-
Notifications
You must be signed in to change notification settings - Fork 49
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Added PanOS 11 syslog standard fields; repaired broken field extracts & name collisions #294
base: develop
Are you sure you want to change the base?
Commits on Mar 24, 2023
-
Configuration menu - View commit details
-
Copy full SHA for 8be768e - Browse repository at this point
Copy the full SHA 8be768eView commit details
Commits on May 9, 2023
-
pan:userid Field Aliases to match corrected Transforms extracts
#Field Aliases to match corrected Transforms extracts from https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/user-id-log-fields
Configuration menu - View commit details
-
Copy full SHA for d21e7f9 - Browse repository at this point
Copy the full SHA d21e7f9View commit details -
pan:system corrected dvc, description extracts
pan:system corrected dvc coalesce, added description extracts
Configuration menu - View commit details
-
Copy full SHA for 9eb72a0 - Browse repository at this point
Copy the full SHA 9eb72a0View commit details -
Configuration menu - View commit details
-
Copy full SHA for e63a6ef - Browse repository at this point
Copy the full SHA e63a6efView commit details -
Configuration menu - View commit details
-
Copy full SHA for e8baad1 - Browse repository at this point
Copy the full SHA e8baad1View commit details -
Configuration menu - View commit details
-
Copy full SHA for a2ac17b - Browse repository at this point
Copy the full SHA a2ac17bView commit details -
Configuration menu - View commit details
-
Copy full SHA for 3028b46 - Browse repository at this point
Copy the full SHA 3028b46View commit details -
Removed devicegroup_level3 and devicegroup_level4 - do not exist in c…
…onfig data Removed "devicegroup_level3" and "devicegroup_level4" fields, which do not exist in the config data, and cause all later fields to parse incorrectly. Added PanOS 11 updated fields at end
Configuration menu - View commit details
-
Copy full SHA for ad20520 - Browse repository at this point
Copy the full SHA ad20520View commit details -
Modified host_id and host_serial
extract_threat, extract_traffic, extract_globalprotect, and extract_hipmatch all contain the fields "host_id" and "host_serial" - this is extremely useful for asset correlation, and needs to be consistently named for analysis. In extract_globalprotect, the old version uses 'serial_number' for this field, which collides with field 3, which is the 'dvc_serial', not the serial of the src/user asset being described in the log
Configuration menu - View commit details
-
Copy full SHA for 84e5d2d - Browse repository at this point
Copy the full SHA 84e5d2dView commit details -
extract_system added high_res_timezone field parsing
"high_res_timestamp"
Configuration menu - View commit details
-
Copy full SHA for 0df9161 - Browse repository at this point
Copy the full SHA 0df9161View commit details -
hipmatch fieldalias & eval updates for CIM consistency
Configuration menu - View commit details
-
Copy full SHA for fced125 - Browse repository at this point
Copy the full SHA fced125View commit details -
pan:globalprotect and pan:config CIM mapping
field aliases and evals added for CIM compatibility
Configuration menu - View commit details
-
Copy full SHA for b9115f9 - Browse repository at this point
Copy the full SHA b9115f9View commit details
Commits on May 11, 2023
-
Configuration menu - View commit details
-
Copy full SHA for cdffaab - Browse repository at this point
Copy the full SHA cdffaabView commit details