Hi,
I followed this post the other day and have been forwarding logs from my firewall for 2 days now, but without any hits, so I am wondering if I have done something wrong? I can see in a tcpdump dump on the minemeld server, that logs are received on port 13514/TCP. Also, the logs that are sent to minemeld are dropped traffic from an EDL, so the indicators should be present.
https://live.paloaltonetworks.com/t5/MineMeld-Articles/Correlating-PAN-OS-syslog-with-indicators/ta-p/72078
I am using the stdlib.localSyslog prototype, as I just want to know whits lists I hit.
Any ideas on how to troubleshoot this?
I'm using:
PAN-OS 8.0.3-h4
Minemeld v 0.9.40
... View more