Syslog to one or two servers with default and custom log format

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Syslog to one or two servers with default and custom log format

L3 Networker

Hey all, I am wondering if this is possible. I understand this duplicates logging, but hopefully it's short-term.

I need to send syslog to either one server in default and custom log formats or send to two syslog servers one in default and the other in custom log format. It seems like the profile only allows for either default or custom log format, and I can only apply one profile per policy.

Really seems like an either/or situation, but I'm hoping I'm missing something.

 

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@MikeSangray2019,

You can't do this in a single syslog server profile, but that doesn't really matter. I would create one "Syslog-Default" and "Syslog-Custom" and then perform any modifications that you need to on the profile. PAN-OS will allow you to have two profiles with the same syslog server address/fqdn specified, so you can do this on a single server.

You would then modify your log-settings or log-forwarding profiles as needed and simply include both syslog profiles that you have created. This will allow you to see how both would come across and customize as needed. 

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

@MikeSangray2019,

You can't do this in a single syslog server profile, but that doesn't really matter. I would create one "Syslog-Default" and "Syslog-Custom" and then perform any modifications that you need to on the profile. PAN-OS will allow you to have two profiles with the same syslog server address/fqdn specified, so you can do this on a single server.

You would then modify your log-settings or log-forwarding profiles as needed and simply include both syslog profiles that you have created. This will allow you to see how both would come across and customize as needed. 

This worked. Confusion here was around Device -> Server Profiles -> Syslog vs Objects -> Log Forwarding.

  • 1 accepted solution
  • 296 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!