<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error in CEF format for Threat logs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/error-in-cef-format-for-threat-logs/m-p/363532#M88374</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44251"&gt;@MarcelST&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the heads up.&amp;nbsp; I've requested a review of the DOC with your information.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Tue, 17 Nov 2020 13:40:51 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2020-11-17T13:40:51Z</dc:date>
    <item>
      <title>Error in CEF format for Threat logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-in-cef-format-for-threat-logs/m-p/363257#M88345</link>
      <description>&lt;P&gt;The following guide provides the parsing for&amp;nbsp;CEF-style Log Formats for PAN-OS 9.1:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/content/dam/techdocs/en_US/pdf/cef/pan-os-91-cef-configuration-guide.pdf" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/content/dam/techdocs/en_US/pdf/cef/pan-os-91-cef-configuration-guide.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have been using this for a while, but because now we have a 2nd source of logs (PRISMA) aside from Panorama, we just found out the parsing suggested for "Threat" log is not correct in our opinion, and that was causing some issues on our SIEM use-cases.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In short, this field is wrong and should be replaced by &lt;FONT color="#339966"&gt;&lt;STRONG&gt;$subtype&lt;/STRONG&gt;&lt;/FONT&gt;:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Threat CEF:0|Palo Alto&lt;BR /&gt;Networks|PAN-OS|$sender_sw_version|&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;$threatid&lt;/STRONG&gt;&lt;/FONT&gt;|$type|$number-of-severity|rt=$cef-formatted-receive_time&lt;BR /&gt;deviceExternalId=$serial src=$src dst=$dst sourceTranslatedAddress=$natsrc&lt;BR /&gt;destinationTranslatedAddress=$natdst cs1Label=Rule cs1=$rule suser=$srcuser duser=$dstuser app=$app&lt;BR /&gt;cs3Label=Virtual System cs3=$vsys cs4Label=Source Zone cs4=$from cs5Label=Destination Zone cs5=$to&lt;BR /&gt;deviceInboundInterface=$inbound_if deviceOutboundInterface=$outbound_if cs6Label=LogProfile cs6=$logset&lt;BR /&gt;cn1Label=SessionID cn1=$sessionid cnt=$repeatcnt spt=$sport dpt=$dport sourceTranslatedPort=$natsport&lt;BR /&gt;destinationTranslatedPort=$natdport flexString1Label=Flags flexString1=$flags proto=$proto act=$action&lt;BR /&gt;request=$misc cs2Label=URL Category cs2=$category flexString2Label=Direction flexString2=$direction&lt;BR /&gt;PanOSActionFlags=$actionflags externalId=$seqno cat=$threatid fileId=$pcap_id PanOSDGl1=$dg_hier_level_1&lt;BR /&gt;PanOSDGl2=$dg_hier_level_2 PanOSDGl3=$dg_hier_level_3 PanOSDGl4=$dg_hier_level_4&lt;BR /&gt;PanOSVsysName=$vsys_name dvchost=$device_name PanOSSrcUUID=$src_uuid PanOSDstUUID=$dst_uuid&lt;BR /&gt;PanOSTunnelID=$tunnelid PanOSMonitorTag=$monitortag PanOSParentSessionID=$parent_session_id&lt;BR /&gt;PanOSParentStartTime=$parent_start_time PanOSTunnelType=$tunnel PanOSThreatCategory=$thr_category&lt;BR /&gt;PanOSContentVer=$contentver PanOSAssocID=$assoc_id PanOSPPID=$ppid PanOSHTTPHeader=$http_headers&lt;BR /&gt;PanOSURLCatList=$url_category_list PanOSRuleUUID=$rule_uuid PanOSHTTP2Con=$http2_connection&lt;BR /&gt;PanDynamicUsrgrp=$dynusergroup_name&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;How can we get this fixed in the document?&lt;/LI&gt;&lt;LI&gt;Additionally, is it possible to get the document updated with PAN-OS 10 in &lt;A href="https://docs.paloaltonetworks.com/resources/cef" target="_self"&gt;here&lt;/A&gt;?&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 16 Nov 2020 10:27:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-in-cef-format-for-threat-logs/m-p/363257#M88345</guid>
      <dc:creator>MarcelST</dc:creator>
      <dc:date>2020-11-16T10:27:16Z</dc:date>
    </item>
    <item>
      <title>Re: Error in CEF format for Threat logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-in-cef-format-for-threat-logs/m-p/363532#M88374</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44251"&gt;@MarcelST&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the heads up.&amp;nbsp; I've requested a review of the DOC with your information.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 17 Nov 2020 13:40:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-in-cef-format-for-threat-logs/m-p/363532#M88374</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-11-17T13:40:51Z</dc:date>
    </item>
  </channel>
</rss>

