This integration is available on our Advanced and Enterprise packages.
Before you get started
Before beginning the integration, you will need to deploy a log collector within the same network as your firewall.
To initiate the collector deployment process, please reach out to our Technical Support team, who'll provide you with a deployment pack that includes all the software and scripts needed to configure this.
If you already have a log collector deployed, please follow the steps outlined below.
Configuring syslog
Log in to the Palo Alto device's web interface.
Navigate to the Syslog settings and go to Device > Server Profiles > Syslog.
Add a New Syslog Server:
Click Add.
Enter a Name for the profile.
Set the Server to the IP address of your collector.
Set the Port to 5514 (not the default 514).
Click Commit to apply the configuration.
Confirming log flow
Once the above steps are complete, your device will now ship logs to our SIEM platform via your collector. You can confirm logs are successfully reaching our SIEM by either.
Navigating to the Log Search feature in Defense.com by browsing to SIEM > Log Search and then filtering the logs by
type:"syslog".Reaching out to our Technical Support team, who'll be able to check and confirm this for you.
And that's it! You've successfully integrated your Palo Alto device π
