<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting PAN FW logs to Azure Sentinel in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/getting-pan-fw-logs-to-azure-sentinel/m-p/306819#M79693</link>
    <description>&lt;P&gt;I have the same issue&lt;/P&gt;</description>
    <pubDate>Wed, 15 Jan 2020 16:19:09 GMT</pubDate>
    <dc:creator>Dwayne</dc:creator>
    <dc:date>2020-01-15T16:19:09Z</dc:date>
    <item>
      <title>Getting PAN FW logs to Azure Sentinel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-pan-fw-logs-to-azure-sentinel/m-p/298582#M78226</link>
      <description>&lt;P&gt;I'm currently sending FW logs to Azure Sentinel, via syslog over SSL to an r-syslog server with the Azure agent on the syslog server forwarding logs to Sentinel. I followed the documentation, format is BSD header with custom CEF format for the logs added. Using local4 facility on PA side as well as r-syslog server. Logs are getting in, but they are missing most of the key value pairs. Attached is a screen shot with basically all I'm getting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone successfully got the Palo Alto Networks FW logs into Sentinel and if so was there anything missing in the documentation or a step that needs to be added?  &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="threat log.JPG" style="width: 658px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22352i55E7D9DD8EE70902/image-dimensions/658x216/is-moderation-mode/true?v=v2" width="658" height="216" role="button" title="threat log.JPG" alt="threat log.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 15:55:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-pan-fw-logs-to-azure-sentinel/m-p/298582#M78226</guid>
      <dc:creator>ChrisRussell</dc:creator>
      <dc:date>2019-11-14T15:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: Getting PAN FW logs to Azure Sentinel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-pan-fw-logs-to-azure-sentinel/m-p/306819#M79693</link>
      <description>&lt;P&gt;I have the same issue&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 16:19:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-pan-fw-logs-to-azure-sentinel/m-p/306819#M79693</guid>
      <dc:creator>Dwayne</dc:creator>
      <dc:date>2020-01-15T16:19:09Z</dc:date>
    </item>
    <item>
      <title>Re: Getting PAN FW logs to Azure Sentinel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-pan-fw-logs-to-azure-sentinel/m-p/306824#M79695</link>
      <description>&lt;P&gt;We solved this by separating all the log values onto individual lines. So hitting enter after each portion of the log. Definitely wasn't part of documentation but it works.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 16:54:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-pan-fw-logs-to-azure-sentinel/m-p/306824#M79695</guid>
      <dc:creator>ChrisRussell</dc:creator>
      <dc:date>2020-01-15T16:54:50Z</dc:date>
    </item>
    <item>
      <title>Re: Getting PAN FW logs to Azure Sentinel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-pan-fw-logs-to-azure-sentinel/m-p/339304#M85223</link>
      <description>&lt;P&gt;Would you paste an example of what that would look like?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 20:03:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-pan-fw-logs-to-azure-sentinel/m-p/339304#M85223</guid>
      <dc:creator>Learfield</dc:creator>
      <dc:date>2020-07-17T20:03:29Z</dc:date>
    </item>
  </channel>
</rss>

