sending NGFW logs to XSIAM without broker-vm

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

sending NGFW logs to XSIAM without broker-vm

L4 Transporter

Hi,

I have a xsiam tenant running and a palo vm-100 (11.2.x) in our lab (xsiam / ngfw exists in the same csp account)

trying to find docs on this process.. the xsiam admin guide is pretty vague, it says yes and explains the steps on the xsiam side mostly. however not much on the ngfw side on how to configure the syslog profile / log forwarder.

my data source in xsiam is added and shows as connected to my lab FW.. so i am guessing i need to configure the FW to send logs to the xsiam tenant but not sure how to configure this to point it to the xsiam tenant. i am testing this with the broker-vm option as that will be a last resort.

i dont have an xsiam / cortex license on the ngfw.

 

any ideas? thanks

 

6 REPLIES 6

L4 Transporter

for those interest on this.. you have to have strata log server licensed on FW and select the cloud logging service in the log option..that way logs will be sent directly to the xsiam via cdl/sls (strata log service)

Hi PA_nts,

 

Just for clarification, Strata Logging Service is not required, nor is it utilized (unless you are still using the legacy connector) for sending firewall logs to Cortex XSIAM.  Please ensure that you follow the documentation for onboarding firewalls, which will ensure that the firewall receives proper licensing (if the firewalls do not have an SLS license) and are able to send logs.

ok thanks. in that case i might be mistaken but its the only way i got it to work.. did go through the doc process but found it did not cover enough on the pan-os side for me.. unless it has changed since then.

L0 Member

Hi @afurze 

We are stuck in the same issue, we cannot forward the palo alto FW or Panorama logs to XSIAM. Data source interface is created successfully on XSIAM to connect to Panorama, but no logs are forwarded from Panorama to XSIAM. Support is saying we need to buy SLS license. So, we got into the same outcome as written by @PA_nts .

On the other side when we try to onboard single FW to XSIAM, we are getting error "Customer is not provisioned in CSP" which is pointing out to "Cortex Data Lake license is not activated into the hub"

Could you please your experience when onboarding Panorama to XSIAM?

Thanks,

L4 Transporter

Just on this.. if you don't have a CDL license.. you can also use a broker-vm with a syslog applet enabled, and configure the panorama to send logs to this broker-VM IP. this should work also for FWs outside of the CSP where the xsiam tenant is registered in.

also.. the error around customer not being in the same CSP.. from memory, if you want to send PAB FW logs direct to xsiam, they have to be registered in the same CSP client ID/tenant as what the XSIAM tenant is registered in. 

Many thanks for the quick reply @PA_nts 

Sending logs though the broker is clear, we would like to use the data source option for direct ingestion. 

I can confirm that we do have the same ID between CSP and XSIAM.

The problem can be either licensing or some bug (which is less relevant)

 

In CSP we could see CDL license activated and valid, but we cannot access any CDL related application into the hub.

All this naming with SLS, CDL, Cloud Logging ... it's very confusing in terms of licensing queries.

 

Anyway, I would like to ask you whether you got/seen a successful on-boarding of NGFW or Panorama into XSIAM via data source? If yes, maybe you share the license names you have had to do that ?

Thank you,

  • 1121 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!