TLS Syslog log source parameters for Palo Alto PA Series

If IBM® QRadar® does not automatically detect the log source, add a Palo Alto PA Series log source on the QRadar Console by using the TLS Syslog protocol.

When you use the TLS Syslog protocol, there are specific parameters that you must configure.

The following table describes the parameters that require specific values to collect TLS Syslog events from Palo Alto PA Series:
Table 1. TLS Syslog log source parameters for the Palo Alto PA Series DSM
Parameter Value
Log Source type Palo Alto PA Series
Protocol Configuration TLS Syslog
Log Source Identifier An IP address or hostname to identify the log source.

For a complete list of TLS Syslog protocol parameters and their values, see TLS Syslog protocol configuration options.