Skip to content

Add Grok pattern for PANW Audit Logs #16566

Open
jameswiggins wants to merge 2 commits intoelastic:mainfrom
jameswiggins:patch-1
Open

Add Grok pattern for PANW Audit Logs #16566
jameswiggins wants to merge 2 commits intoelastic:mainfrom
jameswiggins:patch-1

Conversation

@jameswiggins
Copy link

I added an additional Grok pattern to the list available in the default ingest pipeline. I did this because the PANW audit logs were failing to parse. I have tested these changes in production and verified their efficacy in parsing the panw audit logs.

To test, the reviewer could install the PANW integration, try to ingest some PANW audit logs and verify this pattern is required to parse audit logs and that adding this pattern does in fact parse them correctly

Related issues

#14912

@jameswiggins jameswiggins requested a review from a team as a code owner December 15, 2025 19:37
@cla-checker-service
Copy link

cla-checker-service bot commented Dec 15, 2025

💚 CLA has been signed

@jameswiggins
Copy link
Author

I have signed the CLA

@andrewkroh andrewkroh added Integration:panw Palo Alto Next-Gen Firewall Team:Integration-Experience Security Integrations Integration Experience [elastic/integration-experience] labels Jan 8, 2026
@elasticmachine
Copy link

Pinging @elastic/integration-experience (Team:Integration-Experience)

@botelastic
Copy link

botelastic bot commented Feb 7, 2026

Hi! We just realized that we haven't looked into this PR in a while. We're sorry! We're labeling this issue as Stale to make it hit our filters and make sure we get back to it as soon as possible. In the meantime, it'd be extremely helpful if you could take a look at it as well and confirm its relevance. A simple comment with a nice emoji will be enough :+1. Thank you for your contribution!

@botelastic botelastic bot added the Stalled label Feb 7, 2026
@botelastic
Copy link

botelastic bot commented Mar 9, 2026

Hi! This PR has been stale for a while and we're going to close it as part of our cleanup procedure. We appreciate your contribution and would like to apologize if we have not been able to review it, due to the current heavy load of the team. Feel free to re-open this PR if you think it should stay open and is worth rebasing. Thank you for your contribution!

@botelastic botelastic bot closed this Mar 9, 2026
@botelastic botelastic bot removed the Stalled label Mar 24, 2026
Copy link
Contributor

@taylor-swanson taylor-swanson left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey @jameswiggins, sorry we didn't get to this before.

Do you have a sanitized log sample we can use as pipeline test? We'll also need the version bumped in the manifest file (a patch version change should suffice since this seems like a bugfix) and an entry in the changelog.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Integration:panw Palo Alto Next-Gen Firewall Team:Integration-Experience Security Integrations Integration Experience [elastic/integration-experience]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants