<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Forward logs from firewalls to Panorama and from Panorama to external services in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/forward-logs-from-firewalls-to-panorama-and-from-panorama-to/m-p/545149#M1569</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I planning to forward the Panorama logs to azure sentinel, while I have log collector&amp;nbsp; configured to log to Panorama. I found a document that specifies that it not possible "&lt;SPAN&gt;A Panorama virtual appliance running Panorama 6.0 or later releases, and M-Series appliances running any release, do not support these options because the log database on those models is too large for an export or import to be practical." Please confirm this.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-log-collection/configure-log-forwarding-from-panorama-to-external-destinations" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-log-collection/configure-log-forwarding-from-panorama-to-external-destinations&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The other option could be&amp;nbsp;&lt;SPAN&gt;Log Forwarding to External Services and Panorama in Parallel. In this case do I need to create syslog profile under panorama --&amp;gt; syslog or Device (GLOBAL-COFIG-TEMPLATE)&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Finally can I add syslog profile&amp;nbsp;to Log Forwarding&amp;nbsp;Profile Match List, together with Panorama under the same log forwarding Profile, in which my case is Shared&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Jun 2023 20:00:56 GMT</pubDate>
    <dc:creator>MP-Firewall</dc:creator>
    <dc:date>2023-06-07T20:00:56Z</dc:date>
    <item>
      <title>Forward logs from firewalls to Panorama and from Panorama to external services</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/forward-logs-from-firewalls-to-panorama-and-from-panorama-to/m-p/545149#M1569</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I planning to forward the Panorama logs to azure sentinel, while I have log collector&amp;nbsp; configured to log to Panorama. I found a document that specifies that it not possible "&lt;SPAN&gt;A Panorama virtual appliance running Panorama 6.0 or later releases, and M-Series appliances running any release, do not support these options because the log database on those models is too large for an export or import to be practical." Please confirm this.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-log-collection/configure-log-forwarding-from-panorama-to-external-destinations" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-log-collection/configure-log-forwarding-from-panorama-to-external-destinations&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The other option could be&amp;nbsp;&lt;SPAN&gt;Log Forwarding to External Services and Panorama in Parallel. In this case do I need to create syslog profile under panorama --&amp;gt; syslog or Device (GLOBAL-COFIG-TEMPLATE)&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Finally can I add syslog profile&amp;nbsp;to Log Forwarding&amp;nbsp;Profile Match List, together with Panorama under the same log forwarding Profile, in which my case is Shared&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 20:00:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/forward-logs-from-firewalls-to-panorama-and-from-panorama-to/m-p/545149#M1569</guid>
      <dc:creator>MP-Firewall</dc:creator>
      <dc:date>2023-06-07T20:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: Forward logs from firewalls to Panorama and from Panorama to external services</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/forward-logs-from-firewalls-to-panorama-and-from-panorama-to/m-p/545458#M1575</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/235045"&gt;@MP-Firewall&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;I believe you are interpreting the documentation incorrectly. The document explain that you cannot export logs with SCP from Panorama (..you can &lt;A class="xref" title="" href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-cli-quick-start/use-the-cli/use-secure-copy-to-import-and-export-files.html" target="_blank" rel="noopener" data-scope="external" data-format="dita" data-type=""&gt;use Secure Copy (SCP) commands from the CLI&lt;/A&gt; to export the entire log database...running Panorama 6.0 or later releases... do not support these options )&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;What you are looking for is described in the first figure from this document - &lt;A href="https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/panorama-overview/centralized-logging-and-reporting/log-forwarding-options" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/panorama-overview/centralized-logging-and-reporting/log-forwarding-options&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The link you mentioned provide steps how to configure Syslog forwarding from Panorama to external server.&lt;/P&gt;
&lt;P&gt;Since you are planning to use Azure Sentinel, you need to remember that Sentinel expects logs to be in CEF format.You need to set custom log format for each log time that you want to forward to Sentinel. Here are CEF templates - &lt;A href="https://docs.paloaltonetworks.com/resources/cef" target="_blank"&gt;https://docs.paloaltonetworks.com/resources/cef&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;But be aware that there were some typos as I have explained here - &lt;A href="https://live.paloaltonetworks.com/t5/globalprotect-discussions/pan-os-9-1-globalprotect-cef-format/m-p/378425" target="_blank"&gt;https://live.paloaltonetworks.com/t5/globalprotect-discussions/pan-os-9-1-globalprotect-cef-format/m-p/378425&lt;/A&gt; It was long ago and I am hoping those were fixed, but if you are missing some log types in Sentinel I would suggest you to verify the custom log format first&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2023 09:47:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/forward-logs-from-firewalls-to-panorama-and-from-panorama-to/m-p/545458#M1575</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-06-09T09:47:30Z</dc:date>
    </item>
  </channel>
</rss>

