<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Threat log forwarding from unlicensed PA device? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/threat-log-forwarding-from-unlicensed-pa-device/m-p/271911#M74871</link>
    <description>&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;I believe I know the answer, but wanting to make sure I understand.&amp;nbsp; I am configuring log forwarding to a Varonis server for testing.&amp;nbsp; I've been sending the traffic log, but Varonis will only process the Threat log.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've configured the Threat in the Log forwarding profile, Vulnerability profie, etc and assigned it to my security rule, but my threat log is empty in general.&amp;nbsp; I assuming this is because my device is unlicensed?&amp;nbsp; Pa200 7.1.15.&amp;nbsp; I guess I was hoping that something (anything) would go through.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just checking if there are comments before I give up for now.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pasyslog.jpg" style="width: 801px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20456i6CD79259B6F717FF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pasyslog.jpg" alt="pasyslog.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Jun 2019 21:12:52 GMT</pubDate>
    <dc:creator>OMatlock</dc:creator>
    <dc:date>2019-06-20T21:12:52Z</dc:date>
    <item>
      <title>Threat log forwarding from unlicensed PA device?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-log-forwarding-from-unlicensed-pa-device/m-p/271911#M74871</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;I believe I know the answer, but wanting to make sure I understand.&amp;nbsp; I am configuring log forwarding to a Varonis server for testing.&amp;nbsp; I've been sending the traffic log, but Varonis will only process the Threat log.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've configured the Threat in the Log forwarding profile, Vulnerability profie, etc and assigned it to my security rule, but my threat log is empty in general.&amp;nbsp; I assuming this is because my device is unlicensed?&amp;nbsp; Pa200 7.1.15.&amp;nbsp; I guess I was hoping that something (anything) would go through.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just checking if there are comments before I give up for now.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pasyslog.jpg" style="width: 801px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20456i6CD79259B6F717FF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pasyslog.jpg" alt="pasyslog.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 21:12:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-log-forwarding-from-unlicensed-pa-device/m-p/271911#M74871</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2019-06-20T21:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: Threat log forwarding from unlicensed PA device?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-log-forwarding-from-unlicensed-pa-device/m-p/271918#M74872</link>
      <description>&lt;P&gt;Agreed that without a license, you will not get the AV/Spyware/Vuln signature to match.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could test with enabling Zone Protection Profile and DoS Protection Policies and force an attempted ping flood attack or port scan, or whatever... something that would "hit" as a threat in the logs, but does not require a licensed feature from PANW.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 21:17:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-log-forwarding-from-unlicensed-pa-device/m-p/271918#M74872</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-06-20T21:17:16Z</dc:date>
    </item>
    <item>
      <title>Re: Threat log forwarding from unlicensed PA device?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-log-forwarding-from-unlicensed-pa-device/m-p/271974#M74875</link>
      <description>&lt;P&gt;I think you can forward the threat logs&amp;nbsp; without having the threat license.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 04:54:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-log-forwarding-from-unlicensed-pa-device/m-p/271974#M74875</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-06-21T04:54:39Z</dc:date>
    </item>
    <item>
      <title>Re: Threat log forwarding from unlicensed PA device?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-log-forwarding-from-unlicensed-pa-device/m-p/272009#M74879</link>
      <description>&lt;P&gt;Without a licence there are no threats to forward.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 07:32:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-log-forwarding-from-unlicensed-pa-device/m-p/272009#M74879</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2019-06-21T07:32:09Z</dc:date>
    </item>
  </channel>
</rss>

