<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CONFIG logs and syslog in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/63758#M38321</link>
    <description>&lt;P&gt;Hi Sven,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sorry for quick reading. I would say that is expected behavior, per documentation found here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Articles/PAN-OS-Syslog-Integration/ta-p/55323" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Articles/PAN-OS-Syslog-Integration/ta-p/55323&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CONFIG&lt;BR /&gt;FUTURE_USE, Receive Time, Serial Number, Type, Subtype, FUTURE_USE, FUTURE_USE, Host, Virtual&lt;BR /&gt;System, Command, Admin, Client, Result, Configuration Path, Sequence Number, Action Flags&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;full description on page 14&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luciano&lt;/P&gt;</description>
    <pubDate>Thu, 27 Aug 2015 22:08:21 GMT</pubDate>
    <dc:creator>Lucky</dc:creator>
    <dc:date>2015-08-27T22:08:21Z</dc:date>
    <item>
      <title>CONFIG logs and syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/63523#M38211</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we're shipping our logs to a centralized syslog instance. That works great for all types of logs from the PA with the exceptions of the CONFIG logs.&lt;/P&gt;&lt;P&gt;The CONFIG logs are submitted at all, with the problem that the interesting parts "before-change-detail" and "after-change-detail" are not delivered.&lt;/P&gt;&lt;P&gt;Does anyone else ship CONFIG logs and if yes, do you see the same behaviour?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for advice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Submitted Syslog Message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;2015-02-02 10:32:59	User.Info	1.2.3.4	Feb  2 10:32:59 paloalto.domain.com 1,2015/02/02 10:32:59,123444,CONFIG,0,0,2015/02/02 10:32:59,1.2.33.4,,edit,admin-name,Web,Succeeded, vsys  vsys1 rulebase security rules  one-rule-to-rule-them-all,1544,0x0 &lt;/PRE&gt;&lt;P&gt;Expected Syslog Message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;2015-02-02 10:32:59 User.Info 1.2.3.4 Feb 2 10:32:59 paloalto.domain.com 1,2015/02/02 10:32:59,123444,CONFIG,0,0,2015/02/02 10:32:59,1.2.33.4,,edit,admin-name,Web,Succeeded, vsys vsys1 rulebase security rules one-rule-to-rule-them-all,before-change-detail,after-change-detail,1544,0x0 &lt;/PRE&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 01 Sep 2015 08:48:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/63523#M38211</guid>
      <dc:creator>Sven_Lieckfeldt</dc:creator>
      <dc:date>2015-09-01T08:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: CONFIG logs and syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/63527#M38214</link>
      <description>Hi Sven, can you please tell me what version of PAN-OS are you running? Syslog setup has changed in ver. 7.0. Also, setting forwarding of the config logs is done via tab Device &amp;gt; Log Settings &amp;gt; Config, where you can choose to forward Configs to the pre-defined syslog profile. Now, if you aren't seeing any logs forwarded, you should really be opening the support case &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Can you sniff outgoing traffic from the firewall (take tcpdump from CLI) and see if config logs are also being forwarded? I am not sure about the format question you are asking for, would have to look it up, but forwarding of config logs is simple and should work if configured as explained above. regards Luciano</description>
      <pubDate>Mon, 24 Aug 2015 12:18:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/63527#M38214</guid>
      <dc:creator>Lucky</dc:creator>
      <dc:date>2015-08-24T12:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: CONFIG logs and syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/63530#M38216</link>
      <description>&lt;P&gt;Hi Luciano,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;we're running PAN-OS 6.1.5. Logshipping is done via UDP; we've tried TCP with no difference in the result.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;CONFIG logs are successful submitted, but a portion of the content is missing; see my sample snippets.&lt;/P&gt;&lt;P&gt;When you export Montior &amp;gt; Configuration to a csv file you have two fields called "before-change-detail" and "after-change-detail". Those two fields are missing in the syslog stream.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Update 1: Just did a tcpdump as suggested. Data is sent, but without those two fields in question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Sven&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2015 13:22:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/63530#M38216</guid>
