cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Who Me Too'd this topic

Domain syslog match not functioning

L1 Bithead

Hi!

 

I'm having some trouble matching domain indicators on syslog feeds. So far I have a setup like this:

 

ransomwaretracker_RW_DOMBL (Miner) -> aggregatorDomain (Aggregator) -> feedDomainHCGreenWithValue (Output) -> Domain EDL within PAN-OS

 

The above is working fine and I have verified a positive matches on indicators in the logs.

 

Next I have a localSyslog analyzer also attached to the aggregatorDomain position. Despite having positive matches in the logs this is not shown in the localSyslog analyzer stats. 

 

I have another syslog analyzer correctly parsing syslog messages and performing matches so I know the configuration of both PAN-OS is correct and the syslogAnalyzer. Any pointers on what might be the issue?

 

Regards

Erik Yunghans

 

 

Who Me Too'd this topic