Palo Alto Traps Endpoint Security Manager
What is Discovered and Monitored
Protocol | Information Discovered | Data Collected | Used for |
---|---|---|---|
Syslog (CEF format) | - | Over 150 event types | Security and Compliance |
Event Types
In RESOURCE > Event Types, Search for “PAN-TrapsESM”.
Sample Event Type:
Sep 28 2016 17:38:48 172.16.183.173 CEF:0|Palo Alto Networks|Traps Agent|3.4.1.16709|Traps Service Status Change|Agent|6|rt=Sep 28 2016 17:38:48 dhost=traps-win7x86 duser=Traps msg=Agent Service Status Changed: Stopped-> Running
Sep 28 2016 17:42:04 ESM CEF:0|Palo Alto Networks|Traps ESM|3.4.1.16709|Role Edited|Config|3|rt=Sep 28 2016 17:42:04 shost=ESM suser=administrator msg=Role TechWriter was added\changed
Configuration
Configure Palo Alto Traps Endpoint Security Manager to send syslog on port 514 to FortiSIEM.