      <dc:creator>Sven_Lieckfeldt</dc:creator>
      <dc:date>2015-08-24T13:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: CONFIG logs and syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/63758#M38321</link>
      <description>&lt;P&gt;Hi Sven,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sorry for quick reading. I would say that is expected behavior, per documentation found here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Articles/PAN-OS-Syslog-Integration/ta-p/55323" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Articles/PAN-OS-Syslog-Integration/ta-p/55323&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CONFIG&lt;BR /&gt;FUTURE_USE, Receive Time, Serial Number, Type, Subtype, FUTURE_USE, FUTURE_USE, Host, Virtual&lt;BR /&gt;System, Command, Admin, Client, Result, Configuration Path, Sequence Number, Action Flags&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;full description on page 14&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luciano&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2015 22:08:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/63758#M38321</guid>
      <dc:creator>Lucky</dc:creator>
      <dc:date>2015-08-27T22:08:21Z</dc:date>
    </item>
    <item>
      <title>Re: CONFIG logs and syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/63759#M38322</link>
      <description>&lt;P&gt;test&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2015 00:48:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/63759#M38322</guid>
      <dc:creator>jeleong</dc:creator>
      <dc:date>2015-08-28T00:48:11Z</dc:date>
    </item>
    <item>
      <title>Re: CONFIG logs and syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/63926#M38399</link>
      <description>&lt;P&gt;Hi Luciano,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your answer and sorry for the delay in my answer. I didn't received a&amp;nbsp;notification...&lt;/P&gt;&lt;P&gt;The article refers to PAN-OS 5, so I've double checked the version 6.1 document. And in the syslog portion it is stated that "before change detail" and "after change detail" are onyl used in the custom syslog format, not in the default one.&lt;/P&gt;&lt;P&gt;So I've played around with it now these two&amp;nbsp;informations are submitted, more or less complete. For exmaple: An application group with many apps included would be altered in the "before change detail" but the changed value is&amp;nbsp;available. So one can follow the trace...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now it looks like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;palotalto.domain.com 1,2015/09/01 10:38:49,S/N,CONFIG,0,2015/09/01 10:38:49,1.2.3.4,,edit,admin,Web,Succeeded, vsys  vsys1 application-group  Test-Apps,4296,0x0,Test-Apps { } ,Test-Apps [ aim-file-transfer ]; &lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for you hint!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 08:47:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/63926#M38399</guid>
      <dc:creator>Sven_Lieckfeldt</dc:creator>
      <dc:date>2015-09-01T08:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: CONFIG logs and syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/261642#M74176</link>
      <description>&lt;P&gt;I was looking at this today and it looks like this is still the case - I'm running 8.0 code. Syslog does not contain change information. Can anyone confirm? Just want to make sure before I change the default to custom.&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 14:50:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/261642#M74176</guid>
      <dc:creator>mike406</dc:creator>
      <dc:date>2019-05-20T14:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: CONFIG logs and syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/261702#M74200</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79413"&gt;@mike406&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Mine also does not send what the actual change was to the syslog, 8.0.x.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 20:27:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/261702#M74200</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-05-20T20:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: CONFIG logs and syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/261706#M74203</link>
      <description>&lt;P&gt;Thanks for confirming.&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 21:42:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/261706#M74203</guid>
      <dc:creator>mike406</dc:creator>
      <dc:date>2019-05-20T21:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: CONFIG logs and syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/349446#M86856</link>
      <description>&lt;P&gt;Any update on this? I am running to the same issue where I add custom fields in Config on Palo.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/config-log-fields.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/config-log-fields.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I still see no value in Splunk&amp;nbsp;result after_change_detail&amp;nbsp; and&amp;nbsp; before_change_detail&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 18:06:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/349446#M86856</guid>
      <dc:creator>Abdulmunem</dc:creator>
      <dc:date>2020-09-15T18:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: CONFIG logs and syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/349448#M86858</link>
      <description>&lt;P&gt;Any update on this? I am running to the same issue where I add custom fields in Config on Palo.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/config-log-fields.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/config-log-fields.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I still see no value in Splunk&amp;nbsp;result after_change_detail&amp;nbsp; and&amp;nbsp; before_change_detail&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 18:09:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/349448#M86858</guid>
      <dc:creator>Abdulmunem</dc:creator>
      <dc:date>2020-09-15T18:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: CONFIG logs and syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/1226357#M123958</link>
      <description>&lt;P&gt;Did you ever find a resolution to this? We're running into an issue where the syslog-ng server isn't seeing the before_change_detail and after_change_detail fields.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 16:28:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/1226357#M123958</guid>
      <dc:creator>bgooch</dc:creator>
      <dc:date>2025-04-11T16:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: CONFIG logs and syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/1226358#M123959</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;What format are you sending the logs from the PAN to the syslog server? Its possible the SIEM is not able to parse the log correctly.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 17:02:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/1226358#M123959</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2025-04-11T17:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: CONFIG logs and syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/1226359#M123960</link>
      <description>&lt;P&gt;We've tried the default, but apparently that doesn't contain the&amp;nbsp;&lt;SPAN&gt;before_change_detail and after_change_detail fields. So then we've moved over to doing a custom format where we click the field name on the left hand side for each field we want to include, and syslog-ng still sees a 0 value for those fields. We've also tried to click each field name on the left and separate them with commas hoping that it's a parsing issue, and that also is not working.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 17:09:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/1226359#M123960</guid>
      <dc:creator>bgooch</dc:creator>
      <dc:date>2025-04-11T17:09:11Z</dc:date>
    </item>
    <item>
      <title>Re: CONFIG logs and syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/1226375#M123962</link>
      <description>&lt;P&gt;This should work for you in the custom log field. I found this documented from another user on a Splunk forum and it worked for us after tooling around with it for way too long. Previously, we were sending logs over to syslog-ng and the&amp;nbsp;&lt;SPAN&gt;before_change_detail and after_change_detail fields were 0.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Custom-Log-Format/m-p/416101" target="_blank"&gt;https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Custom-Log-Format/m-p/416101&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Palo Alto Custom Log Format, Config, All Fields&lt;/P&gt;
