Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureEasy
A security operations center (SOC) needs to integrate the Palo Alto Networks firewall logs with their existing Splunk Enterprise SIEM for real-time analysis and alerting. The Splunk instance is configured to receive logs via syslog over UDP on port 514. Which log forwarding method should be configured on the Palo Alto Networks firewall to ensure logs are sent to Splunk?
- ASNMP Trap
- BEmail Server
- CHTTP Server
- DSyslog Server
Show answer & explanationAnswer & explanation
Correct answer: D. Syslog Server
To send logs to a Splunk SIEM that is configured to receive logs via syslog over UDP on port 514, the Palo Alto Networks firewall must be configured with a 'Syslog Server' log forwarding profile. This protocol is the standard for sending security events to SIEMs.
Why the other options are wrong
- A. SNMP Traps are used for network device monitoring and alerts, not for comprehensive log forwarding to a SIEM.
- B. Email Server forwarding is typically for sending specific alerts or reports, not for real-time, high-volume log integration with a SIEM.
- C. HTTP Server forwarding sends logs via HTTP/HTTPS, which is not the protocol specified for this Splunk instance.
Syslog Forwarding
Syslog forwarding sends firewall logs to an external syslog server (like a SIEM) for centralized storage, analysis, and alerting.
- Standard protocol for log aggregation.
- Can use UDP (port 514) or TCP (port 6514) for transport.
- Configured via Log Forwarding Profiles.
Memory trick: Logs Go to Splunk via Syslog.