Regex evaluating new line carriage ?

Reply
L2 Linker

Regex evaluating new line carriage ?

I have a Splunk server that logs all Acitve Directory authentication events on my network. I have set up a syslog feed from the Splunk server to the Palo Alto. On the Palo Alto, I have created a syslog filter and added the Splunk as a User-ID syslog server.

The problem I have is that Splunk sends each logon event as a single syslog entry which contains carriage returns and new lines (\r and \n). From what I can tell, the Palo Alto to expects to receive each user/IP pair in a single line. This means that I cannot parse the syslog to extract the info as user ID and IP are on different lines within a single syslog entry. Any thoughts on this will be of much assistance to me

Thank you. Ram.

L7 Applicator

Re: Regex evaluating new line carriage ?

Can you show a sample log entry that will be parsed?

I assume you have seen these general instructions on how to create the parser for syslog here.  Are the new line CR used as delimiters for a particular field?

How to Configure a Custom Syslog Sender and Test User Mappings

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
L2 Linker

Re: Regex evaluating new line carriage ?

Hi Steven, Thank you for helping me on this query, I have followed the document and still no success. I also tried \n or \s for a new line carriage. The case no# 301775 is for your reference, the attached pcap file is the actual output from the customer.

L7 Applicator

Re: Regex evaluating new line carriage ?

Glad to hear you have a support engineer working the case.  I'm just a PA customer, so I don't have access that system.  But I'm sure if support has a pcap of the logs a good parser will be coming shortly.

And support for Splunk in user-id will be a big win.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!