Palo Alto Networks Firewall
Connect Palo Alto Networks Firewall to Radiant Security to forward firewall and threat logs for AI triage.
Palo Alto Networks Firewall is a next-generation firewall that inspects traffic and enforces security policy to block intrusions, malware, and unauthorized access. Connecting the firewall forwards traffic, threat, and system logs to Radiant Security over syslog. Radiant uses the log data to triage firewall and threat alerts in context, giving analysts faster verdicts on whether observed traffic reflects a real compromise or routine network activity.
Palo Alto Networks Firewall can forward logs to Radiant Security in two ways:
Through the Radiant Agent (recommended). Forward to a Radiant Agent deployed in your environment.
Direct to Radiant Security. Forward over TLS to the Radiant syslog cluster. Use only when a Radiant Agent is not available.
Prerequisites
Add the data connector in Radiant Security
Add the connector that matches the path you chose.
Log in to Radiant Security.
From the navigation menu, click Settings > Data Connectors, then click + Add Connector.
Search for and select Radiant Agent, then click Data Feeds.
Under Select your data feeds, select Palo Alto Firewall 9.1, then click Credentials.
Under Credential Name, enter an identifiable name for the Radiant Agent integration (e.g.,
Radiant Agent integration). To reuse an existing Radiant Agent credential, select it from the drop-down menu.Click Add Connector.
Log in to Radiant Security.
From the navigation menu, click Settings > Data Connectors, then click + Add Connector.
Search for and select Palo Alto Networks Firewall, then click Data Feeds.
Under Select your data feeds, select Palo Alto Firewall 9.1, then click Credentials.
Under Credential Name, enter an identifiable name (e.g.,
PAN Credentials). To reuse an existing credential, select it from the drop-down menu.In the Connector tag field, enter a value (optional).
Click Add Connector.
Download the SSL Certificate and Custom Log files. You use both in the sections below.
Click Done to save your changes.
Configure Palo Alto Networks Firewall to forward syslog through the Radiant Agent
Before starting, confirm the IP address of the Radiant Agent and the port configured to receive Palo Alto Networks Firewall data. If you do not know the port, contact your Customer Success representative.
Log in to the Palo Alto Networks firewall.
On the left navigation list, expand Server Profiles and click Syslog.

At the bottom of the right pane, click Add.
Under Syslog Server Profile, in Name, enter
RadiantSecurity. Click Add to add a server, then configure:Name:
RadiantSecurity AgentSyslog Server: the IP address of the Radiant Agent
Transport:
TCPPort: the port configured on the Radiant Agent to receive Palo Alto Networks Firewall data

Click the Custom Log Format tab.

In the Log Type column, click each log type name and paste its matching log format into the Config Log Format text box, then click OK. The log formats are in the Radiant Security PAN custom templates file for download.

Repeat step 6 for all 14 log types, then click OK on the syslog configuration screen.
Configure Palo Alto Networks Firewall to forward syslog directly to Radiant Security
Use this path only when a Radiant Agent is not available. First, upload the Radiant certificate to the firewall, then configure the syslog server.
Log in to the Palo Alto Networks firewall.
On the top navigation bar, click Device.

On the left navigation list, expand Certificate Management and click Certificates.

At the bottom of the right pane, click Import.
Under Import Certificate, configure:
Certificate Name:
Radiant Security Syslog CACertificate File: the SSL Certificate file you downloaded during the data connector setup
File Format: Base64 Encoded Certificate (PEM)

Click OK to save the CA certificate.
On the left navigation list, expand Server Profiles and click Syslog.

At the bottom of the right pane, click Add.
Under Syslog Server Profile, in Name, enter
RadiantSecurity. Click Add to add a server, then configure:Name:
PrimarySyslog Server:
cluster.syslog.radiantsecurity.aiTransport:
SSLPort:
6514

Click the Custom Log Format tab.

In the Log Type column, click each log type name and paste its matching log format into the Config Log Format text box, then click OK. The log formats are in the Custom Log file you downloaded during the data connector setup.

Repeat step 11 for all 14 log types, then click OK on the syslog configuration screen.
Configure log settings
The following steps apply to both paths.
On the left navigation list, under Certificate Management, click Log Settings.

For each of System, Configuration, User-ID, HIP Match, GlobalProtect, and IP-Tag, complete the following:
Click Add.
Under Log Settings - System, configure:
Name: Radiant Security
Filter: All Logs
Under Syslog, click Add and select the RadiantSecurity syslog server profile you created in the previous section.
Click OK to save.

Configure syslog log forwarding
The following steps apply to both paths.
If log forwarding is already configured on your firewall, add the Radiant Security syslog server to the existing log forwarding profile without removing any current settings. This sends syslog messages to both destinations at the same time.
On the top navigation bar, click Objects.
On the left navigation list, under Security Profiles, click Log Forwarding.

At the bottom of the right pane, click Add. If log forwarding is already configured, click Edit on the current profile instead.
Under Log Forwarding Profile, in Name, enter
Radiant Security Log Profile.

Click Add to add a log forwarding profile match. If the existing profile does not have all log types selected, add each one in the Log Forwarding Profile Match List pane:
Name: use the same name as the Log Type
Panorama: enable this option if you use Panorama for log forwarding
Under Syslog, click Add and select the RadiantSecurity syslog profile you created in the previous section.
Click OK to save.

Once all log types are added, click OK on the Log Forwarding Profile pane.
To assign the log forwarding profile to policy rules, navigate to Policies > Security. For each rule that should forward logs to Radiant Security:
Edit the rule.
Click Actions and select the Radiant Security Log Profile.
For Traffic Logs, select Log at Session End.
For Threat Logs, select the security profile required to generate the log.
Click Commit in the upper-right corner to apply the changes.

When the Commit Status completes, the firewall begins forwarding logs to Radiant Security.

Verify ingestion
After Palo Alto Networks Firewall begins forwarding, confirm alerts and events are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by
rs_connectorType:"paloaltonw9_1".Confirm recent alerts and events appear.
Allow several minutes for alerts and events to be parsed, indexed, and available for search.
Last updated
Was this helpful?