View Cloud NGFW Logs in Cortex Data Lake
Table of Contents
Expand all | Collapse all
-
- About Cloud NGFW for AWS
- Getting Started from the AWS Marketplace
- Cloud NGFW for AWS Pricing
- Link Your PAYG Account with Cloud NGFW Credits
- Cloud NGFW for AWS Free Trial
- Cloud NGFW for AWS Limits and Quotas
- Subscribe to Cloud NGFW for AWS
- Locate Your Cloud NGFW for AWS Serial Number
- Cross-Account Role CFT Permissions for Cloud NGFW
- Invite Users to Cloud NGFW for AWS
- Manage Cloud NGFW for AWS Users
- Deploy Cloud NGFW for AWS with the AWS Firewall Manager
- Enable Programmatic Access
- Terraform Support for Cloud NGFW AWS
- Provision Cloud NGFW Resources to your AWS CFT
- Usage Explorer
- Create a Support Case
-
-
- Prepare for Panorama Integration
- Link the Cloud NGFW to Palo Alto Networks Management
- Unlink the Cloud NGFW from Palo Alto Networks Management
- Associate a Linked Panorama to the Cloud NGFW Resource
- Use Panorama for Cloud NGFW Policy Management
- View Cloud NGFW Logs and Activity in Panorama
- View Cloud NGFW Logs in Cortex Data Lake
- Tag Based Policies
- Enterprise Data Loss Prevention (E-DLP) Integration with Cloud NGFW for AWS
-
View Cloud NGFW Logs in Cortex Data Lake
View logs in Cortex Data Lake for your Cloud NGFW resource.
When you integrate Cloud NGFW with Panorama and Cortex Data Lake (CDL), you forward
logs created by your Cloud NGFW resources and view them in CDL. In the
CDL web interface, you can view the Traffic, threat, and decryption logs generated
by your Cloud NGFW Resources.
If you're using
Panorama and are not using CDL for log collection, you can forward logs to
another entity, however, you must enable CDL in your logging profile.
For information about the log fields, see the Cortex Data Lake Schema
Reference: Traffic, Threat, and Decryption.
- Log in to your Cortex Data Lake instance.
- SelectExplore.
- From the query drop-down, you can select the type of logs. Each page displays 100 logs. However, you can use the CDL Queries to refine the information displayed.
- SelectInventoryto display information about onboarded firewalls.
- In theInventorypage, selectCloud NGFW.
Forward Logs to Cortex Data Lake
To forward logs to CDL:
- In the Panorama console, selectObjectsunderDevice Groups.
- SelectLog Forwarding.
- ClickAddto create a new log forwarding match list profile.
- In theLog Forwarding Profile Match Listscreen, specify a name for the log.
- Select aLog Typefrom the drop-down.
- SelectPanorama/Cortex Data Lakeas theForward Method.
- ClickOK.
- Commit and push your change.
Forward Logs without Cortex Data Lake
If you're using Panorama and are not using CDL for log collection, you can
forward logs to another entity, like AWS Cloudwatch, Amazon S3, or Amazon
Kinesis.
- In the Panorama console, selectObjectsunderDevice Groups.
- SelectLog Forwarding.
- ClickAddto create a new log forwarding match list profile.
- In theLog Forwarding Profile Match Listscreen, specify a name for the log.
- Select aLog Typefrom the drop-down.If Panorama isn't linked to CDL, logs are not forwarded to the Panorama console, they are viewable in another application like Cloud watch, S3, or Kinesis. Use the Cloud NGFW console to configure these other logging methods.Enable CDL in your logging profile even if you don't intend to send logs directly to CDL.
- ClickOK.
- Commit and push your change.