<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TCPDUMP shows syslog traffic going to a specific destination - How to figure out what is sending it there? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/tcpdump-shows-syslog-traffic-going-to-a-specific-destination-how/m-p/31041#M22711</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am hoping this is an "easy" question that I am just missing having been on calls since 4:24 am this morning :smileyconfused:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have used tcpdump to confirm that one of our PAN firewalls are sending syslog traffic to a specific destination (w.x.y.z) which it is not supposed to. (we don't want it going to that 'collector' for band width reasons - we have a 'closer' collector. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Anyone have a trick to figure out what rule/construct is sending the syslog traffic to server w.x.y.z?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; BlueCoat has a "Trace" functionality on their SG-OS that shows the evaluation by each rule as the traffic is evaluated ... that would be helpful... is there a similar thing in PAN-OS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Art&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 Feb 2014 20:02:11 GMT</pubDate>
    <dc:creator>Art</dc:creator>
    <dc:date>2014-02-18T20:02:11Z</dc:date>
    <item>
      <title>TCPDUMP shows syslog traffic going to a specific destination - How to figure out what is sending it there?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcpdump-shows-syslog-traffic-going-to-a-specific-destination-how/m-p/31041#M22711</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am hoping this is an "easy" question that I am just missing having been on calls since 4:24 am this morning :smileyconfused:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have used tcpdump to confirm that one of our PAN firewalls are sending syslog traffic to a specific destination (w.x.y.z) which it is not supposed to. (we don't want it going to that 'collector' for band width reasons - we have a 'closer' collector. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Anyone have a trick to figure out what rule/construct is sending the syslog traffic to server w.x.y.z?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; BlueCoat has a "Trace" functionality on their SG-OS that shows the evaluation by each rule as the traffic is evaluated ... that would be helpful... is there a similar thing in PAN-OS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Art&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Feb 2014 20:02:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcpdump-shows-syslog-traffic-going-to-a-specific-destination-how/m-p/31041#M22711</guid>
      <dc:creator>Art</dc:creator>
      <dc:date>2014-02-18T20:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: TCPDUMP shows syslog traffic going to a specific destination - How to figure out what is sending it there?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcpdump-shows-syslog-traffic-going-to-a-specific-destination-how/m-p/31042#M22712</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A href="https://live.paloaltonetworks.com/u1/11113"&gt;Art&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we look at the below image we see that the Traffic Log type has a field for "Rule" this would indicate the security rule name that is generating the log.&lt;/P&gt;&lt;P&gt;Hope this is exactly what is being looked for.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="syslog.PNG.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11715_syslog.PNG.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Feb 2014 14:31:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcpdump-shows-syslog-traffic-going-to-a-specific-destination-how/m-p/31042#M22712</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2014-02-19T14:31:48Z</dc:date>
    </item>
    <item>
      <title>Re: TCPDUMP shows syslog traffic going to a specific destination - How to figure out what is sending it there?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcpdump-shows-syslog-traffic-going-to-a-specific-destination-how/m-p/31043#M22713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Phoenix... great idea... I will look into it... turned out there was one rule I hadn't noticed that was configured incorrectly that was routing the traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Art&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Feb 2014 21:33:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcpdump-shows-syslog-traffic-going-to-a-specific-destination-how/m-p/31043#M22713</guid>
      <dc:creator>Art</dc:creator>
      <dc:date>2014-02-24T21:33:01Z</dc:date>
    </item>
  </channel>
</rss>

