<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PAN Next Generation Firewall 3020 can't Forward Logs Properly to External Syslog Server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pan-next-generation-firewall-3020-can-t-forward-logs-properly-to/m-p/272436#M74921</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have found out the problem. It was that the service route was not configured properly and so the logs we not sent via the correct IP/Port. Thank you for your help!&lt;/P&gt;</description>
    <pubDate>Sun, 23 Jun 2019 05:41:58 GMT</pubDate>
    <dc:creator>NutellaPie</dc:creator>
    <dc:date>2019-06-23T05:41:58Z</dc:date>
    <item>
      <title>PAN Next Generation Firewall 3020 can't Forward Logs Properly to External Syslog Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-next-generation-firewall-3020-can-t-forward-logs-properly-to/m-p/272418#M74916</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to forward all logs from PAN Firewall 3020 to an external Syslog server. I have followed the guide&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-admin/monitoring/configure-log-forwarding.html#20823" target="_self"&gt;here&lt;/A&gt;&amp;nbsp;and have tried to debug the problem by accessing the firewall through CLI but to no avail. However, I think I might have noticed an error from debugging.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By running this line of code, I get the following results:&lt;/P&gt;&lt;PRE&gt;debug log-receiver statistics&lt;/PRE&gt;&lt;PRE&gt;Logging statistics
------------------------------ -----------
Log incoming rate:             1/sec
Log written rate:              1/sec
Corrupted packets:             0
Corrupted URL packets:         0
Corrupted HTTP HDR packets:    0
Logs discarded (queue full):   0
Traffic logs written:          2168177
URL logs written:              0
Wildfire logs written:         0
Anti-virus logs written:       0
Widfire Anti-virus logs written: 0
Spyware logs written:          0
Attack logs written:           0
Vulnerability logs written:    0
Fileext logs written:          0
URL cache age out count:       0
URL cache full count:          0
URL cache key exist count:     0
URL cache wrt incomplete http hdrs count: 0
URL cache rcv http hdr before url count: 0
URL cache full drop count(url log not received): 0
URL cache age out drop count(url log not received): 0
Traffic alarms dropped due to sysd write failures: 0
Traffic alarms dropped due to global rate limiting: 0
Traffic alarms dropped due to each source rate limiting: 0
Traffic alarms generated count:  0
Log Forward count:             0
Log Forward discarded (queue full) count: 0
Log Forward discarded (send error) count: 0

Summary Statistics:
Num current drop entries in trsum:0
Num cumulative drop entries in trsum:0
Num current drop entries in thsum:0
Num cumulative drop entries in thsum:0

External Forwarding stats:
      Type  Enqueue Count     Send Count     Drop Count    Queue Depth     Send Rate(last 1min)
    syslog          58338          58338              0              0                        0
      snmp              0              0              0              0                        0
     email              0              0              0              0                        0
       raw              0              0              0              0                        0&lt;/PRE&gt;&lt;P&gt;I noticed that the send rate is 0 but the enqueue and send count is quite high, but I can't seem to find any logs that state the reason why it is not being sent to my external syslog server. Could anyone help me with this issue please? Thank you!&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jun 2019 19:05:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-next-generation-firewall-3020-can-t-forward-logs-properly-to/m-p/272418#M74916</guid>
      <dc:creator>NutellaPie</dc:creator>
      <dc:date>2019-06-22T19:05:36Z</dc:date>
    </item>
    <item>
      <title>Re: PAN Next Generation Firewall 3020 can't Forward Logs Properly to External Syslog Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-next-generation-firewall-3020-can-t-forward-logs-properly-to/m-p/272426#M74918</link>
      <description>&lt;P&gt;give us output of show logging status&lt;/P&gt;&lt;P&gt;is correect log forwarding profile applied to security rules?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you see traffic logs in the monitar tab?&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jun 2019 19:41:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-next-generation-firewall-3020-can-t-forward-logs-properly-to/m-p/272426#M74918</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-06-22T19:41:57Z</dc:date>
    </item>
    <item>
      <title>Re: PAN Next Generation Firewall 3020 can't Forward Logs Properly to External Syslog Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-next-generation-firewall-3020-can-t-forward-logs-properly-to/m-p/272436#M74921</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have found out the problem. It was that the service route was not configured properly and so the logs we not sent via the correct IP/Port. Thank you for your help!&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jun 2019 05:41:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-next-generation-firewall-3020-can-t-forward-logs-properly-to/m-p/272436#M74921</guid>
      <dc:creator>NutellaPie</dc:creator>
      <dc:date>2019-06-23T05:41:58Z</dc:date>
    </item>
  </channel>
</rss>

