<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert on Policy Rule Modification in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/alert-on-policy-rule-modification/m-p/462116#M102226</link>
    <description>&lt;P&gt;Hi Valentino,&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Email-server-configlog-change.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38914i1B5E985BB1ADCC20/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Email-server-configlog-change.jpg" alt="Email-server-configlog-change.jpg" /&gt;&lt;/span&gt;Yes, it's possible to configure Configuration log settings with an EMAIL server. You can send a log to email for every policy config change as a notification.&lt;/P&gt;</description>
    <pubDate>Mon, 31 Jan 2022 14:54:00 GMT</pubDate>
    <dc:creator>Mudhireddy</dc:creator>
    <dc:date>2022-01-31T14:54:00Z</dc:date>
    <item>
      <title>Alert on Policy Rule Modification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alert-on-policy-rule-modification/m-p/462101#M102225</link>
      <description>&lt;P&gt;Hello Everybody,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know if there is a possibility to be alerted in case of modification of a rule.&lt;BR /&gt;For example: if a rule is modified, an email is automatically sent to a specific person&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Valentino&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jan 2022 14:00:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alert-on-policy-rule-modification/m-p/462101#M102225</guid>
      <dc:creator>Valentino</dc:creator>
      <dc:date>2022-01-31T14:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: Alert on Policy Rule Modification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alert-on-policy-rule-modification/m-p/462116#M102226</link>
      <description>&lt;P&gt;Hi Valentino,&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Email-server-configlog-change.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38914i1B5E985BB1ADCC20/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Email-server-configlog-change.jpg" alt="Email-server-configlog-change.jpg" /&gt;&lt;/span&gt;Yes, it's possible to configure Configuration log settings with an EMAIL server. You can send a log to email for every policy config change as a notification.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jan 2022 14:54:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alert-on-policy-rule-modification/m-p/462116#M102226</guid>
      <dc:creator>Mudhireddy</dc:creator>
      <dc:date>2022-01-31T14:54:00Z</dc:date>
    </item>
    <item>
      <title>Re: Alert on Policy Rule Modification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alert-on-policy-rule-modification/m-p/462129#M102227</link>
      <description>&lt;P&gt;Thank you for your answer.&lt;BR /&gt;Thus, my need is to alert by mail when modifying specific rules.&lt;/P&gt;&lt;P&gt;Indeed, I have a hundred sensitive rules which must be monitored more precisely than the three thousand other rules.&lt;/P&gt;&lt;P&gt;I have a column "modified" and I thought to create an alert from Splunk with this data. But this column is not shown in Splunk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have any idea, you're welcome&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jan 2022 15:28:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alert-on-policy-rule-modification/m-p/462129#M102227</guid>
      <dc:creator>Valentino</dc:creator>
      <dc:date>2022-01-31T15:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: Alert on Policy Rule Modification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alert-on-policy-rule-modification/m-p/462221#M102232</link>
      <description>&lt;P&gt;Ah, splunk is easier! You would create an HTTP server profile instead of email.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See an example for slack &lt;A href="https://live.paloaltonetworks.com/t5/log-forwarding-articles/pan-os-8-0-http-log-integration-with-slack/ta-p/172093" target="_self"&gt;here&lt;/A&gt;. So you would then just use a predefined format for config logs, but change the parameters to only be for the rules you are referencing. A little HTML copy-paste, but a big automation improvement in monitoring.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jan 2022 19:09:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alert-on-policy-rule-modification/m-p/462221#M102232</guid>
      <dc:creator>LAYER_8</dc:creator>
      <dc:date>2022-01-31T19:09:35Z</dc:date>
    </item>
  </channel>
</rss>

