<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sawmill with PAN URL logs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/sawmill-with-pan-url-logs/m-p/12175#M8925</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like you'll need to setup a syslog profile to use Sawmill from this document.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1418"&gt;https://live.paloaltonetworks.com/docs/DOC-1418&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 13 Jul 2010 18:31:48 GMT</pubDate>
    <dc:creator>mharding</dc:creator>
    <dc:date>2010-07-13T18:31:48Z</dc:date>
    <item>
      <title>Sawmill with PAN URL logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sawmill-with-pan-url-logs/m-p/12174#M8924</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;has anyone integrated PAN URL logs successfully with Sawmill for detailed reporting?&lt;/P&gt;&lt;P&gt;Would need some help on that given that we need to get browse time per user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jul 2010 14:47:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sawmill-with-pan-url-logs/m-p/12174#M8924</guid>
      <dc:creator>vinesh</dc:creator>
      <dc:date>2010-07-13T14:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: Sawmill with PAN URL logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sawmill-with-pan-url-logs/m-p/12175#M8925</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like you'll need to setup a syslog profile to use Sawmill from this document.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1418"&gt;https://live.paloaltonetworks.com/docs/DOC-1418&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jul 2010 18:31:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sawmill-with-pan-url-logs/m-p/12175#M8925</guid>
      <dc:creator>mharding</dc:creator>
      <dc:date>2010-07-13T18:31:48Z</dc:date>
    </item>
    <item>
      <title>Re: Sawmill with PAN URL logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sawmill-with-pan-url-logs/m-p/12176#M8926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here the basic instruction to use Sawmill Reporter to process PAN log to get URL web browse time (session).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This assumes that the PA unit has been configured to upload the threat log (version 2.x) or the url log (version 2.1 or higher) to a syslog server. The log file is accessible to sawmill via a network drive, FTP server, or hTTP server.&amp;nbsp; Here, sawmill is installed on the same server as the syslog server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;- Go to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.sawmill.net/download.html"&gt;http://www.sawmill.net/download.html&lt;/A&gt;&lt;SPAN&gt;, download the latest 'Professional' version, &amp;amp; install. &lt;/SPAN&gt;&lt;BR /&gt;- Stop the sawmill service in Windows Services, copy &amp;amp; put the plug-in file (palo_alto_networks_firewall_URL.cfg) in the LogAnalysisInfo/log_formats directory, and restart the service.&lt;BR /&gt;- Create a New Profile in Sawmill, point to the log source, auto detect the log format, and choose format = "Palo Alto Networks Firewall Threat Log Format (URL Browse Time)"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The result will have "Session" in the Report, and session=browse time.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Jul 2010 18:43:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sawmill-with-pan-url-logs/m-p/12176#M8926</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2010-07-15T18:43:56Z</dc:date>
    </item>
  </channel>
</rss>

