Logo
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Sign in
  1. Guardsix Servicedesk
  2. Products Hub
  3. Marketplace

Palo Alto Network Firewall

Standard

Palo Alto Network Firewall allows you to monitor and identify threats in your organization using Palo Alto Network Firewall data. Logpoint aggregates and normalizes logs from every Palo Alto Networks Firewall device so you can analyze the information through dashboards and security reports. The dashboards provide visualization related to traffic, threat, user, content, system and firewall configurations. When Logpoint identifies traffic, threats, user, content, system and firewall-related events with a potential risk to your environment, it triggers security alerts based on predetermined rules. The automated alerts enable you to detect possible issues early and take corrective actions against them.

Release Details

Version: 5.7.0
Release date: January 28, 2025
Supported On: Logpoint v7.4.0 or later
SHA 256: 06b34923f0f326fb9127138c2c2a52be37a513d676cbb043744b4b439279638a
Palo Alto Network Firewall guide
Download

Enhancement

PLUG-1582484326
Palo Alto Network Firewall now supports PAN-OS 11.1. The Vendor Field Map is also updated according to their latest public documentation published on December 2, 2024.

Bug Fix

KB-1993272614
Some PaloAlto URL logs were not properly normalized by PaloAltoNetworkFirewallCompiledNormalizer.

Past Releases

Palo Alto Network Firewall v5.6.0 ▾
Version: 5.6.0
Release date: May 08, 2024
Supported On: Logpoint v6.7.0 and later
SHA 256: 23c22d761e6006a6817032e48a07fed4ca46b51bfdac9b6ac2f93fdac67b628a
Download

Enhancement

KB-22637
Added Syslog Collector based PaloAlto log source template, simplifying the log source configuration process. To learn more, go to Creating Log Source via a Template .
Palo Alto Network Firewall v5.5.0 ▾
Version: 5.5.0
Release date: June 02, 2023
Supported On: Logpoint v6.7.0 and later
SHA 256: 038a9703f9bf26d7e95ec5bdbadc4785f9926826e1903c4f64714b89ff13724c
Download

Enhancement

KB-19929, KB-17594, KB-20012, KB-20089, KB-19774, KB-19314, KB-20012, KB-2008672371, 67811, 72411, 74272, 72290, 67811, 71193
Updated PaloAltoNetworkFirewallCompiledNormalizer to support PAN-OS v11.0 and v10.2 logs.

Bug Fix

KB-1993272614
Some PaloAlto URL logs were not properly normalized by PaloAltoNetworkFirewallCompiledNormalizer.
Palo Alto Network Firewall v5.4.0 ▾
Version: 5.4.0
Release date: Feb 28, 2023
Supported On: Logpoint v6.7.0 and later
SHA 256: e2a204b65a3833afb8339eb2f115abc9a54a68e22dd9750e6af71da5548611ee
Download

Enhancement

KB-1922671105
Parsed the description fields to extract lease_address , hardware_address , hostname and interface in PaloAltoNetworkFirewallCompiledNormalizer .

Bug Fixes

KB-1715567140
Some PAN-OS logs were not properly normalized by PaloAltoNetworkFirewallCompiledNormalizer.
KB-1666765899
The URL field of some PAN-OS v10.0 THREAT logs were not properly normalized in PaloAltoNetworkFirewallCompiledNormalizer .
KB-1683866374, 68390
The subject field of some PAN-OS v10.0 THREAT logs were not properly normalized in PaloAltoNetworkFirewallCompiledNormalizer .
KB-17919, KB-16032, KB-1717568502, 63946, 67143
The USERID field of PAN-OS logs were not properly normalized by PaloAltoNetworkFirewallCompiledNormalizer.
KB-1821768660
The timezone field in was incorrectly normalized in PAN-OS logs by PaloAltoCEFCompiledNormalizer .
KB-1826769118
Some TRAFFIC and THREAT logs were not normalized by PaloAltoNetworkFirewallCompiledNormalizer.
Palo Alto Network Firewall v5.3.0 ▾
Version: 5.3.0

