-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[filebeat][decode_cef] Unable to parse fields containing hyphen -
#40348
Labels
bug
Filebeat
Filebeat
:Processors
Team:Security-Deployment and Devices
Deployment and Devices Team in Security Solution
Comments
botelastic
bot
added
the
needs_team
Indicates that the issue/PR needs a Team:* label
label
Jul 25, 2024
kcreddy
added
:Processors
and removed
needs_team
Indicates that the issue/PR needs a Team:* label
labels
Jul 25, 2024
botelastic
bot
added
the
needs_team
Indicates that the issue/PR needs a Team:* label
label
Jul 25, 2024
kcreddy
added
Filebeat
Filebeat
Team:Security-Deployment and Devices
Deployment and Devices Team in Security Solution
labels
Jul 25, 2024
Pinging @elastic/sec-deployment-and-devices (Team:Security-Deployment and Devices) |
botelastic
bot
removed
the
needs_team
Indicates that the issue/PR needs a Team:* label
label
Jul 25, 2024
kcreddy
changed the title
decode_cef: Unable to parse fields containing hyphen
[filebeat][decode_cef] Unable to parse fields containing hyphen Jul 25, 2024
-
-
The spec says extensions are alphanumeric. But we made an exception already so allowing
|
6 tasks
vinit-chauhan
added a commit
to vinit-chauhan/beats
that referenced
this issue
Aug 13, 2024
This adds support for hyphens (`-`) in extension keys. The CEF spec says that extension keys alphanumeric. So this is a deviation, but a minor one that is inline with past deviations to allow dots in extension keys. I have also added .ri file to gitignore file as they are intermediate files generated by regel. Closes elastic#40348
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
bug
Filebeat
Filebeat
:Processors
Team:Security-Deployment and Devices
Deployment and Devices Team in Security Solution
This is an extension to #40236 where a workaround was performed before
decode_cef
processor as it is unable to handle fields containing hyphen-
.Sample message:
If
decode_cef
is applied to above message, we get error:malformed value for PanOSDynamicUserGroupName at pos 1617
, because it is unable to parse adjacent fieldPanOSX-Forwarded-ForIP
. When a workaround is applied to remove hyphen-
from the field name, this error is resolved.Below is the filebeat configuration with current workaround (removing hyphen
-
from fields) to mitigate the errors.Filebeat configuration:
The text was updated successfully, but these errors were encountered: