<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic syslog forwarding in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29679#M21688</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have&amp;nbsp; everything configured to send syslog information from the palo alto to one of our syslog server. My issue is that none of the security policy IP ranges allows me to send the syslog information for a specific IP address that is going out to the internet at least that I can find. Any ideas would be appreciated&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 02 Jun 2015 18:45:21 GMT</pubDate>
    <dc:creator>jdprovine</dc:creator>
    <dc:date>2015-06-02T18:45:21Z</dc:date>
    <item>
      <title>syslog forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29679#M21688</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have&amp;nbsp; everything configured to send syslog information from the palo alto to one of our syslog server. My issue is that none of the security policy IP ranges allows me to send the syslog information for a specific IP address that is going out to the internet at least that I can find. Any ideas would be appreciated&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2015 18:45:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29679#M21688</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-06-02T18:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: syslog forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29680#M21689</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not sure I understand the question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;syslog traffic will source from your mgmt interface and ip address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is your syslog server out the internet side of your Palo Alto then?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would need a policy that permits your mgmt address out to untrust and probably a nat policy to the interface address for the traffic as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2015 00:28:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29680#M21689</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-06-03T00:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: syslog forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29681#M21690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jprovine,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am agree with Mr. Steven, please the check the service route for syslog and check the traffic logs. traffic is allowing or blocking by firewall.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="service.PNG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/19908_service.PNG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Satish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2015 07:30:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29681#M21690</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2015-06-03T07:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: syslog forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29682#M21691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what I am saying is that I had no problem configuring syslog to a Linux server I have. The issue is that I want to track a specific IP address, so I want to collect the traffic from and internal IP address to the internet and I want to know if there is a way to be that granular. I have created my syslog forwarder and now I am going through the security policies and adding it as an action to forward the logs to my syslog server but I am getting a lot more information than I want. Instead of a rand of 136.155.x.0-136.155.x.254 I only want the information coming from 136.155.0.64 to the internet to captured and forwarded to the syslog server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2015 12:34:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29682#M21691</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-06-03T12:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: syslog forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29683#M21692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jprovine,&lt;/P&gt;&lt;P&gt;As my understand, you need to create custom report as per your requirement but i am sure about it. it will work or not.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="19916" alt="report1.PNG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/19916_report1.PNG" style="height: 317px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Satish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2015 16:59:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29683#M21692</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2015-06-03T16:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: syslog forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29684#M21693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No I am forwarding&amp;nbsp; from the PA&amp;nbsp; logs to an external log server&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2015 18:13:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29684#M21693</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-06-03T18:13:16Z</dc:date>
    </item>
    <item>
      <title>Re: syslog forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29685#M21694</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My 2 cents and i am pretty sure you would have done it, but to make sure:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please have a standalone syslog server, create a security policy that specifically works on the interested ip address and then forward it to syslog server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with that you should only see the traffic generated by that particular ip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~Harry&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2015 18:35:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29685#M21694</guid>
      <dc:creator>Harshit</dc:creator>
      <dc:date>2015-06-03T18:35:27Z</dc:date>
    </item>
    <item>
      <title>Re: syslog forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29686#M21695</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Harry&lt;/P&gt;&lt;P&gt;Yes I had been thinking that very thing&lt;/P&gt;&lt;P&gt;I have a security policy that has that IP and a wide range of IP's in it, I was considering creating a security policy with that specific IP address I want to monitor and put it above the current one. What I don't know it what that will do to my traffic, will it just say that the rules are shadowing each other or will it interrupt traffic or anything else negative?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2015 18:47:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29686#M21695</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-06-03T18:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: syslog forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29687#M21696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks, if you put that above the rest of the traffic, it should not affect anything else, palo would simply see it as another acl,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you may,get a warning when commiting that the rules are shadowing, but it's fair to live with, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; if your bottom rules have a broader ip range, like a subnet , and the above rule has just an ip, it should not show that warning.too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;let me know how it goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~Harry&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2015 19:27:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29687#M21696</guid>
      <dc:creator>Harshit</dc:creator>
      <dc:date>2015-06-03T19:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: syslog forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29688#M21697</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you ever know of anyone to try to be this granular in the collection of logs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2015 19:32:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29688#M21697</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-06-03T19:32:55Z</dc:date>
    </item>
    <item>
      <title>Re: syslog forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29689#M21698</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Typically we gather all the syslog data to the syslog server then use that server's reporting feature to pull out the information on the specific ip address across all systems that are logging, rather than only log for one ip address in traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Jun 2015 13:11:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29689#M21698</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-06-06T13:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: syslog forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29690#M21699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is how my management has requested it be done so and how the our PA rep send it could be done so we are trying it&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jun 2015 12:47:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29690#M21699</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-06-08T12:47:36Z</dc:date>
    </item>
    <item>
      <title>Re: syslog forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29691#M21700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;jprovine wrote:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Yes I had been thinking that very thing&lt;/P&gt;
&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;I have a security policy that has that IP and a wide range of IP's in it, I was considering creating a security policy with that specific IP address I want to monitor and put it above the current one. What I don't know it what that will do to my traffic, will it just say that the rules are shadowing each other or will it interrupt traffic or anything else negative?&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;You will need to be careful about shadowing rules with this approach.&amp;nbsp; And you are correct that to only syslog for these particular addresses you will need to isolate them to their own rules.&amp;nbsp; then the log portion of the rule will contain your syslog server but none of your other rules will contain this log forwarding profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you create the rule too broadly you can give this user or segment more access than they should have so be careful with the rule construction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the safest approach would be to clone every rule this address may match and make the first of the two rules only have this ip address as the source or destination with the rest of the rule the same.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jun 2015 22:26:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29691#M21700</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-06-08T22:26:28Z</dc:date>
    </item>
    <item>
      <title>Re: syslog forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29692#M21701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I configured it and got it working with no shadowing and without compromising security&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jun 2015 12:54:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29692#M21701</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-06-09T12:54:11Z</dc:date>
    </item>
    <item>
      <title>Re: syslog forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29693#M21702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad to hear you have it all worked out.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jun 2015 21:22:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-forwarding/m-p/29693#M21702</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-06-09T21:22:05Z</dc:date>
    </item>
  </channel>
</rss>

