<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic syslog from PAM OS 3.1 to 4.1 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-from-pam-os-3-1-to-4-1/m-p/5155#M3790</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I migrated our PAN FW from 3.1 to 4.1 and there is some more fields on TRAFFIC and THREAT syslog format.&lt;/P&gt;&lt;P&gt;With 3.1, using syslog-ng, I got:&lt;/P&gt;&lt;P&gt;Sep 27 00:00:35 giacometti-2 00: 00:35,0003C100873,TRAFFIC,end, etc ...&lt;/P&gt;&lt;P&gt;Since by defualt in 4.1 there is more field than with 3.1 I'd like to customize the syslog format in a way that have the sames format as it was on 3.1 (to avoind, for the moment to change syslog parser tool):&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;$serial,$type,$subtype,$padding&lt;/STRONG&gt;,$time_generated,$src,$dst,$natsrc,$natdst,$rule,$srcuser,$dstuser,$app,$vsys,$from,$to,$inbound_if,$outbound_if,$logset,$padding,$sessionid,$repeatcnt,$sport,$dport,$natsport,$natdport,$flags,$proto,$action,$bytes,$bytes_sent,$bytes_received,$packets,$start,$elapsed,$category,$padding&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And with this format i get:&lt;/P&gt;&lt;P&gt;Sep 28 16:29:16 giacometti-test 16: 29:15,10.44.39.26,199.47.219.159,0.0.0.0,0.0.0.0,AC Standard,ac\t128636,,ssl,vsys1,AC-Trust,AC-Untrust,ethernet1/3,ethernet1/4,Netlog-AC,0,136120,1,4310,443,0,0,0x0,tcp,allow,354,288,66,4,2012/09/28 16:29:15,0,any,0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see the firs 4 fields (&lt;STRONG&gt;$serial,$type,$subtype,$padding&lt;/STRONG&gt;) are dropped somewhere, does someone have an idea why ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 28 Sep 2012 14:36:24 GMT</pubDate>
    <dc:creator>helenio.sartori</dc:creator>
    <dc:date>2012-09-28T14:36:24Z</dc:date>
    <item>
      <title>syslog from PAM OS 3.1 to 4.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-from-pam-os-3-1-to-4-1/m-p/5155#M3790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I migrated our PAN FW from 3.1 to 4.1 and there is some more fields on TRAFFIC and THREAT syslog format.&lt;/P&gt;&lt;P&gt;With 3.1, using syslog-ng, I got:&lt;/P&gt;&lt;P&gt;Sep 27 00:00:35 giacometti-2 00: 00:35,0003C100873,TRAFFIC,end, etc ...&lt;/P&gt;&lt;P&gt;Since by defualt in 4.1 there is more field than with 3.1 I'd like to customize the syslog format in a way that have the sames format as it was on 3.1 (to avoind, for the moment to change syslog parser tool):&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;$serial,$type,$subtype,$padding&lt;/STRONG&gt;,$time_generated,$src,$dst,$natsrc,$natdst,$rule,$srcuser,$dstuser,$app,$vsys,$from,$to,$inbound_if,$outbound_if,$logset,$padding,$sessionid,$repeatcnt,$sport,$dport,$natsport,$natdport,$flags,$proto,$action,$bytes,$bytes_sent,$bytes_received,$packets,$start,$elapsed,$category,$padding&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And with this format i get:&lt;/P&gt;&lt;P&gt;Sep 28 16:29:16 giacometti-test 16: 29:15,10.44.39.26,199.47.219.159,0.0.0.0,0.0.0.0,AC Standard,ac\t128636,,ssl,vsys1,AC-Trust,AC-Untrust,ethernet1/3,ethernet1/4,Netlog-AC,0,136120,1,4310,443,0,0,0x0,tcp,allow,354,288,66,4,2012/09/28 16:29:15,0,any,0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see the firs 4 fields (&lt;STRONG&gt;$serial,$type,$subtype,$padding&lt;/STRONG&gt;) are dropped somewhere, does someone have an idea why ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2012 14:36:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-from-pam-os-3-1-to-4-1/m-p/5155#M3790</guid>
      <dc:creator>helenio.sartori</dc:creator>
      <dc:date>2012-09-28T14:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: syslog from PAM OS 3.1 to 4.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-from-pam-os-3-1-to-4-1/m-p/5156#M3791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Checkout device-&amp;gt;server profiles-&amp;gt;syslog&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create a profile and then customize it via the custom log format tab.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2012 16:59:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-from-pam-os-3-1-to-4-1/m-p/5156#M3791</guid>
      <dc:creator>msullivan</dc:creator>
      <dc:date>2012-09-28T16:59:54Z</dc:date>
    </item>
  </channel>
</rss>

