Query on Syslog filter builder

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Query on Syslog filter builder

L3 Networker

Hi Folks,

 

We had configured to forward the system logs for severity of informational, medium, high and critical using filter builder. But we are receiving logs only for informational on our QRadar Syslog.

 

What is the supported format for System log forwarding in PA firewall, we can select only one severity type for each entry or multiple severity type filter for each entry.

 

Thanks in advance

 

tamilvanan_0-1646669140328.png

 

3 REPLIES 3

Cyber Elite
Cyber Elite

you should be able to pick multiple, but have you tried setting that top one to (severity neq low) ?

Tom Piens
PANgurus - (co)managed services and consultancy

L0 Member

Have a similar issue with our device. It won't forward medium, high or critical events to the syslog server.

@tamilvanan 

 

We have this config for syslog 

 

system-infomational  filter  (severity eq informational)

system-low  filter  (severity eq low)

system-high filter  (severity eq high

system-medium  filter  (severity eq medium )

 

We are getting all the logs to the syslog server

 

Regards

MP
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!