<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PANOS 6 Syslog Different? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21576#M15765</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;FYI.&lt;/P&gt;&lt;P&gt;PAN OS 6.0.1 - &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Addressed Issues&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;60816- Following an upgrade to PAN-OS 6.0.0, &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-size: 10pt; line-height: 1.5em;"&gt;syslog&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; connection status warnings for all defined &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-size: 10pt; line-height: 1.5em;"&gt;syslog&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; connections appeared in the system log every hour and were categorized as critical. This was caused by a scheduled hourly rotation of the &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-size: 10pt; line-height: 1.5em;"&gt;syslog&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;-&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-size: 10pt; line-height: 1.5em;"&gt;ng&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; log file, during which the &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-size: 10pt; line-height: 1.5em;"&gt;syslog&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;-&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-size: 10pt; line-height: 1.5em;"&gt;ng&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; daemon would restart. This issue has been fixed by adding a condition to the log file rotation process requiring the log file to be 10 MB or more and the connection status warning will only be seen once every few months.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;60011-When a User ID Agent Setup template was pushed from Panorama to a managed device, the application content updates were not available for viewing or cloning in the &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-size: 10pt; line-height: 1.5em;"&gt;syslog&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-size: 10pt; line-height: 1.5em;"&gt;filters&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; list in the web interface (Device &amp;gt; User Identification &amp;gt; User Mapping &amp;gt; User ID Agent Setup &amp;gt; &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-size: 10pt; line-height: 1.5em;"&gt;Syslog&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; Filters).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 11 Mar 2014 15:43:28 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-03-11T15:43:28Z</dc:date>
    <item>
      <title>PANOS 6 Syslog Different?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21564#M15753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm running a PA-200, recently upgraded to PANOS6.0, and noticed I'm not receiving traffic logs to my syslog server. When on 5.x of PANOS I was receiving change configuration, traffic logs, etc to my syslog/firewall analyzer application ManageEngine FirewallAnalyzer, but after upgrading to 6.0, I'm only receiving config messages (restarts, change to configuration, etc). I confirmed my syslog setting in the PAN and they're identical to what they were before the upgrade and the listening port on my syslog server was up, any ideas? I ensured log at session end was the same, the destination IP/port were correct, and the service route was that of my inside interface, is there something different in PANOS 6 that needs to be configured differently?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any input...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Mar 2014 22:26:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21564#M15753</guid>
      <dc:creator>robg303</dc:creator>
      <dc:date>2014-03-04T22:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 6 Syslog Different?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21565#M15754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;New enhancements in 6.0 related to SYSLOG over TCP or SSL.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;You can verify the same from CLI:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;admin@PA-4020&amp;gt; show counter management-server&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Log action not taken&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-size: 10pt; line-height: 1.5em;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Logs dropped because not logging:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;User information from AD read&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&lt;/P&gt;&lt;P&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Certificates&lt;/SPAN&gt; information &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;read&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;License information fetched from update server:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Log action &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;syslogs&lt;/SPAN&gt; sent&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 557 &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; verify if the counter is incrementing &lt;/P&gt;&lt;P&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Sighash&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;refcount&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&lt;/P&gt;&lt;P&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Tunnelhash&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;refcount&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&lt;/P&gt;&lt;P&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;URLcat&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;refcount&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&lt;/P&gt;&lt;P&gt;ip2loc &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;refcount&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Related CLI command to ensure that the PAN is generating traffic logs:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&amp;gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;debug&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;log&lt;/SPAN&gt;-receiver statistics&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&amp;gt; show logging-status&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Mar 2014 23:02:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21565#M15754</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-03-04T23:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 6 Syslog Different?