We're on v.9.1.8 for Panorama.
I've configured both ways in the MCAS Log collector settings - "PA Series Firewall" & "PA Series Firewall LEEF".
We've built the MCAS Log Collector based on the Ubuntu/Docker.
The Palos are successfully sending to the MCAS-LogCollector server. The MCAS-LogCollector is successfully sending "message" files upto MCAS, but it's not successfully parsing the file.
See the sample logs that M$ provides with each of these - that I've attached here. These don't match our formats.
Looks like we'll need to build a Custom Format on the Palo side???
... View more