-
Notifications
You must be signed in to change notification settings - Fork 24
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
PaloAlto Netflow #27
Comments
I don't have time to address it well here now, but based on experience (and memory, which may fail me) with this plugin this year here are a few things to review. I'm planning to rewrite a version of this plugin to clean, document and fix a few other issues. But that is planned for early January. First go look in your /var/log/td-agent/td-agent.log file
The other option which may or may not work, is to replace line 371 in parser_netflow.rb Please let us know if either of these fixes works. |
Hello, Thanks for you reply ! Now It's OK, i just add the missing fields in template, thank you : 148:
(the firewallEvent always blank !!!), but the plugin handle PaloAlto Netflow now Thx ! But, one last problem is to add 3 others fields from another template (Template ID 257 instead of 256) : 346:
Is the plugin able to handle this case please ? Thanks for your help. |
I didn't write the plugin, but my understanding is that all fields are stored in the same file, no matter which template they come with, so you'd have to add them to this file. To change this may require significant rewrite to the plugin. Higher numbers are left open to each manufacturer, so if you have different devices reporting, you may encounter the same # with different meaning. You'd likely need to treat it within the fluentd config (or another custom plugin). I'll post back on this thread when I have my own plugin written (I have written a few simple ones for my own use) and tested (I have some pcap files from different devices to test it out, but more tests or test files would be welcome). |
I'm not familiar with PaloAlto firewall, so I don't know the differences between PaloAlto and other devices:
netflow_fields.yaml edit.
|
Hello, Thank you all for your replies ! I've tried to had those 3 fields in the template file or in a definition file, the parsing seems correct, no more error message, but the 3 fields in not indexed in ES ??? Is the plugin able to manage 2 templates, the standard template (256) and the Enterprise template (257), Palo Alto privateEnterpriseNumber is 25461, and merge the results please ? Thanks for your help. 346:
|
Hello, I've updated to the last version and change 2 fields type and now everything is ok with app_id and user-id ! Hereis the template :
Thanks for your replies and for this useful plugin. Happy new year :) |
Good to hear! |
Hi, I am facing the same issue with Fortigate Firewalls. Here is the log of the
FYI, I used the template file that @mareban posted. I appreciate any help. |
Hello,
Does someone are able to use this plugin with PaloAlto Firewall please ?
I have no problem with Cisco or software netflow exporters :) !
Thanks for your help.
https://live.paloaltonetworks.com/twzvq79624/attachments/twzvq79624/documentation_tkb/140/1/Netflow-Fields-5.0-RevA.pdf
The text was updated successfully, but these errors were encountered: