Palo Alto Networks’ Next-Generation Firewall (NGFW) is a network security appliance that goes beyond traditional port-and-protocol filtering to inspect traffic by application, user, and content. It provides deep packet inspection, intrusion prevention, and threat prevention capabilities at the network perimeter.
How it works
Dual path: direct API (palo_alto_networks) for native pull, plus via-SIEM ingestion (palo_alto_networks_siem) when logs are routed through Splunk, Sumo Logic, or LogTrust.
Data ingested
Firewall traffic logs, threat prevention alerts, URL filtering
Frequently asked questions
Expel ingests Palo Alto NGFW data through your existing SIEM, or via direct API rather than a standalone native connector. That SIEM-mediated path is standard practice most MDR providers use for firewall log ingestion. Once flowing, logs feed Expel’s detections inside Workbench, Expel’s analyst operations platform.
Expel improves Palo Alto NGFW threat detection by applying custom detections mapped to the MITRE ATT&CK framework against firewall logs. Expel has used this data to detect cryptomining activity, including CoinMiner malware command-and-control traffic. Analysts review confirmed findings in Workbench instead of leaving raw alerts unreviewed.
Native NGFW alerting surfaces firewall events without correlating them to broader attack patterns. Expel ingests those logs through your SIEM, whether Splunk Enterprise Security or Sumo Logic, then applies detections mapped to MITRE ATT&CK, previously catching cryptomining command-and-control traffic this way. Analysts review confirmed findings in Workbench, not raw log noise.
Expel’s Palo Alto NGFW coverage includes support for two SIEM paths, Splunk Enterprise Security and Sumo Logic, plus detections mapped to the MITRE ATT&CK framework. Expel has used NGFW log data to detect cryptomining command-and-control traffic.
Requesting a demo of Expel’s Palo Alto NGFW coverage happens through a form on expel.com/request-demo. The walkthrough shows how NGFW logs flow in through your SIEM, whether Splunk Enterprise Security, or Sumo Logic, and how detections mapped to the MITRE ATT&CK framework are applied to that data.
