<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Way to forward logs from individual rules instead of entire firewall? in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/way-to-forward-logs-from-individual-rules-instead-of-entire/m-p/347631#M2953</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/93223"&gt;@BOkay&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This question will be a PAN-OS question, I know there is an "scp export traffic log" command that you can specify the filter using "query", you might want to open a case with TAC and ask them if there is a way to export only traffic logs matching specific rule name.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 08 Sep 2020 17:56:06 GMT</pubDate>
    <dc:creator>lychiang</dc:creator>
    <dc:date>2020-09-08T17:56:06Z</dc:date>
    <item>
      <title>Way to forward logs from individual rules instead of entire firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/way-to-forward-logs-from-individual-rules-instead-of-entire/m-p/347564#M2951</link>
      <description>&lt;P&gt;Is there a way to forward logs from individual rules by adding Expedition to their Log Forwarding Profile rather than setting up a Scheduled Log Export which forwards an entire firewall's logs?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Reason I ask is I need to use MI to analyze traffic for some specific rules but do not need to analyze traffic on an entire firewall. I have Scheduled Log Export setup for some smaller firewalls where the entire policy needs to be analyzed and this works well.&amp;nbsp; But, I also have some very large high traffic firewalls where I need to analyze only a few rules and scheduling the export of their entire traffic log would just be too much for our Expedition server.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any thoughts?&amp;nbsp; Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 15:34:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/way-to-forward-logs-from-individual-rules-instead-of-entire/m-p/347564#M2951</guid>
      <dc:creator>BOkay</dc:creator>
      <dc:date>2020-09-08T15:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: Way to forward logs from individual rules instead of entire firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/way-to-forward-logs-from-individual-rules-instead-of-entire/m-p/347631#M2953</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/93223"&gt;@BOkay&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This question will be a PAN-OS question, I know there is an "scp export traffic log" command that you can specify the filter using "query", you might want to open a case with TAC and ask them if there is a way to export only traffic logs matching specific rule name.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 17:56:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/way-to-forward-logs-from-individual-rules-instead-of-entire/m-p/347631#M2953</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2020-09-08T17:56:06Z</dc:date>
    </item>
    <item>
      <title>Re: Way to forward logs from individual rules instead of entire firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/way-to-forward-logs-from-individual-rules-instead-of-entire/m-p/347869#M2955</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, this is possible using Expedition as a Syslog server and using a Log Forwarding profile as you stated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To make sure that Expedition is receiving the traffic logs using syslog messages, check this other thread where we mentioned how to set up these parts.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-as-syslog-server-change-logs-directory/td-p/244974" target="_blank"&gt;https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-as-syslog-server-change-logs-directory/td-p/244974&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 10:45:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/way-to-forward-logs-from-individual-rules-instead-of-entire/m-p/347869#M2955</guid>
      <dc:creator>dgildelaig</dc:creator>
      <dc:date>2020-09-09T10:45:57Z</dc:date>
    </item>
  </channel>
</rss>

