Chapter 1: Centralizing Logs
In this chapter, we will take a closer look at how to forward firewall logs to an external system and discuss some of the benefits. Logs can be forwarded to an external Security Incident and Event Management System (SIEM) and can be used to create a range of alerts whenever an interesting event occurs. You will learn how to set up the configuration and apply best practices when dealing with log forwarding. We will then review how logs can be forwarded to Panorama and log collectors, as well as how to leverage alternative log protocols such as syslog. We will also cover how to troubleshoot forwarding issues and how to apply filters to forwarding profiles to specify which log events are forwarded.
In this chapter, we are going to cover the following main topics:
- Understanding log forwarding profiles and best practices
- Learning about Panorama and log collectors
- Forwarding logs to syslog, SMTP, and other options
- Exploring log forwarding profiles
- Troubleshooting logs and log forwarding