Closed kcreddy closed 3 months ago
Pinging @elastic/sec-deployment-and-devices (Team:Security-Deployment and Devices)
The spec says extensions are alphanumeric.
But we made an exception already so allowing -
won't be any bigger of a deviation IMO.
This is an extension to https://github.com/elastic/beats/issues/40236 where a workaround was performed before
decode_cef
processor as it is unable to handle fields containing hyphen-
.Sample message:
If
decode_cef
is applied to above message, we get error:malformed value for PanOSDynamicUserGroupName at pos 1617
, because it is unable to parse adjacent fieldPanOSX-Forwarded-ForIP
. When a workaround is applied to remove hyphen-
from the field name, this error is resolved. Below is the filebeat configuration with current workaround (removing hyphen-
from fields) to mitigate the errors.Filebeat configuration: