↳ GitHub sourceConnector

Azure CloudNGFW By Palo Alto Networks

Description

Cloud Next-Generation Firewall by Palo Alto Networks - an Azure Native ISV Service - is Palo Alto Networks Next-Generation Firewall (NGFW) delivered as a cloud-native service on Azure. You can discover Cloud NGFW in the Azure Marketplace and consume it in your Azure Virtual Networks (VNet). With Cloud NGFW, you can access the core NGFW capabilities such as App-ID, URL filtering based technologies. It provides threat prevention and detection through cloud-delivered security services and threat prevention signatures. The connector allows you to easily connect your Cloud NGFW logs with Microsoft Sentinel, to view dashboards, create custom alerts, and improve investigation. This gives you more insight into your organization's network and improves your security operation capabilities. For more information, see the [Cloud NGFW for Azure documentation](https://docs.paloaltonetworks.com/cloud-ngfw/azure).
Declared status
1
Declared author / publisher
Palo Alto Networks

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

read and write permissions are required.
Workspace
Workspace
read permissions to shared keys for the workspace are required. [See the documentation to learn more about workspace keys](https://docs.microsoft.com/azure/azure-monitor/platform/agent-windows#obtain-workspace-id-and-key).
Keys
Workspace

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Connect Cloud NGFW by Palo Alto Networks to Microsoft Sentinel
Enable Log Settings on All Cloud NGFWs by Palo Alto Networks.
Inside your Cloud NGFW resource: 1. Navigate to the **Log Settings** from the homepage. 2. Ensure the **Enable Log Settings** checkbox is checked. 3. From the **Log Settings** drop-down, choose the desired Log Analytics Workspace. 4. Confirm your selections and configurations. 5. Click **Save** to apply the settings.

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
AzureCloudNGFWByPaloAltoNetworks
Additional source files 1Solutions/Azure Cloud NGFW by Palo Alto Networks/Data Connectors/CloudNgfwByPAN.jsonsource ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.