<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log Forwarding to Crowdstrike SIEM in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/log-forwarding-to-crowdstrike-siem/m-p/1222212#M2793</link>
    <description>&lt;P&gt;&lt;SPAN&gt;There are two options either to use existing Log Scale Connector or can build a seperate&amp;nbsp;Log Scale Connector which integrate with CS SIEM.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Both will work&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 28 Feb 2025 00:29:18 GMT</pubDate>
    <dc:creator>Naga_Chaturvedi</dc:creator>
    <dc:date>2025-02-28T00:29:18Z</dc:date>
    <item>
      <title>Log Forwarding to Crowdstrike SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/log-forwarding-to-crowdstrike-siem/m-p/596140#M2453</link>
      <description>&lt;P&gt;Log Forwarding to Crowdstrike SIEM&lt;/P&gt;
&lt;P&gt;Is there anyway to forward logs to&amp;nbsp;Crowdstrike SIEM by using API&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 08:19:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/log-forwarding-to-crowdstrike-siem/m-p/596140#M2453</guid>
      <dc:creator>Naga_Chaturvedi</dc:creator>
      <dc:date>2024-08-28T08:19:22Z</dc:date>
    </item>
    <item>
      <title>Re: Log Forwarding to Crowdstrike SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/log-forwarding-to-crowdstrike-siem/m-p/596515#M2462</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/245004"&gt;@Naga_Chaturvedi&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for posting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on Crowdstrike documentation:&amp;nbsp;&lt;A href="https://falcon.crowdstrike.com/documentation/page/bb227624/paloalto-next-gen-firewall#we80f504" target="_self"&gt;paloalto-next-gen-firewall&lt;/A&gt;&amp;nbsp;the recommended way is to install Log Scale Connector.&amp;nbsp;Log Scale Connector listens for incoming Syslog traffic from Panorama, then Palo Alto Networks Data Connector will send logs to Crowdstrike Next-Gen SIEM.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alternatively, I can think of to set up in Panorama HTTP log forwarding profile:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/monitoring/forward-logs-to-an-https-destination" target="_self"&gt;forward-logs-to-an-https-destination&lt;/A&gt;&amp;nbsp;and HTTP Event Connector on Crowdstrike side:&amp;nbsp;&lt;A href="https://falcon.crowdstrike.com/documentation/page/bdded008/hec-http-event-connector-guide" target="_self"&gt;hec-http-event-connector-guide&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 04:48:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/log-forwarding-to-crowdstrike-siem/m-p/596515#M2462</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-09-02T04:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: Log Forwarding to Crowdstrike SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/log-forwarding-to-crowdstrike-siem/m-p/1222196#M2791</link>
      <description>&lt;P&gt;Quick question, where do you install the Log Scale Connector on a separate server that will collect the logs from PAN?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 17:59:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/log-forwarding-to-crowdstrike-siem/m-p/1222196#M2791</guid>
      <dc:creator>N.Robertson767642</dc:creator>
      <dc:date>2025-02-27T17:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: Log Forwarding to Crowdstrike SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/log-forwarding-to-crowdstrike-siem/m-p/1222212#M2793</link>
      <description>&lt;P&gt;&lt;SPAN&gt;There are two options either to use existing Log Scale Connector or can build a seperate&amp;nbsp;Log Scale Connector which integrate with CS SIEM.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Both will work&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 00:29:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/log-forwarding-to-crowdstrike-siem/m-p/1222212#M2793</guid>
      <dc:creator>Naga_Chaturvedi</dc:creator>
      <dc:date>2025-02-28T00:29:18Z</dc:date>
    </item>
    <item>
      <title>Re: Log Forwarding to Crowdstrike SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/log-forwarding-to-crowdstrike-siem/m-p/1222288#M2795</link>
      <description>&lt;P&gt;I did check within CrowdStrike and we don't have any Log Scale Connector build. That means I have to download Log Scale Connector from CrowdStrike on my Log server and install it then configure it. That logs sever will communicate with palo alto to forward logs to CrowdStrike.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 15:12:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/log-forwarding-to-crowdstrike-siem/m-p/1222288#M2795</guid>
      <dc:creator>N.Robertson767642</dc:creator>
      <dc:date>2025-02-28T15:12:37Z</dc:date>
    </item>
    <item>
      <title>Re: Log Forwarding to Crowdstrike SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/log-forwarding-to-crowdstrike-siem/m-p/1222391#M2797</link>
      <description>&lt;P&gt;Hi Robert,&lt;/P&gt;
&lt;P&gt;In CS Dwwnloads page download "&lt;SPAN&gt;LogScale Collector For Ubuntu - X64, v1.7.3", Install this file in a ubuntu server as per the instructions in the link "&lt;A href="https://falcon.crowdstrike.com/documentation/page/bb227624/paloalto-next-gen-firewall" target="_blank"&gt;Palo Alto Next Gen Firewall | Next-Gen SIEM Third-Party Integrations | Third-Party Integration and Data Connectors | Falcon Next-Gen SIEM | Documentation | Support and resources | Falcon&lt;/A&gt;"&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Naga_Chaturvedi_0-1740992138572.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66277i5ABE30F7E3855F7C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Naga_Chaturvedi_0-1740992138572.png" alt="Naga_Chaturvedi_0-1740992138572.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 08:55:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/log-forwarding-to-crowdstrike-siem/m-p/1222391#M2797</guid>
      <dc:creator>Naga_Chaturvedi</dc:creator>
      <dc:date>2025-03-03T08:55:58Z</dc:date>
    </item>
  </channel>
</rss>

