Security Compliance

Integrate Palo Alto firewalls with SEM

This article describes how to configure Palo Alto firewalls and the following Palo Alto Networks to connect to your SEM appliance: PA-2000 Series PA-4000 , PA-5000 Series etc

First published date

10/10/2018 2:02 AM

Last published date

9/1/2022 7:03 AM

Overview

This article describes how to configure Palo Alto firewall devices to sent logs to SEM(formerly LEM) appliance:

  • PA-2000 Series
  • PA-4000 Series
  • PA-5000 Series

Product section

Security Event Manager

Cause

N/A

Resolution

Please refer to the below sections in Palo Alto Administrator's Guide on how to configure your firewall to send syslog messages SEM appliance:

  • Defining Configuration and System Log Settings
  • Defining Log Forwarding Profiles

Note: The default logging facility used in the SEM connector for Palo Alto firewalls is local5. If you have choosen a different logging facility during your firewall configuration in Palo Alto Syslog Profile Settings - take a note of that and use in the next steps.

Part 1: Configure A Syslog Profile in Palo Alto
1. Login to Palo Alto Config web console
2. Click on Device tab

3. Click on Syslog under Server Profiles
4. Select a profile OR add new one if none exists
5. Enter Syslog(SEM) server details like Name/IP, Port, Protocol and Facility and leave format default (BSD) as shown below.

6. On Custom log format tab, ensure all logs are set to default and not Custom

7. Save and apply the changes

Part 2: Configure the SEM connector for Palo Alto

SEM HTML5 console (versions 6.6 and newer)

  1. In the SEM Events Console, navigate to Nodes > Manager Connectors.
  2. In the search box, enter Palo Alto.
  3. Select the Palo Alto Network Firewalls connector, and then click Add connector.
  4. Enter a unique name, or accept the default.  
  5. Verify that the Log File value matches the Facility value you selected when defining SEM as a syslog server for your firewall in Part 1 Step 5 above, and then click Add.
  6. Under Configured connectors, select the new connector, and then click Start.


SEM Flash console

  1. Open the SEM Console and log in to the SEM Manager as an administrator.
  2. Click the gear icon next to your SEM Manager and then select Connectors.
  3. In the Connector Configuration window, enter Palo Alto in the search box at the top of the Refine Results pane.
  4. Click the gear icon next to the "Palo Alto Networks PA-2000 Series and PA-4000 Series Firewall" connector, and then select New.
  5. Enter a custom Alias or accept the default.
  6. Verify that the Log File value matches the Facility value you selected when defining SEM as a syslog server for your firewall in Part 1 Step 5 above.
  7. Click Save.
  8. Click the gear icon next to the new connector, and then click Start.
  9. Click Close. 
If everything is fine, then SEM should detect the Palo Alto Device as a new node automatically once it starts receiving logs from Palo Alto.

If no new node is found in SEM web console then refer to Troubleshooting Network Devices Logging to SEM.

Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment.  You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.