Oct 24 2019 04:31 PM
Hello, I was hoping someone can help me with what appears to be incorrect Regex syntax in a configuration file.
I'm trying to connect our Palo Alto logs to Sentinel and i've followed all of the instructions here:
I am receiving syslogs thought rsyslog, the OMS Agent is also receiving logs, however the OMS agent log file shows this:
Oct 24 2019 05:11 PM
Solutiondid you complete all the steps here? https://docs.microsoft.com/en-us/azure/sentinel/connect-paloalto#step-2-forward-palo-alto-networks-l...
This
Oct 24 15:55:45 1,2019/10/24 15:55:45,013201006249,TRAFFIC,start,2049,2019/10/24 15:55:45
does not look like CEF format. in the PAN guides, it shows you to add CEF....blah in the formatting
Oct 25 2019 08:22 AM
Oct 24 2019 05:11 PM
Solutiondid you complete all the steps here? https://docs.microsoft.com/en-us/azure/sentinel/connect-paloalto#step-2-forward-palo-alto-networks-l...
This
Oct 24 15:55:45 1,2019/10/24 15:55:45,013201006249,TRAFFIC,start,2049,2019/10/24 15:55:45
does not look like CEF format. in the PAN guides, it shows you to add CEF....blah in the formatting