<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SNMP Trap Monitoring in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/snmp-trap-monitoring/m-p/547151#M111777</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/298531"&gt;@Khassam&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;As I already mentioned - everything that is logged as log event can be forwarded as SNMP trap, you just need to find which log type and subtype to filter by. The type of information you mention is in system logs.&lt;/P&gt;
&lt;P&gt;Here you can see what subtype its covers -&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/system-log-fields" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/system-log-fields&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/view-and-manage-logs/log-types-and-severity-levels/system-logs" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/view-and-manage-logs/log-types-and-severity-levels/system-logs&lt;/A&gt; &lt;/P&gt;</description>
    <pubDate>Sun, 25 Jun 2023 07:16:57 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2023-06-25T07:16:57Z</dc:date>
    <item>
      <title>SNMP Trap Monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/snmp-trap-monitoring/m-p/546379#M111681</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We were wondering about the feasibility of configuring SNMP traps for some of our Firewalls instead of using SNMP polling.&lt;/P&gt;
&lt;P&gt;Currently we're using SNMP polling to monitor information like :&lt;/P&gt;
&lt;P&gt;- Interface status &lt;BR /&gt;- Interface bandwidth&lt;BR /&gt;- Temperature &lt;BR /&gt;- CPU Management and Data&lt;BR /&gt;- Log Rate &lt;BR /&gt;- Sessions&lt;BR /&gt;- HA cluster&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In your documentation SNMP Monitoring and Traps, it says that we have to use Log Forwarding but we are unsure that the information we want to monitor exist in the Log type.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We will be glad if you could confirm that migrating to a SNMP trap solution will not impact our current monitoring information.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 14:46:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/snmp-trap-monitoring/m-p/546379#M111681</guid>
      <dc:creator>Khassam</dc:creator>
      <dc:date>2023-06-19T14:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP Trap Monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/snmp-trap-monitoring/m-p/546469#M111696</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/298531"&gt;@Khassam&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;You have understand that correctly - SNMP traps in PAN firewalls are configured with log forwarding profiles, where you can specify which log type to be forwarded as trap.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However the screenshot you have provided is for Log Forwarding object, which is used for "traffic related" logs that you can apply on any security rules. What you actually need is here - &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/device/device-log-settings" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/device/device-log-settings&lt;/A&gt; For your specific case you need to configure log forwarding for System Logs and using the Filter to specify which exactly sub-type system logs you want to send as traps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From top of my head I believe the following from your list are available as system logs and therefor can be forwarded as traps:&lt;/P&gt;
&lt;P&gt;- interface status: log event for up or down is generated&lt;/P&gt;
&lt;P&gt;- temperature: not completely sure, but I believe system log will be generated when critical temp is reaced&lt;/P&gt;
&lt;P&gt;- cpu management and data: similar to temp, when critical levels are reached it should be logged.&lt;/P&gt;
&lt;P&gt;- ha state: change in member state (passive, active or down) will be logged as well as HA interfaces (they are logged in ha sub-type )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am not sure the following can be sent as traps:&lt;/P&gt;
&lt;P&gt;- int bandwidth&lt;/P&gt;
&lt;P&gt;- log rate&lt;/P&gt;
&lt;P&gt;- session count&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 11:12:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/snmp-trap-monitoring/m-p/546469#M111696</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-06-20T11:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP Trap Monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/snmp-trap-monitoring/m-p/546586#M111708</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;SNMP polling is preferred to get more information on your device. I highly recommend using SNMPv3 for this purpose.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 21:33:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/snmp-trap-monitoring/m-p/546586#M111708</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-06-20T21:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP Trap Monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/snmp-trap-monitoring/m-p/546660#M111713</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your answer.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried to find some documentation to confirm but with no success. I'll be glad if you have any document that confirm if each monitoring information will be available with SNMP Trap.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 07:36:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/snmp-trap-monitoring/m-p/546660#M111713</guid>
      <dc:creator>Khassam</dc:creator>
      <dc:date>2023-06-21T07:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP Trap Monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/snmp-trap-monitoring/m-p/546661#M111714</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know but we have a new network configuration where It won't be possible to allow incoming SNMP flows. This is why we're trying to figure out the feasibility of a SNMP trap solution.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 07:40:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/snmp-trap-monitoring/m-p/546661#M111714</guid>
      <dc:creator>Khassam</dc:creator>
      <dc:date>2023-06-21T07:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP Trap Monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/snmp-trap-monitoring/m-p/547151#M111777</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/298531"&gt;@Khassam&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;As I already mentioned - everything that is logged as log event can be forwarded as SNMP trap, you just need to find which log type and subtype to filter by. The type of information you mention is in system logs.&lt;/P&gt;
&lt;P&gt;Here you can see what subtype its covers -&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/system-log-fields" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/system-log-fields&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/view-and-manage-logs/log-types-and-severity-levels/system-logs" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/view-and-manage-logs/log-types-and-severity-levels/system-logs&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Sun, 25 Jun 2023 07:16:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/snmp-trap-monitoring/m-p/547151#M111777</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-06-25T07:16:57Z</dc:date>
    </item>
  </channel>
</rss>

