<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Syslog Custom Format for Splunk in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/324830#M82877</link>
    <description>&lt;P&gt;I'm trying to get the firewall to send before and after change detail to splunk. I've tried various formats in Custom Log Format, but any changes I make result in no logs being sent to splunk. What is the correct format for Custom Log Format when using syslog and splunk? I'm running PA OS 8.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 24 Apr 2020 20:30:13 GMT</pubDate>
    <dc:creator>MikeSangray2019</dc:creator>
    <dc:date>2020-04-24T20:30:13Z</dc:date>
    <item>
      <title>Syslog Custom Format for Splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/324830#M82877</link>
      <description>&lt;P&gt;I'm trying to get the firewall to send before and after change detail to splunk. I've tried various formats in Custom Log Format, but any changes I make result in no logs being sent to splunk. What is the correct format for Custom Log Format when using syslog and splunk? I'm running PA OS 8.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2020 20:30:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/324830#M82877</guid>
      <dc:creator>MikeSangray2019</dc:creator>
      <dc:date>2020-04-24T20:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Custom Format for Splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/324916#M82899</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124213"&gt;@MikeSangray2019&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Making a custom format shouldn't break sending the syslog to Splunk, are you sure that the logs aren't actually getting to Splunk at all? If you could share our format and the actual software version you are running we might be able to identify something.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Apr 2020 08:24:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/324916#M82899</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-04-26T08:24:24Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Custom Format for Splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/325022#M82923</link>
      <description>&lt;P&gt;Logs are being shipped to Splunk. I'm following the directions to use custom formatting&amp;nbsp; '&lt;SPAN&gt;Enter the log format above. Click on the field names in the left panel to include them in the log format.' by clicking on the name, then commit, and then no more config logs after that change to use custom log formatting. Return to default and config logs start working again. Just confirmed again. Maybe something for tech support?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 13:56:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/325022#M82923</guid>
      <dc:creator>MikeSangray2019</dc:creator>
      <dc:date>2020-04-27T13:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Custom Format for Splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/335032#M84466</link>
      <description>&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you get any resolution for this issue&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Venky&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2020 14:23:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/335032#M84466</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2020-06-24T14:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Custom Format for Splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/335304#M84513</link>
      <description>&lt;P&gt;No, I did not get a resolution for this.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 14:08:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/335304#M84513</guid>
      <dc:creator>MikeSangray2019</dc:creator>
      <dc:date>2020-06-25T14:08:13Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Custom Format for Splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/335402#M84524</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i'm facing same issue, If you dont mind did you raise it with support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Venky&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 18:23:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/335402#M84524</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2020-06-25T18:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Custom Format for Splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/335435#M84533</link>
      <description>&lt;P&gt;Sorry, I did not open a ticket with support for this.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 21:18:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/335435#M84533</guid>
      <dc:creator>MikeSangray2019</dc:creator>
      <dc:date>2020-06-25T21:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Custom Format for Splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/383467#M89960</link>
      <description>&lt;P&gt;Closer, but still seeing an issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firewall config events are being parsed as pan:config, but without before and after change details. Other details are included, but before and after change details are both 0.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I set a custom log format and test changing an object name on the firewall, the logs are parsed as pan:log (not pan:config) and I can see the change detail in the raw event message, but now I've lost the other fields since it was parsed as pan:log.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 17:29:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/383467#M89960</guid>
      <dc:creator>MikeSangray2019</dc:creator>
      <dc:date>2021-02-02T17:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Custom Format for Splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/383560#M89978</link>
      <description>&lt;P&gt;Frist Click the field names in the left board to remember them for the log design.' by tapping on the name, at that point submit, and afterward no more config logs after that change to utilize custom log organizing.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 06:58:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/383560#M89978</guid>
      <dc:creator>Douglas775</dc:creator>
      <dc:date>2021-02-03T06:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Custom Format for Splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/383942#M89999</link>
      <description>&lt;P&gt;That's not working. As I noted in my update I have tried setting a custom log. Doing this changes the way the logs are parsed either with pan:config or pan:log. "&lt;SPAN&gt;When I set a custom log format and test changing an object name on the firewall, the logs are parsed as pan:log (not pan:config) and I can see the change detail in the raw event message, but now I've lost the other fields since it was parsed as pan:log."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Does anyone have this working? I want to believe this is just something with my config that I can fix, but I haven't seen many posts that this works for others.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2021 19:40:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/383942#M89999</guid>
      <dc:creator>MikeSangray2019</dc:creator>
      <dc:date>2021-02-04T19:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Custom Format for Splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/511897#M106398</link>
      <description>&lt;P&gt;Working on this again, still no change in behavior.&lt;/P&gt;
&lt;P&gt;Does anyone know if this has been addressed in any 9.1 or 10.x releases?&lt;/P&gt;
&lt;P&gt;The log format changes based on if Default logging or Custom Format is used, so the sourcetype isn't set correctly (Splunk).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;DEFAULT (sourcetype is set to pan:config, this is correct and working, but no before/after change detail)&lt;/P&gt;
&lt;P&gt;&amp;lt;14&amp;gt;Aug 15 14:06:53 PA-1 1,2022/08/15 14:06:53,016201015409,CONFIG,0,0,2022/08/15 14:06:53,192.168.1.10,,edit,adminacct,Web,Succeeded, vsys vsys1 address configlog_testobj,24838,0x0,0,0,0,0,,PA-AMA-Pri,0,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CUSTOM FORMAT (sourcetype is set to pan:log, the before/after change detail is present, but the sourcetype is wrong)&lt;BR /&gt;&amp;lt;14&amp;gt;Aug 15 14:18:57 PA-1 0x0 adminacct "configlog_testobj { description ""test change 90""; } " "configlog_testobj { description ""test change 80""; } " Aug 15 2022 19:18:57 GMT Aug 15 2022 19:18:57 GMT Web edit PA-AMA-Pri 192.168.1.10 vsys vsys1 address configlog_testobj 2022/08/15 14:18:57 Succeeded 9.1.12-h3 24843 016201015409 0 2022/08/15 14:18:57 CONFIG&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 19:52:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/511897#M106398</guid>
      <dc:creator>MikeSangray2019</dc:creator>
      <dc:date>2022-08-15T19:52:40Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Custom Format for Splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/595516#M118509</link>
      <description>&lt;P&gt;Cant you just add the other fields you need in the Custom log Format?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;actionflags="$actionflags", admin="$admin", after-change-detail="$after-change-detail", before-change-detail="$before-change-detail", cef-formatted-receive_time="$cef-formatted-receive_time", cef-formatted-time_generated="$cef-formatted-time_generated", client="$client", cmd="$cmd", host="$host", path="$path", receive_time="$receive_time", result="$result", seqno="$seqno", serial="$serial", subtype="$subtype", time_generated="$time_generated", type="$type", vsys="$vsys"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2024 21:27:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/595516#M118509</guid>
      <dc:creator>PerryPapanier</dc:creator>
      <dc:date>2024-08-21T21:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Custom Format for Splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/1226373#M123961</link>
      <description>&lt;P&gt;Just wanted to reply that I used this formatting for a customer and it worked as advertised to bring in the&amp;nbsp;&lt;SPAN&gt;after-change-detail="$after-change-detail", before-change-detail="$before-change-detail" fields. Thank you for posting this!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 18:04:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-custom-format-for-splunk/m-p/1226373#M123961</guid>
      <dc:creator>bgooch</dc:creator>
      <dc:date>2025-04-11T18:04:41Z</dc:date>
    </item>
  </channel>
</rss>

