# Can't integrate Graylog with Palo alto

**URL:** <https://community.graylog.org/t/cant-integrate-graylog-with-palo-alto/19861>\
**Category:** Graylog Central (peer support)\
**Created:** [May 15, 2021, 5:18pm UTC](https://community.graylog.org/t/cant-integrate-graylog-with-palo-alto/19861 "2021-05-15T17:18:08Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gobind](https://avatars.discourse-cdn.com/v4/letter/g/a587f6/32.png) [@Gobind](https://community.graylog.org/u/Gobind)\
**Post date:** [May 15, 2021, 5:18pm UTC](https://community.graylog.org/t/cant-integrate-graylog-with-palo-alto/19861/1 "2021-05-15T17:18:08Z")

</div>

Hi everyone.

I’m new to Graylog. I downloaded the OVA file for my vmware esxi and installed it successfully, but somehow when I created a new INPUT\>SYSTEM named Palo alto for syslog server, I didn’t get any logs or messages in the dashboard. No messages received on the Graylog server. Log forwarding profile and rules are already configured on the Palo alto.

System \>Input\>Palo alto 9.0

> Global  
> Port 1415 (input fails to start on port 514)  
> Rest are default.

Please help me with this if I am missing any steps or configurations.

Thanks.  
Gobind.

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [May 18, 2021, 2:44am UTC](https://community.graylog.org/t/cant-integrate-graylog-with-palo-alto/19861/2 "2021-05-18T02:44:12Z")

</div>

Hello and welcome

What version of Graylog are you using?  
How did you configure you Graylog INPUT?  
Did you check you log files for Elasticsearch, Graylog, and MongoDb? If so did you see anything that would pertain to this issue?  
To help troubleshoot your issue we may need some more details about your environment.  
If you’re unsure what you need then this may enlighten you.

[https://community.graylog.org/t/community-guidelines/6649#before-ask](https://community.graylog.org/t/community-guidelines/6649#before-ask)

Hope that helps

---

<div class="post-metadata">

**Author:** ![Gobind](https://avatars.discourse-cdn.com/v4/letter/g/a587f6/32.png) [@Gobind](https://community.graylog.org/u/Gobind)\
**Post date:** [May 18, 2021, 4:48pm UTC](https://community.graylog.org/t/cant-integrate-graylog-with-palo-alto/19861/3 "2021-05-18T16:48:37Z")

</div>

Hi Gsmith  
Thanks for responding.

The running Graylog version is latest one 4.0  
I configured the Graylog input in menu under system tab and selected Palo alto 9.0 as the input.

Elastic search mongodb are installed properly and are up to date. I am not sure on how to check for log files of these. All I saw was there were no messages to the input and the network IO as 0 B.

 ![Capture](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/1/15319385cd8845293d1da0a41a7e0bbf9cb58712.png)

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [May 19, 2021, 1:30am UTC](https://community.graylog.org/t/cant-integrate-graylog-with-palo-alto/19861/4 "2021-05-19T01:30:28Z")

</div>

Hello,  
Do you have a firewall enabled? Check if you can PING your remote device from graylog server.  
By chance did you check the logs on the remote device? If so is there anything pertaining to this issue?

---

<div class="post-metadata">

**Author:** ![aaronsachs](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/aaronsachs/32/7180_2.png) [@aaronsachs](https://community.graylog.org/u/aaronsachs)\
**Post date:** [May 19, 2021, 1:59am UTC](https://community.graylog.org/t/cant-integrate-graylog-with-palo-alto/19861/5 "2021-05-19T01:59:35Z")

</div>

I’ll second @gsmith 's question about a firewall. This sounds like a host based firewall IMO. Check to see if you have iptables rules in place or if firewalld is running. You might also do a tcpdump to see if packers are hitting the server.

---

<div class="post-metadata">

**Author:** ![Gobind](https://avatars.discourse-cdn.com/v4/letter/g/a587f6/32.png) [@Gobind](https://community.graylog.org/u/Gobind)\
**Post date:** [May 19, 2021, 3:25am UTC](https://community.graylog.org/t/cant-integrate-graylog-with-palo-alto/19861/6 "2021-05-19T03:25:33Z")

</div>

Hi @gsmith  
Yes firewall and graylog are reachable to each other. Ping is fine from both end. I have other syslogs configured as well on the remote firewall… other syslog servers obtain logs from the PA firewall but Graylog doesn’t. Configuration and rules are fine on the firewall… I think something is missing on Graylog.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [June 2, 2021, 3:25am UTC](https://community.graylog.org/t/cant-integrate-graylog-with-palo-alto/19861/7 "2021-06-02T03:25:53Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
