<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Correlation Event logs are not showing the same values as in Summary in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/correlation-event-logs-are-not-showing-the-same-values-as-in/m-p/338233#M85075</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have configured the firewall to forward the correlation event logs to the syslog server. We started verifying the logs in syslog server and found the logs were not matching, all are showing the same value in the syslog server "host visited know malware URL (11 time). Whereas in firewall we see random values.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Firewall:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CSFCSLU_0-1594674922533.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26751i4968E0DDFCA2D6F0/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CSFCSLU_0-1594674922533.png" alt="CSFCSLU_0-1594674922533.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In Syslog server:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CSFCSLU_1-1594675215685.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26752iE70D7B174D89A70B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CSFCSLU_1-1594675215685.png" alt="CSFCSLU_1-1594675215685.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Please let me know why it always shows 11 time in Syslog server rather than showing the same value as in firewall.&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jul 2020 21:23:06 GMT</pubDate>
    <dc:creator>CSFCSLU</dc:creator>
    <dc:date>2020-07-13T21:23:06Z</dc:date>
    <item>
      <title>Correlation Event logs are not showing the same values as in Summary</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correlation-event-logs-are-not-showing-the-same-values-as-in/m-p/338233#M85075</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have configured the firewall to forward the correlation event logs to the syslog server. We started verifying the logs in syslog server and found the logs were not matching, all are showing the same value in the syslog server "host visited know malware URL (11 time). Whereas in firewall we see random values.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Firewall:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CSFCSLU_0-1594674922533.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26751i4968E0DDFCA2D6F0/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CSFCSLU_0-1594674922533.png" alt="CSFCSLU_0-1594674922533.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In Syslog server:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CSFCSLU_1-1594675215685.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26752iE70D7B174D89A70B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CSFCSLU_1-1594675215685.png" alt="CSFCSLU_1-1594675215685.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Please let me know why it always shows 11 time in Syslog server rather than showing the same value as in firewall.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 21:23:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correlation-event-logs-are-not-showing-the-same-values-as-in/m-p/338233#M85075</guid>
      <dc:creator>CSFCSLU</dc:creator>
      <dc:date>2020-07-13T21:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: Correlation Event logs are not showing the same values as in Summary</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correlation-event-logs-are-not-showing-the-same-values-as-in/m-p/338312#M85080</link>
      <description>&lt;P&gt;What PAN-OS version are you currently running?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 02:46:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correlation-event-logs-are-not-showing-the-same-values-as-in/m-p/338312#M85080</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-07-14T02:46:37Z</dc:date>
    </item>
    <item>
      <title>Re: Correlation Event logs are not showing the same values as in Summary</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correlation-event-logs-are-not-showing-the-same-values-as-in/m-p/338427#M85102</link>
      <description>&lt;P&gt;Firewall is running on PAN-OS 9.0.6.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 13:53:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correlation-event-logs-are-not-showing-the-same-values-as-in/m-p/338427#M85102</guid>
      <dc:creator>CSFCSLU</dc:creator>
      <dc:date>2020-07-14T13:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: Correlation Event logs are not showing the same values as in Summary</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correlation-event-logs-are-not-showing-the-same-values-as-in/m-p/338834#M85156</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/87670"&gt;@CSFCSLU&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;So I went and took a look at the logs from my environment just to verify that I'm not seeing the same thing, and at least on 9.0.9-h1 these logs are showing up in my SIEM as expected. If you take a look at the raw syslog data sent to your SIEM, do you still see a discrepancy?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 02:49:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correlation-event-logs-are-not-showing-the-same-values-as-in/m-p/338834#M85156</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-07-16T02:49:41Z</dc:date>
    </item>
  </channel>
</rss>

