<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Kiwi syslog server and Palo Alto app for splunk issues in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Kiwi-syslog-server-and-Palo-Alto-app-for-splunk-issues/m-p/523544#M88403</link>
    <description>&lt;P&gt;So apparently I can strip data out of the syslog file before it is sent to splunk.&amp;nbsp; This will help deal with 1 of my two issues.&amp;nbsp; Here is an example of the start of each row in the log file:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;host&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; serial #&lt;/P&gt;&lt;P&gt;Oct 07 15:01:42 x.x.x.x 1,2020/10/07 15:01:42,xxxxxxxxxxxxxxx,TRAFFIC&lt;/P&gt;&lt;P&gt;To more clearly state my goals:&lt;/P&gt;&lt;P&gt;1)&amp;nbsp; I would love to strip the 1st date/time stamp (as you can see there are 2) from the data before it is indexed.&lt;/P&gt;&lt;P&gt;2)&amp;nbsp; I would love to have splunk identify the host as either the ip address of the host of the serial # of the host instead of the syslog server that is sending this data to splunk&lt;/P&gt;&lt;P&gt;3)&amp;nbsp; Currently the universal forwarder that is sending this data to splunk is using a sourcetype of Pan:logs, but it is not splitting out the logs into their appropriate subcatagory (i.e. Pan:firewall, Pan:System, Pan:traffic etc).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ian&lt;/P&gt;</description>
    <pubDate>Wed, 07 Oct 2020 22:10:33 GMT</pubDate>
    <dc:creator>Iwdavies</dc:creator>
    <dc:date>2020-10-07T22:10:33Z</dc:date>
    <item>
      <title>Kiwi syslog server and Palo Alto app for splunk issues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Kiwi-syslog-server-and-Palo-Alto-app-for-splunk-issues/m-p/523264#M88381</link>
      <description>&lt;P&gt;We have 3 palo alto firewalls that I'm sending syslog data to a solarwinds kiwi syslog server.&amp;nbsp; I am having kiwi write the logs to disk and have the splunk universal forwarder send the logs to my splunk environment.&amp;nbsp; I have 2 issues which I can't seem to figure out (even after looking at various posts here that mention similar scenarios).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1)&amp;nbsp; The Palo Alto app states that there is only 1 firewall.&amp;nbsp; When i look in the logs that "firewall" is the kiwi syslog server.&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;I have tried adding a Host variable to the inputs (no such luck).&amp;nbsp; Tried having kiwi just forward the logs&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;directly to splunk (no such luck).&amp;nbsp; I have even tried to have kiwi just send the raw data.&amp;nbsp; In every case kiwi&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;is appending its own date / time stamp and host value in front of the palo alto messages.&amp;nbsp; I'm not sure&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;how to completely strip that information.&lt;/P&gt;&lt;P&gt;2)&amp;nbsp; The Palo Alto see's the source type as Pan:Logs, but it is not seperating them into their perspective logs:&amp;nbsp; i.e. Pan:Firewall, Pan:System, Pan:traffic etc..&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;I have seen suggestions to use a transforms file and / or a props file, but I'm just too new to understand&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;how to configure them properly.&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2020 19:08:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Kiwi-syslog-server-and-Palo-Alto-app-for-splunk-issues/m-p/523264#M88381</guid>
      <dc:creator>Iwdavies</dc:creator>
      <dc:date>2020-10-06T19:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: Kiwi syslog server and Palo Alto app for splunk issues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Kiwi-syslog-server-and-Palo-Alto-app-for-splunk-issues/m-p/523292#M88385</link>
