<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Logging Discarded Traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/logging-discarded-traffic/m-p/321607#M82304</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I had recently had an issue where I had to move a syslog server behind a cluster of PA-5250.&lt;/P&gt;&lt;P&gt;This syslog server receives logs from different equipements (~ 100GBytes per day) so there is an enormous amount of udp syslog events received by this server.&lt;/P&gt;&lt;P&gt;When the server was behind this cluster, I was not receiving any logs. After some troubleshooting, I found out that the flow was in the "DISCARDED" state in CLI, but there was not any logs that did capture this event. Moreover I did some packet capture and these flows did not appear in the "receiving" state !&lt;/P&gt;&lt;P&gt;I cleared this flow and put an Dos protection rule to permit this type of traffic, but is there a way to log when trafic is in DISCARDED state ? That would help me during future troubleshooting sessions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Wed, 08 Apr 2020 15:50:20 GMT</pubDate>
    <dc:creator>Nico-UBX</dc:creator>
    <dc:date>2020-04-08T15:50:20Z</dc:date>
    <item>
      <title>Logging Discarded Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logging-discarded-traffic/m-p/321607#M82304</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I had recently had an issue where I had to move a syslog server behind a cluster of PA-5250.&lt;/P&gt;&lt;P&gt;This syslog server receives logs from different equipements (~ 100GBytes per day) so there is an enormous amount of udp syslog events received by this server.&lt;/P&gt;&lt;P&gt;When the server was behind this cluster, I was not receiving any logs. After some troubleshooting, I found out that the flow was in the "DISCARDED" state in CLI, but there was not any logs that did capture this event. Moreover I did some packet capture and these flows did not appear in the "receiving" state !&lt;/P&gt;&lt;P&gt;I cleared this flow and put an Dos protection rule to permit this type of traffic, but is there a way to log when trafic is in DISCARDED state ? That would help me during future troubleshooting sessions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2020 15:50:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logging-discarded-traffic/m-p/321607#M82304</guid>
      <dc:creator>Nico-UBX</dc:creator>
      <dc:date>2020-04-08T15:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: Logging Discarded Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logging-discarded-traffic/m-p/321681#M82317</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/137853"&gt;@Nico-UBX&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I don't believe this is anything that is built-in at the moment. You would need to utilize the API to actively pull what sessions are in a discarded state and log them separately and do any alerting you may want to.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2020 17:48:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logging-discarded-traffic/m-p/321681#M82317</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-04-08T17:48:13Z</dc:date>
    </item>
    <item>
      <title>Re: Logging Discarded Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logging-discarded-traffic/m-p/321843#M82342</link>
      <description>&lt;P&gt;Thank you for your answer. I was hoping that this was possible, but well I will do with that.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2020 10:22:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logging-discarded-traffic/m-p/321843#M82342</guid>
      <dc:creator>Nico-UBX</dc:creator>
      <dc:date>2020-04-09T10:22:22Z</dc:date>
    </item>
  </channel>
</rss>

