Forward Logs from Cortex Data Lake to an Email Server
Expand all | Collapse all
Forward Logs from Cortex Data Lake to an Email Server
Learn how to forward logs from Cortex Data Lake to an
email server.
To get email notifications whenever critical
issues occur on your network, you can configure Cortex Data Lake
to send notifications to an email destination. Cortex Data Lake
uses the Palo Alto Networks SMTP server to forward log information
in an email format, and all emails are sent from noreply@cs.paloaltonetworks.com. The
communication between Cortex Data Lake and the email destination
uses SMTP over TLS, and SMTP server certificate is signed by a trusted
root CA.
Select the Cortex Data Lake instance that you want to
configure for email forwarding.
If you have multiple Cortex Data Lake instances, hover
over the Cortex Data Lake tile and then select an instance from
the list of available instances.
Configure email forwarding.
You cannot add your SMTP server to Cortex Data Lake currently.
Select to add a new email forwarding
profile.
Enter a descriptive
Name
for
the profile.
Enter the email address of the administrator
To
whom
you want to send email.
You can enter up to ten additional email addresses, separated
by commas, to add as
BCC
.
Enter the
Email Subject
to
clearly identify the purpose of the notification.
Select the logs you want to forward.
You can
either write your own queries from scratch or use
the query builder. You
can also select the query field to choose from among a set of common
predefined queries.
No subnet masks. To return IP addresses with subnets, use
the
LIKE
operator. Example:
src_ip.value LIKE
“192.1.1.%”
.
If
you want to forward all logs of the type you selected, do not enter
a query. Instead, proceed to the next step.
Add other log types for which you’d like to receive email
notifications.
Email forwarding is rate limited to allow 10 emails
per second.
Verify that the
Status
of
your email forwarding profile is
Running
(

).