criblpacks/cribl-palo-alto-networks

Explain reasoning for why certain fields are dropped

eugene-cribl opened this issue · 0 comments

It's very helpful to have unneeded fields dropped as part of the pack, but it would be great to have justification for each of the drops to help justify why that field is not needed. Some are more obvious than others.

Maybe even a Parse function (disabled by default) which parses the dropped fields into JSON so that they can be reviewed easily.