Forward Logs to an Email Server
Focus
Focus
Strata Logging Service

Forward Logs to an Email Server

Table of Contents

Forward Logs to an Email Server

Forward logs from Strata Logging Service to an email server to receive critical alert notifications.
Where Can I Use This?What Do I Need?
One of these:
Email forwarding is intended for critical alert notifications, not as a general-purpose log forwarding sink. Forwarding high volumes of logs will result in delays in log delivery and log loss. Configure email forwarding only for the logs most critical to your operations.
Strata Logging Service uses the Palo Alto Networks SMTP server to forward log information in an email format, and all emails are sent from noreply@cs.paloaltonetworks.com. The communication between Strata Logging Service and the email destination uses SMTP over TLS, and the SMTP server certificate is signed by a trusted root CA.
Email forwarding is subject to the following rate limits per Strata Logging Service instance:
  • Strata Logging Service bundles log records that accumulate during each five-minute window into a single email, with a maximum of one email sent per window.
  • Strata Logging Service limits email bodies to 20 MB per send and automatically splits log records that exceed 20 MB into multiple emails.
  • If the rate limit applies, Strata Logging Service queues logs and delivers them in the next available window.
  • If you have multiple email forwarding profiles configured, they share the per-instance rate limit and take turns sending in rotation. Each profile gets one send opportunity per cycle.
  1. Sign In to the hub.
  2. Select the Strata Logging Service instance that you want to configure for email forwarding.
    If you have multiple Strata Logging Service instances, hover over the Strata Logging Service tile and then select an instance from the list of available instances.
    If you are using Strata Cloud Manager to manage Strata Logging Service, select System SettingsStrata Logging ServiceLog Forwarding to manage log forwarding from Strata Logging Service instance to an external server.
  3. Configure email forwarding.
    You cannot add your SMTP server to Strata Logging Service currently.
    1. Select Log ForwardingAdd to add a new email forwarding profile.
    2. Enter a descriptive Name for the profile.
    3. Enter the email address of the administrator To whom you want to send email.
      You can enter up to ten additional email addresses, separated by commas, to add as BCC.
      Ensure that all email addresses you enter are valid. Invalid addresses will cause log forwarding to fail.
    4. Enter the Email Subject to clearly identify the purpose of the notification.
    5. Select the logs you want to forward.
      1. Add a new log filter.
      2. Select the Log Type.
      3. Create a log filter to forward only the logs most critical to you. For high-traffic log types such as traffic, threat, and URL logs, a filter with a WHERE clause is required to prevent excessive log volume from causing delivery delays or log loss.
        You can either write your own queries from scratch or use the query builder. You can also select the query field to choose from among a set of common predefined queries.
        • No double quotes (“”).
        • No subnet masks. To return IP addresses with subnets, use the LIKE operator. Example: src_ip.value LIKE “192.1.1.%”.
      4. Save your changes.
      5. Add other log types for which you’d like to receive email notifications.
    6. Save your changes.
  4. Acknowledge to reach out to your Palo Alto Networks team to enable log forwarding from Strata Logging Service in China to an external log server. Be aware that configuring log forwarding profiles to send logs to servers outside China can result in personally identifiable information leaving China.
  5. Verify that the Status of your email forwarding profile is Running (
    ).
  6. (Optional) You can use the running Email forwarding profile to forward past logs spanning up to 3 days.