link-change still informational severity?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

link-change still informational severity?

L4 Transporter

Can someone explain to me the rational behind allowing an interface to drop and having the link-change log a down state and yet have it be INFORMATIONAL severity level? I saw an old question about this and it seems somewhat ridiculous?  We had filtering on higher severity levels and had a circuit drop and never got the alert and then realized why.

 

Just curious if anyone understands the reasoning behind this?

5 REPLIES 5

Community Team Member

Hi @TonyDeHart ,

 

Could you share a screenshot of the alert and blur any IPs/Names? I typically have seen "Critical" for alerts such as VPN tunnel down or interface being down on the Palo. Here is a link to the system logs doc.

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

L4 Transporter

This is straight out of the system log from a link dropping on us.  Bonus for the HSCI being in there. 🙂

 

Our alerting was ignoring information as far as getting a text/email so we never knew until other services dropped that the link had failed on the firewall.

Cyber Elite
Cyber Elite

Yeah those events are informational.

 

Raido_Rattameister_0-1682023746450.png

 

 

I have dedicated syslog/email alert set up under "Device > Log Settings > System" with filter ( subtype eq port ).

You can also be more specific with "( subtype eq port ) and ( eventid eq link-change )" to notify you.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Thanks. That is essentially what I did after I discovered this but I was more curious what, if anything, is the rational behind a port going doing being informational? Not sure if anyone from Palo Alto chimes in but how is this not a more critical type of alert?

Cyber Elite
Cyber Elite

It would be nice if alert severities for different events could be adjusted by admin.

For example in tiny office that has no switch and workstations connect directly to firewall it would be noisy if every workstation reboot causes critical alert in firewall.

On the other hand if firewall is in the datacenter then it is definitely event to pay attention to.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011
  • 1922 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!