Network Management

Inaccurate RTCD Email Received after executing Palo Alto Configuration Change in Log Analyzer

This article discusses being able to receive an inaccurate or one-action delay in RTCD emails from Palo Alto devices configuration change when using a Log Analyzer.

First published date

9/29/2022 8:07 AM

Last published date

9/29/2022 8:28 AM

Overview

This article discusses when a configuration has been made on the Palo Alto device and commit been done. Still, the RTCD email includes the configuration before the change has been made, making it a one-action delay RTCD email. It is commonly encountered on Palo Alto 3200 devices, and a Log Analyzer is used.

Product section

Network Configuration Manager

Cause

This is caused by only configuring the Palo Alto device to send configuration syslogs to Solarwinds and not including system syslogs.

Resolution

On the Palo Alto side, ensure to configure a Solarwinds Server Profile. After configuring a server profile assigned to Solarwinds, configure the device to send out system syslogs. See the steps below:
  • Login to Palo Alto GUI.
  • Proceed to Device > Log Settings > System.
  • Click Add.
  • Enter your preferred name and under Syslog, click Add.
  • Select the Solarwinds server profile.
    • image.png
  • Click OK.
  • Click Commit to apply changes.
Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment.  You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.

On SolarWinds side, after enabling Real-Time Change Detection notification emails and creating a Syslog rule in Log Analyzer, configure the message filter as below:
  • Browse to the Syslog rule created under Alerts & Activity > Syslogs > Settings.
  • Click on the Syslog rule created. 
  • Click Edit.
  • Click Next.
  • Under rule conditions, click This rule fires while the following conditions apply and the message contains "Commit job succeeded." See the screenshot below:
    • image.png
  • Click Next and Save.
Upon clicking commit on Palo Alto side, it is expected to receive the latest configuration change in the RTCD email.