- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-18-2017 05:44 AM
I have dual ISP and I use PBF to automatically fail over. How can I set up an email notification that a PBF rule was triggered?
05-18-2017 07:03 AM
Hi,
With pan-os 8 this could be done relatively easy.
Under Device > Log Settings you can create a "System-Log Setting" where you filter only "pbf" events and then logs that match your filter you could attach a custom log forwarding like e-mail.
(When you use the query builder ... just use any type when you add the query, because in the list of entries which you can choose "pbf" is not shown)
Then with even more specific querys you can filter exactly to the rule you want to only receive the messages you need.
Hope that helps.
Regards,
Remo
05-18-2017 06:34 AM
I'm just here to follow; I can't see an obvious way to actually trigger an alert for this at all.
05-18-2017 07:03 AM
Hi,
With pan-os 8 this could be done relatively easy.
Under Device > Log Settings you can create a "System-Log Setting" where you filter only "pbf" events and then logs that match your filter you could attach a custom log forwarding like e-mail.
(When you use the query builder ... just use any type when you add the query, because in the list of entries which you can choose "pbf" is not shown)
Then with even more specific querys you can filter exactly to the rule you want to only receive the messages you need.
Hope that helps.
Regards,
Remo
05-18-2017 07:32 AM
If memory serves correctly this is only able to be done on pan-os 8. Yet another incentive to actually update 😉
05-18-2017 08:01 AM
Yes, as I wrote. In PAN-OS 8 it is realtively easy 😉
Prior to that you could forward ALL Systemlogs (informational will be quite a few 😛 ) and then filter in the mailbox ... but I think PAN-OS 8 is the better way 😉
05-18-2017 10:35 AM
I've got 8 running on our lab enviroment but getting the a'okay to update production is proving to be a fun challenge.
05-27-2017 07:53 AM
07-29-2018 12:53 PM
Can we configure this in the Panorama which is running on 8.0 version and can get the e-mail alerts of events trigerred by the firewalls that are running on 7.0 versions.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!