<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Understanding Prisma Access Syslog Header &amp;amp; messages in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/understanding-prisma-access-syslog-header-amp-messages/m-p/584750#M746</link>
    <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;I am working on Prisma Access syslog csv format. We are able to forward &amp;amp; receive csv logs successfully.&lt;/P&gt;
&lt;P&gt;Now, I am trying to understand the format. I could able to understand the message part as all the field details are provided in the Palo Alto documentation clearly. However, header is where I am looking for little clarity. Following is the sample header of old log(few things masked):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;889 &amp;lt;14&amp;gt;1 2022-09-29T13:57:16.953Z stream-logfwd20-xxxxxxxx--xxxxxxxx-xxxx-abcxyz-1x2x logforwarder - panwlogs -&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to know:&lt;/P&gt;
&lt;P&gt;1. What is the "logforwarder" and "panwlogs"? And are these going to be static?&lt;/P&gt;
&lt;P&gt;2. Syslog header structure.&lt;/P&gt;
&lt;P&gt;3. How can I differentiate log coming Panorama vs Prisma Access via CDL?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any support document or help regarding above points would would really appreciate.&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Prisma Access" id="Prisma_Access"&gt;&lt;/LI-PRODUCT&gt; &lt;LI-PRODUCT title="Cortex Data Lake" id="Cortex_Data_Lake"&gt;&lt;/LI-PRODUCT&gt; &lt;LI-PRODUCT title="Panorama" id="Panorama"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Apr 2024 07:34:24 GMT</pubDate>
    <dc:creator>sushant1601</dc:creator>
    <dc:date>2024-04-24T07:34:24Z</dc:date>
    <item>
      <title>Understanding Prisma Access Syslog Header &amp; messages</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/understanding-prisma-access-syslog-header-amp-messages/m-p/584750#M746</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;I am working on Prisma Access syslog csv format. We are able to forward &amp;amp; receive csv logs successfully.&lt;/P&gt;
&lt;P&gt;Now, I am trying to understand the format. I could able to understand the message part as all the field details are provided in the Palo Alto documentation clearly. However, header is where I am looking for little clarity. Following is the sample header of old log(few things masked):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;889 &amp;lt;14&amp;gt;1 2022-09-29T13:57:16.953Z stream-logfwd20-xxxxxxxx--xxxxxxxx-xxxx-abcxyz-1x2x logforwarder - panwlogs -&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to know:&lt;/P&gt;
&lt;P&gt;1. What is the "logforwarder" and "panwlogs"? And are these going to be static?&lt;/P&gt;
&lt;P&gt;2. Syslog header structure.&lt;/P&gt;
&lt;P&gt;3. How can I differentiate log coming Panorama vs Prisma Access via CDL?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any support document or help regarding above points would would really appreciate.&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Prisma Access" id="Prisma_Access"&gt;&lt;/LI-PRODUCT&gt; &lt;LI-PRODUCT title="Cortex Data Lake" id="Cortex_Data_Lake"&gt;&lt;/LI-PRODUCT&gt; &lt;LI-PRODUCT title="Panorama" id="Panorama"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 07:34:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/understanding-prisma-access-syslog-header-amp-messages/m-p/584750#M746</guid>
      <dc:creator>sushant1601</dc:creator>
      <dc:date>2024-04-24T07:34:24Z</dc:date>
    </item>
  </channel>
</rss>

