Centralized logging is a core requirement for modern Security Operations Centers (SOC). Security analysts need visibility into network traffic, threat events, and system changes without logging into individual firewalls. Implementing Palo Alto log forwarding to a Syslog server or Security Information and Event Management (SIEM) platform ensures compliance, simplifies audits, and accelerates incident response. This technical tutorial guides you through configuring, routing, and verifying log forwarding on PAN-OS devices.
Related NetworkFix resources: If you are building the underlying firewall policy and connectivity first, see the Palo Alto Security Policy guide and Palo Alto Virtual Router and Default Route guide.
Real-Life Scenario
An enterprise organization is deploying a central SIEM platform to aggregate security telemetry across all locations. The SOC requires the firewall team to stream the following logs to the central SIEM:
- Traffic logs (session end events)
- Threat logs (antivirus, vulnerability, spyware, WildFire, and URL filtering)
- System logs (system state changes, daemon status, interface updates)
- Config logs (administrative changes and commit operations)
The engineering team must ensure logs route reliably, avoid dropped traffic logs, and provide verification steps to confirm delivery from the firewall management plane.
Lab Topology
The following diagram outlines the logical topology for this configuration environment:
+-----------------------------------------------------------+ | Enterprise Network | | | | +--------------------+ +---------------------+ | | | Internal Host | | SIEM / Syslog | | | | 192.168.1.100/24 | | 192.168.10.50/24 | | | +---------+----------+ +----------+----------+ | | | | | | | Trust (Eth1/2) | Management | | | | Network | | +--------v--------------------------------v-------+ | | | Palo Alto Networks Firewall | | | | (PAN-OS 10.2+) | | | +-------------------------------------------------+ | | | +-----------------------------------------------------------+
Example Addressing and Objects
All IP addresses, hostnames, and object names listed below are lab examples. Adapt these parameters to match your network design.
| Parameter / Object | LAB / EXAMPLE Value | Description |
|---|---|---|
| Firewall Management IP | 192.168.1.10/24 |
Out-of-band management interface (default egress interface) |
| Dataplane Interface (eth1/1) | 192.0.2.1/24 |
Untrust zone interface |
| Dataplane Interface (eth1/2) | 192.168.1.1/24 |
Trust zone interface |
| SIEM / Syslog Server IP | 192.168.10.50 |
Target log collector host address |
| Syslog Transport / Port | UDP / Port 514 | Transport protocol and destination port |
| Syslog Server Profile | SP-SIEM-PRIMARY |
Defines Syslog server IP, facility, and format |
| Log Forwarding Profile | LFP-SOC-FORWARDING |
Defines match criteria for policy attachment |
Prerequisites
Before beginning the configuration, ensure you have satisfied the following technical requirements:
- Administrative access to the PAN-OS Web Interface (GUI) and Command Line Interface (CLI).
- Network reachability between the firewall interface (Management or Dataplane) and the Syslog server on UDP port 514 or TCP port 514/6514.
- Information on the required Syslog format expected by your SIEM vendor (such as BSD, IETF, CEF, or custom key-value pairs).
Configuring Palo Alto Log Forwarding Step-by-Step
Log forwarding configuration in PAN-OS consists of three core steps: defining the Syslog target server, building a log forwarding profile, and linking that profile to your operational traffic rules and system events.
Step 1: Create a Syslog Server Profile
The Syslog Server Profile specifies the target IP address, port, transport protocol, and message format for your log collector.
- Log into the firewall Web Interface.
- Navigate to Device > Server Profiles > Syslog.
- Click Add at the bottom of the page.
- Enter a descriptive profile name, such as
SP-SIEM-PRIMARY. - Under the Servers tab, click Add and fill in the server details:
- Name:
SIEM-Server-01 - Syslog Server:
192.168.10.50 - Transport:
UDP(SelectTCPorSSLif your receiver requires it) - Port:
514 - Format:
BSD(Default standard; chooseIETFif required) - Facility:
LOG_USER(Set according to your SIEM categorization rules)
- Name:
- Click OK to save the server definition.
- Click OK to save the Syslog Server Profile.
Step 2: Create a Log Forwarding Profile
A Log Forwarding Profile determines which logs (traffic, threat, URL filtering, WildFire) are sent to the Syslog server profile configured in Step 1.
- Navigate to Objects > Log Forwarding.
- Click Add at the bottom of the page.
- Enter a name for the profile, such as
LFP-SOC-FORWARDING. - Under Log Forwarding List, click Add to create a rule match item.
- In the match rule dialog:
- Name:
Forward-Traffic-Logs - Log Type: Select
traffic. - Filter: Leave as
All Logs(or build a custom query to filter specific events). - Under Syslog, click Add and select
SP-SIEM-PRIMARY.
- Name:
- Click OK.
- Click Add again to create a match item for threat logs:
- Name:
Forward-Threat-Logs - Log Type: Select
threat. - Filter: Select
All Logs. - Under Syslog, click Add and select
SP-SIEM-PRIMARY.
- Name:
- Click OK, then click OK again to save the Log Forwarding Profile.
Step 3: Attach the Log Forwarding Profile to Security Policies
Log Forwarding Profiles do not forward traffic logs automatically. You must explicitly attach the profile to individual Security Policy rules.
- Navigate to Policies > Security.
- Select the Security Rule whose traffic you want to monitor (for example, your outbound internet rule).
- Navigate to the Actions tab.
- Under Log Setting, ensure Log at Session End is checked.
- In the Log Forwarding drop-down menu, select
LFP-SOC-FORWARDING. - Click OK.
- Repeat this step for all Security Rules that require logging.
Step 4: Configure System and Config Log Forwarding
System, Config, and User-ID events are generated by the management plane and are not associated with security policies. Configure these settings separately in the Device tab.
- Navigate to Device > Log Settings.
- Under System, click Add.
- Enter a name (e.g.,
Forward-System-Logs), select your filter criteria (or leave blank for all logs), and addSP-SIEM-PRIMARYunder Syslog. Click OK. - Under Config, click Add.
- Enter a name (e.g.,
Forward-Config-Logs) and addSP-SIEM-PRIMARYunder Syslog. Click OK.
Step 5: Configure the Service Route (Optional but Critical)
By default, PAN-OS sends system traffic (including Syslog export) out of the dedicated management (MGT) interface. If your SIEM server resides on a internal network reachable only through a dataplane interface, you must adjust the Service Route.
- Navigate to Device > Setup > Services.
- Click Service Route Configuration.
- Select Customize.
- Locate the Syslog service item and click on it.
- Select Source Interface and choose the appropriate dataplane interface (for example,
ethernet1/2). - Select the matching Source Address assigned to that interface.
- Click OK, then click OK again to close the window.
- Click Commit to apply all pending changes to the active device configuration.
CLI Operational Checks
Command Line Interface operational commands allow engineers to inspect log processes, verify outbound connections, and ensure service routes match design expectations.
To inspect active Service Routes and confirm which interface handles Syslog outbound traffic:
admin@PA-3220> show service-route
To monitor real-time output from the management plane Syslog daemon (syslogd) and check for connection errors:
admin@PA-3220> tail follow yes mp-log syslogd.log
To confirm local log generation before investigating network delivery, view recent traffic logs on the firewall:
admin@PA-3220> show log traffic direction equal backward limit 5
How the Traffic Flows
Understanding PAN-OS packet and log processing architecture helps diagnose forwarding issues quickly.
- Dataplane Processing: Active network sessions cross the firewall dataplane. When traffic matches a security policy rule configured with logging, the dataplane generates log records when the session terminates (Session End).
- Management Plane Ingestion: The dataplane offloads log events to the management plane logging subsystem. Local log files are written to internal flash/SSD storage.
- Log Forwarding Engine Evaluation: The management plane log daemon matches the newly recorded log event against configured Log Forwarding Profiles and System Log Settings.
- Egress Routing & Framing: The firewall encapsulates the log payload into the specified Syslog format (BSD/IETF). It evaluates routing based on the global Service Route configuration:
- If set to Management, the system sends the log packet out the physical
MGTport. - If customized to a Dataplane Interface, the packet bypasses the management port and exits the designated internal interface.
- If set to Management, the system sends the log packet out the physical
- Delivery: The packet travels across the network to the destination IP and port defined in the Syslog Server Profile.
