May 30 2024 10:43 PM
Hi all,
I've integrated Palo Firewall with MS Sentinel.
For most log type (Traffic, Threat, System), everything is working fine.
But for GlobalProtect log type, it's missing almost all valuable values (no username, authentication status (failed or success), Portal Name, Gateway Name, etc...
I used to following URL to defines CEF format.
https://github.com/pemontto/Palo-Alto-CEF/blob/master/10.0/globalprotect.txt
PS: PANOS version 11.x
Any idea ??
Regards,
HA
Jun 26 2024 07:08 AM
Jun 30 2024 07:00 AM
Jul 24 2024 07:57 AM
SolutionJul 25 2024 01:12 AM
Jul 24 2024 07:57 AM
Solution