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21566#M15755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hulk.. thanks for your input! I've performed the above commands and see NO syslogs sent. Issuing the debug command the traffic log count is incrementing, but showing the logging status, its reporting the below. I can't figure out what configuration change i need to make to send the logs correctly as it worked fine in 5.x can you assist? (for what it's worth, i have my syslog in the PAN configured for UDP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;xxxxx@pa-200&amp;gt; show counter management-server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Log action not taken&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Logs dropped because not logging:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;User information from AD read&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&lt;/P&gt;&lt;P&gt;Certificates information read&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;License information fetched from update server:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Log action syslogs sent&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Sighash refcount&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&lt;/P&gt;&lt;P&gt;Tunnelhash refcount&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&lt;/P&gt;&lt;P&gt;URLcat refcount&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&lt;/P&gt;&lt;P&gt;ip2loc refcount&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;External Forwarding stats:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type&amp;nbsp; Enqueue Count&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Send Count&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Drop Count&amp;nbsp;&amp;nbsp;&amp;nbsp; Queue Depth&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Send&lt;/P&gt;&lt;P&gt;Rate(last 1min)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; syslog&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 267428&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 267428&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;xxxxxx@pa-200&amp;gt; debug log-receiver statistics&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Logging statistics&lt;/P&gt;&lt;P&gt;------------------------------ -----------&lt;/P&gt;&lt;P&gt;Log incoming rate:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/sec&lt;/P&gt;&lt;P&gt;Log written rate:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/sec&lt;/P&gt;&lt;P&gt;Corrupted packets:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Corrupted URL packets:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Logs discarded (queue full):&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Traffic logs written:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 267406&lt;/P&gt;&lt;P&gt;URL logs written:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3&lt;/P&gt;&lt;P&gt;Wildfire logs written:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Anti-virus logs written:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Spyware logs written:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Attack logs written:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Vulnerability logs written:&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Fileext logs written:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 27&lt;/P&gt;&lt;P&gt;URL cache age out count:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;URL cache full count:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;URL cache key exist count:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Traffic alarms dropped due to sysd write failures: 0&lt;/P&gt;&lt;P&gt;Traffic alarms dropped due to global rate limiting: 0&lt;/P&gt;&lt;P&gt;Traffic alarms dropped due to each source rate limiting: 0&lt;/P&gt;&lt;P&gt;Traffic alarms generated count:&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Log Forward count:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Log Forward discarded (queue full) count: 0&lt;/P&gt;&lt;P&gt;Log Forward discarded (send error) count: 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Summary Statistics:&lt;/P&gt;&lt;P&gt;Num current drop entries in trsum:0&lt;/P&gt;&lt;P&gt;Num cumulative drop entries in trsum:0&lt;/P&gt;&lt;P&gt;Num current drop entries in thsum:0&lt;/P&gt;&lt;P&gt;Num cumulative drop entries in thsum:0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;External Forwarding stats:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type&amp;nbsp; Enqueue Count&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Send Count&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Drop Count&amp;nbsp;&amp;nbsp;&amp;nbsp; Queue Depth&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Send&lt;/P&gt;&lt;P&gt;Rate(last 1min)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; syslog&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 267436&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 267436&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; snmp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; email&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; raw&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;xxxxxx@pa-200&amp;gt; debug log-receiver statistics&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Logging statistics&lt;/P&gt;&lt;P&gt;------------------------------ -----------&lt;/P&gt;&lt;P&gt;Log incoming rate:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1/sec&lt;/P&gt;&lt;P&gt;Log written rate:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1/sec&lt;/P&gt;&lt;P&gt;Corrupted packets:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Corrupted URL packets:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Logs discarded (queue full):&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Traffic logs written:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 267410&lt;/P&gt;&lt;P&gt;URL logs written:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3&lt;/P&gt;&lt;P&gt;Wildfire logs written:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Anti-virus logs written:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Spyware logs written:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Attack logs written:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Vulnerability logs written:&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Fileext logs written:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 27&lt;/P&gt;&lt;P&gt;URL cache age out count:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;URL cache full count:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;URL cache key exist count:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Traffic alarms dropped due to sysd write failures: 0&lt;/P&gt;&lt;P&gt;Traffic alarms dropped due to global rate limiting: 0&lt;/P&gt;&lt;P&gt;Traffic alarms dropped due to each source rate limiting: 0&lt;/P&gt;&lt;P&gt;Traffic alarms generated count:&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Log Forward count:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;Log Forward discarded (queue full) count: 0&lt;/P&gt;&lt;P&gt;Log Forward discarded (send error) count: 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Summary Statistics:&lt;/P&gt;&lt;P&gt;Num current drop entries in trsum:0&lt;/P&gt;&lt;P&gt;Num cumulative drop entries in trsum:0&lt;/P&gt;&lt;P&gt;Num current drop entries in thsum:0&lt;/P&gt;&lt;P&gt;Num cumulative drop entries in thsum:0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show logging-status&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;---------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last Log Created&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last Log Fwded&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last Seq Num Fwded&lt;/P&gt;&lt;P&gt;Last Seq Num Acked&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Logs Fwded&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;---------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;gt; CMS 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Not Sending to CMS 0&lt;/P&gt;&lt;P&gt;&amp;gt; CMS 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Not Sending to CMS 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;Log Collector&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Not Sending to Log Collector&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 13:39:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21566#M15755</guid>
      <dc:creator>robg303</dc:creator>
      <dc:date>2014-03-05T13:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 6 Syslog Different?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21567#M15756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Might sound lame, but what about log forwarding profile?&lt;/P&gt;&lt;P&gt;Is it still the same?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 22:03:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21567#M15756</guid>
      <dc:creator>prb</dc:creator>
      <dc:date>2014-03-05T22:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 6 Syslog Different?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21568#M15757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah... sure is. That's what i can't figure out, seems odd and is driving me crazy... I haven't changed anything from the previous version, but also noticed I can only ping my internal DNS and default gateway server when I SSH'd to the management console all of which are on the same class-c subnet, as are my other servers and workstations.My syslog forwarding profile is to my internal log analyzer on standard port udp 514 and my service route is configured for 'source interface any' and source address as 192.168.0.1/24&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 12:38:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21568#M15757</guid>
      <dc:creator>robg303</dc:creator>
      <dc:date>2014-03-07T12:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 6 Syslog Different?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21569#M15758</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just upgraded a PA4020 to 6.0 and I'm seeing similar behavior. The last event time we received on our SIEM platform from the 4020 was 5 minutes before the upgrade, yesterday.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yet another PA QA fail.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 15:35:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21569#M15758</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2014-03-07T15:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 6 Syslog Different?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21570#M15759</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ouch...I feel like we should create a community checklist for their QA department.&amp;nbsp; Things they need to make sure are working before they release an update.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 16:22:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21570#M15759</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2014-03-07T16:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 6 Syslog Different?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21571#M15760</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've opened a case with Palo Alto and have sent tech support files, but as a only have standard support I'm sure it'll take some time to address. I'm glad (in an odd way) that i'm not the only one seeing this problem as I've reconfigured syslog settings on the PAN, syslog server, ports, and firewall configs all with the same results. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 20:10:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21571#M15760</guid>
      <dc:creator>robg303</dc:creator>
      <dc:date>2014-03-07T20:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 6 Syslog Different?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21572#M15761</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we got problems with syslog after upgrading to 6.0&lt;/P&gt;&lt;P&gt;We fixed that using service route for Syslog&lt;STRONG&gt; Destination Tab&lt;/STRONG&gt;.Except using this we had problems.Although there was a source interface choosen for syslog, we also used Destination Tab.With that it worked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I opened a case,I think there is a bug here.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Mar 2014 07:12:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21572#M15761</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-03-08T07:12:49Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 6 Syslog Different?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21573#M15762</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the input on the destination tab, I'm now receiving syslogs! Hopefully this will get addressed soon.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Mar 2014 16:59:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21573#M15762</guid>
