Palo Alto Networks Panorama
Connect Palo Alto Networks Panorama to Radiant Security to forward aggregated firewall logs for AI triage.
Palo Alto Networks Panorama is a centralized management and log aggregation platform that consolidates logs from Palo Alto firewalls across an environment. Connecting Panorama forwards aggregated firewall traffic, threat, and system logs to Radiant Security over TLS syslog. Radiant uses the log data to triage firewall and threat alerts in context, giving analysts faster verdicts on whether observed traffic reflects a real compromise or routine network activity.
To forward logs directly from Palo Alto firewalls without Panorama, refer to Palo Alto Networks Firewall.
Prerequisites
Add the data connector in Radiant Security
Log in to Radiant Security.
From the navigation menu, click Settings > Data Connectors, then click + Add Connector.
Search for and select Palo Alto Networks Firewall, then click Data Feeds.
Under Select your data feeds, select Palo Alto Firewall 9.1, then click Credentials.
Under Credential Name, enter an identifiable name (e.g.,
PAN Credentials). To reuse an existing credential, select it from the drop-down menu.In the Connector tag field, enter a random value. This value acts as the salt to randomize the Token you download in the next step.
Click Add Connector.
Save the Token value, or use Download Files to save the SSL certificate and token files. You use these in the next sections.
Click Done to save your changes.
Upload the certificate to Panorama
Log in to Panorama and navigate to Panorama > Certificate Management > Certificates.
Click Import.
Under Import Certificate, configure:
Certificate Name:
Radiant Security Syslog CACertificate File: the SSL certificate file you downloaded during the data connector setup
File Format: Base64 Encoded Certificate (PEM)
Click OK to save the CA certificate.
Configure the syslog server
Navigate to Panorama > Server Profiles > Syslog, then click Add.
Under Syslog Server Profile, in Name, enter
Radiant Security, then configure:Syslog Server:
cluster.syslog.radiantsecurity.aiTransport:
SSLPort:
6514Format:
BSDFacility:
LOG_USER
Click the Custom Log Format tab.
In the Log Type column, click each log type name and paste its matching log format into the Config Log Format text box, then click OK. The log formats are in the Custom Log file you downloaded during the data connector setup.
Repeat step 4 for all 14 log types, then click OK on the syslog configuration screen.
Configure Panorama log settings
Navigate to Panorama > Log Settings.
For each of System, Configuration, User-ID, HIP Match, GlobalProtect, and IP-Tag, complete the following:
Click Add.
Under Log Settings, configure:
Name:
Radiant SecurityFilter: All Logs
Under Syslog, click Add and select the Radiant Security syslog server profile you created in the previous section.
Click OK to save.
Navigate to Objects > Log Forwarding, then click Add.
Under the log forwarding profile, in Name, enter
Radiant Security, then add a match list.Under Match List, select these log types: auth, data, threat, traffic, tunnel, URL, and WildFire.
Under Syslog, click Add and select the Radiant Security syslog server profile you created in the previous section.
Click OK to save.
Configure log collectors log settings
If your environment uses log collectors, configure them to forward syslog to Radiant Security.
Navigate to Panorama > Collector Groups.
Click Collector Log Forwarding.
For each of System, Configuration, User-ID, HIP Match, GlobalProtect, and IP-Tag, complete the following:
Click Add.
Under Log Settings, configure:
Name:
Radiant SecurityFilter: All Logs
Under Syslog, click Add and select the Radiant Security syslog server profile you created in the previous section.
Click OK to save.
Commit changes
Click Commit in the upper-right corner to apply the changes.
When the Commit Status completes, Panorama begins forwarding logs to Radiant Security.
Verify ingestion
After Palo Alto Networks Panorama begins forwarding, confirm alerts and events are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by
rs_connectorType:"paloaltonw9_1".Confirm recent alerts and events appear.
Allow several minutes for alerts and events to be parsed, indexed, and available for search.
Last updated
Was this helpful?