Skip to main content

Nasuni File Services

Parsing and modeling rules for Nasuni File Services logs via syslog

Nasuni File Services

This pack supports Syslog-based log ingestion from Nasuni File Services and includes parsing and modeling rules (XDM mapping) for Cortex XSIAM.

Supported Event types

Volume audit logs.

Configuration on Nasuni File Services Side

  1. Log in to the Nasuni Management Console (NMC) with admin rights.
  2. Go to: Volumes.
  3. For each relevant volume:
    • Ensure File System Auditing is enabled.
    • Set Output Type to Syslog.
  4. Go to: Filers > Syslog Export Settings.
  5. Select the Edge Appliance(s) and click Edit Filers.
  6. In the Servers text box enter the IP or Hostname of your Broker VM in the following format - IP:port (example - <your-broker-ip>:<port>).
    If no port is specified it will default to UDP 514 (the system support log forwarding via UDP only).
  7. Set the following settings:
    • Send Auditing Messages: On.
    • Facility: local1 (recommended).
    • Log Level: Info or higher.
  8. Click Save Settings.

Log format

Nasuni audit logs are sent in RFC 5424 syslog format with a JSON payload.

Collect Events from Proofpoint Protection Server

In order to use the collector, use the Broker VM option.

Broker VM side

To create or configure the Broker VM, use the information described here.

You can configure the specific vendor and product for this instance.

  1. Navigate to Settings > Configuration > Data Broker > Broker VMs.
  2. Go to the apps tab and add the Syslog app. If it already exists, click the Syslog app and then click Configure.
  3. Click Add New.
  4. When configuring the Syslog Collector, set the following values (not relevant for CEF and LEEF formats):
    -----------------------------------------------------------------------------------------------------------------------------------------------------------
    | Parameter: : | Value : |
    |-------------------------|-------------------------------------------------------------------------------------------------------------------------------|
    | Protocol | Select UDP |
    | Port | Enter the port that Cortex XSIAM Broker VM should listen on for receiving forwarded events from NMC |
    | Vendor | Enter nasuni |
    | Product | Enter file_services |

PUBLISHER

PLATFORMS

Cortex XSIAM

INFO

CertificationRead more
Supported ByCortex
CreatedApril 7, 2025
Last ReleaseApril 7, 2025

DISCLAIMER
Content packs are licensed by the Publisher identified above and subject to the Publisher’s own licensing terms. Palo Alto Networks is not liable for and does not warrant or support any content pack produced by a third-party Publisher, whether or not such packs are designated as “Palo Alto Networks-certified” or otherwise.