<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Setting up syslog forwarding from Panorama to Microsoft Cloud app security in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/setting-up-syslog-forwarding-from-panorama-to-microsoft-cloud/m-p/514174#M1098</link>
    <description>&lt;P&gt;Was anyone ever able to figure this out? I'm fighting with the same issue. Thanks!&lt;/P&gt;</description>
    <pubDate>Wed, 07 Sep 2022 17:40:48 GMT</pubDate>
    <dc:creator>rlewandowski</dc:creator>
    <dc:date>2022-09-07T17:40:48Z</dc:date>
    <item>
      <title>Setting up syslog forwarding from Panorama to Microsoft Cloud app security</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/setting-up-syslog-forwarding-from-panorama-to-microsoft-cloud/m-p/215898#M34</link>
      <description>&lt;P&gt;Wondering if anybody has gotten the syslog forwarding working from panorama traffic logs to Microsofts Cloud App security.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have followed every guide I can find and I have logs passing to the MS log collector, however the syslog connection drops regularly, and despite getting some traffic showing in Cloud Discovery on the CAS dashboard it's approx.2% of total network traffic. Not from any specific system or source just a random .2%.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I feel like it's the formatting of the logs being sent or the handeling on the collector but the vendors just blame each other so it's hard to nail down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;anyone with experience getting the two to play nice would be appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 13:18:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/setting-up-syslog-forwarding-from-panorama-to-microsoft-cloud/m-p/215898#M34</guid>
      <dc:creator>paul.gerloff</dc:creator>
      <dc:date>2018-05-30T13:18:03Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up syslog forwarding from Panorama to Microsoft Cloud app security</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/setting-up-syslog-forwarding-from-panorama-to-microsoft-cloud/m-p/433181#M35</link>
      <description>&lt;P&gt;Did you ever get this figured out?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 18:24:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/setting-up-syslog-forwarding-from-panorama-to-microsoft-cloud/m-p/433181#M35</guid>
      <dc:creator>w116tjb</dc:creator>
      <dc:date>2021-09-10T18:24:53Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up syslog forwarding from Panorama to Microsoft Cloud app security</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/setting-up-syslog-forwarding-from-panorama-to-microsoft-cloud/m-p/445800#M517</link>
      <description>&lt;P&gt;We're on v.9.1.8 for Panorama.&lt;/P&gt;
&lt;P&gt;I've configured both ways in the MCAS Log collector settings - "PA Series Firewall" &amp;amp; "PA Series Firewall LEEF".&lt;/P&gt;
&lt;P&gt;We've built the MCAS Log Collector based on the Ubuntu/Docker.&lt;/P&gt;
&lt;P&gt;The Palos are successfully sending to the MCAS-LogCollector server.&lt;BR /&gt;The MCAS-LogCollector is successfully sending "message" files upto MCAS, but it's not successfully parsing the file.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See the sample logs that M$ provides with each of these - that I've attached here.&lt;BR /&gt;These don't match our formats.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Looks like we'll need to build a Custom Format on the Palo side???&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/cloud-app-security/custom-log-parser" target="_blank"&gt;https://docs.microsoft.com/en-us/cloud-app-security/custom-log-parser&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/use-syslog-for-monitoring.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/use-syslog-for-monitoring.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/configure-palo-alto-panorama-for-cloud-app-discovery/m-p/1816949" target="_blank"&gt;https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/configure-palo-alto-panorama-for-cloud-app-discovery/m-p/1816949&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 16:25:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/setting-up-syslog-forwarding-from-panorama-to-microsoft-cloud/m-p/445800#M517</guid>
      <dc:creator>tbarnhart</dc:creator>
      <dc:date>2021-11-05T16:25:24Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up syslog forwarding from Panorama to Microsoft Cloud app security</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/setting-up-syslog-forwarding-from-panorama-to-microsoft-cloud/m-p/475089#M811</link>
      <description>&lt;P&gt;I'm going through this now and having trouble with the MCAS/MDCA Log Collector Container parsing the logs forwarded from Panorama 9.1 as it won't send to cloud.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm working with Microsoft Support however they haven't been able offer any assistance apart from pointing out Panorama is sending it's hostname in Syslog which isn't supported in the 'PA Series Firewall' Data Source format.&amp;nbsp; Unfortunately disabling this setting isn't an option as it's used for an existing SIEM integration.&lt;/P&gt;
&lt;P&gt;The 'PA Series Firewall LEEF' Data Source format sample does show the Syslog sender hostname so i've changed to LEEF however still not working.&lt;/P&gt;
&lt;P&gt;I'll update if I get resolution on this.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 00:55:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/setting-up-syslog-forwarding-from-panorama-to-microsoft-cloud/m-p/475089#M811</guid>
      <dc:creator>benlewis</dc:creator>
      <dc:date>2022-03-23T00:55:04Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up syslog forwarding from Panorama to Microsoft Cloud app security</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/setting-up-syslog-forwarding-from-panorama-to-microsoft-cloud/m-p/514174#M1098</link>
      <description>&lt;P&gt;Was anyone ever able to figure this out? I'm fighting with the same issue. Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 17:40:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/setting-up-syslog-forwarding-from-panorama-to-microsoft-cloud/m-p/514174#M1098</guid>
      <dc:creator>rlewandowski</dc:creator>
      <dc:date>2022-09-07T17:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up syslog forwarding from Panorama to Microsoft Cloud app security</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/setting-up-syslog-forwarding-from-panorama-to-microsoft-cloud/m-p/520322#M1192</link>
      <description>&lt;P&gt;Try to use TLS or TCP as receiver type.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2022 13:56:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/setting-up-syslog-forwarding-from-panorama-to-microsoft-cloud/m-p/520322#M1192</guid>
      <dc:creator>Farakh_Numan</dc:creator>
      <dc:date>2022-11-04T13:56:33Z</dc:date>
    </item>
  </channel>
</rss>

