Palo Alto Networks Certified Network Security Administrator (PCNSA)Monitoring and ReportingMedium

A network security analyst is reviewing the system logs to identify any recent changes made to the firewall configuration. They need to quickly find entries related to configuration commits and the administrator who performed them. Which filter should be applied to the system logs?

  1. A(subtype eq global-protect)
  2. B(subtype eq auth)
  3. C(subtype eq threat)
  4. D(subtype eq config)
Show answer & explanation

Correct answer: D. (subtype eq config)

System logs categorize events using 'subtypes'. The 'config' subtype specifically logs events related to configuration changes, including commits and the administrator accounts that initiated them. This is the most direct way to find the requested information.

Why the other options are wrong

  • A. The 'global-protect' subtype is for GlobalProtect VPN events.
  • B. The 'auth' subtype is for authentication events, not configuration changes.
  • C. The 'threat' subtype is for security threat detections, not system configuration changes.

System Log Subtypes

System logs in Palo Alto Networks firewalls categorize events using 'subtypes' to help administrators quickly filter and identify specific types of operational activities, such as configuration changes, authentication events, or daemon processes.

  • Subtypes include 'config', 'auth', 'global-protect', 'daemon', 'resource', etc.
  • Used to narrow down System log entries to relevant categories.
  • Essential for auditing administrative actions and system health.

Memory trick: For 'config' changes, filter by 'subtype eq config'!

More Monitoring and Reporting questions