Sending user logins via Syslog

Reply
Highlighted
L0 Member

Sending user logins via Syslog

Hi all,

I have not found a way to send user logins to an external syslog server. I have traffic allows/denies coming through successfully, and "misc. system events." Is there a custom configuration that needs to be done to get user login date/time? We need this for compliance.

Thanks,


Eric H.

Tags (1)

Accepted Solutions
Highlighted
L6 Presenter

Re: Sending user logins via Syslog

Hi Eric,

System logs on the PAN will have the login information of the users. So you can forward the system logs to the Syslog server. You can forward systems log's  to the server like below. System logs will have all kinds of information related to the device so if you do not want all the info and need just the login information in the Syslog's, try just forwarding informational system logs.

dCapture.PNG

View solution in original post


All Replies
Highlighted
L4 Transporter

Re: Sending user logins via Syslog

Objects -> Logging Profiles -> SNMP Traps/Syslog

Apply new profile to the rules you wish and also in Device->Log Settings->System

Works great here.

Highlighted
L0 Member

Re: Sending user logins via Syslog

I appreciate the attempt, but that's a pretty vague answer. I already have syslog configured correctly and am capturing logs. My question was pertaining to whether there was something I was missing. I don't see anything for "user logins" on my syslog appliance.

Highlighted
L6 Presenter

Re: Sending user logins via Syslog

Hi Eric,

System logs on the PAN will have the login information of the users. So you can forward the system logs to the Syslog server. You can forward systems log's  to the server like below. System logs will have all kinds of information related to the device so if you do not want all the info and need just the login information in the Syslog's, try just forwarding informational system logs.

dCapture.PNG

View solution in original post

Highlighted
L0 Member

Re: Sending user logins via Syslog


Thank you. I thought the 'Panorama' option was only used for a separate piece of hardware provided by Palo Alto. Maybe I do not have the correct information.

Highlighted
L6 Presenter

Re: Sending user logins via Syslog

I think there is a confusion here. In the above the pic the "panorama" option is enabled to send logs to panorama, but if you scroll to the right hand corner you will see an option for syslog. In the picture you can see "pc" under syslog. "pc" is my syslog server profile. So I am forwarding my PAN system logs to syslog server that is configured in the syslog server profile named "pc". So I am forwarding severity of low medium and high to the syslog server and not forwarding informational to the syslog server. You need to forward informational also as you need login information in the syslog server.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!