Skip to content

[panw] Parse URL from domain_edl category threat logs - #11837

Merged
mjwolf merged 0 commit into
elastic:mainfrom
mjwolf:panw-threat-fields
Dec 7, 2024
Merged

[panw] Parse URL from domain_edl category threat logs#11837
mjwolf merged 0 commit into
elastic:mainfrom
mjwolf:panw-threat-fields

Conversation

@mjwolf

@mjwolf mjwolf commented Nov 22, 2024

Copy link
Copy Markdown
Contributor

Proposed commit message

In PAN-OS threat logs, when threat_category is 'domain_edl', the misc field will contain a URL. This change adds parsing of the URL for this case.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

Related issues

@mjwolf mjwolf added enhancement New feature or request Integration:panw Palo Alto Next-Gen Firewall Team:Security-Deployment and Devices DEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices] labels Nov 22, 2024
@mjwolf
mjwolf requested a review from a team as a code owner November 22, 2024 21:59
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/sec-deployment-and-devices (Team:Security-Deployment and Devices)

@mjwolf
mjwolf enabled auto-merge (squash) November 22, 2024 21:59
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@mjwolf
mjwolf merged commit 42bd8ea into elastic:main Dec 7, 2024
@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

History

  • 💚 Build #18625 succeeded 312ec7a4c94543421e1a6c1d10d994c88164425f
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package panw - 4.2.0 containing this change is available at https://epr.elastic.co/package/panw/4.2.0/

harnish-crest-data pushed a commit to chavdaharnish/integrations that referenced this pull request Feb 4, 2025
In PAN-OS threat logs, when threat_category is 'domain_edl', the misc field will contain a URL. This change adds parsing of the URL for this case.
harnish-crest-data pushed a commit to chavdaharnish/integrations that referenced this pull request Feb 5, 2025
In PAN-OS threat logs, when threat_category is 'domain_edl', the misc field will contain a URL. This change adds parsing of the URL for this case.
@mjwolf
mjwolf deleted the panw-threat-fields branch February 5, 2025 18:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:panw Palo Alto Next-Gen Firewall Team:Security-Deployment and Devices DEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices]

3 participants