<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: vSZ syslogs missing client IP address in SmartZone and Virtual SmartZone</title>
    <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35221#M2851</link>
    <description>Word of warning to anyone else who is looking for this feature: It is not supported in SmartZone (as of v5.1.0) if you are using 802.1x authentication. Client IP addresses are only included in the clientJoin and clientAuthorization syslogs if you use Open or Web Portal authentication. If you are currently relying on these logs from your ZoneDirector to be exported to your Palo/Meraki/etc. appliances, you will be disappointed if you move to SmartZone. There is an open feature request for this issue (FR-3031). This will NEED to be addressed before the ZoneDirector platform is retired.&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;The underlying problem is that SmartZone sends the clientJoin (after the client is client associated) and clientAuthorized (after the client is authenticated) syslogs, but does not send any syslogs after the client receives an IP address and “officially joins” the controller. Since there is no IP for a client during the association/authorization process, it makes sense that these syslogs are missing that information. The difference with ZoneDirector is that it doesn’t send these detailed syslogs, but instead sends a single “Operational Add” log that summarizes when a client is added to the controller’s client database, which happens after the client obtains an IP. This seems like a large feature gap that needs to be addressed.&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;The SmartZone Alarm and Event Reference Guide is misleading at best, since it indicates that the clientIP attribute should be included in the clientJoin and clientAuthorization syslogs (page 225 and 227). It does not specify that this is only achievable using Open/Web Portal authentication. &lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
    <pubDate>Fri, 12 Apr 2019 16:01:09 GMT</pubDate>
    <dc:creator>nickzourdos</dc:creator>
    <dc:date>2019-04-12T16:01:09Z</dc:date>
    <item>
      <title>vSZ syslogs missing client IP address</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35218#M2848</link>
      <description>We are running into an issue on our vSZ (v5.1.0.0.496) with the clientAuthorization and clientJoin syslogs. Neither of these syslogs contain the clientIP field, which is a problem for customers with security appliances that depend on these syslogs to tie usernames to wireless clients. Strangely, the clientDisconnect syslog&amp;nbsp;&lt;B alt="" name="" rel="" target="" title="" type="" value=""&gt;does&lt;/B&gt; include the clientIP field.&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Is there a way to enable this feature? ZoneDirector syslogs include a field for "sta_ip", which is what we've been using in the past (see &lt;A alt="" href="https://forums.ruckuswireless.com/ruckuswireless/topics/how-to-integrate-between-ruckus-and-palo-alto" name="" rel="nofollow" target="" title="Link httpsforumsruckuswirelesscomruckuswirelesstopicshow-to-integrate-between-ruckus-and-palo-alto" type="" value=""&gt;THIS&lt;/A&gt; thread for context on ZD syslogs in this scenario). The vSZ syslogs are in a completely different format, which is fine, but they are missing this critical information. Here is my vSZ configuration for reference:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="Image_ images_messages_5f91c401135b77e247914f4e_f2c093193ba3fb105226208ee548156e_RackMultipart20190401677842k3u-70e1ba96-c840-43d2-ab40-3031e444beb1-709758273.png1554130312"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/1942iB0AA0261524B637D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Image_ images_messages_5f91c401135b77e247914f4e_f2c093193ba3fb105226208ee548156e_RackMultipart20190401677842k3u-70e1ba96-c840-43d2-ab40-3031e444beb1-709758273.png1554130312" alt="Image_ images_messages_5f91c401135b77e247914f4e_f2c093193ba3fb105226208ee548156e_RackMultipart20190401677842k3u-70e1ba96-c840-43d2-ab40-3031e444beb1-709758273.png1554130312" /&gt;&lt;/span&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Mon, 01 Apr 2019 15:00:38 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35218#M2848</guid>
      <dc:creator>nickzourdos</dc:creator>
      <dc:date>2019-04-01T15:00:38Z</dc:date>
    </item>
    <item>
      <title>Re: vSZ syslogs missing client IP address</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35219#M2849</link>
      <description>Hi Nick,&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;The alarms and events guide posted on the support site for SmartZone mentions the following for ClientAuth and ClientJoin -&amp;gt; "clientIP" .So it should be there.&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Severity must be informational but I believer yours is set to emergency.&amp;nbsp;</description>
      <pubDate>Mon, 01 Apr 2019 15:13:30 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35219#M2849</guid>
      <dc:creator>pasquale_monard</dc:creator>
      <dc:date>2019-04-01T15:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: vSZ syslogs missing client IP address</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35220#M2850</link>
