<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Clarification on Strata Logging Service and eDLP Log Forwarding in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-strata-logging-service-and-edlp-log-forwarding/m-p/1265432#M127098</link>
    <description>&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Hi Team,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;We are an MSSP and have received a request to support eDLP. Since we do not have access to these devices/services in our environment, we primarily rely on the available documentation to understand and support them.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;I have a few questions regarding how Strata Logging Service (SLS) works.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;We currently support Prisma Access using SLS. While reviewing the documentation, I noticed that eDLP logs can also be forwarded through SLS. This raised a few questions:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL start="1" data-spread="true"&gt;
&lt;LI&gt;
&lt;P class="isSelectedEnd"&gt;&lt;STRONG&gt;&lt;SPAN&gt;SLS configuration and log differentiation&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;When configuring SLS, is there any difference in the configuration for Prisma Access versus eDLP?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;If SLS can receive and forward logs from Prisma or other services, how can we differentiate the logs at the SLS level when forwarding them? I found some filtering option but not sure how it works. Similarly, when the logs reach the third-party SIEM, is there a specific field, source, channel, or other identifier that can be used to distinguish Prisma Access logs from eDLP logs?&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN&gt;Direct log forwarding to a third-party SIEM&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;Is there any option to forward eDLP logs directly to a third-party SIEM from the cloud, for example, using an HTTP webhook(HTTP POST), without using SLS? Or is SLS mandatory for forwarding eDLP logs to a third-party SIEM?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;It would be greatly appreciated if you could provide some clarity on the overall SLS architecture and workflow—specifically, how Prisma stores and forwards logs through SLS, and how eDLP and other services send their logs through SLS.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;This will help us better understand the architecture and determine how we should support eDLP log ingestion into our SIEM.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;LI-PRODUCT title="Strata Cloud Manager" id="Strata_Cloud_Manager"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Strata Logging Service" id="Strata_Logging_Service"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Prisma Access" id="Prisma_Access"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Enterprise Data Loss Prevention" id="Enterprise_DLP"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 01 Oct 2026 14:33:37 GMT</pubDate>
    <dc:creator>sushant1601</dc:creator>
    <dc:date>2026-10-01T14:33:37Z</dc:date>
    <item>
      <title>Clarification on Strata Logging Service and eDLP Log Forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-strata-logging-service-and-edlp-log-forwarding/m-p/1265432#M127098</link>
      <description>&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Hi Team,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;We are an MSSP and have received a request to support eDLP. Since we do not have access to these devices/services in our environment, we primarily rely on the available documentation to understand and support them.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;I have a few questions regarding how Strata Logging Service (SLS) works.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;We currently support Prisma Access using SLS. While reviewing the documentation, I noticed that eDLP logs can also be forwarded through SLS. This raised a few questions:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL start="1" data-spread="true"&gt;
&lt;LI&gt;
&lt;P class="isSelectedEnd"&gt;&lt;STRONG&gt;&lt;SPAN&gt;SLS configuration and log differentiation&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;When configuring SLS, is there any difference in the configuration for Prisma Access versus eDLP?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;If SLS can receive and forward logs from Prisma or other services, how can we differentiate the logs at the SLS level when forwarding them? I found some filtering option but not sure how it works. Similarly, when the logs reach the third-party SIEM, is there a specific field, source, channel, or other identifier that can be used to distinguish Prisma Access logs from eDLP logs?&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN&gt;Direct log forwarding to a third-party SIEM&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;Is there any option to forward eDLP logs directly to a third-party SIEM from the cloud, for example, using an HTTP webhook(HTTP POST), without using SLS? Or is SLS mandatory for forwarding eDLP logs to a third-party SIEM?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;It would be greatly appreciated if you could provide some clarity on the overall SLS architecture and workflow—specifically, how Prisma stores and forwards logs through SLS, and how eDLP and other services send their logs through SLS.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;This will help us better understand the architecture and determine how we should support eDLP log ingestion into our SIEM.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;LI-PRODUCT title="Strata Cloud Manager" id="Strata_Cloud_Manager"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Strata Logging Service" id="Strata_Logging_Service"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Prisma Access" id="Prisma_Access"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Enterprise Data Loss Prevention" id="Enterprise_DLP"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2026 14:33:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-strata-logging-service-and-edlp-log-forwarding/m-p/1265432#M127098</guid>
      <dc:creator>sushant1601</dc:creator>
      <dc:date>2026-10-01T14:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on Strata Logging Service and eDLP Log Forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-strata-logging-service-and-edlp-log-forwarding/m-p/1265666#M127119</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/293860"&gt;@sushant1601&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;There are two slightly different logging paths here.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Prisma Access / NGFW logs&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, Strata Logging Service is the central logging layer. You can forward specific log types such as Traffic, Threat, Data Filtering, GlobalProtect, etc, and apply filters before sending them to your SIEM.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Enterprise DLP incident and audit logs&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, SLS is not required. Enterprise DLP has its own log forwarding configuration and can send those logs directly to a third-party SIEM using syslog.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2026 04:55:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-strata-logging-service-and-edlp-log-forwarding/m-p/1265666#M127119</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2026-10-06T04:55:53Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on Strata Logging Service and eDLP Log Forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-strata-logging-service-and-edlp-log-forwarding/m-p/1265838#M127126</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/312350"&gt;@jay&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your response.&amp;nbsp;&lt;/P&gt;
&lt;P data-pm-slice="1 1 []"&gt;&lt;SPAN&gt;Could you please share the steps or documentation for forwarding eDLP logs directly to the SIEM without using SLS? The documentation I found describes forwarding logs via SLS.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-pm-slice="1 1 []"&gt;&lt;SPAN&gt;Thank you again for your help. Really&amp;nbsp;Appreciate it.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-pm-slice="1 1 []"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-pm-slice="1 1 []"&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-pm-slice="1 1 []"&gt;&lt;SPAN&gt;Sushant&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2026 12:44:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-strata-logging-service-and-edlp-log-forwarding/m-p/1265838#M127126</guid>
      <dc:creator>sushant1601</dc:creator>
      <dc:date>2026-10-08T12:44:04Z</dc:date>
    </item>
  </channel>
</rss>

