<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Expedition Panorama Log Collector Forwarding - ML-Learning in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/487883#M3991</link>
    <description>&lt;P&gt;Are you not seeing the log saved in /palogs/{yourpanoramaIP}/ folder ?&lt;/P&gt;</description>
    <pubDate>Tue, 17 May 2022 16:26:38 GMT</pubDate>
    <dc:creator>lychiang</dc:creator>
    <dc:date>2022-05-17T16:26:38Z</dc:date>
    <item>
      <title>Expedition Panorama Log Collector Forwarding - ML-Learning</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/486333#M3979</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have setup expedition as an rsyslog server and configured the Panorama Log collector to forward traffic logs to the expedtion server.&lt;/P&gt;
&lt;P&gt;(for now i am filtering on panaorma to filter on only the device logs I am currently interested in)&lt;/P&gt;
&lt;P&gt;The logs are all collected inside a single file under the folder&lt;/P&gt;
&lt;P&gt;/palogs/panoramip/daily_log.csv.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have imported panorama inside Expedition.&amp;nbsp; My firewalls have global defined policies for all devices inside the device group an specific firewall rules depending on location.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The global firewall policy has rules that have an any in the source and I would like to create more specific rules for the location.&lt;/P&gt;
&lt;P&gt;Since all traffic logs for all devices are in a single file right now I do not know if this is possible.&lt;/P&gt;
&lt;P&gt;Some question I have,&amp;nbsp; where do i have to enable the M-Learning on the panorama device or on the firewall device itself?&lt;/P&gt;
&lt;P&gt;Will expedition be able to make difference between logs comming from Location1 and Location2, both have the same rule but source traffic will be different.&lt;/P&gt;
&lt;P&gt;Is there a way to create seperate log files per device, I think you will have to do this in the rsyslog file.&lt;/P&gt;
&lt;P&gt;So I want a different log analysis per device group for the same rule.&lt;/P&gt;
&lt;P&gt;Hoping this explains a little bit what I want to achieve if not don't hesitate to aks for more info, screenshot, logs, ...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 11:43:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/486333#M3979</guid>
      <dc:creator>zGomez</dc:creator>
      <dc:date>2022-05-11T11:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition Panorama Log Collector Forwarding - ML-Learning</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/486409#M3981</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/211799"&gt;@zGomez&lt;/a&gt;&amp;nbsp;To answer your questions:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Where do i have to enable the M-Learning on the panorama device or on the firewall device itself?&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;You will retrieve all devices from Panorama device tab ,and when you click on right upper corner icon "show all devices" , you will see all firewall devices thats managed by the panorama, and go to the specific firewall device , click on "M. Learning" tab , and process the logs there.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Will expedition be able to make difference between logs coming from Location1 and Location2, both have the same rule but source traffic will be different.&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;ML will analyze the logs based on serial number of the device , so if you only want to analyze specific device, you can define that in the "log connector" that only select the specific firewall under specific Device Group.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Is there a way to create separate log files per device, I think you will have to do this in the rsyslog file.&lt;/P&gt;
&lt;P&gt;So I want a different log analysis per device group for the same rule.&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;When you make the Expedition as syslog server, it should automatically create separate folder based on firewall IP to contain logs that came from separate firewall devices.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;For any questions related ML Process, I would suggest you to review the tutorial video here:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;A href="https://www.youtube.com/playlist?list=PLD6FJ8WNiIqXAfspousboWn6AllrOWVMi" target="_blank"&gt;https://www.youtube.com/playlist?list=PLD6FJ8WNiIqXAfspousboWn6AllrOWVMi&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;Module 4 will show you how to import logs from firewall includes making Expedition as syslog server&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 16:47:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/486409#M3981</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2022-05-11T16:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition Panorama Log Collector Forwarding - ML-Learning</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/486696#M3982</link>
      <description>&lt;P&gt;Hi Lychiang,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your feedback.&lt;/P&gt;
&lt;P&gt;I have setup expedition as syslog server but i am fowarding traffic logs from panorama not with a log profile on the firewall's itself.&amp;nbsp; Since all log are already forwarded to Panorama I am using this approach.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So I have a single log file with all traffic logs from all devices.&amp;nbsp; But indeed I can see the log files includes the serial number of the device so maybe not an issue that I have a single file.&lt;/P&gt;
&lt;P&gt;I will have to play with the log collector and see the outcome of this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 08:58:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/486696#M3982</guid>
      <dc:creator>zGomez</dc:creator>
      <dc:date>2022-05-12T08:58:02Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition Panorama Log Collector Forwarding - ML-Learning</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/487781#M3990</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I have my syslog setup to receive traffic logs from panorama device that forwarding me all firewall logs of my managed devices.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The objective is to create a seperate log file based on the firewall hostname include in the log files( important not the same as the sending hostname, ip of the logs)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Example log file:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;2022-05-16T14:26:01+00:00 PANORAMA 1,2022/05/16 14:26:01,012001050280,TRAFFIC,end,2049,2022/05/16 14:25:57,10.51.10.8,10.52.2.1,0.0.0.0,0.0.0.0,MPLS ,,,snmpv1,vsys1,VPN,trust,tunnel.2001,ethernet1/2.900,LogToPanorama,2022/05/16 14:25:57,76592,1,58824,161,0,0,0x4019,udp,allow,16 90,785,905,18,2022/05/16 14:25:25,1,any,0,578843949,0x8000000000000000,10.0 .0.0-10.255.255.255,10.0.0.0-10.255.255.255,0,9,9,aged-out,29,3090,3092,0,,FIREWALLNAME,from-policy,,,0,,0,,N/A,0,0,0,0,,0,0,,,,,,,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This is currenlty in my syslog file.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;$template DynaTrafficLog,"/palogs/%FROMHOST-IP%/%HOSTNAME%_traffic_%$YEAR%_%$MONTH%_%$DAY%_last_ca lendar_day.csv"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;*.* -?DynaTrafficLog&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Anybody that can help on configuring syslog for this?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2022 12:06:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/487781#M3990</guid>
      <dc:creator>zGomez</dc:creator>
      <dc:date>2022-05-17T12:06:46Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition Panorama Log Collector Forwarding - ML-Learning</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/487883#M3991</link>
      <description>&lt;P&gt;Are you not seeing the log saved in /palogs/{yourpanoramaIP}/ folder ?&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2022 16:26:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/487883#M3991</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2022-05-17T16:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition Panorama Log Collector Forwarding - ML-Learning</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/488756#M3995</link>
      <description>&lt;P&gt;Yes i receive the logs that is not the issue.&lt;/P&gt;
&lt;P&gt;I have my syslog setup to receive traffic logs from panorama device that forwarding me all firewall logs of my managed devices.&lt;BR /&gt;The objective is to create a seperate log file based on the firewall hostname include in the log files( important not the same as the sending hostname, ip of the logs)&lt;BR /&gt;&lt;BR /&gt;Example log file:&lt;BR /&gt;2022-05-16T14:26:01+00:00 PANORAMA 1,2022/05/16 14:26:01,012001050280,TRAFFIC,end,2049,2022/05/16 14:25:57,10.51.10.8,10.52.2.1,0.0.0.0,0.0.0.0,MPLS ,,,snmpv1,vsys1,VPN,trust,tunnel.2001,ethernet1/2.900,LogToPanorama,2022/05/16 14:25:57,76592,1,58824,161,0,0,0x4019,udp,allow,16 90,785,905,18,2022/05/16 14:25:25,1,any,0,578843949,0x8000000000000000,10.0 .0.0-10.255.255.255,10.0.0.0-10.255.255.255,0,9,9,aged-out,29,3090,3092,0,,FIREWALLNAME,from-policy,,,0,,0,,N/A,0,0,0,0,,0,0,,,,,,,&lt;BR /&gt;&lt;BR /&gt;This is currenlty in my syslog file.&lt;BR /&gt;&lt;BR /&gt;$template DynaTrafficLog,"/palogs/%FROMHOST-IP%/%HOSTNAME%_traffic_%$YEAR%_%$MONTH%_%$DAY%_last_ca lendar_day.csv"&lt;BR /&gt;*.* -?DynaTrafficLog&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;This stores the files in /palogs/IP-address/panorama_date_.csv&lt;BR /&gt;&lt;BR /&gt;All traffic logs will be in the same file. I want seperate logs based on FIREWALLNAME (column 53 in the log line) this can be different values.&lt;BR /&gt;I could do this using if msg contains "FIREWALLNAME" but this is not really dynamic and hard to keep up with.&lt;BR /&gt;Can i do this using template?&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2022 07:55:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/488756#M3995</guid>
      <dc:creator>zGomez</dc:creator>
