Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

App is not parsing the URI to create interesting fields #298

Open
jchubbar opened this issue Jun 5, 2023 · 1 comment
Open

App is not parsing the URI to create interesting fields #298

jchubbar opened this issue Jun 5, 2023 · 1 comment
Labels

Comments

@jchubbar
Copy link

jchubbar commented Jun 5, 2023

Describe the bug

In our environment where we have the Splunk Addon 6.6, we can use q=* OR pq=* to parse URIs to gather search terms in search engines. But we upgraded to 8.2 and no longer have that functionality.

Expected behavior

In 6.6 , if I add (pq=* OR query=* OR p=* OR q=*) as a part of the search terms, I see interesting fields that contain what the user searched for.

Current behavior

In 8.2, with the same query, no results are returned.

Possible solution

None

Steps to reproduce

Run a Splunk query like:
(index=corp_palo_alto sourcetype=pan:threat log_subtype=url) (pq=* OR query=* OR p=* OR q=*) categories IN (search-engines, streaming-media)

See the results and Interesting Fields populate in our Splunk environment that has the TA app 6.6.

Context

Need to move all functionality to SplunkCloud and the 6.6 version of the Palo Alto app is not supported.

Your Environment

On-prem Splunk that has the Palo Alto Networks Addon 6.6.0 installed
SplunkCloud that has the Palo Alto Networks Addon 8.2.0 installed

@jchubbar jchubbar added the bug label Jun 5, 2023
@welcome-to-palo-alto-networks
Copy link

🎉 Thanks for opening your first issue here! Welcome to the community!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant