<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Warning: undocumented change in syslog format in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/warning-undocumented-change-in-syslog-format/m-p/48678#M35845</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Heads-up to everybody: in version 4.x of PANOS, they have decided to make the following changes in their syslog format:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. In the Miscellaneous field of the Threat Log syslog, where the URL a user visits is reported, the URL data used to be placed between double quotes. This makes sense because a URL may contain a comma, which is also the separator of the syslog fields. Now, only URLs that contain commas are quoted, and those that don't are not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. The username in all logs, when it comes from the AD user agent, used to be in the format domain\username. It's now domain\\username (double backslash).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tech support confirms that these changes are not bugs, but expected behavior by design. They were apparently made without first notifying their syslog integration partners (&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1418"&gt;https://live.paloaltonetworks.com/docs/DOC-1418&lt;/A&gt;), or bothering to document them in any release notes. This of course affects integration with SIEM (security information and event management) tools that clients like us use to parse, correlate and report on syslog data for different devices, severely impeding our ability to monitor network traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please be aware of this if you export PAN syslogs to other devices.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 24 May 2011 12:45:11 GMT</pubDate>
    <dc:creator>ahopkins</dc:creator>
    <dc:date>2011-05-24T12:45:11Z</dc:date>
    <item>
      <title>Warning: undocumented change in syslog format</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warning-undocumented-change-in-syslog-format/m-p/48678#M35845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Heads-up to everybody: in version 4.x of PANOS, they have decided to make the following changes in their syslog format:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. In the Miscellaneous field of the Threat Log syslog, where the URL a user visits is reported, the URL data used to be placed between double quotes. This makes sense because a URL may contain a comma, which is also the separator of the syslog fields. Now, only URLs that contain commas are quoted, and those that don't are not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. The username in all logs, when it comes from the AD user agent, used to be in the format domain\username. It's now domain\\username (double backslash).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tech support confirms that these changes are not bugs, but expected behavior by design. They were apparently made without first notifying their syslog integration partners (&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1418"&gt;https://live.paloaltonetworks.com/docs/DOC-1418&lt;/A&gt;), or bothering to document them in any release notes. This of course affects integration with SIEM (security information and event management) tools that clients like us use to parse, correlate and report on syslog data for different devices, severely impeding our ability to monitor network traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please be aware of this if you export PAN syslogs to other devices.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 May 2011 12:45:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warning-undocumented-change-in-syslog-format/m-p/48678#M35845</guid>
      <dc:creator>ahopkins</dc:creator>
      <dc:date>2011-05-24T12:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: Warning: undocumented change in syslog format</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warning-undocumented-change-in-syslog-format/m-p/48679#M35846</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for this information.&lt;/P&gt;&lt;P&gt;Does anyone know if syslog integration partners are now notified about this change and if they implemented it on new versions (especially syslog-ng &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Sep 2011 08:11:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warning-undocumented-change-in-syslog-format/m-p/48679#M35846</guid>
      <dc:creator>Duplem</dc:creator>
      <dc:date>2011-09-28T08:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: Warning: undocumented change in syslog format</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warning-undocumented-change-in-syslog-format/m-p/48680#M35847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@eduplaa: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would need to contact the relevant partner to see if they have already adapted their product to read the 4.0 PAN-OS log format changes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syslog Integration Partner list is here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-1418"&gt;https://live.paloaltonetworks.com/docs/DOC-1418&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Sep 2011 21:53:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warning-undocumented-change-in-syslog-format/m-p/48680#M35847</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-09-28T21:53:24Z</dc:date>
    </item>
  </channel>
</rss>

