<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there a way to automate reporting of &amp;quot;auth-fail&amp;quot; system log messages? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-automate-reporting-of-quot-auth-fail-quot/m-p/49548#M36508</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dave,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think at this time you have possibly tried each and every scenario. I am not sure if this can be achieved using XML API but it is worth giving a try.&lt;/P&gt;&lt;P&gt;Appears to me like a Feature Request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 03 Oct 2012 19:00:52 GMT</pubDate>
    <dc:creator>ppatel</dc:creator>
    <dc:date>2012-10-03T19:00:52Z</dc:date>
    <item>
      <title>Is there a way to automate reporting of "auth-fail" system log messages?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-automate-reporting-of-quot-auth-fail-quot/m-p/49547#M36507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm looking for a way to automatically/proactively report on auth-fail system log messages and not finding anything obvious. Some things I've tried;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. I can send email under log-settings -&amp;gt; system -&amp;gt; informational, but a bit too chatty with all the other messages and only interested in auth failures for VPN connections.&lt;/P&gt;&lt;P&gt;2. I created a filter for ( eventid eq auth-fail ) under log -&amp;gt; system,, and can export it to and excel spread sheet which is what I'm looking for but not automated.&lt;/P&gt;&lt;P&gt;3. I looked in PDF reports -&amp;gt; custom reports -&amp;gt; add, but there is not an option to look at the "system logs" there. This seems like the way to go but does not look possible yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems like this may be a feature request to add support for system logs. Any other ideas would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Oct 2012 18:08:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-automate-reporting-of-quot-auth-fail-quot/m-p/49547#M36507</guid>
      <dc:creator>dwgg</dc:creator>
      <dc:date>2012-10-03T18:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to automate reporting of "auth-fail" system log messages?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-automate-reporting-of-quot-auth-fail-quot/m-p/49548#M36508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dave,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think at this time you have possibly tried each and every scenario. I am not sure if this can be achieved using XML API but it is worth giving a try.&lt;/P&gt;&lt;P&gt;Appears to me like a Feature Request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Oct 2012 19:00:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-automate-reporting-of-quot-auth-fail-quot/m-p/49548#M36508</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-10-03T19:00:52Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to automate reporting of "auth-fail" system log messages?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-automate-reporting-of-quot-auth-fail-quot/m-p/49549#M36509</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dave,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However other than reporting, you can also manage to export logs for informational level only to the syslog server&lt;/P&gt;&lt;P&gt;event-id == auth-fail is of informational severity.&lt;/P&gt;&lt;P&gt;Link to the document:- &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-3817"&gt;https://live.paloaltonetworks.com/docs/DOC-3817&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Oct 2012 19:17:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-automate-reporting-of-quot-auth-fail-quot/m-p/49549#M36509</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-10-03T19:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to automate reporting of "auth-fail" system log messages?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-automate-reporting-of-quot-auth-fail-quot/m-p/49550#M36510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Parth,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the feedback. I currently syslog to syslog-ng but looks like long term I will need to forward to splunk and have it do the alerting on and "auth-fail" messages. I will also see the feature request works for the short term.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Oct 2012 20:51:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-automate-reporting-of-quot-auth-fail-quot/m-p/49550#M36510</guid>
      <dc:creator>dwgg</dc:creator>
      <dc:date>2012-10-03T20:51:43Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to automate reporting of "auth-fail" system log messages?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-automate-reporting-of-quot-auth-fail-quot/m-p/49551#M36511</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Speaking of auth-fail (and auth-success), is it me or doesnt PA log which account name was fail/success along with client ip who attempted this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have already filed this to my support (among some other CEF related questions) but I was thinking if someone in here already have been digging into this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2012 07:57:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-automate-reporting-of-quot-auth-fail-quot/m-p/49551#M36511</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-10-04T07:57:22Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to automate reporting of "auth-fail" system log messages?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-automate-reporting-of-quot-auth-fail-quot/m-p/49552#M36512</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see all that information in logs;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;4/26/2012 12:26&lt;/TD&gt;&lt;TD&gt;auth-fail general&lt;/TD&gt;&lt;TD&gt;informational&lt;/TD&gt;&lt;TD&gt;User 'xxx' failed authentication.&amp;nbsp; Reason: Invalid username/password From: 10.x.x.x.&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;4/18/2012 15:34&lt;/TD&gt;&lt;TD&gt;auth-fail general&lt;/TD&gt;&lt;TD&gt;informational&lt;/TD&gt;&lt;TD&gt;User 'xxx' failed authentication.&amp;nbsp; Reason: Invalid username/password From: 10.x.x.x.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2012 16:01:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-automate-reporting-of-quot-auth-fail-quot/m-p/49552#M36512</guid>
      <dc:creator>dwgg</dc:creator>
      <dc:date>2012-10-04T16:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to automate reporting of "auth-fail" system log messages?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-automate-reporting-of-quot-auth-fail-quot/m-p/49553#M36513</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmm, thanks for the reply... then its some error related to CEF (or configuration of it or receiving of it).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2012 17:53:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-automate-reporting-of-quot-auth-fail-quot/m-p/49553#M36513</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-10-04T17:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to automate reporting of "auth-fail" system log messages?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-automate-reporting-of-quot-auth-fail-quot/m-p/49554#M36514</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would like to receive an email everytime a&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;uth-fail (and auth-success) occurs. This is available in Cisco ASA, hopefully PA will include such granular options soon&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jun 2014 00:46:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-automate-reporting-of-quot-auth-fail-quot/m-p/49554#M36514</guid>
      <dc:creator>parichie</dc:creator>
      <dc:date>2014-06-18T00:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to automate reporting of "auth-fail" system log messages?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-automate-reporting-of-quot-auth-fail-quot/m-p/49555#M36515</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since this question was originally asked in 2012, I would *HOPE* some progress has been made on this... I was working with a client today who requested this and I went to write a custom report and was astonished that I couldn't find an easy solution to providing this report.&amp;nbsp; Why would the Configuration and System logs be exempt from the Custom Report builder?!?!?&amp;nbsp; This makes NO SENSE as an end-user.&amp;nbsp; I'm sure there's either a technical reason or a really (really) poor business reason, but either way, this seems like a reasonable and somewhat essential request.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Corey&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ATTN: &lt;A href="https://live.paloaltonetworks.com/u1/27904"&gt;mlutgen&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 May 2015 20:52:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-automate-reporting-of-quot-auth-fail-quot/m-p/49555#M36515</guid>
      <dc:creator>CoreySteele</dc:creator>
      <dc:date>2015-05-04T20:52:33Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to automate reporting of "auth-fail" system log messages?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-automate-reporting-of-quot-auth-fail-quot/m-p/49556#M36516</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree, there should be a way to easily do this. The only way I can see that it is possible currently aside from using a SEIM or Kiwi based alert would be to email every Informational log entry. You could selectively send informational logs to a Kiwi server. In Kiwi or SolarWinds it could discard everything but the auth-fail informational messages and alert on those.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is something built right into several products, including FortiGate firewalls. It would be great if those logs were built into the reporting fuction on the PA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/27904"&gt;mlutgen&lt;/A&gt;, &lt;A href="https://live.paloaltonetworks.com/u1/24344"&gt;cjsteele&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 May 2015 04:14:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-way-to-automate-reporting-of-quot-auth-fail-quot/m-p/49556#M36516</guid>
      <dc:creator>bspilde</dc:creator>
      <dc:date>2015-05-05T04:14:08Z</dc:date>
    </item>
  </channel>
</rss>

