收集 Palo Alto Networks 防火牆記錄
本文說明如何使用兩種主要部署方法,設定 Google SecOps 擷取 Palo Alto Networks 的記錄。
請選取下方與您架構相符的章節:
- Palo Alto Networks 防火牆
- 說明:直接從 PAN-OS 防火牆收集記錄。
- 擷取方法:使用 Syslog 將記錄傳送至 Google SecOps Forwarder 或 Bindplane 代理程式。Google SecOps Forwarder 即將於今年稍晚終止支援並淘汰,請改用 Bindplane 代理程式轉寄記錄。
- 支援的格式:CSV、CEF 和 LEEF。
- Palo Alto Networks Firewall Strata Logging Service
- 說明:從雲端 Strata Logging Service 收集記錄。
- 擷取方式:使用 HTTPS Webhook 將記錄直接轉送至 Google SecOps。這個方法不需要本機轉送站。
- 支援的格式:JSON。
Palo Alto Networks 防火牆
總覽
本文說明如何設定系統記錄檔和 Google SecOps 轉送器,以收集 Palo Alto Networks 防火牆記錄。本文也說明 Palo Alto Networks 防火牆記錄欄位如何對應至 Google SecOps 整合式資料模型 (UDM) 欄位。如要瞭解 Google SecOps 資料擷取作業的概況,請參閱「將資料擷取至 Google SecOps」。擷取標籤會識別剖析器,該剖析器會將原始記錄資料正規化為具結構性的 UDM 格式。本文中的資訊適用於具有 PAN_FIREWALL 擷取標籤的剖析器。
事前準備
- 確認 Palo Alto Networks 防火牆產品已正確部署及設定。如需詳細設定操作說明,請參閱 PAN-OS 說明文件。
如要瞭解部署的元件,以便收集 Palo Alto Networks 防火牆記錄,請查看部署架構。每個客戶部署作業可能與此表示法不同,也可能更複雜。下圖顯示如何在 Palo Alto Networks 防火牆上設定系統記錄,以及在 Linux 伺服器上安裝 Google SecOps 轉送器,將記錄資料轉送至 Google SecOps。剖析器支援以半形逗號分隔值 (CSV)、通用事件格式 (CEF) 和記錄事件擴充格式 (LEEF) 等資料格式編寫的記錄。
確認 Google SecOps 剖析器支援的記錄格式和 PAN-OS 版本。下表列出 Google SecOps 剖析器支援的記錄格式和對應的 PAN-OS 版本:
記錄格式 PAN-OS 版本 CSV 10.1.3 CEF 10.0.0 LEEF 9.1.0 確認 Google SecOps 剖析器支援的 Palo Alto Networks 防火牆記錄檔類型。 Google SecOps 剖析器支援下列 Palo Alto Networks 防火牆記錄類型:
- 流量
- 威脅
- WildFire 提交
- 隧道檢查
- 設定
- 系統
- HIP 比對
- IP-Tag
- User-ID
- 解密
- 驗證
- 網址篩選
- 資料篩選
- GlobalProtect
- 關聯性
- GTP
- SCTP
- 稽核
如要進一步瞭解 Palo Alto Networks 防火牆記錄類型,請參閱 PAN-OS 記錄類型。
請確保部署架構中的所有系統都以世界標準時間設定。
使用 Palo Alto Networks 防火牆剖析器前,請先查看舊版剖析器與現行 Palo Alto Networks 防火牆剖析器之間的欄位對應關係變化。在遷移過程中,請確保依附於原始欄位的規則、搜尋、資訊主頁或其他程序,都使用更新後的欄位。
舉例來說,在先前的剖析器版本中,
category記錄檔欄位會對應至security_result.descriptionUDM 欄位。在目前的 Palo Alto Networks 防火牆剖析器中,category記錄欄位會對應至security_result.category_detailsUDM 欄位。如果您遷移至目前的 Palo Alto Networks 防火牆剖析器,並在規則中使用category欄位,則需要修改規則,才能使用目前剖析器的security_result.category_detailsUDM 欄位。
設定系統記錄和 Google Security Operations 轉送器
如要設定系統記錄和 Google SecOps 轉送器,請完成下列步驟:
- 如要監控 CSV 記錄檔,請設定系統記錄檔伺服器設定檔。詳情請參閱「設定系統記錄伺服器設定檔」。設定系統記錄伺服器設定檔時,請將「Default」指定為自訂記錄格式。
- 如要監控 CEF 記錄,請設定 Palo Alto Networks 防火牆轉送 CEF 記錄。詳情請下載 PAN-OS CEF 整合指南 PDF,並參閱「Configuration of Palo Alto Networks NGFW to output CEF events」(設定 Palo Alto Networks NGFW 以輸出 CEF 事件) 一節。
- 如要監控 LEEF 記錄,請設定系統記錄檔伺服器設定檔。詳情請參閱「以 LEEF 格式轉送自訂記錄」。
設定 Google SecOps 轉送器,將記錄傳送至 Google Security Operations。詳情請參閱「在 Linux 上安裝及設定轉送器」。以下是 Google SecOps 轉送站設定範例:
- syslog: common: enabled: true data_type: PAN_FIREWALL batch_n_seconds: 10 batch_n_bytes: 1048576 tcp_address: 0.0.0.0:10518 connection_timeout_sec: 60
在 PAN 防火牆上設定系統記錄轉送
建立系統記錄伺服器設定檔
- 登入 Palo Alto Networks 防火牆管理主控台。
- 依序前往「裝置」>「伺服器設定檔」>「系統記錄」。
- 按一下「新增」,建立新的伺服器設定檔。
- 請提供下列設定詳細資料:
- 名稱:輸入描述性名稱 (例如
Google SecOps BindPlane)。 - 位置:選取這個設定檔可用的虛擬系統 (vsys) 或「共用」。
- 名稱:輸入描述性名稱 (例如
- 依序點選「Servers」(伺服器) >「Add」(新增),設定系統記錄伺服器。
- 請提供下列伺服器設定詳細資料:
- 名稱:輸入伺服器的描述性名稱 (例如
BindPlane Agent)。 - Syslog 伺服器:輸入 BindPlane 代理程式 IP 位址。
