<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Broker VM || SYSLOG APPLET in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-syslog-applet/m-p/1240221#M8805</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190764"&gt;@eluis&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Iam trying to get the logs of linux server , the unknown_unknown_raw data set itself not getting created.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;2. For IBM guardium log are configured to send in leef format&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PBalan_0-1760687684538.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/69614i115B12B9683B4272/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PBalan_0-1760687684538.png" alt="PBalan_0-1760687684538.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PBalan_1-1760687738380.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/69615i49D01743CF89EE22/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PBalan_1-1760687738380.png" alt="PBalan_1-1760687738380.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Oct 2025 07:56:06 GMT</pubDate>
    <dc:creator>P.Balan</dc:creator>
    <dc:date>2025-10-17T07:56:06Z</dc:date>
    <item>
      <title>Broker VM || SYSLOG APPLET</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-syslog-applet/m-p/1240124#M8798</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have deployed broker vm and enabled syslog applet and configured the broker vm ip as remote host in one of our linux server and IBM guardium database activity monitoring tool but we are unable to see the logs in the console.&lt;BR /&gt;&lt;BR /&gt;unkonwn_unknown_raw data not getting created , but when checked tcp dump in broker vm log received by the broker vm.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;kindly let us know how to torubleshoot the issus&lt;/P&gt;</description>
      <pubDate>Thu, 16 Oct 2025 06:29:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-syslog-applet/m-p/1240124#M8798</guid>
      <dc:creator>P.Balan</dc:creator>
      <dc:date>2025-10-16T06:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: Broker VM || SYSLOG APPLET</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-syslog-applet/m-p/1240166#M8802</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1227665047"&gt;@P.Balan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If your log sources are able to produce LEEF or CEF logs, please configure such.&amp;nbsp;&lt;BR /&gt;Broker vm syslog applet will identify the vendor and will store the logs at a dataset with the vendor and model name of the device. It might be what is happening and you are looking to the wrong dataset =?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If Broker is receiving logs, it should store them. Everyting that is not known will go to unknown_unknown _raw dataset what can create a mix of many different log sources altogether&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;Luis&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Oct 2025 15:42:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-syslog-applet/m-p/1240166#M8802</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2025-10-16T15:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: Broker VM || SYSLOG APPLET</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-syslog-applet/m-p/1240221#M8805</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190764"&gt;@eluis&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Iam trying to get the logs of linux server , the unknown_unknown_raw data set itself not getting created.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;2. For IBM guardium log are configured to send in leef format&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PBalan_0-1760687684538.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/69614i115B12B9683B4272/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PBalan_0-1760687684538.png" alt="PBalan_0-1760687684538.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PBalan_1-1760687738380.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/69615i49D01743CF89EE22/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PBalan_1-1760687738380.png" alt="PBalan_1-1760687738380.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2025 07:56:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-syslog-applet/m-p/1240221#M8805</guid>
      <dc:creator>P.Balan</dc:creator>
      <dc:date>2025-10-17T07:56:06Z</dc:date>
    </item>
    <item>
      <title>Re: Broker VM || SYSLOG APPLET</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-syslog-applet/m-p/1240306#M8808</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1227665047"&gt;@P.Balan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If LEEF / CEF is working properly, you should get the IBM product and model identified so the dataset name should be like:&lt;BR /&gt;IBM_IbmDeviceProductModel_raw&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check if in cogwheel settings configuration dataset management you have something like that. Even if the logs are not parsed, they should be put into unknown_unknown_raw&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Might be that IBM is sending logs not in LEEF ? can you try with CEF ? Both formats should be parsed since are standard logs we understand. = Issue at IBM side generating log in those formats?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If not open a TAC support case since this is a bug-fix that needs to be handled&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;Luis&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Oct 2025 14:19:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-syslog-applet/m-p/1240306#M8808</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2025-10-20T14:19:05Z</dc:date>
    </item>
  </channel>
</rss>

