Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureMedium
A large enterprise is integrating Palo Alto Networks firewalls with their existing Splunk SIEM for centralized log analysis. They need to ensure that all traffic, threat, and system logs are reliably sent to Splunk. Which component on the Palo Alto Networks firewall is responsible for sending these logs to an external syslog server?
- ALog Forwarding Profile
- BLog Monitor
- CLog Collector
- DData Plane Processor
Show answer & explanationAnswer & explanation
Correct answer: A. Log Forwarding Profile
The Log Forwarding Profile is the specific configuration object on a Palo Alto Networks firewall that defines which types of logs to send, to which external destinations (like syslog servers or Panorama), and under what conditions.
Why the other options are wrong
- B. Log Monitor is a GUI tool to view logs on the firewall, not a forwarding mechanism.
- C. A Log Collector is a dedicated device (often Panorama or a separate VM) that aggregates logs, but the firewall itself uses a profile to send logs.
- D. The Data Plane Processor handles packet processing and security functions, but log forwarding configuration is a management plane task.
Log Forwarding Profile
A configuration object on a Palo Alto Networks firewall that specifies how logs (traffic, threat, system, etc.) are sent to external destinations such as syslog servers, SNMP managers, or Panorama.
- Defines log types to be forwarded.
- Specifies external destinations (syslog, SNMP, HTTP, email).
- Can filter logs based on severity or other criteria.
- Applied within security policies or other profiles (e.g., URL Filtering).
Memory trick: Logs in, profile out, no more doubt!