Palo Alto Networks Certified Network Security Administrator (PCNSA)Monitoring and ReportingMedium
A network security engineer is tasked with ensuring all critical firewall logs, including traffic, threat, and system logs, are consistently forwarded to an external Syslog server for long-term archival and SIEM integration. Which configuration object is used to define the destination server and the log types to be sent?
- ALog Storage Profile
- BExternal Log Collector
- CSyslog Server Profile
- DLog Forwarding Profile
Show answer & explanationAnswer & explanation
Correct answer: C. Syslog Server Profile
The 'Syslog Server Profile' is the specific configuration object in Palo Alto Networks firewalls used to define the details of an external Syslog server, including its IP address, port, and transport protocol. This profile is then referenced by Log Forwarding Profiles to direct logs to that server.
Why the other options are wrong
- A. Log Storage Profile relates to internal log retention settings, not external forwarding.
- B. External Log Collector is a general term for a SIEM or log management system, not a firewall configuration object.
- D. Log Forwarding Profile specifies *which* logs to send and *where* to send them, but it references a Syslog Server Profile for the destination details.
Syslog Server Profile
A Syslog Server Profile in Palo Alto Networks firewalls defines the connection parameters for an external Syslog server, such as its IP address, port, and transport protocol (UDP, TCP, SSL).
- Configured under Device > Server Profiles > Syslog.
- Specifies the destination for logs to be forwarded.
- Is referenced by Log Forwarding Profiles to direct logs to the defined server.
Memory trick: To 'send logs', define the 'Syslog Server Profile' first!