Forum Discussion
Micah-NENZ
Oct 06, 2021Copper Contributor
Palo Alto Syslogs to Sentinel
Hi, We are ingesting Palo Alto firewall logs into Sentinel that seems to be mostly working, however the fields are not populating correctly. There is an additional field called 'AdditionalExt...
CliveWatson
Microsoft
Oct 06, 2021There is a ASIM parser for Palo
Main docs:
https://docs.microsoft.com/en-us/azure/sentinel/normalization
Parsers page:
Azure-Sentinel/Parsers/ASimNetworkSession at master · Azure/Azure-Sentinel - https://github.com/
and the parser itself, where that field is normalized:
Azure-Sentinel/ASimNetworkSessionPaloAltoCEF.yaml at master · Azure/Azure-Sentinel - https://github.com/