<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SysLog setup not working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-setup-not-working/m-p/38610#M28281</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As you have mentioned you are not seeing any syslog messages being sent out of the pan in the tcpdump, the issues could be on pan side. I would recommend you to restart the mgmt server and see if it help this will NOT effect any of your live traffic. You can try this with the command "debug software restart management-server" also can you please let me know if the actual traffic logs are showing up as expected ? I mean the device is logging the traffic and you are able to see that in the traffic and threat logs ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sandeep T&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 Sep 2012 23:01:27 GMT</pubDate>
    <dc:creator>sdurga</dc:creator>
    <dc:date>2012-09-18T23:01:27Z</dc:date>
    <item>
      <title>SysLog setup not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-setup-not-working/m-p/38606#M28277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I am using PA-2050, with PAN OS 4.1.3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From few days I am trying to configure the syslog to be sent to a central logging system. I followed every possible documentation, but I am not getting any syslogs coming to the syslog server.&amp;nbsp; I tried on syslog server on linux and windows. I tried splunk, kiwi and few more. and finally I could conclude that PA is not sending out the logs to any servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I followed the configuration as seen on the following URL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.sawmill.co.uk/docs/Sawmill-Integration-with-PaloAlto-Networks.pdf"&gt;http://www.sawmill.co.uk/docs/Sawmill-Integration-with-PaloAlto-Networks.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then I used the tcpdump to verify&amp;nbsp; that PA is sending something to my syslog server but the output was 0. I used the tcpdump as following &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; tcpdump -v udp and port 5055 -w test.log&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;by the way I am not using the standard port, instead I am using udp 5055 to listen on my syslog server. The port is open on my syslog server as I can see that in netstat command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then I configured PA with system logging (Device-&amp;gt; Log Settings -&amp;gt; Config and Device -&amp;gt; log Settings -&amp;gt; System) and what I could see is that system based logs coming to the syslog server, but not anything related to the user traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I doubt if I am missing something. Can you people please help me with this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Sep 2012 11:35:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-setup-not-working/m-p/38606#M28277</guid>
      <dc:creator>shihabhamsa</dc:creator>
      <dc:date>2012-09-18T11:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: SysLog setup not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-setup-not-working/m-p/38607#M28278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you defined the forwarding profile in each security rule?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Sep 2012 13:20:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-setup-not-working/m-p/38607#M28278</guid>
      <dc:creator>mharding</dc:creator>
      <dc:date>2012-09-18T13:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: SysLog setup not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-setup-not-working/m-p/38608#M28279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Absolutely yes. But nothing happens. I just thought of rebooting the device once and remove everything just to start from scratch, "only the logging part"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Sep 2012 15:36:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-setup-not-working/m-p/38608#M28279</guid>
      <dc:creator>shihabhamsa</dc:creator>
      <dc:date>2012-09-18T15:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: SysLog setup not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-setup-not-working/m-p/38609#M28280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Hi,&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Please verify if you have configured in the following manner.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Under Device tab--&amp;gt; server profiles---&amp;gt; syslog&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;you create a syslog server profile&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;and do the commit.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/servlet/JiveServlet/showImage/2-18982-4066/Untitled.png" style="font-style: inherit; font-family: inherit; color: #316989;"&gt;&lt;IMG alt="Untitled.png" class="jive-image-thumbnail jive-image jiveImage" height="216" src="https://live.paloaltonetworks.com/legacyfs/online/4073_Untitled.png" style="font-style: inherit; font-family: inherit;" width="450" /&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Please verify that the ip address of the server and port has been configured correctly and are correct. If ping is allowed then to CLI and use following command to ping the syslog server and see if you get response.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;ping host &amp;lt;ipadress&amp;gt; &lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;This above command will ping from the management server.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Then you go to log forwarding option under&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Objects tab--&amp;gt; log forwarding&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Then choose that profile in the log forwarding profile for the logs you want forwarded to the syslog&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;make sure to do the commit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/servlet/JiveServlet/showImage/2-18982-4067/Untitled1.jpg" style="font-style: inherit; font-family: inherit; color: #316989;"&gt;&lt;IMG alt="Untitled1.jpg" class="jive-image-thumbnail jive-image jiveImage" height="150" src="https://live.paloaltonetworks.com/legacyfs/online/4074_Untitled1.jpg" style="font-style: inherit; font-family: inherit;" width="450" /&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;This will allow you to forward the traffic logs for all the severity and if you want you can forward it for all the threat logs or the needs threat logs.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;How is your management interface configured. Is it passing through the firewall. If yes it is possible that it is getting dropped by one of the security policy.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Please check the traffic log to verify if your traffic is getting dropped. &lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;If it is a internal to internal zone by default that traffic will not show in the logs please make sure a rule is created to show that traffic so you can verify.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-size: 12px; font-family: Arial, Helvetica, sans-serif;"&gt;If the above suggestion doesn't work either then try to route the syslog traffic through one of the data ports.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-size: 12px; font-family: Arial, Helvetica, sans-serif;"&gt;Go to device tab---&amp;gt;setup---&amp;gt; services tab---&amp;gt; service route configuration and select any external interface and see if the traffic is being sent now. &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff;"&gt;&lt;IMG alt="Untitled2.