# Elastic SIEM integration with Palo Alto Network FIrewall

**URL:** <https://discuss.elastic.co/t/elastic-siem-integration-with-palo-alto-network-firewall/209929>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 29, 2019, 6:54am UTC](https://discuss.elastic.co/t/elastic-siem-integration-with-palo-alto-network-firewall/209929 "2019-11-29T06:54:49Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vishnu\_mk](https://avatars.discourse-cdn.com/v4/letter/v/71c47a/32.png) [@Vishnu\_mk](https://discuss.elastic.co/u/Vishnu_mk)\
**Post date:** [November 29, 2019, 6:54am UTC](https://discuss.elastic.co/t/elastic-siem-integration-with-palo-alto-network-firewall/209929/1 "2019-11-29T06:54:50Z")

</div>

Hi Team,

We are integrating Palo Alto Firewall device with Elastic siem. For this we have enabled firewall data on 514 and receiving the same. We want to use the ECS mapping for auto population of SIEM dashboard  
At filebeat, we have enabled the panw module and done the setup process.  
When starting the filebeat instance, I can see the firewall logs getting received, but it is not getting ingested in ELasticsearch index.

The default pipeline has been loaded and is visible at ES. In debug logs, getting following message  
"index 1 exceeds length of 1 when processing mapping for feild event.created"  
"Fail to apply processor client"

There is no relevant information available on this. Request your help  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 27, 2019, 6:54am UTC](https://discuss.elastic.co/t/elastic-siem-integration-with-palo-alto-network-firewall/209929/2 "2019-12-27T06:54:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
