-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
PANW incorrectly parse the timezone to UTC when Timezone in the event #13867
Comments
Maybe @elastic/observability could comment on that? |
I am also investigating these issues, I have opened a PR to avoid using UTC in pipelines testing, so we better see if changes in pipelines incorrectly change the resulting events (#13874). This way I have found that there are some other incorrect modules. The fix would be the one you posted here yes, @ph would you want to open a PR with this fix for this module? I will take care of others I have found. |
I have created #13877 to keep track of this issue in affected modules. |
@jsoriano can you take it over, so only one review is necessary ?:) |
I was involved in a user case concerning the PANW module and I have found out that the date doesn't seem to be correctly parsed by the ingest pipeline when the timezone is found in the event. I've changed the ingest pipeline for the following and it appears to have solved the user problem.
Is there something that I've missed or the pipeline is indeed incorrect?
The text was updated successfully, but these errors were encountered: