Hello,
since we replaced the PaloAlto firewall devices a couple of days ago (the old ones were running PanOS 9.1.7, the new ones are on 10.1.4) for one of our customers, none of the logs coming from the firewalls are normalized anymore (there are 1000s of logs in the repo, but doing a search query “ norm_id="*" “ shows no result).
We are using the same policies (collection, normalization etc) as before, and the firewall admin says that they just migrated the configuration fromt ht eold to the new devices and can not see any changes regarding the log configuration settings.
I already restarted all normalizer services, even rebooted the LP and completely recreated the device configuration.
We are using the latest (5.2.0) PaloAlto Application plugin on LogPoint 6.12.2, and its details clearly state that PanPOS 10 is supported (Palo Alto Network Firewall – ServiceDesk # LogPoint). And taking a look at the raw logs, i can not see any differenc in the log format of PanOS 9 and 10. However, also tried adding the “PaloAltoCEFCompiledNormalizer” to the normalization policy (it “only” included the PaloAltoNetworkFirewallCompiledNormalizer), but nothing helped.
Does anyone has any thought what might be the issue or what else i can check before i open a support ticket. Is there any way to debug the normalization preocess on the LogPoint CLI ?
Regards
Andre