---
title: "panos-parser(): parsing PAN-OS log messages"
url: "https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/panos-parser/"
last_modified: "2026-08-05T15:08:09+02:00"
---

> For the complete documentation index, see [llms.txt](https://axoflow.com/docs/axosyslog-core/4.28/llms.txt).

# panos-parser(): parsing PAN-OS log messages

The [PAN-OS](https://docs.paloaltonetworks.com/pan-os.html) (a short version of Palo Alto Networks Operating System) parser can parse log messages originating from [Palo Alto Networks](https://www.paloaltonetworks.com/) devices. Even though these messages completely comply to the RFC standards, their `MESSAGE` part is not a plain text. Instead, the `MESSAGE` part contains a data structure that requires additional parsing.

The `panos-parser()` of AxoSyslog solves this problem, and can separate PAN-OS log messages to name-value pairs. For details on using value-pairs in AxoSyslog, see [Structuring macros, metadata, and other value-pairs](https://axoflow.com/docs/axosyslog-core/4.28/chapter-concepts/concepts-value-pairs/index.md).

## Prerequisites

- Version 3.29 of AxoSyslog or later.
- Install the `axosyslog-scl` package on [Debian/Ubuntu](https://axoflow.com/docs/axosyslog-core/4.28/install/debian-ubuntu/index.md). On [RHEL and compatible distributions](https://axoflow.com/docs/axosyslog-core/4.28/install/rhel-fedora-almalinux/index.md), the SCL files are part of the `axosyslog` base package.

  Your configuration must also contain `@include "scl.conf"`, which the default configuration file already does. If the SCL files are missing, AxoSyslog fails to start with an [`unexpected LL_IDENTIFIER` error](https://axoflow.com/docs/axosyslog-core/4.28/chapter-troubleshooting-syslog-ng/unexpected-ll-identifier/index.md).

  ```shell
  @include "scl.conf"
  ```

  The `panos-parser()` driver is a reusable configuration snippet (SCL). For details on using or writing such configuration snippets, see [Reusing configuration blocks](https://axoflow.com/docs/axosyslog-core/4.28/chapter-configuration-file/large-configs/config-blocks/index.md). You can find its source in [scl/paloalto/panos.conf](https://github.com/axoflow/axosyslog/blob/main/scl/paloalto/panos.conf) on GitHub.
- PAN-OS log messages from Palo Alto Networks devices.

## Limitations

The `panos-parser()` only works on AxoSyslog version 3.29 or later.

## Configuration

You can include the `panos-parser()` in your AxoSyslog configuration like this:

```shell
   parser p_parser{
        panos-parser();
    };
```

---

[Message format parsed by panos-parser()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/panos-parser/panos-parser-m-form/index.md)

[PAN-OS parser options](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/panos-parser/panos-parser-options/index.md)

Last modified August 5, 2026: [Small fixes and deduplications (99cac43a)](https://github.com/axoflow/axosyslog-core-docs/commit/99cac43a517770299b97c7ed360eb87af9fef5ab)
