Read-only, event-driven diagnostic collector for PAN-OS Packet Buffer Protection incidents. It listens to Palo Alto Networks firewall syslog, runs bounded read-only operational XML API captures while the buffers are under pressure, and produces JSONL, HTML and text evidence for a TAC case. Self-hosted Docker Compose stack.
python docker docker-compose firewall incident-response syslog self-hosted network-monitoring panorama troubleshooting observability xml-api syslog-server network-security dos-protection palo-alto-networks pbp pan-os packet-buffer packet-buffer-protection
-
Updated
Sep 8, 2026 - Python