panos-parser(): parsing PAN-OS log messages

The PAN-OS (a short version of Palo Alto Networks Operating System) parser can parse log messages originating from Palo Alto Networks devices. Even though these messages completely comply to the RFC standards, their MESSAGE part is not a plain text. Instead, the MESSAGE part contains a data structure that requires additional parsing.

The panos-parser() of AxoSyslog solves this problem, and can separate PAN-OS log messages to name-value pairs. For details on using value-pairs in AxoSyslog, see Structuring macros, metadata, and other value-pairs.

Prerequisites

  • Version 3.29 of AxoSyslog or later.

  • Install the axosyslog-scl package on Debian/Ubuntu. On RHEL and compatible distributions, the SCL files are part of the axosyslog base package.

    Your configuration must also contain @include "scl.conf", which the default configuration file already does. If the SCL files are missing, AxoSyslog fails to start with an unexpected LL_IDENTIFIER error.

    Terminal window
    @include "scl.conf"

    The panos-parser() driver is a reusable configuration snippet (SCL). For details on using or writing such configuration snippets, see Reusing configuration blocks. You can find its source in scl/paloalto/panos.conf on GitHub.

  • PAN-OS log messages from Palo Alto Networks devices.

Limitations

The panos-parser() only works on AxoSyslog version 3.29 or later.

Configuration

You can include the panos-parser() in your AxoSyslog configuration like this:

Terminal window
   parser p_parser{
        panos-parser();
    };
Last modified August 5, 2026: Small fixes and deduplications (99cac43a)