Log forwarding has been around on our firewalls since forever. However, the feature had its limitations.
Problem before PAN-OS 8.0:
I HATE LOGS
Solution in PAN-OS 8.0:
Log forwarding profiles are re-designed to accommodate log filtering. Users can now create match lists in the log forwarding profile.
All the forwarding actions mentioned in the match list will be taken against that particular traffic log. A traffic log can match more than one match list, forwarding actions mentioned in all the matching lists will be taken. New match criteria can be added to the forwarding profile with “Add” option. Here in this example, two match lists are configured:
Log Forwarding Profile
Log Forwarding Profile Match List allows for the creation of custom filters as shown here:
Filter Builder
By default, the firewall forwards ALL logs of the selected Log Type. To forward a subset of the logs, select an existing filter from the drop-down or select 'Filter Builder' to add a new filter to select interesting logs to be forwarded. These filters are similar to the existing filters that we already have in the monitor tab:
Create Filter
Use the ‘View Filtered Logs’ tab to verify which logs exactly will be forwarded.
It can be challenging to create your own filter but you can work backwards and have the firewall create a filter for you. Without a configured filter you can goto the 'View Filtered Logs' view and you will have an unfiltered view. From here you can make any selection from the displayed logs and the firewall will create a filter for you in response to that. Notice how the firewall creates a filter for me when I make any selection in the 'View Filtered Logs' tab.
Filter Creation
Click the 'Apply Filter' button to see exactly what will be forwarded :
Apply Filter
Click OK and all that remains to be done is select your Forward method. Once you do that you can click the OK button and you can confirm if the Log Forwarding Profile looks fine and you can click the OK button once more.
Log Forwarding Profile
With this your log forwarding profile is created.
Similarly you have the log settings feature on the device tab. Here you can configure system logs, config logs, UserID, Correlation and HIP match logs (User-ID and Correlation are new in PAN-OS 8.0). The same granularity was added in all of these logs:
Device - Log Settings
As an example check out the 'Log Settings - Configuration' below, where I configured a forwarding option for the filter ( admin neq admin )
Log Settings - Configuration
Notice in the example above that I've set my forwarding option to Panorama. If you are happy with this you can go ahead and click OK and commit the change.
With this new feature, a flood of unwanted logs will soon be a thing of the past!
As always, feel free to add comments to the comments section below or reach out to us in the Live Community Discussions Forum.
Cheers!
-Kim.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
User | Likes Count |
---|---|
13 | |
5 | |
3 | |
3 | |
2 |