Strata Logging Service Logging with CN-Series firewall.
Where Can I Use This?
What Do I Need?
Strata Logging Service with CN-Series firewall
Panorama running with minimum PAN-OS 11.1 version
Strata Logging Service License
Strata Logging Service enables AI-based innovations for cybersecurity
with the industry’s only approach to normalizing and stitching together your
enterprise’s data. For more information, see Introduction to Strata Logging Service and
Strata Logging Service for Panorama-Managed
Firewalls. Strata Logging Service can now collect log data from CN-Series next-generation firewall. When you purchase a Strata Logging
Service license, all firewalls registered to your support account receive a Strata
Logging Service license. You will also receive a magic link that you will need to use to
activate your Strata Logging Service instance.
To get started with CN-Series firewall Strata Logging Service logging, you must
ensure that you Install the Kubernetes Plugin and Set up Panorama for
your CN-Series Firewall. Provide the device certificate to the CN-MGMT pod
for Strata Logging Service connectivity. It is important to register your CN-MGMT pod
with a CSP account to ensure that the CN-MGMT pod reflects in your Strata Logging
Service instance. Add the valid PIN-ID and PIN-value to the
pan-cn-mgmt-secret.yaml file to successfully install the device
certificate. The CN-Series firewall requires a device certificate that authorizes secure
access to Strata Logging Service. For more information, see Install a Device Certificate on the CN-Series
Firewall.
Configure Strata Logging Service for CN-Series firewall
Strata Logging Service provides cloud-based, centralized log storage
and aggregation for cloud-delivered services and applications.
Ensure that you have a logging license and a Strata
Logging Service instance created in your CSP account. For more information, see
Strata Logging Service.
Complete the following steps to configure Strata Logging Service
settings on Panorama and push them to the firewall:
Onboard your Panorama to the Strata
Logging Service to enable settings of Strata Logging Service
configurations on the device.
Go to Cloud Logging pane, and then click Settings icon.
You can
now see that the Region is populated.
Click Enable Cloud Logging.
Click OK.
Go to Commit > Push to Devices.
Select your CN-MGMT pod.
Click OK.
Strata Logging Service configuration for
CN-MGMT pod is pushed now. The CN-MGMT pod will now initiate its connection
to the Strata Logging Service instance.