<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: collecting  palo alto firewall logs with Graylog 2.5 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/collecting-palo-alto-firewall-logs-with-graylog-2-5/m-p/260910#M73964</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Make sure all the filter options are set to syslog.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTrCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTrCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Tue, 14 May 2019 13:45:53 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2019-05-14T13:45:53Z</dc:date>
    <item>
      <title>collecting  palo alto firewall logs with Graylog 2.5</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/collecting-palo-alto-firewall-logs-with-graylog-2-5/m-p/260822#M73934</link>
      <description>&lt;P&gt;Dear&amp;nbsp;palo alto community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I collect the palo alto firewall logs with Graylog 2.5.&lt;/P&gt;&lt;P&gt;When i make an ssh connection to the fw palo alto with an incorrect password, this ssh connection does not get into the logs on Graylog interface web why ? To configure the syslog profile I followed this link&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFfCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFfCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 21:15:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/collecting-palo-alto-firewall-logs-with-graylog-2-5/m-p/260822#M73934</guid>
      <dc:creator>Ayoub2</dc:creator>
      <dc:date>2019-05-13T21:15:14Z</dc:date>
    </item>
    <item>
      <title>Re: collecting  palo alto firewall logs with Graylog 2.5</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/collecting-palo-alto-firewall-logs-with-graylog-2-5/m-p/260844#M73936</link>
      <description>&lt;P&gt;Just tested my setup and was able to see failed SSH attempts.&lt;/P&gt;&lt;P&gt;What version of PAN-OS are you running?&amp;nbsp; I'm on 8.0, has been working since 7.0.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have a log forwarder setup for my syslog profile at all and I only receieve System messages.&amp;nbsp; Try deleting your log forwarder.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 21:41:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/collecting-palo-alto-firewall-logs-with-graylog-2-5/m-p/260844#M73936</guid>
      <dc:creator>ebonjour</dc:creator>
      <dc:date>2019-05-13T21:41:14Z</dc:date>
    </item>
    <item>
      <title>Re: collecting  palo alto firewall logs with Graylog 2.5</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/collecting-palo-alto-firewall-logs-with-graylog-2-5/m-p/260845#M73937</link>
      <description>&lt;P&gt;Found out why I don't have a log forwarder for syslog, its not the right place for system messages!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Device -&amp;gt; Log Settings, you should see at the top System.&amp;nbsp; You need to configure the system-"level" alerts to output to your syslog profile.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 21:50:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/collecting-palo-alto-firewall-logs-with-graylog-2-5/m-p/260845#M73937</guid>
      <dc:creator>ebonjour</dc:creator>
      <dc:date>2019-05-13T21:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: collecting  palo alto firewall logs with Graylog 2.5</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/collecting-palo-alto-firewall-logs-with-graylog-2-5/m-p/260846#M73938</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Also check you log profile settings to make sure its getting sent to the syslog server.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 21:50:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/collecting-palo-alto-firewall-logs-with-graylog-2-5/m-p/260846#M73938</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-05-13T21:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: collecting  palo alto firewall logs with Graylog 2.5</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/collecting-palo-alto-firewall-logs-with-graylog-2-5/m-p/260852#M73944</link>
      <description>&lt;P&gt;thanks for your reply, pan os palo 8.0.9&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 22:10:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/collecting-palo-alto-firewall-logs-with-graylog-2-5/m-p/260852#M73944</guid>
      <dc:creator>Ayoub2</dc:creator>
      <dc:date>2019-05-13T22:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: collecting  palo alto firewall logs with Graylog 2.5</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/collecting-palo-alto-firewall-logs-with-graylog-2-5/m-p/260853#M73945</link>
      <description>&lt;P&gt;I Create a syslog server profile in FW palo and I configured it,&amp;nbsp;I received the logs as examples of rules configured under the firewall&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113438"&gt;@Ayoub2&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;thanks for your reply, pan os palo 8.0.9&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 22:16:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/collecting-palo-alto-firewall-logs-with-graylog-2-5/m-p/260853#M73945</guid>
      <dc:creator>Ayoub2</dc:creator>
      <dc:date>2019-05-13T22:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: collecting  palo alto firewall logs with Graylog 2.5</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/collecting-palo-alto-firewall-logs-with-graylog-2-5/m-p/260854#M73946</link>
      <description>&lt;P&gt;Please,&amp;nbsp;I want to know exactly, how I configure my syslog profile on the palo alto firewall, to have logs ssh login attempts failed on the web interface of my log management "Graylog"&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 22:19:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/collecting-palo-alto-firewall-logs-with-graylog-2-5/m-p/260854#M73946</guid>
      <dc:creator>Ayoub2</dc:creator>
      <dc:date>2019-05-13T22:19:04Z</dc:date>
    </item>
    <item>
      <title>Re: collecting  palo alto firewall logs with Graylog 2.5</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/collecting-palo-alto-firewall-logs-with-graylog-2-5/m-p/260910#M73964</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Make sure all the filter options are set to syslog.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTrCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTrCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 13:45:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/collecting-palo-alto-firewall-logs-with-graylog-2-5/m-p/260910#M73964</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-05-14T13:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: collecting  palo alto firewall logs with Graylog 2.5</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/collecting-palo-alto-firewall-logs-with-graylog-2-5/m-p/260937#M73972</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thank you for your attention to this matter.&amp;nbsp;I'll check.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Ayoub Labidi&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 16:03:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/collecting-palo-alto-firewall-logs-with-graylog-2-5/m-p/260937#M73972</guid>
      <dc:creator>Ayoub2</dc:creator>
      <dc:date>2019-05-14T16:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: collecting  palo alto firewall logs with Graylog 2.5</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/collecting-palo-alto-firewall-logs-with-graylog-2-5/m-p/261098#M74011</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’m sorry for bothering you ,the problem still persists, I can't receive the logs of ssh failed from FW palo, I get except the rules logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Best regards,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Ayoub Labidi&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 10:35:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/collecting-palo-alto-firewall-logs-with-graylog-2-5/m-p/261098#M74011</guid>
      <dc:creator>Ayoub2</dc:creator>
      <dc:date>2019-05-15T10:35:34Z</dc:date>
    </item>
  </channel>
</rss>

