Ingest data from Cloud Next-Generation Firewall
Cloud Next-Generation Firewall (CNGFW) is a fully managed, cloud-native security service from Palo Alto Networks. Enabling CNGFW data collection allows for the ingestion of CNGFW logs into the platform by establishing a dedicated connector within the existing data source configuration flow. The connection is established at the CSP account. You can connect resources regardless of whether they are managed by Strata Cloud Manager (SCM). The interface supports:
Connecting CNGFW to the current account
Connecting CNGFW from other accounts
Cortex products utilize the Cloud Logging Collection Service (CLCS), a pub/sub service, and the Strata Logging Service (SLS) to stream this data. Adding and removing CNGFW devices is recorded in audit logs, and users can view the consent audit during the process. Any issues related to CNGFW logs are created in the same manner as traditional NGFW issues.
Prerequisite
Cortex Cloud RBAC permissions: Requires View/Edit permissions for Data Sources (under Configurations → Data Collections).
Cloud Service Provider (CSP) account permissions: Configuration of data ingestion from multiple accounts and regions requires Super User permissions on both the Cortex Cloud tenant and on the device accounts.
Last updated
Was this helpful?
