# Palo Alto Next-Gen Firewall compatibility with Global Protect VPN Client

**URL:** <https://discuss.elastic.co/t/palo-alto-next-gen-firewall-compatibility-with-global-protect-vpn-client/349084>\
**Category:** Logstash\
**Created:** [December 11, 2023, 7:12pm UTC](https://discuss.elastic.co/t/palo-alto-next-gen-firewall-compatibility-with-global-protect-vpn-client/349084 "2023-12-11T19:12:12Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![CodeMonky](https://avatars.discourse-cdn.com/v4/letter/c/ecccb3/32.png) [@CodeMonky](https://discuss.elastic.co/u/CodeMonky)\
**Post date:** [December 11, 2023, 7:12pm UTC](https://discuss.elastic.co/t/palo-alto-next-gen-firewall-compatibility-with-global-protect-vpn-client/349084/1 "2023-12-11T19:12:12Z")

</div>

Good day all!

I'm looking for confirmation on the features of the Palo Alto Next-Gen Firewall integration with elastic. On the overview page of the integration, it details support of the Global Protect type of message.

Does this mean that it is able to get logs from the actual on computer clients or does this mean something else? We are looking to be able to pull logs from the VPN client ON the machine of the end user.

Thanks!

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [December 11, 2023, 7:30pm UTC](https://discuss.elastic.co/t/palo-alto-next-gen-firewall-compatibility-with-global-protect-vpn-client/349084/2 "2023-12-11T19:30:37Z")

</div>

You can use Elasti agent, which is described [here](https://docs.elastic.co/en/integrations/panw).

If you prefer LS, then you can use the syslog input plugin, and parse with JSON, CEF codec, KV plugin depends in which format a device will send.

In general LS, do not detect source, it just transform data how we set in a .conf file.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [December 11, 2023, 8:08pm UTC](https://discuss.elastic.co/t/palo-alto-next-gen-firewall-compatibility-with-global-protect-vpn-client/349084/3 "2023-12-11T20:08:53Z")

</div>

> [@CodeMonky](#):
>
> Does this mean that it is able to get logs from the actual on computer clients or does this mean something else? We are looking to be able to pull logs from the VPN client ON the machine of the end user.

It means that it can parse the logs with the Global Protect format, to get the logs from the Client on every machine you would need to install the Agent also on every machine.

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [December 12, 2023, 8:25am UTC](https://discuss.elastic.co/t/palo-alto-next-gen-firewall-compatibility-with-global-protect-vpn-client/349084/4 "2023-12-12T08:25:32Z")

</div>

Hi,

When a user connects to the VPN, the firewall generates logs that contain information about the user, the IP address they were assigned, the time they connected and disconnected, and other details. These logs can be forwarded to Elastic for analysis.

However, if you're looking to collect logs directly from the VPN client on the end user's machine, this would require a different approach. You would need to configure the client to generate logs, and then use a log shipper like Filebeat to send these logs to Elastic.

Regards

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [December 12, 2023, 9:22am UTC](https://discuss.elastic.co/t/palo-alto-next-gen-firewall-compatibility-with-global-protect-vpn-client/349084/5 "2023-12-12T09:22:51Z")

</div>

LS has an option called [the persistent queue](https://www.elastic.co/guide/en/logstash/current/persistent-queues.html) and FB has also option [the internal queue](https://www.elastic.co/guide/en/beats/filebeat/current/configuring-internal-queue.html) on the disk.

I don't think ES or LS can detect the active agent and pull data. LS is listening mode and forward data to ES or other destination. What I see as a solution here is FB/EA on VPN client side with buffering on disk, keeping FB active and trying to reconnect. When the connection is established with ES or LS, FB will deliver logs. LS is little bit heavy and complex to install on the VPN clients, I would avoid. Maybe someone else had the experience with this scenario, really would like to hear from 1st hand.

---

<div class="post-metadata">

**Author:** ![CodeMonky](https://avatars.discourse-cdn.com/v4/letter/c/ecccb3/32.png) [@CodeMonky](https://discuss.elastic.co/u/CodeMonky)\
**Post date:** [December 12, 2023, 2:52pm UTC](https://discuss.elastic.co/t/palo-alto-next-gen-firewall-compatibility-with-global-protect-vpn-client/349084/6 "2023-12-12T14:52:15Z")

</div>

So, we do deploy the client on all machines that have the VPN so that is covered. From some of the other posts it sounds like that integration does something like what we are looking for if the VPN client than forwards the logs to the firewall and then us.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 9, 2024, 2:52pm UTC](https://discuss.elastic.co/t/palo-alto-next-gen-firewall-compatibility-with-global-protect-vpn-client/349084/7 "2024-01-09T14:52:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
