Oracle 19c RDBMS Integration SOP
Oracle 19c RDBMS Integration SOP
1
RESTRICTED
Disclaimers
This document is designed to provide helpful information on the subject matter within. The recipient
acknowledges and agrees that any advice, recommendations, reports, analyses, deliverables, or other
material supplied by Rewterz have been intended for the recipient solely for the benefit of the recipient
and not any other third party. Rewterz made every attempt to ensure the accuracy and reliability of the
information in this document. However, it assumes no responsibility for errors, omissions, misuse,
misunderstanding, or inapplicability of the contents of this document.
In no event shall Rewterz be liable for any special, direct, indirect, consequential, or incidental damages
or any damages whatsoever, whether in an action of contract, negligence, or other torts, arising out of
or in connection with the use of the information contained in this document.
Confidentiality
This document may contain information of a sensitive nature. This information should not be shared
with anyone other than those for whom it was originally intended. No one else may disclose, distribute,
or otherwise use the contents of this document without the express written permission of the owner.
Unauthorized use, disclosure, dissemination, duplication, and/or distribution are strictly prohibited and
may be unlawful. If you receive this document in error, please immediately delete it and all copies from
your system, destroy any hard copies and notify Rewterz.
Copyright
The information contained in this document is the proprietary and exclusive property of Rewterz except
as otherwise indicated. Notwithstanding its intended purpose, no part of this document, in whole or in
part, may be reproduced, stored, transmitted, or used for any purpose without the prior written
permission of the Company.
2
Objective
To send Palo Alto PA Series events to IBM QRadar, create a Syslog destination (LEEF or CEF event
format) on your Palo Alto PA Series device. Palo Alto can send only one format to all Syslog devices. By
modifying the Syslog format, any other device that requires Syslog must support that same format.
Pre-Requisites
Following pre-requisites are required for configuration at SIEM end:
Database Name
IP/Hostname
User Name / Password (having read rights for that table/view)
Table / View Name
Compare Fields
Port 1521 (default Oracle Net Listener port) is used for bidirectional communication via TCP
Protocol. Allow inbound TCP port 1521 on the Oracle Database server.
o Verify the Oracle listener is running and listening on port 1521 on public IPv4 address.
Following below mentioned RPMS should be installed in QRadar
o Protocol JDBC RPM
o DSMCommon RPM
o Oracle RDBMS Audit Record DSM RPM
3
4
Procedure
Configure LEEF Formatted Events
Consider the following to configure the Syslog profile on the respective device:
1. Log in to Palo Alto Networks.
2. On the Device tab, click Server Profiles > Syslog, and then click Add.
3. Create a Syslog destination by following these steps:
a) In the Syslog Server Profile dialog box, click Add.
b) Specify the name, server IP address, port, and facility of the QRadar system that you want
to use as a Syslog server.
c) If you are using Syslog, set the Custom Format column to Default for all log types.
4. Configure LEEF events by following these steps:
a) Click the Custom Log Format tab in the Syslog Server Profile dialog.
b) Click Config, copy one of the following texts applicable to the version you are using, and
paste it in the Config Log Format field for the Config log type. If your version is not listed,
omit this step.
5
c) Click System, then copy one of the following texts applicable to the version you are using,
and paste it in the System Log Format field for the System log type. If your version is not
listed, omit this step.
6
d) Click Threat, copy one of the following texts applicable to the version you are using, and
paste it in the Threat Log Format field for the Threat log type. If your version is not listed,
omit this step.
7
dstPostNAT=$natdst|RuleName=$rule|usrName=$srcuser|SourceUser=$srcuser|
DestinationUser=$dstuser|Application=$app|VirtualSystem=$vsys|SourceZone=$from|
DestinationZone=$to|IngressInterface=$inbound_if|EgressInterface=$outbound_if|
LogForwardingProfile=$logset|SessionID=$sessionid|RepeatCount=$repeatcnt|
srcPort=$sport|dstPort=$dport|srcPostNATPort=$natsport|dstPostNATPort=$natdport|
Flags=$flags|proto=$proto|action=$action|Miscellaneous=$misc|ThreatID=$threatid|
URLCategory=$category|sev=$number-of-severity|Severity=$severity|Direction=$direction|
sequence=$seqno|ActionFlags=$actionflags|SourceLocation=$srcloc|
DestinationLocation=$dstloc|ContentType=$contenttype|PCAP_ID=$pcap_id|
FileDigest=$filedigest|Cloud=$cloud|URLIndex=$url_idx|RequestMethod=$http_method|
Subject=$subject|DeviceGroupHierarchyL1=$dg_hier_level_1|
DeviceGroupHierarchyL2=$dg_hier_level_2|DeviceGroupHierarchyL3=$dg_hier_level_3|
DeviceGroupHierarchyL4=$dg_hier_level_4|vSrcName=$vsys_name|
DeviceName=$device_name|SrcUUID=$src_uuid|DstUUID=$dst_uuid|TunnelID=$tunnelid|
MonitorTag=$monitortag|ParentSessionID=$parent_session_id|
ParentStartTime=$parent_start_time|TunnelType=$tunnel|ThreatCategory=$thr_category|
ContentVer=$contentver
PAN-OS 10.0
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$threatid|x7C|
ProfileToken=$actionflags|TimeReceived=$receive_time|DeviceSN=$serial|cat=$type|
SubType=$subtype|ConfigVersion=$sender_sw_version|src=$src|dst=$dst|Rule=$rule|
usrName=$srcuser|Application=$app|VirtualLocation=$vsys|FromZone=$from|ToZone=$to|
InboundInterface=$inbound_if|OutboundInterface=$outbound_if|LogSetting=$logset|
SessionID=$sessionid|RepeatCount=$repeatcnt|srcPort=$sport|dstPort=$dport|
srcPostNATPort=$natsport|dstPostNATPort=$natdport|proto=$proto|Action=$action|
FileName=$misc|VendorSeverity=$severity|DirectionOfAttack=$direction|
SequenceNo=$seqno|SourceLocation=$srcloc|DestinationLocation=$dstloc|
PacketID=$pcap_id|FileHash=$filedigest|ApplianceOrCloud=$cloud|URLCounter=$url_idx|
FileType=$filetype|SenderEmail=$sender|EmailSubject=$subject|RecipientEmail=$recipient|
ReportID=$reportid|DGHierarchyLevel1=$dg_hier_level_1|
DGHierarchyLevel2=$dg_hier_level_2|DGHierarchyLevel3=$dg_hier_level_3|
DGHierarchyLevel4=$dg_hier_level_4|VirtualSystemName=$vsys_name|
DeviceName=$device_name|SourceUUID=$src_uuid|DestinationUUID=$dst_uuid|IMSI=$imsi|
IMEI=$imei|ParentSessionID=$parent_session_id|ParentStarttime=$parent_start_time|
Tunnel=$tunnel|ThreatCategory=$thr_category|ContentVersion=$contentver|
SigFlags=$sig_flags|RuleUUID=$rule_uuid|HTTP2Connection=$http2_connection|
DynamicUserGroupName=$dynusergroup_name|X-Forwarded-ForIP=$xff_ip|
8
SourceDeviceCategory=$src_category|SourceDeviceProfile=$src_profile|
SourceDeviceModel=$src_model|SourceDeviceVendor=$src_vendor|
SourceDeviceOSFamily=$src_osfamily|SourceDeviceOSVersion=$src_osversion|
v6SourceDeviceHost=$src_host|SourceDeviceMac=$src_mac|
DestinationDeviceCategory=$dst_category|DestinationDeviceProfile=$dst_profile|
DestinationDeviceModel=$dst_model|DestinationDeviceVendor=$dst_vendor|
DestinationDeviceOSFamily=$dst_osfamily|DestinationDeviceOSVersion=$dst_osversion|
DestinationDeviceHost=$dst_host|DestinationDeviceMac=$dst_mac|
ContainerID=$container_id|ContainerNameSpace=$pod_namespace|
ContainerName=$pod_name|SourceEDL=$src_edl|DestinationEDL=$dst_edl|HostID=$hostid|
EndpointSerialNumber=$serialnumber|DomainEDL=$domain_edl|
SourceDynamicAddressGroup=$src_dag|DestinationDynamicAddressGroup=$dst_dag|
PartialHash=$partial_hash|TimeGeneratedHighResolution=$high_res_timestamp|
NSSAINetworkSliceType=$nssai_sst|devTimeFormat=$cef-formatted-time_generated
e) Click Traffic, copy one of the following texts applicable to the version you are using, and
paste it in the Traffic Log Format field for the Traffic log type. If your version is not listed,
omit this step.
