Why forwarded GlobalProtect logs are not displayed in correct CEF format on Syslog server?
2694
Created On 01/11/23 09:06 AM - Last Modified 03/08/24 22:05 PM
Question
Why forwarded GlobalProtect logs to Syslog server are not displayed in the correct CEF format like other log types (Traffic, Threat,..)?
Environment
- Firewalls appliances.
- Panorama appliances.
- PAN-OS 10.0.0+
Answer
- GlobalProtect log format has different fields ordering, and some fields don't exist such as severity.
- Reorder the fields in the GlobalProtect CEF log format to match the columns’ configured under the Syslog server.
Additional Information
- Globalprotect CEF Fields
- Forward GlobalProtect Logs to an External Service in PAN-OS
- What is the official custom log format to forward GP logs to LEEF?