Skip to content

Commit c58944e

Browse files
committed
refactor: PANW change Splunk quality PR
1 parent ae3aaaa commit c58944e

File tree

5 files changed

+1
-21
lines changed

5 files changed

+1
-21
lines changed

Splunk_TA_paloalto/default/eventtypes.conf

+1-3
Original file line numberDiff line numberDiff line change
@@ -14,12 +14,10 @@ search = sourcetype=pan_config OR sourcetype=pan:config
1414
#tags = change
1515

1616
[pan_traffic]
17-
search = sourcetype=pan_traffic OR sourcetype=pan:traffic OR (sourcetype=pan:firewall_cloud AND LogType="TRAFFIC") AND log_subtype != "start"
18-
#tags = network communicate
17+
search = sourcetype=pan_traffic OR sourcetype=pan:traffic OR (sourcetype=pan:firewall_cloud AND LogType="TRAFFIC")
1918

2019
[pan_traffic_start]
2120
search = sourcetype=pan_traffic OR sourcetype=pan:traffic OR (sourcetype=pan:firewall_cloud AND LogType="TRAFFIC") AND log_subtype="start"
22-
#tags = network session start
2321

2422
[pan_traffic_end]
2523
search = sourcetype=pan_traffic OR sourcetype=pan:traffic OR (sourcetype=pan:firewall_cloud AND LogType="TRAFFIC") AND log_subtype="end"

Splunk_TA_paloalto/default/props.conf

-2
Original file line numberDiff line numberDiff line change
@@ -323,7 +323,6 @@ EVAL-app = "Palo Alto Networks Firewall"
323323
EVAL-type = "event"
324324
EVAL-src = coalesce(src,src_ip)
325325

326-
LOOKUP-system_change = system_change log_subtype,action OUTPUTNEW change_type,result,status,command,object,object_category
327326

328327
# GlobalProtect logs introduced in PANOS 9.1
329328
[pan_globalprotect]
@@ -383,7 +382,6 @@ EVAL-status = if(result=="Succeeded" OR result=="Submitted", "success", null)
383382
# Manually set log_subtype because it isn't in the log
384383
EVAL-log_subtype = "config"
385384
LOOKUP-vendor_info_for_pan_config = pan_vendor_info_lookup sourcetype OUTPUT vendor,product,vendor_product
386-
LOOKUP-config_change = config_change_lookup log_subtype,configuration_path OUTPUT action,change_type,object,object_attrs,object_cateogry
387385

388386

389387
[pan:hipmatch]

Splunk_TA_paloalto/default/transforms.conf

-5
Original file line numberDiff line numberDiff line change
@@ -281,8 +281,3 @@ filename = minemeld_filethreatlist.csv
281281

282282
[minemeld_urlthreatlist]
283283
filename = minemeld_urlthreatlist.csv
284-
285-
[system_change]
286-
filename = pan_system_change.csv
287-
[config_change_lookup]
288-
filename = pan_config_change.csv

Splunk_TA_paloalto/lookups/pan_config_change.csv

-9
This file was deleted.

Splunk_TA_paloalto/lookups/pan_system_change.csv

-2
This file was deleted.

0 commit comments

Comments
 (0)