<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Flood log triggered by DoS Protection could not be sent to syslog server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/flood-log-triggered-by-dos-protection-could-not-be-sent-to/m-p/114156#M45289</link>
    <description>&lt;P&gt;Is it possible to send flood event to syslog server now, 4 years later?:)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 19 Sep 2016 12:25:01 GMT</pubDate>
    <dc:creator>santonic</dc:creator>
    <dc:date>2016-09-19T12:25:01Z</dc:date>
    <item>
      <title>Flood log triggered by DoS Protection could not be sent to syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flood-log-triggered-by-dos-protection-could-not-be-sent-to/m-p/28507#M20831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Problem description :&lt;/P&gt;&lt;P&gt;Flood log triggered by DoS Protection could not be sent to syslog server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;paloalto deploy: v-wire mode&lt;/P&gt;&lt;P&gt;PANOS : v4.1.8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Settings in paloalto :&lt;/P&gt;&lt;P&gt;1. Device -&amp;gt; Server Profiles -&amp;gt; Syslog -&amp;gt; Add a syslog server with port 514 and LOG_USER facility.&lt;/P&gt;&lt;P&gt;2. Objects -&amp;gt; Log Forwarding -&amp;gt; Add a syslog forwarding profile, all severity(Informational, Low, Medium, High and Critical) under threat settings are set syslog profile.&lt;/P&gt;&lt;P&gt;3. Objects -&amp;gt; DoS Protection -&amp;gt; Add a flood , type 'classified', enable SYN Flood, UDP Flood, ICMP Flood, and Other IP Flood, those alarm rate and active rate is 10 packets/sec.&lt;/P&gt;&lt;P&gt;4. From trust to untrust zone and untrust to trust zone security policy, apply default antivirus profile and log forward to syslog server.&lt;/P&gt;&lt;P&gt;5. Add a DoS Protection policy, from trust to untrust zone, set protect action, and Classified enabled, choose flood profile set in step3, Address choose 'source-ip-only'.&lt;/P&gt;&lt;P&gt;6 commit all settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Testing :&lt;/P&gt;&lt;P&gt;1. A client in trust zone, access eicar virus test file, the eicar test file deny log could be viewed in paloalto Monitor -&amp;gt; Logs -&amp;gt; Threat and in syslog server.&lt;/P&gt;&lt;P&gt;2. A client in trust zone, use 'hping' tool to generate tcp flood, the tcp flood log could be viewed in paloalto&amp;nbsp; Monitor -&amp;gt; Logs -&amp;gt; Threat, but syslog is nothing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could flood log triggered by DoS Protection not be sent to syslog server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The attachment is pa-500 configuration and monitor screenshot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2012 10:22:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flood-log-triggered-by-dos-protection-could-not-be-sent-to/m-p/28507#M20831</guid>
      <dc:creator>marcowang</dc:creator>
      <dc:date>2012-11-26T10:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: Flood log triggered by DoS Protection could not be sent to syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flood-log-triggered-by-dos-protection-could-not-be-sent-to/m-p/114156#M45289</link>
      <description>&lt;P&gt;Is it possible to send flood event to syslog server now, 4 years later?:)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2016 12:25:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flood-log-triggered-by-dos-protection-could-not-be-sent-to/m-p/114156#M45289</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-09-19T12:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: Flood log triggered by DoS Protection could not be sent to syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flood-log-triggered-by-dos-protection-could-not-be-sent-to/m-p/114500#M45329</link>
      <description>&lt;P&gt;So nobody managed to send 'flood' event to syslog?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2016 09:23:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flood-log-triggered-by-dos-protection-could-not-be-sent-to/m-p/114500#M45329</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-09-20T09:23:01Z</dc:date>
    </item>
    <item>
      <title>Re: Flood log triggered by DoS Protection could not be sent to syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flood-log-triggered-by-dos-protection-could-not-be-sent-to/m-p/364741#M88497</link>
      <description>&lt;P&gt;set your zone logging profile to enable logging for Zone Protection events to syslog (or other log forwarding methods)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHICA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHICA0&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Nov 2020 00:32:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flood-log-triggered-by-dos-protection-could-not-be-sent-to/m-p/364741#M88497</guid>
      <dc:creator>epartington</dc:creator>
      <dc:date>2020-11-22T00:32:11Z</dc:date>
    </item>
  </channel>
</rss>

