Syslog Custom Format for Splunk

Reply
Highlighted
L2 Linker

Syslog Custom Format for Splunk

I'm trying to get the firewall to send before and after change detail to splunk. I've tried various formats in Custom Log Format, but any changes I make result in no logs being sent to splunk. What is the correct format for Custom Log Format when using syslog and splunk? I'm running PA OS 8.1

 

Highlighted
Cyber Elite

Re: Syslog Custom Format for Splunk

@MikeSangray2019,

Making a custom format shouldn't break sending the syslog to Splunk, are you sure that the logs aren't actually getting to Splunk at all? If you could share our format and the actual software version you are running we might be able to identify something. 

Highlighted
L2 Linker

Re: Syslog Custom Format for Splunk

Logs are being shipped to Splunk. I'm following the directions to use custom formatting  'Enter the log format above. Click on the field names in the left panel to include them in the log format.' by clicking on the name, then commit, and then no more config logs after that change to use custom log formatting. Return to default and config logs start working again. Just confirmed again. Maybe something for tech support?

Highlighted

Re: Syslog Custom Format for Splunk

Hi Mike,

 

Did you get any resolution for this issue


Regards

Venky

 

Highlighted
L2 Linker

Re: Syslog Custom Format for Splunk

No, I did not get a resolution for this.

Highlighted

Re: Syslog Custom Format for Splunk

Hi 

 

i'm facing same issue, If you dont mind did you raise it with support.

 

Regards

Venky

Highlighted
L2 Linker

Re: Syslog Custom Format for Splunk

Sorry, I did not open a ticket with support for this.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!