<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Collect syslog information in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/collect-syslog-information/m-p/261539#M74147</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This article will probably help in your situation. It is actually written for panorama sozing but the steps you need to take for a proper panorama sizing can be applied also to a syslog server:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/set-up-panorama/determine-panorama-log-storage-requirements.html" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/set-up-panorama/determine-panorama-log-storage-requirements.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 17 May 2019 19:59:24 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2019-05-17T19:59:24Z</dc:date>
    <item>
      <title>Collect syslog information</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/collect-syslog-information/m-p/261457#M74125</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are going to add a new syslog server in PA config. So we would like to do a bit audit about PA supporting syslog sessions.&lt;/P&gt;&lt;P&gt;What si the best way to know:&lt;/P&gt;&lt;P&gt;-Volume of traffic per day for syslog&lt;/P&gt;&lt;P&gt;-Top10 destination syslogs&lt;/P&gt;&lt;P&gt;-.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 08:33:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/collect-syslog-information/m-p/261457#M74125</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2019-05-17T08:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: Collect syslog information</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/collect-syslog-information/m-p/261521#M74139</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;As for syslogs per day. That depends on your environment. Like for us, its in the 10's of millions. I would work with your SIEM vendor and get a demo license first and see what the ingest rate is of all the logs you wish to capture. At that point you can determine what the actual scale would be.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 15:59:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/collect-syslog-information/m-p/261521#M74139</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-05-17T15:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: Collect syslog information</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/collect-syslog-information/m-p/261539#M74147</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This article will probably help in your situation. It is actually written for panorama sozing but the steps you need to take for a proper panorama sizing can be applied also to a syslog server:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/set-up-panorama/determine-panorama-log-storage-requirements.html" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/set-up-panorama/determine-panorama-log-storage-requirements.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 19:59:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/collect-syslog-information/m-p/261539#M74147</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-05-17T19:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: Collect syslog information</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/collect-syslog-information/m-p/261552#M74152</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;, the vast majority of SIEMs will be happy to supply you with an unlimited trial license for a few weeks so you can configure it exactly how you want and have legitimate numbers for how many logs you'll actually pass. Just be mindful of the pricing model of the SIEM when you are deciding what you actually want to send to it and if it'll actually be useful. When you get to something like Splunk pricing alone can determine what you are actually passing off of the box.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 21:20:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/collect-syslog-information/m-p/261552#M74152</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-05-17T21:20:57Z</dc:date>
    </item>
  </channel>
</rss>

