For the complete documentation index, see llms.txt. This page is also available as Markdown.

Palo Alto Networks Strata

Connect Palo Alto Networks Strata to Radiant Security to forward firewall traffic and threat logs for AI triage.

Palo Alto Networks Strata is Palo Alto's network security platform, and Strata Logging Service is its cloud service for storing and managing firewall logs. Connecting Strata Logging Service forwards firewall traffic and threat logs to Radiant Security over TLS syslog. Radiant uses the log data to triage firewall and threat alerts in context, giving analysts faster verdicts on whether observed traffic reflects a real compromise or routine network activity.

Prerequisites

Add the data connector in Radiant Security

  1. Log in to Radiant Security.

  2. From the navigation menu, click Settings > Data Connectors, then click + Add Connector.

  3. Search for and select Palo Alto Networks Strata (syslog), then click Data Feeds.

  4. Under Select your data feeds, select Palo Alto Networks Strata, then click Credentials.

  5. Under Credential Name, enter an identifiable name (e.g., PAN Strata Credentials). To reuse an existing credential, select it from the drop-down menu.

  6. In the Connector tag field, enter a random value. This value acts as the salt to randomize the Token you download in the next step.

  7. Click Add Connector.

  8. Save the Token value, or use Download Files to save the token file. You use it in the next section.

  9. Click Done to save your changes.

Configure log forwarding in Strata Logging Service

  1. Access Strata Logging Service through the Palo Alto Networks Hub.

  2. Select the Strata Logging Service instance you want to configure for syslog forwarding.

  3. Select Log Forwarding, then click Add to add a new syslog forwarding profile.

  4. Configure:

    • Name: Radiant Security Syslog Server

    • Syslog Server: cluster.syslog.radiantsecurity.ai

    • Port: 6514

    • Facility: 1 - LOG_USER / User Level

  5. Click Test Connection.

  6. When the connection succeeds, click Next.

  7. Configure:

    • Format: CSV

    • Delimiter: comma

    • Profile Token: enter the Token you saved during the data connector setup.

  8. (Optional) Create a log filter to control which logs are forwarded.

  9. Click Save, then confirm the syslog forwarding profile Status is Running.

Verify ingestion

After Palo Alto Networks Strata begins forwarding, confirm alerts and events are reaching Radiant.

  1. In Radiant, navigate to Log Management.

  2. Filter by rs_connectorType:"pan_strata".

  3. Confirm recent alerts and events appear.

Allow several minutes for alerts and events to be parsed, indexed, and available for search.

Last updated

Was this helpful?