This information is for Palo Alto Networks Telemetry Pipeline, which is a standalone
product separate from Palo Alto Networks Cortex XCOR.
Configuration parameters
Use the parameters in this section to configure the block records processing rule. The Palo Alto Networks Telemetry Pipeline web interface uses the items in the Name column to describe these parameters. Pipeline configuration files use the items in the Key column as YAML keys.Example
Using the block records rule lets you pare down telemetry data by eliminating records with data you don’t want to keep. For example, given this sample log data:action and the Regex value purchase
returns the following result: