PA Web Proxy has more than syslog / logs on current PA FW

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

PA Web Proxy has more than syslog / logs on current PA FW

L1 Bithead

Dear PA team,

 

PA Firewall and PA Web proxy are integration with SIEM.

 

Before:

When my PC run though connecting on PA firewall has only 1 log ( End Traffic , Deny Access, Permit...) for each session.

 

Example:

        1.  Traffic End -> Feb 2, 2025, 10:15:00 AM

 

Now:

When my PC point connectivity to PA Proxy there have 2 or more for each session.

 

Example: Duplicate logs

           1. Traffic End -> Feb 2, 2025, 10:15:00 AM

           2. Traffic End -> Feb 2, 2025, 10:15:00 AM

 

On Proxy where Security Policy we defined Allow User to proxy and Allow Proxy to Internet.

 

We concern with SIEM consumption resource performance and licensing cost. When has more logs on PA Web proxy.

 

Do we have solution to fix this case? To ensure it has as same as log on PA FW for each session.

 

Thanks,

 

 

 

 

 

1 REPLY 1

L6 Presenter

Hey @Kakada_Sao16 , Please keep in mind that this is a tech forum and most of solutions come from not directly working professionals for Palo Alto that assist each other in the best way possible. What you have seems like a design issue as having a rule for Proxy To Internet seems strange as you are allowing your PA firewall/Proxy to talk to Internet as a user for me if going to internet should match 1 rule if allowed/blocked based better on a AD group 🤔  The only way to match 2 rules for me if you have the so called proxy to internet rule before the client rule and there to be the so called "appshift"  as maybe the first rules matches all web browser traffic and then the application gets detected which is bad design How to Prevent Application Shift - Knowledge Base - Palo Alto Networks

 

I suggest involving Palo Alto Professional Services (PS) or a partner company as this will also probably be outside the scope of the Palo Alto Support TAC team to assist you with.

  • 208 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!