Doubt about costomize config log paloalto

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Doubt about costomize config log paloalto

L4 Transporter

Hi team

The security auditors ask us if in the Config Log it is possible to have an additional field in the log that links all the events of a rule change with a ticket id external to Palo Alto.

That is to say that in the attached logs an additional field with the Ticket appears in a mandatory way to be able to link the event with the ticket:

any idea?

Regards

3 REPLIES 3

Community Team Member

Hi @Alpalo ,

 

Unfortunately, you won't be able to add custom fields directly. Sounds like something where you would have to pull config logs via python, append those logs with the ticket#, and import those logs to an external ticketing system/database. 

 

Good luck! 

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

Cyber Elite
Cyber Elite

@Alpalo,

Couple possible solutions to this:

  • Move the configuration into source control - This requires changing how people are used to configuring things, but it does give you the ability to ensure that every single change can be linked to a ticket easily. Requires that people learn new things, but ultimately gives you exactly what you're looking for and a process to review changes quite a bit easier.
  • Commit Descriptions - This can solve this issue in a round about aspect as you can tie each commit to the tickets that the change addresses. Still some manual processing but it functions.
  • Change in process - Changes to the firewall are only done with a change ticket in whatever your ticket solution is and the security team looks at those tickets instead of firewall logs. Administrators are not allowed to deviate outside of this process without a ticket detailing what is done.

Thank you for answering, I will try it.

  • 363 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!