Enhancements

KB-15859, KB-15707, KB-1428563250, 62134, 60214
New signatures are added in PaloAltoNetworkFirewallCompiledNormalize r to support the PAN-OS v10.1 events as per the Palo Alto Network Firewall's official document.
KB-1528860847
Added support for the PAN-OS v10.0 THREAT logs with a new log format. To learn more, go to the Threat Log Fields section in Palo Alto Network Firewall v5.3.0 guide.
KB-13514
Enhanced the performance of the PaloAltoCEFCompiledNormalizer and PaloAltoNetworkFirewallCompiledNormalize r.
KB-13607, KB-1609363833
Added the VPN label in the GLOBALPROTECT logs to make logs compatible for LogPoint UEBA.
KB-13607
Added the is_flow_offloaded field in the PAN-OS v10.1 TRAFFIC logs.
KB-16157, KB-16236
Removed the event_ts and selection_type fields from the PAN-OS v9.1 Global Protect logs.
Some Palo Alto Network Firewall fields have been renamed. To learn more, go to the A ppendix section in the Palo Alto Network Firewall v5.3.0 guide.

Bug Fixes

KB-13809, KB-14273, KB-13712, KB-14301, KB-15773, KB-15558, KB-1609352401, 58216, 59137, 60368, 60546, 61014, 59897, 60847, 57966, 63146, 61728, 63833
S ome PAN-OS v10.0 THREAT logs, PAN-OS v9.1.x, PAN-OS v9.1 CONFIG logs, and PAN-OS v10.0.x Global Protect logs were not normalized.
KB-1563262130
The URL field of some PAN-OS v10.0 THREAT logs were not normalized.
Palo Alto Network Firewall v5.2.0 ▾
Version: 5.2.0

Enhancements

KB-1215252139
The application now includes new alert packages for the Palo Alto Network Firewall listed in the Package Details section above.
KB-1104547269
In the compiled normalizer PaloAltoCEFCompiledNormalizer, f or the Palo Alto Global Protect CEF logs, the fields user, client_os_version , and reason have been parsed from the field message .

The compiled normalizer PaloAltoNetworkFirewallCompiledNormalizer now supports PAN-OS v10.0 events and Palo Alto Global Protect log for PAN-OS v9.1.0 to PAN-OS v9.1.2. In the compiled normalizer PaloAltoCEFCompiledNormalizer, t he label Detect has been added in the Palo Alto Network Firewall logs for the following sub-category to comply with the Palo Alto Network Firewall convention:

Sub-category Labels
virus Virus, Malware, Detect
spyware Spyware, Malware, Detect
vulnerability Vulnerability, Detect

Bug Fixes

KB-1345257019
An issue where some Palo Alto Network Firewall Threat and Traffic Syslog were not properly normalized.
An issue where some USER-ID logs for Palo Alto Network Firewall v9.0 were not normalized.
An issue where the field User Device Serial Number was missing in the HIP Match log of Palo Alto Network Firewall v9.1.
Palo Alto Network Firewall v3.6.0 ▾
Version: 3.6.0
Release date: May 14, 2020
Supported On: Logpoint v6.0.0 to v6.6.6
SHA 256: cf952a31c0bde19d5e838aef379cee17cbf4cc9e85c3d64e480818170fbcba96
Download

Enhancement

A minor update has been done in the Palo Alto Network Firewall's normalizer for better signature handling.

Support

If you have any questions or require assistance, create a support ticket.

Comments

Article is closed for comments.

Follow

Related articles

  • FortiGate
  • Universal Normalizer
  • AWSServices
  • Sophos
  • Oracle Enrichment Source
Consent Required To Proceed
By clicking “I Agree & Download”, you confirm that you are authorized to act on behalf of your organization and you give explicit consent for Guardsix to share your organization’s customer name and log source count with NXLog for the sole purposes of entitlement management, compliance verification, and support delivery related to the embedded NXLog technology in the Guardsix SIEM solution.

This data will not be used for sales or marketing and will not be shared with other third parties. You may withdraw your consent at any time by contacting Guardsix Support; withdrawal will not affect processing already performed.
Cancel I Agree & Download
Privacy policy    EULA    Terms of service   
Copyright © , Guardsix. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.