<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Log System setting in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/log-system-setting/m-p/549486#M112123</link>
    <description>&lt;P&gt;I want to set up messages to be sent to email&amp;nbsp;&lt;LI-MESSAGE title="Log Settings - Config" uid="338083" url="https://live.paloaltonetworks.com/t5/best-practice-assessment-device/log-settings-config/m-p/338083#U338083" discussion_style_icon_css="lia-mention-container-editor-message lia-img-icon-tkb-thread lia-fa-icon lia-fa-tkb lia-fa-thread lia-fa"&gt;&lt;/LI-MESSAGE&gt;&amp;nbsp;&lt;BR /&gt;I want every user who connects to the admin to receive an email no matter where the WAB or CLI or IP source comes from.&lt;/P&gt;
&lt;P&gt;@filter builder&lt;/P&gt;
&lt;P&gt;(severity eq informational) and (description contains 'logged in via WEB') or (description contains 'logged in via CLI')&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is what I configured Filter but only CLI works&lt;BR /&gt;Am I missing something?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would appreciate your help.3&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shalev_0-1689570642938.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/51624iDA533F5DD923B078/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Shalev_0-1689570642938.png" alt="Shalev_0-1689570642938.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Jul 2023 05:10:52 GMT</pubDate>
    <dc:creator>Shalev</dc:creator>
    <dc:date>2023-07-17T05:10:52Z</dc:date>
    <item>
      <title>Log System setting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-system-setting/m-p/549486#M112123</link>
      <description>&lt;P&gt;I want to set up messages to be sent to email&amp;nbsp;&lt;LI-MESSAGE title="Log Settings - Config" uid="338083" url="https://live.paloaltonetworks.com/t5/best-practice-assessment-device/log-settings-config/m-p/338083#U338083" discussion_style_icon_css="lia-mention-container-editor-message lia-img-icon-tkb-thread lia-fa-icon lia-fa-tkb lia-fa-thread lia-fa"&gt;&lt;/LI-MESSAGE&gt;&amp;nbsp;&lt;BR /&gt;I want every user who connects to the admin to receive an email no matter where the WAB or CLI or IP source comes from.&lt;/P&gt;
&lt;P&gt;@filter builder&lt;/P&gt;
&lt;P&gt;(severity eq informational) and (description contains 'logged in via WEB') or (description contains 'logged in via CLI')&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is what I configured Filter but only CLI works&lt;BR /&gt;Am I missing something?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would appreciate your help.3&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shalev_0-1689570642938.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/51624iDA533F5DD923B078/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Shalev_0-1689570642938.png" alt="Shalev_0-1689570642938.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2023 05:10:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-system-setting/m-p/549486#M112123</guid>
      <dc:creator>Shalev</dc:creator>
      <dc:date>2023-07-17T05:10:52Z</dc:date>
    </item>
    <item>
      <title>Re: Log System setting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-system-setting/m-p/549661#M112133</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/264820"&gt;@Shalev&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for posting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To me it looks like there is an issue with upper/lower case. Could you change it to: "logged in via Web"?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2023 23:21:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-system-setting/m-p/549661#M112133</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-07-17T23:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: Log System setting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-system-setting/m-p/549747#M112136</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Change the filter to:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;(severity eq informational) and (description contains 'logged in via Web') or (description contains 'logged in via CLI')&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This should help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 08:50:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-system-setting/m-p/549747#M112136</guid>
      <dc:creator>akuzhuppilly</dc:creator>
      <dc:date>2023-07-18T08:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: Log System setting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-system-setting/m-p/549770#M112143</link>
      <description>&lt;P&gt;This is not work&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 09:51:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-system-setting/m-p/549770#M112143</guid>
      <dc:creator>Shalev</dc:creator>
      <dc:date>2023-07-18T09:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: Log System setting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-system-setting/m-p/549771#M112144</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/264820"&gt;@Shalev&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you post the screen shot with current filter you put in?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 10:03:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-system-setting/m-p/549771#M112144</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-07-18T10:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: Log System setting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-system-setting/m-p/549773#M112145</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-07-18 130446.png" style="width: 798px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/51719iC1275BE7695380D7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-07-18 130446.png" alt="Screenshot 2023-07-18 130446.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 10:05:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-system-setting/m-p/549773#M112145</guid>
      <dc:creator>Shalev</dc:creator>
      <dc:date>2023-07-18T10:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: Log System setting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-system-setting/m-p/549774#M112146</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I just checked this query from one of my firewalls and the results are as expected. You will need to login to the GUI and CLI to regenerate the alerts.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 10:06:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-system-setting/m-p/549774#M112146</guid>
      <dc:creator>akuzhuppilly</dc:creator>
      <dc:date>2023-07-18T10:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: Log System setting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-system-setting/m-p/549780#M112147</link>
      <description>&lt;P&gt;I exited and entered FW and I only have a notification about CLI and not about Wab&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 10:10:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-system-setting/m-p/549780#M112147</guid>
      <dc:creator>Shalev</dc:creator>
      <dc:date>2023-07-18T10:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: Log System setting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-system-setting/m-p/549798#M112148</link>
      <description>&lt;P&gt;I succeeded&lt;BR /&gt;For general knowledge this is the command:&amp;nbsp;(severity eq informational) and ( description contains 'logged in via Web from') or (description contains 'logged in via CLI')&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 11:57:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-system-setting/m-p/549798#M112148</guid>
      <dc:creator>Shalev</dc:creator>
      <dc:date>2023-07-18T11:57:21Z</dc:date>
    </item>
    <item>
      <title>Re: Log System setting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-system-setting/m-p/549819#M112150</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/264820"&gt;@Shalev&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;A couple notes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The filter you're using really should be grouped to the following "(severity eq informational) and ((description contains 'logged in via Web from') or (description contains 'logged in via CLI')). What you have is functional, but the search is logging for an informational event with 'logged in via Web from' in the description&amp;nbsp;&lt;STRONG&gt;or&amp;nbsp;&lt;/STRONG&gt;&lt;EM&gt;any&amp;nbsp;&lt;/EM&gt;event with 'logged in via CLI' as presently written.&lt;/LI&gt;
&lt;LI&gt;You don't need informational in this at all. You've targeted the description enough that you'll get your events regardless of that being included or not. It's just kind of extra at this point, it's not harming anything but it also isn't needed.&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 18 Jul 2023 13:00:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-system-setting/m-p/549819#M112150</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-07-18T13:00:59Z</dc:date>
    </item>
  </channel>
</rss>

