PSE-STRATA-PRO-24 · Question #49
There are no Advanced Threat Prevention log events in a company's SIEM instance. However, the systems administrator has confirmed that the Advanced Threat Prevention subscription is licensed and…
The correct answer is D. Ensure the Security policy rules that use Advanced Threat Prevention are set for log forwarding to. Understanding the Problem: The issue is that Advanced Threat Prevention (ATP) logs are visible on the firewall but are not being ingested into the company's SIEM. This implies that the ATP subscription is working and generating logs on the firewall but the logs are not being…
Question
There are no Advanced Threat Prevention log events in a company's SIEM instance. However, the systems administrator has confirmed that the Advanced Threat Prevention subscription is licensed and that threat events are visible in the threat logs on the firewall. Which action should the systems administrator take next?
Options
- AEnable the company's Threat Prevention license.
- BCheck with the SIEM vendor to verify that Advanced Threat Prevention logs are reaching the
- CHave the SIEM vendor troubleshoot its software.
- DEnsure the Security policy rules that use Advanced Threat Prevention are set for log forwarding to
How the community answered
(38 responses)- A3% (1)
- B11% (4)
- C3% (1)
- D84% (32)
Explanation
Understanding the Problem: The issue is that Advanced Threat Prevention (ATP) logs are visible on the firewall but are not being ingested into the company's SIEM. This implies that the ATP subscription is working and generating logs on the firewall but the logs are not being forwarded properly to the SIEM. Action to Resolve: Log Forwarding Configuration: Verify that the Security policy rules configured to inspect traffic using Advanced Threat Prevention are set to forward logs to the SIEM instance. This is a common oversight. Even if the logs are generated locally, they will not be forwarded unless explicitly configured. Configuration steps to verify in the Palo Alto Networks firewall: Go to Policies > Security Policies and check the "Log Forwarding" profile applied. Ensure the "Log Forwarding" profile includes the correct settings to forward Threat Logs to the Go to Device > Log Settings and ensure the firewall is set to forward Threat logs to the desired Syslog or SIEM destination.
Topics
Community Discussion
No community discussion yet for this question.