<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Send alerts to Syslog server with TLS failing with Certificate Verification Failed in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/send-alerts-to-syslog-server-with-tls-failing-with-certificate/m-p/556953#M5099</link>
    <description>&lt;P&gt;Hi, I'm trying to configure my TLS enabled Syslog server in Cortex but not successful. I'm always getting "&lt;SPAN&gt;Test failed : Certificate Verification Failed". When I tick the "Ignore certificate errors", the error disappears and one syslog message is received successfully but getting errors after that. Can you please help me figure this out?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Syslog output:&lt;/SPAN&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;Sep  7 12:10:01 syslogtest rsyslogd: unexpected GnuTLS error -110 in nsd_gtls.c:588: The TLS connection was non-properly terminated.  [v8.2112.0 try https://www.rsyslog.com/e/2078 ]
Sep  7 12:10:01 syslogtest rsyslogd: netstream session 0x7f50900098e0 from 34.90.105.250 will be closed due to error [v8.2112.0 try https://www.rsyslog.com/e/2078 ]
Sep  7 09:10:08 cortexxdr - CEF:0|Palo Alto Networks|Cortex XDR|Cortex XDR 3.7.0|XDR Agent|Example Cortex XDR Alert|0|end=1581471661000 shost=3D4WRQ2 suser=acme\\user deviceFacility=None cat=Restrictions externalId=11148 request=https://gan.xdr.eu.paloaltonetworks.com/alerts/11148 cs1=example.exe cs1Label=Initiated by cs2=example.exe cs2Label=Initiator CMD cs3=SIGNATURE_SIGNED-Microsoft Corporation cs3Label=Signature cs4=cmd.exe cs4Label=CGO name cs5=C:\\this\\is\\example.exe /c ""\\\\host1\\files\\example.bat" " cs5Label=CGO CMD cs6=SIGNATURE_SIGNED-Microsoft Corporation cs6Label=CGO Signature fileHash=BBBBBBBE8A5E66AC3C693F9B5D3762805CF2D8F1283291AF38321FC619B23115 targetprocesssignature=SIGNATURE_UNAVAILABLE-N/A tenantname=GAN tenantCDLid=2003685740608 CSPaccountname=Vg Estonia Ou initiatorSha256=BBBBBBBE8A5E66AC3C693F9B5D3762805CF2D8F1283291AF38321FC619B23115 cgoSha256=AAAAAAc4a0b7eb191783c323ab8363ebd1fd10be58d8bcc96b07067743ca81d5 act=Detected (Reported)
Sep  7 12:10:09 syslogtest rsyslogd: unexpected GnuTLS error -110 in nsd_gtls.c:588: The TLS connection was non-properly terminated.  [v8.2112.0 try https://www.rsyslog.com/e/2078 ]
Sep  7 12:10:09 syslogtest rsyslogd: netstream session 0x7f509000e610 from 34.90.105.250 will be closed due to error [v8.2112.0 try https://www.rsyslog.com/e/2078 ]&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Syslog Config:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;global(
DefaultNetstreamDriver="gtls"
DefaultNetstreamDriverCAFile="/etc/rsyslog.d/keys/ca.pem"
DefaultNetstreamDriverCertFile="/etc/rsyslog.d/keys/server-cert.pem"
DefaultNetstreamDriverKeyFile="/etc/rsyslog.d/keys/server-key.pem"
)

module(
load="imtcp"
StreamDriver.Name="gtls"
StreamDriver.Mode="1"
StreamDriver.Authmode="anon"
)

input(type="imtcp" port="6514")&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Sep 2023 09:21:53 GMT</pubDate>
    <dc:creator>Isuru</dc:creator>
    <dc:date>2023-09-07T09:21:53Z</dc:date>
    <item>
      <title>Send alerts to Syslog server with TLS failing with Certificate Verification Failed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/send-alerts-to-syslog-server-with-tls-failing-with-certificate/m-p/556953#M5099</link>
      <description>&lt;P&gt;Hi, I'm trying to configure my TLS enabled Syslog server in Cortex but not successful. I'm always getting "&lt;SPAN&gt;Test failed : Certificate Verification Failed". When I tick the "Ignore certificate errors", the error disappears and one syslog message is received successfully but getting errors after that. Can you please help me figure this out?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Syslog output:&lt;/SPAN&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;Sep  7 12:10:01 syslogtest rsyslogd: unexpected GnuTLS error -110 in nsd_gtls.c:588: The TLS connection was non-properly terminated.  [v8.2112.0 try https://www.rsyslog.com/e/2078 ]
