<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Output detailed HIP logs to syslog in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/output-detailed-hip-logs-to-syslog/m-p/334372#M84354</link>
    <description>&lt;P&gt;I have the same question as starting to implement this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a back end database or a CLI command that will output the rich info that magnifier glass provides ? I am guessing there is a way to do it since the data is there and available. Creating the HIP Objects and Profiles is good but is just basic info and is mostly on/off&amp;nbsp; for example if a system has antivirus or not, if installed or not, does not give specific info with the version and version number.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking on how to pull the rich info that the magnifier glass provides.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Help appreciated.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jun 2020 18:52:29 GMT</pubDate>
    <dc:creator>ChrisCapra</dc:creator>
    <dc:date>2020-06-19T18:52:29Z</dc:date>
    <item>
      <title>Output detailed HIP logs to syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/output-detailed-hip-logs-to-syslog/m-p/257258#M72981</link>
      <description>&lt;P&gt;Does anybody know how to output the detailed HIP match logs to syslog?&lt;/P&gt;&lt;P&gt;As it stands, we've got to go to Monitor &amp;gt; HIP Match &amp;gt; Magnifying Glass Icon to see them.&lt;/P&gt;&lt;P&gt;We'd like to send this rich data set to Splunk or another tool to write reports against.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="scresnshot.png" style="width: 717px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19553iE92349BECF8B5410/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="scresnshot.png" alt="scresnshot.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 15:20:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/output-detailed-hip-logs-to-syslog/m-p/257258#M72981</guid>
      <dc:creator>tmhorne</dc:creator>
      <dc:date>2019-04-11T15:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: Output detailed HIP logs to syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/output-detailed-hip-logs-to-syslog/m-p/257272#M72986</link>
      <description>&lt;P&gt;I use HIP myself&amp;nbsp;and only log to panorama but there is a setting in device\log settings for HIP, have you tried this, it only displays a match and what you called the HIP check so may not be enough information.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 15:49:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/output-detailed-hip-logs-to-syslog/m-p/257272#M72986</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-04-11T15:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: Output detailed HIP logs to syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/output-detailed-hip-logs-to-syslog/m-p/257273#M72987</link>
      <description>&lt;P&gt;I'm already sending Hip Match logs off via syslog, but it is only summary logs. It does not have the rich data that you get when you hit the magnifying glass.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 15:54:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/output-detailed-hip-logs-to-syslog/m-p/257273#M72987</guid>
      <dc:creator>tmhorne</dc:creator>
      <dc:date>2019-04-11T15:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: Output detailed HIP logs to syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/output-detailed-hip-logs-to-syslog/m-p/334372#M84354</link>
      <description>&lt;P&gt;I have the same question as starting to implement this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a back end database or a CLI command that will output the rich info that magnifier glass provides ? I am guessing there is a way to do it since the data is there and available. Creating the HIP Objects and Profiles is good but is just basic info and is mostly on/off&amp;nbsp; for example if a system has antivirus or not, if installed or not, does not give specific info with the version and version number.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking on how to pull the rich info that the magnifier glass provides.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Help appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 18:52:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/output-detailed-hip-logs-to-syslog/m-p/334372#M84354</guid>
      <dc:creator>ChrisCapra</dc:creator>
      <dc:date>2020-06-19T18:52:29Z</dc:date>
    </item>
    <item>
      <title>Re: Output detailed HIP logs to syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/output-detailed-hip-logs-to-syslog/m-p/334375#M84356</link>
      <description>&lt;P&gt;Have a look here...&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClshCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClshCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not had chance myself as the wine doth floweth at a somewhat rapid pace...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;a bit of scripting or api call may be required for automation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 19:00:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/output-detailed-hip-logs-to-syslog/m-p/334375#M84356</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-06-19T19:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: Output detailed HIP logs to syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/output-detailed-hip-logs-to-syslog/m-p/334409#M84361</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/2666"&gt;@tmhorne&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;'s KB article states, this is kept in a local database and isn't really exposed in an easy format to get it exported off of the firewall. The firewall's own API isn't going to be very handy in this type of situation either, given the nature of the command required to access information held in that local database.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would actually look at pulling in the&amp;nbsp;&lt;EM&gt;client's&amp;nbsp;&lt;/EM&gt;GlobalProtect logs instead of dumping them from the firewall's database. That's easier to maintain and will give you the information in the exact same format if it's desired.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jun 2020 03:47:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/output-detailed-hip-logs-to-syslog/m-p/334409#M84361</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-06-20T03:47:48Z</dc:date>
    </item>
  </channel>
</rss>

