<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Syslog forwarding to Microsoft Sentinel in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/syslog-forwarding-to-microsoft-sentinel/m-p/597340#M3716</link>
    <description>&lt;P&gt;hello everyone.&lt;/P&gt;
&lt;P&gt;seems we got a weird one here.&lt;/P&gt;
&lt;P&gt;So we took the CEF format that the pdf guide says&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/content/dam/techdocs/en_US/pdf/cef/pan-os-10-0-cef-configuration-guide.pdf" target="_blank"&gt;https://docs.paloaltonetworks.com/content/dam/techdocs/en_US/pdf/cef/pan-os-10-0-cef-configuration-guide.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;heres the weird thing.&lt;/P&gt;
&lt;P&gt;we truncated it to be under 2048 and the push was completed across the fleet&lt;/P&gt;
&lt;P&gt;now the weird part&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the sentinnel collector reports nothing from the physical hardware applicances&lt;/P&gt;
&lt;P&gt;but does get everything from the VM's in azure.&lt;/P&gt;
&lt;P&gt;The physical applicances using the same share profile/syslog groups ONLY the system logs are being "seen" in the tcp.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IF we take OUT the custom formating.&lt;/P&gt;
&lt;P&gt;the sentinnel collector sees the traffic but of course in an unrecognized format.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thoughts?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we running on 10.2.7-h3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Sep 2024 19:57:41 GMT</pubDate>
    <dc:creator>miguelMA</dc:creator>
    <dc:date>2024-09-09T19:57:41Z</dc:date>
    <item>
      <title>Syslog forwarding to Microsoft Sentinel</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/syslog-forwarding-to-microsoft-sentinel/m-p/597340#M3716</link>
      <description>&lt;P&gt;hello everyone.&lt;/P&gt;
&lt;P&gt;seems we got a weird one here.&lt;/P&gt;
&lt;P&gt;So we took the CEF format that the pdf guide says&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/content/dam/techdocs/en_US/pdf/cef/pan-os-10-0-cef-configuration-guide.pdf" target="_blank"&gt;https://docs.paloaltonetworks.com/content/dam/techdocs/en_US/pdf/cef/pan-os-10-0-cef-configuration-guide.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;heres the weird thing.&lt;/P&gt;
&lt;P&gt;we truncated it to be under 2048 and the push was completed across the fleet&lt;/P&gt;
&lt;P&gt;now the weird part&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the sentinnel collector reports nothing from the physical hardware applicances&lt;/P&gt;
&lt;P&gt;but does get everything from the VM's in azure.&lt;/P&gt;
&lt;P&gt;The physical applicances using the same share profile/syslog groups ONLY the system logs are being "seen" in the tcp.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IF we take OUT the custom formating.&lt;/P&gt;
&lt;P&gt;the sentinnel collector sees the traffic but of course in an unrecognized format.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thoughts?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we running on 10.2.7-h3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 19:57:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/syslog-forwarding-to-microsoft-sentinel/m-p/597340#M3716</guid>
      <dc:creator>miguelMA</dc:creator>
      <dc:date>2024-09-09T19:57:41Z</dc:date>
    </item>
  </channel>
</rss>

