sending NGFW logs to XSIAM without broker-vm

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

sending NGFW logs to XSIAM without broker-vm

L4 Transporter

Hi,

I have a xsiam tenant running and a palo vm-100 (11.2.x) in our lab (xsiam / ngfw exists in the same csp account)

trying to find docs on this process.. the xsiam admin guide is pretty vague, it says yes and explains the steps on the xsiam side mostly. however not much on the ngfw side on how to configure the syslog profile / log forwarder.

my data source in xsiam is added and shows as connected to my lab FW.. so i am guessing i need to configure the FW to send logs to the xsiam tenant but not sure how to configure this to point it to the xsiam tenant. i am testing this with the broker-vm option as that will be a last resort.

i dont have an xsiam / cortex license on the ngfw.

 

any ideas? thanks

 

3 REPLIES 3

L4 Transporter

for those interest on this.. you have to have strata log server licensed on FW and select the cloud logging service in the log option..that way logs will be sent directly to the xsiam via cdl/sls (strata log service)

Hi PA_nts,

 

Just for clarification, Strata Logging Service is not required, nor is it utilized (unless you are still using the legacy connector) for sending firewall logs to Cortex XSIAM.  Please ensure that you follow the documentation for onboarding firewalls, which will ensure that the firewall receives proper licensing (if the firewalls do not have an SLS license) and are able to send logs.

ok thanks. in that case i might be mistaken but its the only way i got it to work.. did go through the doc process but found it did not cover enough on the pan-os side for me.. unless it has changed since then.

  • 710 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!