I believe I have fixed it, at least in the interim until it can be added to the Palo repo. According to Luigi here rsyslog (or more appropriately the package called rsyslog-minemeld in Ubuntu 14.04) Was built by them from source with additional features enabled, and distributed through their repo. It does not seem that rsyslog-minemeld is distrubuted in their current Xenial/16.04 repo.
http://minemeld-updates.panw.io/ubuntu xenial-minemeld main
However, when I built a current version of rsyslog with those features; it was incompatible with the /etc/rsyslog.d/*.conf files. I was able to find an old version of rsyslog "8.19.0", combile it, install the .deb file on my minemeld-server. I also installed I also installed via apt "librabbitmq4" and "liblognorm2" as refferenced by some of my /var/log/syslog errors. Once I did that, all the errors went away, and IPs started showing up in my miner/output.
... View more