<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Are there way that fw forward url &amp; data filtering logs to ESM system by syslog?? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/are-there-way-that-fw-forward-url-data-filtering-logs-to-esm/m-p/1608#M1207</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Like achitwadgi said: If you are receiving URL logs on panorama, then the firewall should have had Log forwarding configured. In GUI:Objects&amp;gt;Log Forwarding Profile, there should have been a profile created with Panorama check box checked for "informational" severity. This profile should then be applied to the security rules.&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-2173"&gt;https://live.paloaltonetworks.com/docs/DOC-2173&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 25 Jul 2013 03:35:58 GMT</pubDate>
    <dc:creator>dreputi</dc:creator>
    <dc:date>2013-07-25T03:35:58Z</dc:date>
    <item>
      <title>Are there way that fw forward url &amp; data filtering logs to ESM system by syslog??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/are-there-way-that-fw-forward-url-data-filtering-logs-to-esm/m-p/1606#M1205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know there are not log type of url &amp;amp; data filtering on syslog server profile.&lt;/P&gt;&lt;P&gt;But my customer want to receive two logs to ESM system by syslog.&lt;/P&gt;&lt;P&gt;Are there ways?&lt;/P&gt;&lt;P&gt;Please let me know it if there are.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I have a question.&lt;/P&gt;&lt;P&gt;Panorama is received this logs(url , data) from FW.&lt;/P&gt;&lt;P&gt;Why is it able to receive?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2013 08:38:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/are-there-way-that-fw-forward-url-data-filtering-logs-to-esm/m-p/1606#M1205</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2013-07-24T08:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: Are there way that fw forward url &amp; data filtering logs to ESM system by syslog??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/are-there-way-that-fw-forward-url-data-filtering-logs-to-esm/m-p/1607#M1206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;URL logs are stored as "informational" threat logs on the PA device.&lt;/P&gt;&lt;P&gt;So, in your log forwarding profile, under Threat, enable "informational" severity. This should enable URL log forwarding to your syslog server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Something similar to your question was discussed in : &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/13326#13326"&gt;https://live.paloaltonetworks.com/message/13326#13326&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2013 12:27:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/are-there-way-that-fw-forward-url-data-filtering-logs-to-esm/m-p/1607#M1206</guid>
      <dc:creator>goku123</dc:creator>
      <dc:date>2013-07-24T12:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: Are there way that fw forward url &amp; data filtering logs to ESM system by syslog??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/are-there-way-that-fw-forward-url-data-filtering-logs-to-esm/m-p/1608#M1207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Like achitwadgi said: If you are receiving URL logs on panorama, then the firewall should have had Log forwarding configured. In GUI:Objects&amp;gt;Log Forwarding Profile, there should have been a profile created with Panorama check box checked for "informational" severity. This profile should then be applied to the security rules.&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-2173"&gt;https://live.paloaltonetworks.com/docs/DOC-2173&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jul 2013 03:35:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/are-there-way-that-fw-forward-url-data-filtering-logs-to-esm/m-p/1608#M1207</guid>
      <dc:creator>dreputi</dc:creator>
      <dc:date>2013-07-25T03:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: Are there way that fw forward url &amp; data filtering logs to ESM system by syslog??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/are-there-way-that-fw-forward-url-data-filtering-logs-to-esm/m-p/1609#M1208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your answer, achitwadgi and dreputi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWs send url logs by threat information severity of syslog. (The value of threat subtype field is url)&lt;/P&gt;&lt;P&gt;Also FWs send file logs by threat low severity of syslog. (The value of threat subtype field is file)&lt;/P&gt;&lt;P&gt;Low severity include alert , allow , forward and deny actions on file log.&lt;/P&gt;&lt;P&gt;Wildfire-upload-skip action is information severity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are they right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Aug 2013 09:07:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/are-there-way-that-fw-forward-url-data-filtering-logs-to-esm/m-p/1609#M1208</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2013-08-01T09:07:21Z</dc:date>
    </item>
  </channel>
</rss>

