5.3 AIOps for NGFW: Telemetry, Proactive Best-Practice Audits, and Operational Insights

Key Takeaways

  • AIOps for NGFW uses machine learning models trained on telemetry from over 60,000 global Palo Alto Networks firewalls to proactively detect misconfigurations, predict operational disruptions, and optimize security posture.
  • AIOps is offered in two tiers: AIOps Free (basic health monitoring, telemetry ingestion, standard Best Practice Assessment audits) and AIOps Premium (real-time anomaly detection, inline policy recommendations, capacity forecasting, and automated ticket integration).
  • Telemetry data collection gathers device health metrics, PAN-OS system logs, App-ID/User-ID adoption statistics, and threat engine counters, streaming data securely via encrypted TLS 1.3 to Cortex Data Lake.
  • The automated Best Practice Assessment (BPA) continuously evaluates firewall security rules against Zero Trust frameworks, generating Security Posture Scores and highlighting overly permissive or shadow rules.
  • Predictive analytics in AIOps anticipate hardware component failures (e.g., power supply, optics), resource exhaustion (CPU, session table, log disk capacity), and license expiration up to 90 days before operational impact occurs.
Last updated: July 2026

5.3 AIOps for NGFW: Telemetry, Proactive Best-Practice Audits, and Operational Insights

Key Concept: AIOps for NGFW integrates artificial intelligence and machine learning directly into Strata Cloud Manager. By ingesting anonymized telemetry data from tens of thousands of global deployments, AIOps transitions enterprise firewall management from reactive firefighting to proactive security posture optimization, predictive health monitoring, and automated policy auditing.

Modern network security environments generate immense operational complexity. Security teams frequently struggle with policy bloat, stale security rules, misconfigured threat prevention profiles, unexpected hardware component failures, and capacity bottlenecks. AIOps for NGFW addresses these operational hurdles by serving as an AI-powered assistant that continuously analyzes firewall configurations, traffic telemetry, and system health metrics to deliver actionable operational insights.


Feature Matrix: AIOps Free vs. AIOps Premium

Palo Alto Networks provides AIOps for NGFW in two operational tiers: AIOps Free (included standard with active support contracts) and AIOps Premium (available as a subscription license).

Capability / FeatureAIOps Free (Standard)AIOps Premium
Core Health MonitoringBasic firewall system health metrics, CPU/memory status, and uptime reporting.Advanced real-time health insights, sub-minute metric streaming, and interactive telemetry dashboards.
Telemetry IngestionStandard periodic telemetry upload to Cortex Data Lake.Continuous, real-time telemetry processing engine with custom retention controls.
Best Practice Assessment (BPA)Periodic/On-demand BPA audits generating static Security Posture Scores.Continuous inline BPA auditing with instant notification of security posture drift.
Policy RecommendationsBasic rule recommendations highlighting unused or shadow rules.ML-powered inline policy recommendations, automated App-ID adoption workflows, and rule optimization.
Anomaly DetectionBasic threshold alerts for system metric spikes.Advanced ML anomaly detection for traffic pattern shifts, session surges, and DDoS indicators.
Capacity ForecastingManual trend visibility for disk and resource usage.Predictive time-series forecasting (predicting CPU, session table, and disk exhaustion up to 90 days out).
Hardware Failure PredictionNot included.Predictive hardware analytics anticipating PSU, fan, and optical transceiver degradation before failure.
ITSM IntegrationNot included.Automated incident ticket generation and remediation workflows via ServiceNow and Jira APIs.

Telemetry Data Collection & Privacy Architecture

AIOps relies on the Device Telemetry service embedded within PAN-OS (version 10.2 and later). Understanding how telemetry is gathered and secured is essential for compliance and security auditing:

+-------------------------------------------------------------------------+
|                   TELEMETRY DATA COLLECTION PIPELINE                   |
+-------------------------------------------------------------------------+
| 1. DATA GATHERING (Local PAN-OS Telemetry Daemon)                       |
|    - System Performance Metrics (Dataplane CPU, RAM, Session Counts)    |
|    - Feature Usage Counters (App-ID, User-ID, Decryption Adoption)      |
|    - Hardware Diagnostics (Fan speeds, Optical Transceiver RX/TX power) |
|    - Threat Engine Summary Counters (WildFire, Anti-Spyware hits)       |
|    * Note: NO PII, Customer Passwords, or Packet Payloads Transmitted * |
+------------------------------------+------------------------------------+
                                     |
                                     v
+------------------------------------+------------------------------------+
| 2. SECURE TRANSMISSION (Encrypted TLS 1.3 Outbound Channel)             |
|    - Transmitted over TCP 443 to regional Cortex Data Lake (CDL)        |
|    - Customer selects data residency region (US, EU, APAC)              |
+------------------------------------+------------------------------------+
                                     |
                                     v
+------------------------------------+------------------------------------+
| 3. ML ANALYTICS & AIOPS ENGINE                                          |
|    - Global baseline comparison against 60,000+ deployments             |
|    - Anomaly detection, BPA scoring, & predictive forecasting           |
+-------------------------------------------------------------------------+
  • Data Privacy Assurance: Device Telemetry collects metadata only. It never extracts sensitive data payload contents, user credentials, private keys, or personally identifiable information (PII).
  • Data Residency Compliance: Telemetry logs stream directly to the organization's dedicated Cortex Data Lake (CDL) instance. Administrators select the geographic location of their CDL instance (e.g., United States, European Union, or Asia-Pacific) to ensure strict adherence to local data sovereignty laws such as GDPR and HIPAA.

Automated Best Practice Assessment (BPA) & Security Posture Scoring

The Best Practice Assessment (BPA) tool in AIOps evaluates firewall configurations against Palo Alto Networks Zero Trust architectural standards and industry compliance frameworks (NIST SP 800-53, CIS Controls).

Security Posture Score (SPS)

AIOps calculates a dynamic Security Posture Score (SPS) (rated on a 0% to 100% scale) across five critical security pillars:

  1. App-ID Adoption Score: Measures the percentage of security rules using specific applications (e.g., web-browsing, ssl, ssh) rather than broad any application definitions or port-based rules.
  2. User-ID Adoption Score: Evaluates how effectively user identity objects are integrated into access policies to enforce role-based access controls.
  3. Security Profiles Adoption Score: Verifies that active Antivirus, Anti-Spyware, Vulnerability Protection, URL Filtering, File Blocking, and WildFire profiles are attached to all inbound and egress security rules.
  4. Decryption Adoption Score: Assesses the percentage of inbound and outbound SSL/TLS traffic subject to active Decryption inspection.
  5. Management Hardening Score: Evaluates device management security, verifying multi-factor authentication (MFA), administrative ACLs, idle timeouts, and SSH/HTTPS hardening settings.

Policy Optimization Engine

AIOps continuously scans rulebases to identify security risks:

  • Shadow Rules: Rules that will never be triggered because a broader rule positioned higher in the rulebase matches all matching criteria.
  • Overly Permissive Rules: Rules utilizing any source/destination or any service ports.
  • Stale / Unused Rules: Rules that have recorded zero traffic hits over a configurable observation window (e.g., 90 days), indicating candidates for decommissioning.

Anomaly Detection & Predictive Capacity Forecasting

AIOps Premium leverages supervised and unsupervised machine learning algorithms to protect network availability and performance.

Machine Learning Anomaly Detection

By continuously tracking baseline operational behavior, AIOps establishes dynamic normal operating bands for each managed firewall. When operational metrics deviate from established baselines, AIOps triggers intelligent alerts:

  • Traffic Anomalies: Sudden surges in session setup rates or unexpected packet drop spikes, indicating potential Distributed Denial of Service (DDoS) attacks or routing loops.
  • Threat Anomalies: Abnormal spikes in WildFire malware detection or DNS security sinkhole hits across specific branch networks.

Predictive Capacity Forecasting

Rather than reacting to outages after a firewall crashes or runs out of resources, AIOps Premium utilizes predictive time-series forecasting models to project resource consumption trends:

  • Session Table Exhaustion: Projects when peak session table utilization will reach 100% capacity based on current organizational growth trends, allowing engineers to upgrade hardware (e.g., migrating from PA-440 to PA-1410) months in advance.
  • Dataplane CPU & Memory Saturation: Identifies firewalls approaching CPU saturation during specific operational hours.
  • Log Disk & Storage Projections: Predicts when local or cloud log storage allocations will fill up, preventing log drop incidents.
Loading diagram...
AIOps Security Posture Scoring (SPS) and Operational Action Framework
Test Your Knowledge

Which capability is provided exclusively in AIOps Premium for NGFW compared to AIOps Free?

A
B
C
D
Test Your Knowledge

What is the primary function of the automated Best Practice Assessment (BPA) engine within AIOps?

A
B
C
D
Test Your Knowledge

How does the PAN-OS Device Telemetry service handle data privacy and security when streaming data to AIOps?

A
B
C
D