When using the Indicator Search in the Panther Console to query specific values from my custom log schema, I don't get any results, even though I know that this value is contained in my logs.
To resolve this issue:
- Open the custom log schema.
- Ensure that any fields which contain indicators (emails, ip addresses, AWS account IDs, etc.) are marked with an indicator type.
- You can read more about this in the Panther documentation here: Log Schema Reference.
This is caused by indicator fields not being configured properly. For custom log schemas, the indicator field must be manually configured in order for Panther to properly parse and index their values.