<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="FeedCreator 1.8" -->
<?xml-stylesheet href="https://www.staffordnet.uk/lib/exe/css.php?s=feed" type="text/css"?>
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="https://www.staffordnet.uk/feed.php">
        <title>Saucepan - paloaltonetworks:logs:syslog</title>
        <description></description>
        <link>https://www.staffordnet.uk/</link>
        <image rdf:resource="https://www.staffordnet.uk/lib/exe/fetch.php?media=favicon.ico" />
       <dc:date>2026-04-06T00:40:05+00:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:auth&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:crypto&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:dhcp&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:dnsproxy&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:fips&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:general&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:globalprotect&amp;rev=1675423645&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:ha&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:hw&amp;rev=1669978202&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:iot&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:lacp&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:monitoring&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:ntpd&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:panorama-check&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:port&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:pppoe&amp;rev=1677487627&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:raid&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:ras&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:routing&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:rtsig&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:satd&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:ssh&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:sslmgr&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:summary&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:syslog&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:tls&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:url-filtering&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:userid&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:vpn&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:wildfire&amp;rev=1669207782&amp;do=diff"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="https://www.staffordnet.uk/lib/exe/fetch.php?media=favicon.ico">
        <title>Saucepan</title>
        <link>https://www.staffordnet.uk/</link>
        <url>https://www.staffordnet.uk/lib/exe/fetch.php?media=favicon.ico</url>
    </image>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:auth&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>auth</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:auth&amp;rev=1669207782&amp;do=diff</link>
        <description>Auth Syslogs

( auth_method eq Other ) can mean local DB users. 

Critical

( subtype eq auth ) and ( severity eq critical )

( eventid eq auth-server-down ) and ( description contains &#039;3 tries to bind back to binddn failed: basedn: DC=DOMAIN,DC=LOCAL ; binddn: administrator@domain.local ; bind_timelimit 30 ; ip: 10.1.1.10 ; uri: ldap://10.1.1.10:389&#039; )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:crypto&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>crypto</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:crypto&amp;rev=1669207782&amp;do=diff</link>
        <description>Crypto Syslogs

Critical

( subtype eq crypto ) and ( severity eq critical )

( eventid eq private-key-export ) and ( description contains &#039;Private key nameofcert was exported by user admin&#039; )

( eventid eq cert-expiry ) and ( description contains &#039;Shared certificate nameofcert and corresponding key have expired&#039; )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:dhcp&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>dhcp</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:dhcp&amp;rev=1669207782&amp;do=diff</link>
        <description>DHCP Syslogs

Critical

( subtype eq dhcp ) and ( severity eq critical )

( eventid eq if-clear ) and ( object eq &#039;ethernet1/1&#039; ) and ( description contains &#039;DHCP client cleared IP address on interface:ethernet1/1 due to: All Request retries exhausted.&#039; )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:dnsproxy&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>dnsproxy</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:dnsproxy&amp;rev=1669207782&amp;do=diff</link>
        <description>DNS Proxy Syslogs

Informational

( subtype eq dnsproxy ) and ( severity eq informational )

( eventid eq object-enable ) and ( object eq dnsproxyName ) and ( description contains &#039;Dnsproxy object:mgmt-obj was enabled.&#039; )

( eventid eq cache-cleared ) and ( object eq dnsproxyName ) and ( description contains &#039;All DNS Proxy cache entries were cleared&#039; )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:fips&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>fips</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:fips&amp;rev=1669207782&amp;do=diff</link>
        <description>FIPS Syslogs

Informational

( subtype eq fips ) and ( severity eq informational )

( eventid eq fips-selftest-integ ) and ( description contains &#039;Software-integrity self-tests passed.&#039; )

( eventid eq fips-selftest-integ ) and ( description contains &#039;RPMS self-tests passed.&#039; )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:general&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>general</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:general&amp;rev=1669207782&amp;do=diff</link>
        <description>Useful

Commit Description

If the administrator includes a description when commiting, it can be found by filtering

( description contains &#039;Commit job started processing&#039; )

The actuall output will look something like the following. (Yes, there is a space after the username).</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:globalprotect&amp;rev=1675423645&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-02-03T11:27:25+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>globalprotect</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:globalprotect&amp;rev=1675423645&amp;do=diff</link>
        <description>GlobalProtect System Logs (&lt; PAN-OS 9.1)

GP Login/Logout

(( eventid eq gateway-connected ) or ( eventid eq gateway-logout ))

(( eventid eq gateway-connected ) or ( eventid eq gateway-logout )) and ( machinename eq GB1LT11111 ) and ( user.src eq jbloggs )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:ha&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>ha</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:ha&amp;rev=1669207782&amp;do=diff</link>
        <description>HA System Logs

Critical

( subtype eq ha ) and ( severity eq critical )

Panorama

( eventid eq connect-change ) and ( description contains &#039;HA1 connection down&#039; )

Firewall

( eventid eq dataplane-down ) and ( description contains &#039;HA Group 1: Dataplane is down: too many dataplane processes exited&#039; )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:hw&amp;rev=1669978202&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-12-02T10:50:02+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>hw</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:hw&amp;rev=1669978202&amp;do=diff</link>
        <description>Hardware Syslogs

Critical

( subtype eq hw ) and ( severity eq critical )

( eventid eq fan-fai ) and ( description contains &#039;Alarm on Fan #4 RPM&#039; )

( eventid eq bootstrap-media-detect ) and ( description contains &#039;Media detect failed due to internal error&#039; )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:iot&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>iot</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:iot&amp;rev=1669207782&amp;do=diff</link>
        <description>IoT Syslogs

High

( subtype eq iot ) and ( severity eq high)

( eventid eq icd-ha-status ) and ( description contains &#039;Icd HA state is changed from 0 to 1 time: 2021-03-27 18:41:52&#039; )

( eventid eq icd-ha-status ) and ( description contains &#039;Icd HA state is changed from 1 to 0 time: 2021-03-27 18:25:43&#039; )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:lacp&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>lacp</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:lacp&amp;rev=1669207782&amp;do=diff</link>
        <description>LACP Syslog

Critical

( subtype eq lacp ) and ( severity eq critical )

( eventid eq unresponsive ) and ( object eq &#039;ethernet1/12&#039; ) and ( description contains &#039;LACP interface ethernet1/12 moved out of AE-group ae2(peer is not responding to new LACP connection)&#039; )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:monitoring&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>monitoring</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:monitoring&amp;rev=1669207782&amp;do=diff</link>
        <description>Monitoring Syslogs

These logs are on Panorama only. They should also exist on the firewall but they will be classed under

( subtype eq general) and ( severity eq informational )

Informational

( subtype eq monitoring) and ( severity eq informational )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:ntpd&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>ntpd</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:ntpd&amp;rev=1669207782&amp;do=diff</link>
        <description>NTP Syslog

Medium

( subtype eq ntpd ) and ( severity eq medium )

( eventid eq auth ) and ( description contains &#039;NTP sync to server 192.168.1.1 failed, authentication type none&#039; )

Informational

( subtype eq ntpd ) and ( severity eq informational )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:panorama-check&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>panorama-check</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:panorama-check&amp;rev=1669207782&amp;do=diff</link>
        <description>Panorama Check Syslogs</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:port&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>port</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:port&amp;rev=1669207782&amp;do=diff</link>
        <description>Port Syslog

High

( subtype eq port ) and ( severity eq high )

( eventid eq link-change ) and ( object eq MGT ) and ( description contains &#039;Port MGT: Down 1Gb/s   Full duplex&#039; )

