<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto Threat Events Not forwarded in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-threat-events-not-forwarded/m-p/260897#M73956</link>
    <description>&lt;P&gt;&lt;SPAN&gt;This is not helping&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 14 May 2019 11:24:30 GMT</pubDate>
    <dc:creator>karthikeyanB</dc:creator>
    <dc:date>2019-05-14T11:24:30Z</dc:date>
    <item>
      <title>Palo Alto Threat Events Not forwarded</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-threat-events-not-forwarded/m-p/260695#M73896</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We are unable to capture below logs in syslog, but in Firewall it appears to be forwarding it to Syslog. Logs are being forwarded, but some fields are empty.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fDqJ6iXKsNJ6GvFv4WlNrTArmuy3jwqbHw.png" style="width: 597px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19986i99E9502E2DDF5A43/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="fDqJ6iXKsNJ6GvFv4WlNrTArmuy3jwqbHw.png" alt="fDqJ6iXKsNJ6GvFv4WlNrTArmuy3jwqbHw.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="w13H2cciKexNWwjLWBA3Cj7L3hxAWer2qA.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19987iFC15323C9507E34F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="w13H2cciKexNWwjLWBA3Cj7L3hxAWer2qA.png" alt="w13H2cciKexNWwjLWBA3Cj7L3hxAWer2qA.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 10:09:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-threat-events-not-forwarded/m-p/260695#M73896</guid>
      <dc:creator>karthikeyanB</dc:creator>
      <dc:date>2019-05-13T10:09:18Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Threat Events Not forwarded</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-threat-events-not-forwarded/m-p/260720#M73902</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/105432"&gt;@karthikeyanB&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As your screenshot indicates you have quite some custom entries.&lt;/P&gt;
&lt;P&gt;You might want to look into customizing the log format :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/custom-logevent-format.html#" target="_blank" rel="noopener"&gt;Custom-logevent-format&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 13 May 2019 10:59:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-threat-events-not-forwarded/m-p/260720#M73902</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2019-05-13T10:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Threat Events Not forwarded</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-threat-events-not-forwarded/m-p/260896#M73955</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/105432"&gt;@karthikeyanB&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We are unable to capture below logs in syslog, but in Firewall it appears to be forwarding it to Syslog. Logs are being forwarded, but some fields are empty.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fDqJ6iXKsNJ6GvFv4WlNrTArmuy3jwqbHw.png" style="width: 597px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19986i99E9502E2DDF5A43/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="fDqJ6iXKsNJ6GvFv4WlNrTArmuy3jwqbHw.png" alt="fDqJ6iXKsNJ6GvFv4WlNrTArmuy3jwqbHw.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="w13H2cciKexNWwjLWBA3Cj7L3hxAWer2qA.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19987iFC15323C9507E34F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="w13H2cciKexNWwjLWBA3Cj7L3hxAWer2qA.png" alt="w13H2cciKexNWwjLWBA3Cj7L3hxAWer2qA.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;BR /&gt;This is not helping&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 11:23:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-threat-events-not-forwarded/m-p/260896#M73955</guid>
      <dc:creator>karthikeyanB</dc:creator>
      <dc:date>2019-05-14T11:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Threat Events Not forwarded</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-threat-events-not-forwarded/m-p/260897#M73956</link>
      <description>&lt;P&gt;&lt;SPAN&gt;This is not helping&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 11:24:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-threat-events-not-forwarded/m-p/260897#M73956</guid>
      <dc:creator>karthikeyanB</dc:creator>
      <dc:date>2019-05-14T11:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Threat Events Not forwarded</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-threat-events-not-forwarded/m-p/260902#M73958</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What log format are you using ? CEF, LEEF ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If default isn't doing the trick, have you tried customizing as shown in the documents ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CEF FORMAT:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;CEF:0|Palo Alto Networks|PAN-OS|$sender_sw_version|$subtype|$type|$number-&lt;BR /&gt;of-severity|rt=$cef-formatted-receive_time deviceExternalId=$serial src=$src &lt;BR /&gt;dst=$dst sourceTranslatedAddress=$natsrc &lt;BR /&gt;destinationTranslatedAddress=$natdst cs1Label=Rule cs1=$rule suser=$srcuser &lt;BR /&gt;duser=$dstuserapp=$app cs3Label=Virtual System cs3=$vsys cs4Label=Source &lt;BR /&gt;Zone cs4=$from cs5Label=Destination Zone cs5=$to &lt;BR /&gt;deviceInboundInterface=$inbound_if deviceOutboundInterface=$outbound_if &lt;BR /&gt;cs6Label=LogProfile cs6=$logset cn1Label=SessionID cn1=$sessionid &lt;BR /&gt;cnt=$repeatcnt spt=$sport dpt=$dport sourceTranslatedPort=$natsport &lt;BR /&gt;destinationTranslatedPort=$natdport flexString1Label=Flags &lt;BR /&gt;flexString1=$flags proto=$proto act=$action request=$misc cs2Label=URL &lt;BR /&gt;Category cs2=$category flexString2Label=Direction flexString2=$direction&lt;BR /&gt;PanOSActionFlags=$actionflags externalId=$seqnocat=$threatid&lt;BR /&gt;fileId=$pcap_id PanOSDGl1=$dg_hier_level_1 PanOSDGl2=$dg_hier_level_2 &lt;BR /&gt;PanOSDGl3=$dg_hier_level_3 PanOSDGl4=$dg_hier_level_4 PanOSVsysName=$vsys_name &lt;BR /&gt;dvchost=$device_namePanOSSrcUUID=$src_uuid PanOSDstUUID=$dst_uuid &lt;BR /&gt;PanOSTunnelID=$tunnelid PanOSMonitorTag=$monitortag PanOSParentSessionID=$parent_session_id &lt;BR /&gt;PanOSParentStartTime=$parent_start_time PanOSTunnelType=$tunnel &lt;BR /&gt;PanOSThreatCategory=$thr_category PanOSContentVer=$contentver&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN style="left: 682.517px; top: 1112.68px; font-size: 15px; font-family: monospace; transform: scaleX(1);"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="left: 682.517px; top: 1112.68px; font-size: 15px; font-family: monospace; transform: scaleX(1);"&gt;LEEF FORMAT:&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;LEEF:1.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$threatid|
ReceiveTime=$receive_time|SerialNumber=$serial|cat=$type|Subtype=$subtype|devTime=$cef-formatted-receive_
time|src=$src|dst=$dst|srcPostNAT=$natsrc|dstPostNAT=$natdst|RuleName=$rule|usrName=$srcuser|
SourceUser=$srcuser|DestinationUser=$dstuser|Application=$app|VirtualSystem=$vsys|SourceZone=$from|
DestinationZone=$to|IngressInterface=$inbound_if|EgressInterface=$outbound_if|
LogForwardingProfile=$logset|SessionID=$sessionid|RepeatCount=$repeatcnt|srcPort=$sport|dstPort=$dport|
srcPostNATPort=$natsport|dstPostNATPort=$natdport|Flags=$flags|proto=$proto|action=$action|
Miscellaneous=$misc|ThreatID=$threatid|URLCategory=$category|sev=$number-of-severity|Severity=$severity|
Direction=$direction|sequence=$seqno|ActionFlags=$actionflags|SourceLocation=$srcloc|
DestinationLocation=$dstloc|ContentType=$contenttype|PCAP_ID=$pcap_id|FileDigest=$filedigest|
Cloud=$cloud|URLIndex=$url_idx|RequestMethod=$http_method|Subject=$subject|
DeviceGroupHierarchyL1=$dg_hier_level_1|DeviceGroupHierarchyL2=$dg_hier_level_2|
DeviceGroupHierarchyL3=$dg_hier_level_3|DeviceGroupHierarchyL4=$dg_hier_level_4|
vSrcName=$vsys_name|DeviceName=$device_name|SrcUUID=$src_uuid|DstUUID=$dst_uuid|
TunnelID=$tunnelid|MonitorTag=$monitortag|ParentSessionID=$parent_session_id|
ParentStartTime=$parent_start_time|TunnelType=$tunnel|ThreatCategory=$thr_category|
ContentVer=$contentver&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;DIV data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV data-extension-version="1.0.4"&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGsCAK" target="_blank" rel="noopener"&gt;Configuring PAN-OS 7.1 Gateways to Generate Logs in LEEF Format&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV data-extension-version="1.0.4"&gt;Cheers !&lt;/DIV&gt;
&lt;DIV data-extension-version="1.0.4"&gt;-Kiwi.&lt;/DIV&gt;</description>
      <pubDate>Tue, 14 May 2019 12:59:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-threat-events-not-forwarded/m-p/260902#M73958</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2019-05-14T12:59:29Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Threat Events Not forwarded</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-threat-events-not-forwarded/m-p/260908#M73962</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using PAN OS 8.0.13 but the document shows&amp;nbsp; pan os 7.1!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is not a issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Karthikeyan&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 13:27:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-threat-events-not-forwarded/m-p/260908#M73962</guid>
      <dc:creator>karthikeyanB</dc:creator>
      <dc:date>2019-05-14T13:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Threat Events Not forwarded</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-threat-events-not-forwarded/m-p/260909#M73963</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEcCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEcCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i found the above kb article for 8.0.X is that ok !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Karthikeyan Balamurugan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 13:32:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-threat-events-not-forwarded/m-p/260909#M73963</guid>
      <dc:creator>karthikeyanB</dc:creator>
      <dc:date>2019-05-14T13:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Threat Events Not forwarded</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-threat-events-not-forwarded/m-p/261042#M73998</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We are using CEF format&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 05:44:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-threat-events-not-forwarded/m-p/261042#M73998</guid>
      <dc:creator>karthikeyanB</dc:creator>
      <dc:date>2019-05-15T05:44:28Z</dc:date>
    </item>
  </channel>
</rss>