- 傳輸:根據 BindPlane Agent 設定選取「UDP」或「TCP」 (預設為 UDP)。
- 「Port」(通訊埠):輸入 BindPlane 代理程式通訊埠編號 (例如
514)。 - 格式:視需求選取「BSD」 (預設) 或「IETF」。
- 設施:選取「LOG_USER」(預設) 或其他設施 (如有需要)。
- 名稱:輸入伺服器的描述性名稱 (例如
- 按一下「確定」儲存系統記錄伺服器設定檔。
選用:設定 CEF 或 LEEF 的自訂記錄格式
如需 CEF (通用事件格式) 或 LEEF (記錄事件擴充格式) 記錄,而非 CSV 檔案,請按照下列步驟操作:
- 在 Syslog 伺服器設定檔中,選取「Custom Log Format」(自訂記錄格式) 分頁。
- 為每種記錄類型 (設定、系統、威脅、流量、網址、資料、WildFire、通道、驗證、User-ID、HIP 比對) 設定自訂記錄格式。
- 如要設定 CEF 格式,請參閱 Palo Alto Networks CEF 設定指南。
- 按一下「確定」儲存設定。
建立記錄檔轉送設定檔
- 依序前往「物件」>「記錄轉送」。
- 按一下「新增」,建立新的記錄轉送設定檔。
- 請提供下列設定詳細資料:
- 名稱:輸入設定檔名稱 (例如
Google SecOps Forwarding)。如要讓防火牆自動將這個設定檔指派給新的安全性規則和區域,請將其命名為default。
- 名稱:輸入設定檔名稱 (例如
- 針對要轉送的每個記錄類型 (流量、威脅、WildFire 提交、網址篩選、資料篩選、通道、驗證),請設定下列項目:
- 在對應的記錄類型部分中,按一下「新增」。
- 「Syslog」Syslog:選取您建立的 Syslog 伺服器設定檔 (例如
Google SecOps BindPlane)。 - 記錄嚴重程度:選取要轉送的嚴重程度等級 (例如「全部」)。
- 按一下「確定」,儲存記錄轉送設定檔。
將記錄轉送設定檔套用至安全性政策
- 依序前往「政策」>「安全性」。
- 選取要啟用記錄轉送的安全規則。
- 按一下規則即可編輯。
- 前往「動作」分頁。
- 在「記錄檔轉送」選單中,選取您建立的記錄檔轉送設定檔 (例如
Google SecOps Forwarding)。 - 按一下「確定」,儲存安全性政策設定。
設定系統記錄的記錄設定
- 依序點選「裝置」>「記錄設定」。
- 針對每種記錄類型 (系統、設定、使用者 ID、HIP 比對、Global Protect、IP 標記、SCTP) 和嚴重程度,選取您建立的系統記錄伺服器設定檔。
- 按一下「確定」儲存記錄設定。
修訂變更
- 按一下防火牆網頁介面頂端的「Commit」。
- 等待提交作業順利完成。
- 檢查 Google SecOps 控制台是否有傳入的 Palo Alto Networks 防火牆記錄,確認記錄已傳送至 Bindplane 代理程式。
使用 Bindplane 代理程式將記錄轉送至 Google SecOps
- 安裝並設定 Linux 虛擬機器。
- 在 Linux 上安裝及設定 Bindplane 代理程式,將記錄轉寄至 Google SecOps。如要進一步瞭解如何安裝及設定 Bindplane 代理程式,請參閱 Bindplane 代理程式安裝及設定說明。
如果在建立動態饋給時遇到問題,請與 Google SecOps 支援團隊聯絡。
支援的記錄格式
Palo Alto Networks 防火牆剖析器支援 LEEF、CEF 和 CSV 格式的記錄。
支援的範例記錄
LEEF
<14>Jan 22 02:20:19 device_host LEEF:1.0|Palo Alto Networks|PAN-OS Syslog Integration|10.2.12-h4|Microsoft MSOFFICE(52033)|ReceiveTime=2025/01/22 02:20:18|SerialNumber=01250100xxxx|cat=THREAT|Subtype=wildfire|devTime=Jan 22 2025 08:20:18 GMT|src=198.50.100.1|dst=198.50.100.2|srcPostNAT=198.50.100.3|dstPostNAT=198.50.100.4|RuleName=AZURE-US-NEW-CNF_Inbound_To_Azure-ALLOW|usrName=|SourceUser=|DestinationUser=|Application=smtp-base|VirtualSystem=vsys1|SourceZone=McD-Global-Zone|DestinationZone=Azure-Zone|IngressInterface=ae1.111|EgressInterface=ae2.409|LogForwardingProfile=Default-Traffic-Logging|SessionID=35331795|RepeatCount=1|srcPort=21578|dstPort=25|srcPostNATPort=0|dstPostNATPort=0|Flags=0x2000|proto=tcp|action=allow|Miscellaneous=\"......3...................xls\"|ThreatID=Microsoft MSOFFICE(52033)|URLCategory=malicious|sev=4|Severity=high|Direction=client-to-server|sequence=7462614601465681755|ActionFlags=0x8000000000000000|SourceLocation=198.50.100.1-198.50.100.255|DestinationLocation=United States|ContentType=|PCAP_ID=0|FileDigest=0ea04c99bf188c2e4207f60f92ca7c6f5088c7943ee63f45c50032bbd2bf7ea9|Cloud=demo.com|URLIndex=1|RequestMethod=|FileType=ms-office|Sender=sender@ab.myownpersonaldomain.com|Subject=\"............:.................................................................................-.........