ML/RE- Split /PALogs per serial# of firewall in the case of forwarding logs from Panorama

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
L6 Presenter
No ratings

UseCase

 

In the ML or RE case, where Expedition is configured as syslog server , and you are forwarding traffic logs from Panorama to Expedition,  by default, the logs will be saved using Panorama_IP . The solution below provides steps on how to  split the logs per serial# of the firewall.

 

Solution

 

Split the logs per FW/Serial number by following below steps:

 

Step 1. Edit your rsyslog.conf file

 

Replace below line:


$template DynaTrafficLog,"/PALogs/%FROMHOST-IP%/%HOSTNAME%traffic%$YEAR%%$MONTH%%$DAY%_last_calendar_day.csv"


to below ones:


set $!SERIAL = field($msg,",",2);
$template DynaTrafficLog,"/PALogs/%FROMHOST-IP%/%$!SERIAL%/%$!SERIAL%%HOSTNAME%_traffic%$YEAR%%$MONTH%%$DAY%_last_calendar_day.csv"

 

The intention of the above configuration is to create a folder with your Panorama IP and subfolders for each FW/Serial number.

 

Step 2. Restart the syslog service

Issue below command:

service rsyslog restart

 

For your reference, next Expedition releases will include a set of rsyslog configuration example files on the path /var/www/html/OS/rsyslog folder .

 

Rate this article:
  • 1404 Views
  • 0 comments
  • 1 Likes
Register or Sign-in
Contributors
Article Dashboard
Version history
Last Updated:
‎03-02-2023 10:40 AM
Updated by: