<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help needed with pruning ikemgr.log outputs to show only interesting traffic log entries in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/help-needed-with-pruning-ikemgr-log-outputs-to-show-only/m-p/313752#M80978</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/134409"&gt;@James_Cook&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;There isn't a good way to export that file if this is something that you are doing on a daily basis, also I can't fathom why someone would need to do this on a daily basis.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can't simply export&amp;nbsp;&lt;EM&gt;just&lt;/EM&gt; this file, but it is included in a technical support file dump; so if you generate a tech-support file you'll be able to export that off of the firewall and then it will contain the ikemgr.log where you can filter it how you like.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Personally I would simply stick to less and build a proper search for what you are looking for. So in the example that you gave you wouldn't actually want to use&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;/&lt;A href="http://www.xxx.yyy.zzz" target="_blank"&gt;www.xxx.yyy.zzz&lt;/A&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;but utilize the search&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;/www[.]xxx[.]yyy[.]zzz&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;instead. Then hit enter to activate the search and you can use 'n' to go to the next result. Maybe that will help make searching through the log in the CLI a bit more usable for you.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 01 Mar 2020 05:26:12 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2020-03-01T05:26:12Z</dc:date>
    <item>
      <title>Help needed with pruning ikemgr.log outputs to show only interesting traffic log entries</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-needed-with-pruning-ikemgr-log-outputs-to-show-only/m-p/313371#M80928</link>
      <description>&lt;P&gt;On Palo Alto CLI the only way I know of to see the logs of VPN tunnel Phase I errors etc is this command from inside the vsys via CLI where the VPN tunnel is built:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;less mp-log ikemgr.log&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Are there commands for CLI where I can show just outputs for ONLY certain tunnel information that I'm seeking from the above log command? I've tried stuff like:&lt;/P&gt;&lt;P&gt;less mp-log ikemgr.log | grep &lt;A href="http://www.xxx.yyy.zzz" target="_blank"&gt;www.xxx.yyy.zzz&lt;/A&gt;&amp;nbsp; (Peer IP address)&lt;/P&gt;&lt;P&gt;it returns with 'invalid syntax'&lt;/P&gt;&lt;P&gt;2) Can the entire ikemgr.log be exported?&amp;nbsp; That way I could pull the entire log and then search it for the interesting traffic I'm looking for.&amp;nbsp; But I need the commands for that too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am able to see some of the related traffic I want by running the command that's listed above to show the ikemgr log, and then putting in /&lt;A href="http://www.xxx.yyy.zzz" target="_blank"&gt;www.xxx.yyy.zzz&lt;/A&gt; after the first page of log results are shown.&amp;nbsp; But that's not exactly what I'm needing.&amp;nbsp; The log file is gigantic and even just going through a single day of the entire log is not possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help/guidance/suggestions is all appreciated.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2020 20:06:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-needed-with-pruning-ikemgr-log-outputs-to-show-only/m-p/313371#M80928</guid>
      <dc:creator>James_Cook</dc:creator>
      <dc:date>2020-02-27T20:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: Help needed with pruning ikemgr.log outputs to show only interesting traffic log entries</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-needed-with-pruning-ikemgr-log-outputs-to-show-only/m-p/313752#M80978</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/134409"&gt;@James_Cook&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;There isn't a good way to export that file if this is something that you are doing on a daily basis, also I can't fathom why someone would need to do this on a daily basis.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can't simply export&amp;nbsp;&lt;EM&gt;just&lt;/EM&gt; this file, but it is included in a technical support file dump; so if you generate a tech-support file you'll be able to export that off of the firewall and then it will contain the ikemgr.log where you can filter it how you like.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Personally I would simply stick to less and build a proper search for what you are looking for. So in the example that you gave you wouldn't actually want to use&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;/&lt;A href="http://www.xxx.yyy.zzz" target="_blank"&gt;www.xxx.yyy.zzz&lt;/A&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;but utilize the search&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;/www[.]xxx[.]yyy[.]zzz&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;instead. Then hit enter to activate the search and you can use 'n' to go to the next result. Maybe that will help make searching through the log in the CLI a bit more usable for you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Mar 2020 05:26:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-needed-with-pruning-ikemgr-log-outputs-to-show-only/m-p/313752#M80978</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-03-01T05:26:12Z</dc:date>
    </item>
  </channel>
</rss>

