<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: threat syslog forwarding panorama -&amp;gt; ossim in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/threat-syslog-forwarding-panorama-gt-ossim/m-p/34587#M25383</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bumping this thread. Also interested if anyone has seen this. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 01 Aug 2012 18:25:27 GMT</pubDate>
    <dc:creator>opiedrah</dc:creator>
    <dc:date>2012-08-01T18:25:27Z</dc:date>
    <item>
      <title>threat syslog forwarding panorama -&gt; ossim</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-syslog-forwarding-panorama-gt-ossim/m-p/34584#M25380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have some problems with forwarding threat syslog events from Panorama to OSSIM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have several PA and they forward their threat logs to our Panorama Appliance via SSL&lt;/P&gt;&lt;P&gt;Now we need this Threatlogs at our OSSIM System as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Because of, Policy restrictions we can not syslog directly from our PAs to our OSSIM System,&lt;/P&gt;&lt;P&gt;so i want use the Panorama instead.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the only syslog information i got are general information logs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do i get my Panorama to forward the threatlogs to our OSSIM System?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx&lt;/P&gt;&lt;P&gt;Pascal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2012 11:55:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-syslog-forwarding-panorama-gt-ossim/m-p/34584#M25380</guid>
      <dc:creator>LCMember436</dc:creator>
      <dc:date>2012-07-11T11:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: threat syslog forwarding panorama -&gt; ossim</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-syslog-forwarding-panorama-gt-ossim/m-p/34585#M25381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First make sure your device is sending all severities to panorama.&amp;nbsp; Next check to make sure panorama is sending all log forwarding to the configured syslog under the objects tab and log forwarding.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jul 2012 19:06:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-syslog-forwarding-panorama-gt-ossim/m-p/34585#M25381</guid>
      <dc:creator>nayubi</dc:creator>
      <dc:date>2012-07-16T19:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: threat syslog forwarding panorama -&gt; ossim</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-syslog-forwarding-panorama-gt-ossim/m-p/34586#M25382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Under Objects-&amp;gt;Log Forwarding--&amp;gt;Log Type-&amp;gt;Threat&lt;/P&gt;&lt;P&gt;For all Severenity there ist the Syslog Server and Panorama configured.&lt;/P&gt;&lt;P&gt;So the PA send all Logs to the Panorama and the syslog server, but because of Firewall policies between the PAs and the syslog server it is not allowed to forwoard syslog through the firewall&lt;/P&gt;&lt;P&gt;And the PAs communicate over ssl witch the panorma which is allowed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;there are no firewall restrictions between Panorama and the syslog server&lt;/P&gt;&lt;P&gt;So I want the Panorama to forward the threat logs from all our PAs to the syslog server,&lt;/P&gt;&lt;P&gt;but the only syslogs the Panorama forwards are System logs from the Panorama itself but not any of the logs which the PAs send to the Panorama&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my Problem is how to configure the log forwarding of the threatlogs, which where send over ssl to the panorama, &lt;/P&gt;&lt;P&gt;now from the panorama to the syslog server&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jul 2012 16:12:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-syslog-forwarding-panorama-gt-ossim/m-p/34586#M25382</guid>
      <dc:creator>LCMember436</dc:creator>
      <dc:date>2012-07-17T16:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: threat syslog forwarding panorama -&gt; ossim</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-syslog-forwarding-panorama-gt-ossim/m-p/34587#M25383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bumping this thread. Also interested if anyone has seen this. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Aug 2012 18:25:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-syslog-forwarding-panorama-gt-ossim/m-p/34587#M25383</guid>
      <dc:creator>opiedrah</dc:creator>
      <dc:date>2012-08-01T18:25:27Z</dc:date>
    </item>
  </channel>
</rss>

