On this page
Panorama 9.x, 10.x, or 11.x Log Forwarding and Accountability
|
|
This topic is intended for TOS Administrators. |
Overview
For general information about sending syslogs, see Sending Additional Information using Syslog.
There are two supported methods for forwarding traffic logs to TOS:
-
The managed firewalls forward traffic logs directly to TOS.
Use this method when the Panorama device is in Management only, or Legacy mode.
-
The Panorama forwards the traffic logs from the managed firewalls to TOS.
Use this method when the Panorama device is in Panorama mode.
Each method requires that accountability be enabled in a different location. Accountability is required to ensure that TOS can see which user made which changes on each revision.
For more information, see the Palo Alto Networks technical documentation site:
-
For PanOS 9: Configure Log Forwarding and Device > Server Profiles > Syslog
-
For PanOS 10: Configure Log Forwarding and Device > Server Profiles > Syslog
-
For PanOS 11: Configure Log Forwarding and Device > Server Profiles > Syslog
Forward traffic logs from firewall to TOS
-
Log into the firewall device.
-
In the Device tab, create a syslog server profile with the following information:
-
Syslog server: TOS syslog VIP
-
Transport: UDP
-
Port: 514
-
Format: BSD
-
Facility: LOG_User
-
-
Modify a log forwarding profile to point to the syslog profile created in the previous step..
-
In the Objects tab, navigate to Log Forwarding.
-
Click the link of the log forwarding profile.
-
Click a log forwarding profile match list link.
-
Select Panorama/Logging Service.
-
In the Syslog area, select an existing syslog profile or click Add to create a syslog profile.
-
Click OK and OK.
-
Add SecureTrack to the syslog server profile to ensure that the Panorama forwards the logs to SecureTrack.
-
In the Devices tab, navigate to Syslog (under Server Profiles).
-
Click the link of the syslog server profile to which you want to add SecureTrack.
-
Click the Add button, and enter the details of the SecureTrack server.
-
Name: The name of the SecureTrack server.
-
Syslog Server: The IP address of the syslog server.
-
Facility: LOG_LOCAL7 facility .
-
The Syslog Server Profile dialog box appears.
-
- Click OK.
The Log Forwarding Profile dialog box appears.
The Log Forwarding Profile Match List dialog box appears.
Enable accountability
- In the Panorama tab, navigate to Server Profiles > Syslog.
-
Add a new syslog server profile.
-
From the bottom of the screen, select +Add.
The Syslog Server Profile dialog box appears.
-
Enter a name for your syslog server profile.
-
+Add at least one syslog server. The syslog server must direct to the appropriate TOS destination described in Sending Additional Information via Syslog.
-
-
In the Panorama tab, navigate to Log Settings.
-
In the Configuration table, click the Add button to configure a new log.
-
In the Forward Method table:
-
Select Syslog
-
Click the Add button, and select the Syslog Server Profile you added in Step 2.
-
-
Click OK.
The Log Settings - Configuration dialog box appears.
Was this helpful?
Thank you!
We’d love your feedback
We really appreciate your feedback
Send this page to a colleague