prophaze waf Log Ingestion in Cortex XDR Management Console

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

prophaze waf Log Ingestion in Cortex XDR Management Console

L2 Linker

I kindly request how to ingest prophaze waf Logs in the cortex console. If possible, could you guide how to proceed with this integration? Additionally, please share any related documents or resources that could be helpful in this process.
Cortex XDR Cortex Data Lake 

  •  
9 REPLIES 9

L4 Transporter

Hi @RajeshPremSingh, thanks for reaching us using the Live Community.

 

To ingest third party logs in the Cortex XDR tenant you need the Cortex XDR Pro Per-GB license.

If the Prophaze Waf supports sending logs to a syslog server, the procedure is the following:

 

  • Install a Broker VM instance in your environment. 
  • Enable the Syslog applet in the Broker VM. Configure the vendor and product for the upcoming raw logs.
  • Create a custom parsing rule to convert the raw data into readable fields by the XDR console that can be used to stitch logs to alerts. This also requires Pro Per-GB license.

Please let me know if this helps.

 

If this post answers your question, please mark it as the solution.

JM

@jmazzeo  possible to do API?

@RajeshPremSingh, not posible to ingest using API, only for the third party supported vendors.

JM

L2 Linker

Hi Jmazzeo,

I am Sreenadh, team member of Rajesh. could you please help with Create a custom parsing rule to convert the raw data into readable fields by the XDR console.

Hi @PoojalaSreenadh, I'll recommend you to watch this Webinar Series about Parsing rules and correlation.

This is the first one with the Parsing basics and how they work: https://live.paloaltonetworks.com/t5/cortex-xdr-webinars/cortex-customer-success-webinar-series-part...

 

Also we have a full Youtube playlist about custom logs parsing from scratch: https://youtube.com/playlist?list=PLD6FJ8WNiIqXct0oWOxUfr0gDGOQLECGS&feature=shared

 

 

JM

L2 Linker

@jmazzeo ,

 

Thanks for the valuable information, we will go through the following videos and if additional information is required we connect with you. 

L2 Linker

Hi @jmazzeo ,

 

is there any possible way to ingest logs or alerts from prophase WAF through HTTP log collector to receive logs?

Hi @PoojalaSreenadh, yes, you can setup a HTTP collector to ingest logs in Raw, JSON, CEF, or LEEF formats.

Here is the official doc: https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Set-up-an-H...

 

And at the top of that doc you can see all the supported additional log ingestion methods: https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Additional-...

 

JM

Hi@jmazzeo,

 

Thanks for the quick reply. we can go through it and let you know if any queries. 

  • 531 Views
  • 9 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!