Palo Alto Networks Certified Network Security Administrator (PCNSA)Monitoring and ReportingHard

A security operations center (SOC) needs to integrate Palo Alto Networks firewall logs with their existing Security Information and Event Management (SIEM) system. Which configuration setting on the firewall is primarily used to forward logs to an external SIEM?

  1. AMonitor > Log Forwarding
  2. BDevice > Log Settings > Log Export
  3. CDevice > Server Profiles > Syslog
  4. DObjects > Log Forwarding
Show answer & explanation

Correct answer: C. Device > Server Profiles > Syslog

To forward logs to an external SIEM, you first define a Syslog Server Profile under Device > Server Profiles > Syslog. This profile specifies the SIEM's IP address, port, and transport protocol. Once defined, this profile is then referenced in a Log Forwarding Profile (under Objects > Log Forwarding) which is applied to security policies.

Why the other options are wrong

  • A. Monitor > Log Forwarding is not a valid navigation path in the GUI for configuration.
  • B. Device > Log Settings > Log Export is not the primary configuration path for real-time log forwarding to a SIEM; it's more for exporting historical logs.
  • D. Objects > Log Forwarding is where you create a Log Forwarding Profile which *references* a Syslog Server Profile, but the server details themselves are defined under Device > Server Profiles.

Palo Alto Syslog Server Profile

A Syslog Server Profile on a Palo Alto Networks firewall defines the destination (IP address, port) and transport protocol for sending logs to an external syslog server or SIEM. It's a prerequisite for configuring log forwarding.

  • Configured under Device > Server Profiles > Syslog.
  • Supports UDP, TCP, and SSL/TLS for secure log transmission.
  • Multiple syslog servers can be defined in one profile for redundancy or different log types.

Memory trick: Define the server, then forward the logs.

More Monitoring and Reporting questions