Integration Palo Alto PAN-OS v7.1.X. using Custom Log Format and improve QRadar (LEEF)

Reply
Highlighted
L4 Transporter

Integration Palo Alto PAN-OS v7.1.X. using Custom Log Format and improve QRadar (LEEF)

Hello Everyone!

We have the following devices:

  • QRADAR Version 7.2.7
  • Palo Alto Firewalls PAN_OS 7.0.9
  • Panorama PAN-OS 7.0.9

Palo Alto Custom Log Format LEEF

If I use the "Custom Log Format" for setup my Syslog Server Profile, as you have shown us in the link I put below:

http://www.ibm.com/support/knowledgecenter/SS42VS_7.2.7/com.ibm.dsm.doc/t_dsm_guide_palo_alto_syslog...

and in my "Log Forwarding Profile" In addition to enabling my Syslog, I have also enabled a 'panorama' as it shown in the image I put below:

https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Create-a-Profile-to-Forward-Logs-...

 

 lqs6cDV

The "Custom Log Format" I used in my Syslog Server Profile, can affect my panorama or the format of my panorama?

 

Thanks and best regards,

 

Diego C.

 


Accepted Solutions
Highlighted
L7 Applicator

Re: Integration Palo Alto PAN-OS v7.1.X. using Custom Log Format and improve QRadar (LEEF)

Hi Diego

 

not fully sure what you want to know, but the 'panorama' flag will forward logs in PANW proprietary format to panorama, and in addition will send a copy in your custom log format to your syslog server

 

the syslog setting does not affect panorama logging

reaper - PANgurus.com
I drink and I know things

View solution in original post


All Replies
Highlighted
L7 Applicator

Re: Integration Palo Alto PAN-OS v7.1.X. using Custom Log Format and improve QRadar (LEEF)

Hi Diego

 

not fully sure what you want to know, but the 'panorama' flag will forward logs in PANW proprietary format to panorama, and in addition will send a copy in your custom log format to your syslog server

 

the syslog setting does not affect panorama logging

reaper - PANgurus.com
I drink and I know things

View solution in original post

Highlighted
L4 Transporter

Re: Integration Palo Alto PAN-OS v7.1.X. using Custom Log Format and improve QRadar (LEEF)

Thanks

I have searched for information about this Because I am interested this topic, but I have not found anything.
But your answer it seems me correct. Thanks again.

 

 

Highlighted
L7 Applicator

Re: Integration Palo Alto PAN-OS v7.1.X. using Custom Log Format and improve QRadar (LEEF)

Hi Diego

 

my pleasure!

 

just for the record: all 4 log forwarding profiles (panorama, snmp, email and syslog) have their own log format output and none interfere with each other

reaper - PANgurus.com
I drink and I know things
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!