Syslog connection broken to server Palo Alto every 20 min

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Syslog connection broken to server Palo Alto every 20 min

L0 Member

Hello,

As per title, I have this problem on a HA scenario with two VM-100 installed on VMware. Practically every 20 min in the system logs  appears:"Syslog connection broken to server". After 0 sec appears:"Syslog connection is established to server".

Can someone help me to better understand what it is?

OS version 10.0.5

HA active-passive

Thx.

 

 

3 REPLIES 3

Cyber Elite
Cyber Elite

Hi @GheorgheR 

 

I had the same issue in the past. There are several reasons for triggering this. In order to drill down into a route cause, would it be possible to get syslog logs from CLI from Active Firewall: tail lines 100 mp-log syslog-ng.log.1

 

Also, would it be possible to take packet capture from management interface (Assuming you are using management interface to send syslog)? Here is the manual: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleECAS You can use for example this filter: tcpdump filter "host <IP address of your syslog server>", then please export it and check it in Wireshark to see reason for closing of the session.

 

In one of my case, the closing reason was periodic TCP FIN. This got resolved by changing timer on server side to keep connection open for longer period.

 

Since, you mentioned that connection gets broken and re-established periodically, this might be the root cause. Could you please confirm what server product you are sending syslog to? Based on what we see in the syslog-ng.log or from packet capture, I would decide what steps to take next for troubleshooting.

 

I hope this helps to narrow down what the root cause is.

 

Thank you and Regards

Pavel

 

 

 

 

 

 

 

 

Help the community: Like helpful comments and mark solutions.

L1 Bithead

I am seeing this on our secondary firewall, but not on our primary. Syslog connection breaks and reconnects every few minutes.

CISSP, CCSP, CISA, CISM

Cyber Elite
Cyber Elite

Hello @LeeSeeman

 

thank you for the comment. Since the passive Firewall does not actively process any traffic, syslog connection will not be sending any Traffic, URL, Threat logs,... The only log that is being generated on passive Firewall is System and Configuration logs. If this log is being sent by syslog out to your server, then as a next thing I would be looking into packet capture to see what side is closing connection.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.
  • 8573 Views
  • 3 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!