Medium

I&#039;ve seen this on a PA-850 that has SFP+ enabled on ports 9-12 and had a DAC SFP+ cable installed. Not sure what cause this message.</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:pppoe&amp;rev=1677487627&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-02-27T08:47:07+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>pppoe</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:pppoe&amp;rev=1677487627&amp;do=diff</link>
        <description>PPPoE Syslog

Informational

( subtype eq pppoe ) and ( severity eq informational )

( eventid eq initiate ) and ( description contains &#039;PPPoE session was initiated for user:username@isp on interface:ethernet1/1&#039; )

( eventid eq connect ) and ( description contains &#039;PPPoE session was connected for user:username@isp on interface:ethernet1/1 to AC:BNG5.TGN-NYK-RA0, mac address: cc:cc:11:ee:bb:ff, session id:4, IP Address negotiated:1.2.3.4&#039; )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:raid&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>raid</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:raid&amp;rev=1669207782&amp;do=diff</link>
        <description>RAID Syslogs

Critical

( subtype eq raid ) and ( severity eq critical )

( eventid eq pair-disappeared ) and ( description contains &#039;Disk Pair A disappeared.&#039; )

Medium

( subtype eq raid ) and ( severity eq medium )

( eventid eq pair-degraded ) and ( description contains &#039;Disk Pair A is degraded and missing a device.&#039; )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:ras&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>ras</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:ras&amp;rev=1669207782&amp;do=diff</link>
        <description>RAS Syslog

Informational

( subtype eq ras ) and ( severity eq informational )

( eventid eq rasmgr-config-p1-success ) and ( description contains &#039;RASMGR daemon configuration load phase-1 succeeded.&#039; )

( eventid eq rasmgr-config-p2-success ) and ( description contains &#039;RASMGR daemon configuration load phase-2 succeeded.&#039; )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:routing&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>routing</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:routing&amp;rev=1669207782&amp;do=diff</link>
        <description>Routing System Logs

Critical

( subtype eq routing ) and ( severity eq critical )

( eventid eq path-monitor-failure ) and ( object eq default ) and ( description contains &#039;Path monitoring failed for static route destination 10.0.0.0/8 with next hop 0.0.0.0. Route removed.&#039; )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:rtsig&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>rtsig</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:rtsig&amp;rev=1669207782&amp;do=diff</link>
        <description>RTSIG Syslogs

These logs are for the connection between PAN-OS and the DNS Security cloud service.

Medium

( subtype eq rtsig ) and ( severity eq medium )

( eventid eq cloud-fail-refused ) and ( object eq dns-signature ) and ( description contains &#039;dns-signature cloud service connection refused.&#039; )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:satd&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>satd</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:satd&amp;rev=1669207782&amp;do=diff</link>
        <description>SATD Syslog

Informational

( subtype eq satd ) and ( severity eq informational )

( eventid eq satd-config-p1-success ) and ( description contains &#039;SATD daemon configuration load phase-1 succeeded.&#039; )

( eventid eq satd-config-p2-success ) and ( description contains &#039;SATD daemon configuration load phase-2 succeeded.&#039; )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:ssh&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>ssh</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:ssh&amp;rev=1669207782&amp;do=diff</link>
        <description>SSH Syslog

Medium

( subtype eq ssh ) and ( severity eq medium )

( eventid eq ssh-session-establishment-failed ) and ( description contains &#039;Protocol major versions differ for 192.168.1.1: SSH-2.0-OpenSSH_12.1 vs. SSH-1.5-Nmap-SSH1-Hostkey.&#039; )

( eventid eq ssh-session-establishment-failed ) and ( description contains &#039;Protocol major versions differ for 192.168.1.1: SSH-2.0-OpenSSH_12.1 vs. SSH-1.5-NmapNSE_1.0.&#039; )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:sslmgr&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>sslmgr</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:sslmgr&amp;rev=1669207782&amp;do=diff</link>
        <description>SSLMGR Syslog

Informational

( subtype eq sslmgr ) and ( severity eq informational )