9
RepeatCount=$repeatcnt|srcPort=$sport|dstPort=$dport|srcPostNATPort=$natsport|
dstPostNATPort=$natdport|Flags=$flags|proto=$proto|action=$action|totalBytes=$bytes|
dstBytes=$bytes_received|srcBytes=$bytes_sent|totalPackets=$packets|StartTime=$start|
ElapsedTime=$elapsed|URLCategory=$category|sequence=$seqno|
ActionFlags=$actionflags|SourceLocation=$srcloc|DestinationLocation=$dstloc|
dstPackets=$pkts_received|srcPackets=$pkts_sent|
SessionEndReason=$session_end_reason|DeviceGroupHierarchyL1=$dg_hier_level_1|
DeviceGroupHierarchyL2=$dg_hier_level_2|DeviceGroupHierarchyL3=$dg_hier_level_3|
DeviceGroupHierarchyL4=$dg_hier_level_4|vSrcName=$vsys_name|
DeviceName=$device_name|ActionSource=$action_source
PAN-OS 8.0 - 9.1
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$action|x7C|
cat=$type|ReceiveTime=$receive_time|SerialNumber=$serial|Type=$type|
Subtype=$subtype|devTime=$cef-formatted-receive_time|src=$src|dst=$dst|
srcPostNAT=$natsrc|dstPostNAT=$natdst|RuleName=$rule|usrName=$srcuser|
SourceUser=$srcuser|DestinationUser=$dstuser|Application=$app|VirtualSystem=$vsys|
SourceZone=$from|DestinationZone=$to|IngressInterface=$inbound_if|
EgressInterface=$outbound_if|LogForwardingProfile=$logset|SessionID=$sessionid|
RepeatCount=$repeatcnt|srcPort=$sport|dstPort=$dport|srcPostNATPort=$natsport|
dstPostNATPort=$natdport|Flags=$flags|proto=$proto|action=$action|totalBytes=$bytes|
dstBytes=$bytes_received|srcBytes=$bytes_sent|totalPackets=$packets|StartTime=$start|
ElapsedTime=$elapsed|URLCategory=$category|sequence=$seqno|
ActionFlags=$actionflags|SourceLocation=$srcloc|DestinationLocation=$dstloc|
dstPackets=$pkts_received|srcPackets=$pkts_sent|
SessionEndReason=$session_end_reason|DeviceGroupHierarchyL1=$dg_hier_level_1|
DeviceGroupHierarchyL2=$dg_hier_level_2|DeviceGroupHierarchyL3=$dg_hier_level_3|
DeviceGroupHierarchyL4=$dg_hier_level_4|vSrcName=$vsys_name|
DeviceName=$device_name|ActionSource=$action_source|SrcUUID=$src_uuid|
DstUUID=$dst_uuid|TunnelID=$tunnelid|MonitorTag=$monitortag|
ParentSessionID=$parent_session_id|ParentStartTime=$parent_start_time|
TunnelType=$tunnel
PAN-OS 10.0
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$action|x7C|
ProfileToken=$actionflags|TimeReceived=$receive_time|DeviceSN=$serial|cat=$type|
SubType=$subtype|ConfigVersion=$sender_sw_version|devTime=$cef-formatted-
receive_time|src=$src|dst=$dst|srcPostNAT=$natsrc|dstPostNAT=$natdst|Rule=$rule|
usrName=$srcuser|DestinationUser=$dstuser|Application=$app|VirtualLocation=$vsys|
10
FromZone=$from|ToZone=$to|InboundInterface=$inbound_if|
OutboundInterface=$outbound_if|LogSetting=$logset|SessionID=$sessionid|
RepeatCount=$repeatcnt|srcPort=$sport|dstPort=$dport|srcPostNATPort=$natsport|
dstPostNATPort=$natdport|proto=$proto|Bytes=$bytes|srcBytes=$bytes_sent|
dstBytes=$bytes_received|totalPackets=$packets|SessionStartTime=$start|
SessionDuration=$elapsed|URLCategory=$category|SequenceNo=$seqno|
SourceLocation=$srcloc|DestinationLocation=$dstloc|srcPackets=$pkts_sent|
dstPackets=$pkts_received|SessionEndReason=$session_end_reason|
DGHierarchyLevel1=$dg_hier_level_1|DGHierarchyLevel2=$dg_hier_level_2|
DGHierarchyLevel3=$dg_hier_level_3|DGHierarchyLevel4=$dg_hier_level_4|
VirtualSystemName=$vsys_name|DeviceName=$device_name|
ActionSource=$action_source|SourceUUID=$src_uuid|DestinationUUID=$dst_uuid|
IMSI=$imsi|IMEI=$imei|ParentSessionID=$parent_session_id|
