I'm unable to determine if this bug is manifesting in actual Filebeat parses of PAN-OS logs as I'm not utilizing them. I'm using the Filebeat configuration to assist in creating my Logstash pipeline to map PAN-OS fields to Elastic Common Schema.
During my review the first thing I notice is that the Filebeat panw module has the csv parse column 1 to "event.created". Upon reviewing Palo Alto's documentation on the field descriptions, the first column presented is labeled "FUTURE_USE", and the second column is "Receive Time". If the panw module is parsing properly it suggests that the module is somehow skipping the first column, which would be sufficient for the panw stance of dropping many of the fields including those marked for "future use", but I'm hesitant to drop fields that could be used in the future for use cases currently unknown.