0% found this document useful (0 votes)
12 views28 pages

Oracle 19c RDBMS Integration SOP

This document outlines the Standard Operating Procedure for integrating Palo Alto PA Series events with IBM QRadar, detailing the objectives, prerequisites, and step-by-step configuration procedures. It emphasizes the necessity of specific database and network configurations, as well as the installation of required RPMs in QRadar. Additionally, it provides detailed instructions for configuring Syslog profiles and log formats for various PAN-OS versions.

Uploaded by

ali.hamza
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
12 views28 pages

Oracle 19c RDBMS Integration SOP

This document outlines the Standard Operating Procedure for integrating Palo Alto PA Series events with IBM QRadar, detailing the objectives, prerequisites, and step-by-step configuration procedures. It emphasizes the necessity of specific database and network configurations, as well as the installation of required RPMs in QRadar. Additionally, it provides detailed instructions for configuring Syslog profiles and log formats for various PAN-OS versions.

Uploaded by

ali.hamza
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Standard Operating Procedure

Palo Alto Network PA Series Integration SOP


Table of Contents
Objective................................................................................................................................................................3
Pre-Requisites.......................................................................................................................................................3
Procedure..............................................................................................................................................................4
Oracle RDBMS Audit Record JDBC log source parameters..................................................................................4
Reference Link:......................................................................................................................................................5

1
RESTRICTED

Disclaimers

This document is designed to provide helpful information on the subject matter within. The recipient
acknowledges and agrees that any advice, recommendations, reports, analyses, deliverables, or other
material supplied by Rewterz have been intended for the recipient solely for the benefit of the recipient
and not any other third party. Rewterz made every attempt to ensure the accuracy and reliability of the
information in this document. However, it assumes no responsibility for errors, omissions, misuse,
misunderstanding, or inapplicability of the contents of this document.

In no event shall Rewterz be liable for any special, direct, indirect, consequential, or incidental damages
or any damages whatsoever, whether in an action of contract, negligence, or other torts, arising out of
or in connection with the use of the information contained in this document.

Confidentiality

This document may contain information of a sensitive nature. This information should not be shared
with anyone other than those for whom it was originally intended. No one else may disclose, distribute,
or otherwise use the contents of this document without the express written permission of the owner.
Unauthorized use, disclosure, dissemination, duplication, and/or distribution are strictly prohibited and
may be unlawful. If you receive this document in error, please immediately delete it and all copies from
your system, destroy any hard copies and notify Rewterz.

Copyright

The information contained in this document is the proprietary and exclusive property of Rewterz except
as otherwise indicated. Notwithstanding its intended purpose, no part of this document, in whole or in
part, may be reproduced, stored, transmitted, or used for any purpose without the prior written
permission of the Company.

2
Objective
To send Palo Alto PA Series events to IBM QRadar, create a Syslog destination (LEEF or CEF event
format) on your Palo Alto PA Series device. Palo Alto can send only one format to all Syslog devices. By
modifying the Syslog format, any other device that requires Syslog must support that same format.

Pre-Requisites
Following pre-requisites are required for configuration at SIEM end:

 Database Name
 IP/Hostname
 User Name / Password (having read rights for that table/view)
 Table / View Name
 Compare Fields
 Port 1521 (default Oracle Net Listener port) is used for bidirectional communication via TCP
Protocol. Allow inbound TCP port 1521 on the Oracle Database server.
o Verify the Oracle listener is running and listening on port 1521 on public IPv4 address.
 Following below mentioned RPMS should be installed in QRadar
o Protocol JDBC RPM
o DSMCommon RPM
o Oracle RDBMS Audit Record DSM RPM

3
4
Procedure
Configure LEEF Formatted Events
Consider the following to configure the Syslog profile on the respective device:
1. Log in to Palo Alto Networks.
2. On the Device tab, click Server Profiles > Syslog, and then click Add.
3. Create a Syslog destination by following these steps:
a) In the Syslog Server Profile dialog box, click Add.
b) Specify the name, server IP address, port, and facility of the QRadar system that you want
to use as a Syslog server.
c) If you are using Syslog, set the Custom Format column to Default for all log types.
4. Configure LEEF events by following these steps:
a) Click the Custom Log Format tab in the Syslog Server Profile dialog.
b) Click Config, copy one of the following texts applicable to the version you are using, and
paste it in the Config Log Format field for the Config log type. If your version is not listed,
omit this step.

PAN-OS 3.0 - 6.1


LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|4.0|$result|x7C|cat=$type|
usrName=$admin|src=$host|devTime=$cef-formatted-receive_time|client=$client|
sequence=$seqno|serial=$serial|msg=$cmd
PAN-OS 7.1 - 9.1
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$result|x7C|
ReceiveTime=$receive_time|SerialNumber=$serial|cat=$type|devTime=$cef-formatted-
receive_time|src=$host|VirtualSystem=$vsys|msg=$cmd|usrName=$admin|client=$client|
Result=$result|ConfigurationPath=$path|sequence=$seqno|ActionFlags=$actionflags|
BeforeChangeDetail=$before-change-detail|AfterChangeDetail=$after-change-detail|
DeviceGroupHierarchyL1=$dg_hier_level_1|DeviceGroupHierarchyL2=$dg_hier_level_2|
DeviceGroupHierarchyL3=$dg_hier_level_3|DeviceGroupHierarchyL4=$dg_hier_level_4|
vSrcName=$vsys_name|DeviceName=$device_name
PAN-OS 10.0
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$result|x7C|
TimeReceived=$receive_time|DeviceSN=$serial|cat=$type|devTime=$cef-formatted-
receive_time|src=$host|VirtualSystem=$vsys|msg=$cmd|usrName=$admin|client=$client|
Result=$result|ConfigurationPath=$path|sequence=$seqno|ActionFlags=$actionflags|
BeforeChangeDetail=$before-change-detail|AfterChangeDetail=$after-change-detail|
DeviceGroupHierarchyL1=$dg_hier_level_1|DeviceGroupHierarchyL2=$dg_hier_level_2|
DeviceGroupHierarchyL3=$dg_hier_level_3|DeviceGroupHierarchyL4=$dg_hier_level_4|
vSrcName=$vsys_name|DeviceName=$device_name

5
c) Click System, then copy one of the following texts applicable to the version you are using,
and paste it in the System Log Format field for the System log type. If your version is not
listed, omit this step.

PAN-OS 3.0 - 6.1


LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|4.0|$eventid|x7C|cat=$type|
Subtype=$subtype|devTime=$cef-formatted-receive_time|sev=$severity|Severity=$number-
of-severity|msg=$opaque|Filename=$object
PAN-OS 7.1 - 9.1
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$eventid|x7C|
ReceiveTime=$receive_time|SerialNumber=$serial|cat=$type|Subtype=$subtype|
devTime=$cef-formatted-receive_time|VirtualSystem=$vsys|Filename=$object|
Module=$module|sev=$number-of-severity|Severity=$severity|msg=$opaque|
sequence=$seqno|ActionFlags=$actionflags|DeviceGroupHierarchyL1=$dg_hier_level_1|
DeviceGroupHierarchyL2=$dg_hier_level_2|DeviceGroupHierarchyL3=$dg_hier_level_3|
DeviceGroupHierarchyL4=$dg_hier_level_4|vSrcName=$vsys_name|
DeviceName=$device_name
PAN-OS 10.0
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$eventid|x7C|
TimeReceived=$receive_time|DeviceSN=$serial|cat=$type|Subtype=$subtype|
devTime=$cef-formatted-receive_time|VirtualSystem=$vsys|Filename=$object|
Module=$module|sev=$number-of-severity|Severity=$severity|msg=$opaque|
sequence=$seqno|ActionFlags=$actionflags|DeviceGroupHierarchyL1=$dg_hier_level_1|
DeviceGroupHierarchyL2=$dg_hier_level_2|DeviceGroupHierarchyL3=$dg_hier_level_3|
DeviceGroupHierarchyL4=$dg_hier_level_4|vSrcName=$vsys_name|
DeviceName=$device_name

6
d) Click Threat, copy one of the following texts applicable to the version you are using, and
paste it in the Threat Log Format field for the Threat log type. If your version is not listed,
omit this step.

