<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall is not forwarding logs to the Syslog server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-is-not-forwarding-logs-to-the-syslog-server/m-p/595404#M118490</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/304204"&gt;@renzanjo11&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the output of tcpdump it looks like that syslog traffic is being sent out. Are you able to confirm that your syslog server is receiving traffic? Is there any Firewall / ACL in between?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 20 Aug 2024 23:33:25 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2024-08-20T23:33:25Z</dc:date>
    <item>
      <title>Firewall is not forwarding logs to the Syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-is-not-forwarding-logs-to-the-syslog-server/m-p/594598#M118341</link>
      <description>&lt;P&gt;Hi everyone!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am kind of bummed on why my syslog configuration is not taking effect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have 2 pairs of firewall, PRD(2 firewalls) and DR(2 firewalls). Both are in HA setup and managed by Panorama. My syslog configuration in DR and PRD are just the same. Same server, same settings. For some reason, the syslog in my PRD is not working. So mysterious.&lt;/P&gt;
&lt;P&gt;I checked the CLI and it appears it is indeed listening on port 514. My PRD Firewalls are new ones coz I migrated from JUNOS to PANOS.&lt;/P&gt;
&lt;P&gt;I use my management for my syslog forwarding.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any thing I missed?&lt;/P&gt;
&lt;P&gt;I did everything here correctly:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/monitoring/use-syslog-for-monitoring/configure-syslog-monitoring" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/monitoring/use-syslog-for-monitoring/conf...&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can see the output of my checking on the PDF File attached.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you guys in advance!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2024 08:50:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-is-not-forwarding-logs-to-the-syslog-server/m-p/594598#M118341</guid>
      <dc:creator>renzanjo11</dc:creator>
      <dc:date>2024-08-12T08:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall is not forwarding logs to the Syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-is-not-forwarding-logs-to-the-syslog-server/m-p/594673#M118363</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/304204"&gt;@renzanjo11&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;from screen shots you provided your configuration looks correct.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you try to restart management service:&amp;nbsp;&lt;STRONG&gt;debug software restart process management-server&lt;/STRONG&gt;. Management service will also restart log receiver service. If it still does not work after management process restart could you please share PAN-OS version firewall is running? Could you also take pcap on management interface?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2024 05:38:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-is-not-forwarding-logs-to-the-syslog-server/m-p/594673#M118363</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-08-13T05:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall is not forwarding logs to the Syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-is-not-forwarding-logs-to-the-syslog-server/m-p/595323#M118473</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Pcap on the management interface means TCPdump right?&lt;/P&gt;
&lt;P&gt;If yes, I also included that on my attachment. the image below the syslog forwarding profile configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Renz&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 06:44:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-is-not-forwarding-logs-to-the-syslog-server/m-p/595323#M118473</guid>
      <dc:creator>renzanjo11</dc:creator>
      <dc:date>2024-08-20T06:44:35Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall is not forwarding logs to the Syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-is-not-forwarding-logs-to-the-syslog-server/m-p/595404#M118490</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/304204"&gt;@renzanjo11&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the output of tcpdump it looks like that syslog traffic is being sent out. Are you able to confirm that your syslog server is receiving traffic? Is there any Firewall / ACL in between?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 23:33:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-is-not-forwarding-logs-to-the-syslog-server/m-p/595404#M118490</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-08-20T23:33:25Z</dc:date>
    </item>
  </channel>
</rss>

