<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Logging events from Panorama to SIEM? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/logging-events-from-panorama-to-siem/m-p/27793#M20263</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What methods are available for sending events from a distributed palo alto deployment which have been aggregated in panorama...to a syslog server or SIEM product?&amp;nbsp; I know how to send events directly from a firewall but would hate for all my remote locations to have to send the logs twice, once to panorama and a second time to the SIEM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In panorama it appears as though the logging configurations relate only to system events within the panorama platform as opposed to forwarding of the logs contained within panorama.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the moment I dont have any siem in mind specifically, I am just working with a linux syslog server but am also interested in siem integration for the future.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 27 Sep 2013 15:25:50 GMT</pubDate>
    <dc:creator>tpb_bubbles</dc:creator>
    <dc:date>2013-09-27T15:25:50Z</dc:date>
    <item>
      <title>Logging events from Panorama to SIEM?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logging-events-from-panorama-to-siem/m-p/27793#M20263</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What methods are available for sending events from a distributed palo alto deployment which have been aggregated in panorama...to a syslog server or SIEM product?&amp;nbsp; I know how to send events directly from a firewall but would hate for all my remote locations to have to send the logs twice, once to panorama and a second time to the SIEM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In panorama it appears as though the logging configurations relate only to system events within the panorama platform as opposed to forwarding of the logs contained within panorama.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the moment I dont have any siem in mind specifically, I am just working with a linux syslog server but am also interested in siem integration for the future.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Sep 2013 15:25:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logging-events-from-panorama-to-siem/m-p/27793#M20263</guid>
      <dc:creator>tpb_bubbles</dc:creator>
      <dc:date>2013-09-27T15:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: Logging events from Panorama to SIEM?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logging-events-from-panorama-to-siem/m-p/27794#M20264</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/24852"&gt;tpb_bubbles&lt;/A&gt; Right now this is true, but there was talk of future plans to write this functionality into Panorama. I believe this feature is being worked on. PA doesn't like to make future projections without an NDA (for legal reasons I'm sure) but it's being worked on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/17386#17386"&gt;https://live.paloaltonetworks.com/message/17386#17386&lt;/A&gt; is the thread I'm thinking of.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Sep 2013 17:29:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logging-events-from-panorama-to-siem/m-p/27794#M20264</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-09-27T17:29:27Z</dc:date>
    </item>
    <item>
      <title>Re: Logging events from Panorama to SIEM?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logging-events-from-panorama-to-siem/m-p/27795#M20265</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Today your option is to setup dual-logging at each PA-device. That is it has one feed towards Panorama and one feed towards your syslog/SIEM. This syslog-feed can also be manually setup in case you only care for a few "columns", or for that matter using CEF format if your SIEM supports that format.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tomorrow hopefully Feature Request ID 782 (tell your sales engineer to add your company to this ID) will be taken care of which means that Panorama will be able to not only forward the logs the Panorama itself created but also "relay" any incoming logs from the PA-devices. This way (since Panorama uses some kind of delivery secured method) the PA devices will only have to log once (compared to twice as today) and if the connection with Panorama is lost the logs will not be lost (as with syslog which sends out to devnull) but buffered on the PA device until Panorama returns and then fetches whatever logs were produced while the link between the PA and Panorama was down.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Sep 2013 09:38:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logging-events-from-panorama-to-siem/m-p/27795#M20265</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-09-30T09:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Logging events from Panorama to SIEM?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logging-events-from-panorama-to-siem/m-p/196287#M58485</link>
      <description>&lt;P&gt;Just an update for anybody who stumbles across this post like I did but since PANOS 6 Panorama will both forward Panorama events to a SIEM AND also send all the logs it receives from the various PA systems as well, i.e. act as a log aggregrator and forward.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I don't know, and I bet you can't, is ONLY send the Panorama logs and not the aggregate logs as support said "&lt;SPAN&gt;Panorama will forward whatever logs in the logdb, no matter it generated locally by Panorama itself or the log aggregated from FW, it will forwarded to the external destination." which suggests to me you can't and is a design flaw but oh well, it is what it is.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For configuration see:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/panorama/panorama_adminguide/manage-log-collection/configure-log-forwarding-from-panorama-to-external-destinations" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/panorama/panorama_adminguide/manage-log-collection/configure-log-forwarding-from-panorama-to-external-destinations&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2018 23:13:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logging-events-from-panorama-to-siem/m-p/196287#M58485</guid>
      <dc:creator>PeterT</dc:creator>
      <dc:date>2018-01-22T23:13:14Z</dc:date>
    </item>
  </channel>
</rss>

