ExamGecko
Question list
Search
Search

List of questions

Search

Question 115 - PCCSE discussion

Report
Export

An administrator has a requirement to ingest all Console and Defender logs to Splunk.

Which option will satisfy this requirement in Prisma Cloud Compute?

A.
Enable the API settings for logging.
Answers
A.
Enable the API settings for logging.
B.
Enable the CSV export in the Console.
Answers
B.
Enable the CSV export in the Console.
C.
Enable the syslog option in the Console
Answers
C.
Enable the syslog option in the Console
D.
Enable the Splunk option in the Console.
Answers
D.
Enable the Splunk option in the Console.
Suggested answer: C

Explanation:

Log into Console. / Go to Manage > Alerts > Logging. / Configure Prisma Cloud to send audit event records to syslog, stdout and Prometheus.

https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/audit/logging

To ingest all Console and Defender logs into Splunk within Prisma Cloud Compute, the most effective method is to enable the syslog option in the Console. This configuration allows the direct export of logs in a format compatible with Splunk, facilitating real-time log analysis and monitoring. This setup supports continuous security monitoring and advanced threat detection capabilities by utilizing Splunk's extensive data processing and visualization tools.

asked 23/09/2024
Razan Althubaiti
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first