panos-parser(): parsing PAN-OS log messages
The PAN-OS (a short version of Palo Alto Networks Operating System) parser can parse log messages originating from Palo Alto Networks devices. Even though these messages completely comply to the RFC standards, their MESSAGE part is not a plain text. Instead, the MESSAGE part contains a data structure that requires additional parsing.
The panos-parser() of AxoSyslog solves this problem, and can separate PAN-OS log messages to name-value pairs. For details on using value-pairs in AxoSyslog, see Structuring macros, metadata, and other value-pairs.
Prerequisites
-
Version 3.29 of AxoSyslog or later.
-
Install the
axosyslog-sclpackage on Debian/Ubuntu. On RHEL and compatible distributions, the SCL files are part of theaxosyslogbase package.Your configuration must also contain
@include "scl.conf", which the default configuration file already does. If the SCL files are missing, AxoSyslog fails to start with anunexpected LL_IDENTIFIERerror.Terminal window @include "scl.conf"The
panos-parser()driver is a reusable configuration snippet (SCL). For details on using or writing such configuration snippets, see Reusing configuration blocks. You can find its source in scl/paloalto/panos.conf on GitHub. -
PAN-OS log messages from Palo Alto Networks devices.
Limitations
The panos-parser() only works on AxoSyslog version 3.29 or later.
Configuration
You can include the panos-parser() in your AxoSyslog configuration like this:
parser p_parser{
panos-parser();
};