<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple syslog servers under one profile in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-syslog-servers-under-one-profile/m-p/47556#M34959</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It should forward the logs to both the syslog servers. Please verify if you can reach the syslog server (not receiving the logs) from the firewall service route.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Apr 2012 20:25:18 GMT</pubDate>
    <dc:creator>zarina</dc:creator>
    <dc:date>2012-04-25T20:25:18Z</dc:date>
    <item>
      <title>Multiple syslog servers under one profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-syslog-servers-under-one-profile/m-p/47555#M34958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A client has set up two syslog servers as destinations on one syslog server profile, but only one of the servers is receiving data. Is that expected behavior on 4.1.3? The hope was to be able to send syslog traffic to both devices.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Apr 2012 13:38:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-syslog-servers-under-one-profile/m-p/47555#M34958</guid>
      <dc:creator>jcostello</dc:creator>
      <dc:date>2012-04-25T13:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple syslog servers under one profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-syslog-servers-under-one-profile/m-p/47556#M34959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It should forward the logs to both the syslog servers. Please verify if you can reach the syslog server (not receiving the logs) from the firewall service route.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Apr 2012 20:25:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-syslog-servers-under-one-profile/m-p/47556#M34959</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2012-04-25T20:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple syslog servers under one profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-syslog-servers-under-one-profile/m-p/47557#M34960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi James,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As said by Sri, you should be able to send logs out to both syslog servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check your Service route configuration to see if the the syslog is configured to connect via the management interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so use the command&lt;/P&gt;&lt;P&gt;admin@PA&amp;gt; telnet host &amp;lt;syslog-server ip&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We wont be able to do a pcap on the Firewall if it goes through management interface. If it is possible to do a pcap on syslog that can also help you determine the cause of failure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it goes through the Dataplane interfaces you can possibly do a pcap on PAN&amp;nbsp; to troubleshoot the connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Apr 2012 21:03:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-syslog-servers-under-one-profile/m-p/47557#M34960</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-04-25T21:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple syslog servers under one profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-syslog-servers-under-one-profile/m-p/47558#M34961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;jcostello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're in the process of testing 4.1.4 before we migrate. Can you give some more detail here? Is it a situation where all logs go to syslog1, but not syslog2? Or, is a certain percentage of logs being lost.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;As I write a test case for this, I want to make sure I'm looking for the right thing.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MJ&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Apr 2012 22:45:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-syslog-servers-under-one-profile/m-p/47558#M34961</guid>
      <dc:creator>markjx</dc:creator>
      <dc:date>2012-04-25T22:45:22Z</dc:date>
    </item>
  </channel>
</rss>

