Integration Palo Alto PAN-OS v7.1.X. using Custom Log Format and improve QRadar (LEEF)

Reply
SOC_CSG
L4 Transporter

Integration Palo Alto PAN-OS v7.1.X. using Custom Log Format and improve QRadar (LEEF)

Hello Everyone!

We have the following devices:

  • QRADAR Version 7.2.7
  • Palo Alto Firewalls PAN_OS 7.0.9
  • Panorama PAN-OS 7.0.9

Palo Alto Custom Log Format LEEF

If I use the "Custom Log Format" for setup my Syslog Server Profile, as you have shown us in the link I put below:

http://www.ibm.com/support/knowledgecenter/SS42VS_7.2.7/com.ibm.dsm.doc/t_dsm_guide_palo_alto_syslog...

and in my "Log Forwarding Profile" In addition to enabling my Syslog, I have also enabled a 'panorama' as it shown in the image I put below:

https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Create-a-Profile-to-Forward-Logs-...

 

 lqs6cDV

The "Custom Log Format" I used in my Syslog Server Profile, can affect my panorama or the format of my panorama?

 

Thanks and best regards,

 

Diego C.

 


Accepted Solutions
reaper
L7 Applicator

Hi Diego

 

not fully sure what you want to know, but the 'panorama' flag will forward logs in PANW proprietary format to panorama, and in addition will send a copy in your custom log format to your syslog server

 

the syslog setting does not affect panorama logging

Tom Piens - PANgurus.com
Like my answer? check out my book! amazon.com/dp/1789956374

View solution in original post


All Replies
reaper
L7 Applicator

Hi Diego

 

not fully sure what you want to know, but the 'panorama' flag will forward logs in PANW proprietary format to panorama, and in addition will send a copy in your custom log format to your syslog server

 

the syslog setting does not affect panorama logging

Tom Piens - PANgurus.com
Like my answer? check out my book! amazon.com/dp/1789956374

View solution in original post

SOC_CSG
L4 Transporter

Thanks

I have searched for information about this Because I am interested this topic, but I have not found anything.
But your answer it seems me correct. Thanks again.

 

 

reaper
L7 Applicator

Hi Diego

 

my pleasure!

 

just for the record: all 4 log forwarding profiles (panorama, snmp, email and syslog) have their own log format output and none interfere with each other

Tom Piens - PANgurus.com
Like my answer? check out my book! amazon.com/dp/1789956374
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!