# Palo Alto Ingest Pipeline

**URL:** <https://discuss.elastic.co/t/palo-alto-ingest-pipeline/213231>\
**Category:** Elasticsearch\
**Created:** [December 27, 2019, 9:40pm UTC](https://discuss.elastic.co/t/palo-alto-ingest-pipeline/213231 "2019-12-27T21:40:54Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![crux](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/crux/32/21918_2.png) [@crux](https://discuss.elastic.co/u/crux)\
**Post date:** [December 27, 2019, 9:40pm UTC](https://discuss.elastic.co/t/palo-alto-ingest-pipeline/213231/1 "2019-12-27T21:40:54Z")

</div>

I'm hoping to get some clarification on how the Palo Alto ingest pipelines work. There don't seem to be any processors shipped by default that actually parse information (i.e. grok). Even when I throw the [sample data from the Beats Github repo](https://github.com/elastic/beats/blob/7.5/x-pack/filebeat/module/panw/panos/test/threat.log) at the auto-generated panos pipeline, I don't get anything that remotely matches the [expected Elasticsearch output](https://github.com/elastic/beats/blob/7.5/x-pack/filebeat/module/panw/panos/test/threat.log-expected.json).

```auto
GET _ingest/pipeline/filebeat-7.4.2-panw-panos-pipeline/_simulate
{
  "docs": [
    {
      "_source": {
        "message": """Nov 30 16:44:36 PA-220 1,2018/11/30 16:44:36,012801096514,THREAT,url,2049,2018/11/30 16:44:36,192.168.15.224,152.195.55.192,192.168.1.63,152.195.55.192,new_outbound_from_trust,,,ssl,vsys1,trust,untrust,ethernet1/2,ethernet1/1,send_to_mac,2018/11/30 16:44:36,28191,1,52984,443,37679,443,0x403000,tcp,block-url,"consent.cmp.oath.com/",(9999),business-and-economy,informational,client-to-server,7726,0x2000000000000000,192.168.0.0-192.168.255.255,United States,0,,0,,,0,,,,,,,,0,0,0,0,0,,PA-220,,,,,0,,0,,N/A,unknown,AppThreat-0-0,0x0,0,4294967295,"""
      }
    }
  ]
}

```

```auto
{
  "docs" : [
    {
      "doc" : {
        "_index" : "_index",
        "_type" : "_doc",
        "_id" : "_id",
        "_source" : {
          "error" : {
            "message" : ""
          },
          "log" : {
            "original" : """Nov 30 16:44:36 PA-220 1,2018/11/30 16:44:36,012801096514,THREAT,url,2049,2018/11/30 16:44:36,192.168.15.224,152.195.55.192,192.168.1.63,152.195.55.192,new_outbound_from_trust,,,ssl,vsys1,trust,untrust,ethernet1/2,ethernet1/1,send_to_mac,2018/11/30 16:44:36,28191,1,52984,443,37679,443,0x403000,tcp,block-url,"consent.cmp.oath.com/",(9999),business-and-economy,informational,client-to-server,7726,0x2000000000000000,192.168.0.0-192.168.255.255,United States,0,,0,,,0,,,,,,,,0,0,0,0,0,,PA-220,,,,,0,,0,,N/A,unknown,AppThreat-0-0,0x0,0,4294967295,"""
          }
        },
        "_ingest" : {
          "timestamp" : "2019-12-27T21:29:13.094132Z"
        }
      }
    }
  ]
}

```

Am I missing something? How is this supposed to work?

[Here's a link to the pipeline for reference](https://github.com/elastic/beats/blob/7.5/x-pack/filebeat/module/panw/panos/ingest/pipeline.yml).

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 24, 2020, 9:40pm UTC](https://discuss.elastic.co/t/palo-alto-ingest-pipeline/213231/2 "2020-01-24T21:40:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
