Skip to content

Conversation

@mjwolf
Copy link
Contributor

@mjwolf mjwolf commented Nov 13, 2024

Proposed commit message

It's been observed that with threat-file events, the URL may be placed in a "FUTURE_USE" field. This adds support for parsing this field to URL, if it appears this is a URL in the file sub_type.

There isn't any PAN-OS documentation on this usage, so this change is based on actual observed events.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • [ ] I have verified that any added dashboard complies with Kibana's Dashboard good practices
@mjwolf mjwolf added enhancement New feature or request Integration:panw Palo Alto Next-Gen Firewall Team:Security-Deployment and Devices DEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices] labels Nov 13, 2024
@mjwolf mjwolf requested a review from a team as a code owner November 13, 2024 19:49
@elasticmachine
Copy link

Pinging @elastic/sec-deployment-and-devices (Team:Security-Deployment and Devices)

@elastic-vault-github-plugin-prod

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@elasticmachine
Copy link

💚 Build Succeeded

History

  • 💚 Build #18288 succeeded 34de6984f872d7d09e33f77ca90331847ab915e7
@mjwolf mjwolf merged commit 60fcb22 into elastic:main Nov 18, 2024
5 checks passed
@mjwolf mjwolf deleted the panw-threat-url branch November 18, 2024 17:30
@elastic-vault-github-plugin-prod

Package panw - 4.1.0 containing this change is available at https://epr.elastic.co/package/panw/4.1.0/

qcorporation pushed a commit that referenced this pull request Feb 3, 2025
It's been observed that with threat-file events, the URL may be placed in a "FUTURE_USE" field. This adds support for parsing this field to URL, if it appears this is a URL in the file sub_type. There isn't any PAN-OS documentation on this usage, so this change is based on actual observed events.
harnish-crest-data pushed a commit to chavdaharnish/integrations that referenced this pull request Feb 4, 2025
It's been observed that with threat-file events, the URL may be placed in a "FUTURE_USE" field. This adds support for parsing this field to URL, if it appears this is a URL in the file sub_type. There isn't any PAN-OS documentation on this usage, so this change is based on actual observed events.
qcorporation pushed a commit that referenced this pull request Feb 4, 2025
It's been observed that with threat-file events, the URL may be placed in a "FUTURE_USE" field. This adds support for parsing this field to URL, if it appears this is a URL in the file sub_type. There isn't any PAN-OS documentation on this usage, so this change is based on actual observed events.
harnish-crest-data pushed a commit to chavdaharnish/integrations that referenced this pull request Feb 5, 2025
It's been observed that with threat-file events, the URL may be placed in a "FUTURE_USE" field. This adds support for parsing this field to URL, if it appears this is a URL in the file sub_type. There isn't any PAN-OS documentation on this usage, so this change is based on actual observed events.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:panw Palo Alto Next-Gen Firewall Team:Security-Deployment and Devices DEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices]

3 participants