Sending user logins via Syslog

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Sending user logins via Syslog

L0 Member

Hi all,

I have not found a way to send user logins to an external syslog server. I have traffic allows/denies coming through successfully, and "misc. system events." Is there a custom configuration that needs to be done to get user login date/time? We need this for compliance.

Thanks,


Eric H.

1 accepted solution

Accepted Solutions

Hi Eric,

System logs on the PAN will have the login information of the users. So you can forward the system logs to the Syslog server. You can forward systems log's  to the server like below. System logs will have all kinds of information related to the device so if you do not want all the info and need just the login information in the Syslog's, try just forwarding informational system logs.

dCapture.PNG

View solution in original post

5 REPLIES 5

L4 Transporter

Objects -> Logging Profiles -> SNMP Traps/Syslog

Apply new profile to the rules you wish and also in Device->Log Settings->System

Works great here.

I appreciate the attempt, but that's a pretty vague answer. I already have syslog configured correctly and am capturing logs. My question was pertaining to whether there was something I was missing. I don't see anything for "user logins" on my syslog appliance.

Hi Eric,

System logs on the PAN will have the login information of the users. So you can forward the system logs to the Syslog server. You can forward systems log's  to the server like below. System logs will have all kinds of information related to the device so if you do not want all the info and need just the login information in the Syslog's, try just forwarding informational system logs.

dCapture.PNG


Thank you. I thought the 'Panorama' option was only used for a separate piece of hardware provided by Palo Alto. Maybe I do not have the correct information.

I think there is a confusion here. In the above the pic the "panorama" option is enabled to send logs to panorama, but if you scroll to the right hand corner you will see an option for syslog. In the picture you can see "pc" under syslog. "pc" is my syslog server profile. So I am forwarding my PAN system logs to syslog server that is configured in the syslog server profile named "pc". So I am forwarding severity of low medium and high to the syslog server and not forwarding informational to the syslog server. You need to forward informational also as you need login information in the syslog server.

  • 1 accepted solution
  • 3322 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!