XSIAM logs from Palo Alto Firewall using syslog

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

XSIAM logs from Palo Alto Firewall using syslog

L2 Linker

https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sourc...


Why does the official guide only highlight Custom Formats for Traffic, Threat, URL, and File data logs? What about other NGFW/panorama log types, such as System logs where can I find the format for those?

 

Does Cortex XSIAM fail to parse remaining CEF logs properly, or does this mean other log categories are unsupported?

 

Cortex XSIAM NGFW 

1 REPLY 1

L6 Presenter

Hello @bridgetlitt ,

 

Greetings for the day.

 

-Cortex XSIAM’s standard CEF/Syslog ingestion officially supports only four NGFW log types: Traffic, Threat, URL, and File Data. These are automatically parsed into their respective datasets.

 

-Other logs such as System, Authentication, GlobalProtect, Tunnel, and User-ID are not officially supported through the standard CEF method and may not parse correctly.

 

Note: For collecting the full range of NGFW logs, CLCS / Strata Logging Service is the recommended approach, as it provides native parsing for these additional log types.Also, avoid using PANW/PALO as the vendor or NGFW_CEF as the product for unsupported log types, as these are reserved for the built-in parser.

 

------------------------------------

 

Through CLCS, XSIAM natively supports and parses a broader spectrum of NGFW/Panorama log types into dedicated datasets, including:

  • System Logs: panw_ngfw_system_raw
  • Authentication Logs: panw_ngfw_auth_raw
  • GlobalProtect Logs: panw_ngfw_globalprotect_raw
  • HIP Match Logs: panw_ngfw_hipmatch_raw
  • User-ID Logs: panw_ngfw_userid_raw
  • Traffic, Threat, URL, and File Data Logs

 

If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".

 

Thanks & Regards,
S. Subashkar Sekar

  • 109 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!