<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sending traffic logs with Syslogs (UDP) from PA-440 -&amp;gt; Collector Server in Azure -&amp;gt; LimaCharlie organization not working in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sending-traffic-logs-with-syslogs-udp-from-pa-440-gt-collector/m-p/573565#M2472</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1278321707"&gt;@SoloSigma&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will verify the following:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;Check the traffic logs on the Monitor tab to see if any traffic is being denied.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;If no traffic logs are found, check the session browser logs (clear the session if needed).&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Thu, 18 Jan 2024 21:25:14 GMT</pubDate>
    <dc:creator>jpomachagua</dc:creator>
    <dc:date>2024-01-18T21:25:14Z</dc:date>
    <item>
      <title>Sending traffic logs with Syslogs (UDP) from PA-440 -&gt; Collector Server in Azure -&gt; LimaCharlie organization not working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sending-traffic-logs-with-syslogs-udp-from-pa-440-gt-collector/m-p/573365#M2461</link>
      <description>&lt;P&gt;I am trying to send Syslog from my PA-440 to a &lt;A href="https://limacharlie.io/" target="_self"&gt;LimaCharlie&lt;/A&gt;&amp;nbsp;organization.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the setup&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;PA-400&lt;/STRONG&gt; &lt;EM&gt;--Syslog--&amp;gt;&lt;/EM&gt; &lt;STRONG&gt;Virtual Machine in Azure running Ubuntu with LimaCharlie Adapter &lt;/STRONG&gt;&lt;EM&gt;--HTTPS--&amp;gt;&lt;/EM&gt; &lt;STRONG&gt;LimaCharlie.io&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;FONT size="6"&gt;This is what I have done in the PA-440&lt;/FONT&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV style="display: inline;"&gt;&lt;FONT size="5"&gt;1. Objects -&amp;gt; Log Forwarding &lt;SPAN class="ph cmd"&gt;and &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV style="display: inline;"&gt;&lt;FONT size="5"&gt;Add &lt;/FONT&gt;&lt;LI-WRAPPER&gt;&lt;SPAN class="ph cmd"&gt;&lt;FONT size="5"&gt;a profile&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/LI-WRAPPER&gt;&lt;/DIV&gt;
&lt;DIV style="display: inline;"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV style="display: inline;"&gt;&lt;SPAN class="ph cmd"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Log fowarding.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56587i93B3EDC318B50559/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Log fowarding.png" alt="Log fowarding.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV style="display: inline;"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV style="display: inline;"&gt;
&lt;UL class="ak-ul" style="margin: 0px; box-sizing: border-box; list-style-type: disc; display: flow-root; color: #172b4d; font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Oxygen, Ubuntu, 'Fira Sans', 'Droid Sans', 'Helvetica Neue', sans-serif; font-size: 16px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: pre-wrap; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; padding: 0px 0px 0px var(      --ed--list--item-counter--padding,      24px    );" data-indent-level="1"&gt;
&lt;LI&gt;
&lt;P style="margin: 0px; padding: 0px; font-size: 1em; line-height: 1.714; font-weight: normal; letter-spacing: -0.005em;" data-renderer-start-pos="1327"&gt;Name: vm-collectorserver-prod&lt;/P&gt;
&lt;/LI&gt;
&lt;LI style="margin-top: var(--ds-space-050, 4px);"&gt;
&lt;P style="margin: 0px; padding: 0px; font-size: 1em; line-height: 1.714; font-weight: normal; letter-spacing: -0.005em;" data-renderer-start-pos="1370"&gt;Syslog server: {Public IP from Azure}&lt;/P&gt;
&lt;/LI&gt;
&lt;LI style="margin-top: var(--ds-space-050, 4px);"&gt;
&lt;P style="margin: 0px; padding: 0px; font-size: 1em; line-height: 1.714; font-weight: normal; letter-spacing: -0.005em;" data-renderer-start-pos="1444"&gt;Port number: 514&lt;/P&gt;
&lt;/LI&gt;
&lt;LI style="margin-top: var(--ds-space-050, 4px);"&gt;
&lt;P style="margin: 0px; padding: 0px; font-size: 1em; line-height: 1.714; font-weight: normal; letter-spacing: -0.005em;" data-renderer-start-pos="1464"&gt;Format: BSD&lt;/P&gt;
&lt;/LI&gt;
&lt;LI style="margin-top: var(--ds-space-050, 4px);"&gt;
&lt;P style="margin: 0px; padding: 0px; font-size: 1em; line-height: 1.714; font-weight: normal; letter-spacing: -0.005em;" data-renderer-start-pos="1479"&gt;Facility&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I named the profile "&lt;STRONG&gt;LFP-Logs to LimaCharlie&lt;/STRONG&gt;".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Log Fowarding profile.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56588i37FB38E49B09C84A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Log Fowarding profile.png" alt="Log Fowarding profile.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV style="display: inline;"&gt;&lt;FONT size="5"&gt;2. Policies&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV style="display: inline;"&gt;&lt;FONT size="5"&gt;&amp;nbsp;-&amp;gt; Security&lt;/FONT&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt; &lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV style="display: inline;"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV style="display: inline;"&gt;&lt;SPAN class="ph cmd"&gt;Actions -&amp;gt; Log Forwarding: LFP-Logs to LimaCharlie&lt;BR /&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV style="display: inline;"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV style="display: inline;"&gt;&lt;SPAN class="ph cmd"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Security Policy Rule.