<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Expedition as a Syslog server in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-as-a-syslog-server/m-p/538627#M4530</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/283781"&gt;@tnamba_evotek&lt;/a&gt;&amp;nbsp;If /PALogs folder does not exist, you will need to manually create them in the Expedition.&amp;nbsp; Please review the tutorial video&amp;nbsp;&lt;A href="https://youtu.be/Ozjx0rfRRmI" target="_blank"&gt;https://youtu.be/Ozjx0rfRRmI&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 13 Apr 2023 16:38:45 GMT</pubDate>
    <dc:creator>lychiang</dc:creator>
    <dc:date>2023-04-13T16:38:45Z</dc:date>
    <item>
      <title>Expedition as a Syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-as-a-syslog-server/m-p/538621#M4529</link>
      <description>&lt;P&gt;Hi all, I'm trying to set up Expedition as a Syslog server. &amp;nbsp;I am following the guides, but a folder under /PALogs is never created with the management IP of firewall sending the logs. &amp;nbsp;Any suggestions? &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2023 16:00:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-as-a-syslog-server/m-p/538621#M4529</guid>
      <dc:creator>tnamba_evotek</dc:creator>
      <dc:date>2023-04-13T16:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition as a Syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-as-a-syslog-server/m-p/538627#M4530</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/283781"&gt;@tnamba_evotek&lt;/a&gt;&amp;nbsp;If /PALogs folder does not exist, you will need to manually create them in the Expedition.&amp;nbsp; Please review the tutorial video&amp;nbsp;&lt;A href="https://youtu.be/Ozjx0rfRRmI" target="_blank"&gt;https://youtu.be/Ozjx0rfRRmI&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2023 16:38:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-as-a-syslog-server/m-p/538627#M4530</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2023-04-13T16:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition as a Syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-as-a-syslog-server/m-p/538629#M4531</link>
      <description>&lt;P&gt;/PALogs directory is there, but the directory under that never gets created with the management IP of the firewall (10.0.0.1). &amp;nbsp;I tried creating the 10.0.0.1 directory manually, but no logs ever get populated.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2023 16:54:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-as-a-syslog-server/m-p/538629#M4531</guid>
      <dc:creator>tnamba_evotek</dc:creator>
      <dc:date>2023-04-13T16:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition as a Syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-as-a-syslog-server/m-p/538630#M4532</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/283781"&gt;@tnamba_evotek&lt;/a&gt;&amp;nbsp; The subfolder should be auto created when Expedition received syslog from firewall. You can try to use "chmod" to change the folder permission, so firewall can write to it , all those are in the tutorial video .&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2023 16:57:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-as-a-syslog-server/m-p/538630#M4532</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2023-04-13T16:57:34Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition as a Syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-as-a-syslog-server/m-p/538632#M4533</link>
      <description>&lt;P&gt;That is my issue, it is not getting created automatically and when I manually create it, the logs never show up. &amp;nbsp;I used chmod and chown to mirror the /PALogs directory permission and ownership to the 10.0.0.1 directory.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2023 17:10:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-as-a-syslog-server/m-p/538632#M4533</guid>
      <dc:creator>tnamba_evotek</dc:creator>
      <dc:date>2023-04-13T17:10:52Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition as a Syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-as-a-syslog-server/m-p/538635#M4534</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/283781"&gt;@tnamba_evotek&lt;/a&gt;&amp;nbsp;Make sure you have modified&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;/var/www/html/OS/rsyslog/rsyslog.conf&lt;/STRONG&gt; to be like the sample in the same directory , for example, if you are sending the syslog in udp , you will reference the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;rsyslog.default-udp in the same directory, double check below:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;1.&amp;nbsp; You have added your firewallIPs as allowed list in the section of the rsyslog.conf &lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;# specify senders you permit to access&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;$AllowedSender TCP, 127.0.0.1, 10.11.29.0/24, 172.16.26.0/24, *.paloaltonetworks &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;(add your firewall IPs)&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;.com&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;$AllowedSender UDP, 127.0.0.1, 10.11.29.0/24, 172.16.26.0/24, *.paloaltonetworks&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;&amp;nbsp;(add your firewall IPs)&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;.com&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p2"&gt;2.&amp;nbsp;In the below section, make sure the folder is /PALogs and the folder exist in your system:&amp;nbsp; (Folder name is Case sensitive)&lt;/P&gt;
&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;$template DynaTrafficLog,&lt;STRONG&gt;"/PALogs/%FROMHOST-IP%/%HOSTNAME%_traffic_%$YEAR%_%$MON&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;&lt;SPAN class="s1"&gt;TH%_%$DAY%_last_calendar_day.csv"&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;3. After modify and save the file, make sure you restart the VM&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2023 17:32:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-as-a-syslog-server/m-p/538635#M4534</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2023-04-13T17:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition as a Syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-as-a-syslog-server/m-p/538893#M4535</link>
      <description>&lt;P&gt;Yes, that is all in the guide which I followed.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Apr 2023 23:40:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-as-a-syslog-server/m-p/538893#M4535</guid>
      <dc:creator>tnamba_evotek</dc:creator>
      <dc:date>2023-04-15T23:40:19Z</dc:date>
    </item>
  </channel>
</rss>

