| Next revision | Previous revision |
| paloaltonetworks:logs:syslog:routing [2020/06/04 07:47] – created bstafford | paloaltonetworks:logs:syslog:routing [2022/11/23 12:49] (current) – external edit 127.0.0.1 |
|---|
| |
| ===== Critical ====== | ===== Critical ====== |
| <code>( subtype eq vpn ) and ( severity eq critical )</code> | <code>( subtype eq routing ) and ( severity eq critical )</code> |
| <code>( eventid eq path-monitor-failure ) and ( object eq default ) and ( description contains 'Path monitoring failed for static route destination 10.0.0.0/8 with next hop 0.0.0.0. Route removed.' )</code> | <code>( eventid eq path-monitor-failure ) and ( object eq default ) and ( description contains 'Path monitoring failed for static route destination 10.0.0.0/8 with next hop 0.0.0.0. Route removed.' )</code> |
| <code>( eventid eq path-monitor-recovery ) and ( object eq default ) and ( description contains 'Path monitoring for static route destination 10.0.0.0/8 with next hop 0.0.0.0 recovered. Route restored.' )</code> | <code>( eventid eq path-monitor-recovery ) and ( object eq default ) and ( description contains 'Path monitoring for static route destination 10.0.0.0/8 with next hop 0.0.0.0 recovered. Route restored.' )</code> |
| |
| ===== High ====== | ===== High ====== |
| <code>( subtype eq vpn ) and ( severity eq high )</code> | <code>( subtype eq routing ) and ( severity eq high )</code> |
| <code>( eventid eq routed-BGP-peer-left-established ) and ( object eq name-of-vr ) and ( description contains 'BGP peer session left established state.peer name: name-of-peer, peer IP: 169.254.42.5.' ) [PAN-OS 9.0] | <code>( eventid eq routed-OSPF-neighbor-down ) and ( object eq name-of-vr ) and ( description contains 'OSPF adjacency with neighbor has gone down. interface ae1.2, neighbor router ID 10.1.1.1, neighbor IP address 10.2.2.2.' )</code> |
| <code>( eventid eq routed-BGP-peer-left-established ) and ( object eq name-of-vr ) and ( description contains 'BGP peer session left established state. peer IP: 10.8.8.4.' ) [PAN-OS 8.1] | PAN-OS 9.0 |
| <code>( eventid eq routed-OSPF-neighbor-down ) and ( object eq name-of-vr ) and ( description contains 'OSPF adjacency with neighbor has gone down. interface ae1.3013, neighbor router ID 10.0.0.4, neighbor IP address 172.23.68.195.' )</code> | <code>( eventid eq routed-BGP-peer-left-established ) and ( object eq name-of-vr ) and ( description contains 'BGP peer session left established state.peer name: name-of-peer, peer IP: 169.254.11.11.' ) </code> |
| | PAN-OS 8.1 |
| | <code>( eventid eq routed-BGP-peer-left-established ) and ( object eq name-of-vr ) and ( description contains 'BGP peer session left established state. peer IP: 10.1.1.1.' )</code> |
| | |
| ===== Low ====== | ===== Low ====== |
| <code>( subtype eq vpn ) and ( severity eq low )</code> | <code>( subtype eq routing ) and ( severity eq low )</code> |
| <code>( eventid eq routed-BGP-peer-failed ) and ( object eq name-of-vr ) and ( description contains 'BGP peer session has failed and may restart. peer name: name-of-peer. peer IP: 169.254.250.20.' )</code> | <code>( eventid eq routed-BGP-peer-failed ) and ( object eq name-of-vr ) and ( description contains 'BGP peer session has failed and may restart. peer name: name-of-peer. peer IP: 169.254.11.11.' )</code> |
| <code>( eventid eq routed-BGP-peer-restarted ) and ( object eq name-of-vr ) and ( description contains 'Initiated graceful-restart with a BGP peer. peer name: name-of-peer. peer IP: 9.9.9.9.' )</code> | <code>( eventid eq routed-BGP-peer-restarted ) and ( object eq name-of-vr ) and ( description contains 'Initiated graceful-restart with a BGP peer. peer name: name-of-peer. peer IP: 9.9.9.9.' )</code> |
| <code>( eventid eq routed-BGP-peer-restart-failed ) and ( object eq name-of-vr ) and ( description contains 'Graceful-restart with a BGP peer failed. peer name: name-of-peer. peer IP: 169.254.250.20, AFI/SAFI: 1/1.' )</code> | <code>( eventid eq routed-BGP-peer-restart-failed ) and ( object eq name-of-vr ) and ( description contains 'Graceful-restart with a BGP peer failed. peer name: name-of-peer. peer IP: 169.254.11.11, AFI/SAFI: 1/1.' )</code> |
| <code>( eventid eq routed-config-p1-failed ) and ( description contains 'Route daemon configuration load phase-1 failed.' )</code> | <code>( eventid eq routed-config-p1-failed ) and ( description contains 'Route daemon configuration load phase-1 failed.' )</code> |
| |
| ===== Informational ====== | ===== Informational ====== |
| <code>( subtype eq vpn ) and ( severity eq informational )</code> | <code>( subtype eq routing ) and ( severity eq informational )</code> |
| <code>( eventid eq routed-fib-sync-self-master ) and ( description contains 'FIB HA sync started when local device becomes master.' )</code> | <code>( eventid eq routed-fib-sync-self-master ) and ( description contains 'FIB HA sync started when local device becomes master.' )</code> |
| |
| |
