&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;You may have setup the older LEEF log format on the Firewall/Panorama. In this case please review the LEEF Log Forwarding Guide and make sure you are using PAN-OS v7.0 - v8.0+ format in the log forwarding profile.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&lt;A title="Creating a Syslog destination on your Palo Alto PA Series device | IBM" href="https://www.ibm.com/support/knowledgecenter/en/SS42VS_DSM/t_dsm_guide_palo_alto_syslog_dest.html?cp=SS42VS_7.3.0" target="_blank" rel="noopener"&gt;LEEF Log Forwarding Guide&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="20"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#FF9900"&gt;&lt;STRONG&gt;NOTE: &lt;/STRONG&gt;&lt;FONT color="#000000"&gt;Make sure you are using LEEF format for PAN-OS v7.0-v8.0+&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="20"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="code-line" style="position: relative; color: #c5c8c6; font-family: -apple-system, system-ui, 'Segoe WPC', 'Segoe UI', HelveticaNeue-Light, Ubuntu, 'Droid Sans', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;" data-line="20"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#FF9900"&gt;&lt;FONT color="#000000"&gt;For further support please contact qradar@paloaltonetworks.com&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2019 19:41:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/app-for-qradar-articles/palo-alto-networks-app-for-qradar-troubleshooting-guide/ta-p/245380</guid>
      <dc:creator>panguyen</dc:creator>
      <dc:date>2019-08-26T19:41:53Z</dc:date>
    </item>
  </channel>
</rss>

