Palo Alto Networks icon

Palo Alto Networks Next Gen Firewall

Next-gen firewall log ingestion & threat correlation

Palo Alto Networks’ Next-Generation Firewall (NGFW) is a network security appliance that goes beyond traditional port-and-protocol filtering to inspect traffic by application, user, and content. It provides deep packet inspection, intrusion prevention, and threat prevention capabilities at the network perimeter.

How it works

Dual path: direct API (palo_alto_networks) for native pull, plus via-SIEM ingestion (palo_alto_networks_siem) when logs are routed through Splunk, Sumo Logic, or LogTrust.

Data ingested

Firewall traffic logs, threat prevention alerts, URL filtering

Frequently asked questions

How does Expel ingest data from my Palo Alto NGFW?

Expel ingests Palo Alto NGFW data through your existing SIEM, or via direct API rather than a standalone native connector. That SIEM-mediated path is standard practice most MDR providers use for firewall log ingestion. Once flowing, logs feed Expel’s detections inside Workbench, Expel’s analyst operations platform.

How does Expel improve threat detection on Palo Alto NGFW?

Expel improves Palo Alto NGFW threat detection by applying custom detections mapped to the MITRE ATT&CK framework against firewall logs. Expel has used this data to detect cryptomining activity, including CoinMiner malware command-and-control traffic. Analysts review confirmed findings in Workbench instead of leaving raw alerts unreviewed.

How is Expel different from relying only on Palo Alto NGFW's native alerting?

Native NGFW alerting surfaces firewall events without correlating them to broader attack patterns. Expel ingests those logs through your SIEM, whether Splunk Enterprise Security or Sumo Logic, then applies detections mapped to MITRE ATT&CK, previously catching cryptomining command-and-control traffic this way. Analysts review confirmed findings in Workbench, not raw log noise.

What are the top features of Expel's Palo Alto NGFW integration?

Expel’s Palo Alto NGFW coverage includes support for two SIEM paths, Splunk Enterprise Security and Sumo Logic, plus detections mapped to the MITRE ATT&CK framework. Expel has used NGFW log data to detect cryptomining command-and-control traffic.

How do I request a demo of Expel with Palo Alto NGFW?

Requesting a demo of Expel’s Palo Alto NGFW coverage happens through a form on expel.com/request-demo. The walkthrough shows how NGFW logs flow in through your SIEM, whether Splunk Enterprise Security, or Sumo Logic, and how detections mapped to the MITRE ATT&CK framework are applied to that data.