About the Device
Prisma Access helps you deliver consistent security to your remote networks and mobile users. All your users—at headquarters, office branches, and on the road—connect to Prisma Access to safely use the internet and cloud and data center applications.
Device Information
Entity | Particulars |
---|---|
Vendor Name | Palo Alto |
Product Name | Prisma Access |
Type of Device | Cloud |
Collection Method
Log Type | Ingestion label | Preferred Logging Protocol | Log collection method |
---|---|---|---|
Palo Alto Networks Firewall | PAN_FIREWALL | Syslog(CSV) | CyberHub |
Port Requirements
Source | Destination | Port |
---|---|---|
Palo Alto Networks Firewall | CyberHub | 601 (TCP) |
Device Configuration
Pre-requisite:
If log forwarding app instance is not added, please refer https://docs.paloaltonetworks.com/cortex/log-forwarding/log-forwarding-app-getting-started/get-started-with-log-forwarding-app/add-log-forwarding-app-instance.html#id186EE0O0PCW and add forwarding app instance.
Forward Logs from Cortex Data Lake to a Syslog Server
Allow below IP ranges to forward logs to syslog receiver based on your region.
Region | IP Ranges |
---|---|
US | 65.154.226.0/24 |
EU | 154.59.126.0/24 |
UK | 35.246.51.240/28 |
SG(Singapore) | 34.87.142.80/28 |
Login to the hub at https://apps.paloaltonetworks.com/
Select the Log Forwarding app instance that you want to configure for Syslog forwarding
Select Syslog > Add to add a new Syslog Forwarding profile.
Enter a descriptive Name for the profile
Enter the Syslog Server IPv4 address
Enter the Port on which the Syslog server is listening
Select the Facility
Select the logs you want to forward.
Add to select the Log Vendor.
Select the Log Type.
Note: After you select the Log Type you want to forward, the predefined filter shows as selected by default. If you want to forward all logs associated with the log type you’ve selected, leave Predefined selected and continue to save this rule without adding any filters.
Save your changes.
Add other log types that you’d like to forward.
Note: These steps have not been verified, these are taken from documentation.
Integration Parameters
Parameters required from customer for Integration.
Property | Default Value | Description |
---|---|---|
IP Address | Palo Alto Networks Firewall IP address | Hostname or IP address of the device which forwards logs to the CyberHub. |