      <dc:date>2022-05-20T07:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition Panorama Log Collector Forwarding - ML-Learning</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/488970#M3996</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/211799"&gt;@zGomez&lt;/a&gt;&amp;nbsp;, What is the purpose to separate&amp;nbsp;logs based on the firewall IP,&amp;nbsp; if you want to only do ML on specific firewall log, you can define log connector in the project that only select that specific firewall, then expedition will only do ML on the device that's defined in the log connector .&amp;nbsp; For example , you can only select specific firewall in DG1 like below screenshot&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2022-05-20 at 8.31.18 AM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41087iC0738A38E1CBC96F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2022-05-20 at 8.31.18 AM.png" alt="Screen Shot 2022-05-20 at 8.31.18 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2022 15:32:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/488970#M3996</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2022-05-20T15:32:42Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition Panorama Log Collector Forwarding - ML-Learning</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/489775#M4000</link>
      <description>&lt;P&gt;Hi Lychiang,&lt;/P&gt;
&lt;P&gt;The issue I am facing is that under the device config M.learning i am not seeing all the files that contain that specific firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Fred1980_0-1653319647589.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41108iD2E1E1934C4C803E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Fred1980_0-1653319647589.png" alt="Fred1980_0-1653319647589.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I only see 1 file the first one created.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there are several files in the directory with the same rights as other file, containg serial and firewallname.&amp;nbsp; i should see 11 files in the above screenshot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Fred1980_1-1653319686304.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41109i127010D8C53DF54F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Fred1980_1-1653319686304.png" alt="Fred1980_1-1653319686304.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The log is currently storing log files for 4 different firewalls.&lt;/P&gt;
&lt;P&gt;If i take&amp;nbsp; another device also in the log file i can see all of the file in /palogs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Fred1980_2-1653319843916.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41110i4C930BFB83784E43/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Fred1980_2-1653319843916.png" alt="Fred1980_2-1653319843916.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When i manual copy the log files by filtering on LInux containing the first firewall logs i can see the file.&lt;/P&gt;
&lt;P&gt;so it is before I create a project log-collector.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 15:37:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/489775#M4000</guid>
      <dc:creator>zGomez</dc:creator>
      <dc:date>2022-05-23T15:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition Panorama Log Collector Forwarding - ML-Learning</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/489789#M4001</link>
      <description>&lt;P&gt;The first screenshot , was it in the panorama or in the specific firewall ?&amp;nbsp; In Device-&amp;gt; Panorama, you will click on the retrieved connected device first , so it will retrieve all the firewall that's managed by the panorama, 2nd, you click on the right upper corner "show all devices" to show all devices that's managed by panorama, and go into the specific firewall device you want to analyze for the logs.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 16:08:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/489789#M4001</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2022-05-23T16:08:38Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition Panorama Log Collector Forwarding - ML-Learning</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/489830#M4004</link>
      <description>&lt;P&gt;Hello the first screenshot was panorama --&amp;gt; show all devices --&amp;gt; then i went into the specific device firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 16:42:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/489830#M4004</guid>
      <dc:creator>zGomez</dc:creator>
      <dc:date>2022-05-23T16:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition Panorama Log Collector Forwarding - ML-Learning</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/489831#M4005</link>
      <description>&lt;P&gt;Then it's correct, if you have serial# of the device matching the serial # in the log , it will show the logs in the device for you to process.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 16:46:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/489831#M4005</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2022-05-23T16:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition Panorama Log Collector Forwarding - ML-Learning</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/494754#M4014</link>