Sep  7 12:10:01 syslogtest rsyslogd: netstream session 0x7f50900098e0 from 34.90.105.250 will be closed due to error [v8.2112.0 try https://www.rsyslog.com/e/2078 ]
Sep  7 09:10:08 cortexxdr - CEF:0|Palo Alto Networks|Cortex XDR|Cortex XDR 3.7.0|XDR Agent|Example Cortex XDR Alert|0|end=1581471661000 shost=3D4WRQ2 suser=acme\\user deviceFacility=None cat=Restrictions externalId=11148 request=https://gan.xdr.eu.paloaltonetworks.com/alerts/11148 cs1=example.exe cs1Label=Initiated by cs2=example.exe cs2Label=Initiator CMD cs3=SIGNATURE_SIGNED-Microsoft Corporation cs3Label=Signature cs4=cmd.exe cs4Label=CGO name cs5=C:\\this\\is\\example.exe /c ""\\\\host1\\files\\example.bat" " cs5Label=CGO CMD cs6=SIGNATURE_SIGNED-Microsoft Corporation cs6Label=CGO Signature fileHash=BBBBBBBE8A5E66AC3C693F9B5D3762805CF2D8F1283291AF38321FC619B23115 targetprocesssignature=SIGNATURE_UNAVAILABLE-N/A tenantname=GAN tenantCDLid=2003685740608 CSPaccountname=Vg Estonia Ou initiatorSha256=BBBBBBBE8A5E66AC3C693F9B5D3762805CF2D8F1283291AF38321FC619B23115 cgoSha256=AAAAAAc4a0b7eb191783c323ab8363ebd1fd10be58d8bcc96b07067743ca81d5 act=Detected (Reported)
Sep  7 12:10:09 syslogtest rsyslogd: unexpected GnuTLS error -110 in nsd_gtls.c:588: The TLS connection was non-properly terminated.  [v8.2112.0 try https://www.rsyslog.com/e/2078 ]
Sep  7 12:10:09 syslogtest rsyslogd: netstream session 0x7f509000e610 from 34.90.105.250 will be closed due to error [v8.2112.0 try https://www.rsyslog.com/e/2078 ]&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Syslog Config:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;global(
DefaultNetstreamDriver="gtls"
DefaultNetstreamDriverCAFile="/etc/rsyslog.d/keys/ca.pem"
DefaultNetstreamDriverCertFile="/etc/rsyslog.d/keys/server-cert.pem"
DefaultNetstreamDriverKeyFile="/etc/rsyslog.d/keys/server-key.pem"
)

module(
load="imtcp"
StreamDriver.Name="gtls"
StreamDriver.Mode="1"
StreamDriver.Authmode="anon"
)

input(type="imtcp" port="6514")&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2023 09:21:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/send-alerts-to-syslog-server-with-tls-failing-with-certificate/m-p/556953#M5099</guid>
      <dc:creator>Isuru</dc:creator>
      <dc:date>2023-09-07T09:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: Send alerts to Syslog server with TLS failing with Certificate Verification Failed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/send-alerts-to-syslog-server-with-tls-failing-with-certificate/m-p/557049#M5107</link>
      <description>&lt;P&gt;Hi &lt;A id="link_7" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/296350" target="_self" aria-label="View Profile of Isuru"&gt;&lt;SPAN class=""&gt;Isuru&lt;/SPAN&gt;&lt;/A&gt;, thanks for reaching out.&lt;/P&gt;
&lt;P&gt;Please double check on these steps to make sure you are not missing one and let us know if this helps:&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Integrate-a-Syslog-Receiver" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Integrate-a-Syslog-Receiver&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2023 20:46:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/send-alerts-to-syslog-server-with-tls-failing-with-certificate/m-p/557049#M5107</guid>
      <dc:creator>mavega</dc:creator>
      <dc:date>2023-09-07T20:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: Send alerts to Syslog server with TLS failing with Certificate Verification Failed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/send-alerts-to-syslog-server-with-tls-failing-with-certificate/m-p/557133#M5110</link>
      <description>&lt;P&gt;Yes, I followed the steps correctly. As you can see, I can get one test syslog message to my server, but nothing after that until I restart my rsyslog service.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2023 07:01:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/send-alerts-to-syslog-server-with-tls-failing-with-certificate/m-p/557133#M5110</guid>
      <dc:creator>Isuru</dc:creator>
      <dc:date>2023-09-08T07:01:19Z</dc:date>
    </item>
    <item>
      <title>Re: Send alerts to Syslog server with TLS failing with Certificate Verification Failed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/send-alerts-to-syslog-server-with-tls-failing-with-certificate/m-p/557424#M5121</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For &lt;SPAN&gt;&amp;nbsp;"&lt;/SPAN&gt;&lt;SPAN&gt;Test failed : Certificate Verification Failed"&lt;/SPAN&gt;, have you tried any of these:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL class="itemizedlist"&gt;
&lt;LI class="listitem"&gt;
&lt;P&gt;Incorrect certificate—to check that the certificate you are uploading corresponds to the server syslog certificate, use the following openssl command.&lt;/P&gt;
&lt;PRE class="programlisting hljs  language-objectivec"&gt;&lt;CODE&gt;openssl verify -verbose -CAfile cortex_upload_certificate syslog_certificate&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;If the certificate is correct, the result is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class="computeroutput hljs language-makefile"&gt;&lt;SPAN class="hljs-section"&gt;syslog_certificate: OK&lt;/SPAN&gt;&lt;/CODE&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="listitem"&gt;
&lt;P&gt;Incorrect hostname—make sure that the hostname/ip in the certificate matches the syslog server.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="listitem"&gt;
&lt;P&gt;Certificate chain—If you are using a list of certificates, merge the chain into one certificate. You can concatenate the certificates using the following cat command in Linux or macOS.&lt;/P&gt;
&lt;PRE class="programlisting hljs  language-bash"&gt;&lt;CODE&gt;cat intermediate_cert root_cert &amp;gt; merged_syslog.crt       &lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;If the concatenated certificate doesn’t work, change the order of the root and intermediate certificates, and try again.&lt;/P&gt;
&lt;P&gt;To verify that the chain certificate was saved correctly, use the following openssl command.&lt;/P&gt;
&lt;PRE class="programlisting hljs  language-objectivec"&gt;&lt;CODE&gt;openssl verify -verbose -CAfile cortex_upload_certificate syslog_certificate&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;If the certificate is correct, the result is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class="computeroutput hljs language-makefile"&gt;&lt;SPAN class="hljs-section"&gt;syslog_certificate: OK&lt;/SPAN&gt;&lt;/CODE&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 11 Sep 2023 21:49:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/send-alerts-to-syslog-server-with-tls-failing-with-certificate/m-p/557424#M5121</guid>
      <dc:creator>mavega</dc:creator>
      <dc:date>2023-09-11T21:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: Send alerts to Syslog server with TLS failing with Certificate Verification Failed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/send-alerts-to-syslog-server-with-tls-failing-with-certificate/m-p/575466#M6005</link>
      <description>&lt;P&gt;i have the same issue, but for log managment audit &amp;amp; agent audit log the server received, any have done for this case?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 07:38:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/send-alerts-to-syslog-server-with-tls-failing-with-certificate/m-p/575466#M6005</guid>
      <dc:creator>al-westcon</dc:creator>
      <dc:date>2024-02-02T07:38:01Z</dc:date>
    </item>
  </channel>
</rss>

