On
May 7, 2025,
Palo Alto Networks is introducing new
Evidence Storage and
Syslog Forwarding service IP
addresses to improve performance and expand availability for these services
globally.
| Where Can I Use This? | What Do I Need? |
- NGFW (Managed by Panorama or Strata Cloud Manager)
- Prisma Access (Managed by Panorama or Strata Cloud Manager)
Prisma Browser
|
Or any of the following licenses that include the Enterprise DLP license
- Prisma Access CASB license
- Next-Generation
CASB for Prisma Access and NGFW (CASB-X) license
- Data Security license
|
To store files scanned by Enterprise Data Loss Prevention (E-DLP), you must specify the SFTP server
connectivity information to upload and write files to a target location on the SFTP
server. Enterprise DLP creates a reportId folder
on first upload to your SFTP server and uploads all subsequent files to the
reportId folder within your folder path. Enterprise DLP automatically names files using the SFTP target folder location,
default reportId folder, and filename.
The following special characters in a file name are not supported and prevent Enterprise DLP from saving files to SFTP storage: '/ \ * ?
<>'. If you have a file name that includes one of these special
characters, you must change the special character to an underscore
(_) so Enterprise DLP can save a copy of the
file.
Enterprise DLP automatically sends email alerts to the data security
administrator who originally connected Enterprise DLP to the SFTP storage
bucket and to the data security admin who last modified the storage bucket settings
in case of connection issues. Enterprise DLP sends the email alert every 48
hours until you restore the connection between Enterprise DLP and the storage
bucket.
Files not scanned while
Enterprise DLP is disconnected from your storage
bucket can't be stored and are lost. This means that all impacted files are not
available for download. However, your data security administrator can still view
all snippet data associated with the
DLP incident.
Enterprise DLP automatically resumes forwarding files to your storage bucket
after you restore the connection.
This procedure assumes you have already set up an SFTP server to save evidence for
investigative analysis.