View Advanced IP Defense Logs
Focus
Focus
Advanced IP Defense

View Advanced IP Defense Logs

Table of Contents

View Advanced IP Defense Logs

Browse and search Advanced IP Defense threat logs to investigate IP-based threats and validate policy rule effectiveness.
Where Can I Use This?What Do I Need?
  • PAN-OS 12.2 and later
  • Strata Cloud Manager
  • PAN-OS 11.1.x and later (EDL-based)
  • Advanced IP Defense license
  • Log forwarding configured (for Strata Cloud Manager log access)
Advanced IP Defense generates threat logs whenever traffic matches a policy rule. You can browse, search, and filter these logs to investigate specific IP-based threats, identify patterns in attacker behavior, and validate that your policy rules are working as intended. Logs are accessible directly on the firewall and through Strata Cloud Manager when log forwarding to Strata Logging Service is configured.
All Advanced IP Defense threat logs share a single unified threat ID and threat category ID, which are delivered through content package updates. Each log entry contains session details (source and destination IP, zone, port, and protocol), the matched IP attributes and their categories, the policy action taken (Block, Allow, or Alert), the log severity level defined in the policy rule, and the Advanced IP Defense profile name. On PAN-OS 12.2 and later, logs include the full set of matched attributes for the IP, providing granular visibility into why the traffic was flagged. On PAN-OS 11.1.x through 12.1.x, logs record the EDL name and the matched IP address.
The Activity Insights threat view in Strata Cloud Manager includes Advanced IP Defense alongside other cloud-delivered security services, allowing you to correlate IP-based threats with DNS, URL, and file-based detections across the same sessions. The threat insights page handles multiple threat categories for IP attributions, so a single IP that matches attributes from several categories (such as both Malware C2 and Direct-to-IP) displays all relevant categories in the log detail. You can also search for a specific IP through IOC Search to view its associated categories and subcategories on the IP Overview page.
On PAN-OS 11.1.x through 12.1.x, Advanced IP Defense threat activity is logged as traffic log entries when EDL-based security rules match. The EDL name appears in the source EDL or destination EDL columns. These logs don't include IP attribute detail but do provide visibility into blocked threats from the predefined Advanced IP Defense External Dynamic Lists.

View Advanced IP Defense Logs in Strata Cloud Manager

View and filter Advanced IP Defense threat logs in Strata Cloud Manager to investigate IP-based threats and track policy rule matches.
Strata Cloud Manager provides a centralized log viewer for Advanced IP Defense threat logs forwarded through Strata Logging Service. You can filter logs by IP attributes, categories, policy actions, and time range to investigate specific threats and assess the effectiveness of your Advanced IP Defense policy rules.
  1. Use the credentials associated with your Palo Alto Networks support account and log in to the Strata Cloud Manager on the hub.
  2. Access the log viewer.
    Select Incidents and AlertsLog Viewer.
  3. Filter for Advanced IP Defense threat logs.
    In the log viewer, filter the log type to Threat and filter by the Advanced IP Defense threat category. You can further narrow results by:
    • IP attribute category or subcategory (such as Anonymizers & Proxies, Malware C2, Direct-to-IP)
    • Policy action (Block, Allow, or Alert)
    • Source or destination IP address
    • Source or destination zone
    • Time range
  4. Review the log details for a specific entry.
    Click a log entry to view the full session details, including the matched IP attributes, the Advanced IP Defense profile and rule that triggered the log, the policy action taken, and the log severity level. For IPs that match multiple attribute categories, all matched categories are displayed in the log detail.
  5. (Optional) Search for a specific IP address in IOC Search.
    From the log entry, you can pivot to IOC Search to view the full set of categories and subcategories associated with a specific IP address on the IP Overview page. This provides additional threat intelligence context beyond the attributes that matched your policy rules.

View Advanced IP Defense Logs in PAN-OS and Panorama

View and filter Advanced IP Defense threat logs on the firewall or Panorama to investigate IP-based threats and track policy rule matches.
The firewall generates threat logs locally whenever traffic matches an Advanced IP Defense policy rule. On PAN-OS 12.2 and later, these logs include full attribute-level detail. On PAN-OS 11.1.x through 12.1.x, threat activity from Advanced IP Defense EDLs is recorded in traffic logs with the EDL name in the source or destination EDL column.
  1. Access the threat log viewer.
    For PAN-OS 12.2 and later, select MonitorLogsThreat to view threat logs that include Advanced IP Defense entries.
    For PAN-OS 11.1.x through 12.1.x, select MonitorLogsTraffic to view traffic logs that include EDL-based Advanced IP Defense hits.
  2. Filter for Advanced IP Defense log entries.
    On PAN-OS 12.2 and later, filter by the Advanced IP Defense threat category to isolate entries generated by Advanced IP Defense policy rules. You can further narrow results by:
    • IP attribute category or subcategory
    • Policy action (Block, Allow, or Alert)
    • Source or destination IP address
    • Source or destination zone
    On PAN-OS 11.1.x through 12.1.x, filter by the destination EDL or source EDL column to find entries that matched the predefined Advanced IP Defense External Dynamic Lists.
  3. Review the log details for a specific entry.
    Click a log entry to view the full session details. On PAN-OS 12.2 and later, the log detail includes the matched IP attributes, the Advanced IP Defense profile and rule name, the policy action, and the log severity level. On PAN-OS 11.1.x through 12.1.x, the log detail shows the EDL name and the matched IP address.
  4. (Optional) Configure log forwarding to Strata Logging Service.
    To access Advanced IP Defense logs in Strata Cloud Manager and enable dashboard visibility, configure log forwarding to send threat logs to Strata Logging Service. Select ObjectsLog Forwarding and create or edit a log forwarding profile to include threat logs.