Send Generated Alarms to Syslog

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Send Generated Alarms to Syslog

L4 Transporter

Hi Guys,

I was wondering if there was a way to send the Alarm messages on the firewall to a syslog.  For example an alarm like "Current size (39047 MB) of traffic log database exceeds alarm threshold value (90%) of total allowed size (39037 MB)".

Is there any way I can have that sent to a syslog server.  I have threats being sent to my syslog server, traffic logs etc.. but unable to figure out a way to get the alarms through. Smiley Happy

Many Thanks..

Regards,

Kal

1 accepted solution

Accepted Solutions

Hi Parth,

I work for a reseller in UK.  I install PA's and even do the evaluations.  Hence stated about feature request here.  I will speak to my SE on this.

Cheers..

Kalyan

View solution in original post

4 REPLIES 4

L4 Transporter

Hi Kal.

As far as I know, currently there is no way we can do log forwardign for Alarm Logs on to a syslog server.

You can enable CLI and Web alarm notifications though.

Device--> Log Settings -->Alarms

The syslog server profile also does not have the way to forward logs to syslog.

Also per the admin guide 4.0, You can view the current list of alarms at any time by clicking the Alarms icon in thelower right corner of the web interface. This opens a window that lists the unacknowledgedand acknowledged alarms in the current alarms log. To acknowledge alarms, select theircheck boxes and click Acknowledge. This action moves the alarms to the AcknowledgeAlarms list. The alarms window also includes paging, column sort, and refresh controls

Regards,

Parth

Hi Parth,

Thanks for the information.  I had all that done before posting my question Smiley Happy.  It would be an added advantage if we could have log forwarding for alarms.

For example; Once the firewall has been configured and is put in production, the customer would usually login frequently for the first couple of months after which it would just be once in a while.  In this scenario, this would really help as we can have alerts forwarded.

Can we have this a feature request..??

Cheers..

Kalyan

Hi Kalyan,

For any issues related to design, feature request, licenseing for the product please contact the Reseller from whom you purchased the device (as a first point of contact) or Palo Alto Networks Sales Engineering Team if you bought the device directly from us.


If you donot happen to know your Regional sales Engineer, please get in touch with our sales Team at the follwoing E-mail.

Sales Inquiries
US and North America:

contact_sales@paloaltonetworks.com

Regards,

Parth

Hi Parth,

I work for a reseller in UK.  I install PA's and even do the evaluations.  Hence stated about feature request here.  I will speak to my SE on this.

Cheers..

Kalyan

  • 1 accepted solution
  • 2522 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!