ParentStarttime=$parent_start_time|Tunnel=$tunnel|EndpointAssociationID=$assoc_id|
ChunksTotal=$chunks|ChunksSent=$chunks_sent|ChunksReceived=$chunks_received|
RuleUUID=$rule_uuid|HTTP2Connection=$http2_connection|
LinkChangeCount=$link_change_count|SDWANPolicyName=$sdwan_ec_applied|
LinkSwitches=$link_switches|SDWANCluster=$sdwan_cluster|
SDWANDeviceType=$sdwan_device_type|SDWANClusterType=$sdwan_cluster_type|
SDWANSite=$sdwan_site|DynamicUserGroupName=$dynusergroup_name|X-Forwarded-
ForIP=$xff_ip|SourceDeviceCategory=$src_category|SourceDeviceProfile=$src_profile|
SourceDeviceModel=$src_model|SourceDeviceVendor=$src_vendor|
SourceDeviceOSFamily=$src_osfamily|SourceDeviceOSVersion=$src_osversion|
SourceDeviceHost=$src_host|SourceDeviceMac=$src_mac|
DestinationDeviceCategory=$dst_category|DestinationDeviceProfile=$dst_profile|
DestinationDeviceModel=$dst_model|DestinationDeviceVendor=$dst_vendor|
DestinationDeviceOSFamily=$dst_osfamily|DestinationDeviceOSVersion=$dst_osversion|
DestinationDeviceHost=$dst_host|DestinationDeviceMac=$dst_mac|
ContainerID=$container_id|ContainerNameSpace=$pod_namespace|
ContainerName=$pod_name|SourceEDL=$src_edl|DestinationEDL=$dst_edl|
GPHostID=$hostid|EndpointSerialNumber=$serialnumber|
SourceDynamicAddressGroup=$src_dag|DestinationDynamicAddressGroup=$dst_dag|
HASessionOwner=$session_owner|TimeGeneratedHighResolution=$high_res_timestamp|
NSSAINetworkSliceType=$nssai_sst|NSSAINetworkSliceDifferentiator=$nssai_sd|
devTimeFormat=$cef-formatted-time_generated
11
f) If you are using versions other than PAN-OS 3.0 - 6.1, click HIP Match, copy one of the
following texts applicable to the version you are using, and paste it in the HIP Match Log
Format field for the HIP Match log type.
PAN-OS 7.1
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$matchname|
x7C|ReceiveTime=$receive_time|SerialNumber=$serial|cat=$type|Subtype=$subtype|
devTime=$cef-formatted-receive_time|usrName=$srcuser|VirtualSystem=$vsys|
identHostName=$machinename|OS=$os|identSrc=$src|HIP=$matchname|
RepeatCount=$repeatcnt|HIPType=$matchtype|sequence=$seqno|
ActionFlags=$actionflags|DeviceGroupHierarchyL1=$dg_hier_level_1|
DeviceGroupHierarchyL2=$dg_hier_level_2|DeviceGroupHierarchyL3=$dg_hier_level_3|
DeviceGroupHierarchyL4=$dg_hier_level_4|vSrcName=$vsys_name|
DeviceName=$device_name
PAN-OS 8.0 - 9.1
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$matchname|
x7C|ReceiveTime=$receive_time|SerialNumber=$serial|cat=$type|Subtype=$subtype|
devTime=$cef-formatted-receive_time|usrName=$srcuser|VirtualSystem=$vsys|
identHostName=$machinename|OS=$os|identsrc=$src|HIP=$matchname|
RepeatCount=$repeatcnt|HIPType=$matchtype|sequence=$seqno|
ActionFlags=$actionflags|DeviceGroupHierarchyL1=$dg_hier_level_1|
DeviceGroupHierarchyL2=$dg_hier_level_2|DeviceGroupHierarchyL3=$dg_hier_level_3|
DeviceGroupHierarchyL4=$dg_hier_level_4|vSrcName=$vsys_name|
DeviceName=$device_name|VirtualSystemID=$vsys_id|srcipv6=$srcipv6|startTime=$cef-
formatted-time_generated
PAN-OS 10.2
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$matchname|
x7C|ProfileToken=$actionflags|TimeReceived=$receive_time|DeviceSN=$serial|cat=$type|
SubType=$subtype|ConfigVersion=$sender_sw_version|devTime=$cef-formatted-
receive_time|usrName=$srcuser|VirtualLocation=$vsys|identHostName=$machinename|
EndpointOSType=$os|iOSsrc=$src|CountOfRepeats=$repeatcnt|SequenceNo=$seqno|
