<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Syslog configuration to Sumo Logic in PAN-OS 7.1 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration-to-sumo-logic-in-pan-os-7-1/m-p/477722#M103696</link>
    <description>&lt;P&gt;want to make hosted collector works. need to do the below setup.&amp;nbsp;&lt;/P&gt;&lt;P&gt;By default, the PA syslog only support 1.2 forced. need to skip.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://weberblog.net/palo-alto-syslog-via-tls/" target="_blank"&gt;https://weberblog.net/palo-alto-syslog-via-tls/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;configure&amp;gt;&lt;/P&gt;&lt;P&gt;set syslogng-ssl-conn-validation explicit OCSP skip CRL skip EKU skip&lt;BR /&gt;set syslogng-ssl-conn-validation all-cons skip&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;syslogng ssl connection validation settings:&lt;BR /&gt;all-conns:skip&lt;BR /&gt;crl:skip&lt;BR /&gt;ocsp:skip&lt;BR /&gt;eku:skip&lt;/P&gt;</description>
    <pubDate>Sat, 02 Apr 2022 10:44:50 GMT</pubDate>
    <dc:creator>RAX-NetSec</dc:creator>
    <dc:date>2022-04-02T10:44:50Z</dc:date>
    <item>
      <title>Syslog configuration to Sumo Logic in PAN-OS 7.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration-to-sumo-logic-in-pan-os-7-1/m-p/186443#M56873</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HI, all.&lt;/P&gt;&lt;P&gt;I'm looking for some reference of integration with Sumo Logic for Syslog setting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My customer wants to receive logs from PA FW.&lt;/P&gt;&lt;P&gt;I'm looking at guides both Sumo logic web site and Live community in here,&lt;/P&gt;&lt;P&gt;but I think there's more information needed. Or I'd configured in wrong way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Syslog Server:&amp;nbsp;syslog.collection.us2.sumologic.com&lt;/P&gt;&lt;P&gt;Transport: TCP TLS Port(Set as 'SSL', when I set as 'TCP' then connection error occured)&lt;/P&gt;&lt;P&gt;Port: 6514&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="syslog-configuration-file.PNG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12377i16AC30603A7E789E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="syslog-configuration-file.PNG" alt="syslog-configuration-file.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;1-1. Syslog Server Profile&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="system-log-file.PNG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12378iD5E646DA7A6E0FA7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="system-log-file.PNG" alt="system-log-file.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;1-2. System Log; connection error (When I set 'TCP' instead of 'SSL' at 'Transport' tap in 1-1)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Customer said, I think I should user 'Token' below in like 1-3, but I think somethings are wrong.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="token-file.PNG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12379iD4B5A355C15F0130/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="token-file.PNG" alt="token-file.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;1-3. Sample - Token/Host/TCP TLS Port&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;####&lt;/P&gt;&lt;P&gt;After I configured like 1-1, and set log settings in system and policies&lt;/P&gt;&lt;P&gt;I could see the session connected in session browser without not disconnection.&lt;/P&gt;&lt;P&gt;But, there were no logs in Sumo Logic Server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think there's more configured needed for intergrated well.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I'm suspecting Syslog Server Address problem, and some addtional configuration for SSL related.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ex) Generate Certificate(but, there was no option of 'Secure Syslog check box' in PAN-OS 7.1), and so on.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If someone did this integration, Sumo Logic with PAN-OS 7.1&lt;/P&gt;&lt;P&gt;Please let me know the solution.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have a great day &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 11:15:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration-to-sumo-logic-in-pan-os-7-1/m-p/186443#M56873</guid>
      <dc:creator>animofernando</dc:creator>
