<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall / Panorama traffic-log via Syslog to Expedition in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/firewall-panorama-traffic-log-via-syslog-to-expedition/m-p/236182#M674</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i'm forwarding at the moment traffic logs from Palo Firewalls and Panorama to the Expedition server. I verified with tcpdump that the Expedition-Server recieves the syslogs. Expedition is up to date.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I modified the configuration files in "/var/www/html/OS/rsyslog" like described in the "Expedition Log Analysis Guide v1.0".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also changed the user permission for the folder like described in the "Expedition Log Analysis Guide v1.0".&lt;/P&gt;
&lt;P&gt;But i don't see any created traffic-log-files for analysis.&lt;/P&gt;
&lt;P&gt;I also restarted the rsyslog daemon multiple times without any result.&lt;/P&gt;
&lt;P&gt;Do you have any idea or something that i should check to solve this problem?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ben&lt;/P&gt;</description>
    <pubDate>Fri, 19 Oct 2018 13:56:19 GMT</pubDate>
    <dc:creator>bebe5001</dc:creator>
    <dc:date>2018-10-19T13:56:19Z</dc:date>
    <item>
      <title>Firewall / Panorama traffic-log via Syslog to Expedition</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/firewall-panorama-traffic-log-via-syslog-to-expedition/m-p/236182#M674</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i'm forwarding at the moment traffic logs from Palo Firewalls and Panorama to the Expedition server. I verified with tcpdump that the Expedition-Server recieves the syslogs. Expedition is up to date.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I modified the configuration files in "/var/www/html/OS/rsyslog" like described in the "Expedition Log Analysis Guide v1.0".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also changed the user permission for the folder like described in the "Expedition Log Analysis Guide v1.0".&lt;/P&gt;
&lt;P&gt;But i don't see any created traffic-log-files for analysis.&lt;/P&gt;
&lt;P&gt;I also restarted the rsyslog daemon multiple times without any result.&lt;/P&gt;
&lt;P&gt;Do you have any idea or something that i should check to solve this problem?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Fri, 19 Oct 2018 13:56:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/firewall-panorama-traffic-log-via-syslog-to-expedition/m-p/236182#M674</guid>
      <dc:creator>bebe5001</dc:creator>
      <dc:date>2018-10-19T13:56:19Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall / Panorama traffic-log via Syslog to Expedition</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/firewall-panorama-traffic-log-via-syslog-to-expedition/m-p/236185#M676</link>
      <description>&lt;P&gt;Maybe the local Firewall?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;sudo /usr/bin/firewall-cmd --permanent --add-port=514/udp
sudo /usr/bin/firewall-cmd --permanent --add-port=514/tcp&lt;/PRE&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Oct 2018 14:01:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/firewall-panorama-traffic-log-via-syslog-to-expedition/m-p/236185#M676</guid>
      <dc:creator>alestevez</dc:creator>
      <dc:date>2018-10-19T14:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall / Panorama traffic-log via Syslog to Expedition</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/firewall-panorama-traffic-log-via-syslog-to-expedition/m-p/236451#M695</link>
      <description>&lt;P&gt;Thanks for the help, but it didn't fix my problem. I checked the server once again and the Syslog-Messages are coming to the server but they appear in the following folder /var/log and in the following files syslog and syslog.1. Usually they should be in /data like it is configured in my rsyslog.default-tcpudp.conf file.&lt;/P&gt;
&lt;P&gt;So it seems, that my server uses the wrong configuration file for rsyslog.&lt;/P&gt;
&lt;P&gt;Does someone know where i can verify which configuration file is used by rsyslog?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 09:53:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/firewall-panorama-traffic-log-via-syslog-to-expedition/m-p/236451#M695</guid>
      <dc:creator>bebe5001</dc:creator>
      <dc:date>2018-10-22T09:53:14Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall / Panorama traffic-log via Syslog to Expedition</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/firewall-panorama-traffic-log-via-syslog-to-expedition/m-p/236453#M696</link>
      <description>&lt;P&gt;You should have to replace the one comes from the OS in /etc/rsyslog.d with the one is&amp;nbsp;provided within Expedition&amp;nbsp;&lt;SPAN&gt;rsyslog.default-tcpudp.conf, then restart the service or the VM....&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 10:04:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/firewall-panorama-traffic-log-via-syslog-to-expedition/m-p/236453#M696</guid>
      <dc:creator>alestevez</dc:creator>
      <dc:date>2018-10-22T10:04:14Z</dc:date>
    </item>
  </channel>
</rss>