DGHierarchyLevel1=$dg_hier_level_1|DGHierarchyLevel2=$dg_hier_level_2|
DGHierarchyLevel3=$dg_hier_level_3|DGHierarchyLevel4=$dg_hier_level_4|
VirtualSystemName=$vsys_name|DeviceName=$device_name|VirtualSystemID=$vsys_id|
SourceIPv6=$srcipv6|HostID=$hostid|EndpointSerialNumber=$serialnumber|
SourceDeviceCategory=$reclassified|SourceDeviceModel=$matchtype|
SourceDeviceMac=$mac|TimestampDeviceIdentification=$time_generated|
12
TimeGeneratedHighResolution=$high_res_timestamp|devTimeFormat=$cef-formatted-
time_generated
g) Copy one of the following texts applicable to the version you are using and paste it in the
Custom Format column for the log type. If you are using PAN-OS 8.0 - 9.1, copy and paste
the text for the URL Filtering log type. If you are using PAN-OS 10.0, copy and paste the
text for the URL log type. If your version is not listed, omit this step.
13
dstPostNATPort=$natdport|proto=$proto|Action=$action|URL=$file_url|
VendorSeverity=$severity|DirectionOfAttack=$direction|SequenceNo=$seqno|
SourceLocation=$srcloc|DestinationLocation=$dstloc|ContentType=$contenttype|
PacketID=$pcap_id|URLCounter=$url_idx|UserAgent=$user_agent|identSrc=$xff|
Referer=$referer|DGHierarchyLevel1=$dg_hier_level_1|DGHierarchyLevel2=$dg_hier_level_2|
DGHierarchyLevel3=$dg_hier_level_3|DGHierarchyLevel4=$dg_hier_level_4|
VirtualSystemName=$vsys_name|DeviceName=$device_name|SourceUUID=$src_uuid|
DestinationUUID=$dst_uuid|HTTPMethod=$http_method|IMSI=$imsi|IMEI=$imei|
ParentSessionID=$parent_session_id|ParentStarttime=$parent_start_time|
Tunnel=$tunnelid|ContentVersion=$contentver|SigFlags=$sig_flags|
HTTPHeaders=$http_headers|URLCategoryList=$url_category_list|RuleUUID=$rule_uuid|
HTTP2Connection=$http2_connection|DynamicUserGroupName=$dynusergroup_name|X-
Forwarded-ForIP=$xff_ip|SourceDeviceCategory=$src_category|
SourceDeviceProfile=$src_profile|SourceDeviceModel=$src_model|
SourceDeviceVendor=$src_vendor|SourceDeviceOSFamily=$src_osfamily|
SourceDeviceOSVersion=$src_osversion|SourceDeviceHost=$src_host|
SourceDeviceMac=$src_mac|DestinationDeviceCategory=$dst_category|
DestinationDeviceProfile=$dst_profile|DestinationDeviceModel=$dst_model|
DestinationDeviceVendor=$dst_vendor|DestinationDeviceOSFamily=$dst_osfamily|
DestinationDeviceOSVersion=$dst_osversion|DestinationDeviceHost=$dst_host|
DestinationDeviceMac=$dst_mac|ContainerID=$container_id|
ContainerNameSpace=$pod_namespace|ContainerName=$pod_name|SourceEDL=$src_edl|
DestinationEDL=$dst_edl|HostID=$hostid|EndpointSerialNumber=$serialnumber|
SourceDynamicAddressGroup=$src_dag|DestinationDynamicAddressGroup=$dst_dag|
TimeGeneratedHighResolution=$high_res_timestamp|NSSAINetworkSliceType=$nssai_sst|
devTimeFormat=$cef-formatted-time_generated
14
h) If you are using PAN-OS 8.0 - 9.1, copy the following text and paste it in the Custom Format
column for the Datalog type.
15
i) Copy one of the following texts applicable to the version you are using and paste it in the
Custom Format column for the WildFire log type. If your version is not listed, omit this
step.
16
SourceLocation=$srcloc|DestinationLocation=$dstloc|PacketID=$pcap_id|
FileHash=$filedigest|ApplianceOrCloud=$cloud
j) Copy one of the following texts applicable to the version you are using and paste it in the
Custom Format column for the Authentication log type. If your version is not listed, omit
this step.
