- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-17-2024 11:10 AM - edited 01-17-2024 11:13 AM
I am trying to send Syslog from my PA-440 to a LimaCharlie organization.
This is the setup
PA-400 --Syslog--> Virtual Machine in Azure running Ubuntu with LimaCharlie Adapter --HTTPS--> LimaCharlie.io
This is what I have done in the PA-440
Name: vm-collectorserver-prod
Syslog server: {Public IP from Azure}
Port number: 514
Format: BSD
Facility
I named the profile "LFP-Logs to LimaCharlie".
This is what I have done in Azure
I created a VM with latest Ubuntu Server.
I opened port 514 UDP.
Next I installed LimaCharlie Adapter on it which is working fine:
I tried to send a syslog message to it which came through to the LimaCharlie organization, meaning that the collector server can receive syslog:
logger -p 0 -n 1.2.3.4 "This is only test message ----- remote"
Screenshot from LimaCharlie.io:
Now I am a bit lost.. What should I try next in order to make sure that logs are sent from the Palo Alto firewall to my collector server in Azure?
01-18-2024 01:25 PM
Hello @SoloSigma
I will verify the following:
Check the traffic logs on the Monitor tab to see if any traffic is being denied.
If no traffic logs are found, check the session browser logs (clear the session if needed).
Regards
01-23-2024 01:08 AM
I have checked the traffic logs and all has Action=allow.
01-23-2024 08:59 AM
Can you verify if there is a NAT source IP address for the packets? Also, can you display the columns for bytes sent and bytes received?
Regards
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!