App for QRadar Articles

LEEF Log Format to Standard Log Format Extension

by panguyen on ‎03-07-2017 08:10 AM (9,499 Views)

 As of Palo Alto Networks App for QRadar version 1.1.0, we have exclusively switched to LEEF log format support. Below are the details on how to install our standard log extension. This will overwrite the custom properties to use standard log format. 


  1. Download extension attached.
  2. In the QRadar console navigate to the "Admin" tab
  3. Click on "Extensions"
  4. Install the extension provided
  5. You will need to confirm that you want to overwrite the current extensions

If you re uninstall and re-install the Palo Alto Networks App for QRadar please be sure to uninstall this extension as well and re-install if needed.


Note: Uninstalling this extension will not restore LEEF format custom event properties. You will have to reinstall the app to get LEEF format to work.



by feaquilino
on ‎09-19-2017 01:28 PM



We are using this extension to keep logs sent in standard format, because we send logs simultaneously to QRadar and to a syslog archive. Box is running 7.1.7.


There's a problem with Config logs. Messages are being sent with "Configuration Path", but fields "Before Change" and "After Change" are missing.

by lparana
on ‎05-02-2018 01:02 PM

Hi everybody


I installed App Palo Alto Networks for Qradar 1.1.1 and Palo Alto Networks Std Log Format for QRadar 1.0 in Qradar 7.3.1, but the app not display any information.


In contact with IBM Support they sayd:


"I see that the installation was successful however you still do not see any data. This is a matter that is supported by Palo Alto since we only take care of the installation.

Unfortunately, you will need to contact the vendor "Palo Alto" for any setup or configuration issues at their end."


Somebody can help-me about this problem?

by samatar
on ‎10-25-2018 04:21 AM

Hi everybody


Facing similar issue. We installed App Palo Alto apps for Qradar 1.2.0 successfully. But, the dashboard for the app is not displaying any information.  All Zeros


Somebody can help us about this problem?

by yzamora1
on ‎11-05-2018 11:27 AM

did anyone get a response or resolution to the Palo Alto app not showing any data?