LEEF Log Format to Standard Log Format Extension

Printer Friendly Page

 As of Palo Alto Networks App for QRadar version 1.1.0, we have exclusively switched to LEEF log format support. Below are the details on how to install our standard log extension. This will overwrite the custom properties to use standard log format. 

 

  1. Download extension attached.
  2. In the QRadar console navigate to the "Admin" tab
  3. Click on "Extensions"
  4. Install the extension provided
  5. You will need to confirm that you want to overwrite the current extensions

If you re uninstall and re-install the Palo Alto Networks App for QRadar please be sure to uninstall this extension as well and re-install if needed.

 

Note: Uninstalling this extension will not restore LEEF format custom event properties. You will have to reinstall the app to get LEEF format to work.

 

 

Comments

Hello,

 

We are using this extension to keep logs sent in standard format, because we send logs simultaneously to QRadar and to a syslog archive. Box is running 7.1.7.

 

There's a problem with Config logs. Messages are being sent with "Configuration Path", but fields "Before Change" and "After Change" are missing.

Hi everybody

 

I installed App Palo Alto Networks for Qradar 1.1.1 and Palo Alto Networks Std Log Format for QRadar 1.0 in Qradar 7.3.1, but the app not display any information.

 

In contact with IBM Support they sayd:

 

"I see that the installation was successful however you still do not see any data. This is a matter that is supported by Palo Alto since we only take care of the installation.

Unfortunately, you will need to contact the vendor "Palo Alto" for any setup or configuration issues at their end."

 

Somebody can help-me about this problem?

Hi everybody

 

Facing similar issue. We installed App Palo Alto apps for Qradar 1.2.0 successfully. But, the dashboard for the app is not displaying any information.  All Zeros

 

Somebody can help us about this problem?

did anyone get a response or resolution to the Palo Alto app not showing any data? 

 

 

I have never actually seen this app working. Right now with the latest version of the app (1.2.0) and the standard log formatting app all we can see is the "Network Incidents", everything else is Error: Request failed with status code 422 

Ask Questions Get Answers Join the Live Community
Article Dashboard
Version history
Revision #:
11 of 11
Last update:
3 weeks ago
Updated by:
 
Contributors