- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-01-2026 07:33 AM
Hi Team,
We are an MSSP and have received a request to support eDLP. Since we do not have access to these devices/services in our environment, we primarily rely on the available documentation to understand and support them.
I have a few questions regarding how Strata Logging Service (SLS) works.
We currently support Prisma Access using SLS. While reviewing the documentation, I noticed that eDLP logs can also be forwarded through SLS. This raised a few questions:
SLS configuration and log differentiation
When configuring SLS, is there any difference in the configuration for Prisma Access versus eDLP?
If SLS can receive and forward logs from Prisma or other services, how can we differentiate the logs at the SLS level when forwarding them? I found some filtering option but not sure how it works. Similarly, when the logs reach the third-party SIEM, is there a specific field, source, channel, or other identifier that can be used to distinguish Prisma Access logs from eDLP logs?
It would be greatly appreciated if you could provide some clarity on the overall SLS architecture and workflow—specifically, how Prisma stores and forwards logs through SLS, and how eDLP and other services send their logs through SLS.
This will help us better understand the architecture and determine how we should support eDLP log ingestion into our SIEM.
Thank you.
Strata Cloud Manager Strata Logging Service Prisma Access Enterprise Data Loss Prevention
10-05-2026 09:55 PM
Hi @sushant1601 ,
There are two slightly different logging paths here.
For Prisma Access / NGFW logs, Strata Logging Service is the central logging layer. You can forward specific log types such as Traffic, Threat, Data Filtering, GlobalProtect, etc, and apply filters before sending them to your SIEM.
For Enterprise DLP incident and audit logs, SLS is not required. Enterprise DLP has its own log forwarding configuration and can send those logs directly to a third-party SIEM using syslog.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

