Palo Alto Networks Strata
Connect Palo Alto Networks Strata to Radiant Security to forward firewall traffic and threat logs for AI triage.
Palo Alto Networks Strata is Palo Alto's network security platform, and Strata Logging Service is its cloud service for storing and managing firewall logs. Connecting Strata Logging Service forwards firewall traffic and threat logs to Radiant Security over TLS syslog. Radiant uses the log data to triage firewall and threat alerts in context, giving analysts faster verdicts on whether observed traffic reflects a real compromise or routine network activity.
Prerequisites
Add the data connector in Radiant Security
Log in to Radiant Security.
From the navigation menu, click Settings > Data Connectors, then click + Add Connector.
Search for and select Palo Alto Networks Strata (syslog), then click Data Feeds.
Under Select your data feeds, select Palo Alto Networks Strata, then click Credentials.
Under Credential Name, enter an identifiable name (e.g.,
PAN Strata Credentials). To reuse an existing credential, select it from the drop-down menu.In the Connector tag field, enter a random value. This value acts as the salt to randomize the Token you download in the next step.
Click Add Connector.
Save the Token value, or use Download Files to save the token file. You use it in the next section.
Click Done to save your changes.
Configure log forwarding in Strata Logging Service
Access Strata Logging Service through the Palo Alto Networks Hub.
Select the Strata Logging Service instance you want to configure for syslog forwarding.
Select Log Forwarding, then click Add to add a new syslog forwarding profile.
Configure:
Name:
Radiant Security Syslog ServerSyslog Server:
cluster.syslog.radiantsecurity.aiPort:
6514Facility:
1 - LOG_USER / User Level
Click Test Connection.
When the connection succeeds, click Next.
Configure:
Format: CSV
Delimiter: comma
Profile Token: enter the Token you saved during the data connector setup.
(Optional) Create a log filter to control which logs are forwarded.
Click Save, then confirm the syslog forwarding profile Status is Running.
Verify ingestion
After Palo Alto Networks Strata begins forwarding, confirm alerts and events are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by
rs_connectorType:"pan_strata".Confirm recent alerts and events appear.
Last updated
Was this helpful?