<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to set selective syslog server? in Log Forwarding Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/how-to-set-selective-syslog-server/m-p/448406#M45</link>
    <description>&lt;P&gt;Hi, I have one query here.&amp;nbsp;&lt;BR /&gt;&lt;SPAN&gt;Imagine the Syslog server is down for a few hours, and later once the syslog server is up again, will the firewall send fresh logs or the meantime logs as well ?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Nov 2021 15:41:13 GMT</pubDate>
    <dc:creator>pchevveti</dc:creator>
    <dc:date>2021-11-18T15:41:13Z</dc:date>
    <item>
      <title>How to set selective syslog server?</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/how-to-set-selective-syslog-server/m-p/437339#M39</link>
      <description>&lt;P&gt;Can I set palo alto to check if syslog server is up before forwarding the log, and if the main syslog server is down then forward log to another server?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have issues that I need palo alto to not forwarding logs to both servers at the same time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 11:39:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/how-to-set-selective-syslog-server/m-p/437339#M39</guid>
      <dc:creator>Theerdam</dc:creator>
      <dc:date>2021-09-29T11:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to set selective syslog server?</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/how-to-set-selective-syslog-server/m-p/438693#M40</link>
      <description>&lt;P&gt;Thank you for posting question&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/174866"&gt;@Theerdam&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was researching this topic and doing some verification. Regardless of PAN-OS version there can be up to 4 syslog servers configured in one syslog server profile, however there is no logic / connection check. Syslog server profile is sending logs to all targets simultaneously. One way to go around it would be to send all the logs to Virtual IP address of Load Balancer, then based on health check send logs to either of the real syslog server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 04:33:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/how-to-set-selective-syslog-server/m-p/438693#M40</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-10-05T04:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to set selective syslog server?</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/how-to-set-selective-syslog-server/m-p/448406#M45</link>
      <description>&lt;P&gt;Hi, I have one query here.&amp;nbsp;&lt;BR /&gt;&lt;SPAN&gt;Imagine the Syslog server is down for a few hours, and later once the syslog server is up again, will the firewall send fresh logs or the meantime logs as well ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 15:41:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/how-to-set-selective-syslog-server/m-p/448406#M45</guid>
      <dc:creator>pchevveti</dc:creator>
      <dc:date>2021-11-18T15:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to set selective syslog server?</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/how-to-set-selective-syslog-server/m-p/534101#M50</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/196667"&gt;@pchevveti&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the syslog server is down then as per my understanding firewall will store logs locally and once server is up it will send old new logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Mahesh&lt;/P&gt;</description>
      <pubDate>Sat, 11 Mar 2023 19:36:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/how-to-set-selective-syslog-server/m-p/534101#M50</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2023-03-11T19:36:29Z</dc:date>
    </item>
  </channel>
</rss>

