Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Incorrect Field Mapping - PAN Threat - User Field (mapped with http category - Sender) #297

Open
dharmanr opened this issue May 25, 2023 · 3 comments

Comments

@dharmanr
Copy link

We have observed the props enabled with comma separated defined fields and its mapped with incorrect values..

User field mapped with the value (music-low risk, private IP addressed) which is actually http category and its mapped to sender.

https://splunkbase.splunk.com/app/2757

EVAL-user = case(SourceUser!="null",'SourceUser',SourceUserName !="null",'SourceUserName',src_user!="null",'src_user',dest_user!="null",'dest_user',recipient!="null",'recipient',sender!="null",'sender',true(),"unknown")

@welcome-to-palo-alto-networks

🎉 Thanks for opening your first issue here! Welcome to the community!

@dharmanr dharmanr changed the title Incorrect Field Mapping - PAN Threat - User Field (mapped with http category) Incorrect Field Mapping - PAN Threat - User Field (mapped with http category - Sender) May 25, 2023
@paulmnguyen paulmnguyen self-assigned this Jun 5, 2023
@paulmnguyen
Copy link
Contributor

Hi @dharmanr Could you please let me know what version of PANOS you are using?

@dharmanr
Copy link
Author

dharmanr commented Jun 8, 2023 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants