<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic UserID Built-in Syslog listener - Limitations? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/userid-built-in-syslog-listener-limitations/m-p/65448#M39084</link>
    <description>&lt;P&gt;We use the Syslog integration in the PAN Agents to forward User/IP-mappings from our wireless controllers to PA 5020 firewalls.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are considering to move the Syslog integration to connect directly with the PA5020 instead of the PAN Agents. But i remember having read something about limitations on the built-in Syslog reciever. That we should still use the PA Agents for "large scale use".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have now searched for hours for a document describing how many mappings (or other nubmers/limits) the built-in Syslog kan handle. But with no luck. Can anyone help with information about what can be expected by the built-in Syslog listener?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our setup is: 30 PA agents in different Active Directory domains forwarding userinformation. 30 Wireless controllers forwarding userinformation to the seperate PA agents. In total there's about 50.000 IP mappings where about 35.000 comes from Syslog.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Oct 2015 09:32:19 GMT</pubDate>
    <dc:creator>HerningsholmIT</dc:creator>
    <dc:date>2015-10-05T09:32:19Z</dc:date>
    <item>
      <title>UserID Built-in Syslog listener - Limitations?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-built-in-syslog-listener-limitations/m-p/65448#M39084</link>
      <description>&lt;P&gt;We use the Syslog integration in the PAN Agents to forward User/IP-mappings from our wireless controllers to PA 5020 firewalls.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are considering to move the Syslog integration to connect directly with the PA5020 instead of the PAN Agents. But i remember having read something about limitations on the built-in Syslog reciever. That we should still use the PA Agents for "large scale use".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have now searched for hours for a document describing how many mappings (or other nubmers/limits) the built-in Syslog kan handle. But with no luck. Can anyone help with information about what can be expected by the built-in Syslog listener?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our setup is: 30 PA agents in different Active Directory domains forwarding userinformation. 30 Wireless controllers forwarding userinformation to the seperate PA agents. In total there's about 50.000 IP mappings where about 35.000 comes from Syslog.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2015 09:32:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-built-in-syslog-listener-limitations/m-p/65448#M39084</guid>
      <dc:creator>HerningsholmIT</dc:creator>
      <dc:date>2015-10-05T09:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: UserID Built-in Syslog listener - Limitations?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-built-in-syslog-listener-limitations/m-p/65450#M39086</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;there is no built-in limit. What matters is logs/second you forward to it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dont use FW embedded agent in general : what will happen the day you start forwarding 10x or 100x more logs than usual when for example, your wifi controllers have issues and start re-authenticatiing people in a loop ?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2015 09:48:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-built-in-syslog-listener-limitations/m-p/65450#M39086</guid>
      <dc:creator>cpainchaud</dc:creator>
      <dc:date>2015-10-05T09:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: UserID Built-in Syslog listener - Limitations?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-built-in-syslog-listener-limitations/m-p/65451#M39087</link>
      <description>&lt;P&gt;At peak hours we have about 300-400 syslog messages/second.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there are no limits at all, then i guess using the built-in would be able to put the management plane to 100% usage if a loop occurs. And that would be a bad thing &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2015 10:34:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-built-in-syslog-listener-limitations/m-p/65451#M39087</guid>
      <dc:creator>HerningsholmIT</dc:creator>
      <dc:date>2015-10-05T10:34:41Z</dc:date>
    </item>
  </channel>
</rss>

