<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unknown additional fields in GlobalProtect logs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unknown-additional-fields-in-globalprotect-logs/m-p/530762#M109501</link>
    <description>&lt;P&gt;Mahalo, Adrian!&lt;/P&gt;</description>
    <pubDate>Fri, 10 Feb 2023 23:55:34 GMT</pubDate>
    <dc:creator>oahuliam</dc:creator>
    <dc:date>2023-02-10T23:55:34Z</dc:date>
    <item>
      <title>Unknown additional fields in GlobalProtect logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unknown-additional-fields-in-globalprotect-logs/m-p/530550#M109478</link>
      <description>&lt;P&gt;v&lt;/P&gt;
&lt;P&gt;I am building a parser for our SIEM for GlobalProtect and have found something odd. The GlobalProtect logs have 12 more fields than the PanOS Administrators Guide labels. What are the additional 12 fields called?&lt;BR /&gt;&lt;BR /&gt;This is a GlobalProtect Log :&lt;/P&gt;
&lt;P&gt;1,2023/02/09 10:25:54,REDACTED,GLOBALPROTECT,0,2562,2023/02/09 10:25:54,vsys1,portal-auth,login,saml,,REDACTED,US,,REDACTED,0.0.0.0,0.0.0.0,0.0.0.0,,,Browser,any,,1,,,,success,,0,,0,REDACTED,REDACTED,0x0,2023-02-09T10:25:54.892-10:00,,,,,,0,0,0,0,,REDACTED,1&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;And these are the field descriptions from the PAN-OS Administrators Guide (for PAN-OS versions 9.1.3 and later.&lt;BR /&gt;&lt;BR /&gt;Format: FUTURE_USE, Receive Time, Serial Number, Type, Threat/Content Type, FUTURE_USE, Generated Time, Virtual System, Event ID, Stage, Authentication Method, Tunnel Type, Source User, Source Region, Machine Name, Public IP, Public IPv6, Private IP, Private IPv6, Host ID, Serial Number, Client Version, Client OS, Client OS Version, Repeat Count, Reason, Error, Description, Status, Location, Login Duration, Connect Method, Error Code, Portal, Sequence Number, Action Flags&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 20:49:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unknown-additional-fields-in-globalprotect-logs/m-p/530550#M109478</guid>
      <dc:creator>oahuliam</dc:creator>
      <dc:date>2023-02-09T20:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown additional fields in GlobalProtect logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unknown-additional-fields-in-globalprotect-logs/m-p/530562#M109483</link>
      <description>&lt;P&gt;If you log into the GUI, go to the GlobalProtect logs, and then export a sample, the first line of the CSV is a header containing all the field names. The header and fields should match the syslogs. Most are relatively self-explanatory. The DG Hierarchy fields are device groups used in Panorama. Checking around, it looks like many of these are documented in the 10.x/11.x versions of the PAN-OS Administrator's Guide.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Domain&lt;/STRONG&gt;, Receive Time,Serial #, Type,Threat/Content Type,&amp;nbsp;&lt;STRONG&gt;Config Version&lt;/STRONG&gt;, Generate Time, Virtual System, Event ID, stage, auth_method, tunnel_type, Source User, srcregion, machinename, public_ip, public_ipv6, private_ip, private_ipv6, hostid, serialnumber, client_ver, client_os, client_os_ver, Repeat Count, reason, error, Description, status, location, login_duration, connect_method, error_code, portal, Sequence Number, Action Flags,&lt;STRONG&gt; DG Hierarchy Level 1, DG Hierarchy Level 2, DG Hierarchy Level 3, DG Hierarchy Level 4, Virtual System Name, Device Name, Virtual System ID&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now weirdness.... That is only 9 fields different than what you listed. Comparing your CSV to mine, yours has 6 additional fields between Action Flags and DG Heirarchy Level 1; one of which contains a datetime stamp with millisecond resolution and timezone offset, and five blank fields. The rest of the fields match mine if those are removed. The PA does not have any millisecond timestamps in logs of that form that I am aware of. That makes me suspect those additional 6 fields are something added onto the record by your syslog receiver (the first being the receive time on SIEM, then SIEM logging/notes, then the additional fields from the PA syslog not in the parser added after?).&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 22:45:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unknown-additional-fields-in-globalprotect-logs/m-p/530562#M109483</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2023-02-09T22:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown additional fields in GlobalProtect logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unknown-additional-fields-in-globalprotect-logs/m-p/530762#M109501</link>
      <description>&lt;P&gt;Mahalo, Adrian!&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2023 23:55:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unknown-additional-fields-in-globalprotect-logs/m-p/530762#M109501</guid>
      <dc:creator>oahuliam</dc:creator>
      <dc:date>2023-02-10T23:55:34Z</dc:date>
    </item>
  </channel>
</rss>

