: Connect SaaS Security Inline and Strata Logging Service
Focus
Focus

Connect SaaS Security Inline and Strata Logging Service

Table of Contents

Connect SaaS Security Inline and Strata Logging Service

Connect SaaS Security Inline to Strata Logging Service to retrieve firewall logs.
You already connected SaaS Security Inline with Strata Logging Service as part of your SaaS Security Inline activation. However, if you need to update SaaS Security Inline with a new Strata Logging Service after activation, contact SaaS Security Technical Support.
When your Strata Logging Service is configured to receive logs from your Palo Alto Networks firewalls , after activation, SaaS Security Inline discovers all SaaS applications and users.
SaaS Security Inline discovers users by using Strata Logging Service logs, specifically the source_user_info field. If the firewall forwards a log to Strata Logging Service and this field is not populated for a given user, SaaS Security Inline considers that user unknown. The SaaS Security web interface excludes all application usage data for unknown users.
  • If you created this connection in advance or at the time of SaaS Security Inline activation, the connection status indicates Monitoring.
  • If the connection message indicates Not Connected, contact SaaS Security Technical Support to manually add the Strata Logging Service serial number.
  • If the connection status indicates Error with Connection Unsuccessful message, contact SaaS Security Technical Support to update the Strata Logging Service serial number.
  1. Navigate to SaaS Security Inline
  2. Select SettingsService Monitoring & LicenseServices.
  3. Verify that the status for the serial number indicates Monitoring.