- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-29-2021 04:39 AM
Can I set palo alto to check if syslog server is up before forwarding the log, and if the main syslog server is down then forward log to another server?
I have issues that I need palo alto to not forwarding logs to both servers at the same time.
10-04-2021 09:33 PM
Thank you for posting question @Theerdam
I was researching this topic and doing some verification. Regardless of PAN-OS version there can be up to 4 syslog servers configured in one syslog server profile, however there is no logic / connection check. Syslog server profile is sending logs to all targets simultaneously. One way to go around it would be to send all the logs to Virtual IP address of Load Balancer, then based on health check send logs to either of the real syslog server.
Kind Regards
Pavel
10-04-2021 09:33 PM
Thank you for posting question @Theerdam
I was researching this topic and doing some verification. Regardless of PAN-OS version there can be up to 4 syslog servers configured in one syslog server profile, however there is no logic / connection check. Syslog server profile is sending logs to all targets simultaneously. One way to go around it would be to send all the logs to Virtual IP address of Load Balancer, then based on health check send logs to either of the real syslog server.
Kind Regards
Pavel
11-18-2021 07:41 AM
Hi, I have one query here.
Imagine the Syslog server is down for a few hours, and later once the syslog server is up again, will the firewall send fresh logs or the meantime logs as well ?
03-11-2023 11:36 AM
If the syslog server is down then as per my understanding firewall will store logs locally and once server is up it will send old new logs.
Regards
Mahesh
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!