Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.
I am trying to configure the Custom Log Format (LEEF) for Palo Alto Firewall. Pan OS is running in 10.X (firmware version), but the official QRadar Documentation https://www.ibm.com/docs/en/dsm?topic=panps-creating-syslog-destination-your-palo-alto-pa-series-device only specifies the Log Event Extended Format (LEEF) only until version 9.1
Will the same config also work for 10.0.4?
How shall I proceed with configuring the Custom Log Format on the PA?
Hi,
I can confirm that the forwarded logs of Palo Release 10.0.4 are also normalized with this configuration in QRadar.
Hope this helps.
Regards,
Ralph