<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: log forwarding to m500 and SIEM in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-m500-and-siem/m-p/236933#M67892</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;raw 2574313513 2574313513 0 0 20895&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Oct 2018 23:55:26 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-10-24T23:55:26Z</dc:date>
    <item>
      <title>log forwarding to m500 and SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-m500-and-siem/m-p/236382#M67746</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have panorama in active and passive and all firewalls are connected to it.&lt;/P&gt;&lt;P&gt;We have m500 log collector and when i run below command&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sh logging status&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i see the firewall is sending logs to m500&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also we have configured logs to be send to SIEM.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;1&amp;gt;Need to know if SIEM logs are directly send from firewall to SIEM?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;how can i verify that?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;2&amp;gt;Need to know if any logs are going to Panorama or not?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;Does Panorama gets all the logs from m500?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;How can i verify the above?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Oct 2018 15:13:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-m500-and-siem/m-p/236382#M67746</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-21T15:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: log forwarding to m500 and SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-m500-and-siem/m-p/236418#M67753</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&amp;nbsp;1&amp;gt;Need to know if SIEM logs are directly send from firewall to SIEM?&lt;P&gt;&lt;FONT color="#FF0000"&gt;how can i verify that?&lt;/FONT&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Depends on how you configured it. If you have configured a log forwarding profile with the forwarding to your SIEM and have attached that profile to your security policies, then the logs are sent directly from the firewall. But you also have the possibility to forward all logs consolidated from the log collecter in the collector group settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is some help to check which way logs are forwarded:&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClqICAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClqICAS&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Oct 2018 20:50:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-m500-and-siem/m-p/236418#M67753</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-21T20:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: log forwarding to m500 and SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-m500-and-siem/m-p/236419#M67754</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;FONT color="#FF0000"&gt;2&amp;gt;Need to know if any logs are going to Panorama or not?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;Does Panorama gets all the logs from m500?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;How can i verify the above?&lt;/FONT&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;If you forward the logs to a log collecter then panorama actually does not get the logs at all. The logs are stored on the collector and panorama connects to the log collector to get logs that you want to see in the monitor tab or for reports.&lt;/P&gt;&lt;P&gt;To check if there are received logs, read this article:&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/71/panorama/panorama_adminguide/manage-log-collection/verify-log-forwarding-to-panorama" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/panorama/panorama_adminguide/manage-log-collection/verify-log-forwarding-to-panorama&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Oct 2018 22:16:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-m500-and-siem/m-p/236419#M67754</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-21T22:16:14Z</dc:date>
    </item>
    <item>
      <title>Re: log forwarding to m500 and SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-m500-and-siem/m-p/236482#M67775</link>
      <description>&lt;P&gt;I check the security policy and log forwarding .&lt;/P&gt;&lt;P&gt;Under log forwarding I see logs are going to SIEM&amp;nbsp; under syslog&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So these logs seems directly go to SIEM right?&lt;/P&gt;&lt;P&gt;Also under location I see panorama what does it mean?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 13:53:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-m500-and-siem/m-p/236482#M67775</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-22T13:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: log forwarding to m500 and SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-m500-and-siem/m-p/236483#M67776</link>
