I currently need to retrieve syslogs from my palo alto firewall, and I just saw that I can either use filebeat's panw module or deploy a fleet servers and use palo alto integration.
So I was wondering what more will the integration and the fleet server bring than just filebeat. (or if it does not change anything)
I guess it depend what you want to be able to do.
Using Filebeat will be quicker and get what you want.
Using Fleet gives you many more capabilities but takes more time to setup.