<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How we can monitor/detect that particular FW stopped sending traffic logs to LogCOllector in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-we-can-monitor-detect-that-particular-fw-stopped-sending/m-p/483445#M104350</link>
    <description>&lt;P&gt;I can't use syslog for some reason which I can't share here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea how to achieve my goal from LogCollector perspective?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;</description>
    <pubDate>Thu, 28 Apr 2022 06:58:03 GMT</pubDate>
    <dc:creator>S_Owoc</dc:creator>
    <dc:date>2022-04-28T06:58:03Z</dc:date>
    <item>
      <title>How we can monitor/detect that particular FW stopped sending traffic logs to LogCOllector</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-we-can-monitor-detect-that-particular-fw-stopped-sending/m-p/483128#M104329</link>
      <description>&lt;P&gt;Hi Community&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm looking for the possibility to be notified (trap/snmp/Panorama event) in the situation that a particular FW which is assigned to LogCollector for some reason stopped sending traffic to it. Let's assume that if there is a 1h gap I want to be notified.&lt;/P&gt;&lt;P&gt;For some reason, I'm not considering implementing Syslog here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When such a situation has occurred FW is logging:&lt;/P&gt;&lt;P&gt;( description contains 'Failed to connect to address: X.X.X.X port: 3978, conn id: lr-X.X.X.X-def' )&lt;/P&gt;&lt;P&gt;( description contains 'Number of hints on disk has exceeded 5000 due to log forward failures.' )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know that I can set up under Device&amp;gt;LogSettings new entry like the below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1862.png" style="width: 797px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40480i9595DED26C458785/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot_1862.png" alt="Screenshot_1862.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But this solution will generate an event on Panorama with severity informational (as the original event "'Failed to connect to address" was") when I'd like to have it marked as critical. Moreover, such config must be deployed to all FW, when we have just one LogCollector per dozens of FW. That's why I'm looking for something more clever &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently, this is my idea, its not tested but I'm pretty sure that guys here had the same problem and maybe someone will share the working solution here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 12:12:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-we-can-monitor-detect-that-particular-fw-stopped-sending/m-p/483128#M104329</guid>
      <dc:creator>S_Owoc</dc:creator>
      <dc:date>2022-04-27T12:12:56Z</dc:date>
    </item>
    <item>
      <title>Re: How we can monitor/detect that particular FW stopped sending traffic logs to LogCOllector</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-we-can-monitor-detect-that-particular-fw-stopped-sending/m-p/483416#M104347</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/138089"&gt;@S_Owoc&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Why aren't you considering implementing a simple syslog server that you could use to handle these alerts? If that's out, I would just have the device send an email/Slack alert itself so you know there's actually a problem.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 00:56:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-we-can-monitor-detect-that-particular-fw-stopped-sending/m-p/483416#M104347</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-04-28T00:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: How we can monitor/detect that particular FW stopped sending traffic logs to LogCOllector</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-we-can-monitor-detect-that-particular-fw-stopped-sending/m-p/483445#M104350</link>
      <description>&lt;P&gt;I can't use syslog for some reason which I can't share here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea how to achieve my goal from LogCollector perspective?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 06:58:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-we-can-monitor-detect-that-particular-fw-stopped-sending/m-p/483445#M104350</guid>
      <dc:creator>S_Owoc</dc:creator>
      <dc:date>2022-04-28T06:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: How we can monitor/detect that particular FW stopped sending traffic logs to LogCOllector</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-we-can-monitor-detect-that-particular-fw-stopped-sending/m-p/484011#M104404</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/138089"&gt;@S_Owoc&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;Only approach I can think of right now is forwarding that logs to Email relay.&lt;/P&gt;&lt;P&gt;- Create log system log forwarding profile, similar to your screenshot&lt;/P&gt;&lt;P&gt;- Select Email for forwarding method and create email profile with email relay that will accept email from the firewall.&lt;/P&gt;&lt;P&gt;- Configure all of this with separate template, that you can assign to any template stack that you want and have it pushed to all firewalls that you manage. You can use template variables to use different IP addresses for the mail relay if the firewalls are in different locations/regions and cannot reach same relay.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have practical experience with dedicated log collectors, but I am wondering wouldn't the log collector/panorama generate similar log if it loss connectivity with firewall? If so you can again have log forwarding to email, but from log collector perspective.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 May 2022 06:07:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-we-can-monitor-detect-that-particular-fw-stopped-sending/m-p/484011#M104404</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-05-01T06:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: How we can monitor/detect that particular FW stopped sending traffic logs to LogCOllector</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-we-can-monitor-detect-that-particular-fw-stopped-sending/m-p/484803#M104456</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This link seems to be a good starting point:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/administer-panorama/monitor-panorama/monitor-panorama-and-log-collector-statistics-using-snmp" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/administer-panorama/monitor-panorama/monitor-panorama-and-log-collector-statistics-using-snmp&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;log forwarding status from individual firewalls to Panorama and external servers.&lt;/P&gt;&lt;P&gt;Unfortunately, there is no OID listed for these values, has anyone idea where to find them?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 12:22:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-we-can-monitor-detect-that-particular-fw-stopped-sending/m-p/484803#M104456</guid>
      <dc:creator>S_Owoc</dc:creator>
      <dc:date>2022-05-04T12:22:37Z</dc:date>
    </item>
  </channel>
</rss>

