<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get/send DNS logs to on-prem SIEM -- DNS Proxy + DNS Security in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-get-send-dns-logs-to-on-prem-siem-dns-proxy-dns-security/m-p/533040#M109836</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/126496"&gt;@jgardner150&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You can setup log forwarding from CDL and setup filtering if required so that it isn't sending&amp;nbsp;&lt;EM&gt;all&amp;nbsp;&lt;/EM&gt;logs unless you need it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-log-forwarding-app/forward-logs-from-logging-service-to-syslog-server" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-log-forwarding-app/forward-logs-from-logging-service-to-syslog-server#id186BM029099&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Mar 2023 22:13:03 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2023-03-02T22:13:03Z</dc:date>
    <item>
      <title>How to get/send DNS logs to on-prem SIEM -- DNS Proxy + DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-get-send-dns-logs-to-on-prem-siem-dns-proxy-dns-security/m-p/532961#M109822</link>
      <description>&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Hello Community!&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Wondering if anyone has this scenario / has experience with retrieving DNS security logs...&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&lt;STRONG class="_12FoOEddL7j_RgMQN0SNeU"&gt;Remote Site Firewall setup:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;- DNS Proxy Enabled (Rules direct internal domains to internal DNS servers across SDWAN, all other DNS request go out local internet to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="_3t5uN8xUmg0TOwRCOGQEcU" href="https://8.8.8.8/" target="_blank" rel="noopener nofollow ugc"&gt;8.8.8.8&lt;/A&gt;)&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;-Firewalls have DNS Security Subscription&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&lt;STRONG class="_12FoOEddL7j_RgMQN0SNeU"&gt;Problem:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;We previously used internal DNS servers for all traffic&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM class="_7s4syPYtk5hfUIjySXcRE"&gt;(due to backhauling internet to the datacenters)&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and forwarded all DNS server logs to our on-prem SIEM. Now with DNS Proxy + External DNS servers we no longer get the detailed DNS logs we used to.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&lt;STRONG class="_12FoOEddL7j_RgMQN0SNeU"&gt;Partial Solution:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;We have &lt;LI-PRODUCT title="DNS Security" id="DNS_Security"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;subscriptions on these remote firewalls, it seems that this logs all DNS queries in Palo's cloud, and I can see them in Autofocus... However, we are stumped on how to get these logs made available to pull down / be sent to our on-prem SIEM so we can use the data for event correlation amongst many other log sources&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;I have been working with our account team to find a solution, but I wanted to float it out here in case anyone has found a solution or has alternate suggestions.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 14:54:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-get-send-dns-logs-to-on-prem-siem-dns-proxy-dns-security/m-p/532961#M109822</guid>
      <dc:creator>jgardner150</dc:creator>
      <dc:date>2023-03-02T14:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to get/send DNS logs to on-prem SIEM -- DNS Proxy + DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-get-send-dns-logs-to-on-prem-siem-dns-proxy-dns-security/m-p/533040#M109836</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/126496"&gt;@jgardner150&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You can setup log forwarding from CDL and setup filtering if required so that it isn't sending&amp;nbsp;&lt;EM&gt;all&amp;nbsp;&lt;/EM&gt;logs unless you need it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-log-forwarding-app/forward-logs-from-logging-service-to-syslog-server" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-log-forwarding-app/forward-logs-from-logging-service-to-syslog-server#id186BM029099&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 22:13:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-get-send-dns-logs-to-on-prem-siem-dns-proxy-dns-security/m-p/533040#M109836</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-03-02T22:13:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to get/send DNS logs to on-prem SIEM -- DNS Proxy + DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-get-send-dns-logs-to-on-prem-siem-dns-proxy-dns-security/m-p/533091#M109839</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;Thanks for the info.&lt;/P&gt;
&lt;P&gt;I did a little research and see they added DNS Security logs as source for CDL about a year back:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-release-notes/cortex-data-lake/new-features" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-release-notes/cortex-data-lake/new-features&lt;/A&gt;&amp;nbsp;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm guessing I'll need to buy a little bit of storage &lt;EM&gt;(I currently don't use CDL)&lt;/EM&gt; to be able to use this option for forwarding the logs I'm looking for. Not ideal, but at least it sounds like it might get the job done.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2023 02:46:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-get-send-dns-logs-to-on-prem-siem-dns-proxy-dns-security/m-p/533091#M109839</guid>
      <dc:creator>jgardner150</dc:creator>
      <dc:date>2023-03-03T02:46:37Z</dc:date>
    </item>
  </channel>
</rss>