      <dc:creator>robg303</dc:creator>
      <dc:date>2014-03-08T16:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 6 Syslog Different?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21574#M15763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've been burned by this and I already rolled back to 5.0.11 on my PA4020. I'll be waiting for a few revs of 6.0 to be out before I take another swing at that piñata.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Mar 2014 13:31:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21574#M15763</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2014-03-10T13:31:37Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 6 Syslog Different?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21575#M15764</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/20817"&gt;robg303&lt;/A&gt; - I just upgraded my PA4020 from 5.0.11 to 6.0.1, and I can confirm the syslog issue has been fixed. The log source now comes in to our SIEM as the hostname of the box instead of the IP address, so there was a moment of panic when we thought the issue wasn't fixed in 6.0.1, but I can confirm that the issue does indeed seem to be fixed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;We are getting lots and lots of syslog from our PA4020 (close to 1 million events in the past 30 minutes).&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2014 13:42:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21575#M15764</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2014-03-11T13:42:50Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 6 Syslog Different?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21576#M15765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;FYI.&lt;/P&gt;&lt;P&gt;PAN OS 6.0.1 - &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Addressed Issues&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;60816- Following an upgrade to PAN-OS 6.0.0, &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-size: 10pt; line-height: 1.5em;"&gt;syslog&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; connection status warnings for all defined &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-size: 10pt; line-height: 1.5em;"&gt;syslog&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; connections appeared in the system log every hour and were categorized as critical. This was caused by a scheduled hourly rotation of the &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-size: 10pt; line-height: 1.5em;"&gt;syslog&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;-&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-size: 10pt; line-height: 1.5em;"&gt;ng&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; log file, during which the &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-size: 10pt; line-height: 1.5em;"&gt;syslog&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;-&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-size: 10pt; line-height: 1.5em;"&gt;ng&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; daemon would restart. This issue has been fixed by adding a condition to the log file rotation process requiring the log file to be 10 MB or more and the connection status warning will only be seen once every few months.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;60011-When a User ID Agent Setup template was pushed from Panorama to a managed device, the application content updates were not available for viewing or cloning in the &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-size: 10pt; line-height: 1.5em;"&gt;syslog&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-size: 10pt; line-height: 1.5em;"&gt;filters&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; list in the web interface (Device &amp;gt; User Identification &amp;gt; User Mapping &amp;gt; User ID Agent Setup &amp;gt; &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-size: 10pt; line-height: 1.5em;"&gt;Syslog&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; Filters).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2014 15:43:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21576#M15765</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-03-11T15:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 6 Syslog Different?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21577#M15766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've upgraded to PANOS 6.01, set the Service Route Configuration for Syslog as Source Interface=Any, and Source Address to be my internal class-c Network. Upon removing the Destination tab information where the destination is my syslog Server IP, source Interface=Any, and Source Interface being the default Gateway IP I'm still only seeing configuration logs items, so it's basically the same issue moving to 6.0.1. If I modify the Destination tab back to what it was previously, i then begin to see Traffic logs again being sent to my firewall analyzer/syslog. If version 6.0.1 correct the issues where I don't have to many put in the destination for my syslog, is there something i'm missing here?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Mar 2014 13:48:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21577#M15766</guid>
      <dc:creator>robg303</dc:creator>
      <dc:date>2014-03-14T13:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 6 Syslog Different?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21578#M15767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is a bug that is currently being worked on. This only affects configurations where the syslog server must be reached through a dataplane interface. The workaround at this time is as you noted, creating a specific destination service route to your syslog server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Mar 2014 16:03:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21578#M15767</guid>
      <dc:creator>NoahMH</dc:creator>
      <dc:date>2014-03-18T16:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 6 Syslog Different?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21579#M15768</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the confirmation, I was wondering what I was missing after upgrading to 6.01 thinking that was the fix &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Mar 2014 14:54:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-6-syslog-different/m-p/21579#M15768</guid>
      <dc:creator>robg303</dc:creator>
      <dc:date>2014-03-19T14:54:46Z</dc:date>
    </item>
  </channel>
</rss>

