<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: access logs from bluecoat proxy to windows user-id agent in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/access-logs-from-bluecoat-proxy-to-windows-user-id-agent/m-p/523399#M108392</link>
    <description>&lt;P&gt;We have the same issue in the palo agent is there more information or a solution?&lt;/P&gt;</description>
    <pubDate>Tue, 06 Dec 2022 15:39:18 GMT</pubDate>
    <dc:creator>netwerkbeheer_aswatson</dc:creator>
    <dc:date>2022-12-06T15:39:18Z</dc:date>
    <item>
      <title>access logs from bluecoat proxy to windows user-id agent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-logs-from-bluecoat-proxy-to-windows-user-id-agent/m-p/92205#M43702</link>
      <description>&lt;P&gt;Trying to get bluecoat proxy to send its access logs to windows user-id agent. configured custom log on bluecoat in the following format&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN Source=$(c-ip) Username=$(cs-username) Action=$(s-action)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On user-id agent side I am seeing server receiving syslog messages in the format specified&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN Source=x.x.x.x Username=usernamexxx Action=TCP_HIT&lt;/P&gt;&lt;P&gt;PAN Source=x.x.x.x Username=usernamexxx Action=TUNNELED&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;User-ID agent is confiured with parse filter using Field&lt;/P&gt;&lt;P&gt;Event String: PAN&lt;/P&gt;&lt;P&gt;Username Prefix: Username=&lt;/P&gt;&lt;P&gt;Username Delimeter: \s&lt;/P&gt;&lt;P&gt;Address Prefix: Source=&lt;/P&gt;&lt;P&gt;Address Delimeter: \s&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the UaDebug keep seeing this error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Error&amp;nbsp; 592]: Syslog msg len read error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone run into the same issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am I doing wrong?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jun 2016 05:02:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-logs-from-bluecoat-proxy-to-windows-user-id-agent/m-p/92205#M43702</guid>
      <dc:creator>fwguy77</dc:creator>
      <dc:date>2016-06-26T05:02:44Z</dc:date>
    </item>
    <item>
      <title>Re: access logs from bluecoat proxy to windows user-id agent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-logs-from-bluecoat-proxy-to-windows-user-id-agent/m-p/93048#M43765</link>
      <description>&lt;P&gt;Can you instruct the BlueCoat to separate the fields with a comma or semi-colon? &amp;nbsp;Then change the setting on the PA to match the delimiter:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Username Delimeter: ,&lt;BR /&gt;Address Delimeter: ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think the \s is used for regex matching whereas the field match is an exact match and the PA was trying to match \s exactly.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2016 13:58:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-logs-from-bluecoat-proxy-to-windows-user-id-agent/m-p/93048#M43765</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2016-06-28T13:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: access logs from bluecoat proxy to windows user-id agent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-logs-from-bluecoat-proxy-to-windows-user-id-agent/m-p/93286#M43784</link>
      <description>&lt;P&gt;Thank you rmonvon. No result &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I see in verbose output that it is processing syslog, but then it shows error at the end.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example first message in a syslog would be&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;PFW Source=some ip,Username=johns,Action=TCP_HIT&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 617]: Syslog msg, skipping&amp;nbsp;P&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 617]: Syslog msg, skipping&amp;nbsp;F&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 617]: Syslog msg, skipping&amp;nbsp;W&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 617]: Syslog msg, skipping&amp;nbsp;&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 617]: Syslog msg, skipping S&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 617]: Syslog msg, skipping o&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 617]: Syslog msg, skipping u&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 617]: Syslog msg, skipping r&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 617]: Syslog msg, skipping c&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 617]: Syslog msg, skipping e&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 617]: Syslog msg, skipping =&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 596]: Syslog msg len is 10&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Debug&amp;nbsp; 371]: Syslog: Unable to display contents of message, it exceeds the length debug messages allow.