Skip to content

Introduced vSys (deviceCustomString3) and DeviceName into the summary rules for Palo Alto Networks.#13585

Open
0xrick-dev wants to merge 4 commits intoAzure:masterfrom
0xrick-dev:master
Open

Introduced vSys (deviceCustomString3) and DeviceName into the summary rules for Palo Alto Networks.#13585
0xrick-dev wants to merge 4 commits intoAzure:masterfrom
0xrick-dev:master

Conversation

@0xrick-dev
Copy link
Copy Markdown

Change(s):

Updated the summary rule to include vSys (deviceCustomString3) and DeviceName in the aggregation logic to ensure proper device-level distinction.

Reason for Change(s):

Addresses false positives caused by overlapping subnets and network ranges, where multiple devices were previously summarized incorrectly.
Using DeviceCustomString3 and DeviceName resolves incorrect correlations and improves detection accuracy.

Version Updated:

Yes
Required for Detections/Analytic Rule templates.

Testing Completed:

Yes

Checked that the validations are passing and have addressed any issues that are present:

Yes

@0xrick-dev 0xrick-dev requested a review from a team as a code owner February 6, 2026 09:56
@v-maheshbh v-maheshbh self-assigned this Feb 6, 2026
@v-maheshbh v-maheshbh added the Solution Solution specialty review needed label Feb 6, 2026
@0xrick-dev
Copy link
Copy Markdown
Author

@microsoft-github-policy-service agree company="Microsoft"

@v-maheshbh
Copy link
Copy Markdown
Contributor

Hi @0xrick-dev

Kindly add the testing screenshot for reference.

Thanks!

@v-maheshbh
Copy link
Copy Markdown
Contributor

Hi @0xrick-dev

Kindly review the comments provided above.

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Solution Solution specialty review needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants