The email alerts received for system logs are not in a readable format
Symptom
- Log forwarding configured to forwards logs by email.
- The email received for system logs are not in a readable format.
- Observed Email Format is shown below
domain: 1<br/>receive_time: 2023/07/12 13:00:49<br/>serial: 012001021440<br/>seqno: 7251694860707566441<br/>actionflags: 0x0<br/>type: SYSTEM<br/>subtype: satd<br/>config_ver: 2816<br/>time_generated: 2023/07/12 13:00:50<br/>high_res_timestamp: 2023-07-12T13:00:50.767-07:00<br/>dg_hier_level_1: 0<br/>dg_hier_level_2: 0<br/>dg_hier_level_3: 0<br/>dg_hier_level_4: 0<br/>vsys_name: <br/>device_name: Lab34-170-PA-820<br/>vsys_id: 0<br/>vsys: <br/>eventid: satd-config-p2-success<br/>object: <br/>fmt: 0<br/>id: 0<br/>module 8; general<br/>severity: informational<br/>opaque: SATD daemon configuration load phase-2 succeeded.<br/>dg_id: 0<br/>tpl_id: 0<br/>
- The expected Email Format is displayed below
domain: 1
receive_time: 2023/07/10 20:55:00
serial: 007307000517
seqno: 7216449117831132378
actionflags: 0x0
type: SYSTEM
subtype: general
config_ver: 0
time_generated: 2023/07/10 20:55:00
high_res_timestamp: 2023-07-10T20:55:00.000-07:00
dg_hier_level_1: 0
dg_hier_level_2: 0
dg_hier_level_3: 0
dg_hier_level_4: 0
vsys_name:
device_name: Lab64-176-M-500
vsys_id: 0
vsys:
eventid: general
object:
fmt: 0
id: 0
module: general
severity: informational
opaque: Partial Commit for JobId=2415 by User: admin are: changes to configuration by administrators: admin.Changes to configuration in Panorama.. Enqueue TIme=2023/07/10 20:55:00.
dg_id: 0
tpl_id: 0
Environment
- Palo Alto Firewalls or Panorama
- PAN-OS: 10.1.10, 10.1.10-h1, 10.2.5 and 11.0.x.
- Log forwarding configured.
Cause
The encoded HTML is missed to encode the fields like to, from, cc & reply id's while sending mail from a mail client.
Resolution
- This issue is being addressed under PAN-221126 in PAN-OS versions 11.1.0, 11.0.3, 10.1.11, and 10.2.7.
- As a workaround, configure the custom log format to send the logs by email forwarding. Now the logs will display correctly
GUI: Device > Server Profiles > Email > Custom Log Format > Select Log Type