Configure PaloAlto Devices
Netwrix Auditor relies on native syslog events for collecting audit data. Therefore, successful change and access auditing requires a certain configuration of native audit settings in the audited environment. Proper audit configuration ensures audit data integrity; otherwise, your change reports may contain warnings, errors, or incomplete audit data.
CAUTION: Exclude the folder associated with Netwrix Auditor from antivirus scanning. See the Antivirus Exclusions for Netwrix Auditor knowledge base article for additional information.
Configure native audit settings manually on the Palo Alto device via the web interface to ensure Netwrix Auditor collects comprehensive and reliable audit data. Create a syslog server profile and assign it to the log settings for each log type.
Configure a syslog server profile
Step 1 – Connect to your PaloAlto device: launch an Internet browser and enter the IP address of
the firewall in the URL field (https://<IP address>).
Step 2 – In the Web Interface, navigate to Device > Server Profiles > Syslog.
Step 3 – Click Add and specify profile name, for example, "SyslogProf1".
Step 4 – Specify syslog server parameters:
| Parameter | Description |
|---|---|
| Name | Specify unique name for a syslog server. |
| Syslog Server | Provide a server name by entering its FQDN or IPv4 address. |
| Transport | Select UDP. |
| Port | Provide the name of the UDP port that Netwrix Auditor uses to listen to network devices (port 514 by default). |
| Format | Select IETF. |
| Facility | Netwrix recommends using default values. |
Configure syslog forwarding
Step 1 – In the Web Interface, navigate to Device > Log Settings.
Step 2 – For System, Config, and User ID logs, click Add and enter unique name of your syslog server.
Step 3 – On the syslog panel, click Add and select the syslog server profile you created in Configure a syslog server profile.
Step 4 – Click Commit and review the logs on the syslog server.
NOTE: After you configure the monitoring plan, Netwrix Auditor listens to the logs that the Palo Alto device forwards.
PaloAlto Devices
Review a full list of object types Netwrix Auditor can collect on PaloAlto network devices.
| Object type | Actions | Event ID |
|---|---|---|
| Logon | - Successful logon | - logged in |
| - Failed logon | - failed authentication for user - authentication failed for user | |
| Authentication | - Successful Logon | - authentication succeeded for user - USERID,login, - globalprotectportal-auth-succ |
| - Failed Logon | - authentication failed for user - globalprotectportal-auth-fail | |
| Configuration | - Modified / Modify (Failed attempt) | - commit |
| Environment | - Read / Read (Failed attempt) | - connect-server-monitor-failure |
| Session | - Logoff | - logged out |
| User | - Add / Added (Failed attempt) | - config mgt-config users - config shared local-user-database user |
| - Modified / Modify (Failed attempt) | - config mgt-config users - config shared local-user-database user | |
| - Removed / Remove (Failed attempt) | - config mgt-config users - config shared local-user-database user |