Skip to main content

Configure PaloAlto Devices

Netwrix Auditor relies on native syslog events for collecting audit data. Therefore, successful change and access auditing requires a certain configuration of native audit settings in the audited environment. Proper audit configuration ensures audit data integrity; otherwise, your change reports may contain warnings, errors, or incomplete audit data.

CAUTION: Exclude the folder associated with Netwrix Auditor from antivirus scanning. See the Antivirus Exclusions for Netwrix Auditor knowledge base article for additional information.

Configure native audit settings manually on the Palo Alto device via the web interface to ensure Netwrix Auditor collects comprehensive and reliable audit data. Create a syslog server profile and assign it to the log settings for each log type.

Configure a syslog server profile

Step 1 – Connect to your PaloAlto device: launch an Internet browser and enter the IP address of the firewall in the URL field (https://<IP address>).

Step 2 – In the Web Interface, navigate to Device > Server Profiles > Syslog.

Step 3 – Click Add and specify profile name, for example, "SyslogProf1".

Step 4 – Specify syslog server parameters:

ParameterDescription
NameSpecify unique name for a syslog server.
Syslog ServerProvide a server name by entering its FQDN or IPv4 address.
TransportSelect UDP.
PortProvide the name of the UDP port that Netwrix Auditor uses to listen to network devices (port 514 by default).
FormatSelect IETF.
FacilityNetwrix recommends using default values.

Configure syslog forwarding

Step 1 – In the Web Interface, navigate to Device > Log Settings.

Step 2 – For System, Config, and User ID logs, click Add and enter unique name of your syslog server.

Step 3 – On the syslog panel, click Add and select the syslog server profile you created in Configure a syslog server profile.

Step 4 – Click Commit and review the logs on the syslog server.

NOTE: After you configure the monitoring plan, Netwrix Auditor listens to the logs that the Palo Alto device forwards.

PaloAlto Devices

Review a full list of object types Netwrix Auditor can collect on PaloAlto network devices.

Object typeActionsEvent ID
Logon- Successful logon- logged in
- Failed logon- failed authentication for user - authentication failed for user
Authentication- Successful Logon- authentication succeeded for user - USERID,login, - globalprotectportal-auth-succ
- Failed Logon- authentication failed for user - globalprotectportal-auth-fail
Configuration- Modified / Modify (Failed attempt)- commit
Environment- Read / Read (Failed attempt)- connect-server-monitor-failure
Session- Logoff- logged out
User- Add / Added (Failed attempt)- config mgt-config users - config shared local-user-database user
- Modified / Modify (Failed attempt)- config mgt-config users - config shared local-user-database user
- Removed / Remove (Failed attempt)- config mgt-config users - config shared local-user-database user