Log Forwarding Rule/Object

Announcements

ATTENTION Customers, All Partners and Employees: The Customer Support Portal (CSP) will be undergoing maintenance and unavailable on Saturday, November 7, 2020, from 11 am to 11 pm PST. Please read our blog for more information.

Reply
Highlighted
L0 Member

Log Forwarding Rule/Object

I have a server that connects every 10 minutes to an SFTP server.  I would ideally like to know when it is done for the day.  So I setup an email server profile and started on a Log Forwarding object.  It does not really have to be a log, just and email that says "Oi the server is done for the day".  The server connecting is a third party so I can't do it from that side.

 

Is it possible to create an object that will be "actioned" once there is no connection from the filtered server after a set amount of time?  So say after 10 minutes if no additional connections are being received.  I say additional connections as I am not interested in an email every 10 minutes stating there are no connections.  I am also not really interested in when they start either as they start during my sleepy time.

 

Thank you so much for helping a Palo Alto noob.

Tags (1)
Highlighted
Cyber Elite

@DIR_IT,

This isn't really going to work. If the sessions happen long enough to stay active you could setup a log-forwarding profile to alert you on session-end, but the fact that these are ten minutes apart means that likely isn't going to be the case. You could of course set something up with the API and checking the session table. 

Highlighted
Cyber Elite

Hello,

Perhaps can be done from a SIEM? However how about adding a schedule to the policy, i.e. its only accessible from point A to point B between the hours of X to Z?

 

Just a thought

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!