How can I set up an email notification that a PBF rule was triggered?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

How can I set up an email notification that a PBF rule was triggered?

L3 Networker

I have dual ISP and I use PBF to automatically fail over. How can I set up an email notification that a PBF rule was triggered?

1 accepted solution

Accepted Solutions

L7 Applicator

Hi,

 

With pan-os 8 this could be done relatively easy.

Under Device > Log Settings you can create a "System-Log Setting" where you filter only "pbf" events and then logs that match your filter you could attach a custom log forwarding like e-mail.

 

Ashampoo_Snap_2017.05.18_15h58m54s_002_.png

 

(When you use the query builder ... just use any type when you add the query, because in the list of entries which you can choose "pbf" is not shown)

 

Then with even more specific querys you can filter exactly to the rule you want to only receive the messages you need.

 

Hope that helps.

 

Regards,

Remo

View solution in original post

7 REPLIES 7

Cyber Elite
Cyber Elite

I'm just here to follow; I can't see an obvious way to actually trigger an alert for this at all. 

L7 Applicator

Hi,

 

With pan-os 8 this could be done relatively easy.

Under Device > Log Settings you can create a "System-Log Setting" where you filter only "pbf" events and then logs that match your filter you could attach a custom log forwarding like e-mail.

 

Ashampoo_Snap_2017.05.18_15h58m54s_002_.png

 

(When you use the query builder ... just use any type when you add the query, because in the list of entries which you can choose "pbf" is not shown)

 

Then with even more specific querys you can filter exactly to the rule you want to only receive the messages you need.

 

Hope that helps.

 

Regards,

Remo

If memory serves correctly this is only able to be done on pan-os 8. Yet another incentive to actually update 😉 

L7 Applicator

Yes, as I wrote. In PAN-OS 8 it is realtively easy 😉

Prior to that you could forward ALL Systemlogs (informational will be quite a few 😛  )  and then filter in the mailbox ... but I think PAN-OS 8 is the better way 😉

@Remo,

I've got 8 running on our lab enviroment but getting the a'okay to update production is proving to be a fun challenge. 

Thanks! I was planning to upgrade to 8.0 anyway

Can we configure this in the Panorama which is running on 8.0 version and can get the e-mail alerts of events trigerred by the firewalls that are running on 7.0 versions.
 

  • 1 accepted solution
  • 6109 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!