Indicator Search does not show results for Custom Log values
Issue
When using the Indicator Search in the Panther Console to query specific values from my custom log schema, I don't get any results, even though I know that this value is contained in my logs.
Resolution
To resolve this issue:
- Open the custom log schema.
- Ensure that any fields which contain indicators (emails, ip addresses, AWS account IDs, etc.) are marked with an indicator type.
- You can read more about this in the Panther documentation here: Log Schema Reference.
Cause
This is caused by indicator fields not being configured properly. For custom log schemas, the indicator field must be manually configured in order for Panther to properly parse and index their values.