-
Configure PAN-OS to output events in Common Event Format (CEF). See the PAN-OS CEF Configuration Guide for instructions.
The vendor documentation references ArcSight, but it applies to USM Anywhere as well.
-
Add a syslog server profile. See the PAN-OS Administrator’s Guide on Configure Syslog Monitoring for instructions.
- For Syslog Server, enter the IP address of the USM Anywhere Sensor.
- Select the transport protocol you want to use. USM Anywhere supports UDP, TCP, and TLS.
- The port number depends on the transport protocol you choose. Use 514 for UDP, 601 for TCP, or 6514 for TLS.
- Configure syslog forwarding on PAN-OS. See the PAN-OS Administrator’s Guide on Configure Log Forwarding for instructions.
The syslog messages from PAN-OS do not include the time zone setting on the device, so USM Anywhere assumes that all time occurs in Coordinated Universal Time (UTC), which is used by most devices. If your Palo Alto Network device is using a different time zone than UTC, the time information in the events will appear wrong. To correct this, configure your Palo Alto Network device to use UTC instead. See PAN-OS Web Interface Reference on Device Management for instructions.