Go to Settings >> Configuration >> Normalization Policies.
Click Add.
Enter a Policy Name.
Select the Compiled Normalizers for Palo Alto Network Firewall.
Click Submit.
Adding a Normalization Policy¶
Go to Settings >> Configuration >> Devices.
Click Add.
Creating Palo Alto Firewall as a Device¶
Enter a device Name.
Enter the IP address(es) of the Palo Alto Network Firewall.
Select the Device Groups.
Select an appropriate Log Collection Policy for the logs.
Select a collector/forwarder from the Distributed Collector.
Note
It is optional to select the Device Groups, the Log Collection Policy, and the Distributed Collector.
Select Time Zone.
Note
The timezone of the device should be the same as its log source.
Configure the Risk Values for Confidentiality, Integrity, and Availability. These values are used to calculate the risk levels of the alerts generated from the device.
Click Submit.
Click Syslog Collector on Available Collectors Fetchers.
Available Collectors Fetchers Panel¶
Select the Syslog Collector.
Configuring Syslog Collector¶
Select the Processing Policy which contains the previously added normalization policy.
Enter the Charset.
In Proxy Server, select None.
Click Submit.
We are glad this guide helped.
Please don't include any personal information in your comment
Contact Support