- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-07-2022 08:12 AM
Hi Folks,
We had configured to forward the system logs for severity of informational, medium, high and critical using filter builder. But we are receiving logs only for informational on our QRadar Syslog.
What is the supported format for System log forwarding in PA firewall, we can select only one severity type for each entry or multiple severity type filter for each entry.
Thanks in advance
03-10-2022 01:28 AM
you should be able to pick multiple, but have you tried setting that top one to (severity neq low) ?
03-24-2022 01:57 AM
Have a similar issue with our device. It won't forward medium, high or critical events to the syslog server.
03-24-2022 09:47 PM
We have this config for syslog
system-infomational filter (severity eq informational)
system-low filter (severity eq low)
system-high filter (severity eq high
system-medium filter (severity eq medium )
We are getting all the logs to the syslog server
Regards
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!