Hi,
Using the Panos module for filebeat:
the field "threat category" (eg dns-proxy) isn't currently parsed into a dedicated field but is dropped and part of the event.original field. This could be a valuable field for threat hunting in our use case. Is there a possibility to include this field into the module?