<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic While integrating panorama with SIEM server( using Syslog server profile ) for log forwarding  from panorama to siem server facing system alert/log on in Log Forwarding Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/while-integrating-panorama-with-siem-server-using-syslog-server/m-p/552214#M84</link>
    <description>&lt;LI-SPOILER&gt;&lt;LI-SPOILER&gt;While integrating panorama with SIEM server( using Syslog server profile ) for log forwarding from panorama to siem server facing system alert/log on panorama i.e “ panorama lost it is connection to peer, No logs will be forwarded ”&lt;BR /&gt;Panorama version- 10.2.4&lt;BR /&gt;Panorama is in HA but both peer have seperate log collector.&amp;nbsp;&lt;BR /&gt;Anyone has faced this same issue, please revert and help&lt;/LI-SPOILER&gt; &lt;/LI-SPOILER&gt;&lt;P&gt;Panorama&lt;/P&gt;</description>
    <pubDate>Thu, 03 Aug 2023 19:46:50 GMT</pubDate>
    <dc:creator>prathamesh_s</dc:creator>
    <dc:date>2023-08-03T19:46:50Z</dc:date>
    <item>
      <title>While integrating panorama with SIEM server( using Syslog server profile ) for log forwarding  from panorama to siem server facing system alert/log on</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/while-integrating-panorama-with-siem-server-using-syslog-server/m-p/552214#M84</link>
      <description>&lt;LI-SPOILER&gt;&lt;LI-SPOILER&gt;While integrating panorama with SIEM server( using Syslog server profile ) for log forwarding from panorama to siem server facing system alert/log on panorama i.e “ panorama lost it is connection to peer, No logs will be forwarded ”&lt;BR /&gt;Panorama version- 10.2.4&lt;BR /&gt;Panorama is in HA but both peer have seperate log collector.&amp;nbsp;&lt;BR /&gt;Anyone has faced this same issue, please revert and help&lt;/LI-SPOILER&gt; &lt;/LI-SPOILER&gt;&lt;P&gt;Panorama&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 19:46:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/while-integrating-panorama-with-siem-server-using-syslog-server/m-p/552214#M84</guid>
      <dc:creator>prathamesh_s</dc:creator>
      <dc:date>2023-08-03T19:46:50Z</dc:date>
    </item>
    <item>
      <title>Re: While integrating panorama with SIEM tool for log forwarding facing error on SIEM tool i.e “ panorama lost it is connection to peer”  Panorama ver</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/while-integrating-panorama-with-siem-server-using-syslog-server/m-p/552267#M85</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/270268"&gt;@prathamesh_s&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you check logs from Panorama CLI to see it can give more details about root cause of the error:&amp;nbsp;tail follow yes mp-log ms.log&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 22:53:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/while-integrating-panorama-with-siem-server-using-syslog-server/m-p/552267#M85</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-08-02T22:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: While integrating panorama with SIEM tool for log forwarding facing error on SIEM tool i.e “ panorama lost it is connection to peer”  Panorama ver</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/while-integrating-panorama-with-siem-server-using-syslog-server/m-p/552379#M86</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi , have run that command&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;Output&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Error: pan_comm_get_tcp_conn_gen (comm_utils.c:702 ) : COMM: connot connect. Remote ip= 172.24.*.* port=3978 err=connection timed out(110) sock 19&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;CMSA: Source bind sock to 172.20.*.*&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;COMM: Souce bind sock 19 to 172.20.*.* before connect to remote ip [172.24.*.*] &amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45675"&gt;@port&lt;/a&gt; 3978&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Note* = panorama is in HA , passive panorama in remote location.&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Active = 172.20.*.*&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Passive= 172.24.*.*&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Have run this command from active panorama&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Please reply&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 09:47:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/while-integrating-panorama-with-siem-server-using-syslog-server/m-p/552379#M86</guid>
      <dc:creator>prathamesh_s</dc:creator>
      <dc:date>2023-08-03T09:47:09Z</dc:date>
    </item>
    <item>
      <title>Re: While integrating panorama with SIEM server( using Syslog server profile ) for log forwarding  from panorama to siem server facing system alert/lo</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/while-integrating-panorama-with-siem-server-using-syslog-server/m-p/552526#M87</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/270268"&gt;@prathamesh_s&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding the first screen shot, it looks like that there is a connectivity issue between Panorama and managed Firewall. There is a time out for TCP 3978, but eventually at the end of the log, there is a message that device has registered. To me it looks like WAN / Connectivity issue. Could you check this KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClaWCAS" target="_self"&gt;Troubleshooting Panorama Connectivity&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding second screen shot with the error: "Panorama has lost...", it looks like a latency / connectivity issue between active and passive Panorama. The maximum recommended latency between both units should be below 500 ms. Here is a reference in documentation&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/panorama-high-availability/panorama-ha-prerequisites#id589e055b-37df-42b2-b710-0941ac00f993" target="_self"&gt;Doc&lt;/A&gt;. Since you mentioned that passive Panorama is in remote location, I would try to adjust HA Timers&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-web-interface-help/panorama-web-interface/panorama-high-availability" target="_self"&gt;Doc.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2023 06:22:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/while-integrating-panorama-with-siem-server-using-syslog-server/m-p/552526#M87</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-08-04T06:22:49Z</dc:date>
    </item>
  </channel>
</rss>

