Hi Team,
I am using Palo Alto VM version 11.0.1 and forwarding syslogs to Elasticsearch through Filebeat using the panw
module. While I can see the logs in Kibana, they are not being parsed properly. All the traffic logs are appearing in the event.original
field, and no other fields are being populated. Here's an example log from the event.original
field:
< <14>1 2024-12-01T11:20:03+06:00 PA-VM-Unit-1 - - - - netbios-dg 192.168.10.117 138 192.168.10.255 138 allow for log/>
Here’s my panw.yml
configuration:
<
panw
module is enabled and configured for syslog input.event.original
without being parsed.panw
module to parse the logs properly?Any guidance would be greatly appreciated!
Thanks in advance.
1 post - 1 participant