To facilitate the integration with external log parsing systems, the firewall allows you to
customize the log format; it also allows you to add custom Key: Value
attribute pairs. Custom message formats can be configured under:
(PAN-OS & Panorama)DeviceServer ProfilesSyslogSyslog Server ProfileCustom Log Format.
(Strata Cloud Manager)
ManageConfigurationObjectsSyslogConfigurationNGFW and Prisma AccessObjectsSyslog and Add Syslog to create a new Syslog
server profile or select an existing Syslog server profile.
When
editing the Syslog server profile, select Custom Log
Format to customize the log format forwarded to the syslog
server.
To achieve ArcSight Common Event Format (CEF) compliant log formatting,
refer to the CEF Configuration Guide.