Palo Alto Networks NGFW
Overview
Palo Alto Networks next-generation firewalls provide advanced threat prevention, URL filtering, and WildFire sandbox analysis. KYRA MDR collects traffic, threat, URL filtering, WildFire, and system logs via syslog forwarding in CEF format from PAN-OS 9.x, 10.x, and 11.x.
Prerequisites
- KYRA MDR account (MDR tier or above)
- KYRA Collector installed and reachable from the firewall management interface
- PAN-OS 9.0 or later with administrative access
- Network connectivity from the firewall to the Collector on TCP/UDP 514
Configuration
Step 1: Configure a Syslog Server Profile
From the PAN-OS CLI, create a syslog server profile pointing to your KYRA Collector:
configureset shared log-settings syslog KYRA-MDR server collector1 transport TCPset shared log-settings syslog KYRA-MDR server collector1 server <COLLECTOR_IP>set shared log-settings syslog KYRA-MDR server collector1 port 514set shared log-settings syslog KYRA-MDR server collector1 format BSDset shared log-settings syslog KYRA-MDR server collector1 facility LOG_USERcommitAlternatively, configure via the web UI: Device > Server Profiles > Syslog, then add a new profile with the Collector IP.
Step 2: Configure Log Forwarding Profile
Create a log forwarding profile that sends logs to the syslog profile:
set shared log-settings profiles KYRA-Forward match-list threat-fwd send-syslog KYRA-MDRset shared log-settings profiles KYRA-Forward match-list threat-fwd log-type threatset shared log-settings profiles KYRA-Forward match-list threat-fwd filter "All Logs"set shared log-settings profiles KYRA-Forward match-list traffic-fwd send-syslog KYRA-MDRset shared log-settings profiles KYRA-Forward match-list traffic-fwd log-type trafficset shared log-settings profiles KYRA-Forward match-list traffic-fwd filter "All Logs"set shared log-settings profiles KYRA-Forward match-list url-fwd send-syslog KYRA-MDRset shared log-settings profiles KYRA-Forward match-list url-fwd log-type urlset shared log-settings profiles KYRA-Forward match-list url-fwd filter "All Logs"set shared log-settings profiles KYRA-Forward match-list wildfire-fwd send-syslog KYRA-MDRset shared log-settings profiles KYRA-Forward match-list wildfire-fwd log-type wildfireset shared log-settings profiles KYRA-Forward match-list wildfire-fwd filter "All Logs"commitStep 3: Attach the Profile to Security Rules
Apply the log forwarding profile to your security policy rules:
set rulebase security rules <RULE_NAME> log-setting KYRA-Forwardset rulebase security rules <RULE_NAME> log-start yesset rulebase security rules <RULE_NAME> log-end yescommitStep 4: Configure System Log Forwarding
Forward system-level events (config changes, authentication, HA):
set shared log-settings system match-list sys-fwd send-syslog KYRA-MDRset shared log-settings system match-list sys-fwd filter "All Logs"set shared log-settings config match-list cfg-fwd send-syslog KYRA-MDRset shared log-settings config match-list cfg-fwd filter "All Logs"commitStep 5: Severity Filtering (Optional)
To reduce volume, filter by severity. PAN-OS severity levels: critical, high, medium, low, informational.
set shared log-settings profiles KYRA-Forward match-list threat-fwd filter "(severity geq medium)"commitStep 6: Verify on KYRA Collector
# Confirm syslog traffic is arrivingsudo tcpdump -i any port 514 -c 10
# Check KYRA Collector log ingestionkyra-collector statuskyra-collector logs --source paloalto --tail 5Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Traffic | Session start/end, allow/deny, bytes, application | Policy violation detection, anomaly analysis |
| Threat | IPS signatures, antivirus, anti-spyware, vulnerability | Real-time attack detection |
| URL Filtering | Web category, URL, action (allow/block/alert) | Policy compliance, phishing detection |
| WildFire | Sandbox verdicts (benign/malware/grayware/phishing) | Zero-day malware detection |
| System | Config changes, HA failover, authentication, SNMP | Change management, admin monitoring |
| Config | Commit actions, admin user, client IP | Configuration audit trail |
Key Syslog Message IDs
| Message ID | Description |
|---|---|
| TRAFFIC | Session logs (start, end, drop, deny) |
| THREAT | Threat detection (virus, spyware, vulnerability, url, wildfire) |
| SYSTEM | System events (auth, dhcp, ha, general) |
| CONFIG | Configuration changes |
| GLOBALPROTECT | VPN client events |
Troubleshooting
- No logs appearing: Run
show log-settings syslogon the firewall CLI to verify the server profile is active. Check that TCP/UDP 514 is not blocked between the firewall and Collector. - Incomplete log types: Ensure the log forwarding profile is attached to security rules and that
log-startandlog-endare enabled. - CEF parsing errors: Verify the syslog format is set to BSD (not IETF) in the server profile. KYRA Collector expects BSD-format CEF messages.
- High volume: Use severity filtering or limit traffic logs to deny-only with
filter "(action eq deny)"on the traffic match list. - Panorama managed devices: Configure the syslog profile on Panorama under the device group template and push to managed firewalls.
Contact kyra@seekerslab.com for integration support.