<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Create test syslog in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/create-test-syslog/m-p/70440#M40511</link>
    <description>&lt;P&gt;Thank you, this would be really helpful.&amp;nbsp; I've had feature request in the past, I'll add to the list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Jan 2016 16:56:24 GMT</pubDate>
    <dc:creator>treese</dc:creator>
    <dc:date>2016-01-06T16:56:24Z</dc:date>
    <item>
      <title>Create test syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/create-test-syslog/m-p/69811#M40404</link>
      <description>&lt;P&gt;I want to know when our PBF rule hits by sending an email when sees the syslog.&amp;nbsp; I want to test this but don't want to actually fail traffic over.&amp;nbsp; There are test commands on the cli but haven't been able to find how to create a false syslog.&amp;nbsp; Please let me know how to create a false syslog.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2015 15:30:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/create-test-syslog/m-p/69811#M40404</guid>
      <dc:creator>treese</dc:creator>
      <dc:date>2015-12-23T15:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: Create test syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/create-test-syslog/m-p/69821#M40408</link>
      <description>&lt;P&gt;In "Log Settings" --&amp;gt; "Config" you can set that to send to your syslog server. &amp;nbsp;Make a configuration change which should send that to your syslog server. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2015 20:17:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/create-test-syslog/m-p/69821#M40408</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2015-12-23T20:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: Create test syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/create-test-syslog/m-p/69827#M40410</link>
      <description>&lt;P&gt;If you want to test if your firewall is sending the logs to the syslog or not.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Step1 Configure syslog server Device&amp;gt;server profile configure the syslog&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1738i5A15CC4AC68C7077/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="Syslog1.PNG" title="Syslog1.PNG" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Step2. Log setting. select the syslog server profile for&lt;/P&gt;
&lt;P&gt;system&amp;gt;information severity or for config&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1739iD33FEBFE5918272D/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="syslog2.PNG" title="syslog2.PNG" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1740i6B831E0028655422/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="syslog3.PNG" title="syslog3.PNG" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Step 3 Do a commit&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now if you navigate through the firewall tabs a system log of information severity will generated and firewall should send the logs to syslog. If you have selected the syslog for config as well then you will get the syslog for any config change.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Make sure the reachablilty to syslog is there. Check the service route if reachability is not there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2015 22:32:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/create-test-syslog/m-p/69827#M40410</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2015-12-23T22:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: Create test syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/create-test-syslog/m-p/70388#M40498</link>
      <description>&lt;P&gt;Thanks for the reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not trying to make a "config" change show up to my syslog server.&amp;nbsp; I want to get a system event regarding a PBF rule to sent the alert to my email.&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2016 22:28:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/create-test-syslog/m-p/70388#M40498</guid>
      <dc:creator>treese</dc:creator>
      <dc:date>2016-01-05T22:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: Create test syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/create-test-syslog/m-p/70390#M40500</link>
      <description>&lt;P&gt;I want to know when our PBF rule hits by sending an email when sees the system log.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2016 22:30:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/create-test-syslog/m-p/70390#M40500</guid>
      <dc:creator>treese</dc:creator>
      <dc:date>2016-01-05T22:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: Create test syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/create-test-syslog/m-p/70394#M40502</link>
      <description>&lt;P&gt;So far, Palo Alto&amp;nbsp;does not have capability to selectively filter system logs or alerts. &amp;nbsp;Mostly such type of alerts can be implemented in some external NMS solutions.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This needs to be a feature request. I see there are feature requests already for both functionalities, i.e. ability to filter events and option to send alert on PBF monitoring events. Kindly check with the Palo Alto SE for&amp;nbsp;the roadmap.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2016 00:39:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/create-test-syslog/m-p/70394#M40502</guid>
      <dc:creator>abjain</dc:creator>
      <dc:date>2016-01-06T00:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: Create test syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/create-test-syslog/m-p/70440#M40511</link>
      <description>&lt;P&gt;Thank you, this would be really helpful.&amp;nbsp; I've had feature request in the past, I'll add to the list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2016 16:56:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/create-test-syslog/m-p/70440#M40511</guid>
      <dc:creator>treese</dc:creator>
      <dc:date>2016-01-06T16:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: Create test syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/create-test-syslog/m-p/70713#M40581</link>
      <description>&lt;P&gt;Look into 'Swatch', its a relic but works. Send events to syslog as outlined then on your Linux host enable Swatch to parse syslog data (one or more log files) and send an alert on any keyword/event ID, etc. I use this for PAN URL, system and threat logs along with Cisco ASA log events. There are a lot of Swatch options including thresholds to suppress repeat events.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2016 20:43:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/create-test-syslog/m-p/70713#M40581</guid>
      <dc:creator>ellisr</dc:creator>
      <dc:date>2016-01-11T20:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: Create test syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/create-test-syslog/m-p/70715#M40582</link>
      <description>&lt;P&gt;I appreciate everyone's help.&amp;nbsp; I believe where I was off was our threats send emails directly from the fw to to us. The fw will send complete syslogs but unable to parse out specific objects/strings.&amp;nbsp; I'll have our solarwinds send over the specifics.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks again.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2016 20:46:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/create-test-syslog/m-p/70715#M40582</guid>
      <dc:creator>treese</dc:creator>
      <dc:date>2016-01-11T20:46:22Z</dc:date>
    </item>
  </channel>
</rss>

