Hello. I've seen some logstash pipelines for parsing Palo Alto logs by using CSV plugin. I'm curious if anyone has taken this a step further and aligned the fields with the Elastic Common Schema. I am working on doing this, and some of the field mappings seem nebulous.
I currently have some of the log types mapped with some additional fields not defined in ECS framework, I am just hoping to find someone else on this path with which I can compare notes.