# Palo Alto \[SIEM\]

**URL:** <https://discuss.elastic.co/t/palo-alto-siem/237667>\
**Category:** SIEM\
**Created:** [June 18, 2020, 3:27pm UTC](https://discuss.elastic.co/t/palo-alto-siem/237667 "2020-06-18T15:27:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![RdrgPorto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rdrgporto/32/13278_2.png) [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Post date:** [June 18, 2020, 3:27pm UTC](https://discuss.elastic.co/t/palo-alto-siem/237667/1 "2020-06-18T15:27:58Z")

</div>

Hi, everyone

I have tested with **Palo Alto** module ( **Filebeat 7.5.2** ). I have used this module with **Syslog** and **File** inputs.

_Syslog_

```auto
- module: panw
  panos:
    enabled: true
    var.syslog_host: 0.0.0.0
    var.syslog_port: 514

```

_File_

```auto
- module: panw
  panos:
    enabled: true
    var.input: file
    var.paths: ["/var/log/palo-alto/messages.log"]

```

It has parsed **Palo Alto** information very well. However, on **SIEM** , it shows the **hostname** in which **Filebeat** has been installed (in my case **labs-eshost7** ).

 ![palo-alto](https://us1.discourse-cdn.com/elastic/original/3X/0/0/003b4a169aa14550f277c33e559d512e1a3e7b52.png)

Moreover, on **Discover** , there are some fields related to **hostname**.

- **agent.hostname** : labs-eshost7
- **host.name** : labs-eshost7 (SIEM use this field)
- **hostname** : "firewall-name"
- **observer.hostname** : "firewall-name"

Is it possible to **use a different field** instead of **host.name**? or Is it possible to **copy the value of hostname** or **observer.hostname** into **host.name**?

Regards 🖖

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [June 19, 2020, 2:18pm UTC](https://discuss.elastic.co/t/palo-alto-siem/237667/2 "2020-06-19T14:18:24Z")

</div>

Yes, we're aware of this limitation. Beats used to hardcode `host.name` to the host they're running on, which is misleading for events received from remote hosts.

Starting on 7.9.0, Filebeat will add the correct `host.name` in the case of PANW and all other modules which receive data from remote systems.

As a quick workaround, you can add the following processor to the main `filebeat.yml`:

```auto
  - convert:
      fields:
          - {from: observer.hostname, to: host.name}
      ignore_missing: true
      when.equals.event.dataset: 'panw.panos'

```

And make sure you undo this when migrating to 7.9+

---

<div class="post-metadata">

**Author:** ![RdrgPorto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rdrgporto/32/13278_2.png) [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Post date:** [June 19, 2020, 2:27pm UTC](https://discuss.elastic.co/t/palo-alto-siem/237667/3 "2020-06-19T14:27:47Z")

</div>

Hi, @adrisr

Thanks for the answer 😀

Thanks in advance,

Regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 17, 2020, 2:27pm UTC](https://discuss.elastic.co/t/palo-alto-siem/237667/4 "2020-07-17T14:27:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