&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 615]: recv 0-2047, msg 23-22&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 596]: Syslog msg len is 4&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Debug&amp;nbsp; 371]: Syslog: Unable to display contents of message, it exceeds the length debug messages allow.&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 615]: recv 0-2047, msg 28-27&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 617]: Syslog msg, skipping r&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 617]: Syslog msg, skipping n&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 617]: Syslog msg, skipping a&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 617]: Syslog msg, skipping m&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 617]: Syslog msg, skipping e&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 617]: Syslog msg, skipping =&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 617]: Syslog msg, skipping&amp;nbsp;j&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 617]: Syslog msg, skipping&amp;nbsp;o&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 617]: Syslog msg, skipping&amp;nbsp;h&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 617]: Syslog msg, skipping&amp;nbsp;n&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Verbo&amp;nbsp; 617]: Syslog msg, skipping&amp;nbsp;s&lt;BR /&gt;&amp;nbsp;06/28/16 20:44:58:388[Error&amp;nbsp; 592]: Syslog msg len read error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will try to make a single message shorter&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2016 00:50:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-logs-from-bluecoat-proxy-to-windows-user-id-agent/m-p/93286#M43784</guid>
      <dc:creator>fwguy77</dc:creator>
      <dc:date>2016-06-29T00:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: access logs from bluecoat proxy to windows user-id agent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-logs-from-bluecoat-proxy-to-windows-user-id-agent/m-p/93296#M43791</link>
      <description>&lt;P&gt;Can you take a screenshot of the syslog field settings on the PA and post it here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, do you have a syslog server like Kiwi syslog server that you can point the BlueCoat to? &amp;nbsp;We want to confirm the exact syslog output that is being forwarded.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2016 02:38:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-logs-from-bluecoat-proxy-to-windows-user-id-agent/m-p/93296#M43791</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2016-06-29T02:38:29Z</dc:date>
    </item>
    <item>
      <title>Re: access logs from bluecoat proxy to windows user-id agent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-logs-from-bluecoat-proxy-to-windows-user-id-agent/m-p/93299#M43792</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 464px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4570iF58E2B95C3F47DFF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have kiwi, but I have wireshark running on windows box where user-id agent is installed and I am seeing in wireshark something like below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_POLICY_REDIRECT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_CLIENT_REFRESH,u:johns,s:10.1.1.100&lt;BR /&gt;TUNNELED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_HIT,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TUNNELED,u:johns,s:10.1.1.100&lt;BR /&gt;TUNNELED,u:johns,s:10.1.1.100&lt;BR /&gt;TUNNELED,u:johns,s:10.1.1.100&lt;BR /&gt;TUNNELED,u:johns,s:10.1.1.100&lt;BR /&gt;TUNNELED,u:johns,s:10.1.1.100&lt;BR /&gt;TUNNELED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TUNNELED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TUNNELED,u:johns,s:10.1.1.100&lt;BR /&gt;TUNNELED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_DENIED,u:-,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_ACCELERATED,u:johns,s:10.1.1.100&lt;BR /&gt;TCP_NC_MISS,u:johns,s:10.1.1.100&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2016 05:44:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-logs-from-bluecoat-proxy-to-windows-user-id-agent/m-p/93299#M43792</guid>
      <dc:creator>fwguy77</dc:creator>
      <dc:date>2016-06-29T05:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: access logs from bluecoat proxy to windows user-id agent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-logs-from-bluecoat-proxy-to-windows-user-id-agent/m-p/93466#M43874</link>
      <description>&lt;P&gt;{edit]&lt;/P&gt;&lt;P&gt;There is no comma after the IP address, and we specify the address delimiter has a comma. &amp;nbsp;Can you add another syslog field after the IP address to get the comma into the syslog message?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other than that, I can't see anything wrong with your setup. &amp;nbsp;The syslog messages match against the fields &amp;amp; delimiters. &amp;nbsp;I would check the agent itself. &amp;nbsp;Restart the agent &amp;amp;&amp;nbsp;maybe re-install agent. &amp;nbsp;Or just install another version of the agent on another server as a test. &amp;nbsp; Open a support case &amp;amp; have it diagnose is another option.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2016 15:00:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-logs-from-bluecoat-proxy-to-windows-user-id-agent/m-p/93466#M43874</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2016-07-01T15:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: access logs from bluecoat proxy to windows user-id agent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-logs-from-bluecoat-proxy-to-windows-user-id-agent/m-p/94120#M43906</link>
      <description>&lt;P&gt;adding comma did not help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am getting the same failure still in vervose log on user-id agent&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;07/05/16 04:16:27:439[Verbo&amp;nbsp; 617]: Syslog msg, skipping T&lt;BR /&gt;&amp;nbsp;07/05/16 04:16:27:439[Verbo&amp;nbsp; 617]: Syslog msg, skipping U&lt;BR /&gt;&amp;nbsp;07/05/16 04:16:27:439[Verbo&amp;nbsp; 617]: Syslog msg, skipping N&lt;BR /&gt;&amp;nbsp;07/05/16 04:16:27:439[Verbo&amp;nbsp; 617]: Syslog msg, skipping N&lt;BR /&gt;&amp;nbsp;07/05/16 04:16:27:439[Verbo&amp;nbsp; 617]: Syslog msg, skipping E&lt;BR /&gt;&amp;nbsp;07/05/16 04:16:27:439[Verbo&amp;nbsp; 617]: Syslog msg, skipping L&lt;BR /&gt;&amp;nbsp;07/05/16 04:16:27:439[Verbo&amp;nbsp; 617]: Syslog msg, skipping E&lt;BR /&gt;&amp;nbsp;07/05/16 04:16:27:439[Verbo&amp;nbsp; 617]: Syslog msg, skipping D&lt;BR /&gt;&amp;nbsp;07/05/16 04:16:27:439[Verbo&amp;nbsp; 617]: Syslog msg, skipping ,&lt;BR /&gt;&amp;nbsp;07/05/16 04:16:27:439[Verbo&amp;nbsp; 617]: Syslog msg, skipping u&lt;BR /&gt;&amp;nbsp;07/05/16 04:16:27:439[Verbo&amp;nbsp; 617]: Syslog msg, skipping :&lt;BR /&gt;&amp;nbsp;07/05/16 04:16:27:439[Verbo&amp;nbsp; 617]: Syslog msg, skipping&amp;nbsp;j&lt;BR /&gt;&amp;nbsp;07/05/16 04:16:27:439[Verbo&amp;nbsp; 617]: Syslog msg, skipping&amp;nbsp;o&lt;BR /&gt;&amp;nbsp;07/05/16 04:16:27:439[Verbo&amp;nbsp; 617]: Syslog msg, skipping&amp;nbsp;h&lt;BR /&gt;&amp;nbsp;07/05/16 04:16:27:439[Verbo&amp;nbsp; 617]: Syslog msg, skipping&amp;nbsp;n&lt;BR /&gt;&amp;nbsp;07/05/16 04:16:27:439[Verbo&amp;nbsp; 617]: Syslog msg, skipping&amp;nbsp;s&lt;BR /&gt;&amp;nbsp;07/05/16 04:16:27:439[Error&amp;nbsp; 592]: Syslog msg len read error&lt;BR /&gt;&amp;nbsp;07/05/16 04:16:27:439[Debug&amp;nbsp; 355]: Event: type="XML API connection" name="&amp;lt;edited proxy IP&amp;gt;" status="Disconnected&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did create a support case, but it appears they are scratching their head too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think it may have something to with amount of data bluecoat is trying to send. It does not send syslog messages as individual messages, rather many of them at once.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 08:24:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-logs-from-bluecoat-proxy-to-windows-user-id-agent/m-p/94120#M43906</guid>
      <dc:creator>fwguy77</dc:creator>
      <dc:date>2016-07-05T08:24:32Z</dc:date>
    </item>
    <item>
      <title>Re: access logs from bluecoat proxy to windows user-id agent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-logs-from-bluecoat-proxy-to-windows-user-id-agent/m-p/94281#M43907</link>
      <description>&lt;P&gt;Humm, that is odd. &amp;nbsp;Any chance you can try the onbox agent on the PA or spinning a new agent on another Win server? &amp;nbsp;Or try a different release 6.x or 7.x agent?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 14:32:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-logs-from-bluecoat-proxy-to-windows-user-id-agent/m-p/94281#M43907</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2016-07-05T14:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: access logs from bluecoat proxy to windows user-id agent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-logs-from-bluecoat-proxy-to-windows-user-id-agent/m-p/523399#M108392</link>
      <description>&lt;P&gt;We have the same issue in the palo agent is there more information or a solution?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2022 15:39:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-logs-from-bluecoat-proxy-to-windows-user-id-agent/m-p/523399#M108392</guid>
      <dc:creator>netwerkbeheer_aswatson</dc:creator>
      <dc:date>2022-12-06T15:39:18Z</dc:date>
    </item>
  </channel>
</rss>

