I'm trying to get the firewall to send before and after change detail to splunk. I've tried various formats in Custom Log Format, but any changes I make result in no logs being sent to splunk. What is the correct format for Custom Log Format when using syslog and splunk? I'm running PA OS 8.1
Making a custom format shouldn't break sending the syslog to Splunk, are you sure that the logs aren't actually getting to Splunk at all? If you could share our format and the actual software version you are running we might be able to identify something.
Logs are being shipped to Splunk. I'm following the directions to use custom formatting 'Enter the log format above. Click on the field names in the left panel to include them in the log format.' by clicking on the name, then commit, and then no more config logs after that change to use custom log formatting. Return to default and config logs start working again. Just confirmed again. Maybe something for tech support?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The LIVEcommunity thanks you for your participation!