<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue in the syslog message format in Palo Alto 6 beta 1 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issue-in-the-syslog-message-format-in-palo-alto-6-beta-1/m-p/25559#M18646</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am currently on Palo Alto v 6.0.0-b23 and facing an issue with the format of syslog message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if we pass the same malicious file through Palo Alto device, syslog message forwarded by Palo Alto v5.0.6 and v6.0 beta are different. Palo Alto 5.0.6 forwards threat name and ID while Palo Alto 6 beta forward threat ID twice. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Log on Palo Alto 6.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dec 05 22:38:41 10.208.35.87 Dec&amp;nbsp; 5 22:36:06 PA-VM 1,2013/12/05 22:36:06,007000001148,THREAT,virus,1,2013/12/05 22:36:01,xx.xx.xx.xx,xx.xx.xx.xx,0.0.0.0,0.0.0.0,Test,,,ftp,vsys1,Trust,Untrust,ethernet1/1,ethernet1/2,Log Forwarding,2013/12/05 22:36:06,38355,1,49512,53627,0,0,0x0,tcp,deny,"filename",&lt;SPAN style="color: #ff9900;"&gt;2001508(2001508)&lt;/SPAN&gt;,any,medium,server-to-client,0,0x0,192.0.0.0-192.255.255.255,192.0.0.0-192.255.255.255,0,,0,,,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Log on Palo Alto 5.0.6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 2 06:33:42 10.102.102.45 1,2013/05/02 06:33:42,0006C111278,THREAT,virus,1,2013/05/02 06:33:36,xx.xx.xx.xx,xx.xx.xx.xx,,,rule2,,,ftp,vsys1,trust,trust,ethernet1/2,ethernet1/1,server-1,2013/05/02 06:33:41,9761,1,32277,44445,0,0,0x80000000,tcp,deny,"filename",&lt;SPAN style="color: #ff9900;"&gt;Trojan/Win32.Loring.a(2001508)&lt;/SPAN&gt;,any,medium,server-to-client,81,0x0,192.0.0.0-192.255.255.255,192.0.0.0-192.255.255.255,0,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this change intentional or will it be fixed in the GA version or already fixed in the beta 4?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Dec 2013 14:28:28 GMT</pubDate>
    <dc:creator>NHorsch</dc:creator>
    <dc:date>2013-12-06T14:28:28Z</dc:date>
    <item>
      <title>Issue in the syslog message format in Palo Alto 6 beta 1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-in-the-syslog-message-format-in-palo-alto-6-beta-1/m-p/25559#M18646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am currently on Palo Alto v 6.0.0-b23 and facing an issue with the format of syslog message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if we pass the same malicious file through Palo Alto device, syslog message forwarded by Palo Alto v5.0.6 and v6.0 beta are different. Palo Alto 5.0.6 forwards threat name and ID while Palo Alto 6 beta forward threat ID twice. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Log on Palo Alto 6.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dec 05 22:38:41 10.208.35.87 Dec&amp;nbsp; 5 22:36:06 PA-VM 1,2013/12/05 22:36:06,007000001148,THREAT,virus,1,2013/12/05 22:36:01,xx.xx.xx.xx,xx.xx.xx.xx,0.0.0.0,0.0.0.0,Test,,,ftp,vsys1,Trust,Untrust,ethernet1/1,ethernet1/2,Log Forwarding,2013/12/05 22:36:06,38355,1,49512,53627,0,0,0x0,tcp,deny,"filename",&lt;SPAN style="color: #ff9900;"&gt;2001508(2001508)&lt;/SPAN&gt;,any,medium,server-to-client,0,0x0,192.0.0.0-192.255.255.255,192.0.0.0-192.255.255.255,0,,0,,,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Log on Palo Alto 5.0.6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 2 06:33:42 10.102.102.45 1,2013/05/02 06:33:42,0006C111278,THREAT,virus,1,2013/05/02 06:33:36,xx.xx.xx.xx,xx.xx.xx.xx,,,rule2,,,ftp,vsys1,trust,trust,ethernet1/2,ethernet1/1,server-1,2013/05/02 06:33:41,9761,1,32277,44445,0,0,0x80000000,tcp,deny,"filename",&lt;SPAN style="color: #ff9900;"&gt;Trojan/Win32.Loring.a(2001508)&lt;/SPAN&gt;,any,medium,server-to-client,81,0x0,192.0.0.0-192.255.255.255,192.0.0.0-192.255.255.255,0,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this change intentional or will it be fixed in the GA version or already fixed in the beta 4?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Dec 2013 14:28:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-in-the-syslog-message-format-in-palo-alto-6-beta-1/m-p/25559#M18646</guid>
      <dc:creator>NHorsch</dc:creator>
      <dc:date>2013-12-06T14:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: Issue in the syslog message format in Palo Alto 6 beta 1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-in-the-syslog-message-format-in-palo-alto-6-beta-1/m-p/25560#M18647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;Please report this issue to the Beta support alias for investigation at : &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:betasupport@paloaltonetworks.com"&gt;betasupport@paloaltonetworks.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Dec 2013 16:07:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-in-the-syslog-message-format-in-palo-alto-6-beta-1/m-p/25560#M18647</guid>
      <dc:creator>goku123</dc:creator>
      <dc:date>2013-12-06T16:07:45Z</dc:date>
    </item>
  </channel>
</rss>

