| Where Can I Use This? | What Do I Need? |
Email forwarding is intended for critical alert notifications, not as a general-purpose log
forwarding sink. Forwarding high volumes of logs will result in delays in log
delivery and log loss. Configure email forwarding only for the logs most critical to
your operations.
Strata Logging Service uses the Palo Alto Networks SMTP server to forward log information
in an email format, and all emails are sent from noreply@cs.paloaltonetworks.com. The
communication between Strata Logging Service and the email destination uses SMTP over TLS,
and the SMTP server certificate is signed by a trusted root CA.
Email forwarding is subject to the following rate limits per Strata Logging Service
instance:
- Strata Logging Service bundles log records that accumulate during each five-minute
window into a single email, with a maximum of one email sent per window.
- Strata Logging Service limits email bodies to 20 MB per send and automatically splits
log records that exceed 20 MB into multiple emails.
- If the rate limit applies, Strata Logging Service queues logs and delivers them in
the next available window.
- If you have multiple email forwarding profiles configured, they share the per-instance rate
limit and take turns sending in rotation. Each profile gets one send opportunity
per cycle.