<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Newbie in need of help: Forwarding traffic logs to a syslog server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/newbie-in-need-of-help-forwarding-traffic-logs-to-a-syslog/m-p/340775#M85500</link>
    <description>&lt;P&gt;Hi community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to forward all traffic and threat logs to a log collector.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand most of the process except the security policy part.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once I create a syslog server profile and then a log forwarding profile, I then need to use that log forwarding profile in my security policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our firewalls have many rules and my only instructions have been "please forward all traffic and threat logs to our log collector".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How best do I do this? Do I manually set the log forwarding profile of every rule to the one I created?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or do I create a new rule? If I create a new rule, what options do I set? Do I put both source and destination address as "any"? everything else as any?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry about sounding confused but I appreciate any help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Mon, 27 Jul 2020 05:42:12 GMT</pubDate>
    <dc:creator>damom10</dc:creator>
    <dc:date>2020-07-27T05:42:12Z</dc:date>
    <item>
      <title>Newbie in need of help: Forwarding traffic logs to a syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/newbie-in-need-of-help-forwarding-traffic-logs-to-a-syslog/m-p/340775#M85500</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to forward all traffic and threat logs to a log collector.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand most of the process except the security policy part.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once I create a syslog server profile and then a log forwarding profile, I then need to use that log forwarding profile in my security policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our firewalls have many rules and my only instructions have been "please forward all traffic and threat logs to our log collector".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How best do I do this? Do I manually set the log forwarding profile of every rule to the one I created?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or do I create a new rule? If I create a new rule, what options do I set? Do I put both source and destination address as "any"? everything else as any?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry about sounding confused but I appreciate any help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 05:42:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/newbie-in-need-of-help-forwarding-traffic-logs-to-a-syslog/m-p/340775#M85500</guid>
      <dc:creator>damom10</dc:creator>
      <dc:date>2020-07-27T05:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie in need of help: Forwarding traffic logs to a syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/newbie-in-need-of-help-forwarding-traffic-logs-to-a-syslog/m-p/340820#M85511</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/150298"&gt;@damom10&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You'll need to add the profile to all your existing rules.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;DO NOT create an ANY ANY ANY rule unless you want to open all the gates &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; !!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check out the following discussion that talks about this exact topic.&amp;nbsp; It might give you some ideas on how to best approach this :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-profile-in-all-security-policies/td-p/205426" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-profile-in-all-security-policies/td-p/205426&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 11:46:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/newbie-in-need-of-help-forwarding-traffic-logs-to-a-syslog/m-p/340820#M85511</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-07-27T11:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie in need of help: Forwarding traffic logs to a syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/newbie-in-need-of-help-forwarding-traffic-logs-to-a-syslog/m-p/341138#M85602</link>
      <description>&lt;P&gt;Thank you Kiwi, great information!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You have helped me immensely.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 23:07:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/newbie-in-need-of-help-forwarding-traffic-logs-to-a-syslog/m-p/341138#M85602</guid>
      <dc:creator>damom10</dc:creator>
      <dc:date>2020-07-28T23:07:46Z</dc:date>
    </item>
  </channel>
</rss>

