All Apps and Add-ons

Palo Alto firewall: FIFO?

jasongb
Path Finder

I am a noob to Enterprise Security.

We recently had a PA event, and the matter of FIFO exceptions for PA devices came up. Someone observed that it would be pretty cool if we could alert on that, and then someone else said, "Sadly, PA firewalls don't let us see that data."

I am neither a network engineer nor an Enterprise Security, but I did poke around online and found a question related to a PA metric (https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLJ7CAO) 'rcv_fifo_overrun'.

Can anyone direct me to a query or data model that contains that field?

Labels (1)
0 Karma
1 Solution

jasongb
Path Finder

Self-answered: that field is not logged by the devices, and would require significant efforts by PA to do so. It's not likely to be made available.

Apparently, the field is available if you query the device via its API. I'm looking into creating a script that will do so, creating a log file in the process. 

The data is highly valuable - although it will primarily be an indication of bursty traffic (no big deal), it can also be an alarm bell for more significant problems.

View solution in original post

0 Karma

jasongb
Path Finder

Self-answered: that field is not logged by the devices, and would require significant efforts by PA to do so. It's not likely to be made available.

Apparently, the field is available if you query the device via its API. I'm looking into creating a script that will do so, creating a log file in the process. 

The data is highly valuable - although it will primarily be an indication of bursty traffic (no big deal), it can also be an alarm bell for more significant problems.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...