If you have access to their forums/discussions, this link may help:
https://live.paloaltonetworks.com/t5/Tech-Note-Articles/PAN-OS-Netflow-Templates-and-Field-Types-PAN-OS-5-0/ta-p/54223
Overview
PAN-OS can generate and export Netflow Version 9 records with unidirectional IP traffic flow information to an outside
collector. Netflow export can be enabled on any ingress interface in the system. Separate template records are defined for
IPv4, IPv4 with NAT, and IPv6 traffic, and PAN-OS specific (enterprise specific) fields for App-ID and User-ID can be
optionally exported. This feature is available on all platforms, except the PA-4000 Series. For more information about
Netflow, refer to the Palo Alto Networks Administrator’s Guide.
To configure Netflow data exports, define a Netflow server profile, which specifies the frequency of the export along with
the Netflow servers that will receive the exported data. When you assign the profile to an existing firewall interface, all
traffic flowing over that interface is exported to the specified servers. All interface types support assignment of a Netflow
profile.
The following tables provide the details of the templates supported including the values, field types, and descriptions for all
the elements in the templates. Templates listed as “Enterprise” include all the field types of the corresponding
“Standard” template, and [Enterprise] additionally include PAN-OS specific fields for App-ID and User-ID.
• IPv4 Traffic Templates
o Template ID 256 – IPv4 Standard
o Template ID 257 – IPv4 Enterprise
• IPv4 with NAT Traffic Templates
o Template ID 260 – IPv4 with NAT Standard
o Template ID 261 – IPv4 with NAT Enterprise
• IPv6 Traffic Templates
o Template ID 258 – IPv6 Standard
o Template ID 259 – IPv6 Enterprise
Add comment