<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Scheduled Log Export based on custom queries in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/scheduled-log-export-based-on-custom-queries/m-p/469118#M102889</link>
    <description>&lt;P&gt;Is there any option to schedule custom traffic reports based on custom queries and to get it exported automatically .?&lt;/P&gt;&lt;P&gt;Currently, we are exporting the traffic logs manually from&amp;nbsp; &lt;FONT face="arial black,avant garde"&gt;Monitor &amp;gt; Logs &amp;gt;Traffic&lt;/FONT&gt; and pasting the queries ( some of the sample queries is mentioned below) in the search bar (apply filter) and export as csv file .&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have many queries like below to export ..Kindly provide any option for scheduled export ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;example of some custom query is given below :&lt;/P&gt;&lt;P&gt;(receive_time geq '2022/01/12') and (receive_time leq '2022/01/13') and (( natdst eq 172.22.123.12 ) or ( addr.dst in 172.22.123.12 ))&lt;/P&gt;&lt;P&gt;(receive_time geq '2022/01/12') and (receive_time leq '2022/01/13') and ( addr.dst in 172.22.114.10 )&lt;/P&gt;&lt;P&gt;(receive_time geq '2022/01/12') and (receive_time leq '2022/01/13') and (( natdst eq 172.22.113.19 ) or ( addr.dst in 172.22.113.19 ))&lt;/P&gt;</description>
    <pubDate>Mon, 28 Feb 2022 06:11:44 GMT</pubDate>
    <dc:creator>anishuthuman</dc:creator>
    <dc:date>2022-02-28T06:11:44Z</dc:date>
    <item>
      <title>Scheduled Log Export based on custom queries</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scheduled-log-export-based-on-custom-queries/m-p/469118#M102889</link>
      <description>&lt;P&gt;Is there any option to schedule custom traffic reports based on custom queries and to get it exported automatically .?&lt;/P&gt;&lt;P&gt;Currently, we are exporting the traffic logs manually from&amp;nbsp; &lt;FONT face="arial black,avant garde"&gt;Monitor &amp;gt; Logs &amp;gt;Traffic&lt;/FONT&gt; and pasting the queries ( some of the sample queries is mentioned below) in the search bar (apply filter) and export as csv file .&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have many queries like below to export ..Kindly provide any option for scheduled export ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;example of some custom query is given below :&lt;/P&gt;&lt;P&gt;(receive_time geq '2022/01/12') and (receive_time leq '2022/01/13') and (( natdst eq 172.22.123.12 ) or ( addr.dst in 172.22.123.12 ))&lt;/P&gt;&lt;P&gt;(receive_time geq '2022/01/12') and (receive_time leq '2022/01/13') and ( addr.dst in 172.22.114.10 )&lt;/P&gt;&lt;P&gt;(receive_time geq '2022/01/12') and (receive_time leq '2022/01/13') and (( natdst eq 172.22.113.19 ) or ( addr.dst in 172.22.113.19 ))&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2022 06:11:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scheduled-log-export-based-on-custom-queries/m-p/469118#M102889</guid>
      <dc:creator>anishuthuman</dc:creator>
      <dc:date>2022-02-28T06:11:44Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled Log Export based on custom queries</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scheduled-log-export-based-on-custom-queries/m-p/469191#M102902</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/210858"&gt;@anishuthuman&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can create a custom report (Monitor &amp;gt; Manage Custom Reports) and add your filters or create new ones using the 'query builder':&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiwi_0-1646041467142.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39384i4E53289941290E26/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiwi_0-1646041467142.png" alt="kiwi_0-1646041467142.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once created, you can add it to a report group (Monitor &amp;gt; PDF Reports &amp;gt; Report Group) and add the report group to an Email Scheduler (Monitor &amp;gt; PDF Reports &amp;gt; Email Scheduler).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or if you don't want to create an email scheduler for it you can, once it's created and ran for a first time check it under 'Monitor &amp;gt; Reports'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=E8TEneszgDc" target="_blank" rel="noopener"&gt;Config Custom Reports&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 28 Feb 2022 09:53:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scheduled-log-export-based-on-custom-queries/m-p/469191#M102902</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2022-02-28T09:53:42Z</dc:date>
    </item>
  </channel>
</rss>

