<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Syslog Issue. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11306#M8316</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The log forwarding and syslog profiles will need to be created in Panorama and then referenced in the Panorama pre/post-rule. This way all elements of the forwarding mechanism are managed inside Panorama.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In 4.0 you are able to reference the Panorama pushed log forwarding profile in a local device rule if needed. This way any change to the Panorama forwarding profile affects both shared pre/post-rules as well as the device rule.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 23 Sep 2011 15:43:20 GMT</pubDate>
    <dc:creator>mschuricht</dc:creator>
    <dc:date>2011-09-23T15:43:20Z</dc:date>
    <item>
      <title>Syslog Issue.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11303#M8313</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi - I may have not understood how this is achieved - so apologies before I start!&lt;/P&gt;&lt;P&gt;I'm trying to forward logs for traffic and threat to syslog We have 2x 4050s and Panorama - all policy rules are added via panorama.&lt;/P&gt;&lt;P&gt;I've created a "log forwarding profile" in Panorama that says - forward all traffic and threats to panorama. This is then added to each rule on Panorma. Both the log forwarding profile and the addition to the individual rules are pushed to both the firewalls fine and I get logs on the Panorama.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, I now want to set the traffic logs to forward to syslog as well. I go into Panorama and under the Panorama tab---&amp;gt;Server profiles-----&amp;gt; syslog.&amp;nbsp; I've created a syslog entry for my server. Still on Panorama I now go back to the "log forwardinng profile" I've already created and used and try and choose the syslog server I just created - it doesn't show on the drop down list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NB - if I go onto the FW itself I can create a syslog server and then a log forwarding profile and choose the syslog server fine. I guess I could apply that to local rules for a full test - but I don't have any local rules only rule generated from Panorama (and of course the rules generated from Panorama can't be changed locally).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I missing something?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Sep 2011 15:19:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11303#M8313</guid>
      <dc:creator>fmd</dc:creator>
      <dc:date>2011-09-22T15:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Issue.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11304#M8314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to forward your log to syslog servers as well you need to forward it from the PA box. Panorama cannot forward the log to syslog server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jones&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Sep 2011 16:13:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11304#M8314</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2011-09-22T16:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Issue.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11305#M8315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Thanks for your reply. I can forward system and config logs fine from the PA boxes (both syslog and forward to panorama). What I can't do is syslog traffic rules (ie rule logging). I can't do this from the PA box itself and the rules were created on Panorama (so are not editable on the PA box). I can't see a way of doinng it - but it must be possible - rules created on Panorama - having them log to syslog. Please help!! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Sep 2011 11:46:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11305#M8315</guid>
      <dc:creator>fmd</dc:creator>
      <dc:date>2011-09-23T11:46:28Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Issue.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11306#M8316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The log forwarding and syslog profiles will need to be created in Panorama and then referenced in the Panorama pre/post-rule. This way all elements of the forwarding mechanism are managed inside Panorama.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In 4.0 you are able to reference the Panorama pushed log forwarding profile in a local device rule if needed. This way any change to the Panorama forwarding profile affects both shared pre/post-rules as well as the device rule.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Sep 2011 15:43:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11306#M8316</guid>
      <dc:creator>mschuricht</dc:creator>
      <dc:date>2011-09-23T15:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Issue.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11307#M8317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi - thanks for your response. I understand what you're saying and it's what I have done. I've created the "log forwarder" and "syslog server" profiles in Panorama. However, the syslog server I've created in panorama doesn't display in the drop down list in the log forwarder I've created in Panorama. I can only use the syslog server I've created on Panorama for use in the "config" and "system" log settings - NOT the "log forwarder" - it just doesn't show up. I assume it's a bug?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Sep 2011 16:14:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11307#M8317</guid>
      <dc:creator>fmd</dc:creator>
      <dc:date>2011-09-23T16:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Issue.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11308#M8318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is a bug.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once you've got the profile for the syslog server entered, do this from the CLI:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;set panorama log-settings system critical send-syslog using-syslog-setting SYSLOG-PROFILE-NAME-GOES-HERE&lt;BR /&gt;set panorama log-settings system high send-syslog using-syslog-setting SYSLOG-PROFILE-NAME-GOES-HERE&lt;BR /&gt;set panorama log-settings system medium send-syslog using-syslog-setting SYSLOG-PROFILE-NAME-GOES-HERE&lt;BR /&gt;set panorama log-settings system low send-syslog using-syslog-setting SYSLOG-PROFILE-NAME-GOES-HERE&lt;BR /&gt;set panorama log-settings system informational send-syslog using-syslog-setting SYSLOG-PROFILE-NAME-GOES-HERE&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Sep 2011 18:57:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11308#M8318</guid>
      <dc:creator>MashRotor</dc:creator>
      <dc:date>2011-09-23T18:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Issue.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11309#M8319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was not able to reproduce the problem. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What Panorama version are you running?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Sep 2011 19:57:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11309#M8319</guid>
      <dc:creator>mschuricht</dc:creator>
      <dc:date>2011-09-23T19:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Issue.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11310#M8320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think you need to reply to &lt;A href="https://live.paloaltonetworks.com/people/farrel.doherty" id="jive-284128,568,264,064,046,334"&gt;farrel.doherty&lt;/A&gt;. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had the same problem with 4.0.3 which was confirmed by an onsite Palo Alto tech at the time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The solution was to plug in the syslog target via the CLI.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Sep 2011 20:08:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11310#M8320</guid>
      <dc:creator>MashRotor</dc:creator>
      <dc:date>2011-09-23T20:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Issue.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11311#M8321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for all your replies! I'll try the CLI option today. We're currently running version 4.0.5 on both Panorama and the 4050s.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Sep 2011 10:17:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11311#M8321</guid>
      <dc:creator>fmd</dc:creator>
      <dc:date>2011-09-28T10:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Issue.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11312#M8322</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi mstingley! Just realised that the CLI options you give aren't quite what I'm looking for. In 4.0.5 I can achieve what you needed to do in the CLI at 4.0.3. My issue is when editing the "Log Forwarding Profile" I can't reference the "syslog server profile" I've created. I can't see a way of doing this via the CLI either!&lt;/P&gt;&lt;P&gt;Anymore advice anyone? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Sep 2011 15:30:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11312#M8322</guid>
      <dc:creator>fmd</dc:creator>
      <dc:date>2011-09-28T15:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Issue.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11313#M8323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for all your replies. I've now worked out what the issue is. When creating the "syslog server profile" in Panorama - I had the location set as Panorama (not Shared). I assumed this would allow me to use the the profile on the policy rules as they were created in Panorama. it doesn't - I've re-created the syslog server and set it to Shared and I now see it referenced in the drop down list in the Log Forward Profile. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Sep 2011 15:53:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11313#M8323</guid>
      <dc:creator>fmd</dc:creator>
      <dc:date>2011-09-28T15:53:23Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Issue.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11314#M8324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you create an object with "Location = Panorama" it means the object should not be pushed to any Managed Device and to keep the object for use on Panorama only. Eg. Auth Profile for Panorama auth you do not want available for viewing or using on a Device.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Sep 2011 16:12:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/11314#M8324</guid>
      <dc:creator>mschuricht</dc:creator>
      <dc:date>2011-09-28T16:12:51Z</dc:date>
    </item>
  </channel>
</rss>

