PaloAltoNetworks/Splunk_TA_paloalto

pan:system events incorrectly tagged as system updates

Closed this issue · 0 comments

Currently, all pan:system events are being tagged as system updates. Per CIM 4.6:

The fields in the Updates data model describe patch management events from individual systems or central management tools.

Most of the events in the pan:system

Solution: remove the tagging for the pan:system events as update, or only tag events which indicate system patching.