Skip to content

[panw] Drop malformed messages from syslog processor - #16949

Merged
mjwolf merged 4 commits into
elastic:mainfrom
mjwolf:panos-drop-syslog
Jan 15, 2026
Merged

[panw] Drop malformed messages from syslog processor#16949
mjwolf merged 4 commits into
elastic:mainfrom
mjwolf:panos-drop-syslog

Conversation

@mjwolf

@mjwolf mjwolf commented Jan 13, 2026

Copy link
Copy Markdown
Contributor

Proposed commit message

In panw, drop events where the syslog processor could not parse a syslog message from the event. This behaviour is the same as the TCP syslog parser, which will also drop unparsable syslog messages.

The drop_event condition is "error.message" is set and "log.syslog.priority" is absent, which should indicate the syslog processor is the source of the error, because the mandatory syslog field is not present, and not drop events where an earlier processor is the cause of the error.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices
In cases where a malformed syslog message is received, drop the message,
since it likely won't contain enough data to parse properly, and will
cause futher errors in the ingest pipeline and the document which would
be stored.
@andrewkroh andrewkroh added the Integration:panw Palo Alto Next-Gen Firewall label Jan 13, 2026
Change the drop_event condition to drop the event when error.message is
set AND log.syslog.priority is absent. This would indicate that the
syslog message was not parsed properly, and the origin of the error
message is in the syslog processor.
@mjwolf mjwolf self-assigned this Jan 15, 2026
@mjwolf mjwolf added bugfix Pull request that fixes a bug issue Team:Integration-Experience Security Integrations Integration Experience [elastic/integration-experience] labels Jan 15, 2026
@mjwolf
mjwolf marked this pull request as ready for review January 15, 2026 19:31
@mjwolf
mjwolf requested a review from a team as a code owner January 15, 2026 19:31
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/integration-experience (Team:Integration-Experience)

@mjwolf
mjwolf enabled auto-merge (squash) January 15, 2026 19:35
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

History

cc @mjwolf

@mjwolf
mjwolf merged commit 125b327 into elastic:main Jan 15, 2026
8 checks passed
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package panw - 5.4.1 containing this change is available at https://epr.elastic.co/package/panw/5.4.1/

jakubgalecki0 pushed a commit to jakubgalecki0/integrations that referenced this pull request Feb 19, 2026
In panw, drop events where the syslog processor could not parse a syslog message from the event. This behaviour is the same as the TCP syslog parser, which will also drop unparsable syslog messages.

The drop_event condition is "error.message" is set and "log.syslog.priority" is absent, which should indicate the syslog processor is the source of the error, because the mandatory syslog field is not present, and not drop events where an earlier processor is the cause of the error.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Pull request that fixes a bug issue Integration:panw Palo Alto Next-Gen Firewall Team:Integration-Experience Security Integrations Integration Experience [elastic/integration-experience]

4 participants