Parser release

Idea ID 2778164

Parser release

0 Votes

Please enable below Fields in upcoming parser as the below are related to Juniper FW which is missing in 7.14.3.

RT_FLOW_SESSION_CREATE_LSRT_FLOW_SESSION_CLOSE_LS

2 Comments
Knowledge Partner Knowledge Partner
Knowledge Partner

Hi I would like to help you out a little,

1) Agent version7.14.0.8241.0 --> 7.15 is out, however still event is not parsed 100%

2) message gets parsed but not 100% --> categorisation is working fine. see your example

 

3) i would open a bug rather an idea:
 - messageid RT_FLOW_SESSION_CLOSE_LS
 - messageid RT_FLOW_SESSION_CREATE_LS

are genrally supported, see working categorisation.

 

update:

- which juniper os do you run on?
- do you use white_space somewhere in any  rule/zone names?
 - - "Autenticacion-DomainControllers-IOMDC Vlan_477 Vlan_300" 

 

 

https://apps.juniper.net/syslog-explorer/#msg=RT_FLOW_SESSION_CREATE_LS&sw=Junos%20OS&rel=20.1R1 shows below format
which differs from your format as  "... Autenticacion-DomainControllers-IOMDC Vlan_477..." Vlan_477 should be just a "session-id-32 "-number...

wonder why this is happening in your config.

 

 

 

 

Lsys logical-system-name: session created source-address/source-port->destination-address/destination-port 0xconnection-tag service-name nat-source-address/nat-source-port->nat-destination-address/nat-destination-port 0xnat-connection-tag src-nat-rule-type src-nat-rule-name dst-nat-rule-type dst-nat-rule-name protocol-id policy-name source-zone-name destination-zone-name session-id-32 username(roles) packet-incoming-interface application nested-application encrypted application-category application-sub-category application-risk application-characteristics src-vrf-grp dst-vrf-grp

 

 

 

 

 

Micro Focus Contributor
Micro Focus Contributor
Status changed to: Under Consideration
 
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.