Palo Alto PA DSM specifications
The following table identifies the specifications for the Palo Alto PA Series DSM:
| Specification | Value |
|---|---|
| Manufacturer | Palo Alto Networks |
| DSM name | Palo Alto PA Series |
| RPM file name | DSM-PaloAltoPaSeries-QRadar_version-build_number.noarch.rpm |
| Event format |
LEEF for PAN-OS v3.0 to v10.2, PAN-OS v11.0.4, and Prisma Access v2. CEF for PAN-OS v4.0 to v6.1 and v11.1.6. (CEF:0 is supported) |
| QRadar recorded log types |
Traffic Threat Config System HIP Match Data WildFire Authentication Tunnel Inspection or Tunnel (v10.0 , v11.0.4) Correlation URL Filtering User-ID SCTP File Data GTP HIP Match IP-Tag Global Protect
Important: To use the Global Protect log type, you must enable the
EventStatus/Status field in Palo Alto.
Decryption URL (for PAN-OS 11.0.4) File (for PAN-OS 11.0.4) DNS (for PAN-OS 11.0.4) |
| Automatically discovered? | Yes |
| Includes identity? | Yes |
| Includes custom properties? | No |
| More information | Palo Alto Networks website (http://www.paloaltonetworks.com) |