Closed FusionFC closed 1 year ago
DECRYPTION logs should be sourcetype pan:decryption not pan:traffic
From the PA TA v7.0.4:
[pan_decryption] DEST_KEY = MetaData:Sourcetype REGEX = ^[^,]+,[^,]+,[^,]+,DECRYPTION, FORMAT = sourcetype::pan:decryption
DECRYPTION logs should be sourcetype pan:decryption not pan:traffic
From the PA TA v7.0.4: