<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Syslog - LFP options in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-lfp-options/m-p/349138#M86803</link>
    <description>&lt;P&gt;here is a quick screen capture&lt;/P&gt;
&lt;P&gt;I hit the dropdown arrow, and the choices are there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SteveCantwell_1-1600093611787.png" style="width: 480px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27753i6293874551574229/image-dimensions/480x199?v=v2" width="480" height="199" role="button" title="SteveCantwell_1-1600093611787.png" alt="SteveCantwell_1-1600093611787.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 14 Sep 2020 14:27:09 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2020-09-14T14:27:09Z</dc:date>
    <item>
      <title>Syslog - LFP options</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-lfp-options/m-p/349042#M86789</link>
      <description>&lt;P&gt;Hi Guys&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have PA with version 9.0.4 and have to configure Syslog server log forwarding on the same. Created (syslog) server profile..Now creating "Log Forwarding Profile" there are options "forward method" and "built-in-action" available there. which is not giving so much clarity what need to be configure there, Referred few articles available on Internet but no-one giving much clarity for the configuration side.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Requesting suggestion for further configuration.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 12:16:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-lfp-options/m-p/349042#M86789</guid>
      <dc:creator>Jimmy20</dc:creator>
      <dc:date>2020-09-14T12:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog - LFP options</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-lfp-options/m-p/349057#M86792</link>
      <description>&lt;P&gt;Good Day&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will be using the forward portion of the Log Forwarding Profile.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/configure-log-forwarding.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/configure-log-forwarding.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Essentially&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Create the profile.&lt;/P&gt;
&lt;P&gt;Add in what notifications you want (Threat logs... ok... ALL logs?... log geq medium? ok.)&lt;/P&gt;
&lt;P&gt;Where do you want these log messages to be fwd to?&amp;nbsp; SNMP, email, syslog, Panorama. ok... good&lt;/P&gt;
&lt;P&gt;Next, modify your security policy and apply the log forward profile to whatever rules you want to be, well, log forwarded to.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me know how else I can assist.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 12:54:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-lfp-options/m-p/349057#M86792</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2020-09-14T12:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog - LFP options</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-lfp-options/m-p/349066#M86794</link>
      <description>&lt;P&gt;Hi Steve,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What if we configure, as found some more ways probably (except Log Forwarding Profile)&lt;/P&gt;&lt;P&gt;1-&amp;nbsp; Configure Syslog Server Profile&lt;/P&gt;&lt;P&gt;2- Device - Log Setting - System -&amp;gt; call Syslog Server created in profile -&amp;gt; Filter logs as per levels Critial , High, informational, Low, Medium.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once configure, commit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is'nt also the correct way ..?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 13:22:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-lfp-options/m-p/349066#M86794</guid>
      <dc:creator>Jimmy20</dc:creator>
      <dc:date>2020-09-14T13:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog - LFP options</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-lfp-options/m-p/349074#M86796</link>
      <description>&lt;P&gt;Well, that will work only if there are SYSTEM logs that match the various levels.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But if a CRITICAL malware or vulnerability came through the FW, this would NOT show up as a SYSTEM log message, and would not be forwarded.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the concern is about SYSTEM logs.. that is fine.. but you are missing out on 99% of the threat notifications on the FW.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this what you are intending?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 13:44:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-lfp-options/m-p/349074#M86796</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2020-09-14T13:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog - LFP options</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-lfp-options/m-p/349077#M86798</link>
      <description>&lt;P&gt;Hi Steve,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for Quick and instant responses.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Well, We need to check with client what they are actually intending. if they are OK with system logs then we are almost done as you rightly said with "Log setting" options.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But if they want Threat and other related logs to be available on Syslog then have to go for "LFP" option.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One more point at this moment : Where do we get option to set log levels (&lt;SPAN&gt;Critial , High, informational, Low, Medium) under Log Forwarding profile option. I can't find these anywhere there...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 13:50:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-lfp-options/m-p/349077#M86798</guid>
      <dc:creator>Jimmy20</dc:creator>
      <dc:date>2020-09-14T13:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog - LFP options</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-lfp-options/m-p/349138#M86803</link>
      <description>&lt;P&gt;here is a quick screen capture&lt;/P&gt;
&lt;P&gt;I hit the dropdown arrow, and the choices are there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SteveCantwell_1-1600093611787.png" style="width: 480px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27753i6293874551574229/image-dimensions/480x199?v=v2" width="480" height="199" role="button" title="SteveCantwell_1-1600093611787.png" alt="SteveCantwell_1-1600093611787.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 14:27:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-lfp-options/m-p/349138#M86803</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2020-09-14T14:27:09Z</dc:date>
    </item>
  </channel>
</rss>

