<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sending logs to SIEM one file per type in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/sending-logs-to-siem-one-file-per-type/m-p/564811#M114271</link>
    <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/313344"&gt;@JuanLondono1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is our &lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/monitoring/use-syslog-for-monitoring/configure-syslog-monitoring" target="_self"&gt;admin guide&lt;/A&gt; for configuring syslog.&amp;nbsp;&lt;SPAN&gt;You can have multiple syslog servers in your Syslog Server Profile, but Im not sure if the logs can be sent in different files to the same syslog server.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Nov 2023 15:02:00 GMT</pubDate>
    <dc:creator>JayGolf</dc:creator>
    <dc:date>2023-11-08T15:02:00Z</dc:date>
    <item>
      <title>Sending logs to SIEM one file per type</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sending-logs-to-siem-one-file-per-type/m-p/564673#M114251</link>
      <description>&lt;P&gt;I am an administrator of a SIEM, for this I have usually asked the paloalto administrator to send me the logs via Syslog using port 514 to the IP of the server I administer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After informing me that the process has been done, I check a specific route of my server where I can verify that the logs are indeed arriving in a file called user.log.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For a specific situation I need to ask the firewall administrator to please send me the TRAFFIC logs in a user.log file, the THREAT logs in another file with another name for example user2.log and the SYSTEM logs in a user3.log.&lt;/P&gt;
&lt;P&gt;He is asking me for the source paloalto where it is specified if this process is possible and how it should be done.&lt;/P&gt;
&lt;P&gt;I would appreciate if you could help me with your knowledge.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 22:01:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sending-logs-to-siem-one-file-per-type/m-p/564673#M114251</guid>
      <dc:creator>JuanLondono1</dc:creator>
      <dc:date>2023-11-07T22:01:07Z</dc:date>
    </item>
    <item>
      <title>Re: Sending logs to SIEM one file per type</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sending-logs-to-siem-one-file-per-type/m-p/564811#M114271</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/313344"&gt;@JuanLondono1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is our &lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/monitoring/use-syslog-for-monitoring/configure-syslog-monitoring" target="_self"&gt;admin guide&lt;/A&gt; for configuring syslog.&amp;nbsp;&lt;SPAN&gt;You can have multiple syslog servers in your Syslog Server Profile, but Im not sure if the logs can be sent in different files to the same syslog server.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 15:02:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sending-logs-to-siem-one-file-per-type/m-p/564811#M114271</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2023-11-08T15:02:00Z</dc:date>
    </item>
  </channel>
</rss>

