<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic A few Panorama-questions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/a-few-panorama-questions/m-p/47037#M34573</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Got a few question related to Panorama which I hope you can help me with?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Whats the FR id regarding having Panorama to be able to forward received logs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is PA-device -&amp;gt; Panorama -&amp;gt; SEIM/Syslogarchive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) For which version is this feature expected to show up, and any ETA for when we will see this version available in the download section (that is version and date)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) If you log towards an ArcSight installation you can use the CEF-format in the PA-devices. However the CEF format has an overhead of approx 220 bytes (or so) per msg. Which gives that during a burst of say 100.000 msgs/sec the overhead is approx 176 Mbit/s on the line.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do there exist a more efficient way of transmitting logs from PA to ArcSight other than CEF?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mean did PA (or HP?) create a custom flexconnector or such to read native format of PA or is CEF the only available option unless I want to create a flexconnector on my own?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) Speaking of CEF, any ETA (version and date) for when we will see panos version as a variable?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Aug 2013 08:41:06 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2013-08-26T08:41:06Z</dc:date>
    <item>
      <title>A few Panorama-questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-few-panorama-questions/m-p/47037#M34573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Got a few question related to Panorama which I hope you can help me with?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Whats the FR id regarding having Panorama to be able to forward received logs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is PA-device -&amp;gt; Panorama -&amp;gt; SEIM/Syslogarchive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) For which version is this feature expected to show up, and any ETA for when we will see this version available in the download section (that is version and date)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) If you log towards an ArcSight installation you can use the CEF-format in the PA-devices. However the CEF format has an overhead of approx 220 bytes (or so) per msg. Which gives that during a burst of say 100.000 msgs/sec the overhead is approx 176 Mbit/s on the line.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do there exist a more efficient way of transmitting logs from PA to ArcSight other than CEF?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mean did PA (or HP?) create a custom flexconnector or such to read native format of PA or is CEF the only available option unless I want to create a flexconnector on my own?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) Speaking of CEF, any ETA (version and date) for when we will see panos version as a variable?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Aug 2013 08:41:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-few-panorama-questions/m-p/47037#M34573</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-08-26T08:41:06Z</dc:date>
    </item>
    <item>
      <title>Re: A few Panorama-questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/a-few-panorama-questions/m-p/47038#M34574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...The FR ID is 782.&amp;nbsp; If you have a customer who wants this feature, please submit the customer's name to your local SE and the SE can add to the FR.&amp;nbsp; This feature is coming soon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For ArcSight, there was a FlexConnector developed several years ago and HP (ArcSight) is responsible for it.&amp;nbsp; You should check with HP to see if they still offer it. Otherwise, CEF format is supported as you have pointed out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Aug 2013 14:59:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/a-few-panorama-questions/m-p/47038#M34574</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2013-08-26T14:59:25Z</dc:date>
    </item>
  </channel>
</rss>