PAN-OS 3.0 - 6.1


LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|4.0|$threatid|x7C|cat=$type|
Subtype=$subtype|src=$src|dst=$dst|srcPort=$sport|dstPort=$dport|proto=$proto|
usrName=$srcuser|SerialNumber=$serial|srcPostNAT=$natsrc|dstPostNAT=$natdst|
RuleName=$rule|SourceUser=$srcuser|DestinationUser=$dstuser|Application=$app|
VirtualSystem=$vsys|SourceZone=$fromDestinationZone=$to|IngressInterface=$inbound_if|
EgressInterface=$outbound_if|LogForwardingProfile=$logset|SessionID=$sessionid|
RepeatCount=$repeatcnt|srcPostNATPort=$natsport|dstPostNATPort=$natdport|
Flags=$flags|URLCategory=$category|sev=$severity|Severity=$number-of-severity|
Direction=$direction|ContentType=$contenttype|action=$action|Miscellaneous=$misc
PAN-OS 7.1
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$threatid|x7C|
ReceiveTime=$receive_time|SerialNumber=$serial|cat=$type|Subtype=$subtype|
devTime=$cef-formatted-receive_time|src=$src|dst=$dst|srcPostNAT=$natsrc|
dstPostNAT=$natdst|RuleName=$rule|usrName=$srcuser|SourceUser=$srcuser|
DestinationUser=$dstuser|Application=$app|VirtualSystem=$vsys|SourceZone=$from|
DestinationZone=$to|IngressInterface=$inbound_if|EgressInterface=$outbound_if|
LogForwardingProfile=$logset|SessionID=$sessionid|RepeatCount=$repeatcnt|
srcPort=$sport|dstPort=$dport|srcPostNATPort=$natsport|dstPostNATPort=$natdport|
Flags=$flags|proto=$proto|action=$action|Miscellaneous=$misc|ThreatID=$threatid|
URLCategory=$category|sev=$number-of-severity|Severity=$severity|Direction=$direction|
sequence=$seqno|ActionFlags=$actionflags|SourceLocation=$srcloc|
DestinationLocation=$dstloc|ContentType=$contenttype|PCAP_ID=$pcap_id|
FileDigest=$filedigest|Cloud=$cloud|URLIndex=$url_idx|UserAgent=$user_agent|
FileType=$filetype|identSrc=$xff|Referer=$referer|Sender=$sender|Subject=$subject|
Recipient=$recipient|ReportID=$reportid|DeviceGroupHierarchyL1=$dg_hier_level_1|
DeviceGroupHierarchyL2=$dg_hier_level_2|DeviceGroupHierarchyL3=$dg_hier_level_3|
DeviceGroupHierarchyL4=$dg_hier_level_4|vSrcName=$vsys_name|
DeviceName=$device_name
PAN-OS 8.0 - 9.1
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$threatid|x7C|
ReceiveTime=$receive_time|SerialNumber=$serial|cat=$type|Subtype=$subtype|
devTime=$cef-formatted-receive_time|src=$src|dst=$dst|srcPostNAT=$natsrc|

7
dstPostNAT=$natdst|RuleName=$rule|usrName=$srcuser|SourceUser=$srcuser|
DestinationUser=$dstuser|Application=$app|VirtualSystem=$vsys|SourceZone=$from|
DestinationZone=$to|IngressInterface=$inbound_if|EgressInterface=$outbound_if|
LogForwardingProfile=$logset|SessionID=$sessionid|RepeatCount=$repeatcnt|
srcPort=$sport|dstPort=$dport|srcPostNATPort=$natsport|dstPostNATPort=$natdport|
Flags=$flags|proto=$proto|action=$action|Miscellaneous=$misc|ThreatID=$threatid|
URLCategory=$category|sev=$number-of-severity|Severity=$severity|Direction=$direction|
sequence=$seqno|ActionFlags=$actionflags|SourceLocation=$srcloc|
DestinationLocation=$dstloc|ContentType=$contenttype|PCAP_ID=$pcap_id|
FileDigest=$filedigest|Cloud=$cloud|URLIndex=$url_idx|RequestMethod=$http_method|
Subject=$subject|DeviceGroupHierarchyL1=$dg_hier_level_1|
DeviceGroupHierarchyL2=$dg_hier_level_2|DeviceGroupHierarchyL3=$dg_hier_level_3|
DeviceGroupHierarchyL4=$dg_hier_level_4|vSrcName=$vsys_name|
DeviceName=$device_name|SrcUUID=$src_uuid|DstUUID=$dst_uuid|TunnelID=$tunnelid|
MonitorTag=$monitortag|ParentSessionID=$parent_session_id|
ParentStartTime=$parent_start_time|TunnelType=$tunnel|ThreatCategory=$thr_category|
ContentVer=$contentver
PAN-OS 10.0
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$threatid|x7C|
ProfileToken=$actionflags|TimeReceived=$receive_time|DeviceSN=$serial|cat=$type|
SubType=$subtype|ConfigVersion=$sender_sw_version|src=$src|dst=$dst|Rule=$rule|
usrName=$srcuser|Application=$app|VirtualLocation=$vsys|FromZone=$from|ToZone=$to|
InboundInterface=$inbound_if|OutboundInterface=$outbound_if|LogSetting=$logset|
SessionID=$sessionid|RepeatCount=$repeatcnt|srcPort=$sport|dstPort=$dport|
srcPostNATPort=$natsport|dstPostNATPort=$natdport|proto=$proto|Action=$action|
FileName=$misc|VendorSeverity=$severity|DirectionOfAttack=$direction|
SequenceNo=$seqno|SourceLocation=$srcloc|DestinationLocation=$dstloc|
PacketID=$pcap_id|FileHash=$filedigest|ApplianceOrCloud=$cloud|URLCounter=$url_idx|
FileType=$filetype|SenderEmail=$sender|EmailSubject=$subject|RecipientEmail=$recipient|
ReportID=$reportid|DGHierarchyLevel1=$dg_hier_level_1|
DGHierarchyLevel2=$dg_hier_level_2|DGHierarchyLevel3=$dg_hier_level_3|
DGHierarchyLevel4=$dg_hier_level_4|VirtualSystemName=$vsys_name|
DeviceName=$device_name|SourceUUID=$src_uuid|DestinationUUID=$dst_uuid|IMSI=$imsi|
IMEI=$imei|ParentSessionID=$parent_session_id|ParentStarttime=$parent_start_time|
Tunnel=$tunnel|ThreatCategory=$thr_category|ContentVersion=$contentver|
SigFlags=$sig_flags|RuleUUID=$rule_uuid|HTTP2Connection=$http2_connection|
DynamicUserGroupName=$dynusergroup_name|X-Forwarded-ForIP=$xff_ip|

8
SourceDeviceCategory=$src_category|SourceDeviceProfile=$src_profile|
SourceDeviceModel=$src_model|SourceDeviceVendor=$src_vendor|
SourceDeviceOSFamily=$src_osfamily|SourceDeviceOSVersion=$src_osversion|
v6SourceDeviceHost=$src_host|SourceDeviceMac=$src_mac|
DestinationDeviceCategory=$dst_category|DestinationDeviceProfile=$dst_profile|
DestinationDeviceModel=$dst_model|DestinationDeviceVendor=$dst_vendor|
DestinationDeviceOSFamily=$dst_osfamily|DestinationDeviceOSVersion=$dst_osversion|
DestinationDeviceHost=$dst_host|DestinationDeviceMac=$dst_mac|
ContainerID=$container_id|ContainerNameSpace=$pod_namespace|
ContainerName=$pod_name|SourceEDL=$src_edl|DestinationEDL=$dst_edl|HostID=$hostid|
EndpointSerialNumber=$serialnumber|DomainEDL=$domain_edl|
SourceDynamicAddressGroup=$src_dag|DestinationDynamicAddressGroup=$dst_dag|
PartialHash=$partial_hash|TimeGeneratedHighResolution=$high_res_timestamp|
NSSAINetworkSliceType=$nssai_sst|devTimeFormat=$cef-formatted-time_generated

e) Click Traffic, copy one of the following texts applicable to the version you are using, and
paste it in the Traffic Log Format field for the Traffic log type. If your version is not listed,
omit this step.