&lt;P&gt;actionflags="$actionflags", admin="$admin", after-change-detail="$after-change-detail", before-change-detail="$before-change-detail", cef-formatted-receive_time="$cef-formatted-receive_time", cef-formatted-time_generated="$cef-formatted-time_generated", client="$client", cmd="$cmd", host="$host", path="$path", receive_time="$receive_time", result="$result", seqno="$seqno", serial="$serial", subtype="$subtype", time_generated="$time_generated", type="$type", vsys="$vsys"&lt;/P&gt;
&lt;P&gt;Palo Alto Custom Log Format, HIP Match, All Fields&lt;BR /&gt;actionflags="$actionflags", cef-formatted-receive_time="$cef-formatted-receive_time", cef-formatted-time_generated="$cef-formatted-time_generated", machinename="$machinename", matchname="$matchname", matchtype="$matchtype", receive_time="$receive_time", repeatcnt="$repeatcnt", seqno="$seqno", serial="$serial", src="$src", srcuser="$srcuser", subtype="$subtype", time_generated="$time_generated", type="$type", vsys="$vsys"&lt;/P&gt;
&lt;P&gt;Palo Alto Custom Log Format, Traffic, All Fields&lt;BR /&gt;action="$action", actionflags="$actionflags", app="$app", bytes="$bytes", bytes_received="$bytes_received", bytes_sent="$bytes_sent", category="$category", cef-formatted-receive_time="$cef-formatted-receive_time", cef-formatted-time_generated="$cef-formatted-time_generated", dport="$dport", dst="$dst", dstloc="$dstloc", dstuser="$dstuser", elapsed="$elapsed", flags="$flags", from="$from", inbound_if="$inbound_if", logset="$logset", natdport="$natdport", natdst="$natdst", natsport="$natsport", natsrc="$natsrc", outbound_if="$outbound_if", packets="$packets", padding="$padding", pkts_received="$pkts_received", pkts_sent="$pkts_sent", proto="$proto", receive_time="$receive_time", repeatcnt="$repeatcnt", rule="$rule", seqno="$seqno", serial="$serial", sessionid="$sessionid", sport="$sport", src="$src", srcloc="$srcloc", srcuser="$srcuser", start="$start", subtype="$subtype", time_generated="$time_generated", time_received="$time_received", to="$to", type="$type", vsys="$vsys"&lt;/P&gt;
&lt;P&gt;Palo Alto Custom Log Format, Threat, All Fields&lt;BR /&gt;action="$action", actionflags="$actionflags", app="$app", category="$category", cef-formatted-receive_time="$cef-formatted-receive_time", cef-formatted-time_generated="$cef-formatted-time_generated", contenttype="$contenttype", direction="$direction", dport="$dport", dst="$dst", dstloc="$dstloc", dstuser="$dstuser", flags="$flags", from="$from", inbound_if="$inbound_if", logset="$logset", misc="$misc", natdport="$natdport", natdst="$natdst", natsport="$natsport", natsrc="$natsrc", number-of-severity="$number-of-severity", outbound_if="$outbound_if", proto="$proto", receive_time="$receive_time", repeatcnt="$repeatcnt", rule="$rule", seqno="$seqno", serial="$serial", sessionid="$sessionid", severity="$severity", sport="$sport", src="$src", srcloc="$srcloc", srcuser="$srcuser", subtype="$subtype", threatid="$threatid", time_generated="$time_generated", time_received="$time_received", to="$to", type="$type", vsys="$vsys"&lt;/P&gt;
&lt;P&gt;Palo Alto Custom Log Format, System, All Fields&lt;BR /&gt;actionflags="$actionflags", cef-formatted-receive_time="$cef-formatted-receive_time", cef-formatted-time_generated="$cef-formatted-time_generated", eventid="$eventid", module="$module", number-of-severity="$number-of-severity", object="$object", opaque="$opaque", receive_time="$receive_time", seqno="$seqno", serial="$serial", severity="$severity", subtype="$subtype", time_generated="$time_generated", type="$type", vsys="$vsys"&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 18:07:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/1226375#M123962</guid>
      <dc:creator>bgooch</dc:creator>
      <dc:date>2025-04-11T18:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: CONFIG logs and syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/1226376#M123963</link>
      <description>&lt;P&gt;Fixed - see reply above.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Palo Alto Custom Log Format, Config, All Fields&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;actionflags="$actionflags", admin="$admin", after-change-detail="$after-change-detail", before-change-detail="$before-change-detail", cef-formatted-receive_time="$cef-formatted-receive_time", cef-formatted-time_generated="$cef-formatted-time_generated", client="$client", cmd="$cmd", host="$host", path="$path", receive_time="$receive_time", result="$result", seqno="$seqno", serial="$serial", subtype="$subtype", time_generated="$time_generated", type="$type", vsys="$vsys"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Palo Alto Custom Log Format, HIP Match, All