PaloAltoNetworks/Splunk_TA_paloalto

Question: Userid logs not consistent

Closed this issue · 2 comments

Would it be appropriate to have our Palo guys submit a support ticket about the log format of the userid logs. The "Generated Time" field is in a different location than the rest of the log types. Userid has it in the 9th field whereas everything else is in the 7th field.

Thanks!

Hi, yes please open a support ticket on this and send the ticket ID to splunkapp@paloaltonetworks.com. Thanks!

Bug PAN-96490 was opened on this. PAN-OS syslog fields for auth logs will be corrected in the next release. Closing this issue for now but let me know if you have any questions.