- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-07-2022 10:21 PM
I searched on internet and I found only setting send traffic log to syslog by per security rule. on situation that has multiple security rules (100-200 rules). Can I set Syslog on global? or It can be set only per security rule?
03-07-2022 11:08 PM
Thank you for the post @jirasith
I am afraid that only option is to set it up per security rule. For all new rules, if you name log forwarding profile as: "default" it is automatically added added to the rule, but this will not help you with existing rules. Please check documentation, step 2:
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/monitoring/configure-log-forwarding.html
Kind Regards
Pavel
03-08-2022 01:53 AM
Hi @jirasith ,
There are some tools out there that allow you to perform bulk edits. Here are some options you might want to look into:
Expedition, primarily used for migrating configurations, can do bulk changes. Please verify if this can help you:
You can look into API and scripting. An example here:
Alternatively you can look at PAN-CONFIGURATOR, a PHP library aimed at making PANOS config changes easy:
Hope this helps,
-Kiwi
03-08-2022 06:18 PM
Thank you for the information. @PavelK
03-08-2022 06:28 PM
Hi @kiwi,
I have a question about Expedition Tool. I have to import the production configuration to Expedition Tool and then do the bulk Changes > Log Forwarding. and then export configuration on Expedition Tool and import to production firewall right?
03-08-2022 07:58 PM
Correct. Export and load your current configuration into Expedition, make the bulk changes, and then export the updated configuration from expedition. You can then import the updated configuration file on the firewall and load and commit it to apply the bulk changes you made in Expedition.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!