<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Decryption Log Forwarding in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-log-forwarding/m-p/424546#M94264</link>
    <description>&lt;P&gt;Thanks BPry for confirming that.&amp;nbsp; I keep notices *.stretchoid.com traffic probing my VPN.&amp;nbsp; Forwarding the decrypt errors are one way to review that to potentially add their ipaddresses to a blocklist.&amp;nbsp; I also have had an issue twice where the firewall rejected valid certificates until a reboot.&amp;nbsp; I want to be alerted about that as well particularly if the upgrade to 10.0.6 did not solve that issue.&amp;nbsp; It's too early for me to definitively tell because I had that issue every couple of months, and recently upgraded.&lt;/P&gt;</description>
    <pubDate>Wed, 04 Aug 2021 18:30:14 GMT</pubDate>
    <dc:creator>fhewiufhwefhwe</dc:creator>
    <dc:date>2021-08-04T18:30:14Z</dc:date>
    <item>
      <title>Decryption Log Forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-log-forwarding/m-p/424345#M94252</link>
      <description>&lt;P&gt;I upgraded to PanOS 10.0.6, and am trying to forward decryption logs via email.&amp;nbsp; If I go to monitor -&amp;gt; decryption, then I see a bunch of rows where zone.src eq untrust and zone.dst eq untrust and ( proxy_type eq GlobalProtect ), application is incomplete, and Policy Name is blank.&amp;nbsp; This is exclusively or almost exclusively from bot or malicious traffic.&amp;nbsp; I have log forwarding via email enabled for decryption logs, but am not receiving the logs.&amp;nbsp; Any idea what the issue could be?&amp;nbsp; Are other people forwarding these logs via email?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know that I can also forward traffic logs with decryption errors, but would prefer to forward decryption logs for decryption errors.&amp;nbsp; I also would like to forward alarm logs because the traffic logs fill up every couple of days since I upgraded to 10.0.x PanOS on PA-220.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 22:50:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-log-forwarding/m-p/424345#M94252</guid>
      <dc:creator>fhewiufhwefhwe</dc:creator>
      <dc:date>2021-08-03T22:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption Log Forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-log-forwarding/m-p/424545#M94263</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/93469"&gt;@fhewiufhwefhwe&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I've never actually tried to email decryption logs previously, but I did just verify that this issue is present across two of my lab systems running 10.0.6 so it's not just a you issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2021 18:23:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-log-forwarding/m-p/424545#M94263</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-08-04T18:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption Log Forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-log-forwarding/m-p/424546#M94264</link>
      <description>&lt;P&gt;Thanks BPry for confirming that.&amp;nbsp; I keep notices *.stretchoid.com traffic probing my VPN.&amp;nbsp; Forwarding the decrypt errors are one way to review that to potentially add their ipaddresses to a blocklist.&amp;nbsp; I also have had an issue twice where the firewall rejected valid certificates until a reboot.&amp;nbsp; I want to be alerted about that as well particularly if the upgrade to 10.0.6 did not solve that issue.&amp;nbsp; It's too early for me to definitively tell because I had that issue every couple of months, and recently upgraded.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2021 18:30:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-log-forwarding/m-p/424546#M94264</guid>
      <dc:creator>fhewiufhwefhwe</dc:creator>
      <dc:date>2021-08-04T18:30:14Z</dc:date>
    </item>
  </channel>
</rss>

