<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: sending NGFW logs to XSIAM without broker-vm in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/sending-ngfw-logs-to-xsiam-without-broker-vm/m-p/1238778#M256</link>
    <description>&lt;P&gt;Just on this.. if you don't have a CDL license.. you can also use a broker-vm with a syslog applet enabled, and configure the panorama to send logs to this broker-VM IP. this should work also for FWs outside of the CSP where the xsiam tenant is registered in.&lt;/P&gt;
&lt;P&gt;also.. the error around customer not being in the same CSP.. from memory, if you want to send PAB FW logs direct to xsiam, they have to be registered in the same CSP client ID/tenant as what the XSIAM tenant is registered in.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Sep 2025 10:39:37 GMT</pubDate>
    <dc:creator>PA_nts</dc:creator>
    <dc:date>2025-09-25T10:39:37Z</dc:date>
    <item>
      <title>sending NGFW logs to XSIAM without broker-vm</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/sending-ngfw-logs-to-xsiam-without-broker-vm/m-p/1085424#M135</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have a xsiam tenant running and a palo vm-100 (11.2.x) in our lab (xsiam / ngfw exists in the same csp account)&lt;/P&gt;
&lt;P&gt;trying to find docs on this process.. the xsiam admin guide is pretty vague, it says yes and explains the steps on the xsiam side mostly. however not much on the ngfw side on how to configure the syslog profile / log forwarder.&lt;/P&gt;
&lt;P&gt;my data source in xsiam is added and shows as connected to my lab FW.. so i am guessing i need to configure the FW to send logs to the xsiam tenant but not sure how to configure this to point it to the xsiam tenant. i am testing this with the broker-vm option as that will be a last resort.&lt;/P&gt;
&lt;P&gt;i dont have an xsiam / cortex license on the ngfw.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any ideas? thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 08:03:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/sending-ngfw-logs-to-xsiam-without-broker-vm/m-p/1085424#M135</guid>
      <dc:creator>PA_nts</dc:creator>
      <dc:date>2025-01-15T08:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: sending NGFW logs to XSIAM without broker-vm</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/sending-ngfw-logs-to-xsiam-without-broker-vm/m-p/1225567#M168</link>
      <description>&lt;P&gt;for those interest on this.. you have to have strata log server licensed on FW and select the cloud logging service in the log option..that way logs will be sent directly to the xsiam via cdl/sls (strata log service)&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 10:19:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/sending-ngfw-logs-to-xsiam-without-broker-vm/m-p/1225567#M168</guid>
      <dc:creator>PA_nts</dc:creator>
      <dc:date>2025-04-03T10:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: sending NGFW logs to XSIAM without broker-vm</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/sending-ngfw-logs-to-xsiam-without-broker-vm/m-p/1225594#M172</link>
      <description>&lt;P&gt;Hi PA_nts,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just for clarification, Strata Logging Service is not required, nor is it utilized (unless you are still using the legacy connector) for sending firewall logs to Cortex XSIAM.&amp;nbsp; Please ensure that you follow the &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Enterprise-Documentation/Ingest-data-from-Next-Generation-Firewall" target="_self"&gt;documentation&lt;/A&gt; for onboarding firewalls, which will ensure that the firewall receives proper licensing (if the firewalls do not have an SLS license) and are able to send logs.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 14:30:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/sending-ngfw-logs-to-xsiam-without-broker-vm/m-p/1225594#M172</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2025-04-03T14:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: sending NGFW logs to XSIAM without broker-vm</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/sending-ngfw-logs-to-xsiam-without-broker-vm/m-p/1225597#M173</link>
      <description>&lt;P&gt;ok thanks. in that case i might be mistaken but its the only way i got it to work.. did go through the doc process but found it did not cover enough on the pan-os side for me.. unless it has changed since then.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 15:00:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/sending-ngfw-logs-to-xsiam-without-broker-vm/m-p/1225597#M173</guid>
      <dc:creator>PA_nts</dc:creator>
      <dc:date>2025-04-03T15:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: sending NGFW logs to XSIAM without broker-vm</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/sending-ngfw-logs-to-xsiam-without-broker-vm/m-p/1238775#M254</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/219403"&gt;@afurze&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are stuck in the same issue, we cannot forward the palo alto FW or Panorama logs to XSIAM. Data source interface is created successfully on XSIAM to connect to Panorama, but no logs are forwarded from Panorama to XSIAM. Support is saying we need to buy SLS license. So, we got into the same outcome as written by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/306035"&gt;@PA_nts&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;