Verification
Verify that your Palo Alto log forwarding deployment is functioning correctly using the following operational checks:
1. Check Local Traffic Logs
Ensure the firewall is actively generating local traffic logs. Navigate to Monitor > Logs > Traffic. Confirm that recent connections show a valid rule match and a non-empty Log Forwarding Profile indicator.
2. Check System Logs for Export Errors
Navigate to Monitor > Logs > System. Filter for Syslog issues using the query search bar:
( subtype eq syslog )
Look for system messages indicating connection failures, unreachable hosts, or socket errors.
3. Verify Receiving Side (SIEM Receiver)
Log into your Syslog collector or SIEM interface. Perform a live stream capture or search query matching the firewall source IP address. Confirm that incoming logs arrive with readable timestamps and expected facilities.
Troubleshooting
When log records fail to appear on your SIEM platform, use this structured troubleshooting workflow to identify the root cause.
Symptom 1: No Syslog Messages Arrive at the Collector
- Cause A: Routing / Service Route misconfiguration. If the SIEM is on an internal network, but the service route is set to Default (Management Interface), the management port may lack a default gateway or route to reach the SIEM IP.
- Check: Verify connectivity using CLI ping sourced from the designated interface:
admin@PA-3220> ping source 192.168.1.10 host 192.168.10.50 - Cause B: Intermediate firewall or network ACL blocking port 514. Ensure network devices between the firewall and SIEM permit UDP/TCP port 514.
Symptom 2: Threat Logs Forward, but Traffic Logs Do Not
- Cause: Missing Log Forwarding Profile on Security Rules. Threat logs, system logs, and traffic logs use different triggers. Traffic logs require explicit assignment on individual Security Rules.
- Check: Open your high-volume Security Rules under Policies > Security > Actions. Ensure Log at Session End is checked and the Log Forwarding Profile is explicitly selected.
Symptom 3: Duplicate Log Entries on the SIEM
- Cause: Enabling both “Log at Session Start” and “Log at Session End”. Enabling session start logging causes the firewall to issue two distinct traffic logs for every connection.
- Check: Uncheck Log at Session Start on your security rules unless specifically required for short-lived transactional sessions.
Common Mistakes
- Forgetting to Commit: Changes made to Server Profiles, Log Forwarding Profiles, and Security Policies do not take effect until an administrative Commit operation completes successfully.
- Configuring Server Profile without attaching Log Forwarding Profile: Creating a Syslog Server Profile under Device settings defines where to send logs, but it does not tell the firewall which traffic rules should use it.
- Ignoring Log Throttling & Management Resource Usage: Assigning log forwarding to high-volume explicit permit rules (such as internal DNS or health checks) can overwhelm management plane log queues. Filter out unnecessary noise using custom log filters within the Log Forwarding Profile.
- Incorrect Facility / Severity Settings: If your SIEM filters incoming events based on Syslog facility tags, incorrect mappings in the Syslog Server Profile can cause the SIEM to silently drop or miscategorize incoming alerts.
Production Considerations
Keep these operational considerations in mind when managing large enterprise firewall installations:
UDP vs. TCP vs. Encrypted Transport (SSL)
UDP port 514 is lightweight and minimizes firewall management plane overhead. However, UDP is stateless and offers no guarantee of delivery during network congestion. If compliance mandates zero log loss, use TCP or SSL transport modes. Be aware that connection disruptions on TCP/SSL sockets can cause local log buffering on the management plane.
HA (High Availability) Environments
Log Forwarding Profiles and Syslog Profiles synchronize automatically across active/passive HA pairs during configuration sync. However, Service Routes are device-specific settings. Verify that custom Service Routes are configured independently on both primary and secondary firewalls.
Custom Log Formatting (CEF / LEEF Templates)
Standard BSD syslog formatting works well for basic syslog collectors. Modern SIEM environments (such as Splunk, IBM QRadar, or Microsoft Sentinel) often require formatted structures like Common Event Format (CEF) or Log Event Extended Format (LEEF). You can customize log templates by editing field mappings directly within the Custom Log Format tab inside your Syslog Server Profile.
Summary
Configuring robust Palo Alto log forwarding requires aligning server definitions, object profiles, security policy actions, and system service routes. By mapping security events to Syslog server profiles and validating connectivity using management CLI tools, network engineers ensure seamless integration with central SIEM platforms and maintain reliable threat visibility across the enterprise.