Closer, but still seeing an issue. Firewall config events are being parsed as pan:config, but without before and after change details. Other details are included, but before and after change details are both 0. When I set a custom log format and test changing an object name on the firewall, the logs are parsed as pan:log (not pan:config) and I can see the change detail in the raw event message, but now I've lost the other fields since it was parsed as pan:log.
... View more