跳至正文

Palo Alto Networks NGFW

Overview

Palo Alto Networks next-generation firewalls provide advanced threat prevention, URL filtering, and WildFire sandbox analysis. KYRA MDR collects traffic, threat, URL filtering, WildFire, and system logs via syslog forwarding in CEF format from PAN-OS 9.x, 10.x, and 11.x.

Prerequisites

  • KYRA MDR account (MDR tier or above)
  • KYRA Collector installed and reachable from the firewall management interface
  • PAN-OS 9.0 or later with administrative access
  • Network connectivity from the firewall to the Collector on TCP/UDP 514

Configuration

Step 1: Configure a Syslog Server Profile

From the PAN-OS CLI, create a syslog server profile pointing to your KYRA Collector:

configure
set shared log-settings syslog KYRA-MDR server collector1 transport TCP
set shared log-settings syslog KYRA-MDR server collector1 server <COLLECTOR_IP>
set shared log-settings syslog KYRA-MDR server collector1 port 514
set shared log-settings syslog KYRA-MDR server collector1 format BSD
set shared log-settings syslog KYRA-MDR server collector1 facility LOG_USER
commit

Alternatively, configure via the web UI: Device > Server Profiles > Syslog, then add a new profile with the Collector IP.

Step 2: Configure Log Forwarding Profile

Create a log forwarding profile that sends logs to the syslog profile:

set shared log-settings profiles KYRA-Forward match-list threat-fwd send-syslog KYRA-MDR
set shared log-settings profiles KYRA-Forward match-list threat-fwd log-type threat
set shared log-settings profiles KYRA-Forward match-list threat-fwd filter "All Logs"
set shared log-settings profiles KYRA-Forward match-list traffic-fwd send-syslog KYRA-MDR
set shared log-settings profiles KYRA-Forward match-list traffic-fwd log-type traffic
set shared log-settings profiles KYRA-Forward match-list traffic-fwd filter "All Logs"
set shared log-settings profiles KYRA-Forward match-list url-fwd send-syslog KYRA-MDR
set shared log-settings profiles KYRA-Forward match-list url-fwd log-type url
set shared log-settings profiles KYRA-Forward match-list url-fwd filter "All Logs"
set shared log-settings profiles KYRA-Forward match-list wildfire-fwd send-syslog KYRA-MDR
set shared log-settings profiles KYRA-Forward match-list wildfire-fwd log-type wildfire
set shared log-settings profiles KYRA-Forward match-list wildfire-fwd filter "All Logs"
commit

Step 3: Attach the Profile to Security Rules

Apply the log forwarding profile to your security policy rules:

set rulebase security rules <RULE_NAME> log-setting KYRA-Forward
set rulebase security rules <RULE_NAME> log-start yes
set rulebase security rules <RULE_NAME> log-end yes
commit

Step 4: Configure System Log Forwarding

Forward system-level events (config changes, authentication, HA):

set shared log-settings system match-list sys-fwd send-syslog KYRA-MDR
set shared log-settings system match-list sys-fwd filter "All Logs"
set shared log-settings config match-list cfg-fwd send-syslog KYRA-MDR
set shared log-settings config match-list cfg-fwd filter "All Logs"
commit

Step 5: Severity Filtering (Optional)

To reduce volume, filter by severity. PAN-OS severity levels: critical, high, medium, low, informational.

set shared log-settings profiles KYRA-Forward match-list threat-fwd filter "(severity geq medium)"
commit

Step 6: Verify on KYRA Collector

Terminal window
# Confirm syslog traffic is arriving
sudo tcpdump -i any port 514 -c 10
# Check KYRA Collector log ingestion
kyra-collector status
kyra-collector logs --source paloalto --tail 5

Collected Log Types

Log TypeDescriptionSecurity Use
TrafficSession start/end, allow/deny, bytes, applicationPolicy violation detection, anomaly analysis
ThreatIPS signatures, antivirus, anti-spyware, vulnerabilityReal-time attack detection
URL FilteringWeb category, URL, action (allow/block/alert)Policy compliance, phishing detection
WildFireSandbox verdicts (benign/malware/grayware/phishing)Zero-day malware detection
SystemConfig changes, HA failover, authentication, SNMPChange management, admin monitoring
ConfigCommit actions, admin user, client IPConfiguration audit trail

Key Syslog Message IDs

Message IDDescription
TRAFFICSession logs (start, end, drop, deny)
THREATThreat detection (virus, spyware, vulnerability, url, wildfire)
SYSTEMSystem events (auth, dhcp, ha, general)
CONFIGConfiguration changes
GLOBALPROTECTVPN client events

Troubleshooting

  • No logs appearing: Run show log-settings syslog on the firewall CLI to verify the server profile is active. Check that TCP/UDP 514 is not blocked between the firewall and Collector.
  • Incomplete log types: Ensure the log forwarding profile is attached to security rules and that log-start and log-end are enabled.
  • CEF parsing errors: Verify the syslog format is set to BSD (not IETF) in the server profile. KYRA Collector expects BSD-format CEF messages.
  • High volume: Use severity filtering or limit traffic logs to deny-only with filter "(action eq deny)" on the traffic match list.
  • Panorama managed devices: Configure the syslog profile on Panorama under the device group template and push to managed firewalls.

Contact kyra@seekerslab.com for integration support.