File: //usr/share/filebeat/module/panw/panos/manifest.yml
module_version: "1.0"
var:
- name: paths
default:
- /var/log/pan-os.log
- name: tags
default: [pan-os, forwarded]
- name: syslog_host
default: localhost
- name: syslog_port
default: 9001
- name: input
default: syslog
- name: community_id
default: true
- name: internal_zones
default:
- trust
- name: external_zones
default:
- untrust
ingest_pipeline:
- ingest/pipeline.yml
- ingest/traffic.yml
- ingest/threat.yml
- ingest/globalprotect.yml
- ingest/userid.yml
- ingest/hipmatch.yml
input: config/input.yml
requires.processors:
- name: geoip
plugin: ingest-geoip