<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Where is the documentation that describes Syslog Log types formats for Palo Alto Firewalls? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/where-is-the-documentation-that-describes-syslog-log-types/m-p/598588#M119057</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1278321707"&gt;@SoloSigma&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;On my Ubuntu Server I receive syslogs, that may look like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;lt;14&amp;gt;Sep 23 20:01:11 PA-440 1,2024/09/23 20:01:11,021201133296,TRAFFIC,end,2561,2024/09/23 20:01:11,10.10.10.103,20.190.177.21,192.168.10.20,22.120.127.11,rule1,,,ssl,vsys1,trust,untrust,ethernet1/2,ethernet1/1,LFP LimaCharlie FW,2024/09/23 20:01:11,121977,1,60637,443,39335,443,0x40041c,tcp,allow,23588,6260,17328,30,2024/09/23 20:00:56,1,any,,7408146363088945002,0x0,10.0.0.0-10.255.255.255,France,,13,17,tcp-fin,0,0,0,0,,PA-440,from-policy,,,0,,0,,N/A,0,0,0,0,a6854971-45bb-499a-86fd-30008807b6e1,0,0,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,2024-09-23T20:01:11.522+02:00,,,encrypted-tunnel,networking,browser-based,4,"used-by-malware,able-to-transfer-file,has-known-vulnerability,tunnel-other-application,pervasive-use",,ssl,no,no,0&lt;/LI-CODE&gt;
&lt;P&gt;I understand that there are different log types that can be sent, including&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Config&lt;/LI&gt;
&lt;LI&gt;System&lt;/LI&gt;
&lt;LI&gt;Threat&lt;/LI&gt;
&lt;LI&gt;Traffic&lt;/LI&gt;
&lt;LI&gt;URL&lt;/LI&gt;
&lt;LI&gt;Data&lt;/LI&gt;
&lt;LI&gt;WildFire&lt;/LI&gt;
&lt;LI&gt;Tunnel&lt;/LI&gt;
&lt;LI&gt;Authentication&lt;/LI&gt;
&lt;LI&gt;User-ID&lt;/LI&gt;
&lt;LI&gt;HIP Match&lt;/LI&gt;
&lt;LI&gt;Globalprotect&lt;/LI&gt;
&lt;LI&gt;Iptag&lt;/LI&gt;
&lt;LI&gt;Decryption&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are there any documentation that shows me how the different log types are constructed?&lt;BR /&gt;I need it in order to create a Regex that will convert syslog into JSON format.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Maybe this is what you're looking for?&amp;nbsp; The LEEF fields?&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/strata-logging-service/log-reference/network-logs/network-traffic-log/network-traffic-leef-fields" target="_blank"&gt;https://docs.paloaltonetworks.com/strata-logging-service/log-reference/network-logs/network-traffic-log/network-traffic-leef-fields&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 23 Sep 2024 20:16:34 GMT</pubDate>
    <dc:creator>Brandon_Wertz</dc:creator>
    <dc:date>2024-09-23T20:16:34Z</dc:date>
    <item>
      <title>Where is the documentation that describes Syslog Log types formats for Palo Alto Firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/where-is-the-documentation-that-describes-syslog-log-types/m-p/598573#M119053</link>
      <description>&lt;P&gt;On my Ubuntu Server I receive syslogs, that may look like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;lt;14&amp;gt;Sep 23 20:01:11 PA-440 1,2024/09/23 20:01:11,021201133296,TRAFFIC,end,2561,2024/09/23 20:01:11,10.10.10.103,20.190.177.21,192.168.10.20,22.120.127.11,rule1,,,ssl,vsys1,trust,untrust,ethernet1/2,ethernet1/1,LFP LimaCharlie FW,2024/09/23 20:01:11,121977,1,60637,443,39335,443,0x40041c,tcp,allow,23588,6260,17328,30,2024/09/23 20:00:56,1,any,,7408146363088945002,0x0,10.0.0.0-10.255.255.255,France,,13,17,tcp-fin,0,0,0,0,,PA-440,from-policy,,,0,,0,,N/A,0,0,0,0,a6854971-45bb-499a-86fd-30008807b6e1,0,0,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,2024-09-23T20:01:11.522+02:00,,,encrypted-tunnel,networking,browser-based,4,"used-by-malware,able-to-transfer-file,has-known-vulnerability,tunnel-other-application,pervasive-use",,ssl,no,no,0&lt;/LI-CODE&gt;
&lt;P&gt;I understand that there are different log types that can be sent, including&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Config&lt;/LI&gt;
&lt;LI&gt;System&lt;/LI&gt;
&lt;LI&gt;Threat&lt;/LI&gt;
&lt;LI&gt;Traffic&lt;/LI&gt;
&lt;LI&gt;URL&lt;/LI&gt;
&lt;LI&gt;Data&lt;/LI&gt;
&lt;LI&gt;WildFire&lt;/LI&gt;
&lt;LI&gt;Tunnel&lt;/LI&gt;
&lt;LI&gt;Authentication&lt;/LI&gt;
&lt;LI&gt;User-ID&lt;/LI&gt;
&lt;LI&gt;HIP Match&lt;/LI&gt;
&lt;LI&gt;Globalprotect&lt;/LI&gt;
&lt;LI&gt;Iptag&lt;/LI&gt;
&lt;LI&gt;Decryption&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are there any documentation that shows me how the different log types are constructed?&lt;BR /&gt;I need it in order to create a Regex that will convert syslog into JSON format.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 18:06:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/where-is-the-documentation-that-describes-syslog-log-types/m-p/598573#M119053</guid>
      <dc:creator>SoloSigma</dc:creator>
      <dc:date>2024-09-23T18:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: Where is the documentation that describes Syslog Log types formats for Palo Alto Firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/where-is-the-documentation-that-describes-syslog-log-types/m-p/598583#M119054</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Your SIEM might already be able to do this? I dont have an example that I can share, but its along similar lines of comma separated values. You could setup a simple syslog server to capture a few logs of each and then base it from there?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is what is shows in the help file of hte two different types of syslogs the firewall can send.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Select the value that maps to how your Syslog server uses the facility field to manage messages. For details on the facility field, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="xref"&gt;&lt;A href="https://tools.ietf.org/html/rfc3164" target="external_window"&gt;RFC 3164&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(BSD format) or&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="xref"&gt;&lt;A href="https://tools.ietf.org/html/rfc5424" target="external_window"&gt;RFC 5424&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(IETF format).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just a few thoughts.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 19:52:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/where-is-the-documentation-that-describes-syslog-log-types/m-p/598583#M119054</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-09-23T19:52:56Z</dc:date>
    </item>
    <item>
      <title>Re: Where is the documentation that describes Syslog Log types formats for Palo Alto Firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/where-is-the-documentation-that-describes-syslog-log-types/m-p/598588#M119057</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1278321707"&gt;@SoloSigma&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;On my Ubuntu Server I receive syslogs, that may look like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;lt;14&amp;gt;Sep 23 20:01:11 PA-440 1,2024/09/23 20:01:11,021201133296,TRAFFIC,end,2561,2024/09/23 20:01:11,10.10.10.103,20.190.177.21,192.168.10.20,22.120.127.11,rule1,,,ssl,vsys1,trust,untrust,ethernet1/2,ethernet1/1,LFP LimaCharlie FW,2024/09/23 20:01:11,121977,1,60637,443,39335,443,0x40041c,tcp,allow,23588,6260,17328,30,2024/09/23 20:00:56,1,any,,7408146363088945002,0x0,10.0.0.0-10.255.255.255,France,,13,17,tcp-fin,0,0,0,0,,PA-440,from-policy,,,0,,0,,N/A,0,0,0,0,a6854971-45bb-499a-86fd-30008807b6e1,0,0,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,2024-09-23T20:01:11.522+02:00,,,encrypted-tunnel,networking,browser-based,4,"used-by-malware,able-to-transfer-file,has-known-vulnerability,tunnel-other-application,pervasive-use",,ssl,no,no,0&lt;/LI-CODE&gt;
&lt;P&gt;I understand that there are different log types that can be sent, including&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Config&lt;/LI&gt;
&lt;LI&gt;System&lt;/LI&gt;
&lt;LI&gt;Threat&lt;/LI&gt;
&lt;LI&gt;Traffic&lt;/LI&gt;
&lt;LI&gt;URL&lt;/LI&gt;
&lt;LI&gt;Data&lt;/LI&gt;
&lt;LI&gt;WildFire&lt;/LI&gt;
&lt;LI&gt;Tunnel&lt;/LI&gt;
&lt;LI&gt;Authentication&lt;/LI&gt;
&lt;LI&gt;User-ID&lt;/LI&gt;
&lt;LI&gt;HIP Match&lt;/LI&gt;
&lt;LI&gt;Globalprotect&lt;/LI&gt;
&lt;LI&gt;Iptag&lt;/LI&gt;
&lt;LI&gt;Decryption&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are there any documentation that shows me how the different log types are constructed?&lt;BR /&gt;I need it in order to create a Regex that will convert syslog into JSON format.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Maybe this is what you're looking for?&amp;nbsp; The LEEF fields?&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/strata-logging-service/log-reference/network-logs/network-traffic-log/network-traffic-leef-fields" target="_blank"&gt;https://docs.paloaltonetworks.com/strata-logging-service/log-reference/network-logs/network-traffic-log/network-traffic-leef-fields&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 20:16:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/where-is-the-documentation-that-describes-syslog-log-types/m-p/598588#M119057</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2024-09-23T20:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: Where is the documentation that describes Syslog Log types formats for Palo Alto Firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/where-is-the-documentation-that-describes-syslog-log-types/m-p/598616#M119063</link>
      <description>&lt;P&gt;My SIEM tool is &lt;A href="http://LimaCharlie.io" target="_self"&gt;LimaCharlie&lt;/A&gt;, and it does not parse Palo Alto logs out of the box. Because of this I will have to create some Regex to convert Syslogs to JSON format.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 06:22:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/where-is-the-documentation-that-describes-syslog-log-types/m-p/598616#M119063</guid>
      <dc:creator>SoloSigma</dc:creator>
      <dc:date>2024-09-24T06:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: Where is the documentation that describes Syslog Log types formats for Palo Alto Firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/where-is-the-documentation-that-describes-syslog-log-types/m-p/598640#M119064</link>
      <description>&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/threat-log-fields#id83052cb2-4798-4f9c-abf8-e0b929ce7a3b" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/threat-log-fields#id83052cb2-4798-4f9c-abf8-e0b929ce7a3b&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/traffic-log-fields#idbe18d2d4-9eb8-4966-bec8-df3a6de70e66" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/traffic-log-fields#idbe18d2d4-9eb8-4966-bec8-df3a6de70e66&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 12:26:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/where-is-the-documentation-that-describes-syslog-log-types/m-p/598640#M119064</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2024-09-24T12:26:37Z</dc:date>
    </item>
  </channel>
</rss>

