Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Field alias inconsistencies between firewall and firewall_cloud #289

Open
shepherdjay opened this issue Mar 9, 2023 · 2 comments
Open
Labels

Comments

@shepherdjay
Copy link

Describe the bug

There appears to be several inconsistencies between aliases for firewall and firewall_cloud. I see some of these have been resolved in 8.0.0.x but others are still outstanding. It is isn't clear if this is as designed.

Expected behavior

Searching for
log_type="TRAFFIC" | stats count by src_translated_ip

Should result in working results for both Cortex forwarded logs firewall_cloud and panorama / palo logs firewall

Current behavior

Instead only on-prem are found

Possible solution

We are utilizing additional aliases in our setup to allow for the dashboards to normalize across onprem and cortex

Steps to reproduce

Utilize 7.1 app or 8.0 app

Context

Consistent dashboard queries for our environment

@shepherdjay shepherdjay added the bug label Mar 9, 2023
@welcome-to-palo-alto-networks
Copy link

🎉 Thanks for opening your first issue here! Welcome to the community!

@shepherdjay
Copy link
Author

Another example - in order to query logs for hip we're construction setups like this:

(sourcetype="pan:hipmatch" OR log_type="HIPMATCH") AND (hip_type=profile OR HipMatchType=profile)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant