Prisma SD-WAN will now generate Syslog messages on initial flow-rule classification and
end-of-flow for all flows handled by the ION device.
Generate Syslog messages on initial flow-rule
classification and end-of-flow for all flows handled by the ION
device. These Syslog messages are in RFC 5424 format. You may configure
to export flow logs from an ION device to one or more Syslog servers.
<13>1 2020-01-28T23:46:17.000035+00:00 ION-BRANCH-01 cgxFlowLogV1 13593 - - 2020-01-28T23:46:17,192.0.2.10,52520,198.51.100.10,80,tcp,,,0,0,0,0,,WAN-PRIMARY,1234567890123456,enterprise-http,New Flow,Allow-All:allow:1
The above Syslog message has a header and a body. The Syslog
message values populated for the header and the body are:
| Syslog Message Header | Header Component Sample Values |
| Syslog export time in UTC | 2020-01-28T23:46:17.000035+00:00 |
| Element device name | ION-BRANCH-01 |
| App name to identify flow event logs | cgxFlowLogV1 |
| Process id of log generator | 13593 |
| Message id (empty) | Message id field is not populated by the
ION device at this time. |
| Structured data (empty) | Structured data field is not populated by
the ION device at this time. |
| Syslog Message Body | Syslog Message Sample Body |
| Flow event log in CSV format |
2020-01-28T23:46:17,192.0.2.10,52520,198.51.100.10,80,tcp,,,0,0,0,0,,WAN-PRIMARY,1234567890123456,enterprise-http,New Flow,Allow-All:allow:1
|
Syslog message body shown above in CSV format can be interpreted
as:
| Headers | Sample Values |
| Time event happened | 2020-01-28T23:46:17 |
| zbfw classification rules | Allow-All:self:unknown:allow:1 |