Symptom
When Palo Alto Strata Logging Service (SLS) sends syslog over TLS to a Cribl.Cloud syslog endpoint, the connection fails with a certificate validation error in the SLS GUI:
Path does not chain with any of the trust anchors
Environment
- Cribl.Cloud Syslog source using TLS
- Palo Alto Strata Logging Service (SLS)
Resolution
-
Obtain the certificate file recommended by Palo Alto Support for the affected SLS environment: b1bc968bd4f49d622aa89a81f2150152a41d829c.pem
-
Import the certificate into the Palo Alto certificate store used for server authentication and Syslog/HTTPS forwarding.
-
Ensure the certificate is trusted for the applicable logging service.
-
Retest the TLS syslog connection.
Cribl’s general documentation recommends importing the GTS Root R1 and WR1 certificates and marking them as trusted root CAs on Palo Alto devices. However, importing these certificates alone may not resolve this SLS-specific trust-path failure.
Cause
The Cribl.Cloud endpoint uses a certificate issued by Google Trust Services (GTS). Palo Alto may fail to build a trusted certificate path for the Google chain because the required root certificate is cross-signed by GlobalSign CA and is not trusted in the SLS certificate store.
This is a Palo Alto validation issue, not necessarily a missing certificate from Cribl.Cloud. Cribl’s endpoint can present the same certificate chain successfully to other clients.
