<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic syslog udp session keep alive ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-udp-session-keep-alive/m-p/525436#M108657</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When forwarding logs, they are being sent to udp 514. The udp time out is 30 seconds, and the syslog server actually receives packets every 5 seconds. However, &lt;STRONG&gt;I wonder why the firewall keeps the session longer than 30 seconds&lt;/STRONG&gt;. When the time is long, it is several minutes or hours, and sometimes the date passes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="스크린샷 2022-12-29 오후 2.34.03.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46553i713A0AD62D5B5680/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="스크린샷 2022-12-29 오후 2.34.03.png" alt="스크린샷 2022-12-29 오후 2.34.03.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="스크린샷 2022-12-29 오후 2.34.50.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46552i6C5E98EDBF7F0C80/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="스크린샷 2022-12-29 오후 2.34.50.png" alt="스크린샷 2022-12-29 오후 2.34.50.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Dec 2022 05:38:11 GMT</pubDate>
    <dc:creator>kimjeonghoon</dc:creator>
    <dc:date>2022-12-29T05:38:11Z</dc:date>
    <item>
      <title>syslog udp session keep alive ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-udp-session-keep-alive/m-p/525436#M108657</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When forwarding logs, they are being sent to udp 514. The udp time out is 30 seconds, and the syslog server actually receives packets every 5 seconds. However, &lt;STRONG&gt;I wonder why the firewall keeps the session longer than 30 seconds&lt;/STRONG&gt;. When the time is long, it is several minutes or hours, and sometimes the date passes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="스크린샷 2022-12-29 오후 2.34.03.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46553i713A0AD62D5B5680/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="스크린샷 2022-12-29 오후 2.34.03.png" alt="스크린샷 2022-12-29 오후 2.34.03.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="스크린샷 2022-12-29 오후 2.34.50.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46552i6C5E98EDBF7F0C80/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="스크린샷 2022-12-29 오후 2.34.50.png" alt="스크린샷 2022-12-29 오후 2.34.50.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2022 05:38:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-udp-session-keep-alive/m-p/525436#M108657</guid>
      <dc:creator>kimjeonghoon</dc:creator>
      <dc:date>2022-12-29T05:38:11Z</dc:date>
    </item>
    <item>
      <title>Re: syslog udp session keep alive ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-udp-session-keep-alive/m-p/525492#M108677</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Its because they are UDP packets/sessions. Here is an article from Palo Alto on this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;When monitoring the traffic logs using&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Monitor &amp;gt; logs &amp;gt; Traffic&lt;/I&gt;&lt;SPAN&gt;, some traffic is seen with the&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Session End Reason&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp; as&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;aged-out.&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp; Any traffic that uses UDP or ICMP is seen will have session end reason as&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;aged-out&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;in the traffic log. This is because unlike TCP, there is there is no way for a graceful termination of UDP session and so&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;aged-out&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;is a legitimate session-end reason for UDP (and ICMP) sessions.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMjLCAW" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMjLCAW&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2022 21:09:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-udp-session-keep-alive/m-p/525492#M108677</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-12-29T21:09:04Z</dc:date>
    </item>
    <item>
      <title>Re: syslog udp session keep alive ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-udp-session-keep-alive/m-p/525538#M108684</link>
      <description>&lt;P&gt;If you add "From port", "Packets sent" and "Packets received" columns you can see that until syslog sender is sending traffic from same source port Palo keeps same session open and packets are gathered under same session.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If no new packets in this session for 30 seconds then this session is closed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Dec 2022 16:51:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-udp-session-keep-alive/m-p/525538#M108684</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2022-12-30T16:51:04Z</dc:date>
    </item>
  </channel>
</rss>

