Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureEasy

An organization uses Panorama to manage multiple Palo Alto Networks firewalls across different geographical locations. They need to ensure that all firewalls log to a central SIEM system using syslog. Which Panorama object should be configured and pushed to the firewalls to achieve this?

  1. ADevice Group Log Settings
  2. BLog Forwarding Profile
  3. CManaged Collector Group
  4. DLog Collector Group
Show answer & explanation

Correct answer: B. Log Forwarding Profile

A Log Forwarding Profile defines where logs (e.g., traffic, threat, system) are sent, including external syslog servers. This profile can be created on Panorama and then pushed to managed firewalls.

Why the other options are wrong

  • A. Device Group Log Settings on Panorama control local logging settings on the firewall, not external forwarding to a SIEM.
  • C. Managed Collector Group is not a standard Panorama object related to log forwarding to external systems.
  • D. Log Collector Group is for Panorama's internal log collection from firewalls, not forwarding from firewalls to external SIEMs.

Log Forwarding Profile

A Log Forwarding Profile on a Palo Alto Networks firewall or Panorama defines the destinations (e.g., syslog server, SNMP trap, email) for different types of logs generated by the firewall.

  • Specifies external log destinations.
  • Can be configured per log type (traffic, threat, system).
  • Centralized management via Panorama.

Memory trick: The 'Log Forwarding Profile' is the postman for firewall logs.

More Deploy and Configure questions