Skip to main content

Palo Alto

Overview

Palo Alto Firewall, the advanced and sophisticated firewall solutions by Palo Alto Networks, seamlessly integrate with Motadata AIOps to provide comprehensive monitoring and management capabilities. With this integration, organizations gain real-time visibility into the performance and security of their Palo Alto Firewalls. Monitor critical firewall metrics such as traffic patterns, connection status, and threat activity to ensure a secure and protected network environment.

Prerequisites

Refer Adding network devices for monitoring to understand the prerequisites necessary for monitoring a network device.

List of Supported KPIs

MetricsDescriptionType
ping.min.latency.msMinimum latency (in milliseconds) observed during pingCount
ping.received.packetsNumber of packets received during pingCount
ping.lost.packetsNumber of packets lost during pingCount
ping.max.latency.msMaximum latency (in milliseconds) observed during pingCount
object.targetTarget object identifierString
ping.sent.packetsNumber of packets sent during pingCount
ping.packet.lost.percentPercentage of packet loss during pingPercent
ping.latency.msAverage latency (in milliseconds) observed during pingCount
system.oidSystem Object IdentifierString
started.time.secUptime in Seconds for the monitorCount
started.timeUptime of the monitorString
object.nameName of the monitorString
system.locationLocation of the monitorString
system.descriptionDescription of the monitorString
correlation.metricsCorrelation metrics between network connectionsString
network.connection.tcp.connectionsNumber of TCP connectionsCount
network.connection.udp.connectionsNumber of UDP connectionsCount
network.connection.udp.error.segmentsNumber of UDP error segmentsCount
network.connection.tcp.error.segmentsNumber of TCP error segmentsCount
network.connection.tcp.retransmitted.segmentsNumber of TCP retransmitted segmentsCount
destination.ipDestination IP addressString
destination.portDestination port numberCount
network.connection.protocolProtocol used for network connectionCount
network.connection.stateState of the network connectionString
source.ipSource IP addressString
source.portSource port numberCount
interface.sent.discard.packetsNumber of discarded packets sent on the interfaceCount
interface.in.packetsNumber of incoming packets on the interfaceCount
interface.packetsNumber of packets on the interfaceCount
interface.error.packetsNumber of error packets on the interfaceCount
interface.sent.error.packetsNumber of error packets sent on the interfaceCount
interface.received.discard.packetsNumber of discarded packets received on the interfaceCount
interface.received.octetsNumber of octets received on the interfaceCount
interface.bit.typeBit type of the interfaceCount
statusStatus of the interfaceString
interface.out.packetsNumber of outgoing packets on the interfaceCount
interface.operational.statusOperational status of the interfaceString
interface.admin.statusAdmin status of the interfaceCount
interface.sent.octetsNumber of octets sent on the interfaceCount
interface.last.changeLast change of the interfaceString
interface.received.error.packetsNumber of error packets received on the interfaceCount
interface.discard.packetsNumber of discarded packets on the interfaceCount
started.timeUptime of the interfaceString
started.time.secUptime in seconds of the interfaceString
system.os.versionThe version of the operating system running on the SNMP device.String
system.hardware.versionThe version of the hardware of the SNMP device.String
system.serial.noThe serial number of the SNMP device.String
paloalto.vpn.client.versionThe version of the VPN client installed on the SNMP device.String
paloalto.application.versionThe version of the application installed on the SNMP device.String
paloalto.antivirus.versionThe version of the antivirus software installed on the SNMP device.String
paloalto.threat.versionThe version of the threat intelligence data installed on the SNMP device.String
paloalto.url.filtering.versionThe version of the URL filtering database installed on the SNMP device.String
paloalto.global.protect.versionThe version of the GlobalProtect client installed on the SNMP device.String
paloalto.opswat.datafile.versionThe version of the OPSWAT data file installed on the SNMP device.String
paloalto.session.percentThe percentage of sessions currently active on the PaloAlto firewall.Percentage
paloalto.active.sessionsThe number of active sessions on the PaloAlto firewall.Count
paloalto.tcp.active.sessionsThe number of active TCP sessions on the PaloAlto firewall.Count
paloalto.udp.active.sessionsThe number of active UDP sessions on the PaloAlto firewall.Count
paloalto.icmp.active.sessionsThe number of active ICMP sessions on the PaloAlto firewall.Count
paloalto.ssl.proxy.active.sessionsThe number of active SSL proxy sessions on the PaloAlto firewall.Count
paloalto.ssl.proxy.session.percentThe percentage of SSL proxy sessions currently active on the PaloAlto firewall.Percentage
paloalto.maximum.sessionsThe maximum number of sessions that the PaloAlto firewall can handle.Count
paloalto.vsys.active.sessionsThe number of active sessions for a specific virtual system (vsys) on the PaloAlto firewall.Count
paloalto.vsys.maximum.sessionsThe maximum number of sessions supported for a specific virtual system (vsys).Count
paloalto.vsys.session.used.percentThe percentage of sessions used for a specific virtual system (vsys) on the PaloAlto firewall.Percentage
system.cpu.percentThe CPU utilization percentage of the SNMP device.Percentage
system.1min.avg.cpu.percentThe average CPU utilization percentage over the last one minute on the SNMP device.Percentage
system.memory.used.percentThe percentage of used memory on the SNMP device.Percentage
system.disk.volume.typeThe type of disk volume on the SNMP device.String
system.disk.volumeThe name of the disk volume on the SNMP device.String
system.disk.volume.capacity.bytesThe total capacity of the disk volume in bytes on the SNMP device.Count
system.disk.volume.used.bytesThe used space in bytes on the disk volume of the SNMP device.Count
system.disk.volume.used.percentThe percentage of used space on the disk volume of the SNMP device.Percentage
paloalto.ha.stateThe state of high availability (HA) on the PaloAlto firewall.String
paloalto.ha.peer.stateThe state of the HA peer on the PaloAlto firewall.String
paloalto.ha.modeThe mode of high availability (HA) on the PaloAlto firewall.String
tunnel.life.time.secThe lifetime duration of the tunnel in seconds.Count
tunnel.active.time.secThe time duration that the tunnel has been active in seconds.Count
tunnelThe identifier or name of the tunnel.String
tunnel.source.ip.addressThe source IP address of the tunnel.String
tunnel.out.traffic.bytes.rateThe rate of outgoing traffic in bytes per second through the tunnel.Count
tunnel.in.traffic.bytes.rateThe rate of incoming traffic in bytes per second through the tunnel.Count
tunnel.destination.ip.addressThe destination IP address of the tunnel.String
tunnel.nameThe name or label assigned to the tunnel.String
tunnel.statusThe current status of the tunnel.String
remote.vpn.active.connectionsThe number of active VPN connections from remote clients.Count
remote.vpn.client.in.traffic.bytes.rateThe incoming traffic rate in bytes per second for VPN clients.Count
remote.vpn.client.out.traffic.bytes.rateThe outgoing traffic rate in bytes per second for VPN clients.Count
remote.vpn.client.protocolThe communication protocol used by the VPN client.String
remote.vpn.client.encryption.algorithmThe encryption algorithm used by the VPN client.String
remote.vpn.clientThe identifier or name of the remote VPN client.String
remote.vpn.client.duration.secThe duration of the VPN client connection in seconds.Count
remote.vpn.client.app.versionThe version of the VPN client application.String
remote.vpn.client.durationThe duration of the VPN client connection.String
remote.vpn.client.statusThe status of the VPN client connection.String
remote.vpn.user.groupThe user group associated with the remote VPN client.String
remote.vpn.client.appThe application name of the remote VPN client.String