| <code>( eventid eq routed-config-p1-success ) and ( description contains 'Route daemon configuration load phase-1 succeeded.' )</code> | <code>( eventid eq routed-config-p1-success ) and ( description contains 'Route daemon configuration load phase-1 succeeded.' )</code> |
| <code>( eventid eq routed-config-p2-success ) and ( description contains 'Route daemon configuration load phase-2 succeeded.' )</code> | <code>( eventid eq routed-config-p2-success ) and ( description contains 'Route daemon configuration load phase-2 succeeded.' )</code> |
| <code>( eventid eq routed-BGP-peer-enter-established ) and ( object eq name-of-vr ) and ( description contains 'BGP peer session enters established state. peer name: BACKUP_US_PALO, peer IP: 169.254.250.40.' )</code> | <code>( eventid eq routed-BGP-peer-enter-established ) and ( object eq name-of-vr ) and ( description contains 'BGP peer session enters established state. peer name: BACKUP_US_PALO, peer IP: 169.254.11.11.' )</code> |
| <code>( eventid eq routed-BGP-refresh-sent ) and ( object eq name-of-vr ) and ( description contains 'ROUTE REFRESH message sent to a BGP peer. peer name: peer-eu-vpc-security-t1, peer IP: 169.254.201.69, AFI/SAFI: 1/1.' )</code> | <code>( eventid eq routed-BGP-refresh-sent ) and ( object eq name-of-vr ) and ( description contains 'ROUTE REFRESH message sent to a BGP peer. peer name: peer-fw01, peer IP: 169.254.11.11, AFI/SAFI: 1/1.' )</code> |
| <code>( eventid eq routed-daemon-init ) and ( description contains 'Route daemon is initializing.' )</code> | <code>( eventid eq routed-daemon-init ) and ( description contains 'Route daemon is initializing.' )</code> |
| <code>( eventid eq routed-daemon-start ) and ( description contains 'Route daemon is ready.' )</code> | <code>( eventid eq routed-daemon-start ) and ( description contains 'Route daemon is ready.' )</code> |
| <code>( eventid eq routed-config-p2-success ) and ( description contains 'Route daemon configuration load phase-2 succeeded.' )</code> | <code>( eventid eq routed-config-p2-success ) and ( description contains 'Route daemon configuration load phase-2 succeeded.' )</code> |
| <code>( eventid eq routed-config-p1-abort ) and ( description contains 'Route daemon configuration load phase-1 aborted.' )</code> | <code>( eventid eq routed-config-p1-abort ) and ( description contains 'Route daemon configuration load phase-1 aborted.' )</code> |
| <code>( eventid eq routed-BGP-peer-enter-established ) and ( object eq name-of-vr ) and ( description contains 'BGP peer session enters established state. peer IP: 10.8.8.3.' )</code> | <code>( eventid eq routed-BGP-peer-enter-established ) and ( object eq name-of-vr ) and ( description contains 'BGP peer session enters established state. peer IP: 10.1.1.1.' )</code> |
| <code>( eventid eq routed-fib-sync-self-master ) and ( description contains 'FIB HA sync started when local device becomes master.' )</code> | <code>( eventid eq routed-fib-sync-self-master ) and ( description contains 'FIB HA sync started when local device becomes master.' )</code> |
| <code>( eventid eq routed-OSPF-neighbor-2dir ) and ( object eq name-of-vr ) and ( description contains 'OSPF two-way communication established with neighbor. interface ae2.3023, neighbor router ID 10.8.8.10, neighbor IP address 10.23.68.197.' )</code> | <code>( eventid eq routed-OSPF-neighbor-2dir ) and ( object eq name-of-vr ) and ( description contains 'OSPF two-way communication established with neighbor. interface ae2.1, neighbor router ID 10.8.8.10, neighbor IP address 10.1.1.1.' )</code> |
| <code>( eventid eq routed-OSPF-neighbor-full ) and ( object eq name-of-vr ) and ( description contains 'OSPF full adjacency established with neighbor. interface ae2.2023, neighbor router ID 10.8.8.1, neighbor IP address 10.23.64.196.' )</code> | <code>( eventid eq routed-OSPF-neighbor-full ) and ( object eq name-of-vr ) and ( description contains 'OSPF full adjacency established with neighbor. interface ae2.1, neighbor router ID 10.2.2.2, neighbor IP address 10.1.1.1.' )</code> |
| <code>( eventid eq routed-BGP-peer-mp-extension-negotiate ) and ( object eq name-of-vr ) and ( description contains 'BGP peer MP extension negotiation. MP-EXTENSION negotiation to peer 10.8.8.3 successful, AFI/SAFI 1/1' )</code> | <code>( eventid eq routed-BGP-peer-mp-extension-negotiate ) and ( object eq name-of-vr ) and ( description contains 'BGP peer MP extension negotiation. MP-EXTENSION negotiation to peer 10.2.2.2 successful, AFI/SAFI 1/1' )</code> |
| <code>( eventid eq routed-BGP-peer-mp-extension-negotiate ) and ( object eq name-of-vr ) and ( description contains 'BGP peer MP extension negotiation. MP-EXTENSION negotiation to peer name: name-of-peer, peer IP: 169.254.250.40 successful, AFI/SAFI 1/1' )</code> | <code>( eventid eq routed-BGP-peer-mp-extension-negotiate ) and ( object eq name-of-vr ) and ( description contains 'BGP peer MP extension negotiation. MP-EXTENSION negotiation to peer name: name-of-peer, peer IP: 169.254.11.11 successful, AFI/SAFI 1/1' )</code> |
| |
| |