Panorama 9.x or 10.x Log Forwarding and Accountability

Overview

For general information about sending syslogs, see Sending Additional Information using Syslog.

Panorama log forwarding requires you to do the following:

  • Forward traffic logs to Panorama: We recommend that traffic logs from PanOS firewalls be sent to Panorama devices that are connected to TOS Aurora. However, TOS Aurora can also receive logs from PanOS firewall devices directly.
  • Enable accountability: Enabling accountability ensures that firewall changes made by SecureChange and manual firewall changes made using Panorama are seen by SecureTrack.

For more information, see the Palo Alto Networks technical documentation site:

Forward Traffic Logs to Panorama

These steps will explain how to send the firewall traffic logs to a Panorama device (for Panorama version 9.x), and then configure the Panorama to forward the logs to SecureTrack.

  1. Log into the Panorama device.

  2. Modify a log forwarding profile to enable the log forwarding for the Panorama device.

    1. In the Objects tab, navigate to Log Forwarding.

    2. Click on the link of the log forwarding profile.

    3. The Log Forwarding Profile dialog box is displayed.

    4. Click on a log forwarding profile match list link.

    5. The Log Forwarding Profile Match List dialog box is displayed.

    6. Select Panorama/Logging Service.

    7. In the Syslog area, select an existing syslog profile or click Add to create a syslog profile.

    8. Click OK and OK.

  3. Add SecureTrack to the syslog server profile to ensure that the Panorama forwards the logs to SecureTrack.

    1. In the Devices tab, navigate to Syslog (under Server Profiles).

    2. Click on the link of the syslog server profile to which you want to add SecureTrack.

    3. The Syslog Server Profile dialog box is displayed.

    4. Click the Add button, and enter the details of the SecureTrack server.

      • Name: The name of the SecureTrack server.

      • Syslog Server: The IP address of the syslog server.

      • Facility: LOG_LOCAL7 facility .

  4. Click OK.

Enable Accountability

  1. In the Panorama tab, navigate to Server Profiles > Syslog.
  2. Add a new syslog server profile.

    1. From the bottom of the screen, select +Add.

      The Syslog Server Profile dialog box appears.

    2. Enter a name for your syslog server profile.

    3. +Add at least one syslog server. The syslog server must direct to the appropriate TOS Aurora destination described in Sending Additional Information via Syslog.

  3. In the Panorama tab, navigate to Log Settings.

  4. In the Configuration table, click the Add button to configure a new log.

  5. The Log Settings - Configuration dialog box is displayed.

  6. In the Forward Method table:

    1. Select Syslog

    2. Click the Add button, and select the Syslog Server Profile you added in Step 2.

  7. Click OK.