<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Managed PAs system log filtering and email alert on Panorama in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/managed-pas-system-log-filtering-and-email-alert-on-panorama/m-p/469505#M765</link>
    <description>&lt;P&gt;Sorry to hijack this thread, but I am having similar issue:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;What am I missing here? I want an email alert when the Panorama sees a device pair not sync'd. I am using the System logs for this following this document:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="_3t5uN8xUmg0TOwRCOGQEcU" href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGjCAK" target="_blank" rel="noopener nofollow ugc"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGjCAK&lt;/A&gt;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Filtering on (description contains 'synchronize manually') and (severity eq high)&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Seems easy enough, but what I don't understand is how do you know it's working? There is no way to test and it doesn't really explain what triggers it to send, how often it checks, nothing.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;The end of the doc says to look at this doc for "How to Configure Email Alerts"&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="_3t5uN8xUmg0TOwRCOGQEcU" href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHZCA0" target="_blank" rel="noopener nofollow ugc"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHZCA0&lt;/A&gt;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;But you can't select the System Logs that you just configured in the previous doc.&lt;/P&gt;</description>
    <pubDate>Tue, 01 Mar 2022 15:14:36 GMT</pubDate>
    <dc:creator>RobertShawver</dc:creator>
    <dc:date>2022-03-01T15:14:36Z</dc:date>
    <item>
      <title>Managed PAs system log filtering and email alert on Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/managed-pas-system-log-filtering-and-email-alert-on-panorama/m-p/451301#M546</link>
      <description>&lt;P&gt;If PAs are managed with Panorama and PAs are configured for log forwarding to Panorama.&amp;nbsp;On Panorama &amp;gt; Log settings, Filter can be added for PAs system logs, logs can be seen on 'view filtered logs' as well. but email alerts are not generated. Only Panorama-based events are sent in email. If log settings are only for panorama system logs, then why it's showing the PAs system logs in view filtered logs. Is it expected to be like this?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If yes, then is there any method to apply a filter for PA systems logs and create email alerts against that filter on Panorama?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Dec 2021 19:41:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/managed-pas-system-log-filtering-and-email-alert-on-panorama/m-p/451301#M546</guid>
      <dc:creator>b.nazir</dc:creator>
      <dc:date>2021-12-03T19:41:55Z</dc:date>
    </item>
    <item>
      <title>Re: Managed PAs system log filtering and email alert on Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/managed-pas-system-log-filtering-and-email-alert-on-panorama/m-p/451337#M547</link>
      <description>&lt;P&gt;Thank you for posting question&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/134139"&gt;@b.nazir&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Getting email alerts from Panorama for Firewall System Logs is functional feature and these alerts are not limited to Panorama System Logs. By looking into my Panorama setup where this is working, the setup is fairly straightforward and based on what you described your setup should work. Just in the case, could you please confirm that you configured it in a similar way as below example for critical logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1638569201649.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37936i21E919D4484F830A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_0-1638569201649.png" alt="PavelK_0-1638569201649.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Dec 2021 22:10:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/managed-pas-system-log-filtering-and-email-alert-on-panorama/m-p/451337#M547</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-12-03T22:10:59Z</dc:date>
    </item>
    <item>
      <title>Re: Managed PAs system log filtering and email alert on Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/managed-pas-system-log-filtering-and-email-alert-on-panorama/m-p/451546#M549</link>
      <description>&lt;P&gt;Hi Pavel,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for the quick reply.&lt;/P&gt;
&lt;P&gt;yes, I have the same config but a different filter. Actually, I am trying to put a filter to detect the license expiration notification for managed PAs via email.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In view filter logs, I can see all the events but not via email. Email settings are correct, getting email alerts for other severity levels.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2021_12_06_14_08_23_Panorama.png" style="width: 827px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37963iEEBDDB7CFDBCB9FB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2021_12_06_14_08_23_Panorama.png" alt="2021_12_06_14_08_23_Panorama.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Dec 2021 13:14:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/managed-pas-system-log-filtering-and-email-alert-on-panorama/m-p/451546#M549</guid>
      <dc:creator>b.nazir</dc:creator>
      <dc:date>2021-12-06T13:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: Managed PAs system log filtering and email alert on Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/managed-pas-system-log-filtering-and-email-alert-on-panorama/m-p/451684#M550</link>
      <description>&lt;P&gt;Thank you for reply and additional information&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/134139"&gt;@b.nazir&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see. I just crosschecked setting on my side and searched my mailbox and I realized that I am getting these license expiration alerts directly from the Firewalls instead of from Panorama. The syslog as well as email profiles are pushed from Template. I have an email alert on Panorama for critical severities, but this alert comes from Firewall itself. I could not find any reference whether this is supported, however all examples from KB are referring to setting this up locally on Firewall, so potentially this is not supported from Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Mon, 06 Dec 2021 22:55:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/managed-pas-system-log-filtering-and-email-alert-on-panorama/m-p/451684#M550</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-12-06T22:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: Managed PAs system log filtering and email alert on Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/managed-pas-system-log-filtering-and-email-alert-on-panorama/m-p/469505#M765</link>
      <description>&lt;P&gt;Sorry to hijack this thread, but I am having similar issue:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;What am I missing here? I want an email alert when the Panorama sees a device pair not sync'd. I am using the System logs for this following this document:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="_3t5uN8xUmg0TOwRCOGQEcU" href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGjCAK" target="_blank" rel="noopener nofollow ugc"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGjCAK&lt;/A&gt;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Filtering on (description contains 'synchronize manually') and (severity eq high)&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Seems easy enough, but what I don't understand is how do you know it's working? There is no way to test and it doesn't really explain what triggers it to send, how often it checks, nothing.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;The end of the doc says to look at this doc for "How to Configure Email Alerts"&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="_3t5uN8xUmg0TOwRCOGQEcU" href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHZCA0" target="_blank" rel="noopener nofollow ugc"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHZCA0&lt;/A&gt;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;But you can't select the System Logs that you just configured in the previous doc.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2022 15:14:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/managed-pas-system-log-filtering-and-email-alert-on-panorama/m-p/469505#M765</guid>
      <dc:creator>RobertShawver</dc:creator>
      <dc:date>2022-03-01T15:14:36Z</dc:date>
    </item>
  </channel>
</rss>