      <dc:date>2017-11-10T11:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog configuration to Sumo Logic in PAN-OS 7.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration-to-sumo-logic-in-pan-os-7-1/m-p/186792#M56934</link>
      <description>&lt;P&gt;Solved.&lt;/P&gt;&lt;P&gt;I should've noticed that I needed to install 'installed collector' as a syslog server.&lt;/P&gt;&lt;P&gt;I misunderstood.&lt;/P&gt;&lt;P&gt;and TCP/UDP supported.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="syslog-monitor.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12410i2F5649930164A25C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="syslog-monitor.png" alt="syslog-monitor.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2017 00:05:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration-to-sumo-logic-in-pan-os-7-1/m-p/186792#M56934</guid>
      <dc:creator>animofernando</dc:creator>
      <dc:date>2017-11-14T00:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog configuration to Sumo Logic in PAN-OS 7.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration-to-sumo-logic-in-pan-os-7-1/m-p/187114#M56984</link>
      <description>&lt;P&gt;Customer asked another one, deploying in 'Hosted Collector'&lt;/P&gt;&lt;P&gt;Hosted Collector needs for rsyslog or syslog-ng, I should look into it.&lt;/P&gt;&lt;P&gt;I think it is more complecated to configure. Anyway.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have a great day&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 06:06:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration-to-sumo-logic-in-pan-os-7-1/m-p/187114#M56984</guid>
      <dc:creator>animofernando</dc:creator>
      <dc:date>2017-11-15T06:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog configuration to Sumo Logic in PAN-OS 7.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration-to-sumo-logic-in-pan-os-7-1/m-p/461760#M102194</link>
      <description>&lt;P&gt;Hi!&lt;BR /&gt;I'm currently facing the same issue. I followed SL &lt;A href="https://help.sumologic.com/Cloud_SIEM_Enterprise/Ingestion_Guides/Palo_Alto_Firewall" target="_self"&gt;documentation&lt;/A&gt;&amp;nbsp;and I wasn't able to forward any logs (status always "None" from SL).&lt;/P&gt;&lt;P&gt;Could you please share the steps (or document) that you followed in order to solve this? Did you change transport to TCP/UDP instead of SSL?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jan 2022 12:52:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration-to-sumo-logic-in-pan-os-7-1/m-p/461760#M102194</guid>
      <dc:creator>echahine</dc:creator>
      <dc:date>2022-01-28T12:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog configuration to Sumo Logic in PAN-OS 7.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration-to-sumo-logic-in-pan-os-7-1/m-p/477722#M103696</link>
      <description>&lt;P&gt;want to make hosted collector works. need to do the below setup.&amp;nbsp;&lt;/P&gt;&lt;P&gt;By default, the PA syslog only support 1.2 forced. need to skip.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://weberblog.net/palo-alto-syslog-via-tls/" target="_blank"&gt;https://weberblog.net/palo-alto-syslog-via-tls/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;configure&amp;gt;&lt;/P&gt;&lt;P&gt;set syslogng-ssl-conn-validation explicit OCSP skip CRL skip EKU skip&lt;BR /&gt;set syslogng-ssl-conn-validation all-cons skip&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;syslogng ssl connection validation settings:&lt;BR /&gt;all-conns:skip&lt;BR /&gt;crl:skip&lt;BR /&gt;ocsp:skip&lt;BR /&gt;eku:skip&lt;/P&gt;</description>
      <pubDate>Sat, 02 Apr 2022 10:44:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration-to-sumo-logic-in-pan-os-7-1/m-p/477722#M103696</guid>
      <dc:creator>RAX-NetSec</dc:creator>
      <dc:date>2022-04-02T10:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog configuration to Sumo Logic in PAN-OS 7.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration-to-sumo-logic-in-pan-os-7-1/m-p/513881#M106703</link>
      <description>&lt;P&gt;This worked fantastic for me but I have one question:&amp;nbsp; After making this change, is it permanent?&amp;nbsp; I see no way to commit or save it.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Sep 2022 19:34:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration-to-sumo-logic-in-pan-os-7-1/m-p/513881#M106703</guid>
      <dc:creator>BaudMatt</dc:creator>
      <dc:date>2022-09-02T19:34:26Z</dc:date>
    </item>
  </channel>
</rss>

