Regex evaluating new line carriage ?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Regex evaluating new line carriage ?

L2 Linker

I have a Splunk server that logs all Acitve Directory authentication events on my network. I have set up a syslog feed from the Splunk server to the Palo Alto. On the Palo Alto, I have created a syslog filter and added the Splunk as a User-ID syslog server.

The problem I have is that Splunk sends each logon event as a single syslog entry which contains carriage returns and new lines (\r and \n). From what I can tell, the Palo Alto to expects to receive each user/IP pair in a single line. This means that I cannot parse the syslog to extract the info as user ID and IP are on different lines within a single syslog entry. Any thoughts on this will be of much assistance to me

Thank you. Ram.

3 REPLIES 3

L7 Applicator

Can you show a sample log entry that will be parsed?

I assume you have seen these general instructions on how to create the parser for syslog here.  Are the new line CR used as delimiters for a particular field?

How to Configure a Custom Syslog Sender and Test User Mappings

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

Hi Steven, Thank you for helping me on this query, I have followed the document and still no success. I also tried \n or \s for a new line carriage. The case no# 301775 is for your reference, the attached pcap file is the actual output from the customer.

Glad to hear you have a support engineer working the case.  I'm just a PA customer, so I don't have access that system.  But I'm sure if support has a pcap of the logs a good parser will be coming shortly.

And support for Splunk in user-id will be a big win.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
  • 2917 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!