Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Filebeat] PANW Module - SYSTEM and CONFIG logs #15603

Closed
nanjum88 opened this issue Jan 15, 2020 · 7 comments
Closed

[Filebeat] PANW Module - SYSTEM and CONFIG logs #15603

nanjum88 opened this issue Jan 15, 2020 · 7 comments

Comments

@nanjum88
Copy link

Currently, PANW module is only able to parse and forward THREAT and TRAFFIC pattern logs, other log types - SYSTEM and CONFIG are discarded. For them to be visible , user needs to run another instance of FileBeat, whitelist the events, develop patterns in Logstash for the logs and then send them to elastic search.

SYSTEM Logs
CONFIG Logs

We'll also need to map the fields in these logs to ECS.

@elasticmachine
Copy link
Collaborator

Pinging @elastic/siem (Team:SIEM)

@willemdh
Copy link

And userid..

@botelastic
Copy link

botelastic bot commented Dec 16, 2020

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@botelastic botelastic bot added the Stalled label Dec 16, 2020
@willemdh
Copy link

#19375 says this is fixed. I didn't have the time to reconfigure our PA syslog output to test this. Will be for 2021..

@elasticmachine
Copy link
Collaborator

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

@botelastic
Copy link

botelastic bot commented Apr 22, 2022

Hi!
We just realized that we haven't looked into this issue in a while. We're sorry!

We're labeling this issue as Stale to make it hit our filters and make sure we get back to it as soon as possible. In the meantime, it'd be extremely helpful if you could take a look at it as well and confirm its relevance. A simple comment with a nice emoji will be enough :+1.
Thank you for your contribution!

@botelastic botelastic bot added the Stalled label Apr 22, 2022
@jamiehynds
Copy link

Closing as we're about to begin development on additional PANW datasets and tracking in the integrations repo: elastic/integrations#2988

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

5 participants