<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Syslog Fields Mismatch the documentation PanOSV9.0 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-fields-mismatch-the-documentation-panosv9-0/m-p/261907#M74224</link>
    <description>&lt;P&gt;is the documentation perhaps for an older version of PAN-OS ?&lt;/P&gt;</description>
    <pubDate>Wed, 22 May 2019 11:49:37 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2019-05-22T11:49:37Z</dc:date>
    <item>
      <title>Syslog Fields Mismatch the documentation PanOSV9.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-fields-mismatch-the-documentation-panosv9-0/m-p/261888#M74221</link>
      <description>&lt;P&gt;I have syslogs coming to my SIEM from the device with PanOS V9.0. The number of fields i am receiving and the number of fields specified in the documentation doesnot match.&lt;/P&gt;&lt;P&gt;For example, in TRAFFIC logs,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;1,2019/05/09 15:09:20,xxxxxxxxxxxx,TRAFFIC,end,2304,2019/05/09 15:09:20,xx.xx.xx.xx,xx.xx.xx.xx,xx.xx.xx.xx,xx.xx.xx.xx,Allow all,,,ocsp,vsys1,Internal Wireless,Internet,ethernetxx,ethernetxx,SIEM,2019/05/09 15:09:20,18812,1,53613,80,40642,80,0x400000,tcp,allow,2322,769,1553,20,2019/05/09 15:02:41,279,computer-and-internet-info,0,192113874,0x0,xx.xx.xx.xx-xx.xx.xx.xx,xxxxx,0,6,14,aged-out,0,0,0,0,,XX-XX,from-policy,,,0,,0,,N/A,0,0,0,0,75a0f003-007b-4ae1-85f2-ede4fa21ea14,0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are total 67 fields.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, according to documentation, the fields should be:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;FUTURE_USE, Receive Time, Serial Number, Type, Threat/Content Type, FUTURE_USE, Generated Time, Source Address, Destination Address, NAT Source IP, NAT Destination IP, Rule Name, Source User, Destination User, Application, Virtual System, Source Zone, Destination Zone, Inbound Interface, Outbound Interface, Log Action, FUTURE_USE, Session ID, Repeat Count, Source Port, Destination Port, NAT Source Port, NAT Destination Port, Flags, Protocol, Action, URL/Filename, Threat ID, Category, Severity, Direction, Sequence Number, Action Flags, Source Location, Destination Location, FUTURE_USE, Content Type, PCAP_ID, File Digest, Cloud, URL Index, User Agent, File Type, X-Forwarded-For, Referer, Sender, Subject, Recipient, Report ID, Device Group Hierarchy Level 1, Device Group Hierarchy Level 2, Device Group Hierarchy Level 3, Device Group Hierarchy Level 4, Virtual System Name, Device Name, FUTURE_USE, Source VM UUID, Destination VM UUID, HTTP Method, Tunnel ID/IMSI, Monitor Tag/IMEI, Parent Session ID, Parent Start Time, Tunnel Type, Threat Category, Content Version, FUTURE_USE, SCTP Association ID, Payload Protocol ID, HTTP Headers, UUID for rule&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;which is 66 fields.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am getting an extra&lt;STRONG&gt; '0'&lt;/STRONG&gt; field at the end. According to documentation, the log should end at UUID for rule, which has value&amp;nbsp;&lt;STRONG&gt;75a0f003-007b-4ae1-85f2-ede4fa21ea14&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Similarly, I am getting more fields in THREAT Logs.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can anyone explain me what is causing this?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 06:05:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-fields-mismatch-the-documentation-panosv9-0/m-p/261888#M74221</guid>
      <dc:creator>gnikesh</dc:creator>
      <dc:date>2019-05-22T06:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Fields Mismatch the documentation PanOSV9.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-fields-mismatch-the-documentation-panosv9-0/m-p/261907#M74224</link>
      <description>&lt;P&gt;is the documentation perhaps for an older version of PAN-OS ?&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 11:49:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-fields-mismatch-the-documentation-panosv9-0/m-p/261907#M74224</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-05-22T11:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Fields Mismatch the documentation PanOSV9.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-fields-mismatch-the-documentation-panosv9-0/m-p/261944#M74234</link>
      <description>&lt;P&gt;The documentation is for PanOS V90&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/traffic-log-fields.html#" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/traffic-log-fields.html#&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 15:46:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-fields-mismatch-the-documentation-panosv9-0/m-p/261944#M74234</guid>
      <dc:creator>gnikesh</dc:creator>
      <dc:date>2019-05-22T15:46:48Z</dc:date>
    </item>
  </channel>
</rss>

