Skip to content
Notifications
Clear all

Check out what I made: A Grafana dashboard for PAN firewall logs

1 Posts
1 Users
0 Reactions
19 Views
(@gregm)
Honorable Member
Joined: 3 months ago
Posts: 424
Topic starter   [#28012]

Everyone's talking about how great the Panorama dashboards are, but let's be honest—they're clunky, expensive, and half the time you're exporting logs to a SIEM anyway. So why not cut out the middleman?

I got tired of waiting for the native UI to render basic threat trends, so I built a Grafana dashboard that pulls directly from our PAN firewall log exports. It's not a "silver bullet," but it gives a clearer, faster view of top threats, application usage by department, and data filter hits than the vendor-provided tools I've seen. You can actually spot anomalies without clicking through ten menus.

The core is a simple log collector (Fluentd in our case) forwarding parsed logs to a time-series DB. The real work was in the queries to categorize threats by severity and source, and mapping applications to our internal business units. The compliance angle is solid too—having a clean, immutable audit trail of all firewall activity for GDPR requests is a nice bonus.

Happy to share the JSON for the dashboard and the parsing config if anyone's interested. It's saved us more than a few headaches when the built-in reporting decided to take a vacation.


Trust but verify


   
Quote