      <description>&lt;P&gt;Hi Liam,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No it is not correct, it should display more files 11 to be correct,&amp;nbsp; I have in total 11 files that contain that firewall and serial number.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Output directory:&amp;nbsp; &amp;nbsp;ls -alh&lt;BR /&gt;total 45G&lt;BR /&gt;drwxr-xr-x 2 www-data expedition 4.0K May 23 15:21 .&lt;BR /&gt;drwxrwxr-x 6 www-data expedition 4.0K May 10 13:47 ..&lt;BR /&gt;-rw-r--r-- 1 www-data expedition 3.0G May 13 23:59 panorama_traffic_2022_05_13_last_calendar_day.csv&lt;BR /&gt;-rw-r--r-- 1 www-data expedition 3.4G May 14 23:59 panorama_traffic_2022_05_14_last_calendar_day.csv&lt;BR /&gt;-rw-r--r-- 1 www-data expedition 3.3G May 15 23:59 panorama_traffic_2022_05_15_last_calendar_day.csv&lt;BR /&gt;-rw-r--r-- 1 www-data expedition 5.0G May 16 23:59 panorama_traffic_2022_05_16_last_calendar_day.csv&lt;BR /&gt;-rw-r--r-- 1 www-data expedition 5.1G May 17 23:59 panorama_traffic_2022_05_17_last_calendar_day.csv&lt;BR /&gt;-rw-r--r-- 1 www-data expedition 5.2G May 18 23:59 panorama_traffic_2022_05_18_last_calendar_day.csv&lt;BR /&gt;-rw-r--r-- 1 www-data expedition 5.2G May 19 23:59 panorama_traffic_2022_05_19_last_calendar_day.csv&lt;BR /&gt;-rw-r--r-- 1 www-data expedition 5.0G May 20 23:59 panorama_traffic_2022_05_20_last_calendar_day.csv&lt;BR /&gt;-rw-r--r-- 1 www-data expedition 3.5G May 21 23:59 panorama_traffic_2022_05_21_last_calendar_day.csv&lt;BR /&gt;-rw-r--r-- 1 www-data expedition 3.3G May 22 23:59 panorama_traffic_2022_05_22_last_calendar_day.csv&lt;BR /&gt;-rw-r--r-- 1 www-data expedition 3.2G May 23 16:55 panorama_traffic_2022_05_23_last_calendar_day.csv&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When i grep for hostname through the files and display only unique files names you can see it has more files.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;lab:/palogs/10.255.125.50$&amp;nbsp;&lt;STRONG&gt;grep -H -r "MX-KIO1-FW0001" /palogs/10.255.125.50/ | cut -d: -f1 | sort -u&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;/palogs/10.255.125.50/panorama_traffic_2022_05_13_last_calendar_day.csv&lt;BR /&gt;/palogs/10.255.125.50/panorama_traffic_2022_05_14_last_calendar_day.csv&lt;BR /&gt;/palogs/10.255.125.50/panorama_traffic_2022_05_15_last_calendar_day.csv&lt;BR /&gt;/palogs/10.255.125.50/panorama_traffic_2022_05_16_last_calendar_day.csv&lt;BR /&gt;/palogs/10.255.125.50/panorama_traffic_2022_05_17_last_calendar_day.csv&lt;BR /&gt;/palogs/10.255.125.50/panorama_traffic_2022_05_18_last_calendar_day.csv&lt;BR /&gt;/palogs/10.255.125.50/panorama_traffic_2022_05_19_last_calendar_day.csv&lt;BR /&gt;/palogs/10.255.125.50/panorama_traffic_2022_05_20_last_calendar_day.csv&lt;BR /&gt;/palogs/10.255.125.50/panorama_traffic_2022_05_21_last_calendar_day.csv&lt;BR /&gt;/palogs/10.255.125.50/panorama_traffic_2022_05_22_last_calendar_day.csv&lt;BR /&gt;/palogs/10.255.125.50/panorama_traffic_2022_05_23_last_calendar_day.csv&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 12:31:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/494754#M4014</guid>
      <dc:creator>zGomez</dc:creator>
      <dc:date>2022-05-30T12:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition Panorama Log Collector Forwarding - ML-Learning</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/497176#M4016</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just wanted to give an update. I figured out that the M.learning under device read the first line of the log and if this contains the serial/firewallname will display the file name.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Fred1980_0-1654094971957.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41530iF045A99FDC7749F5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Fred1980_0-1654094971957.png" alt="Fred1980_0-1654094971957.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Since i have a single file for all traffic logs from different firewalls every day the first line can be different.&amp;nbsp; So best approach is to have really seperate files per firewall device.&amp;nbsp; I have not found how to do this dynamically do this with rsyslog filters but you can use a script to split the single file into multiple files based on the value off a column. (awk in linux)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So my question is more related to rsyslog how do i send the logs to different files if they come from a single source.&lt;/P&gt;
&lt;P&gt;I would like rsyslog to create seperate files based on the $53 column in the traffic log (this is the firewallname).&lt;/P&gt;
&lt;P&gt;If i figure out how to do this in rsyslog i will post this config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 14:57:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/497176#M4016</guid>
      <dc:creator>zGomez</dc:creator>
      <dc:date>2022-06-01T14:57:51Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition Panorama Log Collector Forwarding - ML-Learning</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/501068#M4022</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I asked asked a friend an he was so kind to provide rsyslog config.&lt;/P&gt;
&lt;P&gt;This you can use if you forward all logs from panorama and do not use individual log profile on firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;set $!srcfw = field($msg, ",", 52);&lt;BR /&gt;$template DynaTrafficLog,"/palogs/%FROMHOST-IP%/%$!srcfw%_traffic_%$YEAR%_%$MONTH%_%$DAY%_last_calendar_day.csv"&lt;BR /&gt;*.* -?DynaTrafficLog&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 07:47:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-panorama-log-collector-forwarding-ml-learning/m-p/501068#M4022</guid>
      <dc:creator>zGomez</dc:creator>
      <dc:date>2022-06-07T07:47:41Z</dc:date>
    </item>
  </channel>
</rss>

