<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to change  syslog timestamp format in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-change-syslog-timestamp-format/m-p/177531#M55356</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/35879"&gt;@BankRespublika&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can't say why the entry was added... I don't know the reason why it was added.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can however customize the log entries.&lt;/P&gt;
&lt;P&gt;Depending on your PAN-OS version you can find the CEF configuration guide here :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/misc/cef.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/misc/cef.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example Traffic Log on PAN-OS 8.0 :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;These custom formats include all the fields, in a similar order, that the default format of the syslogs display.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;PRE&gt;CEF:0|Palo Alto Networks|PAN-OS|$sender_sw_version|$subtype|$type|1|rt=$cef-formatted-receive_time deviceExternalId=$serial src=$src dst=$dst 
sourceTranslatedAddress=$natsrc destinationTranslatedAddress=$natdst 
cs1Label=Rule cs1=$rule suser=$srcuser duser=$dstuser app=$app 
cs3Label=Virtual System cs3=$vsys cs4Label=Source Zone cs4=$from 
cs5Label=Destination Zone cs5=$to deviceInboundInterface=$inbound_if 
deviceOutboundInterface=$outbound_if cs6Label=LogProfile cs6=$logset 
cn1Label=SessionID cn1=$sessionid cnt=$repeatcnt spt=$sport dpt=$dport 
sourceTranslatedPort=$natsport destinationTranslatedPort=$natdport 
flexString1Label=Flags flexString1=$flags proto=$proto act=$action
flexNumber1Label=Total bytesflexNumber1=$bytes in=$bytes_sent 
out=$bytes_received cn2Label=Packets cn2=$packets 
PanOSPacketsReceived=$pkts_received PanOSPacketsSent=$pkts_sent start=$cef-formatted-time_generated cn3Label=Elapsed time in seconds cn3=$elapsed 
cs2Label=URL Category cs2=$category externalId=$seqno
reason=$session_end_reason PanOSDGl1=$dg_hier_level_1&lt;BR /&gt;PanOSDGl2=$dg_hier_level_2 PanOSDGl3=$dg_hier_level_3 
PanOSDGl4=$dg_hier_level_4 PanOSVsysName=$vsys_name dvchost=$device_name
cat=$action_source PanOSActionFlags=$actionflags PanOS SrcUUID=$src_uuid
PanOSDstUUID=$dst_uuid PanOSTunnelID=$tunnelid PanOSMonitorTag=$monitortag
PanOSParentSessionID=$parent_session_id 
PanOSParentStartTime=$parent_start_time PanOSTunnelType=$tunnel&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;DIV&gt;I hope this helps,&lt;/DIV&gt;
&lt;DIV&gt;Cheers !&lt;/DIV&gt;
&lt;DIV&gt;-Kiwi&lt;/DIV&gt;</description>
    <pubDate>Tue, 19 Sep 2017 09:41:23 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2017-09-19T09:41:23Z</dc:date>
    <item>
      <title>How to change  syslog timestamp format</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-change-syslog-timestamp-format/m-p/177295#M55308</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We are using syslog forwarding to SIEM system from our PA. Logs were in this format:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1,2017/09/06 23:59:59,007100001147,TRAFFIC,end,0,2017/09/06 23:59:59,X.X.X.X,&lt;SPAN&gt;Y&lt;/SPAN&gt;&lt;SPAN&gt;.Y.Y.Y&lt;/SPAN&gt;,0.0.0.0,0.0.0.0,Firewall To NTP,test\paloalto,,dns,vsys1,Inside,Inside,ethernet1/1,ethernet1/1,Q-Radar,2017/09/06 23:59:59,79361,1,42407,53,0,0,0x4064,udp,allow,409,176,233,4,2017/09/06 23:59:29,0,any,0,6849234946,0x0,172.16.0.0-172.31.255.255,172.16.0.0-172.31.255.255,0,2,2,aged-out,0,0,0,0,,PA-VM,from-policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But now the log timestamp was changed and looks like this:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sep 12 09:22:13 X.X.X.X 1 2017-09-12T09:22:14+04:00 &lt;SPAN&gt;X.X.X.X&lt;/SPAN&gt; - - - - &amp;nbsp;1,2017/09/12 09:22:13,007100001147,TRAFFIC,start,0,2017/09/12 09:22:13,Y&lt;SPAN&gt;.Y.Y.Y&lt;/SPAN&gt;,157.240.9.23,0.0.0.0,0.0.0.0,Internet