Select Log Forwarding Destinations
Table of Contents
Expand all | Collapse all
-
- Objects > Addresses
- Objects > Address Groups
- Objects > Regions
- Objects > Dynamic User Groups
- Objects > Application Groups
- Objects > Application Filters
- Objects > Services
- Objects > Service Groups
- Objects > Devices
- Objects > External Dynamic Lists
- Objects > Custom Objects > Spyware/Vulnerability
- Objects > Custom Objects > URL Category
- Objects > Security Profiles > Antivirus
- Objects > Security Profiles > Anti-Spyware Profile
- Objects > Security Profiles > Vulnerability Protection
- Objects > Security Profiles > File Blocking
- Objects > Security Profiles > WildFire Analysis
- Objects > Security Profiles > Data Filtering
- Objects > Security Profiles > DoS Protection
- Objects > Security Profiles > Mobile Network Protection
- Objects > Security Profiles > SCTP Protection
- Objects > Security Profile Groups
- Objects > Log Forwarding
- Objects > Authentication
- Objects > Decryption > Forwarding Profile
- Objects > Schedules
-
-
- Firewall Interfaces Overview
- Common Building Blocks for Firewall Interfaces
- Common Building Blocks for PA-7000 Series Firewall Interfaces
- Tap Interface
- HA Interface
- Virtual Wire Interface
- Virtual Wire Subinterface
- PA-7000 Series Layer 2 Interface
- PA-7000 Series Layer 2 Subinterface
- PA-7000 Series Layer 3 Interface
- Layer 3 Interface
- Layer 3 Subinterface
- Log Card Interface
- Log Card Subinterface
- Decrypt Mirror Interface
- Aggregate Ethernet (AE) Interface Group
- Aggregate Ethernet (AE) Interface
- Network > Interfaces > VLAN
- Network > Interfaces > Loopback
- Network > Interfaces > Tunnel
- Network > Interfaces > SD-WAN
- Network > VLANs
- Network > Virtual Wires
-
- Network > Network Profiles > GlobalProtect IPSec Crypto
- Network > Network Profiles > IPSec Crypto
- Network > Network Profiles > IKE Crypto
- Network > Network Profiles > Monitor
- Network > Network Profiles > Interface Mgmt
- Network > Network Profiles > QoS
- Network > Network Profiles > LLDP Profile
- Network > Network Profiles > SD-WAN Interface Profile
-
-
- Device > Setup
- Device > Setup > Management
- Device > Setup > Interfaces
- Device > Setup > Telemetry
- Device > Setup > Content-ID
- Device > Setup > WildFire
- Device > Setup > DLP
- Device > Log Forwarding Card
- Device > Config Audit
- Device > Administrators
- Device > Admin Roles
- Device > Access Domain
- Device > Authentication Sequence
- Device > Device Quarantine
-
- Security Policy Match
- QoS Policy Match
- Authentication Policy Match
- Decryption/SSL Policy Match
- NAT Policy Match
- Policy Based Forwarding Policy Match
- DoS Policy Match
- Routing
- Test Wildfire
- Threat Vault
- Ping
- Trace Route
- Log Collector Connectivity
- External Dynamic List
- Update Server
- Test Cloud Logging Service Status
- Test Cloud GP Service Status
- Device > Virtual Systems
- Device > Shared Gateways
- Device > Certificate Management
- Device > Certificate Management > Certificate Profile
- Device > Certificate Management > OCSP Responder
- Device > Certificate Management > SSL/TLS Service Profile
- Device > Certificate Management > SCEP
- Device > Certificate Management > SSL Decryption Exclusion
- Device > Certificate Management > SSH Service Profile
- Device > Response Pages
- Device > Server Profiles
- Device > Server Profiles > SNMP Trap
- Device > Server Profiles > Syslog
- Device > Server Profiles > Email
- Device > Server Profiles > HTTP
- Device > Server Profiles > NetFlow
- Device > Server Profiles > RADIUS
- Device > Server Profiles > TACACS+
- Device > Server Profiles > LDAP
- Device > Server Profiles > Kerberos
- Device > Server Profiles > SAML Identity Provider
- Device > Server Profiles > DNS
- Device > Server Profiles > Multi Factor Authentication
- Device > Local User Database > Users
- Device > Local User Database > User Groups
- Device > Scheduled Log Export
- Device > Software
- Device > Dynamic Updates
- Device > Licenses
- Device > Support
- Device > Policy Recommendation
-
- Network > GlobalProtect > MDM
- Network > GlobalProtect > Clientless Apps
- Network > GlobalProtect > Clientless App Groups
- Objects > GlobalProtect > HIP Profiles
-
- Use the Panorama Web Interface
- Context Switch
- Panorama Commit Operations
- Defining Policies on Panorama
- Log Storage Partitions for a Panorama Virtual Appliance in Legacy Mode
- Panorama > Setup > Interfaces
- Panorama > High Availability
- Panorama > Administrators
- Panorama > Admin Roles
- Panorama > Access Domains
- Panorama > Device Groups
- Panorama > Plugins
- Panorama > Log Ingestion Profile
- Panorama > Log Settings
- Panorama > Server Profiles > SCP
- Panorama > Scheduled Config Export
End-of-Life (EoL)
Select Log Forwarding Destinations
DeviceLog Settings
The Log Settings page allows you to configure log forwarding
to:
- Panorama, SNMP trap receivers, email servers, Syslog servers, and HTTP servers—You can also add or remove tags from a source or destination IP address in a log entry; all log types except System logs and Configuration logs support tagging.
