Palo Alto PAN-OS
You can integrate Palo Alto PAN-OS with Sophos XDR so that it sends alerts to Sophos for analysis.
This page gives you an overview of the integration.
Palo Alto PAN-OS product overview
Palo Alto Networks' Panorama PAN-OS is a centralized security management system that provides users with global visibility, policy control, and workflow automation across their entire firewall deployment. It's a holistic approach to network security that ensures consistent coverage and real-time threat intelligence.
What we ingest
Sophos XDR collects Palo Alto Networks next-generation firewall data over syslog forwarded from your managed firewalls or from Panorama to a Sophos XDR data collector. The same logical log types (for example, Traffic, Threat, System) can arrive in more than one body format, and classification is based on message content rather than on whether the source is a firewall, Panorama, or a log collector. We accept the following Palo Alto Networks log formats:
- Native CSV: After any syslog headers, the body is Palo Alto's standard comma-separated record (receive time, serial, log type, subtype, and remaining fields). Cloud or log-forwarder variants may add an ISO timestamp and a
panwlogs - ...prefix before the CSV. - CEF in syslog: The payload is CEF with vendor Palo Alto Networks in the CEF header (for example,
CEF:0|Palo Alto Networks|...). Extensions are interpreted into the same log type and subtype model used for CSV.
Palo Alto Networks sends these messages exactly as configured in your log forwarding profiles. Which log types and fields appear depends on which features and subscriptions are licensed and enabled (for example, URL Filtering, Threat Prevention, WildFire, GlobalProtect, or User-ID); what your security policy logs at session start, session end, and on threat detection; and which streams each rule forwards.
Event and data types
We ingest the following event and data types from Palo Alto:
- Session traffic (TRAFFIC): End, deny, and drop: netflow-style telemetry. Start: searchable, lighter normalization.
- Threat (THREAT): URL subtype: HTTP-style and network IDS–style telemetry. Other subtypes: network IDS–style telemetry.
- Correlation (CORRELATION): Network IDS–style telemetry (CSV and CEF syslog).
- GlobalProtect (GLOBALPROTECT): Login, logout, tunnel-related: authentication telemetry; other stages may stay generic.
- System (SYSTEM): Mostly generic; authentication and globalprotect subtypes with logon, logoff, or failure outcomes: authentication telemetry.
- Configuration (CONFIG): Generic telemetry with audit-oriented fields preserved.
- User–IP mapping (USERID): Generic telemetry.
- Host posture (HIPMATCH), IP tagging (IPTAG), mobile core (GTP): Generic telemetry (GTP also when sent as CEF where supported).
- SSL/TLS decryption (DECRYPTION) and authentication portal (AUTH): Ingested and searchable on the CSV syslog path (including panwlogs prefixes); generic telemetry in current normalization.
- Other variants: Ingested and searchable as generic Palo Alto telemetry when they match the supported syslog formats, but not a specialized category above.
Data provided by this integration
Data provided by Palo Alto PAN-OS gets normalized to the following schemas:
authhttpnetflownids
For more information about using schemas in Data Lake Search, see Schemas and logical types.