<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Troubleshooting User-ID from syslog listener in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-user-id-from-syslog-listener/m-p/160303#M52277</link>
    <description>&lt;P&gt;I've configured my 5050's to be Syslog Listeners for a couple sources so that I can parse User-ID information out of them. &amp;nbsp;I did so following this document &lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/user-id/configure-user-id-to-receive-user-mappings-from-a-syslog-sender" target="_self"&gt;here&lt;/A&gt;. I can see via the command&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show user server-monitor state XXX&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;that I am receiving log messages, but so far none of the are registering "success messages". &amp;nbsp;I'm having a hell of a time getting a packet capture to show the inbound Syslog messages so I can inspect that I am getting what I expect. Both pcap from the gui and tcpdump from the CLI isn't showing anything. &amp;nbsp;Is there a way to just simply tail the underlying syslog file on the local 5050 to see what it is receiving?&lt;/P&gt;</description>
    <pubDate>Thu, 08 Jun 2017 21:53:39 GMT</pubDate>
    <dc:creator>GeoffSweet</dc:creator>
    <dc:date>2017-06-08T21:53:39Z</dc:date>
    <item>
      <title>Troubleshooting User-ID from syslog listener</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-user-id-from-syslog-listener/m-p/160303#M52277</link>
      <description>&lt;P&gt;I've configured my 5050's to be Syslog Listeners for a couple sources so that I can parse User-ID information out of them. &amp;nbsp;I did so following this document &lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/user-id/configure-user-id-to-receive-user-mappings-from-a-syslog-sender" target="_self"&gt;here&lt;/A&gt;. I can see via the command&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show user server-monitor state XXX&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;that I am receiving log messages, but so far none of the are registering "success messages". &amp;nbsp;I'm having a hell of a time getting a packet capture to show the inbound Syslog messages so I can inspect that I am getting what I expect. Both pcap from the gui and tcpdump from the CLI isn't showing anything. &amp;nbsp;Is there a way to just simply tail the underlying syslog file on the local 5050 to see what it is receiving?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 21:53:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-user-id-from-syslog-listener/m-p/160303#M52277</guid>
      <dc:creator>GeoffSweet</dc:creator>
      <dc:date>2017-06-08T21:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting User-ID from syslog listener</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-user-id-from-syslog-listener/m-p/160314#M52280</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had Captive Portal&amp;nbsp;issue recently, and palo was configured as syslog&amp;nbsp;listener. &amp;nbsp;TAC was doing a pcap from GUI in order to confirm the format of the syslog&amp;nbsp;messages. So you are on the&amp;nbsp;right way. Did you configure your syslog server to forward the syslogsto&amp;nbsp;to palo, did you check if you can reach palo&amp;nbsp;successfully from the syslog server? I believe your mgmt profile&amp;nbsp;is attached&amp;nbsp;to the correct interface with syslog&amp;nbsp;options ticked.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 22:28:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-user-id-from-syslog-listener/m-p/160314#M52280</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-06-08T22:28:35Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting User-ID from syslog listener</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-user-id-from-syslog-listener/m-p/160329#M52282</link>
      <description>&lt;P&gt;Hi Geoff,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you enabled syslog listener on the management profile?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="deleteme.PNG" style="width: 442px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9602i357B9F5C81B579E7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="deleteme.PNG" alt="deleteme.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once you have that committed, you are sure to receive SYSLOG packets in tcpdump. Maybe check/remove any filter you got while taking a tcpdump.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Run the following commands and check logs.&lt;/P&gt;&lt;P&gt;admin@anuragFW&amp;gt; &lt;STRONG&gt;debug user-id on debug&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;admin@anuragFW&amp;gt; &lt;STRONG&gt;debug user-id set userid syslog&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;admin@anuragFW&amp;gt; &lt;STRONG&gt;tail follow yes mp-log useridd.log&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Then, to verify your regex/filter expression use the following commands:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;admin@anuragFW&amp;gt; &amp;nbsp;&lt;STRONG&gt;test user-id user-id-syslog-parse regex-identifier event-regex &amp;lt;value&amp;gt; username-regex &amp;lt;value&amp;gt; address-regex &amp;lt;value&amp;gt; log-string &amp;lt;value&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;admin@anuragFW&amp;gt; &amp;nbsp;&lt;STRONG&gt;test user-id user-id-syslog-parse field-identifier event-string &amp;lt;value&amp;gt; username-prefix &amp;lt;value&amp;gt; username-delimiter &amp;lt;value&amp;gt; address-prefix &amp;lt;value&amp;gt; address-delimiter &amp;lt;value&amp;gt; log-string &amp;lt;value&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are having trouble figuring out which regex is not being read correctly, feed the log-string values different sections of syslog messages. That's just something you gotta play around and figure out. Some special characters need to be escaped while some will not be allowed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can post a sample of syslog messages and we could possibly look into it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anurag&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 00:39:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-user-id-from-syslog-listener/m-p/160329#M52282</guid>
      <dc:creator>ansharma</dc:creator>
      <dc:date>2017-06-09T00:39:01Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting User-ID from syslog listener</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-user-id-from-syslog-listener/m-p/257326#M73003</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/51040"&gt;@ansharma&lt;/a&gt;&amp;nbsp;wrote:&lt;P class="1555011543104"&gt;&amp;nbsp;&lt;/P&gt;&lt;SPAN&gt;Then, to verify your regex/filter expression use the following commands:&lt;/SPAN&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;admin@anuragFW&amp;gt; &amp;nbsp;&lt;STRONG&gt;test user-id user-id-syslog-parse regex-identifier event-regex &amp;lt;value&amp;gt; username-regex &amp;lt;value&amp;gt; address-regex &amp;lt;value&amp;gt; log-string &amp;lt;value&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;admin@anuragFW&amp;gt; &amp;nbsp;&lt;STRONG&gt;test user-id user-id-syslog-parse field-identifier event-string &amp;lt;value&amp;gt; username-prefix &amp;lt;value&amp;gt; username-delimiter &amp;lt;value&amp;gt; address-prefix &amp;lt;value&amp;gt; address-delimiter &amp;lt;value&amp;gt; log-string &amp;lt;value&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are having trouble figuring out which regex is not being read correctly, feed the log-string values different sections of syslog messages. That's just something you gotta play around and figure out. Some special characters need to be escaped while some will not be allowed.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Thank you!&amp;nbsp; Those "test user-id" commands were exactly what I've been searching for.&amp;nbsp; Trying to get a custom syslog filter working has been a pain, especially since the online regex tools say they work, but there's no logs on the PA200 to check if it's working or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You saved me a lot of desk-head interactions today.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 19:40:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-user-id-from-syslog-listener/m-p/257326#M73003</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2019-04-11T19:40:21Z</dc:date>
    </item>
  </channel>
</rss>