17
18
k) Copy one of the following texts applicable to the version you are using and paste it in the
Custom Format column for the User-ID log type. If your version is not listed, omit this step.
19
l) Copy one of the following texts applicable to the version you are using and paste it in the
Custom Format column for the log type. If you are using PAN-OS 8.0 - 9.1, copy and paste
the text for the Tunnel Inspection log type. If you are using PAN-OS 10.0, copy and paste
the text for the Tunnel log type. If your version is not listed, omit this step.
20
DGHierarchyLevel4=$dg_hier_level_4|VirtualSystemName=$vsys_name|
DeviceName=$device_name|ParentSessionID=$parent_session_id|
ParentStarttime=$parent_start_time|Tunnel=$tunnel|Bytes=$bytes|srcBytes=$bytes_sent|
dstBytes=$bytes_received|totalPackets=$packets|srcPackets=$pkts_sent|
dstPackets=$pkts_received|TunnelSessionsCreated=$sessions_created|
TunnelSessionsClosed=$sessions_closed|SessionEndReason=$session_end_reason|
ActionSource=$action_source|startTime=$start|SessionDuration=$elapsed|
RuleUUID=$rule_uuid|DynamicUserGroupName=$dynusergroup_name|
ContainerID=$container_id|ContainerNameSpace=$pod_namespace|
ContainerName=$pod_name|SourceEDL=$src_edl|DestinationEDL=$dst_edl|
SourceDynamicAddressGroup=$src_dag|DestinationDynamicAddressGroup=dst_dag|
TimeGeneratedHighResolution=$high_res_timestamp|
NSSAINetworkSliceDifferentiator=$nssai_sd|NSSAINetworkSliceType=$nssai_sst|
ProtocolDataUnitsessionID=$pdu_session_id|devTimeFormat=$cef-formatted-
time_generated
m) If you are using PAN-OS 8.0 - 9.1, copy the following text and paste it in the Custom Format
column for the Correlation log type.
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|8.0|$category|
ReceiveTime=$receive_time|x7C|SerialNumber=$serial|cat=$type|devTime=$cef-formatted-
receive_time|startTime=$cef-formatted-time_generated|Severity=$severity|
VirtualSystem=$vsys|VirtualSystemID=$vsys_id|src=$src|SourceUser=$srcuser|
msg=$evidence|DeviceGroupHierarchyL1=$dg_hier_level_1|
DeviceGroupHierarchyL2=$dg_hier_level_2|DeviceGroupHierarchyL3=$dg_hier_level_3|
DeviceGroupHierarchyL4=$dg_hier_level_4|vSrcName=$vsys_name|
DeviceName=$device_name|ObjectName=$object_name|ObjectID=$object_id
21
n) If you are using PAN-OS 8.1 - 9.1, copy the following text, and paste it in the Custom Format
column for the SCTP log type.
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$action|x7C|
ReceiveTime=$receive_time|SerialNumber=$serial|cat=$type|genTime=$time_generated|
src=$src|dst=$dst|VirtualSystem=$vsys|SourceZone=$from|DestinationZone=$to|
IngressInterface=$inbound_if|EgressInterface=$outbound_if|SessionID=$sessionid|
RepeatCount=$repeatcnt|srcPort=$sport|dstPort=$dport|proto=$proto|action=$action|
DeviceGroupHierarchyL1=$dg_hier_level_1|DeviceGroupHierarchyL2=$dg_hier_level_2|
DeviceGroupHierarchyL3=$dg_hier_level_3|DeviceGroupHierarchyL4=$dg_hier_level_4|
vsysName=$vsys_name|DeviceName=$device_name|sequence=$seqno|AssocID=$assoc_id|
PayloadProtoID=$ppid|sev=$num_of_severity|SCTPChunkType=$sctp_chunk_type|
SCTPVerTag1=$verif_tag_1|SCTPVerTag2=$verif_tag_2|
SCTPCauseCode=$sctp_cause_code|DiamAppID=$diam_app_id|
DiamCmdCode=$diam_cmd_code|DiamAVPCode=$diam_avp_code|
SCTPStreamID=$stream_id|SCTPAssEndReason=$assoc_end_reason|OpCode=$op_code|
CPSSN=$sccp_calling_ssn|CPGlobalTitle=$sccp_calling_gt|SCTPFilter=$sctp_filter|
SCTPChunks=$chunks|SrcSCTPChunks=$chunks_sent|DstSCTPChunks=$chunks_received|
Packets=$packets|srcPackets=$pkts_sent|dstPackets=$pkts_received
22
o) Copy one of the following texts applicable to the version you are using and paste it in the
Custom Format column for the IP-Tag log type. If your version is not listed, omit this step.
