-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[filebeat] panw.panos indexing denied twice in event.type #22413
Labels
Comments
botelastic
bot
added
the
needs_team
Indicates that the issue/PR needs a Team:* label
label
Nov 4, 2020
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
botelastic
bot
removed
the
needs_team
Indicates that the issue/PR needs a Team:* label
label
Nov 4, 2020
This should be an easy fix |
6 tasks
leehinman
pushed a commit
to legoguy1000/beats
that referenced
this issue
Mar 30, 2021
elastic#22748: Parsed panos logs for virtual system
leehinman
added a commit
that referenced
this issue
Mar 30, 2021
6 tasks
leehinman
pushed a commit
to leehinman/beats
that referenced
this issue
Mar 30, 2021
PanOS Updates - prevent duplicates in event.* - add virtual system field Closes elastic#22413 Closes elastic#22748 Co-authored-by: Lee E. Hinman <lee.e.hinman@elastic.co> (cherry picked from commit c94a8f8)
6 tasks
leehinman
pushed a commit
to leehinman/beats
that referenced
this issue
Mar 30, 2021
PanOS Updates - prevent duplicates in event.* - add virtual system field Closes elastic#22413 Closes elastic#22748 Co-authored-by: Lee E. Hinman <lee.e.hinman@elastic.co> (cherry picked from commit c94a8f8)
leweafan
pushed a commit
to leweafan/beats
that referenced
this issue
Apr 28, 2023
…lastic#24858) PanOS Updates - prevent duplicates in event.* - add virtual system field Closes elastic#22413 Closes elastic#22748 Co-authored-by: Lee E. Hinman <lee.e.hinman@elastic.co> (cherry picked from commit 1d67812) Co-authored-by: Alex Resnick <adr8292@gmail.com>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
panw.panos dataset's event.type field is populated with the value 'denied' twice.
Elastic 7.9.2
https://discuss.elastic.co/t/siem-rule-override-not-working-as-expected/253933/4
In /usr/share/filebeat/module/panw/panos/ingest/pipeline.yml I can find:
So my guess is that the first block should possibly be removed? And the second block should maybe add connection too?
The text was updated successfully, but these errors were encountered: