<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Syslog Data for UserID from Cisco 3850 WLC to Palo Alto PA-500 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-data-for-userid-from-cisco-3850-wlc-to-palo-alto-pa-500/m-p/18389#M13419</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used the debug user-id command for syslog strings given as example in below and it it worked fine. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333330154419px;"&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6664"&gt;How to Configure a Custom Syslog Sender and Test User Mappings&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;gt; debug user-id test user-id-syslog-parse field-identifier event-string "User Authentication Successful:" username-prefix "username=" username-delimiter "\s" address-prefix "IP=" address-delimiter "\s" log-string "2013-03-20 12:56:53 local4.notice Aruba-Local3 authmgr[1568]: &amp;lt;522008&amp;gt; &amp;lt;NOTI&amp;gt; &amp;lt;Aruba-Local3 10.200.10.10&amp;gt; User Authentication Successful: username=ilija MAC=78:f5:fd:dd:ff:90 IP=10.200.27.67"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Field parsing successful, Username 'ilija', Address '10.200.27.67'&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which syslog server you are using? Can it convert snmp trap to syslog format? I did some research and found this link and I hope it is helpful in&amp;nbsp; fixing the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-8523"&gt;Use Syslog Receiver to Integrate with Cisco Wireless Controller Series&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check the above two links and if still no success, then you can open a case with support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 Mar 2015 03:59:10 GMT</pubDate>
    <dc:creator>jthakur</dc:creator>
    <dc:date>2015-03-04T03:59:10Z</dc:date>
    <item>
      <title>Syslog Data for UserID from Cisco 3850 WLC to Palo Alto PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-data-for-userid-from-cisco-3850-wlc-to-palo-alto-pa-500/m-p/18383#M13413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just wondering if there is any documentation for verifying the syntax in PA-500 that is configured correctly to identify UserID data from a Cisco 3850 Intergrated WLD via a dedicated Syslog server.&lt;/P&gt;&lt;P&gt;Cisco 3850 uses the IOS-XE platform.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="syslog parameters.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/18510_syslog parameters.png" style="height: 326px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Mel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Mar 2015 05:32:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-data-for-userid-from-cisco-3850-wlc-to-palo-alto-pa-500/m-p/18383#M13413</guid>
      <dc:creator>MelLi</dc:creator>
      <dc:date>2015-03-02T05:32:46Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Data for UserID from Cisco 3850 WLC to Palo Alto PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-data-for-userid-from-cisco-3850-wlc-to-palo-alto-pa-500/m-p/18384#M13414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone please help to point me to the right direction?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Mar 2015 23:53:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-data-for-userid-from-cisco-3850-wlc-to-palo-alto-pa-500/m-p/18384#M13414</guid>
      <dc:creator>MelLi</dc:creator>
      <dc:date>2015-03-02T23:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Data for UserID from Cisco 3850 WLC to Palo Alto PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-data-for-userid-from-cisco-3850-wlc-to-palo-alto-pa-500/m-p/18385#M13415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you past the syslogs event to get better idea about the strings ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And give a try for "Field Identifier" which is easier than regex.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Mar 2015 00:42:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-data-for-userid-from-cisco-3850-wlc-to-palo-alto-pa-500/m-p/18385#M13415</guid>
      <dc:creator>jthakur</dc:creator>
