<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: syslog configuration in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration/m-p/75129#M41884</link>
    <description>&lt;P&gt;As I understand syslog facility is used on the syslog server to decide which log goes into which file. Facility will not help to increase or decrease the level of logging on the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As per RFC:&amp;nbsp;&lt;A href="https://tools.ietf.org/html/rfc3164" target="_blank"&gt;https://tools.ietf.org/html/rfc3164&lt;/A&gt; following are the facility codes defined:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="wikitable"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TH&gt;Facility code&lt;/TH&gt;
&lt;TH&gt;Keyword&lt;/TH&gt;
&lt;TH&gt;Description&lt;/TH&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;TD&gt;kern&lt;/TD&gt;
&lt;TD&gt;kernel messages&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;1&lt;/TD&gt;
&lt;TD&gt;user&lt;/TD&gt;
&lt;TD&gt;user-level messages&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2&lt;/TD&gt;
&lt;TD&gt;mail&lt;/TD&gt;
&lt;TD&gt;mail system&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;3&lt;/TD&gt;
&lt;TD&gt;daemon&lt;/TD&gt;
&lt;TD&gt;system daemons&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;4&lt;/TD&gt;
&lt;TD&gt;auth&lt;/TD&gt;
&lt;TD&gt;security/authorization messages&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;5&lt;/TD&gt;
&lt;TD&gt;syslog&lt;/TD&gt;
&lt;TD&gt;messages generated internally by syslogd&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;6&lt;/TD&gt;
&lt;TD&gt;lpr&lt;/TD&gt;
&lt;TD&gt;line printer subsystem&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;7&lt;/TD&gt;
&lt;TD&gt;news&lt;/TD&gt;
&lt;TD&gt;network news subsystem&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;8&lt;/TD&gt;
&lt;TD&gt;uucp&lt;/TD&gt;
&lt;TD&gt;UUCP subsystem&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;9&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;clock daemon&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;10&lt;/TD&gt;
&lt;TD&gt;authpriv&lt;/TD&gt;
&lt;TD&gt;security/authorization messages&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;11&lt;/TD&gt;
&lt;TD&gt;ftp&lt;/TD&gt;
&lt;TD&gt;FTP daemon&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;12&lt;/TD&gt;
&lt;TD&gt;-&lt;/TD&gt;
&lt;TD&gt;NTP subsystem&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;13&lt;/TD&gt;
&lt;TD&gt;-&lt;/TD&gt;
&lt;TD&gt;log audit&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;14&lt;/TD&gt;
&lt;TD&gt;-&lt;/TD&gt;
&lt;TD&gt;log alert&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;15&lt;/TD&gt;
&lt;TD&gt;cron&lt;/TD&gt;
&lt;TD&gt;scheduling daemon&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;16&lt;/TD&gt;
&lt;TD&gt;local0&lt;/TD&gt;
&lt;TD&gt;local use 0 (local0)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;17&lt;/TD&gt;
&lt;TD&gt;local1&lt;/TD&gt;
&lt;TD&gt;local use 1 (local1)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;18&lt;/TD&gt;
&lt;TD&gt;local2&lt;/TD&gt;
&lt;TD&gt;local use 2 (local2)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;19&lt;/TD&gt;
&lt;TD&gt;local3&lt;/TD&gt;
&lt;TD&gt;local use 3 (local3)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;20&lt;/TD&gt;
&lt;TD&gt;local4&lt;/TD&gt;
&lt;TD&gt;local use 4 (local4)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;21&lt;/TD&gt;
&lt;TD&gt;local5&lt;/TD&gt;
&lt;TD&gt;local use 5 (local5)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;22&lt;/TD&gt;
&lt;TD&gt;local6&lt;/TD&gt;
&lt;TD&gt;local use 6 (local6)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;23&lt;/TD&gt;
&lt;TD&gt;local7&lt;/TD&gt;
&lt;TD&gt;local use 7 (local7)&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Whereas the severity under the Log forwarding profile helps to decide what kind of logs you want to send to the syslog server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can choose to send different severity logs to the same syslog server with different facility values, so that they can be handled separately by the server. I hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-BR&lt;/P&gt;</description>
    <pubDate>Thu, 24 Mar 2016 00:50:28 GMT</pubDate>
    <dc:creator>abjain</dc:creator>
    <dc:date>2016-03-24T00:50:28Z</dc:date>
    <item>
      <title>syslog configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration/m-p/75098#M41878</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have attached &amp;nbsp;my syslog configuration .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but in my syslog i missed most of the logs .&lt;/P&gt;
&lt;P&gt;then assigned to the &amp;nbsp;policy &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To &amp;nbsp;forward all the logs&amp;nbsp;&amp;nbsp;, attached configuration&amp;nbsp;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/3171iE1BAD549E280A19D/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="Palo alto syslog server.png" title="Palo alto syslog server.png" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/3172i91C751788DDD8B20/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="server pofile.png" title="server pofile.png" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what if &amp;nbsp;i choose another facilty &amp;nbsp;?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if i put one interface in tap mode &amp;nbsp;can i &amp;nbsp;forward the log to syslog server&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2016 14:25:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration/m-p/75098#M41878</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2016-03-23T14:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: syslog configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration/m-p/75100#M41880</link>
      <description>&lt;P&gt;Yes you can. Make sure the security policy that you will create for the tap mode apply the syslog profile in the security policy.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2016 14:29:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration/m-p/75100#M41880</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2016-03-23T14:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: syslog configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration/m-p/75102#M41882</link>
      <description>&lt;P&gt;Hi Sib&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;are you seeing some logs or none on the syslog server ?&lt;/P&gt;
&lt;P&gt;the facility is merely a 'view' option in syslog, you should be able to toggle your syslog server to that view to make sure the logs are being received&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to verify logs are being forwarded properly, please take a look at&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&amp;gt; debug log-receiver statistics&lt;/PRE&gt;
&lt;P&gt;at the bottom you will see&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;External Forwarding stats:
      Type  Enqueue Count     Send Count     Drop Count    Queue Depth     Send Rate(last 1min)
    syslog              0              0              0              0                        0
&lt;/PRE&gt;
&lt;P class="p1"&gt;which can help determine if syslog is being sent out properly or not&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2016 14:43:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration/m-p/75102#M41882</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-03-23T14:43:58Z</dc:date>
    </item>
    <item>
      <title>hRe: syslog configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration/m-p/75109#M41883</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the differnces between facility 7 and facilty 6 .&lt;/P&gt;
&lt;P&gt;choosing facilty 7 will increase the visibilty of the logs , (mean wil it include all logs )&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2016 16:38:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration/m-p/75109#M41883</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2016-03-23T16:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: syslog configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration/m-p/75129#M41884</link>
      <description>&lt;P&gt;As I understand syslog facility is used on the syslog server to decide which log goes into which file. Facility will not help to increase or decrease the level of logging on the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As per RFC:&amp;nbsp;&lt;A href="https://tools.ietf.org/html/rfc3164" target="_blank"&gt;https://tools.ietf.org/html/rfc3164&lt;/A&gt; following are the facility codes defined:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="wikitable"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TH&gt;Facility code&lt;/TH&gt;
&lt;TH&gt;Keyword&lt;/TH&gt;
&lt;TH&gt;Description&lt;/TH&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;TD&gt;kern&lt;/TD&gt;
&lt;TD&gt;kernel messages&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;1&lt;/TD&gt;
&lt;TD&gt;user&lt;/TD&gt;
&lt;TD&gt;user-level messages&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2&lt;/TD&gt;
&lt;TD&gt;mail&lt;/TD&gt;
&lt;TD&gt;mail system&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;3&lt;/TD&gt;
&lt;TD&gt;daemon&lt;/TD&gt;
&lt;TD&gt;system daemons&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;4&lt;/TD&gt;
&lt;TD&gt;auth&lt;/TD&gt;
&lt;TD&gt;security/authorization messages&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;5&lt;/TD&gt;
&lt;TD&gt;syslog&lt;/TD&gt;
&lt;TD&gt;messages generated internally by syslogd&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;6&lt;/TD&gt;
&lt;TD&gt;lpr&lt;/TD&gt;
&lt;TD&gt;line printer subsystem&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;7&lt;/TD&gt;
&lt;TD&gt;news&lt;/TD&gt;
&lt;TD&gt;network news subsystem&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;8&lt;/TD&gt;
&lt;TD&gt;uucp&lt;/TD&gt;
&lt;TD&gt;UUCP subsystem&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;9&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;clock daemon&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;10&lt;/TD&gt;
&lt;TD&gt;authpriv&lt;/TD&gt;
&lt;TD&gt;security/authorization messages&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;11&lt;/TD&gt;
&lt;TD&gt;ftp&lt;/TD&gt;
&lt;TD&gt;FTP daemon&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;12&lt;/TD&gt;
&lt;TD&gt;-&lt;/TD&gt;
&lt;TD&gt;NTP subsystem&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;13&lt;/TD&gt;
&lt;TD&gt;-&lt;/TD&gt;
&lt;TD&gt;log audit&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;14&lt;/TD&gt;
&lt;TD&gt;-&lt;/TD&gt;
&lt;TD&gt;log alert&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;15&lt;/TD&gt;
&lt;TD&gt;cron&lt;/TD&gt;
&lt;TD&gt;scheduling daemon&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;16&lt;/TD&gt;
&lt;TD&gt;local0&lt;/TD&gt;
&lt;TD&gt;local use 0 (local0)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;17&lt;/TD&gt;
&lt;TD&gt;local1&lt;/TD&gt;
&lt;TD&gt;local use 1 (local1)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;18&lt;/TD&gt;
&lt;TD&gt;local2&lt;/TD&gt;
&lt;TD&gt;local use 2 (local2)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;19&lt;/TD&gt;
&lt;TD&gt;local3&lt;/TD&gt;
&lt;TD&gt;local use 3 (local3)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;20&lt;/TD&gt;
&lt;TD&gt;local4&lt;/TD&gt;
&lt;TD&gt;local use 4 (local4)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;21&lt;/TD&gt;
&lt;TD&gt;local5&lt;/TD&gt;
&lt;TD&gt;local use 5 (local5)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;22&lt;/TD&gt;
&lt;TD&gt;local6&lt;/TD&gt;
&lt;TD&gt;local use 6 (local6)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;23&lt;/TD&gt;
&lt;TD&gt;local7&lt;/TD&gt;
&lt;TD&gt;local use 7 (local7)&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Whereas the severity under the Log forwarding profile helps to decide what kind of logs you want to send to the syslog server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can choose to send different severity logs to the same syslog server with different facility values, so that they can be handled separately by the server. I hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-BR&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2016 00:50:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-configuration/m-p/75129#M41884</guid>
      <dc:creator>abjain</dc:creator>
      <dc:date>2016-03-24T00:50:28Z</dc:date>
    </item>
  </channel>
</rss>

