<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to test regex for syslog parsing correctly or not for user-ID? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-regex-for-syslog-parsing-correctly-or-not-for-user/m-p/220987#M63676</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/82863"&gt;@faizankhurshid&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Currect. You've recorded 6 messages from that host but your custom parser didn't actually succesfully map the UID for whatever reason.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 07 Jul 2018 00:51:01 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-07-07T00:51:01Z</dc:date>
    <item>
      <title>How to test regex for syslog parsing correctly or not for user-ID?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-regex-for-syslog-parsing-correctly-or-not-for-user/m-p/220853#M63658</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Syslog server is sending logs to firewall for user-ID parsing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1- How can I verify that logs are receiving on firewall?&lt;/P&gt;&lt;P&gt;2- How can I test, my custom parser is working to identify the user/ip mapping?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jul 2018 10:07:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-regex-for-syslog-parsing-correctly-or-not-for-user/m-p/220853#M63658</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-07-06T10:07:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to test regex for syslog parsing correctly or not for user-ID?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-regex-for-syslog-parsing-correctly-or-not-for-user/m-p/220885#M63660</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/82863"&gt;@faizankhurshid&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For both of your questions, you can check the Monitor -&amp;gt; User-ID logs, filtering for the datasource of your syslog sender.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the parse filter is set up correcltly, you should see the usernames being correctly popualted in the "username" column as opposed to some string you don't want like a MAC address or something else wrong entirely.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jul 2018 12:48:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-regex-for-syslog-parsing-correctly-or-not-for-user/m-p/220885#M63660</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-07-06T12:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to test regex for syslog parsing correctly or not for user-ID?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-regex-for-syslog-parsing-correctly-or-not-for-user/m-p/220931#M63672</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52796"&gt;@LukeBullimore&lt;/a&gt;&amp;nbsp;Thanks but when I am running&amp;nbsp; below command, I am seeing 'number of auth success messages 0)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@PA-5050&amp;gt; show user server-monitor state Syslog2&lt;/P&gt;&lt;P&gt;UDP Syslog Listener Service is enabled&lt;/P&gt;&lt;P&gt;SSL Syslog Listener Service is disabled&lt;/P&gt;&lt;P&gt;Proxy: Syslog2(vsys: vsys1) Host: Syslog2(10.5.204.41)&lt;/P&gt;&lt;P&gt;number of log messages : 6&lt;/P&gt;&lt;P&gt;number of auth. success messages : 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, I am not able to see any user-ip mapping from syslog (even if it is wrong). So means messages are comming from syslog but parser should give me correct or wrong username/ip mapping?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jul 2018 15:05:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-regex-for-syslog-parsing-correctly-or-not-for-user/m-p/220931#M63672</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-07-06T15:05:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to test regex for syslog parsing correctly or not for user-ID?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-regex-for-syslog-parsing-correctly-or-not-for-user/m-p/220987#M63676</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/82863"&gt;@faizankhurshid&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Currect. You've recorded 6 messages from that host but your custom parser didn't actually succesfully map the UID for whatever reason.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jul 2018 00:51:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-regex-for-syslog-parsing-correctly-or-not-for-user/m-p/220987#M63676</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-07-07T00:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to test regex for syslog parsing correctly or not for user-ID?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-regex-for-syslog-parsing-correctly-or-not-for-user/m-p/221004#M63686</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;thanks. Is there any way to troubleshoot that my custom parser is matching (any CLI comamnd in firewall) or if my custom parser is not matching, then how can I troubleshoot this?&lt;/P&gt;&lt;P&gt;Also from syslog, I noticed that username is in different line of log and IP is in different line of log? Does multiline matching is supported with syslog or I have to use SSL?&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jul 2018 06:38:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-regex-for-syslog-parsing-correctly-or-not-for-user/m-p/221004#M63686</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-07-07T06:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to test regex for syslog parsing correctly or not for user-ID?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-regex-for-syslog-parsing-correctly-or-not-for-user/m-p/221070#M63700</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/82863"&gt;@faizankhurshid&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'm not sure that the firewall really has a built in way of testing a parser outside of simply seeing if you are getting the syslog messages and seeing if they are mapping any of the users. Since the parser is telling the firewall how to read the logs there really isn't a way to 'test' this as your telling it what the actual message even says.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Things to keep in mind when using Syslog over SSL&lt;/P&gt;&lt;P&gt;-&amp;nbsp;&lt;SPAN&gt;Each syslog message must be a single line text string. Line breaks are delimited by a carriage return and a new line (\r\n) or a new line (\n). So essentially yes you would fully expect the username and the IP in different lines of the log, that's perfectly fine and what you need to get this to work. &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- The maximum allowed bytes is 2048 for any one message, so make sure you aren't surpassing that as the messages would get dropped.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Jul 2018 10:17:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-regex-for-syslog-parsing-correctly-or-not-for-user/m-p/221070#M63700</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-07-08T10:17:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to test regex for syslog parsing correctly or not for user-ID?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-regex-for-syslog-parsing-correctly-or-not-for-user/m-p/221092#M63716</link>
      <description>&lt;P&gt;To test your regex string you can use one of the online test tools. My favourite one is this one here:&amp;nbsp;&lt;A href="https://regex101.com" target="_blank"&gt;https://regex101.com&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Jul 2018 20:39:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-regex-for-syslog-parsing-correctly-or-not-for-user/m-p/221092#M63716</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-07-08T20:39:42Z</dc:date>
    </item>
  </channel>
</rss>