PAN-OS 9.x
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$event_id|x7C|
cat=$type|devTime=$cef-formatted-receive_time|ReceiveTime=$receive_time|
SerialNumber=$serial|Subtype=$subtype|GenerateTime=$time_generated|
VirtualSystem=$vsys|src=$ip|TagName=$tag_name|EventID=$eventid|
RepeatCount=$repeatcnt|TimeoutThreshold=$timeout|
DataSourceName=$datasourcename|DataSource=$datasource_type|
DataSourceType=$datasource_subtype|sequence=$seqno|ActionFlags=$actionflags|
DeviceGroupHierarchyL1=$dg_hier_level_1|DeviceGroupHierarchyL2=$dg_hier_level_2|
DeviceGroupHierarchyL3=$dg_hier_level_3|DeviceGroupHierarchyL4=$dg_hier_level_4|
vSrcName=$vsys_name|DeviceName=$device_name|VirtualSystemID=$vsys_id
PAN-OS 10.2
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$event_id|x7C|
ProfileToken=$actionflags|TimeReceived=$receive_time|DeviceSN=$serial|cat=$type|
SubType=$subtype|ConfigVersion=$sender_sw_version|devTime=$cef-formatted-
receive_time|VirtualLocation=$vsys|src=$ip|TagName=$tag_name|
CountOfRepeats=$repeatcnt|MappingTimeout=$timeout|
MappingDataSource=$datasourcename|MappingDataSourceType=$datasource_type|
MappingDataSourceSubType=$datasource_subtype|SequenceNo=$seqno|
DGHierarchyLevel1=$dg_hier_level_1|DGHierarchyLevel2=$dg_hier_level_2|
DGHierarchyLevel3=$dg_hier_level_3|DGHierarchyLevel4=$dg_hier_level_4|
VirtualSystemName=$vsys_name|DeviceName=$device_name|VirtualSystemID=$vsys_id|
IPSubnetRange=$ip_subnet_range|TimeGeneratedHighResolution=$high_res_timestamp|
devTimeFormat=$cef-formatted-time_generated
23
p) If you are using PAN-OS 10.2, copy the following text, and paste it in the Custom Format
column for the GlobalProtect log type.
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$eventid|x7C|
TimeReceived=$receive_time|DeviceSN=$serial|cat=$type|SubType=$subtype|
ConfigVersion=$sender_sw_version|devTime=$cef-formatted-receive_time|
VirtualSystem=$vsys|Stage=$stage|AuthMethod=$auth_method|TunnelType=$tunnel_type|
usrName=$srcuser|SourceRegion=$srcregion|EndpointDeviceName=$machinename|
PublicIPv4=$public_ip|PublicIPv6=$public_ipv6|PrivateIPv4=$private_ip|
PrivateIPv6=$private_ipv6|HostID=$hostid|EndpointSN=$serialnumber|
GlobalProtectClientVersion=$client_ver|EndpointOSType=$client_os|
EndpointOSVersion=$client_os_ver|CountOfRepeats=$repeatcnt|
QuarantineReason=$reason|ConnectionError=$error|Description=$opaque|
EventStatus=$status|GlobalProtectGatewayLocation=$location|
LoginDuration=$login_duration|ConnectionMethod=$connect_method|
ConnectionErrorID=$error_code|Portal=$portal|SequenceNo=$seqno|
TimeGeneratedHighResolution=$high_res_timestamp|
GatewaySelectionType=$selection_type|SSLResponseTime=$response_time|
GatewayPriority=$priority|AttemptedGateways=$attempted_gateways|Gateway=$gateway|
DGHierarchyLevel1=$dg_hier_level_1|DGHierarchyLevel2=$dg_hier_level_2|
DGHierarchyLevel3=$dg_hier_level_3|DGHierarchyLevel4=$dg_hier_level_4|
VirtualSystemName=$vsys_name|DeviceName=$device_name|VirtualSystemID=$vsys_id|
devTimeFormat=$cef-formatted-time_generated
24
q) If you are using PAN-OS 10.2, copy the following text, and paste it in the Custom Format
column for the Decryption log type.
25
r) If you are using PAN-OS 10.0, copy the following text, and paste it in the Custom Format
column for the File Data log type.
LEEF:2.0|Palo Alto Networks|PAN-OS Syslog Integration|$sender_sw_version|$action|x7C|
ProfileToken=$actionflags|TimeReceived=$receive_time|DeviceSN=$serial|cat=$type|
SubType=$subtype|ConfigVersion=$sender_sw_version|devTime=$cef-formatted-
receive_time|src=$src|dst=$dst|srcPostNAT=$natsrc|dstPostNAT=$natdst|Rule=$rule|
usrName=$srcuser|DestinationUser=$dstuser|Application=$app|VirtualLocation=$vsys|
FromZone=$from|ToZone=$to|InboundInterface=$inbound_if|
OutboundInterface=$outbound_if|LogSetting=$logset|SessionID=$sessionid|
RepeatCount=$repeatcnt|srcPort=$sport|dstPort=$dport|srcPostNATPort=$natsport|
dstPostNATPort=$natdport|proto=$proto|Bytes=$bytes|srcBytes=$bytes_sent|
dstBytes=$bytes_received|totalPackets=$packets|SessionStartTime=$start|
SessionDuration=$elapsed|URLCategory=$category|SequenceNo=$seqno|
SourceLocation=$srcloc|DestinationLocation=$dstloc|srcPackets=pkts_sent|
dstPackets=$pkts_received|SessionEndReason=$session_end_reason|
DGHierarchyLevel1=$dg_hier_level_1|DGHierarchyLevel2=$dg_hier_level_2|
DGHierarchyLevel3=$dg_hier_level_3|DGHierarchyLevel4=$dg_hier_level_4|
VirtualSystemName=$vsys_name|DeviceName=$device_name|
ActionSource=$action_source|SourceUUID=$src_uuid|DestinationUUID=$dst_uuid|
IMSI=$imsi|IMEI=$imei|ParentSessionID=$parent_session_id|
ParentStarttime=parent_start_time|Tunnel=$tunnel|EndpointAssociationID=-$assoc_id|
ChunksTotal=$chunks|ChunksSent=$chunks_sent|ChunksReceived=$chunks_received|
RuleUUID=$rule_uuid|HTTP2Connection=$http2_connection|
LinkChangeCount=$link_change_count|SDWANPolicyName=$sdwan_ec_applied|
LinkSwitches=$link_switches|SDWANCluster=$sdwan_cluster|
SDWANDeviceType=$sdwan_device_type|SDWANClusterType=$sdwan_cluster_type|
SDWANSite=$sdwan_site|DynamicUserGroupName=$dynusergroup_name|X-Forwarded-
ForIP=$xff_ip|SourceDeviceCategory=$src_category|SourceDeviceProfile=$src_profile|
SourceDeviceModel=$src_model|SourceDeviceVendor=$src_vendor|
SourceDeviceOSFamily=$src_osfamily|SourceDeviceOSVersion=$src_osversion|
SourceDeviceHost=$src_host|SourceDeviceMac=$src_mac|
DestinationDeviceCategory=$dst_category|DestinationDeviceProfile=$dst_profile|
DestinationDeviceModel=$dst_model|DestinationDeviceVendor=$dst_vendor|
DestinationDeviceOSFamily=$dst_osfamily|DestinationDeviceOSVersion=$dst_osversion|
DestinationDeviceHost=$dst_host|DestinationDeviceMac=$dst_mac|
ContainerID=$container_id|ContainerNameSpace=$pod_namespace|
ContainerName=$pod_name|SourceEDL=$src_edl|DestinationEDL=$dst_edl|
26
GPHostID=$hostid|EndpointSerialNumber=$serialnumber|
SourceDynamicAddressGroup=$src_dag|DestinationDynamicAddressGroup=$dst_dag|
HASessionOwner=$session_owner|TimeGeneratedHighResolution=$high_res_timestamp|
NSSAINetworkSliceType=$nssai_sst|NSSAINetworkSliceDifferentiator=$nssai_sd|
devTimeFormat=$cef-formatted-time_generated
5. Click OK.
6. To specify the severity of events that are contained in the Syslog messages, click Log Settings.
a) For each severity that you want to include in the Syslog message, click the Severity name
and select the Syslog destination from the Syslog menu.
b) Click OK.
7. Click Commit.
27