      <dc:date>2015-03-03T00:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Data for UserID from Cisco 3850 WLC to Palo Alto PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-data-for-userid-from-cisco-3850-wlc-to-palo-alto-pa-500/m-p/18386#M13416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jthakur,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;Please find a sample of the data&lt;/P&gt;&lt;P&gt;Feb 27 16:18:52 syslog1 snmptrapd[2559]: 2015-02-27 16:18:52 10.5.80.1(via UDP: [10.5.80.1]:1028-&amp;gt;[10.5.80.47]:162) TRAP, SNMP v1, community public#012#011iso.3.6.1.4.1.14179.2.6.3 Enterprise Specific Trap (53) Uptime: 78 days, 7:24:55.14#012#011iso.3.6.1.4.1.14179.2.6.2.35.0 = Hex-STRING: F8 4F 57 A4 C2 B0 #011iso.3.6.1.4.1.14179.2.6.2.36.0 = INTEGER: 0#011iso.3.6.1.4.1.14179.2.6.2.43.0 = IpAddress: 10.5.185.5#011iso.3.6.1.4.1.14179.2.6.2.34.0 = Hex-STRING: D8 96 95 11 3D 8F #011iso.3.6.1.4.1.14179.2.6.2.39.0 = STRING: "sarah.harris"#011iso.3.6.1.4.1.14179.2.2.1.1.3.6.248.79.87.164.194.176 = STRING: "WAP-001”&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have used the document &lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #1f497d;"&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-8771"&gt;&lt;SPAN style="color: purple;"&gt;https://live.paloaltonetworks.com/docs/DOC-8771&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #1f497d;"&gt;However,the date output is completely different between the WLC5500 and 3850. Is there any other document we can refer to?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Mel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Mar 2015 02:33:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-data-for-userid-from-cisco-3850-wlc-to-palo-alto-pa-500/m-p/18386#M13416</guid>
      <dc:creator>MelLi</dc:creator>
      <dc:date>2015-03-03T02:33:15Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Data for UserID from Cisco 3850 WLC to Palo Alto PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-data-for-userid-from-cisco-3850-wlc-to-palo-alto-pa-500/m-p/18387#M13417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your regex appears to be correct. But I am not sure how PAN is interpreting #012 and #011. #011 is HT and #012 is LF in ASCII.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is a command used to test regex for syslog. &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;debug user-id test user-id-syslog-parse regex-identifier &lt;SPAN style="font-size: 13.3333330154419px;"&gt;event-regex "&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;Enterprise Specific Trap&lt;/SPAN&gt;" &lt;/SPAN&gt;username-regex "&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;3.6.1.4.1.14179.2.6.2.39.0 = STRING: &lt;/SPAN&gt;"&amp;nbsp; address-regex "&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;IpAddress: &lt;/SPAN&gt;" log-string "syslog string".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For "Field Identifier" you can try below example strings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Event String -&amp;gt;&amp;nbsp; Enterprise Specific Trap&lt;/P&gt;&lt;P&gt;Username Prefix -&amp;gt;&amp;nbsp; 3.6.1.4.1.14179.2.6.2.39.0 = STRING: &lt;/P&gt;&lt;P&gt;Username Delimiter -&amp;gt; \s&lt;/P&gt;&lt;P&gt;Address Prefix -&amp;gt; 3.6.1.4.1.14179.2.6.2.43.0 = IpAddress: &lt;/P&gt;&lt;P&gt;Address Delimiter -&amp;gt; \s&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to replace \s with #011 if above delimiter doesn't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Mar 2015 04:18:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-data-for-userid-from-cisco-3850-wlc-to-palo-alto-pa-500/m-p/18387#M13417</guid>
      <dc:creator>jthakur</dc:creator>
      <dc:date>2015-03-03T04:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Data for UserID from Cisco 3850 WLC to Palo Alto PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-data-for-userid-from-cisco-3850-wlc-to-palo-alto-pa-500/m-p/18388#M13418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;Hi Jthakur,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;Thank you for your suggestions. But there is still no success from our end.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #212121; font-family: wf_segoe-ui_normal, 'Segoe UI', 'Segoe WP', Tahoma, Arial, sans-serif; font-size: 15px;"&gt;&lt;SPAN style="font-size: 12px; font-family: Helvetica;"&gt;Please find our amended config using Field Identifier rather than Regex, in addition another SNMP trap from our test machine.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #212121; font-family: wf_segoe-ui_normal, 'Segoe UI', 'Segoe WP', Tahoma, Arial, sans-serif; font-size: 15px;"&gt;&lt;SPAN style="font-size: 12px; font-family: Helvetica;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #212121; font-family: wf_segoe-ui_normal, 'Segoe UI', 'Segoe WP', Tahoma, Arial, sans-serif; font-size: 15px;"&gt;&lt;/P&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt; font-family: Helvetica;"&gt;Mar&amp;nbsp; 4 13:00:27 syslog1 snmptrapd[2559]: 2015-03-04 13:00:27 10.5.80.1(via UDP: [10.5.80.1]:1028-&amp;gt;[10.5.80.47]:162) TRAP, SNMP v1, community public#012#011iso.3.6.1.4.1.14179.2.6.3 Enterprise Specific Trap (53) Uptime: 83 days, 4:06:36.07#012#011iso.3.6.1.4.1.14179.2.6.2.35.0 = Hex-STRING: F8 4F 57 A4 C2 B0 #011iso.3.6.1.4.1.14179.2.6.2.36.0 = INTEGER: 0#011iso.3.6.1.4.1.14179.2.6.2.43.0 = IpAddress: 10.5.185.2#011iso.3.6.1.4.1.14179.2.6.2.34.0 = Hex-STRING: E4 CE 8F 5B A5 54 #011iso.3.6.1.4.1.14179.2.6.2.39.0 = STRING: "test.staff"#011iso.3.6.1.4.1.14179.2.2.1.1.3.6.248.79.87.164.194.176 = STRING: "WAP-001”&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;P style="color: #212121; font-family: wf_segoe-ui_normal, 'Segoe UI', 'Segoe WP', Tahoma, Arial, sans-serif; font-size: 15px;"&gt;&lt;SPAN style="font-size: 12px; font-family: Helvetica;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #212121; font-family: wf_segoe-ui_normal, 'Segoe UI', 'Segoe WP', Tahoma, Arial, sans-serif; font-size: 15px;"&gt;&lt;SPAN style="font-size: 12px; font-family: Helvetica;"&gt;Doing a TCP dump, we can certainly verify that the PAN is receiving the messages.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #212121; font-family: wf_segoe-ui_normal, 'Segoe UI', 'Segoe WP', Tahoma, Arial, sans-serif; font-size: 15px;"&gt;&lt;SPAN style="font-size: 12px; font-family: Helvetica;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #212121; font-family: wf_segoe-ui_normal, 'Segoe UI', 'Segoe WP', Tahoma, Arial, sans-serif; font-size: 15px;"&gt;&lt;SPAN style="font-size: 12px; font-family: Helvetica;"&gt;Is there any debugging commands we can use on the PAN to see whether the device is interpreting the messages correctly?&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #212121; font-family: wf_segoe-ui_normal, 'Segoe UI', 'Segoe WP', Tahoma, Arial, sans-serif; font-size: 15px;"&gt;&lt;SPAN style="font-size: 12px; font-family: Helvetica;"&gt;We can see the below output from our PAN:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Proxy: syslog1(vsys: vsys1)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Host: syslog1(10.5.80.47)&lt;/P&gt;&lt;P style="color: #212121; font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 16px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; number of log messages&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 75255&lt;/P&gt;&lt;P style="color: #212121; font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 16px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; number of auth. success messages&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;/P&gt;&lt;P style="color: #212121; font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 16px;"&gt;&lt;/P&gt;&lt;P style="color: #212121; font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 16px;"&gt;kris.kopicki@gw&amp;gt; show user server-monitor state syslog1&lt;/P&gt;&lt;P style="color: #212121; font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 16px;"&gt;&lt;/P&gt;&lt;P style="color: #212121; font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 16px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP Syslog Listener Service is enabled&lt;/P&gt;&lt;P style="color: #212121; font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 16px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SSL Syslog Listener Service is enabled&lt;/P&gt;&lt;P style="color: #212121; font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 16px;"&gt;&lt;/P&gt;&lt;P style="color: #212121; font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 16px;"&gt;Proxy: syslog1(vsys: vsys1)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Host: syslog1(10.5.80.47)&lt;/P&gt;&lt;P style="color: #212121; font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 16px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; number of log messages&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 75259&lt;/P&gt;&lt;P style="color: #212121; font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 16px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; number of auth. success messages&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;/P&gt;&lt;P style="color: #212121; font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 16px;"&gt;&lt;/P&gt;&lt;P style="color: #212121; font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 16px;"&gt;Have you got any suggestions? Should we open a support case for this?&lt;/P&gt;&lt;P style="color: #212121; font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 16px;"&gt;&lt;/P&gt;&lt;P style="color: #212121; font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 16px;"&gt;Thanks in advance.&lt;/P&gt;&lt;P style="color: #212121; font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 16px;"&gt;&lt;/P&gt;&lt;P style="color: #212121; font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 16px;"&gt;Cheers,&lt;/P&gt;&lt;P style="color: #212121; font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 16px;"&gt;Mel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Mar 2015 03:05:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-data-for-userid-from-cisco-3850-wlc-to-palo-alto-pa-500/m-p/18388#M13418</guid>
      <dc:creator>MelLi</dc:creator>
      <dc:date>2015-03-04T03:05:48Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Data for UserID from Cisco 3850 WLC to Palo Alto PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-data-for-userid-from-cisco-3850-wlc-to-palo-alto-pa-500/m-p/18389#M13419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used the debug user-id command for syslog strings given as example in below and it it worked fine. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333330154419px;"&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6664"&gt;How to Configure a Custom Syslog Sender and Test User Mappings&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;gt; debug user-id test user-id-syslog-parse field-identifier event-string "User Authentication Successful:" username-prefix "username=" username-delimiter "\s" address-prefix "IP=" address-delimiter "\s" log-string "2013-03-20 12:56:53 local4.notice Aruba-Local3 authmgr[1568]: &amp;lt;522008&amp;gt; &amp;lt;NOTI&amp;gt; &amp;lt;Aruba-Local3 10.200.10.10&amp;gt; User Authentication Successful: username=ilija MAC=78:f5:fd:dd:ff:90 IP=10.200.27.67"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Field parsing successful, Username 'ilija', Address '10.200.27.67'&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which syslog server you are using? Can it convert snmp trap to syslog format? I did some research and found this link and I hope it is helpful in&amp;nbsp; fixing the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-8523"&gt;Use Syslog Receiver to Integrate with Cisco Wireless Controller Series&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check the above two links and if still no success, then you can open a case with support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Mar 2015 03:59:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-data-for-userid-from-cisco-3850-wlc-to-palo-alto-pa-500/m-p/18389#M13419</guid>
      <dc:creator>jthakur</dc:creator>
      <dc:date>2015-03-04T03:59:10Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Data for UserID from Cisco 3850 WLC to Palo Alto PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-data-for-userid-from-cisco-3850-wlc-to-palo-alto-pa-500/m-p/18390#M13420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;For "Field Identifier" I use the following strings: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Username Prefix -&amp;gt;&amp;nbsp; &lt;STRONG style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;cldcClientUsername.0=&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Username Delimiter -&amp;gt; ,&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Address Prefix -&amp;gt; &lt;STRONG style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;cldcClientIPAddress.0=&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Address Delimiter -&amp;gt; ,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jul 2015 16:50:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-data-for-userid-from-cisco-3850-wlc-to-palo-alto-pa-500/m-p/18390#M13420</guid>
      <dc:creator>Oleksandr</dc:creator>
      <dc:date>2015-07-14T16:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Data for UserID from Cisco 3850 WLC to Palo Alto PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-data-for-userid-from-cisco-3850-wlc-to-palo-alto-pa-500/m-p/191092#M57614</link>
      <description>&lt;P&gt;Please can you help me with Cisco iOS XE configuration how to send the snmp traps (or syslog)&amp;nbsp;to kiwi syslog or the firewall?&lt;/P&gt;&lt;P&gt;I mean what is the commands in Cisco iOS that generate client IP addressa and username (like aa accounting, radius-server and snmp-server commands)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry I don't have much experiance with cisco on this manner.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2017 17:02:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-data-for-userid-from-cisco-3850-wlc-to-palo-alto-pa-500/m-p/191092#M57614</guid>
      <dc:creator>mikealanni</dc:creator>
      <dc:date>2017-12-11T17:02:24Z</dc:date>
    </item>
  </channel>
</rss>

