Configure Palo Alto Prisma Access to forward syslog to Radiant Security.
Overview
Palo Alto Networks Prisma Access is a cloud-delivered security platform designed to provide secure access to applications and data for remote and mobile users. This guide will walk you through the steps needed to configure Prisma Access to forward logs to Radiant Security via syslog TLS.
To complete this configuration, you’ll need to complete the following steps:
Prerequisites
- Access to the Palo Alto Networks Hub
- You must have at least one of the following licenses to use Strata Cloud Manager: Prisma Access, AIOps for NGFW Premium, Prisma SD-WAN
Add the data connector in Radiant Security
Configure log forwarding in Prisma Access Console
- Access the Palo Alto Networks Hub.
- Select the Strata Logging Service that you want to configure for syslog forwarding. If you are using Strata Cloud Manager to manage Strata Logging Service, navigate to Settings > Strata Logging Service > Log Forwarding
- Select the Syslog tab and click + to add a new syslog forwarding profile.
- Fill the fields with the following values:
- Name:
Radiant Security Syslog Connector
- Syslog Server:
primary-k8s.syslog.radiantsecurity.ai
- Port: 6514
- Facility: LOG_LOCAL0
- Under Server Authentication, click Upload and upload the CA certificate that you created in the Add the data connector in Radiant Security section.
- Name:
- Click Test Connection. If the test fails, refer to the last section of this guide for instructions on how to contact your Customer Success Manager.
- Click Next.
- Fill the fields with the following values:
- Format: CEF
- Delimiter: Space
- Profile Token: Enter the Token that you generated in the Add the data connector in Radiant Security section
- Filters: Click Add and select the following log types:
- Traffic
- Threat
- URL
- Data
- Authentication
- DNS Security
- File
- GlobalProtect
- IPTag
- URL
- UserID
- Remote Browser Isolation
- Click Save to save the changes.
We value your opinion. Did you find this article helpful? Share your thoughts by clicking here or reach to our Product and Customer Success teams at support@radiantsecurity.ai
Last updated: 2024-12-02