Email Alert on PAN/PAFW for new admin account Creation

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Email Alert on PAN/PAFW for new admin account Creation

L1 Bithead

Hi,

 

I am looking to create email alerts for when ANY user creates a new admin account of anytype on both our Panorama and any of our firewalls managed by panorama.  Our PAFW send/forward their logs to our M600 Panorama device.

 

Any have any link or suggestions?  Purpose being to know if any admin create local or alternate admin accounts, or scenario if an admin account was compromised and that intruder went to create an alternate account.

 

Thanks,

Adam D

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Hi @Adam_DiMarco ,

 

  1. Follow steps 1 and 2 here.  You will need an SMTP Relay IP address.  https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/configure-email-alerts
  2. For step 3, configure the settings below under Device > Log Settings > Configuration.  If you open Filter Builder, you can test the filter with View Filtered Logs.  You can also test the filter under Monitor > Logs > Configuration.

TomYoung_0-1695752036607.png

 

If you are forwarding all of your configuration logs to Panorama, you only have to do it once on Panorama.  It also catches administrators configured in a template.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

Hi @Adam_DiMarco ,

 

  1. Follow steps 1 and 2 here.  You will need an SMTP Relay IP address.  https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/configure-email-alerts
  2. For step 3, configure the settings below under Device > Log Settings > Configuration.  If you open Filter Builder, you can test the filter with View Filtered Logs.  You can also test the filter under Monitor > Logs > Configuration.

TomYoung_0-1695752036607.png

 

If you are forwarding all of your configuration logs to Panorama, you only have to do it once on Panorama.  It also catches administrators configured in a template.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

L1 Bithead

Thanks Tom, just configured that and tested it out and got an email notification.

  • 1 accepted solution
  • 1208 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!