- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-20-2025 01:03 AM
Hi team,
I'm currently working on integrating log analysis and would like to collect sample log events for all Next Generation Firewall log event types
Is there a way to access a reference dataset or sample payloads for each log event type for testing and validation purposes?
Thanks in advance!
06-23-2025 12:43 PM
Hello,
I'm have not seen one. I do alert on High and Critical events. Alerting by criticality rather than an actual event. Some events I do create specific alerts on however.
Is this for a SIEM or from the PAN?
Regards,
06-23-2025 08:36 PM
Thanks for your response.
Just to clarify, I’m looking for logs for both:
SIEM Integration: We’re testing alert rules and correlation based on Palo Alto Networks (PAN) logs. This includes high and critical severity events, along with specific log types like threat, traffic, config, and system logs.
Direct from PAN: We’re also reviewing alerting capabilities directly from the PAN platform, so we need log samples to help with testing, enrichment, and validation.
If you could share sample logs (sanitized if needed) for key PAN log types like THREAT, TRAFFIC, SYSTEM, CONFIG, HIPMATCH, and CORRELATION, that would be very helpful for our integration work.
Thanks again
06-24-2025 05:07 AM
I'm not sure about the platform you are using but I found this
07-09-2025 12:24 AM
can you provide sample schema for these THREAT, TRAFFIC, SYSTEM, CONFIG, HIPMATCH, and CORRELATION in Json format.
07-09-2025 07:59 PM
Hello @suresh.nalamolu
You can find all the fields for each type of logs in the documentation.
https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/monitoring/use-syslog-for-monitoring/sysl...
Olivier
PCSNE - CISSP
Best Effort contributor
Check out our PANCast Channel
Disclaimer : All messages are my personal ones and do not represent my company's view in any way.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!