- Logging Service—If you have a Logging Service subscription and have enabled the Logging Service (Device > Setup > Management), then the firewall will send the logs to the Logging Service when you configure log forwarding to Panorama/Logging Service. Panorama will query the Logging Service to access the logs, to display the logs, and to generate reports.
- Azure Security Center—The integration with Azure Security Center is available only for VM-Series firewalls on Azure.
- If you launched the VM-Series firewall from Azure Security Center, a security policy rule with the log forwarding profiles is automatically enabled for you.
- If you launched the VM-Series firewall from the Azure Marketplace or using custom Azure templates, you must manually select Azure-Security-Center-Integration to forward System logs, User-ID logs, and HIP Match logs to Azure Security Center and use the Log Forwarding profile for other log types (see Objects > Log Forwarding).The free tier of Security Center is automatically enabled on your Azure subscription.
You can forward the following log types
: System, Configuration,
User-ID, HIP Match, and Correlation logs. To specify destinations
for each log type, Add one or more match
list profiles (up to 64) and complete the fields described in the
following table.
To forward Traffic, Threat, WildFire Submissions,
URL Filtering, Data Filtering, Tunnel Inspection, GTP, and Authentication
logs, you must configure a Log Forwarding profile (see Objects
> Log Forwarding).
Match List Profile
Settings | Description |
---|---|
Name | Enter a name (up to 31 characters) to identify
the match list profile. A valid name must start with an alphanumeric
character and can contain zeros, alphanumeric characters, underscores,
hyphens, periods, or spaces. |
Filter | By default, the firewall forwards All Logs of
the type for which you add the match list profile. To forward a
subset of the logs, open the drop-down and select an existing filter
or select Filter Builder to add a new filter.
For each query in a new filter, specify the following fields and Add the
query:
To display or export Set the filter to forward logs for all
event severity levels (the default filter is All Logs). To
create separate log forwarding methods for different severity levels, specify
one or more severity levels in the Filter,
configure a Forward Method, and then repeat
the process for the rest of the severity levels. |
Description | Enter a description (up to 1,023 characters)
to explain the purpose of this match list profile. |
Panorama/Logging Service | Select Panorama/Logging Service if you
want to forward logs to the Logging Service, Log Collectors or the Panorama
management server. If you enable this option, you must configure log forwarding to Panorama You
cannot forward Correlation logs from firewalls to Panorama. Panorama
generates Correlation logs based on the firewall logs it receives. |
SNMP | Add one or more SNMP
Trap server profiles to forward logs as SNMP traps (see Device
> Server Profiles > SNMP Trap). |
Email | Add one or more Email
server profiles to forward logs as email notifications (see Device
> Server Profiles > Email). |
Syslog | Add one or more Syslog
server profiles to forward logs as syslog messages (see Device
> Server Profiles > Syslog). |
HTTP | Add one or more HTTP
server profiles to forward logs as HTTP requests (see Device
> Server Profiles > HTTP). |
Built-in Actions | You can select from two types of built-in
actions when you Add an action to perform—Tagging
and Integration.
To add a device to the
quarantine list based on the log forwarding profile filter, select Quarantine. |