Glad to see someone else out there using LEM and PALO! We have 5.0.6 deployed on some of our firewalls. As you probably know, Palo Altos are very feature rich devices and are more than just firewalls. LEM imports firewall data just fine. One of the key issues you may find is specifying these additional feature logs to export. We are currently having to specify $category$src$misc$srcuser$contenttype on the Palo to get all the items we would like to see in the LEM raw/nDepth logs. The AV and URL Logs may require some more connector tweaking to get LEM to parse correctly. I have an open case regarding URL tracking. The Palo $misc category contains all the URL data but the LEM Palo Connector only identifies destination IP. It does not currently identify that data in the URL field. See the image below for a typical Palo Web event. I will try to update this post if the URL field is parsed correctly in any new Palo connector.