Learn how to monitor Cloud NGFW health.
Where Can I Use This? | What Do I Need? |
|
- Cloud NGFW subscription
- Palo Alto Networks Customer Support Portal account
- Azure Marketplace subscription
|
You can monitor the service's overall health and gain deep insights into
traffic and operations using various Cloud NGFW logs and metrics.
Service Status and Notifications
To monitor the overall health of the Cloud NGFW service, check the Palo Alto Networks
status page. This page provides region-specific status information and allows you to
subscribe to service notifications, ensuring you are aware of any ongoing service
events. For more information, see
Palo Alto Networks Status
page.
Traffic and Threat Logs
Cloud NGFW publishes a variety of logs to help you monitor traffic and
threats for analysis and compliance. These
traffic and threat logs provide detailed
information about network sessions passing through your Cloud NGFW resource. Analyze
permitted and denied traffic, inspect source/destination IP addresses, URLs, port
numbers, and protocols. This data is crucial for understanding traffic patterns,
identifying potential security threats, and troubleshooting connectivity issues.
These can be streamed to other AWS services for analysis and alarming.
Destinations:
Viewing Logs:
Performance and Metrics
Audit Logs
Activity logs track user and API activity
within your Cloud NGFW tenant. These logs help you audit operations related to
firewall resources, such as creating, updating, or deleting rules and policies.
Reviewing these logs helps maintain a historical record of configuration changes and
ensures compliance with security requirements.
Destination: Cloud NGFW streams audit logs to Azure,
tracking all tenant activity.
Viewing Logs: Use the Azure Portal