Data pattern limitations.

L1 Bithead

Data pattern limitations.

Hi All,

"Save the telnet" movement inspired me :smileyhappy: . I'd like to find out if any one is experiencing same limitations I do:
- " at least 7 bytes" limit in Custom Data Patterns.

- "regex" has very limited capabilities in Custom Data Patterns.

Would adding this features be beneficial for the next release?

I'm also curious about Predefined Patterns (CC number, SSN, SSN(without dash)). Does it work for anyone? Without additional custom conditions (true regex), these seem to be a road paved by false positives :smileyhappy:

Thanks for reading,


L5 Sessionator

Re: Data pattern limitations.

Hi Andrei,

We do indeed have some limitations in terms of what patterns you can use for custom data patterns - there is a 7 byte minimum requirement, and we do use a modified "regex" for pattern creation.  If there is a pattern that you'd like to create but are limited by our restrictions, please feel free to contact your SE for a possible feature request. 

In terms of the pre-defined patterns, PAN-OS will perform some additional checks in place to prevent false positives.  For example, the Luhn algorithm is used to validate credit card numbers, and there are also certain rules to determine valid Social Security numbers.

Hope this helps,


Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!