<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fowarding to syslog- best practice in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/fowarding-to-syslog-best-practice/m-p/252125#M71684</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/17058"&gt;@fmurray&lt;/a&gt;&amp;nbsp;, FYI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have just about everything going to syslog, including Global Protect.&amp;nbsp; this is our corp policy and to do with legal stuff.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have logrotate&amp;nbsp; that zips files up and deletes them after a required ammount of time.&lt;/P&gt;&lt;P&gt;the information is quite overwhelming but with various scripts you can pull out the information you require.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;very rarely use it for traffic reports but every month reports are run for GlobalProtect activity.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 04 Mar 2019 12:30:40 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2019-03-04T12:30:40Z</dc:date>
    <item>
      <title>Fowarding to syslog- best practice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fowarding-to-syslog-best-practice/m-p/251965#M71644</link>
      <description>&lt;P&gt;Currently we forward nearly all of the firewall's logs to our syslog server, but the amount of irrelevant&amp;nbsp;minutiae is over-whelming the syslog server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a best-practice for what information should be forwarded to syslog?&amp;nbsp; I don't want to miss anything important but I ready want to eliminate the un-important.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 19:49:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fowarding-to-syslog-best-practice/m-p/251965#M71644</guid>
      <dc:creator>fmurray</dc:creator>
      <dc:date>2019-03-01T19:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: Fowarding to syslog- best practice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fowarding-to-syslog-best-practice/m-p/251975#M71645</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Honestly that is a 'it depends' answer as every one has a different set of requirements and thing sthey alert on. We also send everything to our SIEM but so that it can be correlated with other logs and events. While some traffic may look beging, it could actually be malicious.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know its not a great answer, but we scalled out SIEM to handel everything at only 60% capacity.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 20:29:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fowarding-to-syslog-best-practice/m-p/251975#M71645</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-03-01T20:29:44Z</dc:date>
    </item>
    <item>
      <title>Re: Fowarding to syslog- best practice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fowarding-to-syslog-best-practice/m-p/252037#M71662</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/17058"&gt;@fmurray&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp; mentioned this isn't something you could really make a best-practice on, as nobody has the same requirements. Personally, I like having all of the logs we can get into the SIEM and find it cheaper to just upgrade the device to function under the required load.&lt;/P&gt;&lt;P&gt;However, if your SIEM isn't able to handle that load you'll need to actually go through and determine the most important logs for your organization&amp;nbsp;that you want to forward to your SIEM. That could mean that you only forward traffic for external access rules, or maybe access to your server infrastructure. That all depends on what your organizational needs are. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Mar 2019 20:53:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fowarding-to-syslog-best-practice/m-p/252037#M71662</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-03-02T20:53:38Z</dc:date>
    </item>
    <item>
      <title>Re: Fowarding to syslog- best practice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fowarding-to-syslog-best-practice/m-p/252125#M71684</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/17058"&gt;@fmurray&lt;/a&gt;&amp;nbsp;, FYI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have just about everything going to syslog, including Global Protect.&amp;nbsp; this is our corp policy and to do with legal stuff.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have logrotate&amp;nbsp; that zips files up and deletes them after a required ammount of time.&lt;/P&gt;&lt;P&gt;the information is quite overwhelming but with various scripts you can pull out the information you require.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;very rarely use it for traffic reports but every month reports are run for GlobalProtect activity.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 12:30:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fowarding-to-syslog-best-practice/m-p/252125#M71684</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-03-04T12:30:40Z</dc:date>
    </item>
  </channel>
</rss>

