Skip to content

Conversation

@jameswiggins
Copy link

I added an additional Grok pattern to the list available in the default ingest pipeline. I did this because the PANW audit logs were failing to parse. I have tested these changes in production and verified their efficacy in parsing the panw audit logs.

To test, the reviewer could install the PANW integration, try to ingest some PANW audit logs and verify this pattern is required to parse audit logs and that adding this pattern does in fact parse them correctly

Related issues

#14912

@jameswiggins jameswiggins requested a review from a team as a code owner December 15, 2025 19:37
@cla-checker-service
Copy link

cla-checker-service bot commented Dec 15, 2025

💚 CLA has been signed

@jameswiggins
Copy link
Author

I have signed the CLA

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

1 participant