Palo Alto PA DSM specifications

The following table identifies the specifications for the Palo Alto PA Series DSM:

Table 1. DSM specifications for Palo Alto PA Series
Specification Value
Manufacturer Palo Alto Networks
DSM name Palo Alto PA Series
RPM file name DSM-PaloAltoPaSeries-QRadar_version-build_number.noarch.rpm
Event format

LEEF for PAN-OS v3.0 to v10.2, PAN-OS v11.0.4, and Prisma Access v2.

CEF for PAN-OS v4.0 to v6.1 and v11.1.6. (CEF:0 is supported)

QRadar recorded log types

Traffic

Threat

Config

System

HIP Match

Data

WildFire

Authentication

Tunnel Inspection or Tunnel (v10.0 , v11.0.4)

Correlation

URL Filtering

User-ID

SCTP

File Data

GTP

HIP Match

IP-Tag

Global Protect
Important: To use the Global Protect log type, you must enable the EventStatus/Status field in Palo Alto.

Decryption

URL (for PAN-OS 11.0.4)

File (for PAN-OS 11.0.4)

DNS (for PAN-OS 11.0.4)

Automatically discovered? Yes
Includes identity? Yes
Includes custom properties? No
More information Palo Alto Networks website (http://www.paloaltonetworks.com)