<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA VM-Series syslog ingest log to  Azure log analytic workspace in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/pa-vm-series-syslog-ingest-log-to-azure-log-analytic-workspace/m-p/565589#M2031</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/330369"&gt;@Meng_Kiat_DOS-GCC&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Basically yes. However if you plan it to use Microsoft Sentinel to ingest those logs, you will need to configure PAN firewall to use CEF, otherwise the AMA will ignore the syslog messages from the firewall and will not forward them to the workspace.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the following link you can find reference guide how to setup custom sylog format to CEF - &lt;A href="https://docs.paloaltonetworks.com/resources/cef" target="_blank"&gt;https://docs.paloaltonetworks.com/resources/cef&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 14 Nov 2023 14:26:32 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2023-11-14T14:26:32Z</dc:date>
    <item>
      <title>PA VM-Series syslog ingest log to  Azure log analytic workspace</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/pa-vm-series-syslog-ingest-log-to-azure-log-analytic-workspace/m-p/565462#M2030</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;May i know if anyone had experience setting up VM Series FW to ingest the syslog to Azure log analytic? Is it the only is to setup a new intermediate syslog server install with Azure AMA, the VM series will send syslog to the new syslog server and AMA will ingest the log to log analytic ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;Meng Kiat&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2023 03:36:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/pa-vm-series-syslog-ingest-log-to-azure-log-analytic-workspace/m-p/565462#M2030</guid>
      <dc:creator>Meng_Kiat_DOS-GCC</dc:creator>
      <dc:date>2023-11-14T03:36:27Z</dc:date>
    </item>
    <item>
      <title>Re: PA VM-Series syslog ingest log to  Azure log analytic workspace</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/pa-vm-series-syslog-ingest-log-to-azure-log-analytic-workspace/m-p/565589#M2031</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/330369"&gt;@Meng_Kiat_DOS-GCC&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Basically yes. However if you plan it to use Microsoft Sentinel to ingest those logs, you will need to configure PAN firewall to use CEF, otherwise the AMA will ignore the syslog messages from the firewall and will not forward them to the workspace.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the following link you can find reference guide how to setup custom sylog format to CEF - &lt;A href="https://docs.paloaltonetworks.com/resources/cef" target="_blank"&gt;https://docs.paloaltonetworks.com/resources/cef&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2023 14:26:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/pa-vm-series-syslog-ingest-log-to-azure-log-analytic-workspace/m-p/565589#M2031</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-11-14T14:26:32Z</dc:date>
    </item>
    <item>
      <title>Re: PA VM-Series syslog ingest log to  Azure log analytic workspace</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/pa-vm-series-syslog-ingest-log-to-azure-log-analytic-workspace/m-p/565751#M2034</link>
      <description>&lt;P&gt;Hi Aleksandar,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank for the information. Take note and will try out.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you !!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 06:10:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/pa-vm-series-syslog-ingest-log-to-azure-log-analytic-workspace/m-p/565751#M2034</guid>
      <dc:creator>Meng_Kiat_DOS-GCC</dc:creator>
      <dc:date>2023-11-15T06:10:12Z</dc:date>
    </item>
  </channel>
</rss>

