<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reading firewall palo A20 logs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/reading-firewall-palo-a20-logs/m-p/262068#M74263</link>
    <description>You will want to compare the logs you receive to the actual logs on the firewalls, they'll make much more sense to you then&lt;BR /&gt;&lt;BR /&gt;Afaik lvl6 is informational, facility is configured in the log forwarding profile, subtype is the subtype (url threat traffic wildfire,...) repeat count is the nu ber of tines an identical log was counted in a short timeframe</description>
    <pubDate>Thu, 23 May 2019 14:41:23 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2019-05-23T14:41:23Z</dc:date>
    <item>
      <title>Reading firewall palo A20 logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reading-firewall-palo-a20-logs/m-p/261924#M74231</link>
      <description>&lt;P&gt;Hello Paloalto community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I ask for help please,&amp;nbsp;I collect the logs of a&amp;nbsp;Firewall palo lato A20&amp;nbsp; with graylog, I find a difficulty in reading Firewall logs. Can anyone help me&amp;nbsp;to explain this logs,&amp;nbsp;I want a clear interpretation of this logs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;On the web interface of Graylog I see this logs from&amp;nbsp;FW Palo alto:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;1/ All the logs of the FW palo&amp;nbsp; are "level6",&amp;nbsp;what does mean "level 6" ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2/ Facility ( local 0, local 6, user-level) ???&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3/ log_subtype, url_category ( any) ? , " session_flags =" 0x1b", " 0x10001c " ", ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;4/ repeat_cout=1 , time generated ???&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;Please I want a clear interpretation&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="F LOGS.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20132i8FD4365BD31E2F3D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="F LOGS.PNG" alt="F LOGS.PNG" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks ,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;AYOUB LABIDI&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 14:08:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reading-firewall-palo-a20-logs/m-p/261924#M74231</guid>
      <dc:creator>Ayoub2</dc:creator>
      <dc:date>2019-05-22T14:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: Reading firewall palo A20 logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reading-firewall-palo-a20-logs/m-p/262068#M74263</link>
      <description>You will want to compare the logs you receive to the actual logs on the firewalls, they'll make much more sense to you then&lt;BR /&gt;&lt;BR /&gt;Afaik lvl6 is informational, facility is configured in the log forwarding profile, subtype is the subtype (url threat traffic wildfire,...) repeat count is the nu ber of tines an identical log was counted in a short timeframe</description>
      <pubDate>Thu, 23 May 2019 14:41:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reading-firewall-palo-a20-logs/m-p/262068#M74263</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-05-23T14:41:23Z</dc:date>
    </item>
  </channel>
</rss>

