Threat logs

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Threat logs

L4 Transporter

Can the threats logs be sent to a 3rd party syslog server?

21 REPLIES 21

I thought that was going to be the case but my boss asked me to investigate and I was unable to find a way to do it that is why I posted on this board

I think maybe his boss is worried about storage retention, just guessing, that's why he's trying to not even send certain ones.  The point of the SIEM though is to have all logs and let the correlation engine decide based upon all possible related information to bring to the front the most relevant logs.

No actually I think my boss is trying to find out all the PA can do and use it to its fullest extent

Following what you were asking before:

Sending filters that you establish from the threat logs to your syslog SIEM:

IE..( subtype eq vulnerability ) and ( threatid eq 34804 ) and ( app eq web-browsing ) and ( action eq alert ) and ( severity eq medium ) and ( rule eq 'OBB -  Alw Guest Netwrk to Inet' )

What would be the point of sending this specifically?  Wouldn't it just be easier to use the native functions within the respective tools?  IE...the "clickable" filtering in the Palo UI and the regex parsing within your SIEM?

I don't know just trying to do what my boss asked. So I will just tell him that it has to be done on the seim side

jprovineIf I am understanding your question properly to get more granular you could create a rule that only has a vulnerability profile assigned to it and forward to your SIEM. With a custom vulnerability profile you could get granular too. I may be misinterpreting what you are looking to do and disregard if I am missing your objective.

That is a very interesting thought

  • 6324 Views
  • 21 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!