      <description>We are receiving the clientJoin syslogs with the current configuration, aren't those sent as part of the "Event Facility" and "Event Filter" settings? I intentionally set the "Application", "Administrator", and "Other" settings to the highest level in order to avoid overrunning our syslog server. Does one of these need to be set to Info in order for the clientIP field to appear?&amp;nbsp;</description>
      <pubDate>Mon, 01 Apr 2019 15:36:53 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35220#M2850</guid>
      <dc:creator>nickzourdos</dc:creator>
      <dc:date>2019-04-01T15:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: vSZ syslogs missing client IP address</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35221#M2851</link>
      <description>Word of warning to anyone else who is looking for this feature: It is not supported in SmartZone (as of v5.1.0) if you are using 802.1x authentication. Client IP addresses are only included in the clientJoin and clientAuthorization syslogs if you use Open or Web Portal authentication. If you are currently relying on these logs from your ZoneDirector to be exported to your Palo/Meraki/etc. appliances, you will be disappointed if you move to SmartZone. There is an open feature request for this issue (FR-3031). This will NEED to be addressed before the ZoneDirector platform is retired.&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;The underlying problem is that SmartZone sends the clientJoin (after the client is client associated) and clientAuthorized (after the client is authenticated) syslogs, but does not send any syslogs after the client receives an IP address and “officially joins” the controller. Since there is no IP for a client during the association/authorization process, it makes sense that these syslogs are missing that information. The difference with ZoneDirector is that it doesn’t send these detailed syslogs, but instead sends a single “Operational Add” log that summarizes when a client is added to the controller’s client database, which happens after the client obtains an IP. This seems like a large feature gap that needs to be addressed.&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;The SmartZone Alarm and Event Reference Guide is misleading at best, since it indicates that the clientIP attribute should be included in the clientJoin and clientAuthorization syslogs (page 225 and 227). It does not specify that this is only achievable using Open/Web Portal authentication. &lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Fri, 12 Apr 2019 16:01:09 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35221#M2851</guid>
      <dc:creator>nickzourdos</dc:creator>
      <dc:date>2019-04-12T16:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: vSZ syslogs missing client IP address</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35222#M2852</link>
      <description>Thanks for this info nick,&amp;nbsp; that is good to know/be aware of before hand.&amp;nbsp; And i agree this is almost a requirement to be added.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;I think alot more work needs to be done to vsz syslog data/output - (and standalone syslogs for that matter).&amp;nbsp; most in the know, use remote syslogs, so the data needs to be detailed and complete (and often can be behind a nat / masq rule, so dont count on src IP IDing the source).&amp;nbsp; this, and / or ruk needs to allow the customer more syslog options or flexibility.&amp;nbsp; as an extreme/awesome case, on our axis ip cameras, axis allows advanced customers direct access to the rsyslog.conf file, so the sky is the limit!&amp;nbsp; They ofcourse dont suggest you edit this, and if you do, they will not support anything related to syslog after edits.&amp;nbsp; but the option is there.)&amp;nbsp; &amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;tks</description>
      <pubDate>Fri, 12 Apr 2019 19:20:42 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35222#M2852</guid>
      <dc:creator>stephen_hall_60</dc:creator>
      <dc:date>2019-04-12T19:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: vSZ syslogs missing client IP address</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35223#M2853</link>
      <description>We too need this badly.. Hope Ruckus has an update soon...</description>
      <pubDate>Thu, 08 Aug 2019 22:35:04 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35223#M2853</guid>
      <dc:creator>jeff_baublitz_7</dc:creator>
      <dc:date>2019-08-08T22:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: vSZ syslogs missing client IP address</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35224#M2854</link>
      <description>This feature is now available as an AP patch, and it should be included in the next major release of SmartZone. You may want to ask support if they can get you the patch, you can reference my case#&amp;nbsp;00914107.&amp;nbsp;</description>
      <pubDate>Fri, 09 Aug 2019 13:13:58 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35224#M2854</guid>
      <dc:creator>nickzourdos</dc:creator>
