nerdexam
Palo_Alto_Networks

PCCSE · Question #131

An administrator has a requirement to ingest all Console and Defender logs to Splunk. Which option will satisfy this requirement in Prisma Cloud Compute?

The correct answer is C. Enable the syslog option in the Console. To forward all Console and Defender logs to an external SIEM like Splunk, the correct method is to enable the syslog option in the Prisma Cloud Compute Console (C). Syslog provides a comprehensive, standardized stream of all log data - including both Console and Defender logs…

Security Operations and Incident Response

Question

An administrator has a requirement to ingest all Console and Defender logs to Splunk. Which option will satisfy this requirement in Prisma Cloud Compute?

Options

  • AEnable the API settings for logging.
  • BEnable the CSV export in the Console.
  • CEnable the syslog option in the Console
  • DEnable the Splunk option in the Console.

How the community answered

(50 responses)
  • A
    6% (3)
  • B
    2% (1)
  • C
    80% (40)
  • D
    12% (6)

Explanation

To forward all Console and Defender logs to an external SIEM like Splunk, the correct method is to enable the syslog option in the Prisma Cloud Compute Console (C). Syslog provides a comprehensive, standardized stream of all log data - including both Console and Defender logs - which Splunk can ingest via a syslog listener. The API settings (A) and CSV export (B) are not designed for continuous log streaming. While Prisma Cloud does have alert integrations, syslog is the mechanism for comprehensive log forwarding.

Topics

#Prisma Cloud Compute#Log Management#SIEM Integration#Syslog

Community Discussion

No community discussion yet for this question.

Full PCCSE Practice