Set up the Wirespeed forwarder
- Follow the shared Log Forwarders guide to add Palo Alto Networks NGFW and open Forwarder Details
- Copy the hostname or IP address and listener port shown by Wirespeed
- Keep Forwarder Details available while configuring PAN-OS
Create a PAN-OS syslog server profile
- Sign in to the firewall or Panorama:
- On a firewall, go to Device > Server Profiles > Syslog
- In Panorama, select the template or template stack for the managed firewalls, then go to Device > Server Profiles > Syslog
- Click Add, name the profile, and select its virtual-system location when applicable
- Add a syslog server and enter the Wirespeed hostname or IP address and port
- Choose the transport configured in Wirespeed:
- TCP provides reliable cleartext delivery
- SSL provides reliable encrypted delivery using TLS 1.2
- UDP provides connectionless cleartext delivery
- Select IETF format when available. Its timezone-aware header provides a safer timestamp fallback than BSD format
- Select the facility your organization uses, then save the server profile
Choose which logs to forward
You control which PAN-OS log categories Wirespeed receives. You can forward all supported categories, only categories such as Traffic, Threat, or URL Filtering, or a filtered subset of each category.Policy-generated logs
- Go to Objects > Log Forwarding. In Panorama, first select the device group for the managed firewalls
- Add a Log Forwarding profile
- Add one match-list entry for each desired log type, such as:
- Traffic
- Threat
- URL Filtering
- Data Filtering
- WildFire Submissions
- Authentication
- Tunnel Inspection
- GTP
- SCTP
- Select the Wirespeed syslog server profile for each entry
- Optionally add a Palo Alto filter to restrict that log type by severity, verdict, zone, rule, or another available log attribute
- Attach the Log Forwarding profile to the applicable Security, Authentication, Decryption, DoS Protection, and Tunnel Inspection policy rules
- For Traffic logs, enable Log at Session Start, Log at Session End, or both according to your monitoring requirements
Device-generated logs
Go to Device > Log Settings and select the Wirespeed syslog server profile for the desired System, Config, User-ID, HIP Match, Correlation, IP-Tag, GlobalProtect, and Audit log settings available in your PAN-OS release. In Panorama, configure these settings in the template or template stack for the managed firewalls.Wirespeed supports the standard Traffic, Threat, URL Filtering, Data Filtering, WildFire, HIP Match, GlobalProtect, IP-Tag, User-ID, Decryption, Tunnel Inspection, SCTP, Config, Authentication, System, Correlated Events, GTP, and Audit syslog layouts. You do not need to enable every type.
Commit and verify
- Deploy the PAN-OS configuration:
- On a firewall, select Commit
- In Panorama, select Commit > Commit and Push and include the affected device groups and templates
- Generate an event for each enabled category
- Confirm that events appear under Events in Wirespeed