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4069_Untitled2.jpg" width="450" /&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P&gt;If the above configuration works then there might be an issue for the management server to reach to the syslog server.&lt;/P&gt;&lt;P&gt;Let us know if this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you &lt;/P&gt;&lt;P&gt;mbutt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Sep 2012 22:15:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-setup-not-working/m-p/38609#M28280</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2012-09-18T22:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: SysLog setup not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-setup-not-working/m-p/38610#M28281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As you have mentioned you are not seeing any syslog messages being sent out of the pan in the tcpdump, the issues could be on pan side. I would recommend you to restart the mgmt server and see if it help this will NOT effect any of your live traffic. You can try this with the command "debug software restart management-server" also can you please let me know if the actual traffic logs are showing up as expected ? I mean the device is logging the traffic and you are able to see that in the traffic and threat logs ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sandeep T&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Sep 2012 23:01:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-setup-not-working/m-p/38610#M28281</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-09-18T23:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: SysLog setup not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-setup-not-working/m-p/38611#M28282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mbutt,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thank you for the screenshots. I did exactly as you said, but the only thing I didn't do is that I didn't commit after every single step, but I did after everything. Not sure how the PA does normally but in my case PA will take almost 2-4 minutes for each commit.&lt;/P&gt;&lt;P&gt;My setup is as following&lt;/P&gt;&lt;P&gt;My syslog server listening for port 5140&amp;nbsp; (I am using 514 for something else)&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;IMG alt="syslogServerPort.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4075_syslogServerPort.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My PA setup&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Log forwarding Profile&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; My security Rules&lt;/P&gt;&lt;P&gt;&lt;IMG alt="PASyslogServer.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4077_PASyslogServer.png" width="450" /&gt;&lt;IMG alt="PALogForwardingProfile.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4078_PALogForwardingProfile.png" width="450" /&gt; &lt;IMG alt="PASecurityRule.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4079_PASecurityRule.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Service Route (I changed after your reply)&lt;/P&gt;&lt;P&gt;&lt;IMG alt="PAServiceRoute.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4080_PAServiceRoute.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After all these I am not getting any hit on syslog server on port 5140, it stays 0 I verified this after dumping on port 5140 for more than 12 hours and still the count is zero. basically I would expect few hundreds hits per second. I have huge activity on my network&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; a tcpdump showing if any hits on the specific port 5140, unfortunately there is 0 hits&lt;/P&gt;&lt;P&gt;&lt;IMG alt="syslogServerMonitor.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4082_syslogServerMonitor.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here ends my configuration and monitoring.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I configured the syslog for the system from the following&lt;/P&gt;&lt;P&gt;&lt;IMG alt="PASyslogforSystem.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4083_PASyslogforSystem.png" width="450" /&gt;&lt;IMG alt="PASyslogforSystem2.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4085_PASyslogforSystem2.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;I believe this is for the PA system logs and not related with any user traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But when I configure this log to my central logging server I will get hit like 1 or 2 in few minutes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="SyslogServerAfterPAServerLog.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4086_SyslogServerAfterPAServerLog.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;This is just to confirm that there is no routing issue between PA and my server and there is no configuration mistakes on both syslog server and PA config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No idea how to proceed now. It was working before. The only change is that I had my server changed to new IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As sdurga said I had a management server restart, that also didn't help. But when I executed the &lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;"debug software restart management-server" &lt;/SPAN&gt; command I got an output like the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Process 'mgmtsrvr' executing RESTART&lt;/P&gt;&lt;P&gt;Sep 19 07:33:36 Error: pan_read_full(comm_utils.c:97): srvr: fatal recv error. sock=3 err=Connection reset by peer (131)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Sep 2012 05:54:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-setup-not-working/m-p/38611#M28282</guid>
      <dc:creator>shihabhamsa</dc:creator>
      <dc:date>2012-09-19T05:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: SysLog setup not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-setup-not-working/m-p/38612#M28283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is expected output. Please open up a ticket with support there might be something else going on the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Sandeep T&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Sep 2012 06:31:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-setup-not-working/m-p/38612#M28283</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-09-19T06:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: SysLog setup not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-setup-not-working/m-p/584536#M116759</link>
      <description>&lt;P&gt;Hello, i&amp;nbsp; know this is the old post, I am having a similar issue. Were you able to fix the issue? If so do you remember the fix?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2024 21:34:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-setup-not-working/m-p/584536#M116759</guid>
      <dc:creator>surazr</dc:creator>
      <dc:date>2024-04-22T21:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: SysLog setup not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-setup-not-working/m-p/586798#M117101</link>
      <description>&lt;P&gt;I face the same issue after changing the Syslog IP to the new server.&lt;/P&gt;
&lt;P&gt;May i know what version you are running on? Just to verify if we are running on same version may be it could be bug.&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 14:15:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-setup-not-working/m-p/586798#M117101</guid>
      <dc:creator>Sanjay_Ramaiah</dc:creator>
      <dc:date>2024-05-15T14:15:24Z</dc:date>
    </item>
  </channel>
</rss>

