Integration Palo Alto PAN-OS v7.1.X. using Custom Log Format and improve QRadar (LEEF)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Integration Palo Alto PAN-OS v7.1.X. using Custom Log Format and improve QRadar (LEEF)

L4 Transporter

Hello Everyone!

We have the following devices:

  • QRADAR Version 7.2.7
  • Palo Alto Firewalls PAN_OS 7.0.9
  • Panorama PAN-OS 7.0.9

Palo Alto Custom Log Format LEEF

If I use the "Custom Log Format" for setup my Syslog Server Profile, as you have shown us in the link I put below:

http://www.ibm.com/support/knowledgecenter/SS42VS_7.2.7/com.ibm.dsm.doc/t_dsm_guide_palo_alto_syslog...

and in my "Log Forwarding Profile" In addition to enabling my Syslog, I have also enabled a 'panorama' as it shown in the image I put below:

https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Create-a-Profile-to-Forward-Logs-...

 

 lqs6cDV

The "Custom Log Format" I used in my Syslog Server Profile, can affect my panorama or the format of my panorama?

 

Thanks and best regards,

 

Diego C.

 

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Hi Diego

 

not fully sure what you want to know, but the 'panorama' flag will forward logs in PANW proprietary format to panorama, and in addition will send a copy in your custom log format to your syslog server

 

the syslog setting does not affect panorama logging

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

Hi Diego

 

not fully sure what you want to know, but the 'panorama' flag will forward logs in PANW proprietary format to panorama, and in addition will send a copy in your custom log format to your syslog server

 

the syslog setting does not affect panorama logging

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Thanks

I have searched for information about this Because I am interested this topic, but I have not found anything.
But your answer it seems me correct. Thanks again.

 

 

Hi Diego

 

my pleasure!

 

just for the record: all 4 log forwarding profiles (panorama, snmp, email and syslog) have their own log format output and none interfere with each other

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 1 accepted solution
  • 5474 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!