09-19-2012 07:18 AM
Hi all,
I have not found a way to send user logins to an external syslog server. I have traffic allows/denies coming through successfully, and "misc. system events." Is there a custom configuration that needs to be done to get user login date/time? We need this for compliance.
Thanks,
Eric H.
09-19-2012 10:47 AM
Hi Eric,
System logs on the PAN will have the login information of the users. So you can forward the system logs to the Syslog server. You can forward systems log's to the server like below. System logs will have all kinds of information related to the device so if you do not want all the info and need just the login information in the Syslog's, try just forwarding informational system logs.
09-19-2012 07:26 AM
Objects -> Logging Profiles -> SNMP Traps/Syslog
Apply new profile to the rules you wish and also in Device->Log Settings->System
Works great here.
09-19-2012 09:57 AM
I appreciate the attempt, but that's a pretty vague answer. I already have syslog configured correctly and am capturing logs. My question was pertaining to whether there was something I was missing. I don't see anything for "user logins" on my syslog appliance.
09-19-2012 10:47 AM
Hi Eric,
System logs on the PAN will have the login information of the users. So you can forward the system logs to the Syslog server. You can forward systems log's to the server like below. System logs will have all kinds of information related to the device so if you do not want all the info and need just the login information in the Syslog's, try just forwarding informational system logs.
09-19-2012 10:58 AM
Thank you. I thought the 'Panorama' option was only used for a separate piece of hardware provided by Palo Alto. Maybe I do not have the correct information.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!