Expedition as a Syslog server

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Expedition as a Syslog server

L1 Bithead

Hi all, I'm trying to set up Expedition as a Syslog server.  I am following the guides, but a folder under /PALogs is never created with the management IP of firewall sending the logs.  Any suggestions?  

6 REPLIES 6

L6 Presenter

Hi @tnamba_evotek If /PALogs folder does not exist, you will need to manually create them in the Expedition.  Please review the tutorial video https://youtu.be/Ozjx0rfRRmI

/PALogs directory is there, but the directory under that never gets created with the management IP of the firewall (10.0.0.1).  I tried creating the 10.0.0.1 directory manually, but no logs ever get populated.

@tnamba_evotek  The subfolder should be auto created when Expedition received syslog from firewall. You can try to use "chmod" to change the folder permission, so firewall can write to it , all those are in the tutorial video . 

That is my issue, it is not getting created automatically and when I manually create it, the logs never show up.  I used chmod and chown to mirror the /PALogs directory permission and ownership to the 10.0.0.1 directory.

@tnamba_evotek Make sure you have modified

/var/www/html/OS/rsyslog/rsyslog.conf to be like the sample in the same directory , for example, if you are sending the syslog in udp , you will reference the rsyslog.default-udp in the same directory, double check below:

1.  You have added your firewallIPs as allowed list in the section of the rsyslog.conf

# specify senders you permit to access

$AllowedSender TCP, 127.0.0.1, 10.11.29.0/24, 172.16.26.0/24, *.paloaltonetworks (add your firewall IPs)

.com

$AllowedSender UDP, 127.0.0.1, 10.11.29.0/24, 172.16.26.0/24, *.paloaltonetworks (add your firewall IPs)

.com

2. In the below section, make sure the folder is /PALogs and the folder exist in your system:  (Folder name is Case sensitive)

 

$template DynaTrafficLog,"/PALogs/%FROMHOST-IP%/%HOSTNAME%_traffic_%$YEAR%_%$MON

TH%_%$DAY%_last_calendar_day.csv"

 

3. After modify and save the file, make sure you restart the VM

Yes, that is all in the guide which I followed. 

  • 2053 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!