<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Decrypt log missing in list of logs in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decrypt-log-missing-in-list-of-logs/m-p/589276#M3296</link>
    <description>&lt;P&gt;I spent several hours yesterday trying to get decryption working.&amp;nbsp; Everything kept coming back to being able to view the decryption log under Monitor&amp;gt;Logs&amp;gt;Decryption.&amp;nbsp; However, my Palos did not have a "Decryption" option under Logs, and I could not figure out why, and could not find any documentation to explain why I could not see that option on my firewalls.&amp;nbsp; Was it because I didn't have the right license? Was it a configuration setting somewhere that was not enabled?&amp;nbsp; Was it because decryption just wasn't working and so there were no log messages to display?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm putting this here so that hopefully if someone else has the same problem they don't waste hours like I did trying to figure out why this thing that all the documentation says you can just find at Monitor&amp;gt;Logs&amp;gt;Decryption, was no where to be found. (So frustration...)&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem for me came down to the fact that we use Radius for normal access to our Palos.&amp;nbsp; If I logged in with the local admin account, I was able to see the decryption log under the list of logs.&amp;nbsp; Now I need to find out if there is a way to have Radius authenticated Admins receive Admin level access to the Palos so admins don't have to login with the local admin account.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Jun 2024 13:22:56 GMT</pubDate>
    <dc:creator>dsmall-pa</dc:creator>
    <dc:date>2024-06-11T13:22:56Z</dc:date>
    <item>
      <title>Decrypt log missing in list of logs</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decrypt-log-missing-in-list-of-logs/m-p/589276#M3296</link>
      <description>&lt;P&gt;I spent several hours yesterday trying to get decryption working.&amp;nbsp; Everything kept coming back to being able to view the decryption log under Monitor&amp;gt;Logs&amp;gt;Decryption.&amp;nbsp; However, my Palos did not have a "Decryption" option under Logs, and I could not figure out why, and could not find any documentation to explain why I could not see that option on my firewalls.&amp;nbsp; Was it because I didn't have the right license? Was it a configuration setting somewhere that was not enabled?&amp;nbsp; Was it because decryption just wasn't working and so there were no log messages to display?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm putting this here so that hopefully if someone else has the same problem they don't waste hours like I did trying to figure out why this thing that all the documentation says you can just find at Monitor&amp;gt;Logs&amp;gt;Decryption, was no where to be found. (So frustration...)&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem for me came down to the fact that we use Radius for normal access to our Palos.&amp;nbsp; If I logged in with the local admin account, I was able to see the decryption log under the list of logs.&amp;nbsp; Now I need to find out if there is a way to have Radius authenticated Admins receive Admin level access to the Palos so admins don't have to login with the local admin account.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 13:22:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decrypt-log-missing-in-list-of-logs/m-p/589276#M3296</guid>
      <dc:creator>dsmall-pa</dc:creator>
      <dc:date>2024-06-11T13:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: Decrypt log missing in list of logs</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/decrypt-log-missing-in-list-of-logs/m-p/589333#M3297</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/287993"&gt;@dsmall-pa&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for post.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on what you described my first thought is that your RADIUS authenticated account is bound to custom role that does not have decryption logs enabled. Below is a sample:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1718147557558.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60309i97737BEDF0FE44B5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PavelK_0-1718147557558.png" alt="PavelK_0-1718147557558.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The decryption logs were introduced in PAN-OS 10.0 (Here is the reference: &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/decryption/verify-decryption#id185BG0KL0W1" target="_self"&gt;Verify Decryption&lt;/A&gt;) and it is possible that whoever created a custom role in earlier version of PAN-OS prior to 10.0 has enabled access to log options available at that time. After decryption logs were introduced this log option comes automatically as disabled therefore it is not available to your RADIUS account.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would recommend to review setting for custom role if this is indeed being used.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 23:17:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/decrypt-log-missing-in-list-of-logs/m-p/589333#M3297</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-06-11T23:17:54Z</dc:date>
    </item>
  </channel>
</rss>

