Palo Alto Prisma Access (syslog)
Configure Palo Alto Prisma Access to forward syslog to Radiant Security.
In this guide, you'll configure Palo Alto Networks Prisma Access to set up Prisma Access to forward logs securely to Radiant Security using syslog TLS.
Prerequisites
Add the data connector in Radiant Security
Log in to Radiant Security.
From the navigation menu, click Settings > Data Connectors and click + Add Connector.
Search for and select the Palo Alto Prisma Access option and then click Data Feeds.
Under Select your data feeds, select the Palo Alto Prisma Access data feed and then click Credentials.
Under Credential Name, give the credential an identifiable name (e.g.
PAN Credentials
). If you already have a credential in place, select it from the drop-down menu. Click Credentials.In the Connector tag field, enter a random value. This value will act as the salt to randomize the unique Token you’ll download in the next step.
Click Add Connector.
Save the Token value and use the Download Files option to download the SSL certificate file. This token will be used in the upcoming section.
Click Done to save your changes.
Configure log forwarding in Prisma Access Console
Access the Palo Alto Networks Hub.
Select the Strata Logging Service that you want to configure for syslog forwarding. If you are using Strata Cloud Manager to manage Strata Logging Service, navigate to Settings > Strata Logging Service > Log Forwarding.
Select the Syslog tab and click + to add a new syslog forwarding profile.
Fill the fields with the following values:
Name:
Radiant Security Syslog Connector
Syslog Server:
primary-k8s.syslog.radiantsecurity.ai
Port:
6514
Facility:
LOG_LOCAL0
Under Server Authentication, click Upload and upload the CA certificate that you created in the Add the data connector in Radiant Security section.
Click Test Connection. If the test fails, refer to the last section of this guide for instructions on how to contact your Customer Success Manager.
Click Next.
Fill the fields with the following values:
Format: CEF
Delimiter: Space
Profile Token: Enter the Token that you generated in the Add the data connector in Radiant Security section.
Filters: Click Add and select the following log types:
Traffic
Threat
URL
Data
Authentication
DNS Security
File
GlobalProtect
IPTag
URL
UserID
Remote Browser Isolation
Click Save to save the changes.
Last updated