# Palo Alto integration with USERID \[SIEM Feature\]

**URL:** https://discuss.elastic.co/t/palo-alto-integration-with-userid-siem-feature/268173
**Category:** Beats
**Tags:** filebeat
**Created:** [March 24, 2021, 7:41am UTC](https://discuss.elastic.co/t/palo-alto-integration-with-userid-siem-feature/268173 "2021-03-24T07:41:54Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![RdrgPorto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rdrgporto/32/13278_2.png) [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)
#### Post date: [March 24, 2021, 7:41am UTC](https://discuss.elastic.co/t/palo-alto-integration-with-userid-siem-feature/268173/1 "2021-03-24T07:41:54Z")

</div>

Hi, everyone

I have been working with **Palo Alto and Filebeat** over several days. I have looked on **Elastic documentation** that it currently supports messages of **Traffic** and **Threat** types.

Is it considered to parsing [User-ID type](https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/user-id-log-fields.html) ? I would like to get it because it provides information about **login** and **logouts** of **usernames**.

Thanks in advance,

Rodrigo

---

<div class="post-metadata">

### Author: ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)
#### Post date: [March 24, 2021, 8:28am UTC](https://discuss.elastic.co/t/palo-alto-integration-with-userid-siem-feature/268173/2 "2021-03-24T08:28:05Z")

</div>

Hi!

You can find the fields that this module populates/handles at [Palo Alto Networks module | Filebeat Reference [7.12] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-panw.html) and [panw fields | Filebeat Reference [7.12] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields-panw.html).  
If you think the information you are interested into is not included in the supported fields right now please go ahead and open a Github issue for the team to request adding it.

C.

---

<div class="post-metadata">

### Author: ![RdrgPorto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rdrgporto/32/13278_2.png) [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)
#### Post date: [March 24, 2021, 9:30am UTC](https://discuss.elastic.co/t/palo-alto-integration-with-userid-siem-feature/268173/3 "2021-03-24T09:30:44Z")

</div>

Hi, @ChrsMark

I just created an issue on [GitHub](https://github.com/elastic/beats/issues/24722).

Thanks 🙂 ,

Rodrigo

---

<div class="post-metadata">

### Author: ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)
#### Post date: [March 24, 2021, 10:25am UTC](https://discuss.elastic.co/t/palo-alto-integration-with-userid-siem-feature/268173/4 "2021-03-24T10:25:36Z")

</div>

Hello @RdrgPorto and @ChrsMark ,

We too are very much interested in extending / improving the Palo Alto datasets... Not only for userid, but also for globalprotect and system logs.

Another important question I've been asking is when we can expect the panw module to go out of beta? The module is imho our most important dataset and it has been in beta since the beginning. I also created multiple issue with the existing threat and traffic data

> <https://github.com/elastic/beats/issues/22413>
>
> panw.panos dataset's event.type field is populated with the value 'denied' twice.
> Elastic 7.9.2
> https://discuss.elastic.co/t/siem-rule-override-not-working-as-expected/253933/4
> In /usr/share/filebeat/module/panw/panos/ingest/pipeline.yml I can find:
> - append:
> field: event.type
> value:
> ...

> <https://github.com/elastic/beats/issues/20517>
>
> The panw.panos related.user field contains duplicate user names when client/source and server/destination user name are identical.
> The filebeat-7.8.1-panw-panos-pipeline should contain logic to...

Please please dedicate some resources into the panw module, so that it finally becomes a supported and trusted dataset which covers all panw event types.

Best regards,

Willem

---

<div class="post-metadata">

### Author: ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)
#### Post date: [March 24, 2021, 10:32am UTC](https://discuss.elastic.co/t/palo-alto-integration-with-userid-siem-feature/268173/5 "2021-03-24T10:32:31Z")

</div>

Created [[Filebeat] Palo Alto integration with GlobalProtect · Issue #24724 · elastic/beats · GitHub](https://github.com/elastic/beats/issues/24724)

---

<div class="post-metadata">

### Author: ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)
#### Post date: [March 24, 2021, 3:13pm UTC](https://discuss.elastic.co/t/palo-alto-integration-with-userid-siem-feature/268173/6 "2021-03-24T15:13:57Z")

</div>

Thank you all!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 21, 2021, 5:14pm UTC](https://discuss.elastic.co/t/palo-alto-integration-with-userid-siem-feature/268173/7 "2021-04-21T17:14:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
