cancel
Showing results for 
Search instead for 
Did you mean: 

Who Me Too'd this topic

Syslogs vs. Traffic Logs in Monitor

L0 Member

Good evening,

 

I am working on a project that requires the use of threat logs and traffic logs of an institution with which I am affiliated. Our security manager can provide me access to our threat logs via the Monitor tab in PAN-OS. However, we are experiencing difficulty finding the traffic logs I need.

 

I am looking for specific traffic logs, including the following features described in Traffic Log Fields:

  • Serial Number
  • Type
  • Threat/Content Type
  • Generate Time
  • Session ID
  • Repeat Count
  • Flags
  • Action
  • Bytes
  • Bytes Sent, Bytes Received
  • Packets, Packets Sent, Packets Received
  • Start Time
  • Elapsed Time
  • Session End Reason
  • Device Name

In conversations with the security manager, he says, "that articles refers to what you can push to syslog.. our logrythm system. Not what you can see on their logs. I am trying to see what else we can view." When I asked for clarification, he stated, "The document you cite is in regards to data sent to syslogs, not what is actually available via our log export on the traffic section of monitor." He isn't sure how or where we can find the aforementioned data features I am looking for.

 

I have two questions:

  1. Is there a relatively easy way for someone who has access to PAN-OS to download traffic log data containing those fields?
  2. What is the difference between the logs in Monitor versus those in the Syslog?
  3. What data is available via log export from the web interface? Can I include the fields in my list above that are missing from the logs he found in the web interface?

Thank you so much for your help. I am brand new to PAN-OS, and my coworker is doing me a favor by getting logs for me, so I want to be sure we can find them before I ask him to look again.

Who Me Too'd this topic