- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-13-2010 07:47 AM
Hello,
has anyone integrated PAN URL logs successfully with Sawmill for detailed reporting?
Would need some help on that given that we need to get browse time per user.
thanks
07-15-2010 11:43 AM
Here the basic instruction to use Sawmill Reporter to process PAN log to get URL web browse time (session).
This assumes that the PA unit has been configured to upload the threat log (version 2.x) or the url log (version 2.1 or higher) to a syslog server. The log file is accessible to sawmill via a network drive, FTP server, or hTTP server. Here, sawmill is installed on the same server as the syslog server.
- Go to http://www.sawmill.net/download.html, download the latest 'Professional' version, & install.
- Stop the sawmill service in Windows Services, copy & put the plug-in file (palo_alto_networks_firewall_URL.cfg) in the LogAnalysisInfo/log_formats directory, and restart the service.
- Create a New Profile in Sawmill, point to the log source, auto detect the log format, and choose format = "Palo Alto Networks Firewall Threat Log Format (URL Browse Time)"
The result will have "Session" in the Report, and session=browse time.
07-13-2010 11:31 AM
Looks like you'll need to setup a syslog profile to use Sawmill from this document.
07-15-2010 11:43 AM
Here the basic instruction to use Sawmill Reporter to process PAN log to get URL web browse time (session).
This assumes that the PA unit has been configured to upload the threat log (version 2.x) or the url log (version 2.1 or higher) to a syslog server. The log file is accessible to sawmill via a network drive, FTP server, or hTTP server. Here, sawmill is installed on the same server as the syslog server.
- Go to http://www.sawmill.net/download.html, download the latest 'Professional' version, & install.
- Stop the sawmill service in Windows Services, copy & put the plug-in file (palo_alto_networks_firewall_URL.cfg) in the LogAnalysisInfo/log_formats directory, and restart the service.
- Create a New Profile in Sawmill, point to the log source, auto detect the log format, and choose format = "Palo Alto Networks Firewall Threat Log Format (URL Browse Time)"
The result will have "Session" in the Report, and session=browse time.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!