PAN-OS 3.0 - 6.1


LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|4.0|$action|x7C|cat=$type|src=$src|
dst=$dst|srcPort=$sport|dstPort=$dport|proto=$proto|usrName=$srcuser|
SerialNumber=$serial|Type=$type|Subtype=$subtype|srcPostNAT=$natsrc|
dstPostNAT=$natdst|RuleName=$rule|SourceUser=$srcuser|DestinationUser=$dstuser|
Application=$app| VirtualSystem=$vsys|SourceZone=$from|DestinationZone=$to|
IngressInterface=$inbound_if|EgressInterface=$outbound_if|LogForwardingProfile=$logset|
SessionID=$sessionid|RepeatCount=$repeatcnt|srcPostNATPort=$natsport|
dstPostNATPort=$natdport|Flags=$flags|totalBytes=$bytes|totalPackets=$packets|
ElapsedTime=$elapsed|URLCategory=$category|dstBytes=$bytes_received|
srcBytes=$bytes_sent|action=$action
PAN-OS 7.1
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$action|x7C|
cat=$type|ReceiveTime=$receive_time|SerialNumber=$serial|Type=$type|
Subtype=$subtype|devTime=$cef-formatted-receive_time|src=$src|dst=$dst|
srcPostNAT=$natsrc|dstPostNAT=$natdst|RuleName=$rule|usrName=$srcuser|
SourceUser=$srcuser|DestinationUser=$dstuser|Application=$app|VirtualSystem=$vsys|
SourceZone=$from|DestinationZone=$to|IngressInterface=$inbound_if|
EgressInterface=$outbound_if|LogForwardingProfile=$logset|SessionID=$sessionid|

9
RepeatCount=$repeatcnt|srcPort=$sport|dstPort=$dport|srcPostNATPort=$natsport|
dstPostNATPort=$natdport|Flags=$flags|proto=$proto|action=$action|totalBytes=$bytes|
dstBytes=$bytes_received|srcBytes=$bytes_sent|totalPackets=$packets|StartTime=$start|
ElapsedTime=$elapsed|URLCategory=$category|sequence=$seqno|
ActionFlags=$actionflags|SourceLocation=$srcloc|DestinationLocation=$dstloc|
dstPackets=$pkts_received|srcPackets=$pkts_sent|
SessionEndReason=$session_end_reason|DeviceGroupHierarchyL1=$dg_hier_level_1|
DeviceGroupHierarchyL2=$dg_hier_level_2|DeviceGroupHierarchyL3=$dg_hier_level_3|
DeviceGroupHierarchyL4=$dg_hier_level_4|vSrcName=$vsys_name|
DeviceName=$device_name|ActionSource=$action_source
PAN-OS 8.0 - 9.1
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$action|x7C|
cat=$type|ReceiveTime=$receive_time|SerialNumber=$serial|Type=$type|
Subtype=$subtype|devTime=$cef-formatted-receive_time|src=$src|dst=$dst|
srcPostNAT=$natsrc|dstPostNAT=$natdst|RuleName=$rule|usrName=$srcuser|
SourceUser=$srcuser|DestinationUser=$dstuser|Application=$app|VirtualSystem=$vsys|
SourceZone=$from|DestinationZone=$to|IngressInterface=$inbound_if|
EgressInterface=$outbound_if|LogForwardingProfile=$logset|SessionID=$sessionid|
RepeatCount=$repeatcnt|srcPort=$sport|dstPort=$dport|srcPostNATPort=$natsport|
dstPostNATPort=$natdport|Flags=$flags|proto=$proto|action=$action|totalBytes=$bytes|
dstBytes=$bytes_received|srcBytes=$bytes_sent|totalPackets=$packets|StartTime=$start|
ElapsedTime=$elapsed|URLCategory=$category|sequence=$seqno|
ActionFlags=$actionflags|SourceLocation=$srcloc|DestinationLocation=$dstloc|
dstPackets=$pkts_received|srcPackets=$pkts_sent|
SessionEndReason=$session_end_reason|DeviceGroupHierarchyL1=$dg_hier_level_1|
DeviceGroupHierarchyL2=$dg_hier_level_2|DeviceGroupHierarchyL3=$dg_hier_level_3|
DeviceGroupHierarchyL4=$dg_hier_level_4|vSrcName=$vsys_name|
DeviceName=$device_name|ActionSource=$action_source|SrcUUID=$src_uuid|
DstUUID=$dst_uuid|TunnelID=$tunnelid|MonitorTag=$monitortag|
ParentSessionID=$parent_session_id|ParentStartTime=$parent_start_time|
TunnelType=$tunnel
PAN-OS 10.0
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$action|x7C|
ProfileToken=$actionflags|TimeReceived=$receive_time|DeviceSN=$serial|cat=$type|
SubType=$subtype|ConfigVersion=$sender_sw_version|devTime=$cef-formatted-
receive_time|src=$src|dst=$dst|srcPostNAT=$natsrc|dstPostNAT=$natdst|Rule=$rule|
usrName=$srcuser|DestinationUser=$dstuser|Application=$app|VirtualLocation=$vsys|

10
FromZone=$from|ToZone=$to|InboundInterface=$inbound_if|
OutboundInterface=$outbound_if|LogSetting=$logset|SessionID=$sessionid|
RepeatCount=$repeatcnt|srcPort=$sport|dstPort=$dport|srcPostNATPort=$natsport|
dstPostNATPort=$natdport|proto=$proto|Bytes=$bytes|srcBytes=$bytes_sent|
dstBytes=$bytes_received|totalPackets=$packets|SessionStartTime=$start|
SessionDuration=$elapsed|URLCategory=$category|SequenceNo=$seqno|
SourceLocation=$srcloc|DestinationLocation=$dstloc|srcPackets=$pkts_sent|
dstPackets=$pkts_received|SessionEndReason=$session_end_reason|
DGHierarchyLevel1=$dg_hier_level_1|DGHierarchyLevel2=$dg_hier_level_2|
DGHierarchyLevel3=$dg_hier_level_3|DGHierarchyLevel4=$dg_hier_level_4|
VirtualSystemName=$vsys_name|DeviceName=$device_name|
ActionSource=$action_source|SourceUUID=$src_uuid|DestinationUUID=$dst_uuid|
IMSI=$imsi|IMEI=$imei|ParentSessionID=$parent_session_id|
ParentStarttime=$parent_start_time|Tunnel=$tunnel|EndpointAssociationID=$assoc_id|
ChunksTotal=$chunks|ChunksSent=$chunks_sent|ChunksReceived=$chunks_received|
RuleUUID=$rule_uuid|HTTP2Connection=$http2_connection|
LinkChangeCount=$link_change_count|SDWANPolicyName=$sdwan_ec_applied|
LinkSwitches=$link_switches|SDWANCluster=$sdwan_cluster|
SDWANDeviceType=$sdwan_device_type|SDWANClusterType=$sdwan_cluster_type|
SDWANSite=$sdwan_site|DynamicUserGroupName=$dynusergroup_name|X-Forwarded-
ForIP=$xff_ip|SourceDeviceCategory=$src_category|SourceDeviceProfile=$src_profile|
SourceDeviceModel=$src_model|SourceDeviceVendor=$src_vendor|
SourceDeviceOSFamily=$src_osfamily|SourceDeviceOSVersion=$src_osversion|
SourceDeviceHost=$src_host|SourceDeviceMac=$src_mac|
DestinationDeviceCategory=$dst_category|DestinationDeviceProfile=$dst_profile|
DestinationDeviceModel=$dst_model|DestinationDeviceVendor=$dst_vendor|
DestinationDeviceOSFamily=$dst_osfamily|DestinationDeviceOSVersion=$dst_osversion|
DestinationDeviceHost=$dst_host|DestinationDeviceMac=$dst_mac|
ContainerID=$container_id|ContainerNameSpace=$pod_namespace|
ContainerName=$pod_name|SourceEDL=$src_edl|DestinationEDL=$dst_edl|
GPHostID=$hostid|EndpointSerialNumber=$serialnumber|
SourceDynamicAddressGroup=$src_dag|DestinationDynamicAddressGroup=$dst_dag|
HASessionOwner=$session_owner|TimeGeneratedHighResolution=$high_res_timestamp|
NSSAINetworkSliceType=$nssai_sst|NSSAINetworkSliceDifferentiator=$nssai_sd|
devTimeFormat=$cef-formatted-time_generated

11
f) If you are using versions other than PAN-OS 3.0 - 6.1, click HIP Match, copy one of the
following texts applicable to the version you are using, and paste it in the HIP Match Log
Format field for the HIP Match log type.

