Package paloalto/firewall Release Notes

Package paloalto/firewall Release Notes Version 1.1.0
  • Adds support for PAN-OS v11.0

  • Improves the field extraction and performance.

  • Renames the fields under the Vendor namespace to pascal case notation. It's a breaking change so don't update to this version in case your queries rely on the Vendor specific fields.

  • Bumps the minimum LogScale version to 1.142 to support assertions in yaml files.

  • Adds threat.*, event.severity fields and more.

  • Sets the event.action for Authentication events.

  • Sets the event.category to intrusion_detection and malware for Colleration events.

  • Classifies events according to a threat taxonomy as the MITRE ATT&CK framework.

  • Renames the parser to paloalto-ngfw.

Package paloalto/firewall Release Notes Version 1.0.0
  • Adds new event.module and Cps.version fields

  • Removes the Product, related.hash, related.user, related.hosts, related.ip and message fields

  • Sets following tags: Cps.version, Vendor, ecs.version, event.dataset, event.kind, event.module, event.outcome, observer.type

Package paloalto/firewall Release Notes Version 0.2.0