How can I set up an email notification that a PBF rule was triggered?

Reply
L3 Networker

How can I set up an email notification that a PBF rule was triggered?

I have dual ISP and I use PBF to automatically fail over. How can I set up an email notification that a PBF rule was triggered?

L7 Applicator

Re: How can I set up an email notification that a PBF rule was triggered?

I'm just here to follow; I can't see an obvious way to actually trigger an alert for this at all. 

L7 Applicator

Re: How can I set up an email notification that a PBF rule was triggered?

Hi,

 

With pan-os 8 this could be done relatively easy.

Under Device > Log Settings you can create a "System-Log Setting" where you filter only "pbf" events and then logs that match your filter you could attach a custom log forwarding like e-mail.

 

Ashampoo_Snap_2017.05.18_15h58m54s_002_.png

 

(When you use the query builder ... just use any type when you add the query, because in the list of entries which you can choose "pbf" is not shown)

 

Then with even more specific querys you can filter exactly to the rule you want to only receive the messages you need.

 

Hope that helps.

 

Regards,

Remo

L7 Applicator

Re: How can I set up an email notification that a PBF rule was triggered?

If memory serves correctly this is only able to be done on pan-os 8. Yet another incentive to actually update ;) 

L7 Applicator

Re: How can I set up an email notification that a PBF rule was triggered?

Yes, as I wrote. In PAN-OS 8 it is realtively easy ;)

Prior to that you could forward ALL Systemlogs (informational will be quite a few :P  )  and then filter in the mailbox ... but I think PAN-OS 8 is the better way ;)

L7 Applicator

Re: How can I set up an email notification that a PBF rule was triggered?

@vsys_remo,

I've got 8 running on our lab enviroment but getting the a'okay to update production is proving to be a fun challenge. 

L3 Networker

Re: How can I set up an email notification that a PBF rule was triggered?

Thanks! I was planning to upgrade to 8.0 anyway
L2 Linker

Re: How can I set up an email notification that a PBF rule was triggered?

Can we configure this in the Panorama which is running on 8.0 version and can get the e-mail alerts of events trigerred by the firewalls that are running on 7.0 versions.
 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!