<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log Forwarding to Panorama in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/log-forwarding-to-panorama/m-p/248048#M1078</link>
    <description>&lt;P&gt;You can follow these steps to apply changes to multiple policies - including adding a log forwarding profile.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) if not already present you must create a LogForward profile: OBJECTS --&amp;gt; OTHER --&amp;gt; LogForward&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can use the snippet below to create a profile&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;lt;entry name="panorama"&amp;gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&amp;lt;match-list&amp;gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&amp;lt;entry name="pan-1"&amp;gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&amp;lt;log-type&amp;gt;traffic&amp;lt;/log-type&amp;gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&amp;lt;filter&amp;gt;All Logs&amp;lt;/filter&amp;gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&amp;lt;send-to-panorama&amp;gt;yes&amp;lt;/send-to-panorama&amp;gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&amp;lt;/entry&amp;gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&amp;lt;/match-list&amp;gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&amp;lt;/entry&amp;gt;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;2) use the multi-edit option for the policies to select the policies you want to apply the log fowarding profile to&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Jan 2019 21:06:45 GMT</pubDate>
    <dc:creator>sjanita</dc:creator>
    <dc:date>2019-01-29T21:06:45Z</dc:date>
    <item>
      <title>Log Forwarding to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/log-forwarding-to-panorama/m-p/247917#M1075</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using expedition tool to migrate the configuration from Cisco FWSM to Panorama. While reading the documents for "Log forwarding to Panorama", i understand that we need to select a security rule and set the log forwarding profile in order to receive the logs in Panorama.&amp;nbsp; I have thousands of security rules which are being migrated and hence assigning forwarding profiles to individual security rules will consume a lot of time.&amp;nbsp;&amp;nbsp;Is there a way in which we can assign a log forwarding profile of an entire policy set to Panorama?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2019 06:57:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/log-forwarding-to-panorama/m-p/247917#M1075</guid>
      <dc:creator>MGRashmi</dc:creator>
      <dc:date>2019-01-29T06:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: Log Forwarding to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/log-forwarding-to-panorama/m-p/248048#M1078</link>
      <description>&lt;P&gt;You can follow these steps to apply changes to multiple policies - including adding a log forwarding profile.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) if not already present you must create a LogForward profile: OBJECTS --&amp;gt; OTHER --&amp;gt; LogForward&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can use the snippet below to create a profile&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;lt;entry name="panorama"&amp;gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&amp;lt;match-list&amp;gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&amp;lt;entry name="pan-1"&amp;gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&amp;lt;log-type&amp;gt;traffic&amp;lt;/log-type&amp;gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&amp;lt;filter&amp;gt;All Logs&amp;lt;/filter&amp;gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&amp;lt;send-to-panorama&amp;gt;yes&amp;lt;/send-to-panorama&amp;gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&amp;lt;/entry&amp;gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&amp;lt;/match-list&amp;gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&amp;lt;/entry&amp;gt;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;2) use the multi-edit option for the policies to select the policies you want to apply the log fowarding profile to&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2019 21:06:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/log-forwarding-to-panorama/m-p/248048#M1078</guid>
      <dc:creator>sjanita</dc:creator>
      <dc:date>2019-01-29T21:06:45Z</dc:date>
    </item>
    <item>
      <title>Re: Log Forwarding to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/log-forwarding-to-panorama/m-p/248109#M1081</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot for your response. If i use the multi-edit option, is there a way to apply the log forwarding profile for all rules? Or do i need to select , let's say 20 rules at a time and apply the log forwarding profile?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 06:06:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/log-forwarding-to-panorama/m-p/248109#M1081</guid>
      <dc:creator>MGRashmi</dc:creator>
      <dc:date>2019-01-30T06:06:12Z</dc:date>
    </item>
    <item>
      <title>Re: Log Forwarding to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/log-forwarding-to-panorama/m-p/248132#M1083</link>
      <description>&lt;P&gt;to use the multi edit option you need to select the policies you want to edit.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can expand the default view of 50 policies to 500 for example, and select 500, if you do not want to make changes in 50 count batches.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 09:16:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/log-forwarding-to-panorama/m-p/248132#M1083</guid>
      <dc:creator>sjanita</dc:creator>
      <dc:date>2019-01-30T09:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: Log Forwarding to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/log-forwarding-to-panorama/m-p/248240#M1086</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN class=""&gt;&lt;A id="link_5" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41" target="_self"&gt;sjanita&lt;/A&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;Thanks a lot for your response. I will do that.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jan 2019 06:36:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/log-forwarding-to-panorama/m-p/248240#M1086</guid>
      <dc:creator>MGRashmi</dc:creator>
      <dc:date>2019-01-31T06:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: Log Forwarding to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/log-forwarding-to-panorama/m-p/515928#M4195</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;We migrated ASA policy security rules to PA firewall, and now we want to&amp;nbsp;&lt;SPAN&gt;amend these policies rules to add both&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;log forwarding profile or Security profiles.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, if I c&lt;SPAN&gt;onnect the FW to Expedition tool (or simply upload FW XM config into Expedition), ingest policies, multi-rule edit, then API push the rules back to the FW, will the new amended&amp;nbsp;policy&amp;nbsp;rules override&amp;nbsp;the current existing rule when I use API (load partial config) or crate duplicated&amp;nbsp;ones&amp;nbsp;?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 12:32:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/log-forwarding-to-panorama/m-p/515928#M4195</guid>
      <dc:creator>AK74</dc:creator>
      <dc:date>2022-09-26T12:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: Log Forwarding to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/log-forwarding-to-panorama/m-p/515948#M4198</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/169335"&gt;@AK74&lt;/a&gt; Yes, it will overwrite whatever you have on firewall , you can&amp;nbsp; either push the modified rules back to firewall via API calls or use load config partial in replace mode.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 15:36:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/log-forwarding-to-panorama/m-p/515948#M4198</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2022-09-26T15:36:35Z</dc:date>
    </item>
  </channel>
</rss>

