Fortinet black logo

External Systems Configuration Guide

Palo Alto Traps Endpoint Security Manager

Palo Alto Traps Endpoint Security Manager

What is Discovered and Monitored

Protocol Information Discovered Data Collected Used for
Syslog (CEF format) - Over 150 event types Security and Compliance

Event Types

In RESOURCES > Event Types, search for "PAN-TrapsESM" in the main content panel Search... field.

Sample Event Type

Sep 28 2016 17:38:48 172.16.183.173 CEF:0|Palo Alto Networks|Traps Agent|3.4.1.16709|Traps Service Status Change|Agent|6|rt=Sep 28 2016 17:38:48 dhost=traps-win7x86 duser=Traps msg=Agent Service Status Changed: Stopped-> Running
Sep 28 2016 17:42:04 ESM CEF:0|Palo Alto Networks|Traps ESM|3.4.1.16709|Role Edited|Config|3|rt=Sep 28 2016 17:42:04 shost=ESM suser=administrator msg=Role TechWriter was added\changed

Configuration

Configure Palo Alto Traps Endpoint Security Manager to send syslog on port 514 to FortiSIEM.

Palo Alto Traps Endpoint Security Manager

Palo Alto Traps Endpoint Security Manager

What is Discovered and Monitored

Protocol Information Discovered Data Collected Used for
Syslog (CEF format) - Over 150 event types Security and Compliance

Event Types

In RESOURCES > Event Types, search for "PAN-TrapsESM" in the main content panel Search... field.

Sample Event Type

Sep 28 2016 17:38:48 172.16.183.173 CEF:0|Palo Alto Networks|Traps Agent|3.4.1.16709|Traps Service Status Change|Agent|6|rt=Sep 28 2016 17:38:48 dhost=traps-win7x86 duser=Traps msg=Agent Service Status Changed: Stopped-> Running
Sep 28 2016 17:42:04 ESM CEF:0|Palo Alto Networks|Traps ESM|3.4.1.16709|Role Edited|Config|3|rt=Sep 28 2016 17:42:04 shost=ESM suser=administrator msg=Role TechWriter was added\changed

Configuration

Configure Palo Alto Traps Endpoint Security Manager to send syslog on port 514 to FortiSIEM.