Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

filebeat/panw: ingest fails with date parsing error when ingested via logstash #33829

Closed
efd6 opened this issue Nov 27, 2022 · 1 comment · Fixed by #33830
Closed

filebeat/panw: ingest fails with date parsing error when ingested via logstash #33829

efd6 opened this issue Nov 27, 2022 · 1 comment · Fixed by #33830
Labels

Comments

@efd6
Copy link
Contributor

efd6 commented Nov 27, 2022

The PANW PANOS module ingest fails with a date parsing error during mapping when the documents have been sent via a logstash-containing path when logstash is 8.x. This appears to be due to logstash by default setting ecs_compatibility to true. This results in event.original being populated and to the ingest pipeline failing before the non-conforming date has been converted, resulting a the ingest failure being noted as being caused by the date format error.

@botelastic botelastic bot added the needs_team Indicates that the issue/PR needs a Team:* label label Nov 27, 2022
@elasticmachine
Copy link
Collaborator

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

@botelastic botelastic bot removed the needs_team Indicates that the issue/PR needs a Team:* label label Nov 27, 2022
@efd6 efd6 added the bug label Nov 27, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants