Initialize the Prisma Cloud Beat

Prerequisites

  • Open Collector is installed. If you have not already installed it, follow the instructions in the Open Collector Installation and User Guide, and then return to this topic.

  • API URL (These are specific to audit and alert logs, and the version of these APIs depends on the users. For example, https://api.prismacloud.io/alert).

  • Prisma Cloud Access Key ID (User-provided).

  • Prisma Cloud Secret Key (User-provided).

  • The following port is open:

    Direction

    Port

    Protocol

    Source

    Outbound

    443

    HTTPS

    prismacloudbeat

Initialize the Beat via the Web Console (Recommended)

  1. Ensure that the Open Collector Connection to the SIEM (WebUI) setup has been completed.

  2. Ensure that the System Monitor Agent to which you intend to send these logs has been Configured for JSON Parsing.

Use either the Enable JSON Parsing on System Monitor Agents or the Enable JSON Parsing for an Existing System Monitor Agent sections at the above link to configure the System Monitor Agent for JSON Parsing.

  1. Follow the steps outlined in Add a Beat in the Web Console to create the Beat via the Web UI.

Initialize the Beat via Command Line (Legacy)

  1. Confirm Open Collector is running:

    ./lrctl status
    

    You should see the open_collector and metrics versions.
    If Open Collector is not running correctly, see Troubleshoot the Open Collector in the Open Collector Installation and User Guide.

  2. Start the beat:

    ./lrctl prismacloudbeat start
    
  3. Select New prismacloudbeat instance from the list and press Enter.

  4. Enter a unique identifier for this Prisma Cloud Beat instance and press Enter.

  5. Enter the Prisma Cloud Audit API URL and press Enter.

    Create a new Prisma Cloud Beat instance with the Alert API URL to collect Prisma Cloud CSPM Alert logs simultaneously.

  6. Enter the Prisma Cloud Client ID (the Access Key ID obtained in the Configure Prisma Cloud topic), and press Enter.

  7. Enter the Prisma Cloud Client Secret (the Secret Key obtained in the Configure Prisma Cloud topic), and press Enter.

    For security purposes, the Client ID and Client Secret are stored in an encrypted format.

    The prismacloudbeat service started message appears.

  8. Check the status of the service by entering the following command:

    ./lrctl prismacloudbeat status
    

    Currently, the Prisma Cloud Beat doesn't support log parsing. All collected logs appear under the "Logrhythm - Open Collector" log source.

For commands to inspect or edit a configuration, see the configuration information in Open Collector Installation Tips.