PAN-OS 7.1
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$matchname|
x7C|ReceiveTime=$receive_time|SerialNumber=$serial|cat=$type|Subtype=$subtype|
devTime=$cef-formatted-receive_time|usrName=$srcuser|VirtualSystem=$vsys|
identHostName=$machinename|OS=$os|identSrc=$src|HIP=$matchname|
RepeatCount=$repeatcnt|HIPType=$matchtype|sequence=$seqno|
ActionFlags=$actionflags|DeviceGroupHierarchyL1=$dg_hier_level_1|
DeviceGroupHierarchyL2=$dg_hier_level_2|DeviceGroupHierarchyL3=$dg_hier_level_3|
DeviceGroupHierarchyL4=$dg_hier_level_4|vSrcName=$vsys_name|
DeviceName=$device_name
PAN-OS 8.0 - 9.1
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$matchname|
x7C|ReceiveTime=$receive_time|SerialNumber=$serial|cat=$type|Subtype=$subtype|
devTime=$cef-formatted-receive_time|usrName=$srcuser|VirtualSystem=$vsys|
identHostName=$machinename|OS=$os|identsrc=$src|HIP=$matchname|
RepeatCount=$repeatcnt|HIPType=$matchtype|sequence=$seqno|
ActionFlags=$actionflags|DeviceGroupHierarchyL1=$dg_hier_level_1|
DeviceGroupHierarchyL2=$dg_hier_level_2|DeviceGroupHierarchyL3=$dg_hier_level_3|
DeviceGroupHierarchyL4=$dg_hier_level_4|vSrcName=$vsys_name|
DeviceName=$device_name|VirtualSystemID=$vsys_id|srcipv6=$srcipv6|startTime=$cef-
formatted-time_generated
PAN-OS 10.2
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$matchname|
x7C|ProfileToken=$actionflags|TimeReceived=$receive_time|DeviceSN=$serial|cat=$type|
SubType=$subtype|ConfigVersion=$sender_sw_version|devTime=$cef-formatted-
receive_time|usrName=$srcuser|VirtualLocation=$vsys|identHostName=$machinename|
EndpointOSType=$os|iOSsrc=$src|CountOfRepeats=$repeatcnt|SequenceNo=$seqno|
DGHierarchyLevel1=$dg_hier_level_1|DGHierarchyLevel2=$dg_hier_level_2|
DGHierarchyLevel3=$dg_hier_level_3|DGHierarchyLevel4=$dg_hier_level_4|
VirtualSystemName=$vsys_name|DeviceName=$device_name|VirtualSystemID=$vsys_id|
SourceIPv6=$srcipv6|HostID=$hostid|EndpointSerialNumber=$serialnumber|
SourceDeviceCategory=$reclassified|SourceDeviceModel=$matchtype|
SourceDeviceMac=$mac|TimestampDeviceIdentification=$time_generated|

12
TimeGeneratedHighResolution=$high_res_timestamp|devTimeFormat=$cef-formatted-
time_generated

g) Copy one of the following texts applicable to the version you are using and paste it in the
Custom Format column for the log type. If you are using PAN-OS 8.0 - 9.1, copy and paste
the text for the URL Filtering log type. If you are using PAN-OS 10.0, copy and paste the
text for the URL log type. If your version is not listed, omit this step.

PAN-OS 8.0 - 9.1


LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$threatid|x7C|
ReceiveTime=$receive_time|SerialNumber=$serial|cat=$type|Subtype=$subtype|
devTime=$cef-formatted-receive_time|src=$src|dst=$dst|srcPostNAT=$natsrc|
dstPostNAT=$natdst|RuleName=$rule|usrName=$srcuser|SourceUser=$srcuser|
DestinationUser=$dstuser|Application=$app|VirtualSystem=$vsys|SourceZone=$from|
DestinationZone=$to|IngressInterface=$inbound_if|EgressInterface=$outbound_if|
LogForwardingProfile=$logset|SessionID=$sessionid|RepeatCount=$repeatcnt|
srcPort=$sport|dstPort=$dport|srcPostNATPort=$natsport|dstPostNATPort=$natdport|
Flags=$flags|proto=$proto|action=$action|Miscellaneous=$misc|ThreatID=$threatid|
URLCategory=$category|sev=$number-of-severity|Severity=$severity|Direction=$direction|
sequence=$seqno|ActionFlags=$actionflags|SourceLocation=$srcloc|
DestinationLocation=$dstloc|ContentType=$contenttype|PCAP_ID=$pcap_id|
FileDigest=$filedigest|Cloud=$cloud|URLIndex=$url_idx|RequestMethod=$http_method|
UserAgent=$user_agent|identSrc=$xff|Referer=$referer|Subject=$subject|
DeviceGroupHierarchyL1=$dg_hier_level_1|DeviceGroupHierarchyL2=$dg_hier_level_2|
DeviceGroupHierarchyL3=$dg_hier_level_3|DeviceGroupHierarchyL4=$dg_hier_level_4|
vSrcName=$vsys_name|DeviceName=$device_name|SrcUUID=$src_uuid|
DstUUID=$dst_uuid|TunnelID=$tunnelid|MonitorTag=$monitortag|
ParentSessionID=$parent_session_id|ParentStartTime=$parent_start_time|
TunnelType=$tunnel|ThreatCategory=$thr_category|ContentVer=$contentver
PAN-OS 10.0
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$threatid|x7C|
ProfileToken=$actionflags|TimeReceived=$receive_time|DeviceSN=$serial|cat=$type|
SubType=$subtype|ConfigVersion=$sender_sw_version|devTime=$cef-formatted-
receive_time|src=$src|dst=$dst|srcPostNAT=$natsrc|dstPostNAT=$natdst|Rule=$rule|
usrName=$srcuser|DestinationUser=$dstuser|Application=$app|VirtualLocation=$vsys|
FromZone=$from|ToZone=$to|InboundInterface=$inbound_if|
OutboundInterface=$outbound_if|LogSetting=$logset|SessionID=$sessionid|
RepeatCount=$repeatcnt|srcPort=$sport|dstPort=$dport|srcPostNATPort=$natsport|

