<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PAN to rsyslog on Ubuntu 22 yields unusable file names in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-to-rsyslog-on-ubuntu-22-yields-unusable-file-names/m-p/520355#M538</link>
    <description>&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Hi.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;I have a default setup w/ Ubuntu 22 as a rsyslog server. I pointed my PAN 10.2 to it, and am getting log data, but I am not getting a usable / meaningful file name. I'd like the log file name to be something like "perimfw" or some such to start.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Hoping that some other PAN users here are logging to rsyslog and have a usable template line = because the PAN log record does not appear to include a process name because it looks like this "2022-11-04T12:54:13-04:00 perimfw.ad.local 1,2022/11/04 12:54:13,012801088067,THREAT,url,2561,2022/11/04 12:54:13, ...."&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;In the rsyslog file has these lines:&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;$template remote-incoming-logs,"/var/log/%HOSTNAME%/%PROGRAMNAME%.log"&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;*.* ?remote-incoming-logs&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;amp; ~&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;The log file generated is =&amp;gt; 1,2022.log (for BSD format from PAN) and =&amp;gt; "-.log" format if you change to IEFT. In contrast, because the Infoblox servers that are already logging to the same rsyslog server have a traditional process name, I get a nice file and record layout. Example =&amp;gt; "ssh.log" comes from this log line "2022-10-26T19:19:56+02:00 192.168.1.27 sshd[9011]: Local authentication succeeded for user admin";&amp;nbsp; and rsyslog can easily peel off the process name.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Nov 2022 17:18:13 GMT</pubDate>
    <dc:creator>dmurdoch</dc:creator>
    <dc:date>2022-11-04T17:18:13Z</dc:date>
    <item>
      <title>PAN to rsyslog on Ubuntu 22 yields unusable file names</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-to-rsyslog-on-ubuntu-22-yields-unusable-file-names/m-p/520355#M538</link>
      <description>&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Hi.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;I have a default setup w/ Ubuntu 22 as a rsyslog server. I pointed my PAN 10.2 to it, and am getting log data, but I am not getting a usable / meaningful file name. I'd like the log file name to be something like "perimfw" or some such to start.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Hoping that some other PAN users here are logging to rsyslog and have a usable template line = because the PAN log record does not appear to include a process name because it looks like this "2022-11-04T12:54:13-04:00 perimfw.ad.local 1,2022/11/04 12:54:13,012801088067,THREAT,url,2561,2022/11/04 12:54:13, ...."&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;In the rsyslog file has these lines:&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;$template remote-incoming-logs,"/var/log/%HOSTNAME%/%PROGRAMNAME%.log"&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;*.* ?remote-incoming-logs&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;amp; ~&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;The log file generated is =&amp;gt; 1,2022.log (for BSD format from PAN) and =&amp;gt; "-.log" format if you change to IEFT. In contrast, because the Infoblox servers that are already logging to the same rsyslog server have a traditional process name, I get a nice file and record layout. Example =&amp;gt; "ssh.log" comes from this log line "2022-10-26T19:19:56+02:00 192.168.1.27 sshd[9011]: Local authentication succeeded for user admin";&amp;nbsp; and rsyslog can easily peel off the process name.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2022 17:18:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-to-rsyslog-on-ubuntu-22-yields-unusable-file-names/m-p/520355#M538</guid>
      <dc:creator>dmurdoch</dc:creator>
      <dc:date>2022-11-04T17:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: PAN to rsyslog on Ubuntu 22 yields unusable file names</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-to-rsyslog-on-ubuntu-22-yields-unusable-file-names/m-p/520944#M562</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I have a workable answer, this does solve the problem by sending data to a usable file name. Doesn't address why the process name is missing. X.Y are replacements for your site.....&lt;U&gt;&lt;/U&gt;&lt;U&gt;&lt;/U&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;if $fromhost-ip == "192.168.X.Y" then {&lt;BR /&gt;Action (type="omfile" file="/var/log/perimfw.X.Y/&lt;WBR /&gt;firewall.log")&lt;BR /&gt;stop&lt;BR /&gt;}&lt;BR /&gt;if $hostname == "perimfw.X.Y" then {&lt;BR /&gt;Action (type="omfile" file="/var/log/perimfw.X.Yl/&lt;WBR /&gt;firewall.log")&lt;BR /&gt;stop&lt;BR /&gt;}&lt;BR /&gt;## This is a commonly suggested template to direct messages to a specific directory. It works for Infoblox NIOS very well - you get individual log files, as if you were looking at local syslog on a NIOS grid member.&lt;BR /&gt;$template remote-incoming-logs,"/var/&lt;WBR /&gt;log/%HOSTNAME%/%PROGRAMNAME%.&lt;WBR /&gt;log"&lt;BR /&gt;*.* ?remote-incoming-logs&lt;BR /&gt;stop&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 22:08:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-to-rsyslog-on-ubuntu-22-yields-unusable-file-names/m-p/520944#M562</guid>
      <dc:creator>donmrdch@gmail.com</dc:creator>
      <dc:date>2022-11-10T22:08:12Z</dc:date>
    </item>
  </channel>
</rss>

