Palo Alto Traffic Log Filters

Use traffic logs to confirm rule matches, application identification, NAT, zones, and deny reasons.

GUI filters

Common filters in Monitor > Traffic:

( addr.src in <source-ip> )
( addr.dst in <destination-ip> )
( port.dst eq 443 )
( rule eq "Allow-Web" )
( action eq allow )
( action eq deny )

Combine filters:

( addr.src in <source-ip> ) and ( addr.dst in <destination-ip> ) and ( port.dst eq 443 )

CLI view

show log traffic direction equal backward query '(addr.src in <source-ip>) and (addr.dst in <destination-ip>)'

What to check

  • Rule name and action.
  • Application detected.
  • Source and destination zones.
  • NAT source and NAT destination.
  • Session end reason.
  • Bytes sent and received.