Palo Alto Networks Certified Network Security Administrator (PCNSA)Monitoring and ReportingMedium
A network engineer wants to configure an alert that triggers whenever the number of critical severity threat logs exceeds 50 within a 5-minute period. Where would this alert be configured in the Palo Alto Networks firewall GUI?
- AObjects > Log Forwarding
- BMonitor > Manage Custom Reports > Alerts
- CMonitor > Logs > Threat
- DACC > Custom Widgets
Show answer & explanationAnswer & explanation
Correct answer: B. Monitor > Manage Custom Reports > Alerts
Alerts based on log thresholds are configured under Monitor > Manage Custom Reports > Alerts. This section allows defining alert conditions and actions based on various log types and criteria.
Why the other options are wrong
- A. Objects > Log Forwarding is for sending logs to external syslog servers or SIEMs, not for internal threshold-based alerts.
- C. Monitor > Logs > Threat is for viewing existing threat logs, not configuring new alerts.
- D. ACC > Custom Widgets are for dashboard visualizations, not proactive alerting.
Palo Alto Custom Alerts
Custom alerts on Palo Alto Networks firewalls allow administrators to define specific conditions based on log data that, when met, trigger notifications or other actions. These are configured under the 'Monitor' tab.
- Provide proactive notification of critical events.
- Can be based on any log type and complex query criteria.
- Actions include email, SNMP trap, or syslog messages.
Memory trick: Monitor your reports to manage your alerts.