<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data Lake status SNMP monitoring in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/data-lake-status-snmp-monitoring/m-p/306507#M79624</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/60153"&gt;@Jan_Linhart&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There's only a limited set op counters that you can monitor with SNMP ... I don't think that the cert is part of it but it's worth a look :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CllvCAC" target="_blank" rel="noopener"&gt;SNMP Counter Monitoring&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you see anything in the system logs about the expired certificate ? If so you could create a mail alert based on those logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Mon, 13 Jan 2020 15:36:52 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2020-01-13T15:36:52Z</dc:date>
    <item>
      <title>Data Lake status SNMP monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/data-lake-status-snmp-monitoring/m-p/306325#M79602</link>
      <description>&lt;P&gt;Hi everybody,&lt;/P&gt;
&lt;P&gt;we are quite often have a problem with logging to Data Lake.&lt;/P&gt;
&lt;P&gt;Mostly Data Lake certificate expires and is not being renew automatically, so logs are not being forwarded to Data Lake and XDR doesn't have info.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way, how to monitor certificate status, or dropped logs counters using snmp? (it is drop counter in command&amp;nbsp;debug log-receiver rawlog_fwd_trial stats global show). Or any other way, for example raising an alarm etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;Jan&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 19:33:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/data-lake-status-snmp-monitoring/m-p/306325#M79602</guid>
      <dc:creator>Jan_Linhart</dc:creator>
      <dc:date>2024-04-18T19:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: Data Lake status SNMP monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/data-lake-status-snmp-monitoring/m-p/306507#M79624</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/60153"&gt;@Jan_Linhart&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There's only a limited set op counters that you can monitor with SNMP ... I don't think that the cert is part of it but it's worth a look :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CllvCAC" target="_blank" rel="noopener"&gt;SNMP Counter Monitoring&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you see anything in the system logs about the expired certificate ? If so you could create a mail alert based on those logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 13 Jan 2020 15:36:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/data-lake-status-snmp-monitoring/m-p/306507#M79624</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-01-13T15:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: Data Lake status SNMP monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/data-lake-status-snmp-monitoring/m-p/306695#M79663</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;there are two ways, how to find out, that logs are not being sent to data lake (from the FW perspective)&lt;/P&gt;&lt;P&gt;1) check increasing drop counter for log forwarding (mentioned debug command)&lt;/P&gt;&lt;P&gt;2) check the reason - usualy expired certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no SNMP counter or log for the first one, so you have to do it manualy. You also cannot use API operational command call, because drop info is in debug command and there is no support for debug commands in API.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a workaround, I've configured API call for certificate status (request logging-service certificate info) and than I parse XML output and look for string specific string. It is cumbersome, but better than nothing. Hope, that Data Lake monitoring will be added any time soon.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Jan&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2020 19:22:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/data-lake-status-snmp-monitoring/m-p/306695#M79663</guid>
      <dc:creator>Jan_Linhart</dc:creator>
      <dc:date>2020-01-14T19:22:43Z</dc:date>
    </item>
  </channel>
</rss>

