How to Forward Traffic Logs to Syslog Server Labels
09-26-2012 12:19 AM (16,199 Views)

Labels: Configuration, Logs
Forwarding traffic logs to a syslog server requires four steps
Create a syslog server profile
Use the log forwarding profile in the security rules
Syslog server profile Decryption (3)
Go to Device > Server Profiles > Syslog
Name: Name of the syslog server
Port: Default port 514
Log forwarding profile Go to Objects > Log forwarding Select the syslog server profile for forwarding traffic logs to the configured server. Panorama (40)

Security Rule Go to Policies > Security Rule Select the rule for which the log forwarding needs to be applied. Go to Actions > Log forwarding and select the log
forwarding profile from drop down list.

How to Setup Log Forwarding From Log Collector To ... How to Forward Firewall Logs

Comments

by edwinchristopher on ​09-04-2013 03:14 AM
those steps i know ..but my question is does palo alto support syslog over tcp?

by kfindlen on ​09-04-2013 08:14 AM
Syslog over TCP is not currently supported, however, is there a guide to parsing the sys logs, and what categories they are all in so admins can decide which to alert on. For alertings there are severity levels for both system and threat logs. I would also review the CEF(Common event format) log format as it has some information that is useful even though your using Documentation

by rivkin on ​05-16-2014 07:53 AM
I have configured third party syslog server to receive traffic log.. it was found that the time zone is different between PA console and Syslog server console. will it send the GMT time zone log to syslog rather than configured time zone? How to configure it? Thanks!

by timothyyip on ​07-17-2014 12:30 AM
is there a way to do this for all rules at once, or does it have to be applied one at a time?  If so, a feature request to be able to apply to multiple at once would be nice.

by jkim2 on ​07-17-2014 04:30 AM
Easiest way to set logging options on all rules is to export the config in set format, add the log parameters then add it back in, should take only a few minutes.

by jkim2 on ​07-17-2014 04:32 AM
Upgrade to 6.0 it supports SSL & TCP custom ports :smileyhappy:

Copyright 2007-2016 Palo Alto Networks Privacy Policy Terms of Use