<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Capturing and logging dot1x traffic in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/capturing-and-logging-dot1x-traffic/m-p/5665#M148</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you tried adding a pcap filter with non-IP option set to 'include'?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 23 Dec 2011 02:34:34 GMT</pubDate>
    <dc:creator>SRA</dc:creator>
    <dc:date>2011-12-23T02:34:34Z</dc:date>
    <item>
      <title>Capturing and logging dot1x traffic</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/capturing-and-logging-dot1x-traffic/m-p/5662#M145</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking to capture some dot1x traffic. The goal would be to simply log the dot1x under a custom application.&lt;/P&gt;&lt;P&gt;The problem is i dont see a context that I can use for the dot1x traffic (screenshot) under the application signature&amp;nbsp; to be able to do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to do some pattern matching that would accomplish the same goal?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Dec 2011 15:46:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/capturing-and-logging-dot1x-traffic/m-p/5662#M145</guid>
      <dc:creator>bmaslakovic</dc:creator>
      <dc:date>2011-12-21T15:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: Capturing and logging dot1x traffic</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/capturing-and-logging-dot1x-traffic/m-p/5663#M146</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Custom application signatures are for tcp/udp traffic. You cannot use them for non-IP layer 3 traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Dec 2011 17:19:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/capturing-and-logging-dot1x-traffic/m-p/5663#M146</guid>
      <dc:creator>SRA</dc:creator>
      <dc:date>2011-12-21T17:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: Capturing and logging dot1x traffic</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/capturing-and-logging-dot1x-traffic/m-p/5664#M147</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the clear answer - that makes perfect sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to capture dot1x traffic in pattern matching then?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Dec 2011 17:23:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/capturing-and-logging-dot1x-traffic/m-p/5664#M147</guid>
      <dc:creator>bmaslakovic</dc:creator>
      <dc:date>2011-12-21T17:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: Capturing and logging dot1x traffic</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/capturing-and-logging-dot1x-traffic/m-p/5665#M148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you tried adding a pcap filter with non-IP option set to 'include'?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Dec 2011 02:34:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/capturing-and-logging-dot1x-traffic/m-p/5665#M148</guid>
      <dc:creator>SRA</dc:creator>
      <dc:date>2011-12-23T02:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: Capturing and logging dot1x traffic</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/capturing-and-logging-dot1x-traffic/m-p/5666#M149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see the option - but I want the dot1x traffic to be logged on the PA traffic log as perhaps another custom app. I was looking further into it and perhaps the REST API is the answer...?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to insert a log entry with REST?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Dec 2011 17:01:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/capturing-and-logging-dot1x-traffic/m-p/5666#M149</guid>
      <dc:creator>bmaslakovic</dc:creator>
      <dc:date>2011-12-23T17:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: Capturing and logging dot1x traffic</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/capturing-and-logging-dot1x-traffic/m-p/5667#M150</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried this and yes this does capture the radius traffic going from the WLC &amp;lt;-&amp;gt; Radius. by the way.....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Dec 2011 20:49:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/capturing-and-logging-dot1x-traffic/m-p/5667#M150</guid>
      <dc:creator>bmaslakovic</dc:creator>
      <dc:date>2011-12-23T20:49:53Z</dc:date>
    </item>
    <item>
      <title>Re: Capturing and logging dot1x traffic</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/capturing-and-logging-dot1x-traffic/m-p/5668#M151</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok i have been trying to get the data pattern working. Attached is a screenshot of a EAPOL packet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How would my regex look if i wanted to capture any packet with this source address? (assume the source is 7 bytes).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Dec 2011 21:36:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/capturing-and-logging-dot1x-traffic/m-p/5668#M151</guid>
      <dc:creator>bmaslakovic</dc:creator>
      <dc:date>2011-12-23T21:36:11Z</dc:date>
    </item>
    <item>
      <title>Re: Capturing and logging dot1x traffic</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/capturing-and-logging-dot1x-traffic/m-p/5669#M152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;any answer to last three posts?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 15 Jan 2012 20:44:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/capturing-and-logging-dot1x-traffic/m-p/5669#M152</guid>
      <dc:creator>bmaslakovic</dc:creator>
      <dc:date>2012-01-15T20:44:23Z</dc:date>
    </item>
  </channel>
</rss>

