<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Free visualisation (NOC screenboards) for PANW firewall performance/monitoring using Elastic Stack in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/free-visualisation-noc-screenboards-for-panw-firewall/m-p/196155#M58471</link>
    <description>&lt;P&gt;I was looking for ways to provide 'at-a-glance' visualisation of PANW firewall health, including traffic, threat, system &amp;amp; config logs. The stock capabilities, including ACC, are decent but somewhat lacking in providing NOC-style dashboards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Inspired by other visualisation solutions I've seen around, such as the Splunk App &amp;amp; Graylog dashboards, I spent the last 48 hours tinkering with ElasticStack 6.1 and came up with a series of 9 dashboards (and 66 visualisations) that can be derived from PANW Firewall syslogs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dashboard examples here;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Overview:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://imgur.com/xxl0XCf" target="_blank"&gt;https://imgur.com/xxl0XCf&lt;/A&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Traffic:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://imgur.com/xuxsmno" target="_blank"&gt;https://imgur.com/xuxsmno&lt;/A&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Applications:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://imgur.com/x7vdEwn" target="_blank"&gt;https://imgur.com/x7vdEwn&lt;/A&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Threats:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://imgur.com/obE4dIb" target="_blank"&gt;https://imgur.com/obE4dIb&lt;/A&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;System:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://imgur.com/O3A4p3n" target="_blank"&gt;https://imgur.com/O3A4p3n&lt;/A&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;There's another 4 dashboards too (Config, Threat [Warning+], URL &amp;amp; Blocked URLs)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The process of spinning up a Linux/Windows VM &amp;amp; installing Elastic Stack is pretty painless. Once done, dropping in the files required to create a syslog instance, ingest the syslogs and output the visualisations/dashboard is quite easy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've put all the relevant information, including a full tutorial on installing Elastic Stack, up on GitHub:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://github.com/sm-biz/paloalto-elasticstack-viz" target="_blank"&gt;https://github.com/sm-biz/paloalto-elasticstack-viz&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If anyone's interested, have a look and provide feedback. Any other types of dashboards that would be useful?&lt;/P&gt;&lt;P&gt;(Note: Wildfire dashboard is still-to-come, I need to generate some sample data)&lt;/P&gt;</description>
    <pubDate>Mon, 22 Jan 2018 09:49:38 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2018-01-22T09:49:38Z</dc:date>
    <item>
      <title>Free visualisation (NOC screenboards) for PANW firewall performance/monitoring using Elastic Stack</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/free-visualisation-noc-screenboards-for-panw-firewall/m-p/196155#M58471</link>
      <description>&lt;P&gt;I was looking for ways to provide 'at-a-glance' visualisation of PANW firewall health, including traffic, threat, system &amp;amp; config logs. The stock capabilities, including ACC, are decent but somewhat lacking in providing NOC-style dashboards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Inspired by other visualisation solutions I've seen around, such as the Splunk App &amp;amp; Graylog dashboards, I spent the last 48 hours tinkering with ElasticStack 6.1 and came up with a series of 9 dashboards (and 66 visualisations) that can be derived from PANW Firewall syslogs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dashboard examples here;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Overview:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://imgur.com/xxl0XCf" target="_blank"&gt;https://imgur.com/xxl0XCf&lt;/A&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Traffic:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://imgur.com/xuxsmno" target="_blank"&gt;https://imgur.com/xuxsmno&lt;/A&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Applications:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://imgur.com/x7vdEwn" target="_blank"&gt;https://imgur.com/x7vdEwn&lt;/A&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Threats:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://imgur.com/obE4dIb" target="_blank"&gt;https://imgur.com/obE4dIb&lt;/A&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;System:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://imgur.com/O3A4p3n" target="_blank"&gt;https://imgur.com/O3A4p3n&lt;/A&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;There's another 4 dashboards too (Config, Threat [Warning+], URL &amp;amp; Blocked URLs)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The process of spinning up a Linux/Windows VM &amp;amp; installing Elastic Stack is pretty painless. Once done, dropping in the files required to create a syslog instance, ingest the syslogs and output the visualisations/dashboard is quite easy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've put all the relevant information, including a full tutorial on installing Elastic Stack, up on GitHub:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://github.com/sm-biz/paloalto-elasticstack-viz" target="_blank"&gt;https://github.com/sm-biz/paloalto-elasticstack-viz&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If anyone's interested, have a look and provide feedback. Any other types of dashboards that would be useful?&lt;/P&gt;&lt;P&gt;(Note: Wildfire dashboard is still-to-come, I need to generate some sample data)&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2018 09:49:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/free-visualisation-noc-screenboards-for-panw-firewall/m-p/196155#M58471</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2018-01-22T09:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: Free visualisation (NOC screenboards) for PANW firewall performance/monitoring using Elastic Sta</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/free-visualisation-noc-screenboards-for-panw-firewall/m-p/288844#M76886</link>
      <description>&lt;P&gt;Can you please post any video tutorial for this ELK + palo alto log monitoring.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2019 18:18:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/free-visualisation-noc-screenboards-for-panw-firewall/m-p/288844#M76886</guid>
      <dc:creator>Chander</dc:creator>
      <dc:date>2019-09-17T18:18:17Z</dc:date>
    </item>
    <item>
      <title>Re: Free visualisation (NOC screenboards) for PANW firewall performance/monitoring using Elastic Sta</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/free-visualisation-noc-screenboards-for-panw-firewall/m-p/289010#M76915</link>
      <description>&lt;P&gt;Awesome. Thanks. Took me about a day to get this up and running on Ubuntu 18. The installation of Java 8 has changed, the PPA repo is no longer a viable solution, had to install it manually. The only other thing that tripped me up was the sysylog port, it was 5514 instead of the usual 514. Once I changed that on the syslog forward in the PA, everything started flowing ing in.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2019 20:54:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/free-visualisation-noc-screenboards-for-panw-firewall/m-p/289010#M76915</guid>
      <dc:creator>VincentPresogna</dc:creator>
      <dc:date>2019-09-18T20:54:56Z</dc:date>
    </item>
  </channel>
</rss>

