<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Flags field in csv file in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/flags-field-in-csv-file/m-p/224782#M64517</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/91319"&gt;@hbshin&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I actually don't know what this 0x19 means as this does not matches one of the values in the documentation. Maybe support could tell you more ...&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;how or from where do you know what this 0x19 means? Is there somewhere a documentation page that shows more of these values?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Back to the question: this value in the flag column should be ANDed with the values from the documentation: for example the value 0x400019 means there was NAT applied:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; 10000000000000000011001&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; 10000000000000000000000 (0x00400000 = NAT applied)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;= 10000000000000000000000&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 03 Aug 2018 20:35:26 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-08-03T20:35:26Z</dc:date>
    <item>
      <title>Flags field in csv file</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flags-field-in-csv-file/m-p/224525#M64457</link>
      <description>&lt;P&gt;i have a question about flags in csv log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="20180802_154251.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16130iE6EE5ECDF1852654/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="20180802_154251.png" alt="20180802_154251.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do you know what does mean Flags 0x19?&lt;/P&gt;&lt;P&gt;in NTP OR DNS logs, flag is 0x19.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Aug 2018 06:50:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flags-field-in-csv-file/m-p/224525#M64457</guid>
      <dc:creator>hbshin</dc:creator>
      <dc:date>2018-08-02T06:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: Flags field in csv file</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flags-field-in-csv-file/m-p/224584#M64470</link>
      <description>&lt;P&gt;0x19 is essentially saying "Okay close the socket". Essentially if you send a UDP request and a response comes back, it's likely to have the 0x19 flag so that the return traffic knows "Okay we're done" and that it can close it's side of the connection.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Aug 2018 13:48:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flags-field-in-csv-file/m-p/224584#M64470</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-08-02T13:48:11Z</dc:date>
    </item>
    <item>
      <title>Re: Flags field in csv file</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flags-field-in-csv-file/m-p/224671#M64485</link>
      <description>&lt;P&gt;Hi BPry.&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;Do you know what does 0x19&amp;nbsp;have to do with AND-ing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="20180803_092259.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16140i3BCB3A27D24FD491/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="20180803_092259.png" alt="20180803_092259.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Aug 2018 00:25:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flags-field-in-csv-file/m-p/224671#M64485</guid>
      <dc:creator>hbshin</dc:creator>
      <dc:date>2018-08-03T00:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: Flags field in csv file</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flags-field-in-csv-file/m-p/224754#M64509</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/91319"&gt;@hbshin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'm not entirely sure what they want you to AND the value with to be honest; AND works like this:&lt;/P&gt;&lt;P&gt;A&amp;nbsp; &amp;nbsp;B&amp;nbsp; =&lt;/P&gt;&lt;P&gt;0&amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp;0= off&lt;/P&gt;&lt;P&gt;0&amp;nbsp; &amp;nbsp;1&amp;nbsp; &amp;nbsp;0= off&lt;/P&gt;&lt;P&gt;1&amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp;0=&amp;nbsp; off&lt;/P&gt;&lt;P&gt;1&amp;nbsp; &amp;nbsp;1&amp;nbsp; &amp;nbsp;1=ON&lt;/P&gt;&lt;P&gt;So essentially unless the binary lines up '1' with '1' you get 0 (or off).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So you would have to convert 0x19 to binary and then convert (I assume) the values that they listed to binary and use AND-ing to combine them. This should give you a binary that once convirted should match one of the listed values? Honestly, not sure.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Aug 2018 16:31:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flags-field-in-csv-file/m-p/224754#M64509</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-08-03T16:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: Flags field in csv file</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flags-field-in-csv-file/m-p/224782#M64517</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/91319"&gt;@hbshin&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I actually don't know what this 0x19 means as this does not matches one of the values in the documentation. Maybe support could tell you more ...&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;how or from where do you know what this 0x19 means? Is there somewhere a documentation page that shows more of these values?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Back to the question: this value in the flag column should be ANDed with the values from the documentation: for example the value 0x400019 means there was NAT applied:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; 10000000000000000011001&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; 10000000000000000000000 (0x00400000 = NAT applied)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;= 10000000000000000000000&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Aug 2018 20:35:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flags-field-in-csv-file/m-p/224782#M64517</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-08-03T20:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: Flags field in csv file</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flags-field-in-csv-file/m-p/224785#M64519</link>
      <description>&lt;P&gt;The operation is to apply a bitwise AND operation to the number logged (0x19) with each value from the documentation image posted. If the bitwise AND result is 0, then then the documentation detail is false. If it's 1, then it's true.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;0x19&amp;nbsp;AND&amp;nbsp;0x00400000 = 0 (no NAT applied)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;0x19 by itself doesn't mean anything, it's just a value that can be ANDed to produce a result of zero for each of the types there are.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;mentions, another set of flags will produce a different result. On my logs, I have NAT enabled, so my logs flags are:&lt;/P&gt;&lt;P&gt;0x400019. When I do a bitwise AND operation on that and 0x00400000 I get a non-zero result, meaning it's "true".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Aug 2018 21:07:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flags-field-in-csv-file/m-p/224785#M64519</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2018-08-03T21:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: Flags field in csv file</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flags-field-in-csv-file/m-p/224816#M64530</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Flags in my experiance isn't really documented at all in any official&amp;nbsp;Palo Alto documentation.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Aug 2018 20:22:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flags-field-in-csv-file/m-p/224816#M64530</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-08-05T20:22:31Z</dc:date>
    </item>
    <item>
      <title>Re: Flags field in csv file</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flags-field-in-csv-file/m-p/224817#M64531</link>
      <description>&lt;P&gt;That's what I thought but it's good to know we can always count on&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/28203"&gt;@gwesson&lt;/a&gt;&amp;nbsp;to know all that more technical answers. I don't go playing this far deep in the syslog values often; and you won't see the flag value when you look in the CLI or GUI, pretty much only going to see them looking at the CSV values or the straight Syslog if you forward it to some type of collector.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Aug 2018 20:25:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flags-field-in-csv-file/m-p/224817#M64531</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-08-05T20:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: Flags field in csv file</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flags-field-in-csv-file/m-p/235885#M67616</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was also looking at this, Can you clarify the query.&lt;/P&gt;&lt;P&gt;Is this anyway related to the TCP control flags like for 0x19 which is in binary&amp;nbsp;0001 1001, If we relate it to the TCP header options, the packet will have FIN-PSH-ACK bit set.&lt;/P&gt;&lt;P&gt;Similary for 0x53, in binary&amp;nbsp;0101 0011. This will have&amp;nbsp;FIN-SYN-ACK-ECN bits set.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I didnt run tcpdump or wireshark. but trying to understand it from the firewall logs.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 20:24:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flags-field-in-csv-file/m-p/235885#M67616</guid>
      <dc:creator>chells2</dc:creator>
      <dc:date>2018-10-17T20:24:53Z</dc:date>
    </item>
  </channel>
</rss>

