- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-19-2012 07:18 AM
Hi all,
I have not found a way to send user logins to an external syslog server. I have traffic allows/denies coming through successfully, and "misc. system events." Is there a custom configuration that needs to be done to get user login date/time? We need this for compliance.
Thanks,
Eric H.
09-19-2012 10:47 AM
Hi Eric,
System logs on the PAN will have the login information of the users. So you can forward the system logs to the Syslog server. You can forward systems log's to the server like below. System logs will have all kinds of information related to the device so if you do not want all the info and need just the login information in the Syslog's, try just forwarding informational system logs.
09-19-2012 07:26 AM
Objects -> Logging Profiles -> SNMP Traps/Syslog
Apply new profile to the rules you wish and also in Device->Log Settings->System
Works great here.
09-19-2012 09:57 AM
I appreciate the attempt, but that's a pretty vague answer. I already have syslog configured correctly and am capturing logs. My question was pertaining to whether there was something I was missing. I don't see anything for "user logins" on my syslog appliance.
09-19-2012 10:47 AM
Hi Eric,
System logs on the PAN will have the login information of the users. So you can forward the system logs to the Syslog server. You can forward systems log's to the server like below. System logs will have all kinds of information related to the device so if you do not want all the info and need just the login information in the Syslog's, try just forwarding informational system logs.
09-19-2012 10:58 AM
Thank you. I thought the 'Panorama' option was only used for a separate piece of hardware provided by Palo Alto. Maybe I do not have the correct information.
09-19-2012 11:24 AM
I think there is a confusion here. In the above the pic the "panorama" option is enabled to send logs to panorama, but if you scroll to the right hand corner you will see an option for syslog. In the picture you can see "pc" under syslog. "pc" is my syslog server profile. So I am forwarding my PAN system logs to syslog server that is configured in the syslog server profile named "pc". So I am forwarding severity of low medium and high to the syslog server and not forwarding informational to the syslog server. You need to forward informational also as you need login information in the syslog server.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!