( eventid eq sslmgr-config-p1-success ) and ( description contains &#039;SSLMGR daemon configuration load phase-1 succeeded.&#039; )

( eventid eq sslmgr-config-p2-success ) and ( description contains &#039;SSLMGR daemon configuration load phase-2 succeeded.&#039; )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:summary&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>summary</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:summary&amp;rev=1669207782&amp;do=diff</link>
        <description>Syslog Summary

PAN-OS has the following syslog types

	*  ( subtype neq general )
	*  ( subtype neq dnsproxy )
	*  ( subtype neq sslmgr )
	*  ( subtype neq satd )
	*  ( subtype neq ras )
	*  ( subtype neq vpn )
	*  ( subtype neq routing )
	*  ( subtype neq url-filtering )
	*  ( subtype neq auth )
	*  ( subtype neq</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:syslog&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>syslog</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:syslog&amp;rev=1669207782&amp;do=diff</link>
        <description>Syslog Sylogs

High

( subtype eq syslog ) and ( severity eq high )

( eventid eq syslog-conn-status ) and ( description contains &#039;Syslog connection failed to server[\&#039;AF_INET.192.168.1.1:514.\&#039;]&#039; )

( eventid eq syslog-conn-status ) and ( description contains &#039;Syslog connection established to server[\&#039;AF_INET.192.168.1.1:5515.\&#039;]&#039; )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:tls&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>tls</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:tls&amp;rev=1669207782&amp;do=diff</link>
        <description>TLS Syslog

High

PAN let WF cert expire 12th April 2020.

( subtype eq tls ) and ( severity eq high )

( eventid eq tls-X509-validation-failed ) and ( description contains &#039; Public Cloud Server certificate validation failed. Dest Addr: eu-panos.wildfire.paloaltonetworks.com, Reason: certificate has expired&#039; )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:url-filtering&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>url-filtering</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:url-filtering&amp;rev=1669207782&amp;do=diff</link>
        <description>URL Filtering Syslog

Medium

( subtype eq url-filtering ) and ( severity eq medium )

( eventid eq url-cloud-connection-failure ) and ( description contains &#039;CURL ERROR: bind failed with errno 124: Address family not supported by protocol&#039; )

( eventid eq url-cloud-connection-failure ) and ( description contains &#039;CURL ERROR: bind failed with errno 97: Address family not supported by protocol&#039; )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:userid&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>userid</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:userid&amp;rev=1669207782&amp;do=diff</link>
        <description>User-ID Syslogs

Critical

( subtype eq userid ) and ( severity eq critical )

( eventid eq registered-ip-max-platform-limit-exceeded ) and ( description contains &#039;max registered-ip for the platform reached (1000)&#039; )

High

( subtype eq userid ) and ( severity eq high )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:vpn&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>vpn</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:vpn&amp;rev=1669207782&amp;do=diff</link>
        <description>VPN Syslog Messages

( subtype eq vpn )

Critical

( subtype eq vpn ) and ( severity eq critical )

( eventid eq tunnel-status-up ) and ( object eq IPSEC_TUN_NAME ) and ( description contains &#039;Tunnel IPSEC_TUN_NAME is down&#039; )

( eventid eq tunnel-status-down ) and ( object eq IPSEC_TUN_NAME ) and ( description contains &#039;Tunnel IPSEC_TUN_NAME is down&#039; )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:wildfire&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wildfire</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:logs:syslog:wildfire&amp;rev=1669207782&amp;do=diff</link>
        <description>WildFire Syslogs

Critical

This happened when Palo Alto Networks let their wildfire certificate expire in early 2020.

( subtype eq wildfire ) and ( severity eq critical )

( eventid eq wildfire-auth-failed ) and ( description contains &#039;Validation of Local client certificate failed resulting in error 58, Problem with the local SSL certificate&#039; )</description>
    </item>
</rdf:RDF>