&lt;P&gt;On the other side when we try to onboard single FW to XSIAM, we are getting error "Customer is not provisioned in CSP" which is pointing out to "Cortex Data Lake license is not activated into the hub"&lt;/P&gt;
&lt;P&gt;Could you please your experience when onboarding Panorama to XSIAM?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 09:48:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/sending-ngfw-logs-to-xsiam-without-broker-vm/m-p/1238775#M254</guid>
      <dc:creator>M.Mickoski</dc:creator>
      <dc:date>2025-09-25T09:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: sending NGFW logs to XSIAM without broker-vm</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/sending-ngfw-logs-to-xsiam-without-broker-vm/m-p/1238778#M256</link>
      <description>&lt;P&gt;Just on this.. if you don't have a CDL license.. you can also use a broker-vm with a syslog applet enabled, and configure the panorama to send logs to this broker-VM IP. this should work also for FWs outside of the CSP where the xsiam tenant is registered in.&lt;/P&gt;
&lt;P&gt;also.. the error around customer not being in the same CSP.. from memory, if you want to send PAB FW logs direct to xsiam, they have to be registered in the same CSP client ID/tenant as what the XSIAM tenant is registered in.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 10:39:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/sending-ngfw-logs-to-xsiam-without-broker-vm/m-p/1238778#M256</guid>
      <dc:creator>PA_nts</dc:creator>
      <dc:date>2025-09-25T10:39:37Z</dc:date>
    </item>
    <item>
      <title>Re: sending NGFW logs to XSIAM without broker-vm</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/sending-ngfw-logs-to-xsiam-without-broker-vm/m-p/1238779#M257</link>
      <description>&lt;P&gt;Many thanks for the quick reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/306035"&gt;@PA_nts&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sending logs though the broker is clear, we would like to use the data source option for direct ingestion.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can confirm that we do have the same ID between CSP and XSIAM.&lt;/P&gt;
&lt;P&gt;The problem can be either licensing or some bug (which is less relevant)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In CSP we could see CDL license activated and valid, but we cannot access any CDL related application into the hub.&lt;/P&gt;
&lt;P&gt;All this naming with SLS, CDL, Cloud Logging ... it's very confusing in terms of licensing queries.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyway, I would like to ask you whether you got/seen a successful on-boarding of NGFW or Panorama into XSIAM via data source? If yes, maybe you share the license names you have had to do that ?&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 11:19:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/sending-ngfw-logs-to-xsiam-without-broker-vm/m-p/1238779#M257</guid>
      <dc:creator>M.Mickoski</dc:creator>
      <dc:date>2025-09-25T11:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: sending NGFW logs to XSIAM without broker-vm</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/sending-ngfw-logs-to-xsiam-without-broker-vm/m-p/1239938#M259</link>
      <description>&lt;P&gt;To send logs from Palo Alto Firewall directly to Cortex XSIAM you need to have Strata Logging Service license. After that you need to enable Cloud Logging and then create a Log Forwarding profiles for theblog types that you want to send to Cortex XSIAM (traffic, threat, URL, etc) and select/tick mark cloud logging option to start forwarding the logs to Cortex XSIAM from your Palo Alto firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope you understood the process of sending logs from Palo Alto Firewall to Cortex XSIAM. Please feel free to reachout again in case you have any queries.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2025 22:36:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/sending-ngfw-logs-to-xsiam-without-broker-vm/m-p/1239938#M259</guid>
      <dc:creator>PJagtap1</dc:creator>
      <dc:date>2025-10-13T22:36:19Z</dc:date>
    </item>
    <item>
      <title>Re: sending NGFW logs to XSIAM without broker-vm</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/sending-ngfw-logs-to-xsiam-without-broker-vm/m-p/1240061#M262</link>
      <description>&lt;P&gt;Also.. on your Panorama or ngfw, in the cli, run the following commands to see if the SLS (strata logging Service/cdl) license is active.&lt;/P&gt;
&lt;P&gt;'request license info'&lt;/P&gt;
&lt;P&gt;'request logging-service-forwarding status'&lt;/P&gt;
&lt;P&gt;you can also check the logging status under 'device&amp;gt;setup&amp;gt;logging and reporting settings' and click on the 'show status' next to the 'log collector status' option&lt;/P&gt;
&lt;P&gt;if yes then it should work.. if no, then you need to investigate further. i have had instances where i had to download the SLS license key from the CSP and import this into the FW directly for it to work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 14:29:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/sending-ngfw-logs-to-xsiam-without-broker-vm/m-p/1240061#M262</guid>
      <dc:creator>PA_nts</dc:creator>
      <dc:date>2025-10-15T14:29:14Z</dc:date>
    </item>
  </channel>
</rss>

