<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama system logs -&amp;gt;  Sending to Slack via HTTP profile -&amp;gt; NEED TO SEND PANORAMA DEVICE HOSTNAME in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-system-logs-gt-sending-to-slack-via-http-profile-gt/m-p/406877#M355</link>
    <description>&lt;P&gt;I know you say that the Device name does not show up properly, but what about the serial #?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;Serial Number (serial)&lt;/SPAN&gt;"&lt;/P&gt;
&lt;P&gt;Is it showing up? and is that unique?&lt;/P&gt;</description>
    <pubDate>Fri, 14 May 2021 22:02:48 GMT</pubDate>
    <dc:creator>jdelio</dc:creator>
    <dc:date>2021-05-14T22:02:48Z</dc:date>
    <item>
      <title>Panorama system logs -&gt;  Sending to Slack via HTTP profile -&gt; NEED TO SEND PANORAMA DEVICE HOSTNAME</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-system-logs-gt-sending-to-slack-via-http-profile-gt/m-p/406447#M354</link>
      <description>&lt;P&gt;I am using an HTTP profile to send PANORAMA CRITICAL SYSTEM events to Slack. The integration is working well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My Panoramas are an A/P HA cluster. The issue that I have is that I'm unable to delineate the device names via the HTTP profile payload (because the HTTP profile payload gets duplicated between both the active and the passive device).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's my HTTP profile SYSTEM payload:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;{"text": "*Panorama System Log*\n&lt;/P&gt;&lt;P&gt;*Device Name*:$device_name\n&lt;/P&gt;&lt;P&gt;*Receive Time*: $receive_time *Severity:* $severity *Type*: $subtype\n&lt;/P&gt;&lt;P&gt;*Log Message:* $opaque"}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This works well except for the $device_name variable (variable i.e.: system log field).&amp;nbsp; For my Panorama instance, the $device_name returns IP address 1.1.1.1. I would expect it to return the device's hostname.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In reviewing the System log fields documentation,&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/system-log-fields.html#id9502d0c7-67d3-4f74-a0a9-3fdd671afd28" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/system-log-fields.html#id9502d0c7-67d3-4f74-a0a9-3fdd671afd28&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the field "device_name" is described as "the hostname of the firewall on which the session was logged". The key word here is "firewall" as this does not seem to function correctly for Panorama.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In a nutshell, I want to include the Panorama hostname (or Panorama mgmt IP address) within the log(alert) output. That way I know which device in the HA pair is generating the log/alert. For a Panorama A/P HA pair, the HTTP profile payload is duplicated across both devices, and therefore I cannot hard code the device name in the payload, I need to use a variable (i.e.: system log field name). Does anybody know how I can get the Panorama hostname or mgmt IP address to show up in output? How would I build the HTTP Profile SYSTEM payload? Any ideas are appreciated. Thanks!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 18:50:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-system-logs-gt-sending-to-slack-via-http-profile-gt/m-p/406447#M354</guid>
      <dc:creator>Eric.Hernandez</dc:creator>
      <dc:date>2021-05-12T18:50:26Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama system logs -&gt;  Sending to Slack via HTTP profile -&gt; NEED TO SEND PANORAMA DEVICE HOSTNAME</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-system-logs-gt-sending-to-slack-via-http-profile-gt/m-p/406877#M355</link>
      <description>&lt;P&gt;I know you say that the Device name does not show up properly, but what about the serial #?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;Serial Number (serial)&lt;/SPAN&gt;"&lt;/P&gt;
&lt;P&gt;Is it showing up? and is that unique?&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 22:02:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-system-logs-gt-sending-to-slack-via-http-profile-gt/m-p/406877#M355</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2021-05-14T22:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama system logs -&gt;  Sending to Slack via HTTP profile -&gt; NEED TO SEND PANORAMA DEVICE HOSTNAME</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-system-logs-gt-sending-to-slack-via-http-profile-gt/m-p/407263#M356</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23567"&gt;@jdelio&lt;/a&gt;&amp;nbsp;Thanks for responding.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried this during my testing. When I send the serial number ($serial), both the Active and the Passive Panorama return the same 10-digit number. If I search the config for this 10-digit number (show | match &amp;lt;number&amp;gt;) I can't find a record of the number anywhere in the config.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FYI both my Panorama serial numbers are 12-digit numbers.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 14:29:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-system-logs-gt-sending-to-slack-via-http-profile-gt/m-p/407263#M356</guid>
      <dc:creator>Eric.Hernandez</dc:creator>
      <dc:date>2021-05-17T14:29:23Z</dc:date>
    </item>
  </channel>
</rss>

