<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL VPN event logging... in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ssl-vpn-event-logging/m-p/341842#M321</link>
    <description>&lt;P&gt;It's now getting into the tunnel. I had to set a source interface/address on the syslog service route.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 03 Aug 2020 13:22:47 GMT</pubDate>
    <dc:creator>megrez80</dc:creator>
    <dc:date>2020-08-03T13:22:47Z</dc:date>
    <item>
      <title>SSL VPN event logging...</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ssl-vpn-event-logging/m-p/341114#M300</link>
      <description>&lt;P&gt;Does the Global Protect functionality produce logs that can be then forwarded to a remote syslog server?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 19:56:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ssl-vpn-event-logging/m-p/341114#M300</guid>
      <dc:creator>megrez80</dc:creator>
      <dc:date>2020-07-28T19:56:06Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN event logging...</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ssl-vpn-event-logging/m-p/341121#M301</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131948"&gt;@megrez80&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Yes. How you would go about doing so is slightly different due to the recent changes to log location in 9.1+ for GlobalProtect, but you have forwarding options across every release. What exactly are you looking to forward, and what what release are you actively running?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 20:27:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ssl-vpn-event-logging/m-p/341121#M301</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-07-28T20:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN event logging...</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ssl-vpn-event-logging/m-p/341218#M302</link>
      <description>&lt;P&gt;I want to get connect/disconnect events and possibly session statistics.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently on 9.1.0-h3.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2020 11:47:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ssl-vpn-event-logging/m-p/341218#M302</guid>
      <dc:creator>megrez80</dc:creator>
      <dc:date>2020-07-29T11:47:59Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN event logging...</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ssl-vpn-event-logging/m-p/341471#M311</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131948"&gt;@megrez80&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Are you actually still running 9.1.0? If so, I would migrate to a newer release so you get some of those all important bug fixes from that initial release.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;More directly to your question, under your device Log Settings you would want to add entries under the GlobalProtect logs. You would simply want an entry to capture the login/logout stage, as the logout event will include the login duration field which is measured in seconds.&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;((stage eq login) or (stage eq logout)) and not (auth_method eq Cookie)&lt;/LI-CODE&gt;
&lt;P&gt;Note that I've selected to not show Cookie authentications, but whether or not you include that statement is up to you and your configuration. Arguably, if your syslog server has enough space you might want to just not include a filter and keep 'All Logs' specified so your syslog server gets everything, but that may not be needed in your case.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 17:46:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ssl-vpn-event-logging/m-p/341471#M311</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-07-30T17:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN event logging...</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ssl-vpn-event-logging/m-p/341663#M315</link>
      <description>&lt;P&gt;I got vpn event syslog forwarding to work with the configuration step you specified, but the Syslog Server Profile I used had to also be associated with a Log Forwarding Profile. In the Log Forwarding Profile where you specify the Log Type (eg. auth, traffic, tunnel) it did not matter what I used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2020 20:11:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ssl-vpn-event-logging/m-p/341663#M315</guid>
      <dc:creator>megrez80</dc:creator>
      <dc:date>2020-07-31T20:11:34Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN event logging...</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ssl-vpn-event-logging/m-p/341665#M316</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131948"&gt;@megrez80&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The wording of your post above was kind of garbled. Are you still having an issue with this or are you good at this point?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2020 20:19:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ssl-vpn-event-logging/m-p/341665#M316</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-07-31T20:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN event logging...</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ssl-vpn-event-logging/m-p/341672#M317</link>
      <description>&lt;P&gt;Sorry for the confusion. It's working, regardless of the Log Forwarding Profile Log Type specified.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2020 20:24:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ssl-vpn-event-logging/m-p/341672#M317</guid>
      <dc:creator>megrez80</dc:creator>
      <dc:date>2020-07-31T20:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN event logging...</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ssl-vpn-event-logging/m-p/341841#M320</link>
      <description>&lt;P&gt;So now that it's working, I'd like to be able to send thru an IPsec tunnel to a collector on the other end.&lt;/P&gt;&lt;P&gt;I have set my SysLog Server profile with the target IP address, but the logs aren't getting into the tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a trick to accomplish this?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 12:52:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ssl-vpn-event-logging/m-p/341841#M320</guid>
      <dc:creator>megrez80</dc:creator>
      <dc:date>2020-08-03T12:52:02Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN event logging...</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ssl-vpn-event-logging/m-p/341842#M321</link>
      <description>&lt;P&gt;It's now getting into the tunnel. I had to set a source interface/address on the syslog service route.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 13:22:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ssl-vpn-event-logging/m-p/341842#M321</guid>
      <dc:creator>megrez80</dc:creator>
      <dc:date>2020-08-03T13:22:47Z</dc:date>
    </item>
  </channel>
</rss>

