main
mdx 36 lines 823 Bytes
Raw
1 ---
2 title: Palo Alto Networks (syslog)
3 ---
4
5 ## What you get (high level)
6
7 - Traffic logs
8 - Threat logs
9 - System logs (optional)
10
11 ## Data path (how it flows)
12
13 PAN-OS → syslog → ingestion/collector → Graylog parsing/routing → storage/indexing → alerts (`gl-events*`) → CoPilot Alerts/Cases.
14
15 ## Setup (wireframe)
16
17 - Configure PAN-OS to export syslog.
18 - Confirm parsing and tenant-aware routing.
19
20 ## Success criteria
21
22 - [ ] You can find fresh PAN logs
23 - [ ] You can identify source device
24 - [ ] Events are tenant-aware
25
26 ## Starter alerts
27
28 - Threat log severity thresholding (high/critical)
29 - Repeated denies/drops from a single source
30 - Admin login/config change events
31
32 ## Troubleshooting
33
34 - Confirm syslog profile and server configuration
35 - Confirm connectivity and UDP/TCP choice
36 - Confirm parsing fields exist