<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Syslog connection broken to server Palo Alto every 20 min in Log Forwarding Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/syslog-connection-broken-to-server-palo-alto-every-20-min/m-p/426053#M30</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As per title, I have this problem on a HA scenario with two VM-100 installed on VMware.&lt;/SPAN&gt; &lt;SPAN&gt;Practically every 20 min in the system logs&amp;nbsp; appears:"Syslog connection broken to server". After 0 sec appears:"Syslog connection is established to server".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can someone help me to better understand what it is?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;OS version 10.0.5&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;HA active-passive&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thx.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Aug 2021 08:58:23 GMT</pubDate>
    <dc:creator>GheorgheR</dc:creator>
    <dc:date>2021-08-11T08:58:23Z</dc:date>
    <item>
      <title>Syslog connection broken to server Palo Alto every 20 min</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/syslog-connection-broken-to-server-palo-alto-every-20-min/m-p/426053#M30</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As per title, I have this problem on a HA scenario with two VM-100 installed on VMware.&lt;/SPAN&gt; &lt;SPAN&gt;Practically every 20 min in the system logs&amp;nbsp; appears:"Syslog connection broken to server". After 0 sec appears:"Syslog connection is established to server".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can someone help me to better understand what it is?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;OS version 10.0.5&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;HA active-passive&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thx.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 08:58:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/syslog-connection-broken-to-server-palo-alto-every-20-min/m-p/426053#M30</guid>
      <dc:creator>GheorgheR</dc:creator>
      <dc:date>2021-08-11T08:58:23Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog connection broken to server Palo Alto every 20 min</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/syslog-connection-broken-to-server-palo-alto-every-20-min/m-p/431855#M32</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/154704"&gt;@GheorgheR&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had the same issue in the past. There are several reasons for triggering this. In order to drill down into a route cause, would it be possible to get syslog logs from CLI from Active Firewall:&amp;nbsp;&lt;STRONG&gt;tail lines 100 mp-log syslog-ng.log.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, would it be possible to take packet capture from management interface (Assuming you are using management interface to send syslog)? Here is the manual:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleECAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleECAS&lt;/A&gt;&amp;nbsp;You can use for example this filter:&amp;nbsp;&lt;STRONG&gt;tcpdump filter "host &amp;lt;IP address of your syslog server&amp;gt;"&lt;/STRONG&gt;, then please export it and check it in Wireshark to see reason for closing of the session.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In one of my case, the closing reason was periodic TCP FIN. This got resolved by changing timer on server side to keep connection open for longer period.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since, you mentioned that connection gets broken and re-established periodically, this might be the root cause. Could you please confirm what server product you are sending syslog to? Based on what we see in the syslog-ng.log or from packet capture, I would decide what steps to take next for troubleshooting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps to narrow down what the root cause is.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you and Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Sep 2021 02:14:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/syslog-connection-broken-to-server-palo-alto-every-20-min/m-p/431855#M32</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-09-06T02:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog connection broken to server Palo Alto every 20 min</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/syslog-connection-broken-to-server-palo-alto-every-20-min/m-p/486378#M47</link>
      <description>&lt;P&gt;I am seeing this on our secondary firewall, but not on our primary. Syslog connection breaks and reconnects every few minutes.&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 14:53:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/syslog-connection-broken-to-server-palo-alto-every-20-min/m-p/486378#M47</guid>
      <dc:creator>LeeSeeman</dc:creator>
      <dc:date>2022-05-11T14:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog connection broken to server Palo Alto every 20 min</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/syslog-connection-broken-to-server-palo-alto-every-20-min/m-p/486617#M48</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83040"&gt;@LeeSeeman&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for the comment. Since the passive Firewall does not actively process any traffic, syslog connection will not be sending any Traffic, URL, Threat logs,... The only log that is being generated on passive Firewall is System and Configuration logs. If this log is being sent by syslog out to your server, then as a next thing I would be looking into packet capture to see what side is closing connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 06:30:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/syslog-connection-broken-to-server-palo-alto-every-20-min/m-p/486617#M48</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-05-12T06:30:06Z</dc:date>
    </item>
  </channel>
</rss>

