PA VM-Series syslog ingest log to Azure log analytic workspace

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

PA VM-Series syslog ingest log to Azure log analytic workspace

Hi all,

 

May i know if anyone had experience setting up VM Series FW to ingest the syslog to Azure log analytic? Is it the only is to setup a new intermediate syslog server install with Azure AMA, the VM series will send syslog to the new syslog server and AMA will ingest the log to log analytic ?

 

Thanks for the help 🙂

 

Thank you,

Meng Kiat

2 REPLIES 2

Hi @Meng_Kiat_DOS-GCC ,

Basically yes. However if you plan it to use Microsoft Sentinel to ingest those logs, you will need to configure PAN firewall to use CEF, otherwise the AMA will ignore the syslog messages from the firewall and will not forward them to the workspace.

 

On the following link you can find reference guide how to setup custom sylog format to CEF - https://docs.paloaltonetworks.com/resources/cef

 

Hi Aleksandar,

 

Thank for the information. Take note and will try out.

 

Thank you !!

  • 528 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!