Skip to content

[Bug] panw fields unknown #5015

@y0no

Description

@y0no

Describe the Bug

Hello,
I don't know if this is the right way to report this issue. But I use detection-rules to export my rules from the elastic stack. Unfortunately, a high numbers of our rules rely on Palo Alto integrations and are not validated by detection-rules with a lot of unknown fields. Is there a way to import theses fields that seems to be known by elastic ? (https://www.elastic.co/docs/reference/integrations/panw#ecs-field-reference)

To Reproduce

Try to import a rule with a query like :

panw.panos.threat_category : "dns"

Expected Behavior

No response

Screenshots

No response

Desktop - OS

None

Desktop - Version

No response

Additional Context

No response

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions