<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA syslogs and change logs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67694#M39644</link>
    <description>&lt;P&gt;How do you do it?&lt;/P&gt;</description>
    <pubDate>Thu, 05 Nov 2015 13:54:35 GMT</pubDate>
    <dc:creator>jdprovine</dc:creator>
    <dc:date>2015-11-05T13:54:35Z</dc:date>
    <item>
      <title>PA syslogs and change logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67405#M39517</link>
      <description>&lt;P&gt;Is it possible to send the syslogs for only the system changes from the pa to solarwinds?&amp;nbsp; How to you configure the PA to send the change logs to solarwinds?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2015 14:15:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67405#M39517</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-10-28T14:15:15Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslogs and change logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67473#M39546</link>
      <description>&lt;P&gt;Hi...Yes, you can forward config logs from the PA to any syslog server including SolarWinds.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 19:06:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67473#M39546</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2015-10-29T19:06:05Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslogs and change logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67475#M39548</link>
      <description>&lt;P&gt;I only want to send system and config changes to the solarwinds server is that done through snmp traps only and how is that configured?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 20:23:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67475#M39548</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-10-29T20:23:32Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslogs and change logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67480#M39551</link>
      <description>&lt;P&gt;In "Device" --&amp;gt; "Log Settings" &amp;nbsp;--&amp;gt; "System" and "Config" just use a configured Syslog profile to send have the desired logs sent to the configured syslog profile&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;--Edit--&lt;/P&gt;
&lt;P&gt;The same can be said for SNMP.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 21:02:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67480#M39551</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2015-10-29T21:02:53Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslogs and change logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67497#M39557</link>
      <description>&lt;P&gt;So what works better system and config sent by syslog or by snmp traps?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2015 12:36:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67497#M39557</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-10-30T12:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslogs and change logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67506#M39562</link>
      <description>&lt;P&gt;I don't think there's a "better," more to do with which you can use...I played with the idea of using SNMP for "important" stuff and syslog for general logs, but in the end I just went with syslog.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2015 14:47:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67506#M39562</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2015-10-30T14:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslogs and change logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67509#M39563</link>
      <description>&lt;P&gt;Well the thing is I don't think they can handle or want to deal with threat&amp;nbsp; logs on solarwinds&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2015 18:18:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67509#M39563</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-10-30T18:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslogs and change logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67603#M39609</link>
      <description>&lt;P&gt;I don't see where you can choose to only send config and system logs using syslog server&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2015 15:34:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67603#M39609</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-11-03T15:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslogs and change logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67613#M39616</link>
      <description>&lt;P&gt;That piece is under the log settings. Device-&amp;gt; Log Settings -&amp;gt;System.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2015 17:51:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67613#M39616</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-11-03T17:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslogs and change logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67649#M39623</link>
      <description>&lt;P&gt;Yes I found that so it that better than using the syslogs? Can you narrow down the syslogs and only send config and system logs no threat logs.&amp;nbsp; I already have snmp traps configured and added to the location you are recommending and its not giving us what we need on solarwinds&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 13:41:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67649#M39623</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-11-04T13:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslogs and change logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67677#M39632</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Yes this is possible as the threat logs are set in a different locations. So you can have only Config and System logs sent to your SIEM or logg collector and the threat and traffic stay on the PAN or Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 23:51:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67677#M39632</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-11-04T23:51:23Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslogs and change logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67694#M39644</link>
      <description>&lt;P&gt;How do you do it?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2015 13:54:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67694#M39644</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-11-05T13:54:35Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslogs and change logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67697#M39647</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I'm going to guess at what you are asking:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will first need to setup a syslog profile Device -&amp;gt; Server Profile -&amp;gt; Syslog&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;System logs are configured under Device -&amp;gt;Log Settings -&amp;gt; System&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Forward-System-Logs-to-Syslog-Server/ta-p/61804" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Forward-System-Logs-to-Syslog-Server/ta-p/61804&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Config logs are configured under Device -&amp;gt;Log Settings -&amp;gt; Config&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Forward-Config-Logs-to-Syslog-Server/ta-p/52099" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Forward-Config-Logs-to-Syslog-Server/ta-p/52099&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thats is if that is all you wish to send outside of the PAN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To export Threat and Traffic logs:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Setup a log forwarder: Objects -&amp;gt; Log Forwarding&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Forward-Threat-Logs-to-Syslog-Server/ta-p/59980" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Forward-Threat-Logs-to-Syslog-Server/ta-p/59980&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To have policies that are triggered to be sent exteranlly:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Within each policy: Policy -&amp;gt; Security -&amp;gt; 'Edit the Policy' -&amp;gt; Actions -&amp;gt; Log forwarding 'Select the Log forwarder you already setup'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Forward-Traffic-Logs-to-Syslog-Server/ta-p/62154" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Forward-Traffic-Logs-to-Syslog-Server/ta-p/62154&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2015 14:29:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67697#M39647</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-11-05T14:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslogs and change logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67727#M39654</link>
      <description>&lt;P&gt;Yes but I don't want to send the threat logs to the solarwinds server. I don't see where this is being excluded&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2015 22:14:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67727#M39654</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-11-05T22:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslogs and change logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67862#M39701</link>
      <description>&lt;P&gt;It doesnt have to be excluded. If you dont setup the traffic logs to forward, they will not send to the SIEM.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2015 18:49:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67862#M39701</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-11-09T18:49:20Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslogs and change logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67869#M39704</link>
      <description>&lt;P&gt;So are you saying if I set up a syslog server for solarwinds and go to device\logging setting\config and add it there it will only send config changes and system logs to the solarwinds server? I have snmp traps on that location too but it can probably be replaced with the syslog server&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2015 20:46:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67869#M39704</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-11-09T20:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslogs and change logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67871#M39705</link>
      <description>&lt;P&gt;That just sets up the PAN to send config changes, you would also need to go to Device-&amp;gt;LogSettings-&amp;gt;System and configure which type of system logs you would like to send.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Neither of the above settings are for the traffic or threat logs.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2015 20:55:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67871#M39705</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-11-09T20:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslogs and change logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67873#M39706</link>
      <description>&lt;P&gt;By type you mean informationanl critical, high etc&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2015 21:23:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67873#M39706</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-11-09T21:23:51Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslogs and change logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67876#M39707</link>
      <description>&lt;P&gt;For the system logs, correct. Config logs is all or none. Makes sense that way, to me at least.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2015 22:13:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67876#M39707</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-11-09T22:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: PA syslogs and change logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67899#M39716</link>
      <description>&lt;P&gt;Right now I have snmp traps enabled by going to device\server profiles\snmp traps. I went to device\log settings\system and configured snmp traps for the high and critca alerts then I added the snmp trap profile to device\log settings\config&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My other option is to go to the device\server profiles\syslog and create a syslog server profile and then add it to to device\log settings\config. In this option I don't see a way to pick and choose what information goes to the solarwinds server. It looks like to me that all the traffic, threat logs everything goes to the solar wind server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To me it looks like the syslogs server sends far more informaiton than the snmp traps does but it also sends much more than system and configuration changes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 13:47:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-syslogs-and-change-logs/m-p/67899#M39716</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-11-10T13:47:18Z</dc:date>
    </item>
  </channel>
</rss>