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56589iF134592643CA922D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Security Policy Rule.png" alt="Security Policy Rule.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV style="display: inline;"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV style="display: inline;"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;FONT size="6"&gt;This is what I have done in Azure&lt;/FONT&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;I created a VM with latest Ubuntu Server.&lt;BR /&gt;I opened port 514 UDP.&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Azure.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56590iEA1616ED70DD2F7F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Azure.png" alt="Azure.png" /&gt;&lt;/span&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;Next I installed LimaCharlie Adapter on it which is working fine:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LimaCharlie Adapter.png" style="width: 862px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56591i1D7EFA8037566D36/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="LimaCharlie Adapter.png" alt="LimaCharlie Adapter.png" /&gt;&lt;/span&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;I tried to send a syslog message to it which came through to the LimaCharlie organization, meaning that the collector server can receive syslog:&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV style="background-color: #1e1f22; color: #bcbec4;"&gt;
&lt;PRE style="font-family: 'JetBrains Mono',monospace; font-size: 9,8pt;"&gt;&lt;SPAN&gt;logger -p 0 -n 1.2.3.4 "This is only test message ----- remote"&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;P&gt;Screenshot from LimaCharlie.io:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LimaCharlie.io.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56592iDD95A106FC120557/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="LimaCharlie.io.png" alt="LimaCharlie.io.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now I am a bit lost.. What should I try next in order to make sure that logs are sent from the Palo Alto firewall to my collector server in Azure?&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 Jan 2024 19:13:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sending-traffic-logs-with-syslogs-udp-from-pa-440-gt-collector/m-p/573365#M2461</guid>
      <dc:creator>SoloSigma</dc:creator>
      <dc:date>2024-01-17T19:13:34Z</dc:date>
    </item>
    <item>
      <title>Re: Sending traffic logs with Syslogs (UDP) from PA-440 -&gt; Collector Server in Azure -&gt; LimaCharlie organization not working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sending-traffic-logs-with-syslogs-udp-from-pa-440-gt-collector/m-p/573565#M2472</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1278321707"&gt;@SoloSigma&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will verify the following:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;Check the traffic logs on the Monitor tab to see if any traffic is being denied.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;If no traffic logs are found, check the session browser logs (clear the session if needed).&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 21:25:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sending-traffic-logs-with-syslogs-udp-from-pa-440-gt-collector/m-p/573565#M2472</guid>
      <dc:creator>jpomachagua</dc:creator>
      <dc:date>2024-01-18T21:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: Sending traffic logs with Syslogs (UDP) from PA-440 -&gt; Collector Server in Azure -&gt; LimaCharlie organization not working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sending-traffic-logs-with-syslogs-udp-from-pa-440-gt-collector/m-p/574056#M2502</link>
      <description>&lt;P&gt;I have checked the traffic logs and all has Action=allow.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Traffic log page 1" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56780iC8863155F92A655B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Traffic log 1.png" alt="Traffic log page 1" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Traffic log page 1&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Traffic log page 2" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56781iEF49A868DAAEEC99/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Traffic log 2.png" alt="Traffic log page 2" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Traffic log page 2&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 09:08:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sending-traffic-logs-with-syslogs-udp-from-pa-440-gt-collector/m-p/574056#M2502</guid>
      <dc:creator>SoloSigma</dc:creator>
      <dc:date>2024-01-23T09:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: Sending traffic logs with Syslogs (UDP) from PA-440 -&gt; Collector Server in Azure -&gt; LimaCharlie organization not working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sending-traffic-logs-with-syslogs-udp-from-pa-440-gt-collector/m-p/574120#M2509</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1278321707"&gt;@SoloSigma&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can you verify if there is a NAT source IP address for the packets? Also, can you display the columns for bytes sent and bytes received?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 16:59:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sending-traffic-logs-with-syslogs-udp-from-pa-440-gt-collector/m-p/574120#M2509</guid>
      <dc:creator>jpomachagua</dc:creator>
      <dc:date>2024-01-23T16:59:01Z</dc:date>
    </item>
  </channel>
</rss>

