Configure Panorama for Cortex Data Lake (10.0 or Earlier)
Table of Contents
9.1
Expand all | Collapse all
-
- Cortex Data Lake for Panorama-Managed Firewalls
- Start Sending Logs to a New Cortex Data Lake Instance
- Configure Panorama in High Availability for Cortex Data Lake
- Allocate Storage Based on Log Type
- View Cortex Data Lake Status
- View Logs in Cortex Data Lake
- TCP Ports and FQDNs Required for Cortex Data Lake
- Sizing for Cortex Data Lake Storage
-
- Forward Logs from Cortex Data Lake to a Syslog Server
- Forward Logs from Cortex Data Lake to an HTTPS Server
- Forward Logs from Cortex Data Lake to an Email Server
- Log Record Formats
- Create Log Filters
- Server Certificate Validation
- List of Trusted Certificates for Syslog and HTTPS Forwarding
- Log Forwarding Errors
Configure Panorama for Cortex Data Lake (10.0 or Earlier)
Follow these steps to activate Cortex Data Lake for Panorama-managed
firewalls running PAN-OS 10.0 or earlier.
If you’re using Panorama™ to manage Prisma™ Access or on-premises firewalls, you have some
preliminary steps to accomplish before you can activate Cortex Data Lake. These steps
include downloading and installing the Cloud Services Plugin and generating a
one-time password (OTP) in the Cortex Data Lake app.
Because Panorama can provision the device certificate that
firewalls require to securely connect to Cortex Data Lake, this
gives you a way to onboard multiple firewalls to Cortex Data Lake
simultaneously.
If you are onboarding a Panorama in high availability mode (HA),
follow the steps for configuring an
HA Panorama with Prisma Access. Instead of the step where
you install the Prisma access components on Panorama, follow the
steps for activating Cortex Data Lake below.
- To set up Panorama, install the Panorama virtual appliance and perform initial configuration or set up an M-Series appliance.You must configure one or more DNS servers and an NTP server instead of setting the date and time manually so that Panorama can stay in sync with Cortex Data Lake.
- To configure NTP, selectand set a value for thePanoramaSetupServicesNTPNTP server. For example:pool.ntp.org.
- To configure DNS servers, selectand enter a value for the primary and optionally for the secondary DNS servers.PanoramaSetupServices
- (Optional, Panorama 10.0 and later versions) To configure Panorama to connect to Cortex Data Lake through a proxy server, selectandPanoramaSetupServicesSettings (
)
Use proxy to send logs to Cortex Data Lake.
- Log in to the Customer Support Portal (CSP) and select.AssetsDevicesRegister New Device
- SelectRegister device using Serial Number or Authorization Codeand thenSubmit.
- Enter the Panorama Serial Number provided in the email you received with your order fulfillment along with the required Location Information (as indicated by the asterisks) and thenAgree and Submit the EULA.After you see the registration complete message, close the Device Registration dialog.
- Find the Panorama instance you just registered and click the corresponding edit (Actions column).
- To activate the Support license, selectActivate Auth-Codeand then enter the Support Authorization Code you received in your email and thenAgree and Submit.
- (Optional) Onboard Panorama to your Cortex Data Lake instance.This is necessary only if you did not onboard Panorama as part of activation.
- Log in to the hub and open the Cortex Data Lake app to the instance to which you are onboarding.
- Select.InventoryPanorama AppliancesAdd
- SelectAddandNext.
- Select the Panorama appliances you want to onboard andSubmit.
- Verify the Quantity and Part Description of the Cortex Data Lake license (named Logging Service below) that you just activated.
- Retrieve the Cortex Data Lake and support license on Panorama.
- SelectandPanoramaLicensesRetrieve license keys from license server.
- Verify that you see the Cortex Data Lake license and the support license.
- Download and install the Cloud Services plugin.The way you download and install the plugin depends on whether you are using Panorama 8.0.6 or a later Panorama version.On Panorama 8.0.x:
- Log in to the Customer Support Portal and select.UpdatesSoftware Updates
- Find a supported Cloud Services plugin version in the Panorama Integration Plug In section and download it. Plugin 1.0 versions are no longer supported on any version of Panorama.Do not rename the plugin file or you will not be able to install it on Panorama.
- To install the plugin, log in to the Panorama web interface of the Panorama you selected when you licensed Prisma Access, select, andPanoramaPluginsUploadBrowseto the pluginFilethat you downloaded from the CSP.
- Installthe plugin.
On Panorama 8.1.0 and later versions:On Panorama 8.1 and later versions, you can either download the plugin from the CSP and then upload it to Panorama or you can check for plugin updates directly from Panorama as follows:- SelectandPanoramaPluginsCheck Nowto display the latest Cloud Services plugin updates.
- Downloada supported plugin version.Plugin 1.0 versions 1.0.x are no longer supported on any version of Panorama.
- After you downloading the plugin,Installit.
Installing a newer version of the Cloud Services plugin overwrites the previously installed version. If you are installing the plugin for the first time, after you successfully install the plugin, Panorama will refresh and the Cloud Services menu will display on thePanoramatab. - Generate an OTP from the Inventory in the Cortex Data Lake app and copy it to your clipboard.You have ten minutes to enter the OTP before it expires.
- Go back to Panorama and selectto display the Verify Account dialog.PanoramaCloud ServicesStatus
- Paste the OTP you just generated andVerifyit.IfVerifyis disabled, check that you have configured both a DNS server and an NTP server ().PanoramaSetupServices
- Verify the connection status between Panorama and Cortex Data Lake.You can use the Panorama CLI or the Panorama web interface with the Cloud Services plugin to verify that the connection is successful.
- Use the following CLI command:admin@Panorama> request plugins cloud_services logging-service statuspass{"@status": "success", .....
- Selectand viewPanoramaCloud ServicesStatusStatusdetailsto verify that Panorama was able to successfully retrieve the Cortex Data Lake certificate, fetch the Customer Identification number and the region in which your Cortex Data Lake instance is deployed, and confirm that the Panorama appliance is connected to Cortex Data Lake (Logging Service below). If any of these checks fail, the Status is reported as anError.
- On the hub, View Cortex Data Lake Status to verify that Cortex Data Lake is provisioned successfully.
- Allocate Storage Based on Log Type. Make sure to allocate log quota for each log type because there are no log quota allocation defaults.