Forward Logs to OCI Bucket
Focus
Focus
Strata Logging Service

Forward Logs to OCI Bucket

Table of Contents

Forward Logs to OCI Bucket

Learn how to forward logs from the Strata Logging Service to an Oracle Cloud Infrastructure (OCI) Storage Bucket.
Where Can I Use This?What Do I Need?
One of these:
Strata Logging Service™ (SLS) allows you to forward logs to an Oracle Cloud Infrastructure (OCI) Storage Bucket for long-term retention, compliance auditing, and external analysis. By integrating your logging infrastructure with OCI, you can leverage cloud-native storage to manage large volumes of security data efficiently.
Use OCI log forwarding when you need to archive network traffic, threat, and system logs outside of the Palo Alto Networks® ecosystem for custom reporting or third-party security information and event management (SIEM) integration.
Before you begin, ensure you have your OCI Bucket Name, Region, Namespace, Secret Key, and Access Key ID.
  1. Enable communication between the Strata Logging Service and your OCI account (Access the Customer Secret Keys).
    1. Click the Profile icon in the top-right corner of the console.
    2. Select User Settings (or My Profile) and Select Tokens and keys Customer Secret Keys from the left-hand menu.
    3. To open the configuration dialog, click Generate Secret Key.
    4. In the Name field, enter a descriptive name for the key (for example, Bucket-Access-Key).
    5. Click Generate Secret Key.
      Copy the Secret Key and save it in a secure location. OCI displays this secret key only once. If you lose it, you must generate a new one.
    6. Click Close.
    7. Locate your new key in the Customer Secret Keys table. Record the string in the Access Key column; this is your Access Key ID.
  2. Sign In to the hub.
  3. Select the Strata Logging Service instance that you want to configure for log forwarding.
    If you have multiple Strata Logging Service instances, click the Strata Logging Service tile and select an instance from the list of those available.
    If you are using Strata Cloud Manager to manage Strata Logging Service, click System SettingsStrata Logging ServiceLog Forwarding to forward logs to an external server.
  4. Select Log ForwardingCloud Storage to add a new OCI log forwarding profile.
  5. Configure the log forwarding profile to forward logs to Cloud Storage.
    1. Enter a unique descriptive Profile Nameto identify this forwarding configuration.
    2. Select the Oracle Cloud Bucket option under Cloud Storage to enable OCI-specific fields.
    3. Enter the Bucket Name exactly as it appears in your OCI console.
    4. Enter the Region where your bucket is hosted
    5. Enter your Access Key ID.
    6. Enter your OCI Secret Key in the provided field.
    7. Enter the OCI Bucket Namespace associated with your OCI tenancy.
  6. To confirm the credentials and bucket details are valid, click Test Connection.
    This sends an empty log to the configured destination to verify that transmission is possible.
    If the test fails, you won't be able to proceed.
  7. After you see the Test Connection successful! message, click OK to save your changes.
  8. Specify the Payload Format as JSON - the log format in which the Strata Logging Service forwards logs.
  9. (Optional) To receive a STATUS NOTIFICATION when the Strata Logging Service is unable to connect to the OCI, enter the email address at which you’d like to receive the notification.
    You will continue to receive these notifications at least once every 60 minutes until connectivity is restored. If the connectivity issue is addressed within 72 hours, no logs will be lost. However, any log older than 72 hours following the service disconnection could be lost.
  10. Select the log type , Log source and optionally write a query to create filter to forward only the logs that are most critical to you. Save your changes
    If you want to forward all logs of the type you selected, do not enter a query.
  11. Click Ok to complete the profile configuration.
  12. Verify that the Status of your forwarding profile is Running (
    ).
  13. (Optional) You can use the running OCI forwarding profile to forward past logs spanning up to 3 days.