13
dstPostNATPort=$natdport|proto=$proto|Action=$action|URL=$file_url|
VendorSeverity=$severity|DirectionOfAttack=$direction|SequenceNo=$seqno|
SourceLocation=$srcloc|DestinationLocation=$dstloc|ContentType=$contenttype|
PacketID=$pcap_id|URLCounter=$url_idx|UserAgent=$user_agent|identSrc=$xff|
Referer=$referer|DGHierarchyLevel1=$dg_hier_level_1|DGHierarchyLevel2=$dg_hier_level_2|
DGHierarchyLevel3=$dg_hier_level_3|DGHierarchyLevel4=$dg_hier_level_4|
VirtualSystemName=$vsys_name|DeviceName=$device_name|SourceUUID=$src_uuid|
DestinationUUID=$dst_uuid|HTTPMethod=$http_method|IMSI=$imsi|IMEI=$imei|
ParentSessionID=$parent_session_id|ParentStarttime=$parent_start_time|
Tunnel=$tunnelid|ContentVersion=$contentver|SigFlags=$sig_flags|
HTTPHeaders=$http_headers|URLCategoryList=$url_category_list|RuleUUID=$rule_uuid|
HTTP2Connection=$http2_connection|DynamicUserGroupName=$dynusergroup_name|X-
Forwarded-ForIP=$xff_ip|SourceDeviceCategory=$src_category|
SourceDeviceProfile=$src_profile|SourceDeviceModel=$src_model|
SourceDeviceVendor=$src_vendor|SourceDeviceOSFamily=$src_osfamily|
SourceDeviceOSVersion=$src_osversion|SourceDeviceHost=$src_host|
SourceDeviceMac=$src_mac|DestinationDeviceCategory=$dst_category|
DestinationDeviceProfile=$dst_profile|DestinationDeviceModel=$dst_model|
DestinationDeviceVendor=$dst_vendor|DestinationDeviceOSFamily=$dst_osfamily|
DestinationDeviceOSVersion=$dst_osversion|DestinationDeviceHost=$dst_host|
DestinationDeviceMac=$dst_mac|ContainerID=$container_id|
ContainerNameSpace=$pod_namespace|ContainerName=$pod_name|SourceEDL=$src_edl|
DestinationEDL=$dst_edl|HostID=$hostid|EndpointSerialNumber=$serialnumber|
SourceDynamicAddressGroup=$src_dag|DestinationDynamicAddressGroup=$dst_dag|
TimeGeneratedHighResolution=$high_res_timestamp|NSSAINetworkSliceType=$nssai_sst|
devTimeFormat=$cef-formatted-time_generated

14
h) If you are using PAN-OS 8.0 - 9.1, copy the following text and paste it in the Custom Format
column for the Datalog type.

LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$threatid|x7C|


ReceiveTime=$receive_time|SerialNumber=$serial|cat=$type|Subtype=$subtype|
devTime=$cef-formatted-receive_time|src=$src|dst=$dst|srcPostNAT=$natsrc|
dstPostNAT=$natdst|RuleName=$rule|usrName=$srcuser|SourceUser=$srcuser|
DestinationUser=$dstuser|Application=$app|VirtualSystem=$vsys|SourceZone=$from|
DestinationZone=$to|IngressInterface=$inbound_if|EgressInterface=$outbound_if|
LogForwardingProfile=$logset|SessionID=$sessionid|RepeatCount=$repeatcnt|
srcPort=$sport|dstPort=$dport|srcPostNATPort=$natsport|dstPostNATPort=$natdport|
Flags=$flags|proto=$proto|action=$action|Miscellaneous=$misc|ThreatID=$threatid|
URLCategory=$category|sev=$number-of-severity|Severity=$severity|Direction=$direction|
sequence=$seqno|ActionFlags=$actionflags|SourceLocation=$srcloc|
DestinationLocation=$dstloc|ContentType=$contenttype|PCAP_ID=$pcap_id|
FileDigest=$filedigest|Cloud=$cloud|URLIndex=$url_idx|RequestMethod=$http_method|
Subject=$subject|DeviceGroupHierarchyL1=$dg_hier_level_1|
DeviceGroupHierarchyL2=$dg_hier_level_2|DeviceGroupHierarchyL3=$dg_hier_level_3|
DeviceGroupHierarchyL4=$dg_hier_level_4|vSrcName=$vsys_name|
DeviceName=$device_name|SrcUUID=$src_uuid|DstUUID=$dst_uuid|TunnelID=$tunnelid|
MonitorTag=$monitortag|ParentSessionID=$parent_session_id|
ParentStartTime=$parent_start_time|TunnelType=$tunnel|ThreatCategory=$thr_category|
ContentVer=$contentver

15
i) Copy one of the following texts applicable to the version you are using and paste it in the
Custom Format column for the WildFire log type. If your version is not listed, omit this
step.

PAN-OS 8.0 - 9.1


LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$threatid|x7C|
ReceiveTime=$receive_time|SerialNumber=$serial|cat=$type|Subtype=$subtype|
devTime=$cef-formatted-receive_time|src=$src|dst=$dst|srcPostNAT=$natsrc|
dstPostNAT=$natdst|RuleName=$rule|usrName=$srcuser|SourceUser=$srcuser|
DestinationUser=$dstuser|Application=$app|VirtualSystem=$vsys|SourceZone=$from|
DestinationZone=$to|IngressInterface=$inbound_if|EgressInterface=$outbound_if|
LogForwardingProfile=$logset|SessionID=$sessionid|RepeatCount=$repeatcnt|
srcPort=$sport|dstPort=$dport|srcPostNATPort=$natsport|dstPostNATPort=$natdport|
Flags=$flags|proto=$proto|action=$action|Miscellaneous=$misc|ThreatID=$threatid|
URLCategory=$category|sev=$number-of-severity|Severity=$severity|Direction=$direction|
sequence=$seqno|ActionFlags=$actionflags|SourceLocation=$srcloc|
DestinationLocation=$dstloc|ContentType=$contenttype|PCAP_ID=$pcap_id|
FileDigest=$filedigest|Cloud=$cloud|URLIndex=$url_idx|RequestMethod=$http_method|
FileType=$filetype|Sender=$sender|Subject=$subject|Recipient=$recipient|
ReportID=$reportid|DeviceGroupHierarchyL1=$dg_hier_level_1|
DeviceGroupHierarchyL2=$dg_hier_level_2|DeviceGroupHierarchyL3=$dg_hier_level_3|
DeviceGroupHierarchyL4=$dg_hier_level_4|vSrcName=$vsys_name|
DeviceName=$device_name|SrcUUID=$src_uuid|DstUUID=$dst_uuid|TunnelID=$tunnelid|
MonitorTag=$monitortag|ParentSessionID=$parent_session_id|
ParentStartTime=$parent_start_time|TunnelType=$tunnel|ThreatCategory=$thr_category|
ContentVer=$contentver
PAN-OS 10.2
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$threatid|x7C|
ProfileToken=$actionflags|TimeReceived=$receive_time|DeviceSN=$serial|cat=$type|
SubType=$subtype|ConfigVersion=$sender_sw_version|devTime=$cef-formatted-
receive_time|src=$src|dst=$dst|srcPostNAT=$natsrc|dstPostNAT=$natdst|Rule=$rule|
usrName=$srcuser|DestinationUser=$dstuser|Application=$app|VirtualLocation=$vsys|
FromZone=$from|ToZone=$to|InboundInterface=$inbound_if|
OutboundInterface=$outbound_if|LogSetting=$logset|SessionID=$sessionid|
RepeatCount=$repeatcnt|srcPort=$spor|dstPort=$dport|srcPostNATPort=$natsport|
dstPostNATPort=$natdport|proto=$proto|Action=$action|FileName=$misc|
VendorSeverity=$severity|DirectionOfAttack=$direction|SequenceNo=$seqno|

16
SourceLocation=$srcloc|DestinationLocation=$dstloc|PacketID=$pcap_id|
FileHash=$filedigest|ApplianceOrCloud=$cloud

j) Copy one of the following texts applicable to the version you are using and paste it in the
Custom Format column for the Authentication log type. If your version is not listed, omit
this step.

