[filebeat][decode_cef] Unable to parse fields containing hyphen -
#40348
Labels
bug
Filebeat
Filebeat
:Processors
Team:Security-Deployment and Devices
Deployment and Devices Team in Security Solution
This is an extension to #40236 where a workaround was performed before
decode_cef
processor as it is unable to handle fields containing hyphen-
.Sample message:
If
decode_cef
is applied to above message, we get error:malformed value for PanOSDynamicUserGroupName at pos 1617
, because it is unable to parse adjacent fieldPanOSX-Forwarded-ForIP
. When a workaround is applied to remove hyphen-
from the field name, this error is resolved.Below is the filebeat configuration with current workaround (removing hyphen
-
from fields) to mitigate the errors.Filebeat configuration:
The text was updated successfully, but these errors were encountered: