<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: firewall change event monitor in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/firewall-change-event-monitor/m-p/525161#M1296</link>
    <description>&lt;P&gt;Hello Pavel,&lt;/P&gt;
&lt;P&gt;Thank you for the suggestion pavel.!&lt;/P&gt;</description>
    <pubDate>Tue, 27 Dec 2022 08:17:01 GMT</pubDate>
    <dc:creator>SunilduttJ</dc:creator>
    <dc:date>2022-12-27T08:17:01Z</dc:date>
    <item>
      <title>firewall change event monitor</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/firewall-change-event-monitor/m-p/525081#M1294</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello Guy's&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. Add allow any/any rule:- If adding any new policies any/any rules in our environment. How I can forward/analyze logs to the Syslog server?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2. Added administrator account:- If any new admin account is added in Palo Alto locally. How can see the logs in the Syslog server?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3. Add authentication method:- We have SAML authentication in our environment. Do we have any other method to do that without using the SAML authentication method? How can we see the authentication logs in the Syslog server?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Sunildutt&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Dec 2022 08:56:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/firewall-change-event-monitor/m-p/525081#M1294</guid>
      <dc:creator>SunilduttJ</dc:creator>
      <dc:date>2022-12-26T08:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: firewall change event monitor</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/firewall-change-event-monitor/m-p/525142#M1295</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/224635"&gt;@SunilduttJ&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.&lt;/P&gt;
&lt;P&gt;All the configurations logs can be found under: &lt;STRONG&gt;Monitor&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Logs&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Configuration&lt;/STRONG&gt;. You can send all the configuration logs to syslog server from: &lt;STRONG&gt;Device&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Log Settings&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Configuration&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Add&lt;/STRONG&gt;, then select syslog server from drop down list. If you are interested only in sending security policy creation logs, then you can use this filter: &lt;STRONG&gt;( full-path contains '/rulebase/security/' )&lt;/STRONG&gt;. Unless the name of the policy includes some indication that it is "any" policy, I do not think there is another way to send selectively forward only logs related to "any/any" policy.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1672113447394.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46450i222443D1497243F6/image-size/large?v=v2&amp;amp;px=999" role="button" title="PavelK_0-1672113447394.png" alt="PavelK_0-1672113447394.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2.&lt;/P&gt;
&lt;P&gt;For the second point, these logs are in the configuration logs as well. You can setup the same forwarding. You can narrow down only add new account related logs by using this filter:&amp;nbsp;&lt;STRONG&gt;( full-path contains '/users/entry' ) and ( cmd eq set&lt;/STRONG&gt; ).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3.&lt;/P&gt;
&lt;P&gt;Some of the authentication logs are located under: &lt;STRONG&gt;Monitor&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Logs&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Authentication&lt;/STRONG&gt; and some under &lt;STRONG&gt;System&lt;/STRONG&gt;. You can forward these logs to syslog server. If you are searching only logs related to admin adding authentication method, then this will be recorded in the configuration logs. Would it be possible to elaborate more what information would you like to capture from SAML logs?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2022 04:18:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/firewall-change-event-monitor/m-p/525142#M1295</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-12-27T04:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: firewall change event monitor</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/firewall-change-event-monitor/m-p/525161#M1296</link>
      <description>&lt;P&gt;Hello Pavel,&lt;/P&gt;
&lt;P&gt;Thank you for the suggestion pavel.!&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2022 08:17:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/firewall-change-event-monitor/m-p/525161#M1296</guid>
      <dc:creator>SunilduttJ</dc:creator>
      <dc:date>2022-12-27T08:17:01Z</dc:date>
    </item>
  </channel>
</rss>

