Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Palo Alto Networks Firewall TCP (PAN-OS v9+) input parse error #956

Open
qaxi opened this issue Dec 29, 2021 · 1 comment
Open

Palo Alto Networks Firewall TCP (PAN-OS v9+) input parse error #956

qaxi opened this issue Dec 29, 2021 · 1 comment

Comments

@qaxi
Copy link

qaxi commented Dec 29, 2021

Expected Behavior

field pan_source_user contains date 2021-12-29 08:06:50.775 +00:00

Current Behavior

field pan_source_user should contain username

Possible Solution

Take a look to https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/user-id-log-fields.html#id23f3cbfb-946f-423f-bc48-50fdc2b68238

Steps to Reproduce (for bugs)

  1. Use Graylog 4.2.4+b643d2b on f687edde0f02 (Oracle Corporation 1.8.0_312 on Linux 5.4.0-53-generic)
  2. and Palo Alto Firewall 10.0.8
  3. create Palo Alto Networks Firewall TCP (PAN-OS v9+) input

Context

Your Environment

  • Graylog Version: 4.2.4+b643d2b
  • Java Version: f687edde0f02 (Oracle Corporation 1.8.0_312 on Linux 5.4.0-53-generic)
  • Elasticsearch Version: 7.10.2
  • MongoDB Version: 4.2
  • Operating System: Ubuntu 20.04
  • Browser version: FF 95
@bernd bernd transferred this issue from Graylog2/graylog2-server Jan 3, 2022
@bernd
Copy link
Member

bernd commented Jan 3, 2022

FYI: I moved this from the server repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants