Skip to content
This repository was archived by the owner on Dec 14, 2024. It is now read-only.

Commit e2903be

Browse files
as3923btorresgil
andauthored
fix(addon): Change fwcloud src to EVAL and remove fwcloud dest alias
Update Props.conf (#257) Resolve issue #220 * fix(addon): Change fwcloud src to EVAL and remove fwcloud dest alias --------- Co-authored-by: Brian Torres-Gil <btorres-gil@paloaltonetworks.com>
1 parent f1b0cb4 commit e2903be

File tree

1 file changed

+1
-3
lines changed

1 file changed

+1
-3
lines changed

Splunk_TA_paloalto/default/props.conf

+1-3
Original file line numberDiff line numberDiff line change
@@ -73,7 +73,7 @@ FIELDALIAS-fwcloud_session_id = SessionID as session_id
7373
EVAL-severity = coalesce(Severity, VendorSeverity)
7474
FIELDALIAS-fwcloud_signature = ThreatName as signature
7575
FIELDALIAS-fwcloud_signature_id = ThreatID as signature_id
76-
FIELDALIAS-fwcloud_src = SourceAddress as src
76+
EVAL-src = coalesce(SourceAddress, PublicIPv4)
7777
FIELDALIAS-fwcloud_src_host = SourceDeviceHost as src_host
7878
FIELDALIAS-fwcloud_src_interface = InboundInterface as src_interface
7979
EVAL-src_ip = coalesce(SourceAddress, PublicIPv4)
@@ -98,8 +98,6 @@ FIELDALIAS-fwcloud_vsys_id = VirtualSystemID as vsys_id
9898
FIELDALIAS-fwcloud_vsys_name = VirtualSystemName as vsys_name
9999

100100
LOOKUP-vendor_action = pan_vendor_action_lookup vendor_action OUTPUT action
101-
FIELDALIAS-src_for_pan_cloud = src_ip as src
102-
FIELDALIAS-dest_for_pan_cloud = dest_ip as dest
103101
FIELDALIAS-dvc_for_pan_cloud = host as dvc
104102

105103
EVAL-dest_name = replace(dest_hostname, "^([^:/]+).*", "\1")

0 commit comments

Comments
 (0)