<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Scheduled Log Export to a AWS Expedition Server in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/scheduled-log-export-to-a-aws-expedition-server/m-p/308321#M2252</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone know how to configure the Scheduled Log Export in a firewall to use the AWS ubuntu username and key pair?&amp;nbsp; The Expedition-LogAnalysisGuide_v1.0.2.pdf document on page 7 states to use the "expedition" username and password on the Expedition server, but our Expedition server is in AWS and uses the username is ubuntu with a key pair.&amp;nbsp; How do we export the firewall's logs to the Expedition server in AWS if we cannot use the "expedition" username and password?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jan 2020 21:03:23 GMT</pubDate>
    <dc:creator>jrtuck</dc:creator>
    <dc:date>2020-01-28T21:03:23Z</dc:date>
    <item>
      <title>Scheduled Log Export to a AWS Expedition Server</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/scheduled-log-export-to-a-aws-expedition-server/m-p/308321#M2252</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone know how to configure the Scheduled Log Export in a firewall to use the AWS ubuntu username and key pair?&amp;nbsp; The Expedition-LogAnalysisGuide_v1.0.2.pdf document on page 7 states to use the "expedition" username and password on the Expedition server, but our Expedition server is in AWS and uses the username is ubuntu with a key pair.&amp;nbsp; How do we export the firewall's logs to the Expedition server in AWS if we cannot use the "expedition" username and password?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2020 21:03:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/scheduled-log-export-to-a-aws-expedition-server/m-p/308321#M2252</guid>
      <dc:creator>jrtuck</dc:creator>
      <dc:date>2020-01-28T21:03:23Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled Log Export to a AWS Expedition Server</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/scheduled-log-export-to-a-aws-expedition-server/m-p/308396#M2254</link>
      <description>&lt;P&gt;Not sure how to define in PANOS to do a log export with keys, but you should not feel restricted to use only the expedition user.&lt;/P&gt;
&lt;P&gt;Just make sure that whatever user you are using to upload the CSV files to Expedition, would also allow www-data to read those files and to delete them (in case you want to compress or delete after processing)&lt;/P&gt;
&lt;P&gt;You could use the groups in Linux to make sure that www-data belongs to the group of the user you select to upload the files.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2020 23:10:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/scheduled-log-export-to-a-aws-expedition-server/m-p/308396#M2254</guid>
      <dc:creator>dgildelaig</dc:creator>
      <dc:date>2020-01-28T23:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled Log Export to a AWS Expedition Server</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/scheduled-log-export-to-a-aws-expedition-server/m-p/308477#M2259</link>
      <description>&lt;P&gt;I solved the issue by editing the&amp;nbsp;&lt;SPAN&gt;/etc/ssh/sshd_config, changing "PasswordAuthentication no" to "PasswordAuthentication yes", saving the file and restarting the ssh service -&amp;nbsp;sudo service ssh restart.&amp;nbsp; Now the "expedition" username and passwords works properly.&amp;nbsp; The Expedition-LogAnalysisGuide_v1.0.2.pdf guide should be updated with these steps for people who use Expedition in AWS.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 13:14:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/scheduled-log-export-to-a-aws-expedition-server/m-p/308477#M2259</guid>
      <dc:creator>jrtuck</dc:creator>
      <dc:date>2020-01-29T13:14:17Z</dc:date>
    </item>
  </channel>
</rss>

