Palo Alto Networks Prisma Access
Connect Palo Alto Networks Prisma Access to Radiant Security to forward traffic, threat, and access logs for AI triage.
Palo Alto Networks Prisma Access is a cloud-delivered security platform that secures access for remote users and branch offices, inspecting traffic to block malware, intrusions, and risky web activity. Connecting Prisma Access forwards traffic, threat, URL, and authentication logs to Radiant Security over TLS syslog. Radiant uses the log data to triage access and threat alerts in context, giving analysts faster verdicts on whether observed activity reflects a real compromise or routine user behavior.
Prerequisites
Add the data connector in Radiant Security
Log in to Radiant Security.
From the navigation menu, click Settings > Data Connectors, then click + Add Connector.
Search for and select Palo Alto Prisma Access, then click Data Feeds.
Under Select your data feeds, select Palo Alto Prisma Access, then click Credentials.
Under Credential Name, enter an identifiable name (e.g.,
PAN Credentials). To reuse an existing credential, select it from the drop-down menu.In the Connector tag field, enter a random value. This value acts as the salt to randomize the Token you download in the next step.
Click Add Connector.
Save the Token value and use Download Files to download the SSL certificate file. You use both in the next section.
Click Done to save your changes.
Configure log forwarding in Prisma Access
Go to the Palo Alto Networks Hub.
Select the Strata Logging Service you want to configure for syslog forwarding. If you use Strata Cloud Manager to manage Strata Logging Service, navigate to Settings > Strata Logging Service > Log Forwarding.
Select the Syslog tab, then click + to add a new syslog forwarding profile.
Configure:
Name:
Radiant Security Syslog ConnectorSyslog Server:
primary-k8s.syslog.radiantsecurity.aiPort:
6514Facility:
LOG_LOCAL0Under Server Authentication, click Upload and upload the CA certificate you downloaded during the data connector setup.
Click Test Connection. If the test fails, contact your Customer Success Manager.
Click Next.
Configure:
Format: CEF
Delimiter: Space
Profile Token: enter the Token you saved during the data connector setup.
Filters: click Add and select these log types: Traffic, Threat, URL, Data, Authentication, DNS Security, File, GlobalProtect, IPTag, UserID, and Remote Browser Isolation.
Click Save.
Verify ingestion
After Palo Alto Networks Prisma Access begins forwarding, confirm alerts and events are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by
rs_connectorType:"pan_prisma".Confirm recent alerts and events appear.
Last updated
Was this helpful?