Clarification on Strata Logging Service and eDLP Log Forwarding

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Clarification on Strata Logging Service and eDLP Log Forwarding

L2 Linker

Hi Team,

We are an MSSP and have received a request to support eDLP. Since we do not have access to these devices/services in our environment, we primarily rely on the available documentation to understand and support them.

I have a few questions regarding how Strata Logging Service (SLS) works.

 

We currently support Prisma Access using SLS. While reviewing the documentation, I noticed that eDLP logs can also be forwarded through SLS. This raised a few questions:

  1. SLS configuration and log differentiation
    When configuring SLS, is there any difference in the configuration for Prisma Access versus eDLP?

    If SLS can receive and forward logs from Prisma or other services, how can we differentiate the logs at the SLS level when forwarding them? I found some filtering option but not sure how it works. Similarly, when the logs reach the third-party SIEM, is there a specific field, source, channel, or other identifier that can be used to distinguish Prisma Access logs from eDLP logs?

  2. Direct log forwarding to a third-party SIEM
    Is there any option to forward eDLP logs directly to a third-party SIEM from the cloud, for example, using an HTTP webhook(HTTP POST), without using SLS? Or is SLS mandatory for forwarding eDLP logs to a third-party SIEM?

It would be greatly appreciated if you could provide some clarity on the overall SLS architecture and workflow—specifically, how Prisma stores and forwards logs through SLS, and how eDLP and other services send their logs through SLS.

 

This will help us better understand the architecture and determine how we should support eDLP log ingestion into our SIEM.

Thank you.

Strata Cloud Manager Strata Logging Service Prisma Access Enterprise Data Loss Prevention 

1 REPLY 1

Community Team Member

Hi @sushant1601 ,

 

There are two slightly different logging paths here.

 

For Prisma Access / NGFW logs, Strata Logging Service is the central logging layer. You can forward specific log types such as Traffic, Threat, Data Filtering, GlobalProtect, etc, and apply filters before sending them to your SIEM.

 

For Enterprise DLP incident and audit logs, SLS is not required. Enterprise DLP has its own log forwarding configuration and can send those logs directly to a third-party SIEM using syslog.

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 41 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!