<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Swamped with Syslog logging... in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/swamped-with-syslog-logging/m-p/13445#M9860</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Our PAN is in an L3 config, and our syslog server is in a virtual-wire zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically, if I look at monitor/traffic or monitor/session browser, I'm simply swamped with syslog messages as everything is being syslogged once as the PAN management NIC goes from trust (LAN) to untrust, then again as it goes through the vwire-untrust to the vwire-dmz.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way to reduce this at all please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 05 Nov 2010 17:54:00 GMT</pubDate>
    <dc:creator>networkadmin</dc:creator>
    <dc:date>2010-11-05T17:54:00Z</dc:date>
    <item>
      <title>Swamped with Syslog logging...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/swamped-with-syslog-logging/m-p/13445#M9860</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Our PAN is in an L3 config, and our syslog server is in a virtual-wire zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically, if I look at monitor/traffic or monitor/session browser, I'm simply swamped with syslog messages as everything is being syslogged once as the PAN management NIC goes from trust (LAN) to untrust, then again as it goes through the vwire-untrust to the vwire-dmz.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way to reduce this at all please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Nov 2010 17:54:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/swamped-with-syslog-logging/m-p/13445#M9860</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2010-11-05T17:54:00Z</dc:date>
    </item>
    <item>
      <title>Re: Swamped with Syslog logging...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/swamped-with-syslog-logging/m-p/13446#M9861</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps youcould create a specific rule for the traffic that is being double counted in the VWire and set the option to not log (or not send to syslog - which ever you prefer).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Nov 2010 18:09:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/swamped-with-syslog-logging/m-p/13446#M9861</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2010-11-05T18:09:49Z</dc:date>
    </item>
    <item>
      <title>Re: Swamped with Syslog logging...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/swamped-with-syslog-logging/m-p/13447#M9862</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks James, that's what I've done in the interim, I didn't know if there was a "smarter" way of tackling it was all?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We don't really need real-time logging, we just want &lt;EM&gt;some&lt;/EM&gt; off box logging, and my limited experience of the FTP export found it a bit hit and miss as you have to look in several places to marry up all the data.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have to say as an aside, this thing rocks, I setup a vwire today and it's saved me having to totally re-IP (is that a word?!) our websites and services on our DMZ hosts to be able to do application recognition and decryption and IPS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Nov 2010 18:17:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/swamped-with-syslog-logging/m-p/13447#M9862</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2010-11-05T18:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: Swamped with Syslog logging...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/swamped-with-syslog-logging/m-p/13448#M9863</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This would be the only option - as we must log (as a security device) everything we see and where we see it.&amp;nbsp; Unless the administrator configures the PA Appliance not to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are right that FTP export does not correllate the data for you - the two items to look at when cross referencing logs is the time and session ID.&amp;nbsp; Session ID's do wrap, but within a time frame they are unique - Session ID is a "tag" PANOS puts on the logs for this purpose (and other purposes).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good to hear the DMZ insertion worked well for - VWire is very handy.&amp;nbsp; Also nice you can mix and match deployment modes in one box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Nov 2010 18:31:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/swamped-with-syslog-logging/m-p/13448#M9863</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2010-11-05T18:31:49Z</dc:date>
    </item>
    <item>
      <title>Re: Swamped with Syslog logging...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/swamped-with-syslog-logging/m-p/13449#M9864</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks James, and yes feeling quite peeved at not trying the vwire stuff sooner.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll go with the policy with no logging for now, if it becomes too much I can always look at running a syslog box on the LAN so the management NIC won't be traversing zones.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Nov 2010 18:38:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/swamped-with-syslog-logging/m-p/13449#M9864</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2010-11-05T18:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: Swamped with Syslog logging...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/swamped-with-syslog-logging/m-p/13450#M9865</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Aaah, OK - now I get you.&lt;/P&gt;&lt;P&gt;Try using the service route configuration under the Device tab - main setup screen.&amp;nbsp; You'll need to scroll down to see it.&amp;nbsp; You can then change the source of the syslog traffic to be an alternative L3 Interface - so you could plug another L3 interface into the DMZ and use it just for logging.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen shot 2010-11-05 at 18.40.43.png" class="jive-image" src="https://live.paloaltonetworks.com/servlet/JiveServlet/downloadImage/1959/Screen+shot+2010-11-05+at+18.40.43.png" /&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Nov 2010 18:45:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/swamped-with-syslog-logging/m-p/13450#M9865</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2010-11-05T18:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: Swamped with Syslog logging...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/swamped-with-syslog-logging/m-p/13451#M9866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ah I never spotted that!&amp;nbsp; Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tbh right now it's not much better simply because even if I change the L3 interface it would have to cross zones to get to the syslog box on the vwire.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As it stands with the "no log" policy it looks like the logs are clear and the syslog stuff only shows up in the session browser, which of course it has to because it's active traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Nov 2010 18:48:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/swamped-with-syslog-logging/m-p/13451#M9866</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2010-11-05T18:48:56Z</dc:date>
    </item>
    <item>
      <title>Re: Swamped with Syslog logging...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/swamped-with-syslog-logging/m-p/13452#M9867</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could put a dedicated L3 interface in the DMZ, which does nothing except send syslog - then it would not cross the VWire.&amp;nbsp; Or leave it as is &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Nov 2010 18:52:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/swamped-with-syslog-logging/m-p/13452#M9867</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2010-11-05T18:52:06Z</dc:date>
    </item>
  </channel>
</rss>

