Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

Version 1 Current »

About the Device

 Prisma Access helps you deliver consistent security to your remote networks and mobile users. All your users—at headquarters, office branches, and on the road—connect to Prisma Access to safely use the internet and cloud and data center applications.

Device Information

 Entity

Particulars

Vendor Name

 Palo Alto

Product Name

 Prisma Access

Type of Device

 Cloud

Collection Method

Log Type

 Ingestion label

Preferred Logging Protocol

Log collection method

Palo Alto Networks Firewall

 PAN_FIREWALL

Syslog(CSV)

 CyberHub

Port Requirements

Source

Destination

Port

Palo Alto Networks Firewall

CyberHub

601 (TCP)

Device Configuration

Pre-requisite:

If log forwarding app instance is not added, please refer https://docs.paloaltonetworks.com/cortex/log-forwarding/log-forwarding-app-getting-started/get-started-with-log-forwarding-app/add-log-forwarding-app-instance.html#id186EE0O0PCW and add forwarding app instance.

Forward Logs from Cortex Data Lake to a Syslog Server

  1. Allow below IP ranges to forward logs to syslog receiver based on your region.

Region

IP Ranges

US

65.154.226.0/24
34.67.106.64/28

EU

154.59.126.0/24
34.90.138.80/28

UK

35.246.51.240/28

SG(Singapore)

34.87.142.80/28

  1. Login to the hub at https://apps.paloaltonetworks.com/

  2. Select the Log Forwarding app instance that you want to configure for Syslog forwarding

  3. Select Syslog > Add to add a new Syslog Forwarding profile.

image-20240104-130455.png
  1. Enter a descriptive Name for the profile

  2. Enter the Syslog Server IPv4 address

  3. Enter the Port on which the Syslog server is listening 

  4. Select the Facility

  5. Select the logs you want to forward. 

    1. Add to select the Log Vendor.

    2. Select the Log Type.

Note: After you select the Log Type you want to forward, the predefined filter shows as selected by default. If you want to forward all logs associated with the log type you’ve selected, leave Predefined selected and continue to save this rule without adding any filters.

image-20240104-130705.png

  1. Save your changes.

  2. Add other log types that you’d like to forward.

Note: These steps have not been verified, these are taken from documentation. 

Integration Parameters

Parameters required from customer for Integration.

Property

Default Value

Description

IP Address

Palo Alto Networks Firewall IP address

Hostname or IP address of the device which forwards logs to the CyberHub.

  • No labels