PAN-OS 8.0 - 9.1


LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$event|x7C|
ReceiveTime=$receive_time|SerialNumber=$serial|cat=$type|Subtype=$subtype|
devTime=$cef-formatted-receive_time|ServerProfile=$serverprofile|
LogForwardingProfile=$logset|VirtualSystem=$vsys|AuthPolicy=$authpolicy|
ClientType=$clienttype|NormalizeUser=$normalize_user|ObjectName=$object|
FactorNumber=$factorno|AuthenticationID=$authid|src=$ip|RepeatCount=$repeatcnt|
usrName=$user|Vendor=$vendor|msg=$event|sequence=$seqno|
DeviceGroupHierarchyL1=$dg_hier_level_1|DeviceGroupHierarchyL2=$dg_hier_level_2|
DeviceGroupHierarchyL3=$dg_hier_level_3|DeviceGroupHierarchyL4=$dg_hier_level_4|
vSrcName=$vsys_name|DeviceName=$device_name|AdditionalAuthInfo=$desc|
ActionFlags=$actionflags
PAN-OS 10.0
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$event|x7C|
ProfileToken=$actionflags|TimeReceived=$receive_time|DeviceSN=$serial|cat=$type|
SubType=$subtype|ConfigVersion=$sender_sw_version|devTime=$cef-formatted-
receive_time|VirtualLocation=$vsys|src=$ip|User=$normalize_user|usrName=$user|
Object=$object|object2AuthenticationPolicy=$authpolicy|CountOfRepeats=$repeatcnt|
MFAAuthenticationID=-$authid|MFAVendor=$vendor|LogSetting=$logset|
AuthServerProfile=$serverprofile|AuthenticationDescription=$desc|ClientType=$clienttype|
AuthFactorNo=$factorno|SequenceNo=$seqno|DGHierarchyLevel1=$dg_hier_level_1|
DGHierarchyLevel2=$dg_hier_level_2|DGHierarchyLevel3=$dg_hier_level_3|
DGHierarchyLevel4=$dg_hier_level_4|VirtualSystemName=$vsys_name|
DeviceName=$device_name|VirtualSystemID=$vsys_id|AuthenticationProtocol=$authproto|
RuleMatchedUUID=$rule_uuid|TimeGeneratedHighResolution=$high_res_timestamp|
SourceDeviceCategory=$src_category|SourceDeviceProfile=$src_profile|
SourceDeviceModel=$src_model|SourceDeviceVendor=$src_vendor|
SourceDeviceOSFamily=$src_osfamily|SourceDeviceOSVersion=$src_osversion|
SourceDeviceHost=$src_host|SourceDeviceMac=s$src_mac|
AuthCacheServiceRegion=$region|UserAgentString=$user_agent|SessionID=$sessionid|
devTimeFormat=$cef-formatted-time_generated

17
18
k) Copy one of the following texts applicable to the version you are using and paste it in the
Custom Format column for the User-ID log type. If your version is not listed, omit this step.

PAN-OS 8.0 - 9.1


LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$subtype|x7C|
ReceiveTime=$receive_time|SerialNumber=$serial|cat=$type|Subtype=$subtype|
devTime=$cef-formatted-receive_time|FactorType=$factortype|VirtualSystem=$vsys|
DataSourceName=$datasourcename|DataSource=$datasource|
DataSourceType=$datasourcetype|FactorNumber=$factorno|VirtualSystemID=$vsys_id|
TimeoutThreshold=$timeout|src=$ip|srcPort=$beginport|dstPort=$endport|
RepeatCount=$repeatcnt|usrName=$user|sequence=$seqno|EventID=$eventid|
FactorCompletionTime=$factorcompletiontime|DeviceGroupHierarchyL1=$dg_hier_level_1|
DeviceGroupHierarchyL2=$dg_hier_level_2|DeviceGroupHierarchyL3=$dg_hier_level_3|
DeviceGroupHierarchyL4=$dg_hier_level_4|vSrcName=$vsys_name|
DeviceName=$device_name|ActionFlags=$actionflags
PAN-OS 10.2
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$subtype|x7C|
ProfileToken=$actionflags|TimeReceived=$receive_time|DeviceSN=$serial|cat=$type|
ConfigVersion=$sender_sw_version|devTime=$cef-formatted-receive_time|
VirtualLocation=$vsys|src=$ip|usrName=$user|
MappingDataSourceName=$datasourcename|EventIdName=$eventid|
CountofRepeats=$repeatcnt|MappingTimeout=$timeout|srcPort=$beginport|
dstPort=$endport|MappingDataSource=$datasource|
MappingDataSourceType=$datasourcetype|SequenceNo=$seqno|
DGHierarchyLevel1=$dg_hier_level_1|DGHierarchyLevel2=$dg_hier_level_2|
DGHierarchyLevel3=$dg_hier_level_3|DGHierarchyLevel4=$dg_hier_level_4|
VirtualSystemName=$vsys_name|DeviceName=$device_name|VirtualSystemID=$vsys_id|
MFAFactorType=$factortype|AuthCompletionTime=$factorcompletiontime|
AuthFactorNo=$factorno|UGFlags=$ugflags|UserIdentifiedBySource=$userbysource|
Tag=$tag_name|TimeGeneratedHighResolution=$high_res_timestamp|
devTimeFormat=$cef-formatted-time_generated

19
l) Copy one of the following texts applicable to the version you are using and paste it in the
Custom Format column for the log type. If you are using PAN-OS 8.0 - 9.1, copy and paste
the text for the Tunnel Inspection log type. If you are using PAN-OS 10.0, copy and paste
the text for the Tunnel log type. If your version is not listed, omit this step.

PAN-OS 8.0 - 9.1


LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$action|x7C|
ReceiveTime=$receive_time|SerialNumber=$serial|cat=$type|Subtype=$subtype|
devTime=$cef-formatted-receive_time|src=$src|dst=$dst|srcPostNAT=$natsrc|
dstPostNAT=$natdst|RuleName=$rule|usrName=$srcuser|SourceUser=$srcuser|
DestinationUser=$dstuser|Application=$app|VirtualSystem=$vsys|SourceZone=$from|
DestinationZone=$to|IngressInterface=$inbound_if|EgressInterface=$outbound_if|
LogForwardingProfile=$logset|SessionID=$sessionid|RepeatCount=$repeatcnt|
srcPort=$sport|dstPort=$dport|srcPostNATPort=$natsport|dstPostNATPort=$natdport|
Flags=$flags|proto=$proto|action=$action|sequence=$seqno|ActionFlags=$actionflags|
DeviceGroupHierarchyL1=$dg_hier_level_1|DeviceGroupHierarchyL2=$dg_hier_level_2|
DeviceGroupHierarchyL3=$dg_hier_level_3|DeviceGroupHierarchyL4=$dg_hier_level_4|
vSrcName=$vsys_name|DeviceName=$device_name|TunnelID=$tunnelid|
MonitorTag=$monitortag|ParentSessionID=$parent_session_id|
ParentStartTime=$parent_start_time|TunnelType=$tunnel|totalBytes=$bytes|
dstBytes=$bytes_received|srcBytes=$bytes_sent|totalPackets=$packets|
dstPackets=$pkts_received|srcPackets=$pkts_sent|MaximumEncapsulation=$max_encap|
UnknownProtocol=$unknown_proto|StrictChecking=$strict_check|
TunnelFragment=$tunnel_fragment|SessionsCreated=$sessions_created|
SessionsClosed=$sessions_closed|SessionEndReason=$session_end_reason|
ActionSource=$action_source|startTime=$start|ElapsedTime=$elapsed
PAN-OS 10.0
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$action|x7C|
ProfileToken=$actionflags|TimeReceived=$receive_time|DeviceSN=$serial|cat=$type|
SubType=$subtype|ConfigVersion=$sender_sw_version|devTime=$cef-formatted-
receive_time|src=$src|dst=$dst|srcPostNAT=$natsrc|dstPostNAT=$natdst|Rule=$rule|
usrName=$srcuser|DestinationUser=$dstuse|Application=$app|VirtualLocation=$vsys|
FromZone=$from|ToZone=$to|InboundInterface=$inbound_if|
OutboundInterface=$outbound_if|LogSetting=$logset|SessionID=$sessionid|
RepeatCount=$repeatcnt|srcPort=$sport|dstPort=$dport|srcPostNATPort=$natsport|
dstPostNATPort=$natdport|proto=$proto|SequenceNo=$seqno|SourceLocation=$srcloc|
DestinationLocation=$dstloc|DGHierarchyLevel1=$dg_hier_level_1|
DGHierarchyLevel2=$dg_hier_level_2|DGHierarchyLevel3=$dg_hier_level_3|

