<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo alto splunk syslog view in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-splunk-syslog-view/m-p/335227#M84495</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't think so it is vsys, because it is mentioned in the last stage of format.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;venky&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jun 2020 08:38:13 GMT</pubDate>
    <dc:creator>Venkatesan_radhakrishnan</dc:creator>
    <dc:date>2020-06-25T08:38:13Z</dc:date>
    <item>
      <title>Palo alto splunk syslog view</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-splunk-syslog-view/m-p/335195#M84491</link>
      <description>&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While exporting syslog from palo alto splunk in default format, what is the default format for config logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where I can see the default format. Next to hostname what is that value "1" where it comes from?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="output.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26403iB35A67C0FFFAA6A5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="output.jpg" alt="output.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 06:45:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-splunk-syslog-view/m-p/335195#M84491</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2020-06-25T06:45:29Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto splunk syslog view</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-splunk-syslog-view/m-p/335223#M84494</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97701"&gt;@Venkatesan_radhakrishnan&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Guessing that will be vsys:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CEF-style format that was used for Config log type :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;CEF:0|Palo Alto Networks|PAN-OS|$sender_sw_version|$result|$type|1|rt=$cef-formatted-receive_time deviceExternalId=$serial shost=$host cs3Label=Virtual System cs3=$vsys act=$cmd duser=$admin destinationServiceName=$client msg=$path externalId=$seqno PanOSDGl1=$dg_hier_level_1 PanOSDGl2=$dg_hier_level_2 PanOSDGl3=$dg_hier_level_3 PanOSDGl4=$dg_hier_level_4 PanOSVsysName=$vsys_name dvchost=$device_name PanOSActionFlags=$actionflags cs1Label=Before Change Detail cs1=$before-change-detail cs2Label=After Change Detail cs2=$after-change-detail&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check out all other CEF-style formats :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/resources/cef.html" target="_blank" rel="noopener"&gt;Common Event Format (CEF) Configuration Guides&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 25 Jun 2020 08:34:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-splunk-syslog-view/m-p/335223#M84494</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-06-25T08:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto splunk syslog view</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-splunk-syslog-view/m-p/335227#M84495</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't think so it is vsys, because it is mentioned in the last stage of format.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;venky&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 08:38:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-splunk-syslog-view/m-p/335227#M84495</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2020-06-25T08:38:13Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto splunk syslog view</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-splunk-syslog-view/m-p/335409#M84527</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you guess know what that value "1"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="shared-eventsviewer-shared-rawfield"&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t h"&gt;Jun&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;25&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;11:44:54&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;172.16.3.30&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Jun&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;25&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;22:52:00&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;PA-VM&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;,&lt;SPAN class="t"&gt;2020/06/25&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;22:52:00&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;015351000048743&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;CONFIG&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;2020/06/25&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;22:52:00&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;192.168.167.94&lt;/SPAN&gt;,,&lt;SPAN class="t"&gt;commit&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;venky&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;Web&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;Submitted&lt;/SPAN&gt;,,&lt;SPAN class="t"&gt;9377&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;0x0&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;,,&lt;SPAN class="t"&gt;PA-VM&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 25 Jun 2020 18:57:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-splunk-syslog-view/m-p/335409#M84527</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2020-06-25T18:57:58Z</dc:date>
    </item>
  </channel>
</rss>

