For the complete documentation index, see llms.txt. This page is also available as Markdown.

Ingest data from Cloud Next-Generation Firewall

Notice

Requires the Data Collection add-on.

Cloud Next-Generation Firewall (CNGFW) is a fully managed, cloud-native security service from Palo Alto Networks. Enabling CNGFW data collection allows for the ingestion of CNGFW logs into the platform by establishing a dedicated connector within the existing data source configuration flow. The connection is established at the CSP account. You can connect resources regardless of whether they are managed by Strata Cloud Manager (SCM). The interface supports:

  • Connecting CNGFW to the current account

  • Connecting CNGFW from other accounts

Cortex products utilize the Cloud Logging Collection Service (CLCS), a pub/sub service, and the Strata Logging Service (SLS) to stream this data. Adding and removing CNGFW devices is recorded in audit logs, and users can view the consent audit during the process. Any issues related to CNGFW logs are created in the same manner as traditional NGFW issues.

Prerequisite

Supported log types and datasets

Once ingested, your data is stored in the panw_ngfw_*_raw datasets. You can query this data using Cortex Query Language (XQL).

Note

When using a multi-tenant firewall with virtual system (vsys) instances, the _reporting_device_name field presents the NGFW instance name, vsys_name, and vsys_id using the following format; log_source_name>-<vsys_name>-<vsys_id>.

The following log types are supported for CNGFW ingestion:

Log Type
Dataset Name

Authentication Logs

panw_ngfw_auth_raw

Configuration Logs

panw_ngfw_config_raw

File Data Logs

panw_ngfw_filedata_raw

Global Protect Logs

panw_ngfw_globalprotect_raw

Hipmatch Logs

panw_ngfw_hipmatch_raw*

System Logs

panw_ngfw_system_raw

Threat Logs

panw_ngfw_threat_raw*

Traffic Logs

panw_ngfw_traffic_raw*

Tunnel Logs

panw_ngfw_tunnel_raw

URL Logs

panw_ngfw_url_raw*

User ID Logs

panw_ngfw_userid_raw

*Note: These datasets use the query field names as described in the Cortex schema documentation. For more information about the logs, see Strata Logging Service Log Reference.

How to ingest detection data from CNGFW:
  1. Select SettingsData Sources & Integrations

  2. On the Data Sources & Integrations page, click + Add New, search for CNGFW, then hover over and click Add.

  3. In the Add Cloud Next-Generation Firewall dialog box, you can choose to connect CNGFW to this account or other accounts.

    • To connect CNGFW from the current account, select Connect Cloud NGFW from current account (default), and select the applicable regions.

    • To connect CNGFW from another account, select Connect Cloud NGFW from other accounts and select the applicable regions for the other accounts. You can search and multi-select accounts by account number, account name, or region. For cross-account connections, you must have Super User permissions on the CSP account and the device account.

      Important

      This cross-account support is limited to the same SFDC hierarchy; it does not extend to MSSP scenarios where the customer and provider own separate ends of the solution.

    Depending on the regions selected, you may need to read the Cloud NGFW Connection from other regions disclaimer and approve the CNGFW connection.

    Note

    If you change a device region, you must first disconnect the device from Cortex Cloud and then reconnect it after the region change is complete.

  4. Click Connect to establish the instance.

    Connection is established regardless of the firewall credential status and can take up to several minutes, select Sync now to refresh your instances.

Last updated

Was this helpful?