Missing multi-category URL Filtering field extraction
Noted on Palo Alto Add-on for Splunk the field extraction for log type pan:threat logs stops at field content_version section (comma "," separated section) not capturing the 5th section "ahead" available in the firewall raw logs, which is the proposed new field category.
The field category is currently evaluated from raw_category or threat_category fields not providing the full multi category URL filtering visibility as available in the firewall raw logs.

Nice work @linsmeyerh, great fix
This will save a lot of headache. Thanks @linsmeyerh !
Thanks @linsmeyerh , nice find!
Great work, Thanks @linsmeyerh
Great job @linsmeyerh !
awesome work @linsmeyerh
Thanks @linsmeyerh this will really help us!