Palo Alto 11 Content Pack

The following content pack is available for use with a Graylog Illuminate license and Graylog Enterprise or Graylog Security. Contact sales to learn more about obtaining Illuminate.

Palo Alto Networks next-generation firewalls provide real-time threat prevention, application visibility, and user-based policy enforcement. This technology pack processes Palo Alto PAN-OS 11.x logs, providing normalization and enrichment of common events of interest across all supported log types.

Supported Versions

  • PAN-OS 11.1+

Requirements

  • Graylog Server 6.1.0+ with a valid Enterprise license.

  • Palo Alto Device(s) sending logs to the Palo Alto 11.x input on the Graylog system.

Warning: Palo Alto devices must be configured to send data without custom formats. Custom syslog formats are not supported.

Stream Configuration

This technology pack includes 1 stream. If you were previously using the Palo Alto 9.x pack with Illuminate, this pack uses the same stream:

  • "Illuminate:Palo Alto Messages"

Hint: If this stream does not exist prior to the activation of this pack then it is created and configured to route messages to this stream and the associated index set. There should not be any stream rules configured for this stream.

Index Set Configuration

This technology pack includes 1 index set definition:

  • "Palo Alto Logs"

Hint: If this index set is already defined, then nothing is changed. If this index set does not exist, then it is created with retention settings of a daily rotation and 90 days of retention. These settings can be adjusted as required after installation.

Log Collection

Configure Palo Alto devices to send logs via TCP transport using BSD format. Refer to the Palo Alto syslog monitoring guide for device configuration. Devices must send data without custom formats for proper processing.

Hint: Enable the Store full message? option on the Palo Alto 11 input if you require the unmodified, full log message stored in Graylog. Otherwise common fields are pruned from message values.

Log Processing

This content pack processes the following PAN-OS 11.x log types. Newer PAN-OS versions may introduce additional fields; these are captured in placeholder fields prefixed with additional_field_ (a through x). When only an IPv6 address is present (IPv4 logged as 0.0.0.0), the IPv6 value is reassigned to the appropriate IP field. Brief message summaries are generated for Threat and Traffic logs in place of verbose CSV data.

  • Config - administrator configuration change events.

  • Decryption - SSL/TLS inspection events with certificate and cipher details.

  • GlobalProtect - VPN client tunnel lifecycle and authentication events.

  • HIP Match - host information profile compliance check events.

  • System - firewall system and DHCP events.

  • Threat - intrusion detection alerts including virus, spyware, vulnerability, WildFire, and URL filtering.

  • Traffic - network session start, end, and drop events.

  • User-ID - user-to-IP mapping and logout events.

GIM Categorization

GIM event type categorization is provided for the following message types:

Field Normalization

Fields extracted and normalized for each PAN-OS 11.x log type.

Common Fields

Config Log Fields

Decryption Log Fields

GlobalProtect Log Fields

HIP Match Log Fields

System Log Fields

Threat Log Fields

Traffic Log Fields

User-ID Log Fields

Enrichments

Illuminate enriches events with data to make working with events easier.

application_risk

Some Palo Alto logs include a numeric risk-scoring value, assigned to the field application_risk_level for logged applications, on a scale of 1 (lowest) to 5 (highest). Illuminate also adds the field application_risk_score, which provides a text value that reflects the rating of the numeric risk score.

Palo Alto 11 Spotlight Content Pack

This spotlight offers a dashboard with 6 tabs:

Overview

Traffic

Threat

GlobalProtect

URL Filtering

Decryption