<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log Forwarding Rule/Object in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-rule-object/m-p/352269#M87160</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Perhaps can be done from a SIEM? However how about adding a schedule to the policy, i.e. its only accessible from point A to point B between the hours of X to Z?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just a thought&lt;/P&gt;</description>
    <pubDate>Fri, 25 Sep 2020 20:11:01 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2020-09-25T20:11:01Z</dc:date>
    <item>
      <title>Log Forwarding Rule/Object</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-rule-object/m-p/351864#M87106</link>
      <description>&lt;P&gt;I have a server that connects every 10 minutes to an SFTP server.&amp;nbsp; I would ideally like to know when it is done for the day.&amp;nbsp; So I setup an email server profile and started on a Log Forwarding object.&amp;nbsp; It does not really have to be a log, just and email that says "Oi the server is done for the day".&amp;nbsp; The server connecting is a third party so I can't do it from that side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to create an object that will be "actioned" once there is no connection from the filtered server after a set amount of time?&amp;nbsp; So say after 10 minutes if no additional connections are being received.&amp;nbsp; I say additional connections as I am not interested in an email every 10 minutes stating there are no connections.&amp;nbsp; I am also not really interested in when they start either as they start during my sleepy time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much for helping a Palo Alto noob.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 17:20:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-rule-object/m-p/351864#M87106</guid>
      <dc:creator>DIR_IT</dc:creator>
      <dc:date>2020-09-24T17:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: Log Forwarding Rule/Object</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-rule-object/m-p/352035#M87124</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/152284"&gt;@DIR_IT&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;This isn't really going to work.&amp;nbsp;&lt;EM&gt;If&lt;/EM&gt; the sessions happen long enough to stay active you could setup a log-forwarding profile to alert you on session-end, but the fact that these are ten minutes apart means that likely isn't going to be the case. You could of course set something up with the API and checking the session table.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 03:22:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-rule-object/m-p/352035#M87124</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-09-25T03:22:00Z</dc:date>
    </item>
    <item>
      <title>Re: Log Forwarding Rule/Object</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-rule-object/m-p/352269#M87160</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Perhaps can be done from a SIEM? However how about adding a schedule to the policy, i.e. its only accessible from point A to point B between the hours of X to Z?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just a thought&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 20:11:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-rule-object/m-p/352269#M87160</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-09-25T20:11:01Z</dc:date>
    </item>
  </channel>
</rss>

