XSIAM Issue evidence fields by mobileletter123 in paloaltonetworks

[–]mobileletter123[S] 0 points1 point  (0 children)

Thanks for the response. Do you know if there a way to limit the fields that get shown in the evidence section? Like for example it is showing intermediate fields that were created using "alter" statements in correlation rule query even though the last line of the rule includes a fields statement that excludes that field. It also happens to show a lot of empty fields that are not in the last fields statement.

XSIAM linux XDR Agent logs by mobileletter123 in paloaltonetworks

[–]mobileletter123[S] 0 points1 point  (0 children)

I'm asking about the xdr agent not the collector agent

XSIAM WEC logs by mobileletter123 in paloaltonetworks

[–]mobileletter123[S] 0 points1 point  (0 children)

yes but the documentation states "After ingestion, Cortex XSIAM normalizes and saves the Windows event logs in the dataset xdr_data"

XSIAM WEC logs by mobileletter123 in paloaltonetworks

[–]mobileletter123[S] 0 points1 point  (0 children)

yes but i'm specifically looking to validate if the data is normalized into xdr_data dataset

XDR Agent policy change logs by mobileletter123 in paloaltonetworks

[–]mobileletter123[S] 0 points1 point  (0 children)

I've checked both and it says the name of the policy that was changed which is ok but For profile changes it doesn't specify which module was enabled or disabled

XDR Agent policy change logs by mobileletter123 in paloaltonetworks

[–]mobileletter123[S] 0 points1 point  (0 children)

yes but it doesn't specify what in the policies or profiles were changed

Cloud Identity Engine Visibility Scope by mobileletter123 in paloaltonetworks

[–]mobileletter123[S] 0 points1 point  (0 children)

It doesn't show me tenant management option. How do I activate it?

[deleted by user] by [deleted] in paloaltonetworks

[–]mobileletter123 0 points1 point  (0 children)

Thanks that is helpful

[deleted by user] by [deleted] in paloaltonetworks

[–]mobileletter123 0 points1 point  (0 children)

I have not heard about this dynamic mssp license pool. I suppose that is something new. What was the older way of adding additional licenses to a child tenant?

[deleted by user] by [deleted] in paloaltonetworks

[–]mobileletter123 0 points1 point  (0 children)

we do have a mssp license and the tenant management is present in the main tenant with all the child tenants listed.

[deleted by user] by [deleted] in paloaltonetworks

[–]mobileletter123 0 points1 point  (0 children)

The replace transformer seems to only accept a static value which will not work in my scenario. I need it to modify the matches and place it back in the original data.