- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-17-2023 11:28 AM
Can someone explain to me the rational behind allowing an interface to drop and having the link-change log a down state and yet have it be INFORMATIONAL severity level? I saw an old question about this and it seems somewhat ridiculous? We had filtering on higher severity levels and had a circuit drop and never got the alert and then realized why.
Just curious if anyone understands the reasoning behind this?
04-20-2023 01:28 PM
Hi @TonyDeHart ,
Could you share a screenshot of the alert and blur any IPs/Names? I typically have seen "Critical" for alerts such as VPN tunnel down or interface being down on the Palo. Here is a link to the system logs doc.
04-20-2023 01:50 PM
Yeah those events are informational.
I have dedicated syslog/email alert set up under "Device > Log Settings > System" with filter ( subtype eq port ).
You can also be more specific with "( subtype eq port ) and ( eventid eq link-change )" to notify you.
04-21-2023 04:37 AM
Thanks. That is essentially what I did after I discovered this but I was more curious what, if anything, is the rational behind a port going doing being informational? Not sure if anyone from Palo Alto chimes in but how is this not a more critical type of alert?
04-21-2023 05:30 AM
It would be nice if alert severities for different events could be adjusted by admin.
For example in tiny office that has no switch and workstations connect directly to firewall it would be noisy if every workstation reboot causes critical alert in firewall.
On the other hand if firewall is in the datacenter then it is definitely event to pay attention to.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!