      <dc:date>2019-08-09T13:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: vSZ syslogs missing client IP address</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35225#M2855</link>
      <description>Thank you, asking right now. I'll update when I hear back.&amp;nbsp;</description>
      <pubDate>Tue, 20 Aug 2019 15:40:50 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35225#M2855</guid>
      <dc:creator>jeff_baublitz_7</dc:creator>
      <dc:date>2019-08-20T15:40:50Z</dc:date>
    </item>
    <item>
      <title>Re: vSZ syslogs missing client IP address</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35226#M2856</link>
      <description>Support confirms this will be addressed in 5.1.2.X. I'll be updating in a month when this is available. Thanks again!</description>
      <pubDate>Tue, 03 Sep 2019 20:37:54 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35226#M2856</guid>
      <dc:creator>jeff_baublitz_7</dc:creator>
      <dc:date>2019-09-03T20:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: vSZ syslogs missing client IP address</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35227#M2857</link>
      <description>Would you mind sharing your regex expressions? i can't seem to get mine to map correctly.</description>
      <pubDate>Thu, 19 Sep 2019 04:10:42 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35227#M2857</guid>
      <dc:creator>thomas_kranzler</dc:creator>
      <dc:date>2019-09-19T04:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: vSZ syslogs missing client IP address</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35228#M2858</link>
      <description>Yeah, but the impact to one camera isn't the same as a controller which may be hosting 10's of thousands of APs. Mess with a single Axis, and you lose perhaps a single camera as Axis give all customers access to nearly all CONF files on the unit.&lt;BR /&gt;In our org, we use both Axis cameras (several hundred units) and Ruckus (several thousand units.), and&amp;nbsp; I've got my issues with Axis. P1428's and their penchant for rebooting constantly, image ghosting looks which give my surveillance videos a somewhat RETRO FUTURE type vibe.&amp;nbsp; I've got a few Q3708's and Axis has NEVER been able to fix my issue with camera 1 going black and white suddenly.&lt;BR /&gt;As for logs, does change the log you need to Debug help? it's helped us.&lt;BR /&gt;Sorry for the rant, I'm up late dealing with an AXIS camera issue as we speak!</description>
      <pubDate>Thu, 19 Sep 2019 04:25:47 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35228#M2858</guid>
      <dc:creator>andrew_giancol1</dc:creator>
      <dc:date>2019-09-19T04:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: vSZ syslogs missing client IP address</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35229#M2859</link>
      <description>Would you mind sharing your regex expressions? i can't seem to get mine to map correctly.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Thu, 19 Sep 2019 04:28:07 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35229#M2859</guid>
      <dc:creator>thomas_kranzler</dc:creator>
      <dc:date>2019-09-19T04:28:07Z</dc:date>
    </item>
    <item>
      <title>Re: vSZ syslogs missing client IP address</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35230#M2860</link>
      <description>/[^\d.]60:f8:1d:c2:53:6e/&lt;BR /&gt;This is the mac address of my mac book pro. Hope the syntax helps you!</description>
      <pubDate>Thu, 19 Sep 2019 04:43:00 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35230#M2860</guid>
      <dc:creator>andrew_giancol1</dc:creator>
      <dc:date>2019-09-19T04:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: vSZ syslogs missing client IP address</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35231#M2861</link>
      <description>A little.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;here's an exert from the vscg syslogs:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;2019-09-18 21:32:10	Local0.Info	10.250.10.230	Sep 19 04:32:10 RuckusController1 Core: User[bob] disconnects from WLAN[STAFF] at AP[WAP1] with session data(Client Mac[someMac],Client IP[10.250.24.11],OS Type[iOS],Host Name[pickles],BSSID[some BSSID],User Name[bob],VLAN[24],Encryption[WPA2-AES],Association Time[01 01 00:00:00 1970],Disconnect Reason[client Disconnect],Session Duration[75s],Bytes to User[6679],Bytes from User [21624],RSSI[35],SNR[-70],Client Radio[a/n/ac],AP Location[],AP GPS[])&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Here are the PAN settings I'm using:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Event Regex&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;disconnects&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Username Regex&amp;nbsp; &amp;nbsp; &amp;nbsp;User\ Name([[a-zA-Z0-9\\\._]+])&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Address Regex&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Client\ IP([[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}])&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;looks good in&amp;nbsp;&lt;A alt="" href="https://regex101.com/" name="" rel="nofollow" target="" title="" type="" value=""&gt;https://regex101.com/&lt;/A&gt;&amp;nbsp;, but the PAN doesn't seem to parse the logs</description>
      <pubDate>Thu, 19 Sep 2019 04:50:27 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35231#M2861</guid>
      <dc:creator>thomas_kranzler</dc:creator>
      <dc:date>2019-09-19T04:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: vSZ syslogs missing client IP address</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35232#M2862</link>
      <description>Ahh. so you're not getting the Drop codes 75 seconds from "I'm on the wifi! to "I'm leaving the wifi" is suspect. . Anything fresh from the AP logs directly? Have you grabbed Wireshark Pcaps from the ap? I know your issue is with Syslogs and their lack of verbosity, but I feel like there are some ways around this. Pcap is a great way to find this. Post your Pcap, (Filtering for your mac address of course!) and I'm SURE one of us can figure out the connection issue!&lt;BR /&gt;Also, PAN settings? Are you logging to Panorama?</description>
      <pubDate>Thu, 19 Sep 2019 06:45:36 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35232#M2862</guid>
      <dc:creator>andrew_giancol1</dc:creator>
      <dc:date>2019-09-19T06:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: vSZ syslogs missing client IP address</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35233#M2863</link>
      <description>Also, if you happen to be using a OSX box, the program named CONSOLE can be your friend. as you don't need REGEX to find / filter through AP logs.</description>
      <pubDate>Thu, 19 Sep 2019 06:46:58 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35233#M2863</guid>
      <dc:creator>andrew_giancol1</dc:creator>
      <dc:date>2019-09-19T06:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: vSZ syslogs missing client IP address</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35234#M2864</link>
      <description>I have been in contact with Ruckus who have now fixed the syslog bug so it works correctly!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;The Palo Alto regex I am using is the following,&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Device &amp;gt; User Identification &amp;gt; Palo Alto Networks User-ID Agent Setup(the tiny cog on the top right) &amp;gt; Syslog Filters&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Type: Regex Identifier&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Event Regex:&amp;nbsp;(?=.*clientInfoUpdate)(.*"ssid"="YourWirelessSSID")(.*"clientIP"=")&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Username Regex:&amp;nbsp;"userName"="([a-zA-Z0-9.\-\_\\]+)&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Address Regex:&amp;nbsp;"clientIP"="(\b(?:(?:25[0-5]|2[0-4]\d|[01]?\d\d?)\.){3}(?:25[0-5]|2[0-4]\d|[01]?\d\d?)\b)&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;You can also remove the requirements for a specific SSID you can use the following,&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Event Regex:&amp;nbsp;(?=.*clientInfoUpdate)(.*"clientIP"=")&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Dont forget to turn on "Allow matching usernames without domains" for the Palo Alto to allow it to digest logins without the domain if you use RADIUS for auth.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;on the Palo Alto you turn on the following,&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Device &amp;gt; User Identification &amp;gt; Palo Alto Networks User-ID Agent Setup(the tiny cog on the top right) &amp;gt; Cache &amp;gt; Allow matching usernames without domains(tick box)&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Server Monitor also needs to be setup,&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Add the Device &amp;gt; User Identification &amp;gt;&amp;nbsp;Server Monitor&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Type: Syslog Sender&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Network Address: IP of the SmartZone controller&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Connection: UDP&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Add the Ruckus Regex under "Syslog Parse Profile"&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;The SmartZone Controller has the following settings,&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;System &amp;gt; General Settings &amp;gt; Syslog&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Enable Syslog&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Primary Syslog: Palo Alto Management interface IP(the default for user auth)&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Port: 514&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Protocol: UDP&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Event Filter: All Events above a severity&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Event Filter Severity: Informational&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Fri, 10 Jan 2020 02:52:42 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vSZ-syslogs-missing-client-IP-address/m-p/35234#M2864</guid>
      <dc:creator>ict_corpus_chri</dc:creator>
      <dc:date>2020-01-10T02:52:42Z</dc:date>
    </item>
  </channel>
</rss>

