Join GitHub today
GitHub is home to over 36 million developers working together to host and review code, manage projects, and build software together.Sign up
Palo Alto Input parser does not properly capture quoted values #15
Palo Alto logs are comma separated with optional double quotes for values that may include a comma. In the case of a quoted value, the Palo Alto Input breaks and counts the comma within the quotes and shifts the fields.
Steps To Reproduce
1.Forward Palo Alto logs to Palo Alto TCP Input for a Firewall with ThreatDetect enabled.
A packet capture containing the offending messages are included.
referenced this issue
Apr 5, 2019
My testing with the latest PCAP shows that this issue is resolved with the latest snapshot build. There might have been an issue with the previous jar. @waynekearns is planning to test a new snapshot build at the customer site to test confirm (probably tomorrow).