<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect VPN logs from Panorama to Cortex XSOAR in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/global-protect-vpn-logs-from-panorama-to-cortex-xsoar/m-p/592252#M3469</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/188208"&gt;@STeegarden&lt;/a&gt;&amp;nbsp;– There is no way to have the integration fetch GlobalProtect logs into XSOAR (short of customizing the integration), but you should be able to query for GP logs. Then you could set up a job to periodically query the logs and take action accordingly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please test and see if the following command works to return GP logs. If not, please attach a screenshot of the error and debug log.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;!pan-os-query-logs log-type=globalprotect query=&amp;lt;QUERY&amp;gt; debug-mode=true&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jul 2024 00:06:54 GMT</pubDate>
    <dc:creator>asawyer</dc:creator>
    <dc:date>2024-07-17T00:06:54Z</dc:date>
    <item>
      <title>Global Protect VPN logs from Panorama to Cortex XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/global-protect-vpn-logs-from-panorama-to-cortex-xsoar/m-p/592048#M3462</link>
      <description>&lt;P&gt;Hello, was reviewing Globalprotect VPN Logs in Panorama and am currently stumped on how to even create an alert or find the logs in which to send to XSOAR. I reviewed the PAN-OS integration, and I can link it to Panorama, but it will collect logs based on specific queries into the logs. None of which go directly to Global protect. Anyone out there run into the same issue or is there something I'm overlooking?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 15:46:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/global-protect-vpn-logs-from-panorama-to-cortex-xsoar/m-p/592048#M3462</guid>
      <dc:creator>STeegarden</dc:creator>
      <dc:date>2024-07-15T15:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect VPN logs from Panorama to Cortex XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/global-protect-vpn-logs-from-panorama-to-cortex-xsoar/m-p/592252#M3469</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/188208"&gt;@STeegarden&lt;/a&gt;&amp;nbsp;– There is no way to have the integration fetch GlobalProtect logs into XSOAR (short of customizing the integration), but you should be able to query for GP logs. Then you could set up a job to periodically query the logs and take action accordingly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please test and see if the following command works to return GP logs. If not, please attach a screenshot of the error and debug log.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;!pan-os-query-logs log-type=globalprotect query=&amp;lt;QUERY&amp;gt; debug-mode=true&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2024 00:06:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/global-protect-vpn-logs-from-panorama-to-cortex-xsoar/m-p/592252#M3469</guid>
      <dc:creator>asawyer</dc:creator>
      <dc:date>2024-07-17T00:06:54Z</dc:date>
    </item>
  </channel>
</rss>

