<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Automated alerts when Log Forwarding stops / freezes? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/automated-alerts-when-log-forwarding-stops-freezes/m-p/18585#M13569</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks &lt;A href="https://live.paloaltonetworks.com/u1/17985"&gt;Steven Puluka&lt;/A&gt;, the problem is though, that our logging platform is Panorama.&amp;nbsp; Panorama doesn't offer any of those features.&amp;nbsp; It seems so ridiculous that a system that is specifically designed (M-100) to be a Log Collector, doesn't have a way to notify its admins when it's not actually collecting logs from a device that it was previously collecting logs from.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 26 Jun 2014 14:21:20 GMT</pubDate>
    <dc:creator>MRosloniec</dc:creator>
    <dc:date>2014-06-26T14:21:20Z</dc:date>
    <item>
      <title>Automated alerts when Log Forwarding stops / freezes?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/automated-alerts-when-log-forwarding-stops-freezes/m-p/18583#M13567</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Community - &lt;/P&gt;&lt;P&gt;Wondering if anyone has come up with a good way to automate an alert / alarm when there is an issue with a Firewall reporting to a DLC (distributed log collector)?&amp;nbsp; We have about 27 firewalls all of which send to 1 of 4 log collectors, and we are seeing an increase of Log Forwarding issues --&amp;gt;&amp;nbsp; Some sending only Denies (when all rules are set to forward logs), Some not sending Any... The fix for this is to restart the Log Forwarding process on each device, but this can be very time consuming to check each of the 27 devices to make sure we're getting the logs we expect to get, and then restart the process if necessary.&amp;nbsp; We are relying on the logs in the DLC's for PCI compliance, and to date, Palo Alto Support claims there is no way to get notified if a Firewall stops sending logs to a log forwarder.&amp;nbsp; I would love to hear anything creative anyone else has done to help alleviate this headache...?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jun 2014 14:10:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/automated-alerts-when-log-forwarding-stops-freezes/m-p/18583#M13567</guid>
      <dc:creator>MRosloniec</dc:creator>
      <dc:date>2014-06-23T14:10:31Z</dc:date>
    </item>
    <item>
      <title>Re: Automated alerts when Log Forwarding stops / freezes?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/automated-alerts-when-log-forwarding-stops-freezes/m-p/18584#M13568</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't have a specific answer.&amp;nbsp; But if your logging platform supports some kind of dashboard page you could setup a graph for the log volume per time period on each firewall.&amp;nbsp; When the graph drops below normal you would see the problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jun 2014 22:08:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/automated-alerts-when-log-forwarding-stops-freezes/m-p/18584#M13568</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-06-23T22:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: Automated alerts when Log Forwarding stops / freezes?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/automated-alerts-when-log-forwarding-stops-freezes/m-p/18585#M13569</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks &lt;A href="https://live.paloaltonetworks.com/u1/17985"&gt;Steven Puluka&lt;/A&gt;, the problem is though, that our logging platform is Panorama.&amp;nbsp; Panorama doesn't offer any of those features.&amp;nbsp; It seems so ridiculous that a system that is specifically designed (M-100) to be a Log Collector, doesn't have a way to notify its admins when it's not actually collecting logs from a device that it was previously collecting logs from.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jun 2014 14:21:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/automated-alerts-when-log-forwarding-stops-freezes/m-p/18585#M13569</guid>
      <dc:creator>MRosloniec</dc:creator>
      <dc:date>2014-06-26T14:21:20Z</dc:date>
    </item>
    <item>
      <title>Re: Automated alerts when Log Forwarding stops / freezes?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/automated-alerts-when-log-forwarding-stops-freezes/m-p/18586#M13570</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I feel your pain.&amp;nbsp; We use a third party log collector for long term archives and forward directly for the PAN firewalls via syslog.&amp;nbsp; this has consistently worked even when Panorama logging stops collecting.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 28 Jun 2014 00:21:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/automated-alerts-when-log-forwarding-stops-freezes/m-p/18586#M13570</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-06-28T00:21:12Z</dc:date>
    </item>
  </channel>
</rss>

