IncidentResponsev2

PAN Forward Syslog to Security Onion

Task

Configure Palo Alto Networking Device to forward all alerts and logs to Security Onion Syslog server for ingestion and analysis.


Conditions

Given a Palo Alto Networking device and Security Onion / Syslog server.


Standards


End State

Logs from PAN firewall are forwarded to Security Onion, parsed by NIDS and available for analysis and alerting.


Notes


Manual Steps

Step 1: Access Palo Alto WebUI

Step 2: Configure Syslog Service Route

ScreenShots


Step 3: Create Syslog Server Profile

ScreenShots

Operator Note: Use TCP where reliable delivery is mandatory.


Step 4: Create Security Profiles

Antivirus

ScreenShots ScreenShots

Anti-Spyware

ScreenShots ScreenShots ScreenShots

DNS Signatures

ScreenShots

Vulnerability Protection

ScreenShots ScreenShots

URL Filtering

ScreenShots ScreenShots

File Blocking

ScreenShots ScreenShots


Step 5: Create Security Profile Group

ScreenShots ScreenShots


Step 6: Create Log Forwarding Profile

ScreenShots ScreenShots


Step 7: Apply Security Profiles to Security Policy

ScreenShots


Step 8: Configure Log Settings for System/Configuration Events

ScreenShots ScreenShots ScreenShots ScreenShots ScreenShots ScreenShots


Step 9: Commit Changes

Operator Note: Always add change description → assists during audit or troubleshooting.


Step 10: Validate Logging


Dependencies


Other Available Tools

Tool Platform Installation Usage
Wireshark Cross-platform Package manager Validate syslog traffic arriving

Operator Recommendations and Additional Tools

Operator Checklist

Best Practices


References

PAN OS 9.0 Admin Guide
PAN Syslog Setup KB


Revision History

Date Version Description Author
2025-05-02 1.0 Corrected and expanded version preserving original + operator guidance Leo