Palo Alto firewalls alerts

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

Palo Alto firewalls alerts

L1 Bithead

Hello,

 

Recently we have started working on enabling email alerts for our Palo Alto firewalls. One of the alert is for interface and HA status change alerts. Could you please let me know what can I do to enable same? Do I need any external tool for it? Any sort of help would be appreciated. 

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Thank you for the post @PA-NewBie

 

Interface and HA status related events are recorded in system logs. Below is a KB describing how to enable email alerts for system logs:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGjCAK

 

Enabling email alert for system logs can be noise especially if you enable all severities. If you want to narrow down only HA logs, then you can use this filter: ( subtype eq ha ) in the system log setting:

PavelK_1-1649679796673.png

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

Thank you for the post @PA-NewBie

 

Interface and HA status related events are recorded in system logs. Below is a KB describing how to enable email alerts for system logs:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGjCAK

 

Enabling email alert for system logs can be noise especially if you enable all severities. If you want to narrow down only HA logs, then you can use this filter: ( subtype eq ha ) in the system log setting:

PavelK_1-1649679796673.png

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

L1 Bithead

Thank you Pavel. This is helpful.
So basically if I want to add same alert for interface status change also then need to put that event under filter right?

I would give a try the way you have mentioned and update you. Thank you 

L1 Bithead

Hi Pavel,

Thanks again! I was able to set alerts for HA state change.

  • 1 accepted solution
  • 2332 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!