# Panw Schema Bugs in Bytes Sent/Received and Packets Sent/Received

**URL:** <https://discuss.elastic.co/t/panw-schema-bugs-in-bytes-sent-received-and-packets-sent-received/208090>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 15, 2019, 2:24pm UTC](https://discuss.elastic.co/t/panw-schema-bugs-in-bytes-sent-received-and-packets-sent-received/208090 "2019-11-15T14:24:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![davidhowell.tx](https://avatars.discourse-cdn.com/v4/letter/d/6de8d8/32.png) [@davidhowell.tx](https://discuss.elastic.co/u/davidhowell.tx)\
**Post date:** [November 15, 2019, 2:24pm UTC](https://discuss.elastic.co/t/panw-schema-bugs-in-bytes-sent-received-and-packets-sent-received/208090/1 "2019-11-15T14:24:07Z")

</div>

There are some inconsistencies in the way the bytes sent/received and packets sent/received are being mapped in the panw module for filebeat. According to ECS the traditional "bytes\_sent" would be mapped to "client.bytes" and/or "source.bytes", and "bytes\_received" would be mapped to "server.bytes" and/or "destination.bytes". "packets\_sent" would be mapped to "client.packets" and/or "source.packets", and "packets\_received" would be mapped to "server.packets" and/or "destination.packets". This is not how panw has been implemented.

References:

- [PAN-OS 7.1 Traffic Log Field Descriptions](https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/traffic-log-fields.html#ide7d8511f-7bd4-490b-a9b2-b5be12b1e9f2)
- [PANW Filebeat Module](https://github.com/elastic/beats/blob/master/x-pack/filebeat/module/panw/panos/config/input.yml)

Column 32

- PAN-OS Documentation: "Bytes Sent" from client-to-server
- PANW Parse: "client.bytes", "destination.bytes"
- Should be: "client.bytes", "source.bytes"
- Lines Affected: 75, 76

Column 33

- PAN-OS Documentation: "Bytes Received" from server-to-client direction
- PANW Parse: "server.bytes", "source. bytes"
- Should be: "server.bytes", "destination.bytes"
- Lines Affected: 77, 78

Column 44

- PAN-OS Documentation: "Packets Sent" from client-to-server direction
- PANW Parse: "server.packets", "destination.packets"
- Should be: "client.packets", "source.packets"
- Lines Affected: 84, 85

Column 45

- PAN-OS Documentation: "Packets Received" from server-to-client direction
- PANW Parse: "client.packets", "source.packets"
- Should be: "server.packets", "destination.packets"
- Lines Affected: 86, 87

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [December 2, 2019, 2:55pm UTC](https://discuss.elastic.co/t/panw-schema-bugs-in-bytes-sent-received-and-packets-sent-received/208090/2 "2019-12-02T14:55:18Z")

</div>

Any news on this? It would be nice if this was cleared out, as the current implementation seems indeed that it does not follow the ecs guidelines, such as:

Palo Alto:

```
Bytes Sent (bytes_sent) Number of bytes in the client-to-server direction of the session.
Bytes Received (bytes_received) Number of bytes in the server-to-client direction of the session.

```

ECS:

```
source.bytes => Bytes sent from the source to the destination.
destination.bytes => Bytes sent from the destination to the source.

```

Same for packets.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 30, 2019, 2:55pm UTC](https://discuss.elastic.co/t/panw-schema-bugs-in-bytes-sent-received-and-packets-sent-received/208090/3 "2019-12-30T14:55:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 14, 2020, 5:19pm UTC](https://discuss.elastic.co/t/panw-schema-bugs-in-bytes-sent-received-and-packets-sent-received/208090/4 "2020-05-14T17:19:56Z")

</div>

There's a PR open to fix this at [https://github.com/elastic/beats/pull/18525](https://github.com/elastic/beats/pull/18525).

Thanks for reporting it. Sorry we missed this post for so long.
