<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue that specific policy traffic logs fail to forward to syslog server and drop from firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issue-that-specific-policy-traffic-logs-fail-to-forward-to/m-p/515417#M107043</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/208779"&gt;@JoHyeonJae&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;your customer might be hitting an issue&amp;nbsp;PAN-185616 addressed in 9.1.14:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1663648642166.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44000i5B2B54A66F1C15BA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_0-1663648642166.png" alt="PavelK_0-1663648642166.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
    <pubDate>Tue, 20 Sep 2022 04:38:25 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2022-09-20T04:38:25Z</dc:date>
    <item>
      <title>Issue that specific policy traffic logs fail to forward to syslog server and drop from firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-that-specific-policy-traffic-logs-fail-to-forward-to/m-p/515409#M107040</link>
      <description>&lt;P class=""&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;OS : 9.1.6&lt;BR /&gt;&lt;BR /&gt;Currently, my customer is facing Issues where logs generated (TO_DNS policy) from a specific policy of more than 10,000 LPS are dropped without being forwarded to the syslog server.&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;The Traffic Log of the firewall is verifiable, but the Forwarding Stats Syslog Drop Count is constantly increasing, debug log-receiver statistics have been confirmed, and less than 1,000 Total LPS appear in addition to this policy.&lt;BR /&gt;&lt;BR /&gt;There is no logs for that policy on the syslog server because it is dropped without being forwarded by the firewall.&lt;BR /&gt;&lt;BR /&gt;The Log Setting/Log Forwarding Profile in the policy settings is set normally, so it seems to be no problem with the settings.&lt;BR /&gt;&lt;BR /&gt;I will let you know, if you guys need additional info.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The Device Log Forwarding Limit of PA-3260 is written in 24,000/LPS as shown in the document below, so I wonder why it is dropped.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="스크린샷 2022-09-20 오전 11.52.58.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43998i726D3056CED47FB2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="스크린샷 2022-09-20 오전 11.52.58.png" alt="스크린샷 2022-09-20 오전 11.52.58.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;BR /&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 02:53:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-that-specific-policy-traffic-logs-fail-to-forward-to/m-p/515409#M107040</guid>
      <dc:creator>JoHyeonJae</dc:creator>
      <dc:date>2022-09-20T02:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: Issue that specific policy traffic logs fail to forward to syslog server and drop from firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-that-specific-policy-traffic-logs-fail-to-forward-to/m-p/515417#M107043</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/208779"&gt;@JoHyeonJae&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;your customer might be hitting an issue&amp;nbsp;PAN-185616 addressed in 9.1.14:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1663648642166.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44000i5B2B54A66F1C15BA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_0-1663648642166.png" alt="PavelK_0-1663648642166.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 04:38:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-that-specific-policy-traffic-logs-fail-to-forward-to/m-p/515417#M107043</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-09-20T04:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: Issue that specific policy traffic logs fail to forward to syslog server and drop from firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-that-specific-policy-traffic-logs-fail-to-forward-to/m-p/515419#M107045</link>
      <description>&lt;P&gt;Thank you for your information.&lt;BR /&gt;&lt;BR /&gt;Due to this bug can cause drop in a particular policy?&lt;BR /&gt;&lt;BR /&gt;I am not sure this can match about this issue..&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 04:44:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-that-specific-policy-traffic-logs-fail-to-forward-to/m-p/515419#M107045</guid>
      <dc:creator>JoHyeonJae</dc:creator>
      <dc:date>2022-09-20T04:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: Issue that specific policy traffic logs fail to forward to syslog server and drop from firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-that-specific-policy-traffic-logs-fail-to-forward-to/m-p/515421#M107046</link>
      <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/208779"&gt;@JoHyeonJae&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this fix is applied to sending queue which is processing all the logs irrespectively what policy has generated it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 04:58:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-that-specific-policy-traffic-logs-fail-to-forward-to/m-p/515421#M107046</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-09-20T04:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: Issue that specific policy traffic logs fail to forward to syslog server and drop from firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-that-specific-policy-traffic-logs-fail-to-forward-to/m-p/515428#M107049</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have one more question.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Since the send queue has become smaller due to the OS bug, is the issue caused when the LPS value increases?&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 06:07:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-that-specific-policy-traffic-logs-fail-to-forward-to/m-p/515428#M107049</guid>
      <dc:creator>JoHyeonJae</dc:creator>
      <dc:date>2022-09-20T06:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: Issue that specific policy traffic logs fail to forward to syslog server and drop from firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-that-specific-policy-traffic-logs-fail-to-forward-to/m-p/515546#M107072</link>
      <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/208779"&gt;@JoHyeonJae&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can't answer this with certainty. In any case, I would recommend to upgrade PAN-OS to the version that has this fix or newer, then observe this issue again. The symptom of this bug is random log loss while sending logs to 3rd party system causing difference in logs between Firewall and 3rd party SIEM. If you are hitting serios s&lt;SPAN&gt;yslog drop count after reaching certain log rate, then the issue might be something else. Opening a ticket to support might be appropriate in this case.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Kind Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Pavel&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 22:06:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-that-specific-policy-traffic-logs-fail-to-forward-to/m-p/515546#M107072</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-09-20T22:06:25Z</dc:date>
    </item>
    <item>
      <title>Re: Issue that specific policy traffic logs fail to forward to syslog server and drop from firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-that-specific-policy-traffic-logs-fail-to-forward-to/m-p/515556#M107075</link>
      <description>&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 00:18:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-that-specific-policy-traffic-logs-fail-to-forward-to/m-p/515556#M107075</guid>
      <dc:creator>JoHyeonJae</dc:creator>
      <dc:date>2022-09-21T00:18:44Z</dc:date>
    </item>
  </channel>
</rss>

