Custom Email alerts based on System logs in Panorama 8.x

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Custom Email alerts based on System logs in Panorama 8.x

L4 Transporter

I have configured Scheduled configuratio export for Panorama and all firewalls to an SCP server

This is done via Panorama.

Is there any way to schedule an email alert after evry succesful backup of configuration. Or in case of failed  export of configuration . I can see the SCP export happening through system logs in panorama.

I have filtererd with the SCP/SFTP server IP like below: Is it possible to filter this and create email alert:( custom email Alerts):

backuplogs.png

PCNSE-7, ACE-6,ACE 7 , CCNP, CCNA,CCIE(theory) , RHCE
Firewalldog dot com
1 ACCEPTED SOLUTION

Accepted Solutions

Community Team Member

@Roby_Sreejith,

 

For forwarding filtered System Logs :

 

Device tab (or Panorama tab on Panorama) > Log Settings > System (+Add) > Filter Builder :

 

2018-04-12_13-31-09.jpg

 

Cheers !

-Kiwi.

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Don't forget to hit that Like button if a post is helpful to you!

View solution in original post

16 REPLIES 16

Community Team Member

Hi @Roby_Sreejith,

 

I haven't checked it myself yet but if there's a log generated then you could use PAN-OS 8.0 filtered log forwarding feature to accomplish this.

 

Hope this helps.

Cheers !

-Kiwi.

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Don't forget to hit that Like button if a post is helpful to you!

I'm curious, maybe I don't understand what you're trying to do but Panorama automatically takes a config backup everytime you make a commit change that's attached to panorama.  It stores 100 unqiue configs by default.  (I'm not sure why you'd need a seperate process to export the configs?)

 

PAN_Backups.PNG

There is is a problem with this bacakup. It stores in Panorama. I can not extarct this to locally. 

PCNSE-7, ACE-6,ACE 7 , CCNP, CCNA,CCIE(theory) , RHCE
Firewalldog dot com


@Roby_Sreejith wrote:

There is is a problem with this bacakup. It stores in Panorama. I can not extarct this to locally. 


 

I guess I don't understand the requirement.  You need it "locally" and not in Panorama because Panorama has the potential to be inaccessible and if at that same time you have a firewall down and need to restore said firewall relying on Panorama is a failure point?

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!