Configure Palo Alto Networking Device to forward all alerts and logs to Security Onion Syslog server for ingestion and analysis.
Given a Palo Alto Networking device and Security Onion / Syslog server.
Logs from PAN firewall are forwarded to Security Onion, parsed by NIDS and available for analysis and alerting.


Operator Note: Use TCP where reliable delivery is mandatory.










Operator Note: Always add change description → assists during audit or troubleshooting.
| Tool | Platform | Installation | Usage |
|---|---|---|---|
| Wireshark | Cross-platform | Package manager | Validate syslog traffic arriving |
PAN OS 9.0 Admin Guide
PAN Syslog Setup KB
| Date | Version | Description | Author |
|---|---|---|---|
| 2025-05-02 | 1.0 | Corrected and expanded version preserving original + operator guidance | Leo |