<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Syslog parser in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-parser/m-p/78034#M42796</link>
    <description>&lt;P&gt;I don't think you can either do that or use that. Syslog listerner is designed only to work with User-ID. And even if you managed to extract OS info by some 3rd party syslog parser there is no way to use it in FW policy afaik.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is only used with GP checks.&lt;/P&gt;</description>
    <pubDate>Fri, 13 May 2016 06:34:30 GMT</pubDate>
    <dc:creator>santonic</dc:creator>
    <dc:date>2016-05-13T06:34:30Z</dc:date>
    <item>
      <title>Syslog parser</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-parser/m-p/78008#M42790</link>
      <description>&lt;P&gt;Hi all, do you know if it is possible to use the syslog parser to obtain device information (for instance Operating system) and use this info in security rules?. I am using the syslog parser to obtain the IP-User mapping and it works perfectly, now I would like to obtain more info from the log. I know that the device info is available if you use GlobalProtect and HIP profiles but I would like to have this feature without install globalprotect (I am thinking in Wifi devices)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any possibility?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Samuel&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 16:21:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-parser/m-p/78008#M42790</guid>
      <dc:creator>ssancho</dc:creator>
      <dc:date>2016-05-12T16:21:44Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog parser</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-parser/m-p/78034#M42796</link>
      <description>&lt;P&gt;I don't think you can either do that or use that. Syslog listerner is designed only to work with User-ID. And even if you managed to extract OS info by some 3rd party syslog parser there is no way to use it in FW policy afaik.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is only used with GP checks.&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2016 06:34:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-parser/m-p/78034#M42796</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-05-13T06:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog parser</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-parser/m-p/78037#M42797</link>
      <description>&lt;P&gt;I'd recommend reaching out to your SE to create a feature request&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;currently the syslog parser will only collect username and IP information. other details like OS need to be detected through HIP checks on an installed GlobalProtect client&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2016 08:06:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-parser/m-p/78037#M42797</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-05-13T08:06:44Z</dc:date>
    </item>
  </channel>
</rss>

