- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-24-2021 01:21 AM
Hi All,
Is there a way where, I can generate report of firewall events, Like login events from system logs, As daily basis. And I will share through email.
12-24-2021 06:02 AM
Thank you for the post @SubaMuthuram
All the reports in Firewall/Panorama are supporting only Traffic, Threat,... related events. I could not find any way to run a report for system logs, however if you are only interested in login events, then potentially one of the workaround could be enable under log setting in: Device > Log Settings > System, then use for example this filter: ( subtype eq auth ). The disadvantage of this, you will get an email for every login attempt.
Another alternative would be to let all System logs forward to 3rd party monitoring system / SIEM and run report from there against system logs.
Kind Regards
Pavel
12-24-2021 06:02 AM
Thank you for the post @SubaMuthuram
All the reports in Firewall/Panorama are supporting only Traffic, Threat,... related events. I could not find any way to run a report for system logs, however if you are only interested in login events, then potentially one of the workaround could be enable under log setting in: Device > Log Settings > System, then use for example this filter: ( subtype eq auth ). The disadvantage of this, you will get an email for every login attempt.
Another alternative would be to let all System logs forward to 3rd party monitoring system / SIEM and run report from there against system logs.
Kind Regards
Pavel
12-24-2021 08:27 AM
Thanks for the reply. Pavel.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!