Activate Cortex Data Lake
Table of Contents
Expand all | Collapse all
-
- Cortex Data Lake for Panorama-Managed Firewalls
- Start Sending Logs to a New Cortex Data Lake Instance
- Configure Panorama in High Availability for Cortex Data Lake
- Allocate Storage Based on Log Type
- View Cortex Data Lake Status
- View Logs in Cortex Data Lake
- TCP Ports and FQDNs Required for Cortex Data Lake
- Sizing for Cortex Data Lake Storage
-
- Forward Logs from Cortex Data Lake to a Syslog Server
- Forward Logs from Cortex Data Lake to an HTTPS Server
- Forward Logs from Cortex Data Lake to an Email Server
- Log Record Formats
- Create Log Filters
- Server Certificate Validation
- List of Trusted Certificates for Syslog and HTTPS Forwarding
- Log Forwarding Errors
Activate Cortex
Data Lake
Cortex
Data Lake
This is how you activate
Cortex
Data Lake
.After purchasing
Cortex
Data Lake
, you should have received an email with a
link to activate Cortex
Data Lake
. Click on the link and follow
the steps below to complete activation.You do not need to follow this procedure if you have already activated
Cortex
Data Lake
as part of another product purchase (for example,
Prisma Access
).If you are using PAN-OS 10.0 or later firewalls, and if you were sharing telemetry data with Palo
Alto Networks prior to purchasing a
Cortex
Data Lake
license,
then you already have a small, unlicensed Cortex
Data Lake
instance. This instance exists solely for the purpose of storing your PAN-OS
telemetry data. When you activate your license Palo Alto Networks will upgrade this tenant to a full
Cortex
Data Lake
instance, so long as the region you use to send
telemetry data to Palo Alto Networks is the same region that you use when you
activate your Cortex
Data Lake
license. If you use different
regions for this purpose, then the small telemetry-specific tenant will not
upgrade to your new, licensed Cortex
Data Lake
instance. - Click on the link in your purchase confirmation email.
- Select yourCortex Data Lakesubscription and clickActivate Subscription.
- Log in to the hub with your Palo Alto Networks Customer Support credentials.
- Select the customer support account that you want to associate with your subscription.
- If you are activating theCortex Data Lakeinstance in a new tenant service group (TSG), selectCreate Newfrom the Tenant drop-down list and then enter a tenant name.OrIf you want to add theCortex Data Lakeinstance to an existing TSG, select the TSG from the drop-down list. A tenant can have only oneCortex Data Lakeinstance running on it.
- Select the geographicalRegionfor yourCortex Data Lakeinstance.
- Add aCortex Data Lakeinstance to the TSG.
- Verify the storage space and region for yourCortex Data Lakeinstance. The default storage space forCortex Data Lakedata is set to 10 TB.If you choose to store data (after activation, onboard and configure your device and clickInventory> turn onStore Log Datato store log data),Cortex Data Lakewill keep a record of your logs for future reference. If you choose not to,Cortex Data Lakewill delete the logs after they are used for whatever analytics services you have subscribed to (for example, IoT Security), without saving a copy.
- Review your selections, Agree to the Terms and Conditions, and clickActivate Now.
- Onboard devices to Cortex Data Lake, then configure your devices to send logs to Cortex Data Lake, and configure your log storage settings.