Access For Mrktd,test\user1,,facebook-base,vsys1,Inside,Outside,ethernet1/1,ethernet1/3,Q-Radar,2017/09/12 09:22:13,3539,1,4378,443,0,0,0x4000,tcp,allow,763,697,66,4,2017/09/12 09:22:14,0,social-networking,0,6936146804,0x0,172.16.0.0-172.31.255.255,US,0,3,1,n/a,0,0,0,0,,PA-VM,from-policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you noticed &amp;nbsp;this entry was added &amp;nbsp;to logs :&amp;nbsp;&lt;SPAN&gt;Sep 12 09:22:13 X.X.X.X 1 2017-09-12T09:22:14+04:00&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;X.X.X.X&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;- - - - &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Maybe you know what was the reason of this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It will be great if you help us to remove this entry from logs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2017 12:35:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-change-syslog-timestamp-format/m-p/177295#M55308</guid>
      <dc:creator>BankRespublika</dc:creator>
      <dc:date>2017-09-18T12:35:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to change  syslog timestamp format</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-change-syslog-timestamp-format/m-p/177531#M55356</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/35879"&gt;@BankRespublika&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can't say why the entry was added... I don't know the reason why it was added.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can however customize the log entries.&lt;/P&gt;
&lt;P&gt;Depending on your PAN-OS version you can find the CEF configuration guide here :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/misc/cef.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/misc/cef.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example Traffic Log on PAN-OS 8.0 :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;These custom formats include all the fields, in a similar order, that the default format of the syslogs display.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;PRE&gt;CEF:0|Palo Alto Networks|PAN-OS|$sender_sw_version|$subtype|$type|1|rt=$cef-formatted-receive_time deviceExternalId=$serial src=$src dst=$dst 
sourceTranslatedAddress=$natsrc destinationTranslatedAddress=$natdst 
cs1Label=Rule cs1=$rule suser=$srcuser duser=$dstuser app=$app 
cs3Label=Virtual System cs3=$vsys cs4Label=Source Zone cs4=$from 
cs5Label=Destination Zone cs5=$to deviceInboundInterface=$inbound_if 
deviceOutboundInterface=$outbound_if cs6Label=LogProfile cs6=$logset 
cn1Label=SessionID cn1=$sessionid cnt=$repeatcnt spt=$sport dpt=$dport 
sourceTranslatedPort=$natsport destinationTranslatedPort=$natdport 
flexString1Label=Flags flexString1=$flags proto=$proto act=$action
flexNumber1Label=Total bytesflexNumber1=$bytes in=$bytes_sent 
out=$bytes_received cn2Label=Packets cn2=$packets 
PanOSPacketsReceived=$pkts_received PanOSPacketsSent=$pkts_sent start=$cef-formatted-time_generated cn3Label=Elapsed time in seconds cn3=$elapsed 
cs2Label=URL Category cs2=$category externalId=$seqno
reason=$session_end_reason PanOSDGl1=$dg_hier_level_1&lt;BR /&gt;PanOSDGl2=$dg_hier_level_2 PanOSDGl3=$dg_hier_level_3 
PanOSDGl4=$dg_hier_level_4 PanOSVsysName=$vsys_name dvchost=$device_name
cat=$action_source PanOSActionFlags=$actionflags PanOS SrcUUID=$src_uuid
PanOSDstUUID=$dst_uuid PanOSTunnelID=$tunnelid PanOSMonitorTag=$monitortag
PanOSParentSessionID=$parent_session_id 
PanOSParentStartTime=$parent_start_time PanOSTunnelType=$tunnel&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;DIV&gt;I hope this helps,&lt;/DIV&gt;
&lt;DIV&gt;Cheers !&lt;/DIV&gt;
&lt;DIV&gt;-Kiwi&lt;/DIV&gt;</description>
      <pubDate>Tue, 19 Sep 2017 09:41:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-change-syslog-timestamp-format/m-p/177531#M55356</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-09-19T09:41:23Z</dc:date>
    </item>
  </channel>
</rss>