Fields&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;actionflags="$actionflags", cef-formatted-receive_time="$cef-formatted-receive_time", cef-formatted-time_generated="$cef-formatted-time_generated", machinename="$machinename", matchname="$matchname", matchtype="$matchtype", receive_time="$receive_time", repeatcnt="$repeatcnt", seqno="$seqno", serial="$serial", src="$src", srcuser="$srcuser", subtype="$subtype", time_generated="$time_generated", type="$type", vsys="$vsys"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Palo Alto Custom Log Format, Traffic, All Fields&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;action="$action", actionflags="$actionflags", app="$app", bytes="$bytes", bytes_received="$bytes_received", bytes_sent="$bytes_sent", category="$category", cef-formatted-receive_time="$cef-formatted-receive_time", cef-formatted-time_generated="$cef-formatted-time_generated", dport="$dport", dst="$dst", dstloc="$dstloc", dstuser="$dstuser", elapsed="$elapsed", flags="$flags", from="$from", inbound_if="$inbound_if", logset="$logset", natdport="$natdport", natdst="$natdst", natsport="$natsport", natsrc="$natsrc", outbound_if="$outbound_if", packets="$packets", padding="$padding", pkts_received="$pkts_received", pkts_sent="$pkts_sent", proto="$proto", receive_time="$receive_time", repeatcnt="$repeatcnt", rule="$rule", seqno="$seqno", serial="$serial", sessionid="$sessionid", sport="$sport", src="$src", srcloc="$srcloc", srcuser="$srcuser", start="$start", subtype="$subtype", time_generated="$time_generated", time_received="$time_received", to="$to", type="$type", vsys="$vsys"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Palo Alto Custom Log Format, Threat, All Fields&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;action="$action", actionflags="$actionflags", app="$app", category="$category", cef-formatted-receive_time="$cef-formatted-receive_time", cef-formatted-time_generated="$cef-formatted-time_generated", contenttype="$contenttype", direction="$direction", dport="$dport", dst="$dst", dstloc="$dstloc", dstuser="$dstuser", flags="$flags", from="$from", inbound_if="$inbound_if", logset="$logset", misc="$misc", natdport="$natdport", natdst="$natdst", natsport="$natsport", natsrc="$natsrc", number-of-severity="$number-of-severity", outbound_if="$outbound_if", proto="$proto", receive_time="$receive_time", repeatcnt="$repeatcnt", rule="$rule", seqno="$seqno", serial="$serial", sessionid="$sessionid", severity="$severity", sport="$sport", src="$src", srcloc="$srcloc", srcuser="$srcuser", subtype="$subtype", threatid="$threatid", time_generated="$time_generated", time_received="$time_received", to="$to", type="$type", vsys="$vsys"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Palo Alto Custom Log Format, System, All Fields&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;actionflags="$actionflags", cef-formatted-receive_time="$cef-formatted-receive_time", cef-formatted-time_generated="$cef-formatted-time_generated", eventid="$eventid", module="$module", number-of-severity="$number-of-severity", object="$object", opaque="$opaque", receive_time="$receive_time", seqno="$seqno", serial="$serial", severity="$severity", subtype="$subtype", time_generated="$time_generated", type="$type", vsys="$vsys"&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 18:08:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/1226376#M123963</guid>
      <dc:creator>bgooch</dc:creator>
      <dc:date>2025-04-11T18:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: CONFIG logs and syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/1226991#M124059</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1012064451"&gt;@bgooch&lt;/a&gt;&amp;nbsp;what version of code are you using?&lt;BR /&gt;On 10.2.10, configuring a custom log format which includes $before-change-detail and&amp;nbsp;$after-change-detail does not yield field values with details.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I opened&amp;nbsp;&lt;SPAN&gt;NSFR-I-28389 for this in 2019.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 18:57:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/1226991#M124059</guid>
      <dc:creator>fwmike2</dc:creator>
      <dc:date>2025-04-21T18:57:06Z</dc:date>
    </item>
    <item>
      <title>Re: CONFIG logs and syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/1227120#M124067</link>
      <description>&lt;P&gt;My customer is on 11.1.6-h1 at the moment.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 13:13:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-logs-and-syslog/m-p/1227120#M124067</guid>
      <dc:creator>bgooch</dc:creator>
      <dc:date>2025-04-22T13:13:04Z</dc:date>
    </item>
  </channel>
</rss>

