# PANW schema bugs take 2

**URL:** <https://discuss.elastic.co/t/panw-schema-bugs-take-2/232388>\
**Category:** Beats\
**Tags:** ecs-elastic-common-schema, filebeat\
**Created:** [May 13, 2020, 8:19am UTC](https://discuss.elastic.co/t/panw-schema-bugs-take-2/232388 "2020-05-13T08:19:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [May 13, 2020, 8:19am UTC](https://discuss.elastic.co/t/panw-schema-bugs-take-2/232388/1 "2020-05-13T08:19:29Z")

</div>

Hello,

Could someone please take a look at:

> [@Panw Schema Bugs in Bytes Sent/Received and Packets Sent/Received](https://discuss.elastic.co/t/panw-schema-bugs-in-bytes-sent-received-and-packets-sent-received/208090):
>
> There are some inconsistencies in the way the bytes sent/received and packets sent/received are being mapped in the panw module for filebeat. According to ECS the traditional "bytes\_sent" would be mapped to "client.bytes" and/or "source.bytes", and "bytes\_received" would be mapped to "server.bytes" and/or "destination.bytes". "packets\_sent" would be mapped to "client.packets" and/or "source.packets", and "packets\_received" would be mapped to "server.packets" and/or "destination.packets". This is…

And confirm this is a bug?

This is generating confusion.... As source.bytes and destination.bytes are quite important field in a very important dataset, this should be handled asap imho.....

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [May 14, 2020, 7:58pm UTC](https://discuss.elastic.co/t/panw-schema-bugs-take-2/232388/2 "2020-05-14T19:58:38Z")

</div>

@andrewkroh Thanks for taking action on this. Please have a look at my comment on `event.end` in [https://github.com/elastic/beats/pull/18525](https://github.com/elastic/beats/pull/18525)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2020, 7:58pm UTC](https://discuss.elastic.co/t/panw-schema-bugs-take-2/232388/3 "2020-06-11T19:58:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
