<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Log/syslog  forwarding to Microsoft Azure/Sentinel in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/log-syslog-forwarding-to-microsoft-azure-sentinel/m-p/485524#M104534</link>
    <description>&lt;P&gt;Entire company uses log analytics and Sentinel for logging.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Found this excellent article&amp;nbsp; below on how to accomplish this task.&lt;/P&gt;&lt;P&gt;&lt;A title="Azure Sentinel: Log Forwarder Configuration" href="https://davicruz.com/en-US/azure-sentinel/2021/03/rsyslog-sentinel-log-forwarder" target="_self"&gt;https://davicruz.com/en-US/azure-sentinel/2021/03/rsyslog-sentinel-log-forwarder&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone done this before?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have stand-alone PA's that are now dumping sylog to Splunk.&lt;/P&gt;&lt;P&gt;Splunk is being replaced with log analytics.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 06 May 2022 22:08:54 GMT</pubDate>
    <dc:creator>dmoore-acc360</dc:creator>
    <dc:date>2022-05-06T22:08:54Z</dc:date>
    <item>
      <title>Log/syslog  forwarding to Microsoft Azure/Sentinel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-syslog-forwarding-to-microsoft-azure-sentinel/m-p/485524#M104534</link>
      <description>&lt;P&gt;Entire company uses log analytics and Sentinel for logging.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Found this excellent article&amp;nbsp; below on how to accomplish this task.&lt;/P&gt;&lt;P&gt;&lt;A title="Azure Sentinel: Log Forwarder Configuration" href="https://davicruz.com/en-US/azure-sentinel/2021/03/rsyslog-sentinel-log-forwarder" target="_self"&gt;https://davicruz.com/en-US/azure-sentinel/2021/03/rsyslog-sentinel-log-forwarder&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone done this before?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have stand-alone PA's that are now dumping sylog to Splunk.&lt;/P&gt;&lt;P&gt;Splunk is being replaced with log analytics.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 22:08:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-syslog-forwarding-to-microsoft-azure-sentinel/m-p/485524#M104534</guid>
      <dc:creator>dmoore-acc360</dc:creator>
      <dc:date>2022-05-06T22:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: Log/syslog  forwarding to Microsoft Azure/Sentinel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-syslog-forwarding-to-microsoft-azure-sentinel/m-p/485946#M104561</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/218383"&gt;@dmoore-acc360&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;I would assume that you have figured out how to setup the collector - Enabling the connector in AZ Sentinel should give you all the steps of installing and preparing the syslog listener.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From firewall prespective you need first to create Syslog profile with customized formatting. Because Sentinel expect CEF, you need to tell the firewall to use CEF for each log type (that you want to forward to Sentinel).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the following link you will find documentation how to define CEF format for each log type based on PanOS version. - &lt;A href="https://docs.paloaltonetworks.com/resources/cef" target="_blank"&gt;https://docs.paloaltonetworks.com/resources/cef&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I have notice some issues with 9.1, which I have described here - &lt;A href="https://live.paloaltonetworks.com/t5/globalprotect-discussions/pan-os-9-1-globalprotect-cef-format/m-p/475444#M2620" target="_blank"&gt;https://live.paloaltonetworks.com/t5/globalprotect-discussions/pan-os-9-1-globalprotect-cef-format/m-p/475444#M2620&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2022 21:43:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-syslog-forwarding-to-microsoft-azure-sentinel/m-p/485946#M104561</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-05-09T21:43:30Z</dc:date>
    </item>
  </channel>
</rss>

