<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sending user logins via Syslog in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/sending-user-logins-via-syslog/m-p/20119#M14641</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I appreciate the attempt, but that's a pretty vague answer. I already have syslog configured correctly and am capturing logs. My question was pertaining to whether there was something I was missing. I don't see anything for "user logins" on my syslog appliance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 19 Sep 2012 16:57:26 GMT</pubDate>
    <dc:creator>eharvey</dc:creator>
    <dc:date>2012-09-19T16:57:26Z</dc:date>
    <item>
      <title>Sending user logins via Syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sending-user-logins-via-syslog/m-p/20117#M14639</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not found a way to send user logins to an external syslog server. I have traffic allows/denies coming through successfully, and "misc. system events." Is there a custom configuration that needs to be done to get user login date/time? We need this for compliance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Eric H.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Sep 2012 14:18:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sending-user-logins-via-syslog/m-p/20117#M14639</guid>
      <dc:creator>eharvey</dc:creator>
      <dc:date>2012-09-19T14:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: Sending user logins via Syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sending-user-logins-via-syslog/m-p/20118#M14640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Objects -&amp;gt; Logging Profiles -&amp;gt; SNMP Traps/Syslog &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apply new profile to the rules you wish and also in Device-&amp;gt;Log Settings-&amp;gt;System&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Works great here.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Sep 2012 14:26:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sending-user-logins-via-syslog/m-p/20118#M14640</guid>
      <dc:creator>essnet</dc:creator>
      <dc:date>2012-09-19T14:26:46Z</dc:date>
    </item>
    <item>
      <title>Re: Sending user logins via Syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sending-user-logins-via-syslog/m-p/20119#M14641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I appreciate the attempt, but that's a pretty vague answer. I already have syslog configured correctly and am capturing logs. My question was pertaining to whether there was something I was missing. I don't see anything for "user logins" on my syslog appliance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Sep 2012 16:57:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sending-user-logins-via-syslog/m-p/20119#M14641</guid>
      <dc:creator>eharvey</dc:creator>
      <dc:date>2012-09-19T16:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: Sending user logins via Syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sending-user-logins-via-syslog/m-p/20120#M14642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Eric,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;System logs on the PAN will have the login information of the users. So you can forward the system logs to the Syslog server. You can forward systems log's&amp;nbsp; to the server like below. System logs will have all kinds of information related to the device so if you do not want all the info and need just the login information in the Syslog's, try just forwarding informational system logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="4097" alt="dCapture.PNG" class="jive-image-thumbnail jive-image" height="268" src="https://live.paloaltonetworks.com/legacyfs/online/4097_dCapture.PNG" style="height: 268px; width: 1608px;" width="1608" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Sep 2012 17:47:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sending-user-logins-via-syslog/m-p/20120#M14642</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-09-19T17:47:53Z</dc:date>
    </item>
    <item>
      <title>Re: Sending user logins via Syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sending-user-logins-via-syslog/m-p/20121#M14643</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;Thank you. I thought the 'Panorama' option was only used for a separate piece of hardware provided by Palo Alto. Maybe I do not have the correct information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Sep 2012 17:58:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sending-user-logins-via-syslog/m-p/20121#M14643</guid>
      <dc:creator>eharvey</dc:creator>
      <dc:date>2012-09-19T17:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: Sending user logins via Syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sending-user-logins-via-syslog/m-p/20122#M14644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think there is a confusion here. In the above the pic the "panorama" option is enabled to send logs to panorama, but if you scroll to the right hand corner you will see an option for syslog. In the picture you can see "pc" under syslog. "pc" is my syslog server profile. So I am forwarding my PAN system logs to syslog server that is configured in the syslog server profile named "pc". So I am forwarding severity of low medium and high to the syslog server and not forwarding informational to the syslog server. You need to forward informational also as you need login information in the syslog server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Sep 2012 18:24:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sending-user-logins-via-syslog/m-p/20122#M14644</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-09-19T18:24:47Z</dc:date>
    </item>
  </channel>
</rss>

