Forward logs from firewalls to Panorama and from Panorama to external services

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Forward logs from firewalls to Panorama and from Panorama to external services

L1 Bithead

Hi, 

 

I planning to forward the Panorama logs to azure sentinel, while I have log collector  configured to log to Panorama. I found a document that specifies that it not possible "A Panorama virtual appliance running Panorama 6.0 or later releases, and M-Series appliances running any release, do not support these options because the log database on those models is too large for an export or import to be practical." Please confirm this. 

 

https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-log-collection/configure-log-fo....

 

The other option could be Log Forwarding to External Services and Panorama in Parallel. In this case do I need to create syslog profile under panorama --> syslog or Device (GLOBAL-COFIG-TEMPLATE) 

 

Finally can I add syslog profile to Log Forwarding Profile Match List, together with Panorama under the same log forwarding Profile, in which my case is Shared

1 REPLY 1

Hi @MP-Firewall ,

I believe you are interpreting the documentation incorrectly. The document explain that you cannot export logs with SCP from Panorama (..you can use Secure Copy (SCP) commands from the CLI to export the entire log database...running Panorama 6.0 or later releases... do not support these options )

What you are looking for is described in the first figure from this document - https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/panorama-overview/centralized-logging-...

 

The link you mentioned provide steps how to configure Syslog forwarding from Panorama to external server.

Since you are planning to use Azure Sentinel, you need to remember that Sentinel expects logs to be in CEF format.You need to set custom log format for each log time that you want to forward to Sentinel. Here are CEF templates - https://docs.paloaltonetworks.com/resources/cef

But be aware that there were some typos as I have explained here - https://live.paloaltonetworks.com/t5/globalprotect-discussions/pan-os-9-1-globalprotect-cef-format/m... It was long ago and I am hoping those were fixed, but if you are missing some log types in Sentinel I would suggest you to verify the custom log format first

  • 1194 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!