: UserID Syslog Default Field Order
Focus
Focus

UserID Syslog Default Field Order

Table of Contents

UserID Syslog Default Field Order

Example UserID log in Syslog:
Oct 13 01:23:58 gke-standard-cluster-2-pool-1-6ea9f13a-g2z7 498 <142>1 2020-10-13T01:23:58.167Z stream-logfwd20-156653024-10121421-eq28-harness-16kn logforwarder - panwlogs - 1,​2020-10-13T01:23:50.000000Z,​007051000113358,​USERID,​login,​10.0,​2020-10-13T01:23:34.000000Z,​vsys1,​::c28:7141:ffff:0,​"xxxxx\xxxxx o"xxxxxxxxxx"'"xxxxxxxxxx"test",​fake-data-source-95,​1694498816,​16777216,​-1694302208,​63502,​60246,​server_session_monitor,​exchange_server,​551324,​-9223372036854775808,​0,​0,​0,​0,​,​PA-VM,​1,​xxxxx,​2050-04-13T10:41:35.000000Z,​1,​64,​xxxxxxxxxxxxxx,​,​2020-10-13T01:23:35.350000Z
The following identifies the default field order for filters migrated from an earlier version of the log forwarding application. For log filters created after that migration, you specify the field order when you create a log filter by specifying the columns you want to receive.
The fields are identified in the default order that they appear in each log line.

Recommended For You