On-Prem

Panther Log Forwarder

Get on-premises logs into Panther without the infrastructure overhead.

Integration Overview

Not every log source lives in the cloud. For on-premises infrastructure, like servers, network devices, and legacy applications, Panther Log Forwarder is a lightweight agent that collects logs from files or syslog and forwards them to Panther over HTTPS. It runs as a systemd service on Linux, requires no cloud credentials, and includes built-in disk buffering to prevent data loss during network disruptions.

Use Cases

  • Forward logs from on-premises servers, appliances, and legacy applications that can't push directly to cloud-based log sources

  • Receive syslog over TCP or UDP from network devices and route them to Panther

  • Tail application log files and stream new entries to Panther in near real-time

  • Buffer logs locally during network outages and deliver them once connectivity is restored

Getting Started

Panther Log Forwarder runs on Linux (x86_64 and ARM64) with systemd, supporting Ubuntu 20.04+, Debian 11+, RHEL 8+, and Rocky Linux 8+. Download the latest release, run the installer, and configure a forwarder YAML file pointing at your Panther HTTP source. Logs typically appear in Data Explorer within a few minutes.

For full setup instructions, view the Panther Log Forwarder documentation here.

Share:

Seamless integration with your security stack

Unlock the full power of Panther by integrating with the tools your team already uses.

More integrations

Bolt-on AI closes alerts. Panther closes the loop.

See how Panther compounds intelligence across the SOC.

Bolt-on AI closes alerts. Panther closes the loop.

See how Panther compounds intelligence across the SOC.

Bolt-on AI closes alerts. Panther closes the loop.

See how Panther compounds intelligence across the SOC.

Bolt-on AI closes alerts. Panther closes the loop.

See how Panther compounds intelligence across the SOC.