How to Filter logs from Strata Logging Service (CDL)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

How to Filter logs from Strata Logging Service (CDL)

L1 Bithead

This doc will walk through how to filter log fields directly from the Strata Logging Service to limit the amount of data being sent out Log Forwarding Profiles via Syslog, HTTPS or Email.

 

First log into your hub instance at apps.paloaltonetworks.com and click on the tile for Strata Logging Service.

nayubi_5-1714496856798.png

 

Next click on Log Forwarding to setup your Log forwarding Profiles and any formats or filters.

 

nayubi_6-1714496892719.png

 

Once you have setup the Forwarding Profiles, click on test to validate connectivity and then the 'Next" button.

nayubi_8-1714497239572.png

 

Now you will add which log types you want to send out from Strata Logging Service.

nayubi_9-1714497366791.png

 

If you want to send all log types, then create a filter with each log type by pulling down the drop down and saving with the default fields for each.

nayubi_15-1714499370095.png

 

nayubi_14-1714499225742.png

 

If you also want to filter which fields are sent via those log types, then you will need to click on the hamburger Icon in a field type, then chose the vertical hamburger.

nayubi_12-1714498324638.png

In this drop down you can choose which fields you want to forward based on what fields you use.  It will also filter the view as you add or remove fields.

nayubi_13-1714498454232.png

Next Save the changes and the Strata Logging Services will make the changes to start forwarding only these fields.

 

 

 

 

 

 

 

 

 

 

 

1 REPLY 1

L2 Linker

@nayubi wrote:

This doc will walk through how to filter log fields directly from the Strata Logging Service to limit the amount of data being sent out Log Forwarding Profiles via Syslog, HTTPS or Email.

 

First log into your hub instance at apps.paloaltonetworks.com and click on the tile for Strata Logging Service.

nayubi_5-1714496856798.png

 

Next click on Log Forwarding to setup your Log forwarding Profiles and any formats or filters.

 

nayubi_6-1714496892719.png

 

Once you have setup the Forwarding Profiles, click on test to validate connectivity and then the 'Next" button.

nayubi_8-1714497239572.png

 

Now you will add which log types you want to send out from Strata Logging Service.

nayubi_9-1714497366791.png

 

If you want to send all log types, then create a filter with each log type by pulling down the drop down and saving with the default fields for each.

nayubi_15-1714499370095.png

 

nayubi_14-1714499225742.png

 

If you also want to filter which fields are sent via those log types, then you will need to click on the hamburger Icon in a field type, then chose the vertical hamburger.

nayubi_12-1714498324638.png

In this drop down you can choose which fields you want to forward based on what fields you use.  It will also filter the view as you add or remove fields.

nayubi_13-1714498454232.png

Next Save the changes and the Strata Logging Services will make the changes to start forwarding only these fields.

 

 

 

 

 

 

 

 

 

 

 


Thank you @nayubi for putting this together. 

  • 363 Views
  • 1 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!