      <description>&lt;P&gt;The Kiwi Syslog Server is something many people have problems out of.&amp;nbsp; Indeed, the Venn diagram of "people who use kiwi" and "people who have problems with kiwi" is nearly two overlapping circles.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Possible solution if you stick with Kiwi&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;It might be that there are some kiwi syslog settings you can change.&amp;nbsp; It appears there's a whole section in the admin manual about log file and database formats.&lt;/P&gt;&lt;P&gt;What to change it to?&amp;nbsp; Well, I'd skip anything with the word "Kiwi" in it, because those are of course all non-standard "kiwi specific" file formats, which means nothing else understands them.&lt;/P&gt;&lt;P&gt;Maybe the BSD style log format will work?&amp;nbsp; You could give it a try, won't be any worse than what you have now.&lt;/P&gt;&lt;P&gt;Though at some point you'll hit Kiwi's scaling limits, which I hear are very, very low.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Better Solutions&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I don't really mean to disrespect Kiwi Syslog Server, but it's really been a problem for a lot of people.&lt;/P&gt;&lt;P&gt;If it were me, I'd stand up a small virtual machine running Linux or pretty much any distribution, remove rsyslog if it has it (Just way harder to configure due to a really obtuse syntax), install &lt;STRONG&gt;syslog-ng&lt;/STRONG&gt; and google for the configs you'll want there, put on the Universal Forwarder configured to send its output to your indexer and ... bask in the gloriously well-working, nearly bullet proof zero maintenance syslog server that works in a standard, predictable and compatible way.&lt;/P&gt;&lt;P&gt;Heck, I bet you could run syslog-ng in Ubuntu on WSL, right there "inside windows".&amp;nbsp; Try that - get Window's Ubuntu up on WSL, and do a "sudo apt install syslog-ng" and go from there.&amp;nbsp; You MIGHT have to configure it to listen to a higher port instead of 514 (because... well, reasons, possibly), but even with that, it's worth a try.&lt;/P&gt;&lt;P&gt;Happy Splunking!&lt;/P&gt;&lt;P&gt;-Rich&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2020 20:51:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Kiwi-syslog-server-and-Palo-Alto-app-for-splunk-issues/m-p/523292#M88385</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2020-10-06T20:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: Kiwi syslog server and Palo Alto app for splunk issues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Kiwi-syslog-server-and-Palo-Alto-app-for-splunk-issues/m-p/523526#M88400</link>
      <description>&lt;P&gt;After looking at this from a kiwi side, I realized that it doesn't matter how much data kiwi adds to the stream.&amp;nbsp; Even if I were to be able to remove all the kiwi header, splunk would still think the host is only 1 server (the kiwi server) since only one server is technically sending data to kiwi.&amp;nbsp; So my real issue is to get splunk to recognize the host from the log file and not from the sending device.&amp;nbsp; I understand that to do this I need to use a transforms and props file, but am still very confused on how to accomplish this.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 21:03:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Kiwi-syslog-server-and-Palo-Alto-app-for-splunk-issues/m-p/523526#M88400</guid>
      <dc:creator>Iwdavies</dc:creator>
      <dc:date>2020-10-07T21:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Kiwi syslog server and Palo Alto app for splunk issues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Kiwi-syslog-server-and-Palo-Alto-app-for-splunk-issues/m-p/523544#M88403</link>
      <description>&lt;P&gt;So apparently I can strip data out of the syslog file before it is sent to splunk.&amp;nbsp; This will help deal with 1 of my two issues.&amp;nbsp; Here is an example of the start of each row in the log file:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;host&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; serial #&lt;/P&gt;&lt;P&gt;Oct 07 15:01:42 x.x.x.x 1,2020/10/07 15:01:42,xxxxxxxxxxxxxxx,TRAFFIC&lt;/P&gt;&lt;P&gt;To more clearly state my goals:&lt;/P&gt;&lt;P&gt;1)&amp;nbsp; I would love to strip the 1st date/time stamp (as you can see there are 2) from the data before it is indexed.&lt;/P&gt;&lt;P&gt;2)&amp;nbsp; I would love to have splunk identify the host as either the ip address of the host of the serial # of the host instead of the syslog server that is sending this data to splunk&lt;/P&gt;&lt;P&gt;3)&amp;nbsp; Currently the universal forwarder that is sending this data to splunk is using a sourcetype of Pan:logs, but it is not splitting out the logs into their appropriate subcatagory (i.e. Pan:firewall, Pan:System, Pan:traffic etc).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ian&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 22:10:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Kiwi-syslog-server-and-Palo-Alto-app-for-splunk-issues/m-p/523544#M88403</guid>
      <dc:creator>Iwdavies</dc:creator>
      <dc:date>2020-10-07T22:10:33Z</dc:date>
    </item>
  </channel>
</rss>

