pemontto / Palo-Alto-CEF

Plaintext CEF format strings for Palo Alto Firewalls

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Decryption CEF format is too long

MReprogle1 opened this issue · comments

Decryption CEF format is too long

@MReprogle1 can you provide some detail?

Sorry, I thought I had a description of my issue in there.

So, with v10 of PAN-OS, they started to limit CEF logs to a max of 2048 characters, so when you attempt to copy/paste the contents, it throws an error when you try to save the configuration:

Sentinel -> format -> decryption can be at most 2048 characters, but current length: 2688 value: CEF:0|Palo Alto Networks|PAN-OS|$sender_sw_version|$type|$subtype|rt=$receive_ti... Sentinel -> format -> decryption is invalid

This occurs when attempting to save the Decryption as well as the URL CEF log contents.

Hello,

This is an issue Palo Alto made with themselves , they know about it, its even mentioned in the PDF - KB HERE

Basically you cannot just copypaste, you must trim it to 2048 by removing fields you dont need. Or you can use the 9.1 ones which works.

HTH

@Atroskelis thanks for following up! That's is indeed sad state of affairs...