<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SNMP notifications - some missing? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/snmp-notifications-some-missing/m-p/51603#M37959</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi @mcocat,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure SNMP under Objects -&amp;gt; Log Forwarding. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="snmp_1.JPG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16948_snmp_1.JPG" style="height: 306px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then use this log forwarding on all security policy that you want get alerts from. Under Policies - &amp;gt; Security -&amp;gt; Action -&amp;gt; Log Forwarding&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 19 Nov 2014 15:00:45 GMT</pubDate>
    <dc:creator>ssharma</dc:creator>
    <dc:date>2014-11-19T15:00:45Z</dc:date>
    <item>
      <title>SNMP notifications - some missing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/snmp-notifications-some-missing/m-p/51602#M37958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have enabled SNMP notifications on threats greater than or equal to severity "medium". Under monitor &amp;gt; threats I am seeing my alerts, but I only receive (via SNMP) some of the threats that shows up on the PA interface. Here is an example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am only receiving SNMP alarms on the "SCAN: Host Sweeps", but not the spyware or the virus.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2014-11-19 at 8.37.46 AM.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16947_Screen Shot 2014-11-19 at 8.37.46 AM.png" style="height: 124px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this because of the rule being hit? How can I enable notifications on all of the rules?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 14:39:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/snmp-notifications-some-missing/m-p/51602#M37958</guid>
      <dc:creator>mcocat</dc:creator>
      <dc:date>2014-11-19T14:39:18Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP notifications - some missing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/snmp-notifications-some-missing/m-p/51603#M37959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi @mcocat,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure SNMP under Objects -&amp;gt; Log Forwarding. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="snmp_1.JPG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16948_snmp_1.JPG" style="height: 306px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then use this log forwarding on all security policy that you want get alerts from. Under Policies - &amp;gt; Security -&amp;gt; Action -&amp;gt; Log Forwarding&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 15:00:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/snmp-notifications-some-missing/m-p/51603#M37959</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-11-19T15:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP notifications - some missing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/snmp-notifications-some-missing/m-p/51604#M37960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So for my P_User Rule -Apps Allowed rule, I already have log forwarding enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2014-11-19 at 9.06.05 AM.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16949_Screen Shot 2014-11-19 at 9.06.05 AM.png" style="height: 340px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And here is my log forwarding settings:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2014-11-19 at 9.08.15 AM.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16950_Screen Shot 2014-11-19 at 9.08.15 AM.png" style="height: 137px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 15:08:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/snmp-notifications-some-missing/m-p/51604#M37960</guid>
      <dc:creator>mcocat</dc:creator>
      <dc:date>2014-11-19T15:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP notifications - some missing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/snmp-notifications-some-missing/m-p/51605#M37961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you are using P-Panorama log forwarding profile, which does not have SNMP enabled on them. You have Panorama rule, which has SNMP but that is not used in your P_User Rule -Apps Allowed rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So 2 options,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. either use Panorama log forwarding instead of P-Panorama in P_User Rule -Apps Allowed rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Or modify P-Panorama rule to include snmp on them&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 15:13:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/snmp-notifications-some-missing/m-p/51605#M37961</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-11-19T15:13:02Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP notifications - some missing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/snmp-notifications-some-missing/m-p/51606#M37962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That makes sense, I have a commit running now. So the fact that I was receiving alerts for the entries that didn't match a rule would mean that my default isn't configured correctly to use P-Panorama. Where can I change the default? Thanks for your help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 15:21:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/snmp-notifications-some-missing/m-p/51606#M37962</guid>
      <dc:creator>mcocat</dc:creator>
      <dc:date>2014-11-19T15:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP notifications - some missing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/snmp-notifications-some-missing/m-p/51607#M37963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have to change P-Panorama from the Panorama server, which is pushing these configuration. Hope this helps. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 15:35:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/snmp-notifications-some-missing/m-p/51607#M37963</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-11-19T15:35:27Z</dc:date>
    </item>
  </channel>
</rss>

