<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Config/System Logs Not Forwarding to Syslog Server in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/config-system-logs-not-forwarding-to-syslog-server/m-p/1251011#M6795</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/788658209"&gt;@V.Sambath&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;A couple of questions:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Was this working previously, or is this a brand new setup that has never worked?&lt;/LI&gt;
&lt;LI&gt;Have you verified whether or not you're actually seeing traffic from the firewall on the receiving node or not? Depending on the system and the way that it's configured, it could be dropping the logs because it's failing to parse them.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;If the traffic crosses the dataplane (IE: if your MGMT interface routes through your firewall to reach your syslog server or you utilize a dataplane interface to send the logs) have you verified that the firewall is attempting to send the logs?&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Thu, 26 Mar 2026 14:03:50 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2026-03-26T14:03:50Z</dc:date>
    <item>
      <title>Config/System Logs Not Forwarding to Syslog Server</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/config-system-logs-not-forwarding-to-syslog-server/m-p/1251005#M6791</link>
      <description>&lt;P&gt;I am currently facing an issue where Configuration and System logs are not being forwarded to the syslog server, even though the configuration appears to be correct.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-end="595" data-start="560" data-section-id="1hqulds"&gt;Standalone Firewall&lt;/LI&gt;
&lt;LI data-end="620" data-start="596" data-section-id="16p0tn4"&gt;PAN-OS Version: 11.x&lt;/LI&gt;
&lt;LI data-end="681" data-start="621" data-section-id="zxpui"&gt;Syslog Server: (configured and reachable for traffic logs)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="2560" data-start="2478"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone encountered this issue? despite being following the ref article by Palo?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClM2CAK" target="_self"&gt;How to Forward Config Logs to Syslog Server&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2026 13:53:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/config-system-logs-not-forwarding-to-syslog-server/m-p/1251005#M6791</guid>
      <dc:creator>V.Sambath</dc:creator>
      <dc:date>2026-03-26T13:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: Config/System Logs Not Forwarding to Syslog Server</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/config-system-logs-not-forwarding-to-syslog-server/m-p/1251007#M6793</link>
      <description />
      <pubDate>Thu, 26 Mar 2026 13:55:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/config-system-logs-not-forwarding-to-syslog-server/m-p/1251007#M6793</guid>
      <dc:creator>V.Sambath</dc:creator>
      <dc:date>2026-03-26T13:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: Config/System Logs Not Forwarding to Syslog Server</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/config-system-logs-not-forwarding-to-syslog-server/m-p/1251010#M6794</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Config1.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/71047i11A10AB52A2062BD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Config1.png" alt="Config1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Config2.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/71048iB2DA8E47C8EC0E0F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Config2.png" alt="Config2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2026 13:59:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/config-system-logs-not-forwarding-to-syslog-server/m-p/1251010#M6794</guid>
      <dc:creator>V.Sambath</dc:creator>
      <dc:date>2026-03-26T13:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: Config/System Logs Not Forwarding to Syslog Server</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/config-system-logs-not-forwarding-to-syslog-server/m-p/1251011#M6795</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/788658209"&gt;@V.Sambath&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;A couple of questions:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Was this working previously, or is this a brand new setup that has never worked?&lt;/LI&gt;
&lt;LI&gt;Have you verified whether or not you're actually seeing traffic from the firewall on the receiving node or not? Depending on the system and the way that it's configured, it could be dropping the logs because it's failing to parse them.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;If the traffic crosses the dataplane (IE: if your MGMT interface routes through your firewall to reach your syslog server or you utilize a dataplane interface to send the logs) have you verified that the firewall is attempting to send the logs?&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Thu, 26 Mar 2026 14:03:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/config-system-logs-not-forwarding-to-syslog-server/m-p/1251011#M6795</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2026-03-26T14:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: Config/System Logs Not Forwarding to Syslog Server</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/config-system-logs-not-forwarding-to-syslog-server/m-p/1251017#M6796</link>
      <description>&lt;P&gt;1. This is an existing setup. Traffic and other logs are being successfully forwarded to the syslog server; however, Config and System logs have never been forwarded.&lt;/P&gt;
&lt;P&gt;2. Service Route is currently set to "Use Default."&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. Since traffic logs are working, it appears the dataplane path is fine. I also tried validating logs sent and I could see that Config logs are sent as expected. Below o/p,&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Config3.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/71049iE9098632BE3F92AA/image-size/large?v=v2&amp;amp;px=999" role="button" title="Config3.png" alt="Config3.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2026 14:23:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/config-system-logs-not-forwarding-to-syslog-server/m-p/1251017#M6796</guid>
      <dc:creator>V.Sambath</dc:creator>
      <dc:date>2026-03-26T14:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: Config/System Logs Not Forwarding to Syslog Server</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/config-system-logs-not-forwarding-to-syslog-server/m-p/1251022#M6797</link>
      <description>&lt;P&gt;Having the same issue since early February, opened a case with Palo.&lt;/P&gt;
&lt;P&gt;All other syslog types are sending&lt;/P&gt;
&lt;P&gt;Running 11.1.13&lt;/P&gt;
&lt;P&gt;CLI syslog forwarding show dequeued packets, but most of the time no sent packets.&lt;/P&gt;
&lt;P&gt;Interesting on a reboot or restart of the management plane it will then dump all the config logs but still broke after&amp;nbsp;the reboot.&amp;nbsp; Seeing dropped packets.&amp;nbsp; Palo and Syslog server are on the same zone.&lt;/P&gt;
&lt;P&gt;Have a DR firewall same hardware, PAN-OS, syslog configuration and same syslog server and its working.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe Palo has a bug in 11.1&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2026 15:26:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/config-system-logs-not-forwarding-to-syslog-server/m-p/1251022#M6797</guid>
      <dc:creator>ChrisWietharn</dc:creator>
      <dc:date>2026-03-26T15:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: Config/System Logs Not Forwarding to Syslog Server</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/config-system-logs-not-forwarding-to-syslog-server/m-p/1251657#M6810</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/40721"&gt;@ChrisWietharn&lt;/a&gt;&amp;nbsp; Today I noticed a strange thing, when i execute &amp;gt;debug log-receiver statistics,&amp;nbsp; my Config logs written rate is not increasing whereas System logs are continue to increase. Despite of this, no logs are sent. I am gonna clear the session between Syslog and MGT IP and see the results. Has Palo provided a fix for this issue to date?&lt;/P&gt;
&lt;P data-pm-slice="0 0 []"&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV data-olk-copy-source="MessageBody" data-ogsc="black"&gt;Line &amp;nbsp; 22: Config logs written: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 4334&lt;/DIV&gt;
&lt;DIV data-ogsc="black"&gt;Line 257: Config logs written: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 4334&lt;/DIV&gt;
&lt;DIV data-ogsc="black"&gt;Line 491: Config logs written: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 4334&lt;/DIV&gt;</description>
      <pubDate>Mon, 06 Apr 2026 10:34:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/config-system-logs-not-forwarding-to-syslog-server/m-p/1251657#M6810</guid>
      <dc:creator>V.Sambath</dc:creator>
      <dc:date>2026-04-06T10:34:15Z</dc:date>
    </item>
  </channel>
</rss>

