PCCSE · Question #131
An administrator has a requirement to ingest all Console and Defender logs to Splunk. Which option will satisfy this requirement in Prisma Cloud Compute?
The correct answer is C. Enable the syslog option in the Console. To forward all Console and Defender logs to an external SIEM like Splunk, the correct method is to enable the syslog option in the Prisma Cloud Compute Console (C). Syslog provides a comprehensive, standardized stream of all log data - including both Console and Defender logs…
Question
An administrator has a requirement to ingest all Console and Defender logs to Splunk. Which option will satisfy this requirement in Prisma Cloud Compute?
Options
- AEnable the API settings for logging.
- BEnable the CSV export in the Console.
- CEnable the syslog option in the Console
- DEnable the Splunk option in the Console.
How the community answered
(50 responses)- A6% (3)
- B2% (1)
- C80% (40)
- D12% (6)
Explanation
To forward all Console and Defender logs to an external SIEM like Splunk, the correct method is to enable the syslog option in the Prisma Cloud Compute Console (C). Syslog provides a comprehensive, standardized stream of all log data - including both Console and Defender logs - which Splunk can ingest via a syslog listener. The API settings (A) and CSV export (B) are not designed for continuous log streaming. While Prisma Cloud does have alert integrations, syslog is the mechanism for comprehensive log forwarding.
Topics
Community Discussion
No community discussion yet for this question.