20
DGHierarchyLevel4=$dg_hier_level_4|VirtualSystemName=$vsys_name|
DeviceName=$device_name|ParentSessionID=$parent_session_id|
ParentStarttime=$parent_start_time|Tunnel=$tunnel|Bytes=$bytes|srcBytes=$bytes_sent|
dstBytes=$bytes_received|totalPackets=$packets|srcPackets=$pkts_sent|
dstPackets=$pkts_received|TunnelSessionsCreated=$sessions_created|
TunnelSessionsClosed=$sessions_closed|SessionEndReason=$session_end_reason|
ActionSource=$action_source|startTime=$start|SessionDuration=$elapsed|
RuleUUID=$rule_uuid|DynamicUserGroupName=$dynusergroup_name|
ContainerID=$container_id|ContainerNameSpace=$pod_namespace|
ContainerName=$pod_name|SourceEDL=$src_edl|DestinationEDL=$dst_edl|
SourceDynamicAddressGroup=$src_dag|DestinationDynamicAddressGroup=dst_dag|
TimeGeneratedHighResolution=$high_res_timestamp|
NSSAINetworkSliceDifferentiator=$nssai_sd|NSSAINetworkSliceType=$nssai_sst|
ProtocolDataUnitsessionID=$pdu_session_id|devTimeFormat=$cef-formatted-
time_generated

m) If you are using PAN-OS 8.0 - 9.1, copy the following text and paste it in the Custom Format
column for the Correlation log type.
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|8.0|$category|
ReceiveTime=$receive_time|x7C|SerialNumber=$serial|cat=$type|devTime=$cef-formatted-
receive_time|startTime=$cef-formatted-time_generated|Severity=$severity|
VirtualSystem=$vsys|VirtualSystemID=$vsys_id|src=$src|SourceUser=$srcuser|
msg=$evidence|DeviceGroupHierarchyL1=$dg_hier_level_1|
DeviceGroupHierarchyL2=$dg_hier_level_2|DeviceGroupHierarchyL3=$dg_hier_level_3|
DeviceGroupHierarchyL4=$dg_hier_level_4|vSrcName=$vsys_name|
DeviceName=$device_name|ObjectName=$object_name|ObjectID=$object_id

21
n) If you are using PAN-OS 8.1 - 9.1, copy the following text, and paste it in the Custom Format
column for the SCTP log type.
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$action|x7C|
ReceiveTime=$receive_time|SerialNumber=$serial|cat=$type|genTime=$time_generated|
src=$src|dst=$dst|VirtualSystem=$vsys|SourceZone=$from|DestinationZone=$to|
IngressInterface=$inbound_if|EgressInterface=$outbound_if|SessionID=$sessionid|
RepeatCount=$repeatcnt|srcPort=$sport|dstPort=$dport|proto=$proto|action=$action|
DeviceGroupHierarchyL1=$dg_hier_level_1|DeviceGroupHierarchyL2=$dg_hier_level_2|
DeviceGroupHierarchyL3=$dg_hier_level_3|DeviceGroupHierarchyL4=$dg_hier_level_4|
vsysName=$vsys_name|DeviceName=$device_name|sequence=$seqno|AssocID=$assoc_id|
PayloadProtoID=$ppid|sev=$num_of_severity|SCTPChunkType=$sctp_chunk_type|
SCTPVerTag1=$verif_tag_1|SCTPVerTag2=$verif_tag_2|
SCTPCauseCode=$sctp_cause_code|DiamAppID=$diam_app_id|
DiamCmdCode=$diam_cmd_code|DiamAVPCode=$diam_avp_code|
SCTPStreamID=$stream_id|SCTPAssEndReason=$assoc_end_reason|OpCode=$op_code|
CPSSN=$sccp_calling_ssn|CPGlobalTitle=$sccp_calling_gt|SCTPFilter=$sctp_filter|
SCTPChunks=$chunks|SrcSCTPChunks=$chunks_sent|DstSCTPChunks=$chunks_received|
Packets=$packets|srcPackets=$pkts_sent|dstPackets=$pkts_received

22
o) Copy one of the following texts applicable to the version you are using and paste it in the
Custom Format column for the IP-Tag log type. If your version is not listed, omit this step.

PAN-OS 9.x
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$event_id|x7C|
cat=$type|devTime=$cef-formatted-receive_time|ReceiveTime=$receive_time|
SerialNumber=$serial|Subtype=$subtype|GenerateTime=$time_generated|
VirtualSystem=$vsys|src=$ip|TagName=$tag_name|EventID=$eventid|
RepeatCount=$repeatcnt|TimeoutThreshold=$timeout|
DataSourceName=$datasourcename|DataSource=$datasource_type|
DataSourceType=$datasource_subtype|sequence=$seqno|ActionFlags=$actionflags|
DeviceGroupHierarchyL1=$dg_hier_level_1|DeviceGroupHierarchyL2=$dg_hier_level_2|
DeviceGroupHierarchyL3=$dg_hier_level_3|DeviceGroupHierarchyL4=$dg_hier_level_4|
vSrcName=$vsys_name|DeviceName=$device_name|VirtualSystemID=$vsys_id
PAN-OS 10.2
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$event_id|x7C|
ProfileToken=$actionflags|TimeReceived=$receive_time|DeviceSN=$serial|cat=$type|
SubType=$subtype|ConfigVersion=$sender_sw_version|devTime=$cef-formatted-
receive_time|VirtualLocation=$vsys|src=$ip|TagName=$tag_name|
CountOfRepeats=$repeatcnt|MappingTimeout=$timeout|
MappingDataSource=$datasourcename|MappingDataSourceType=$datasource_type|
MappingDataSourceSubType=$datasource_subtype|SequenceNo=$seqno|
DGHierarchyLevel1=$dg_hier_level_1|DGHierarchyLevel2=$dg_hier_level_2|
DGHierarchyLevel3=$dg_hier_level_3|DGHierarchyLevel4=$dg_hier_level_4|
VirtualSystemName=$vsys_name|DeviceName=$device_name|VirtualSystemID=$vsys_id|
IPSubnetRange=$ip_subnet_range|TimeGeneratedHighResolution=$high_res_timestamp|
devTimeFormat=$cef-formatted-time_generated

23
p) If you are using PAN-OS 10.2, copy the following text, and paste it in the Custom Format
column for the GlobalProtect log type.
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$eventid|x7C|
TimeReceived=$receive_time|DeviceSN=$serial|cat=$type|SubType=$subtype|
ConfigVersion=$sender_sw_version|devTime=$cef-formatted-receive_time|
VirtualSystem=$vsys|Stage=$stage|AuthMethod=$auth_method|TunnelType=$tunnel_type|
usrName=$srcuser|SourceRegion=$srcregion|EndpointDeviceName=$machinename|
PublicIPv4=$public_ip|PublicIPv6=$public_ipv6|PrivateIPv4=$private_ip|
PrivateIPv6=$private_ipv6|HostID=$hostid|EndpointSN=$serialnumber|
GlobalProtectClientVersion=$client_ver|EndpointOSType=$client_os|
EndpointOSVersion=$client_os_ver|CountOfRepeats=$repeatcnt|
QuarantineReason=$reason|ConnectionError=$error|Description=$opaque|
EventStatus=$status|GlobalProtectGatewayLocation=$location|
LoginDuration=$login_duration|ConnectionMethod=$connect_method|
ConnectionErrorID=$error_code|Portal=$portal|SequenceNo=$seqno|
TimeGeneratedHighResolution=$high_res_timestamp|
GatewaySelectionType=$selection_type|SSLResponseTime=$response_time|
GatewayPriority=$priority|AttemptedGateways=$attempted_gateways|Gateway=$gateway|
DGHierarchyLevel1=$dg_hier_level_1|DGHierarchyLevel2=$dg_hier_level_2|
DGHierarchyLevel3=$dg_hier_level_3|DGHierarchyLevel4=$dg_hier_level_4|
VirtualSystemName=$vsys_name|DeviceName=$device_name|VirtualSystemID=$vsys_id|
devTimeFormat=$cef-formatted-time_generated

24
q) If you are using PAN-OS 10.2, copy the following text, and paste it in the Custom Format
column for the Decryption log type.

LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$proxy_type|


x7C|ProfileToken=$actionflags|TimeReceived=$receive_time|DeviceSN=$serial|cat$type|
SubType=$subtype|ConfigVersion=$sender_sw_version|devTime=$cef-formatted-
receive_time|src=$src|dst=$dst|srcPostNAT=$natsrc|dstPostNAT=$natdst|Rule=$rule|
usrName=$srcuser|DestinationUser=$dstuser|Application=$app|VirtualLocation=vsys1|
FromZone=$from|ToZone=$to|InboundInterface=$inbound_if|
OutboundInterface=$outbound_if|LogSetting=$logset|
TimeReceivedManagementPlane=$time_received|SessionID=$sessionid|
CountOfRepeat=$repeatcnt|srcPort=$sport|dstPort=$dport|srcPostNATPort=$natsport|
dstPostNATPort=$natdport|proto=$proto|Action=$action|Tunnel=$tunnel|
SourceUUID=$src_uuid|DestinationUUID=$dst_uuid|RuleUUID=$rule_uuid|
TLSVersion=$tls_version|TLSKeyExchange=$tls_keyxchg|TLSEncryptionAlgorithm=$tls_enc|
TLSAuth=$tls_auth|PolicyName=$policy_name|EllipticCurve=$ec_curve|
ErrorIndex=$err_index|RootStatus=$root_status|ChainStatus=$chain_status|
CertificateSerial=$cert_serial|Fingerprint=$fingerprint|TimeNotBefore=$notbefore|
TimeNotAfter=$notafter|CertificateVersion=$cert_ver|CertificateSize=$cert_size|
CommonNameLength=$cn_len|IssuerNameLength=$issuer_len|RootCNLength=$rootcn_len|
SNILength=$sni_len|CertificateFlags=$cert_flags|CommonName=$cn|
IssuerCommonName=$issuer_cn|RootCommonName=$root_cn|ServerNameIndication=$sni|
ErrorMessage=$error|ContainerID=$container_id|ContainerNameSpace=$pod_namespace|
ContainerName=$pod_name|SourceEDL=$src_edl|DestinationEDL=$dst_edl|
SourceDynamicAddressGroup=$src_dag|DestinationDynamicAddressGroup=$dst_dag|
TimeGeneratedHighResolution=$high_res_timestamp|
SourceDeviceCategory=$src_category|SourceDeviceProfile=$src_profile|
SourceDeviceModel=$src_model|SourceDeviceVendor=$src_vendor|
SourceDeviceOSFamily=$src_osfamily|SourceDeviceOSVersion=$src_osversion|
SourceDeviceHost=$src_host|SourceDeviceMac=$src_mac|
DestinationDeviceCategory=$dst_category|DestinationDeviceProfile=$dst_profile|
DestinationDeviceModel=$dst_model|DestinationDeviceVendor=$dst_vendor|
DestinationDeviceOSFamily=$dst_osfamily|DestinationDeviceOSVersion=$dst_osversion|
DestinationDeviceHost=$dst_host|DestinationDeviceMac=$dst_mac|SequenceNo=$seqno|
devTimeFormat=$cef-formatted-time_generated

25
r) If you are using PAN-OS 10.0, copy the following text, and paste it in the Custom Format
column for the File Data log type.
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$action|x7C|
ProfileToken=$actionflags|TimeReceived=$receive_time|DeviceSN=$serial|cat=$type|
SubType=$subtype|ConfigVersion=$sender_sw_version|devTime=$cef-formatted-
receive_time|src=$src|dst=$dst|srcPostNAT=$natsrc|dstPostNAT=$natdst|Rule=$rule|
usrName=$srcuser|DestinationUser=$dstuser|Application=$app|VirtualLocation=$vsys|
FromZone=$from|ToZone=$to|InboundInterface=$inbound_if|
OutboundInterface=$outbound_if|LogSetting=$logset|SessionID=$sessionid|
RepeatCount=$repeatcnt|srcPort=$sport|dstPort=$dport|srcPostNATPort=$natsport|
dstPostNATPort=$natdport|proto=$proto|Bytes=$bytes|srcBytes=$bytes_sent|
dstBytes=$bytes_received|totalPackets=$packets|SessionStartTime=$start|
SessionDuration=$elapsed|URLCategory=$category|SequenceNo=$seqno|
SourceLocation=$srcloc|DestinationLocation=$dstloc|srcPackets=pkts_sent|
dstPackets=$pkts_received|SessionEndReason=$session_end_reason|
DGHierarchyLevel1=$dg_hier_level_1|DGHierarchyLevel2=$dg_hier_level_2|
DGHierarchyLevel3=$dg_hier_level_3|DGHierarchyLevel4=$dg_hier_level_4|
VirtualSystemName=$vsys_name|DeviceName=$device_name|
ActionSource=$action_source|SourceUUID=$src_uuid|DestinationUUID=$dst_uuid|
IMSI=$imsi|IMEI=$imei|ParentSessionID=$parent_session_id|
ParentStarttime=parent_start_time|Tunnel=$tunnel|EndpointAssociationID=-$assoc_id|
ChunksTotal=$chunks|ChunksSent=$chunks_sent|ChunksReceived=$chunks_received|
RuleUUID=$rule_uuid|HTTP2Connection=$http2_connection|
LinkChangeCount=$link_change_count|SDWANPolicyName=$sdwan_ec_applied|
LinkSwitches=$link_switches|SDWANCluster=$sdwan_cluster|
SDWANDeviceType=$sdwan_device_type|SDWANClusterType=$sdwan_cluster_type|
SDWANSite=$sdwan_site|DynamicUserGroupName=$dynusergroup_name|X-Forwarded-
ForIP=$xff_ip|SourceDeviceCategory=$src_category|SourceDeviceProfile=$src_profile|
SourceDeviceModel=$src_model|SourceDeviceVendor=$src_vendor|
SourceDeviceOSFamily=$src_osfamily|SourceDeviceOSVersion=$src_osversion|
SourceDeviceHost=$src_host|SourceDeviceMac=$src_mac|
DestinationDeviceCategory=$dst_category|DestinationDeviceProfile=$dst_profile|
DestinationDeviceModel=$dst_model|DestinationDeviceVendor=$dst_vendor|
DestinationDeviceOSFamily=$dst_osfamily|DestinationDeviceOSVersion=$dst_osversion|
DestinationDeviceHost=$dst_host|DestinationDeviceMac=$dst_mac|
ContainerID=$container_id|ContainerNameSpace=$pod_namespace|
ContainerName=$pod_name|SourceEDL=$src_edl|DestinationEDL=$dst_edl|

26
GPHostID=$hostid|EndpointSerialNumber=$serialnumber|
SourceDynamicAddressGroup=$src_dag|DestinationDynamicAddressGroup=$dst_dag|
HASessionOwner=$session_owner|TimeGeneratedHighResolution=$high_res_timestamp|
NSSAINetworkSliceType=$nssai_sst|NSSAINetworkSliceDifferentiator=$nssai_sd|
devTimeFormat=$cef-formatted-time_generated

5. Click OK.
6. To specify the severity of events that are contained in the Syslog messages, click Log Settings.
a) For each severity that you want to include in the Syslog message, click the Severity name
and select the Syslog destination from the Syslog menu.
b) Click OK.
7. Click Commit.

Creating a Forwarding Policy on Your Palo Alto PA Series Device


If your IBM®QRadar® Console or Event Collector is in a different security zone than your Palo Alto PA
Series device, create a forwarding policy rule.

a. Log in to Palo Alto Networks.


b. Click Policies > Policy Based Forwarding.
c. Click Add.
d. Configure the parameters. For descriptions of the policy-based forwarding values, see your Palo
Alto Networks Administrator’s Guide.

27

You might also like