Monitor Cloud NGFW for Azure Resources
Focus
Focus
Cloud NGFW for Azure

Monitor Cloud NGFW for Azure Resources

Table of Contents

Monitor Cloud NGFW for Azure Resources

Learn how to monitor Cloud NGFW health.
Where Can I Use This?What Do I Need?
  • Cloud NGFW for Azure
  • Cloud NGFW subscription
  • Palo Alto Networks Customer Support Portal account
  • Azure Marketplace subscription
You can monitor the service's overall health and gain deep insights into traffic and operations using various Cloud NGFW logs and metrics.
Service Status and Notifications
To monitor the overall health of the Cloud NGFW service, check the Palo Alto Networks status page. This page provides region-specific status information and allows you to subscribe to service notifications, ensuring you are aware of any ongoing service events. For more information, see Palo Alto Networks Status page.
Traffic and Threat Logs
Cloud NGFW publishes a variety of logs to help you monitor traffic and threats for analysis and compliance. These traffic and threat logs provide detailed information about network sessions passing through your Cloud NGFW resource. Analyze permitted and denied traffic, inspect source/destination IP addresses, URLs, port numbers, and protocols. This data is crucial for understanding traffic patterns, identifying potential security threats, and troubleshooting connectivity issues. These can be streamed to other AWS services for analysis and alarming.
  • Destinations:
    • Azure Log Analytic Workspace: Stream logs for real-time monitoring and analysis. You can then forward these logs to a Storage Account or an Event Hub for third-party integrations.
    • Strata Logging Service: Stream logs to Palo Alto Networks Strata Logging Service for real-time monitoring and advanced analysis.
  • Viewing Logs:
Performance and Metrics
Cloud NGFW publishes a variety of metrics to help you monitor resource health, performance, and traffic usage. These resources assess the overall health of your Cloud NGFW resources, identify performance bottlenecks, and detect anomalies.
  • Monitoring: Cloud NGFW streams these metrics to the Application Insights instance in your Azure Subscription. You can use these metrics to access historical performance data. You can query and also set alarms that monitor specific thresholds and send notifications when these thresholds are reached.
Audit Logs
Activity logs track user and API activity within your Cloud NGFW tenant. These logs help you audit operations related to firewall resources, such as creating, updating, or deleting rules and policies. Reviewing these logs helps maintain a historical record of configuration changes and ensures compliance with security requirements.
  • Destination: Cloud NGFW streams audit logs to Azure, tracking all tenant activity.
  • Viewing Logs: Use the Azure Portal