Log Forwarding Discussions
The HTTP Log Forwarding Discussion Forum is a space to share and collaborate on various HTTP log forwarding integrations with the community. Users are encouraged to post their own integrations and engage in discussions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Log Forwarding Discussions
The HTTP Log Forwarding Discussion Forum is a space to share and collaborate on various HTTP log forwarding integrations with the community. Users are encouraged to post their own integrations and engage in discussions.
About Log Forwarding Discussions

Welcome to HTTP Log Forwarding Discussion Forum!

We want to hear from you! The goal of this page is to share and collaborate on different HTTP log forwarding integrations amongst the community. Please feel free to post any integrations that you come up with in the discussions below.

Note: Support for HTTP Log Forwarding scripts/templates is provided here in this Live Community discussion board. Requests for technical support by phone or web will be redirected to this page.

Discussions

Scheduled logs export on a Palo Alto.

Folks, can we have some scheduling done on logs which are being sent to a syslog server? The traffic logs are so huge that they consume too much bandwidth when we send them to a central syslog. It seems that they are all being sent when some buffer fills up. If my assumption is correct maybe there is some method to reduce the buffer size?? Thank...

nson2139 by L3 Networker
  • 5798 Views
  • 0 replies
  • 0 Likes

Send logs to Panorama without Panorama managing the firewall

This might be a really weird question and I expect people to ask why I want to do this. If that is going to be your response, then please don't respond. I have a couple PA-220s at a remote location. I want to send logs from the PA-220s to Panrorama. I don't want to push configurations from Panorama to the devices (well maybe templates are ok...

ScottF by L1 Bithead
  • 7236 Views
  • 1 replies
  • 0 Likes

System Log "Number of hints on disk has exceeded 5000 due to log forward failures."

Buenas tardes, Tengo un cliente (PA 5220 version 8.0.9) al que continuamente (cada hora) le está apareciendo este mensaje de error en Monitor --> System: "Number of hints on disk has exceeded 5000 due to log forward failures." En un principio pensamos que era debido al parametro configurado bajoDevice --> Setup --> Management --> Log...

Detailed Logging for attempts externally

Hello Community!Occasionally we get "SYSTEM ALERT" forwarded to the mailbox, in regards to failed authentications where there was an attempt using a non-existent user. Is it possible to add more information in these logs?Specifically whether the user tried to log on using the GlobalProtect client, or the portal login page?Which portal was used?U...

Collector groups always need to be pushed

Hi everyone, I have 1 Panorama and one pair of Firewall in HA. I have configured the collector Groups and Managed collector so I can send logs to Panorama.Everything is working well but on the Panorama, if I select Commit > Push to devices, I constantly see a push to do for collector Groups. No matter if I push, it is always there. Did I miss...

Palo alto Netflow integration with Orion

Hello all, I'm trying to create netflow between PA3020 and solarwinds orion. I follow the step by step process and manage to see limited information on the Orion side, I can see the logs on Orion but I can't drill down with the links to see the endpoint and which application or traffic it runs. Palo alto support told me to customize netflow traf...

SShnap by L3 Networker
  • 6215 Views
  • 0 replies
  • 0 Likes

Panorama Firewall Syslog Timestamp

I'm trying to find a way to timestamp syslogs with milliseconds and can't seem to find a way. We want to be able to see milliseconds in our logs from our Firewalls which are then being forwarded to Panroama, and then finally to our syslog server. Thanks.

Where I can see the log traffic Policy Based Forwarding

Hi, I had some security rules to deny all the traffic that I generated with my dynamic lists and MInemeld. As I was reading it was better to make the denial of this traffic instead of "Polices / Security" in "Policies / Policy Based Forwarding".The problem I have is that now I do not see the matching of the denials of these rules. Before I could...

Customise Alert Mail Configuration

Hi Guys, Im Aashik , i just configured Alert mail in my Palo Alto , im reciveing Alert mails. but the thing is i just want to configure Customise Alert mail ,is there any Possiblity of reciveing alert mails for every 30 minutes. If Possible or not possible please share your thoughts Thanks&RegardsM Mohammed Aashik

HTTP Log Forwarding to MineMeld

With MineMeld 0.9.42 you can now use HTTP Log Forwarding with MineMeld API for Incident Response:https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-MineMeld-as-a-Incident-Response-Platform/ta-p/174690

lmori by L7 Applicator
  • 4531 Views
  • 0 replies
  • 0 Likes
  • 26 Posts
  • 28 Subscriptions