      <description>&lt;P&gt;is it&amp;nbsp; safe to run below command&amp;nbsp;&lt;/P&gt;&lt;PRE&gt; debug log-receiver statistics?&lt;/PRE&gt;</description>
      <pubDate>Mon, 22 Oct 2018 13:54:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-m500-and-siem/m-p/236483#M67776</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-22T13:54:40Z</dc:date>
    </item>
    <item>
      <title>Re: log forwarding to m500 and SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-m500-and-siem/m-p/236574#M67815</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;is it&amp;nbsp; safe to run below command&amp;nbsp;&lt;/P&gt;&lt;PRE&gt; debug log-receiver statistics?&lt;/PRE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Yes, it is.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 22:23:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-m500-and-siem/m-p/236574#M67815</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-22T22:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: log forwarding to m500 and SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-m500-and-siem/m-p/236576#M67816</link>
      <description>&lt;P&gt;which counter will tell me logs are going to collector?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;debug log-receiver statistics&lt;/P&gt;&lt;P&gt;Logging statistics&lt;BR /&gt;------------------------------ -----------&lt;BR /&gt;Log incoming rate: 260/sec&lt;BR /&gt;Log written rate: 260/sec&lt;BR /&gt;Corrupted packets: 0&lt;BR /&gt;Corrupted URL packets: 0&lt;BR /&gt;Corrupted HTTP HDR packets: 0&lt;BR /&gt;Corrupted EMAIL HDR packets: 0&lt;BR /&gt;Logs discarded (queue full): 0&lt;BR /&gt;Traffic logs written: 1574247759&lt;BR /&gt;GTP logs written: 0&lt;BR /&gt;Tunnel logs written: 0&lt;BR /&gt;Auth logs written: 58&lt;BR /&gt;Userid logs written: 60429003&lt;BR /&gt;URL logs written: 812033478&lt;BR /&gt;Wildfire logs written: 4420&lt;BR /&gt;Anti-virus logs written: 49&lt;BR /&gt;Widfire Anti-virus logs written: 219&lt;BR /&gt;Spyware logs written: 176790587&lt;BR /&gt;Spyware-DNS logs written: 1426&lt;BR /&gt;Attack logs written: 0&lt;BR /&gt;Vulnerability logs written: 11236847&lt;BR /&gt;Fileext logs written: 40&lt;BR /&gt;Fileext logs URL not written: 40&lt;BR /&gt;Fileext logs URL not written (timedout): 0&lt;BR /&gt;URL cache age out count: 0&lt;BR /&gt;URL cache full count: 786944447&lt;BR /&gt;URL cache key exist count: 2633725&lt;BR /&gt;URL cache wrt incomplete http hdrs count: 0&lt;BR /&gt;URL cache rcv http hdr before url count: 0&lt;BR /&gt;URL cache full drop count(url log not received): 0&lt;BR /&gt;URL cache age out drop count(url log not received): 0&lt;BR /&gt;Email hdr cache count: 4531&lt;BR /&gt;Email hdr cache hit count: 1182961&lt;BR /&gt;Traffic alarms dropped due to sysd write failures: 0&lt;BR /&gt;Traffic alarms dropped due to global rate limiting: 0&lt;BR /&gt;Traffic alarms dropped due to each source rate limiting: 0&lt;BR /&gt;Traffic alarms generated count: 0&lt;BR /&gt;Netflow incoming count: 0&lt;BR /&gt;Log Forward count: 8444&lt;BR /&gt;Log Forward discarded (queue full) count: 0&lt;BR /&gt;Log Forward discarded (send error) count: 0&lt;BR /&gt;Total logs not written due to disk unavailability: 0&lt;BR /&gt;Logs not written since disk became unavailable: 0&lt;/P&gt;&lt;P&gt;Summary Statistics:&lt;BR /&gt;Num current drop entries in trsum:0&lt;BR /&gt;Num cumulative drop entries in trsum:0&lt;BR /&gt;Num current drop entries in thsum:0&lt;BR /&gt;Num cumulative drop entries in thsum:0&lt;BR /&gt;Num current drop entries in gtpsum:0&lt;BR /&gt;Num cumulative drop entries in gtpsum:0&lt;/P&gt;&lt;P&gt;External Forwarding stats:&lt;BR /&gt;Type Enqueue Count Send Count Drop Count Queue Depth Send Rate(last 1min)&lt;BR /&gt;syslog 4543321883 4543321883 0 0 33955&lt;BR /&gt;snmp 0 0 0 0 0&lt;BR /&gt;email 6306 6306 0 0 0&lt;BR /&gt;raw 2574313513 2574313513 0 0 20895&lt;BR /&gt;http 0 0 0 0 0&lt;BR /&gt;autotag 0 0 0 0 0&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 22:28:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-m500-and-siem/m-p/236576#M67816</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-22T22:28:07Z</dc:date>
    </item>
    <item>
      <title>Re: log forwarding to m500 and SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-m500-and-siem/m-p/236933#M67892</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;raw 2574313513 2574313513 0 0 20895&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 23:55:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-m500-and-siem/m-p/236933#M67892</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-24T23:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: log forwarding to m500 and SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-m500-and-siem/m-p/236945#M67895</link>
      <description>&lt;P&gt;Many thanks !!&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 00:47:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-m500-and-siem/m-p/236945#M67895</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-25T00:47:33Z</dc:date>
    </item>
  </channel>
</rss>

