Palo Alto Networks Prisma Access
Connect Palo Alto Networks Prisma Access to Radiant Security to forward traffic, threat, and access logs for AI triage.
Last updated
Was this helpful?
Connect Palo Alto Networks Prisma Access to Radiant Security to forward traffic, threat, and access logs for AI triage.
Palo Alto Networks Prisma Access is a cloud-delivered security platform that secures access for remote users and branch offices, inspecting traffic to block malware, intrusions, and risky web activity. Connecting Prisma Access forwards traffic, threat, URL, and authentication logs to Radiant Security over TLS syslog. Radiant uses the log data to triage access and threat alerts in context, giving analysts faster verdicts on whether observed activity reflects a real compromise or routine user behavior.
Log in to Radiant Security.
From the navigation menu, click Settings > Data Connectors, then click + Add Connector.
Search for and select Palo Alto Prisma Access, then click Data Feeds.
Under Select your data feeds, select Palo Alto Prisma Access, then click Credentials.
Under Credential Name, enter an identifiable name (e.g., PAN Credentials). To reuse an existing credential, select it from the drop-down menu.
In the Connector tag field, enter a random value. This value acts as the salt to randomize the Token you download in the next step.
Click Add Connector.
Save the Token value and use Download Files to download the SSL certificate file. You use both in the next section.
Click Done to save your changes.
Go to the Palo Alto Networks Hub.
Select the Strata Logging Service you want to configure for syslog forwarding. If you use Strata Cloud Manager to manage Strata Logging Service, navigate to Settings > Strata Logging Service > Log Forwarding.
Select the Syslog tab, then click + to add a new syslog forwarding profile.
Configure:
Name: Radiant Security Syslog Connector
Syslog Server: primary-k8s.syslog.radiantsecurity.ai
Port: 6514
Facility: LOG_LOCAL0
Under Server Authentication, click Upload and upload the CA certificate you downloaded during the data connector setup.
Click Test Connection. If the test fails, contact your Customer Success Manager.
Click Next.
Configure:
Format: CEF
Delimiter: Space
Profile Token: enter the Token you saved during the data connector setup.
Filters: click Add and select these log types: Traffic, Threat, URL, Data, Authentication, DNS Security, File, GlobalProtect, IPTag, UserID, and Remote Browser Isolation.
Click Save.
After Palo Alto Networks Prisma Access begins forwarding, confirm alerts and events are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by rs_connectorType:"pan_prisma".
Confirm recent alerts and events appear.
Allow several minutes for alerts and events to be parsed, indexed, and available for search.
Last updated
Was this helpful?
Was this helpful?