<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Traffic logs filter on syslog in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-filter-on-syslog/m-p/319992#M81984</link>
    <description>&lt;P&gt;Hello team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are sending all the traffic logs to our inhouse syslog servers. So whatever traffic is matching current security policies, all such traffic logs are forwarded to syslog server. Now in those logs, i am seeing everything like Source, Destination, port everything. Now our requirement, we need to send only specific logs to syslog for specific traffic. e.g. dont want to disclose source IP. How can i configure this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pls suggest.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Apr 2020 13:31:06 GMT</pubDate>
    <dc:creator>johnde</dc:creator>
    <dc:date>2020-04-01T13:31:06Z</dc:date>
    <item>
      <title>Traffic logs filter on syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-filter-on-syslog/m-p/319992#M81984</link>
      <description>&lt;P&gt;Hello team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are sending all the traffic logs to our inhouse syslog servers. So whatever traffic is matching current security policies, all such traffic logs are forwarded to syslog server. Now in those logs, i am seeing everything like Source, Destination, port everything. Now our requirement, we need to send only specific logs to syslog for specific traffic. e.g. dont want to disclose source IP. How can i configure this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pls suggest.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 13:31:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-filter-on-syslog/m-p/319992#M81984</guid>
      <dc:creator>johnde</dc:creator>
      <dc:date>2020-04-01T13:31:06Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic logs filter on syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-filter-on-syslog/m-p/320005#M81989</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132841"&gt;@johnde&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think you are looking for FILTER BUILDER under&amp;nbsp; Log Forwarding Profiles. By default, it select 'All Logs' under Filter. But you can create custom filter as per your requirement. PFB snap for your ref. Once you create Filter, attach that Log Forwarding Profile to required security policies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Log-Filter.PNG" style="width: 350px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24832i6552D10A114DF751/image-dimensions/350x220/is-moderation-mode/true?v=v2" width="350" height="220" role="button" title="Log-Filter.PNG" alt="Log-Filter.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 13:50:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-filter-on-syslog/m-p/320005#M81989</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-04-01T13:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic logs filter on syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-filter-on-syslog/m-p/320010#M81990</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132841"&gt;@johnde&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt; mentions will work and is very granular.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to customize for your syslog-server you can also do this:&lt;/P&gt;
&lt;P&gt;Goto your syslog server profile on the Device tab. There's a Custom Log Format tab ... click the Traffic one :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2020-04-01_15-53-38.jpg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24833iE5A530C95AB13F6E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2020-04-01_15-53-38.jpg" alt="2020-04-01_15-53-38.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Add the field you want :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2020-04-01_15-55-46.jpg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24834i96057E2B856766C6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2020-04-01_15-55-46.jpg" alt="2020-04-01_15-55-46.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;Kiwi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 01 Apr 2020 14:00:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-filter-on-syslog/m-p/320010#M81990</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-04-01T14:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic logs filter on syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-filter-on-syslog/m-p/320021#M81994</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks Mayur, i will try it.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 15:05:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-filter-on-syslog/m-p/320021#M81994</guid>
      <dc:creator>johnde</dc:creator>
      <dc:date>2020-04-01T15:05:30Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic logs filter on syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-filter-on-syslog/m-p/320022#M81995</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;hey, thanks much! I will try this also.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will keep you posted.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 15:07:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-filter-on-syslog/m-p/320022#M81995</guid>
      <dc:creator>johnde</dc:creator>
      <dc:date>2020-04-01T15:07:38Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic logs filter on syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-filter-on-syslog/m-p/320051#M82003</link>
      <description>&lt;P&gt;Yes, this is very helpful when you have multiple syslog servers and you want to filter specific logs fields for specific syslog server only.&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;Thanks for sharing this too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 16:15:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-filter-on-syslog/m-p/320051#M82003</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-04-01T16:15:50Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic logs filter on syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-filter-on-syslog/m-p/320243#M82036</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for all your suggestions and inputs. I did try both the configurations and both works for me.&lt;/P&gt;&lt;P&gt;Appreciate your help!&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2020 10:35:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-filter-on-syslog/m-p/320243#M82036</guid>
      <dc:creator>johnde</dc:creator>
      <dc:date>2020-04-02T10:35:15Z</dc:date>
    </item>
  </channel>
</rss>

