cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who rated this post

How to Filter logs from Strata Logging Service (CDL)

L1 Bithead

This doc will walk through how to filter log fields directly from the Strata Logging Service to limit the amount of data being sent out Log Forwarding Profiles via Syslog, HTTPS or Email.

 

First log into your hub instance at apps.paloaltonetworks.com and click on the tile for Strata Logging Service.

nayubi_5-1714496856798.png

 

Next click on Log Forwarding to setup your Log forwarding Profiles and any formats or filters.

 

nayubi_6-1714496892719.png

 

Once you have setup the Forwarding Profiles, click on test to validate connectivity and then the 'Next" button.

nayubi_8-1714497239572.png

 

Now you will add which log types you want to send out from Strata Logging Service.

nayubi_9-1714497366791.png

 

If you want to send all log types, then create a filter with each log type by pulling down the drop down and saving with the default fields for each.

nayubi_15-1714499370095.png

 

nayubi_14-1714499225742.png

 

If you also want to filter which fields are sent via those log types, then you will need to click on the hamburger Icon in a field type, then chose the vertical hamburger.

nayubi_12-1714498324638.png

In this drop down you can choose which fields you want to forward based on what fields you use.  It will also filter the view as you add or remove fields.

nayubi_13-1714498454232.png

Next Save the changes and the Strata Logging Services will make the changes to start forwarding only these fields.

 

 

 

 

 

 

 

 

 

 

 

Who rated this post