<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto Custom Log Format in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Custom-Log-Format/m-p/416106#M50729</link>
    <description>&lt;P&gt;No I did not.  but wanted to post the info in case someone else was looking for it.  thanks monkeyK&lt;/P&gt;</description>
    <pubDate>Tue, 18 Dec 2018 15:35:26 GMT</pubDate>
    <dc:creator>ghostdog920</dc:creator>
    <dc:date>2018-12-18T15:35:26Z</dc:date>
    <item>
      <title>Palo Alto Custom Log Format</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Custom-Log-Format/m-p/416101#M50724</link>
      <description>&lt;P&gt;I am trying to setup a custom log format so that the before change and after change detail for a config change are included in the splunk log rather than a 0 value.  I tried a CEF format, but it isn't working and it is also causing all pan:config events to be identified as pan:traps.  I tried a few things unsuccessfully but wondered if anyone has any experience or examples of how to create a valid custom log that splunk can get.&lt;/P&gt;

&lt;P&gt;On a side note, can splunk interpret CEF log events, or do i have to install one of the CEF addons?  Going to need this later for my traps endpoint security manager.&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Nov 2018 18:06:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Custom-Log-Format/m-p/416101#M50724</guid>
      <dc:creator>ghostdog920</dc:creator>
      <dc:date>2018-11-30T18:06:54Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Custom Log Format</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Custom-Log-Format/m-p/416102#M50725</link>
      <description>&lt;P&gt;Figured it out with some google searching help.  Posting the results in case anyone else needs this.&lt;/P&gt;

&lt;P&gt;Palo Alto Custom Log Format, Confi, All Fields&lt;BR /&gt;
actionflags="$actionflags", admin="$admin", after-change-detail="$after-change-detail", before-change-detail="$before-change-detail", cef-formatted-receive_time="$cef-formatted-receive_time", cef-formatted-time_generated="$cef-formatted-time_generated", client="$client", cmd="$cmd", host="$host", path="$path", receive_time="$receive_time", result="$result", seqno="$seqno", serial="$serial", subtype="$subtype", time_generated="$time_generated", type="$type", vsys="$vsys"&lt;/P&gt;

&lt;P&gt;Palo Alto Custom Log Format, HIP Match, All Fields&lt;BR /&gt;
actionflags="$actionflags", cef-formatted-receive_time="$cef-formatted-receive_time", cef-formatted-time_generated="$cef-formatted-time_generated", machinename="$machinename", matchname="$matchname", matchtype="$matchtype", receive_time="$receive_time", repeatcnt="$repeatcnt", seqno="$seqno", serial="$serial", src="$src", srcuser="$srcuser", subtype="$subtype", time_generated="$time_generated", type="$type", vsys="$vsys"&lt;/P&gt;

&lt;P&gt;Palo Alto Custom Log Format, Traffic, All Fields&lt;BR /&gt;
action="$action", actionflags="$actionflags", app="$app", bytes="$bytes", bytes_received="$bytes_received", bytes_sent="$bytes_sent", category="$category", cef-formatted-receive_time="$cef-formatted-receive_time", cef-formatted-time_generated="$cef-formatted-time_generated", dport="$dport", dst="$dst", dstloc="$dstloc", dstuser="$dstuser", elapsed="$elapsed", flags="$flags", from="$from", inbound_if="$inbound_if", logset="$logset", natdport="$natdport", natdst="$natdst", natsport="$natsport", natsrc="$natsrc", outbound_if="$outbound_if", packets="$packets", padding="$padding", pkts_received="$pkts_received", pkts_sent="$pkts_sent", proto="$proto", receive_time="$receive_time", repeatcnt="$repeatcnt", rule="$rule", seqno="$seqno", serial="$serial", sessionid="$sessionid", sport="$sport", src="$src", srcloc="$srcloc", srcuser="$srcuser", start="$start", subtype="$subtype", time_generated="$time_generated", time_received="$time_received", to="$to", type="$type", vsys="$vsys"&lt;/P&gt;

&lt;P&gt;Palo Alto Custom Log Format, Threat, All Fields&lt;BR /&gt;
action="$action", actionflags="$actionflags", app="$app", category="$category", cef-formatted-receive_time="$cef-formatted-receive_time", cef-formatted-time_generated="$cef-formatted-time_generated", contenttype="$contenttype", direction="$direction", dport="$dport", dst="$dst", dstloc="$dstloc", dstuser="$dstuser", flags="$flags", from="$from", inbound_if="$inbound_if", logset="$logset", misc="$misc", natdport="$natdport", natdst="$natdst", natsport="$natsport", natsrc="$natsrc", number-of-severity="$number-of-severity", outbound_if="$outbound_if", proto="$proto", receive_time="$receive_time", repeatcnt="$repeatcnt", rule="$rule", seqno="$seqno", serial="$serial", sessionid="$sessionid", severity="$severity", sport="$sport", src="$src", srcloc="$srcloc", srcuser="$srcuser", subtype="$subtype", threatid="$threatid", time_generated="$time_generated", time_received="$time_received", to="$to", type="$type", vsys="$vsys"&lt;/P&gt;

&lt;P&gt;Palo Alto Custom Log Format, System, All Fields&lt;BR /&gt;
actionflags="$actionflags", cef-formatted-receive_time="$cef-formatted-receive_time", cef-formatted-time_generated="$cef-formatted-time_generated", eventid="$eventid", module="$module", number-of-severity="$number-of-severity", object="$object", opaque="$opaque", receive_time="$receive_time", seqno="$seqno", serial="$serial", severity="$severity", subtype="$subtype", time_generated="$time_generated", type="$type", vsys="$vsys"&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:17:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Custom-Log-Format/m-p/416102#M50725</guid>
      <dc:creator>ghostdog920</dc:creator>
      <dc:date>2020-09-29T22:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Custom Log Format</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Custom-Log-Format/m-p/416103#M50726</link>
      <description>&lt;P&gt;@ghostdog920, If your problem is resolved, please accept the answer to help future readers.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 12:43:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Custom-Log-Format/m-p/416103#M50726</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-12-04T12:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Custom Log Format</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Custom-Log-Format/m-p/416104#M50727</link>
      <description>&lt;P&gt;Sorry, thanks for catching that.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 13:06:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Custom-Log-Format/m-p/416104#M50727</guid>
      <dc:creator>ghostdog920</dc:creator>
      <dc:date>2018-12-04T13:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Custom Log Format</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Custom-Log-Format/m-p/416105#M50728</link>
      <description>&lt;P&gt;ghostdog920, you listed all of the syslogs.  Did you need to modify all of them?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Dec 2018 15:05:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Custom-Log-Format/m-p/416105#M50728</guid>
      <dc:creator>MonkeyK</dc:creator>
      <dc:date>2018-12-18T15:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Custom Log Format</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Custom-Log-Format/m-p/416106#M50729</link>
      <description>&lt;P&gt;No I did not.  but wanted to post the info in case someone else was looking for it.  thanks monkeyK&lt;/P&gt;</description>
      <pubDate>Tue, 18 Dec 2018 15:35:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Custom-Log-Format/m-p/416106#M50729</guid>
      <dc:creator>ghostdog920</dc:creator>
      <dc:date>2018-12-18T15:35:26Z</dc:date>
    </item>
  </channel>
</rss>

