This information is for Palo Alto Networks Telemetry Pipeline, which is a standalone
product separate from Palo Alto Networks Cortex XCOR.
Configuration parameters
Use the parameters in this section to configure the allow records processing rule. The Palo Alto Networks Telemetry Pipeline web interface uses the items in the Name column to describe these parameters. Pipeline configuration files use the items in the Key column as YAML keys.Example
Using the allow records rule lets you pare down telemetry data by retaining only the records with key-value pairs that you explicitly choose to keep. For example, given this sample log data:action and the Regex value purchase
returns the following result: