Elastic Cluster Version 7.14.0. I am using Elastic-Agent and the PANW integration to ingest Palo Alto Firewall logs. Once ingested the event times are incorrect by the equivalent of the timezone offset. I have found articles on how to resolve this with Filebeat and associated module but I'm struggling on how to achieve this in the Elastic-Agent and integration world. I'm referencing https://discuss.elastic.co/t/panw-module-timezone-offset/191360
When I view the record there is no event.timezone field. I have tried to add to the integration processor as follows (I have left the drop_fields line in ):
- drop_fields.fields: ['event.timezone'] - add_fields: target: event fields: timezone: 'Australia/Brisbane'
But I presume I need to account for
filebeat.overwrite_pipelines: true somehow - is that correct? Or is there something else I'm missing?