(Name)-2025-01-22...............:Y107202501220005, ............:........................, ...............:.........\"|Recipient=abc@demo.myownpersonaldomain.com|ReportID=117022282776|DeviceGroupHierarchyL1=143|DeviceGroupHierarchyL2=144|DeviceGroupHierarchyL3=39|DeviceGroupHierarchyL4=0|vSrcName=|DeviceName=device_host|SrcUUID=|DstUUID=|TunnelID=0|MonitorTag=|ParentSessionID=0|ParentStartTime=|TunnelType=N/A|ThreatCategory=N/A|ContentVer=WildFire-0CEF
14>1 2024-04-04T16:21:56+02:00 FW-PERIMETRAL-AVG-01 - - - - CEF:0|Palo Alto Networks|PAN-OS|10.1.10-h2|end|TRAFFIC|1|src=198.51.100.1 dst=198.51.100.2 srcTranslatedAddress=198.51.100.3 dstTranslatedAddress=198.51.100.4 rule=FW_USER_NATS2_APP suser= duser= app=bittorrent vs=vsys1 sz=INSIDE dz=EXTERNAL InboundInterface=ae2.2266 OutboundInterface=ae1 lp=log_forwarding sid=2935823 cnt=1 spt=6881 dpt=51413 srcTranslatedPort=0 dstTranslatedPort=0 flags=0x7a proto=udp act=allow tbytes=475 in=150 out=325 pkt=2 pktReceived=1 pktSent=1 start=Apr 04 2024 14:21:56 GMT stime=1206 urlcat=any externalId=externalId reason=aged-out DGl1=11 DGl2=161 DGl3=0 DGl4=0 VsysName=STONESOFT dvchost=FW-PERIMETRAL-AVG-01 cat=from-policy ActionFlags=0x8000000000000000 srcUUID= dstUUID= TunnelID=0 MonitorTag= ParentSessionID=0 ParentStartTime= TunnelType=N/A SCTPAssocID=0 SCTPChunks=0 SCTPChunkSent=0 SCTPChunksRcv=0 RuleUUID=746c3eb6-3d51-4679-8438-bd0e00e170a8 HTTP2Con=0 LinkChange=0 PolicyID= LinkDetail= SDWANCluster= SDWANDevice= SDWANClustype= SDWANSite= DynamicUsrgrp= XFFIP= srcDevCat= srcDevProf= srcDevModel= srcDevVendor= srcDevOS= srcDevOSv= srcHostname= srcMac= dstDevCat= dstDevProf= dstDevModel= dstDevVendor= dstDevOS= dstDevOSv= dstHostname= dstMac= ContainerName= PODNamespace= PODName= srcEDL= dstEDL= GPHostID= EPSerial= srcDAG= dstDAG= HASessionOwner= TimeHighRes=2024-04-04T16:21:56.250+02:00 ASServiceType= ASServiceDiff="CSV
1,2021/10/24 15:30:07,,CONFIG,0,2561,2021/10/24 15:30:07,198.51.100.0,,set,admin,Web,Succeeded, network virtual-router VR1,,VR1 { ecmp { algorithm { ip-modulo ; } } protocol { bgp { routing-options { graceful-restart { enable yes; } } enable no; } rip { enable no; } ospf { enable no; } ospfv3 { enable no; } } routing-table { ip { static-route { vr1-log { path-monitor { enable no; failure-condition any; hold-time 2; } nexthop { ip-address 198.51.100.0; } bfd { profile None; } interface ethernet1/1; metric 10; destination 0.0.0.0/0; route-table { unicast ; } } } } } interface [ ethernet1/1 ethernet1/2 ]; } ,7022390503849066572,0x0,0,0,0,0,,PA-VM,0,
欄位對應參考資料:記錄欄位對應至 UDM 欄位
本節說明剖析器如何將 Palo Alto Networks 防火牆記錄欄位對應至各記錄類型的 Google SecOps UDM 事件欄位。Google SecOps 標籤鍵是指對應至 Labels.key UDM 欄位的鍵名稱。
舉例來說,如果是「虛擬系統」欄位,欄位名稱在 CEF 格式中為「cs3」,在 LEEF 格式中則為「VirtualSystem」。UDM 欄位「about.labels.key」包含值「vsys」,而 UDM 欄位「about.labels.value」包含該欄位的值。部分 CEF 或 LEEF 欄位名稱沒有對應的 CSV 欄位名稱。在這種情況下,如果您在系統記錄檔設定檔的自訂記錄格式中加入自己的變數名稱,剖析器不會將該名稱對應至 UDM 欄位。
如需各記錄類型的對應參考資料,請參閱下列章節:
系統
下表列出系統記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|
| 序號 (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number intermediary.asset.hardware.serial_number |
|
| 類型 (型別) | type (Header) | cat | metadata.product_event_type 已設為「%{type} - %{subtype}」。 | |
| 威脅/內容類型 (子類型) | 子類型 (標題) | 子類型 | metadata.product_event_type 已設為「%{type} - %{subtype}」。 | |
| 產生時間 (time_generated 或 cef-formatted-time_generated) | metadata.event_timestamp | |||
| 虛擬系統 (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value intermediary.asset.attribute.labels.key/value |
| 事件 ID (eventid) | cat | eventid | additional.fields.key 和 additional.fields.value.string_value | |
| 物件 (物件) | fname | 檔案名稱 | object | target.resource.name |
| 模組 (module) | flexString2 | Module | 模組 | additional.fields.key 和 additional.fields.value.string_value |
| 嚴重性 (severity) | $number-of-severity(header) | 嚴重性 | security_result.severity 和 security_result.severity_details | |
| 說明 (不透明) | msg | msg | metadata.description | |
| principal_user_userid (這個欄位是從 msg 欄位擷取) | principal.user.userid | |||
| principal_ip3 (這個欄位是從 msg 欄位擷取) | principal.ip | |||
| 原因 (這個欄位是從 msg 欄位擷取) | security_result.description | |||
| server_address (這個欄位是從 msg 欄位擷取而來) | target.ip | |||
| server_profile (這個欄位是從 msg 欄位擷取而來) | additional.fields.key 和 additional.fields.value.string_value | |||
| 序號 (seqno) | externalId | sequence | metadata.product_log_id | |
| 動作旗標 (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_1 至 dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value |
| 虛擬系統名稱 (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value intermediary.asset.attribute.labels.key/value |
|
| 裝置名稱 (device_name) | dvchost | DeviceName | target.hostname intermediary.hostname |
|
| 高解析度時間戳記 (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key 和 additional.fields.value.string_value |
設定
下表列出設定記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|
| 序號 (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number intermediary.asset.hardware.serial_number |
|
| 類型 (型別) | type (Header) | cat | metadata.product_event_type | |
| 威脅/內容類型 (子類型) | 子類型 (標題) | metadata.product_event_type | ||
| 產生時間 (time_generated 或 cef-formatted-time_generated) | metadata.event_timestamp | |||
| 主機 (host) | shost | src | principal.ip/hostname | |
| 虛擬系統 (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value intermediary.asset.attribute.labels.key/value |
| 指令 (cmd) | act | msg | cmd | principal.process.command_line |
| 管理員 (admin) | duser | usrName | principal.user.userid | |
| 用戶端 (用戶端) | destinationServiceName | 用戶端 | principal.application | |
| 結果 (結果) | 簽章 ID (標頭)(原因) | 結果 | security_result.summary | |
| 設定路徑 (路徑) | msg | ConfigurationPath | principal.process.command_line | |
| 變更前詳細資料 (before_change_detail) | cs1 | BeforeChangeDetail | before_change_detail | target.resource.attribute.labels.key/value |
| 變更詳細資料 (after_change_detail) | cs2 | AfterChangeDetail | after_change_detail | target.resource.attribute.labels.key/value |
| 序號 (seqno) | externalId | sequence | metadata.product_log_id | |
| 動作旗標 (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_1 至 dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value |
| 虛擬系統名稱 (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value intermediary.asset.attribute.labels.key/value |
|
| 裝置名稱 (device_name) | dvchost | DeviceName | target.hostname intermediary.hostname |
|
| 裝置群組 (dg_id) | PanOSFWDeviceGroup | dg_id | target.asset.attribute.labels.key/value | |
| 稽核註解 (註解) | PanOSPolicyAuditComment | 註解 | additional.fields.key 和 additional.fields.value.string_value | |
| 高解析度時間戳記 (high_res_timestamp) | additional.fields.key 和 additional.fields.value.string_value | |||
| 嚴重性 (severity) | number-of-severity(header) | security_result.severity 和 security_result.severity_details |
威脅/WildFire
下表列出 Threat/WildFire 記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|
| 序號 (序號) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| 類型 (type) | type (Header) | cat | metadata.product_event_type | |
| 威脅/內容類型 (子類型) | cat/subtype (Header) | 子類型 | metadata.product_event_type | |
| 產生時間 (time_generated 或 cef-formatted-time_generated) | metadata.event_timestamp | |||
| 來源地址 (src) | src | src | principal.ip | |
| 目的地地址 (dst) | dst | dst | target.ip | |
| NAT 來源 IP (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| 網路位址轉譯 (NAT) 目的地 IP (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| 規則名稱 (規則) | cs1 | RuleName | security_result.rule_name | |
| 來源使用者 (srcuser) | suser | SourceUser / usrName | principal.user.userid | |
| 目的地使用者 (dstuser) | duser | DestinationUser | target.user.userid | |
| 應用程式 (app) | 應用程式 | 應用程式 | target.application | |
| 虛擬系統 (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| 來源區域 (從) | cs4 | SourceZone | 從 | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 目的地 (到) | cs5 | DestinationZone | 到 | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 傳入介面 (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 傳出介面 (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 記錄動作 (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key 和 additional.fields.value.string_value |
| 工作階段 ID (sessionid) | cn1 | SessionID | network.session_id | |
| 重複次數 (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key 和 additional.fields.value.string_value |
| 來源通訊埠 (sport) | spt | srcPort | principal.port | |
| 目的地通訊埠 (dport) | dpt | dstPort | target.port | |
| NAT 來源通訊埠 (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| NAT 目的地通訊埠 (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| 旗標 (flags) | flexString1 | 旗標 | flags | additional.fields.key 和 additional.fields.value.string_value |
| IP 通訊協定 (proto) | proto | proto | network.ip_protocol | |
| 動作 (動作) | act | action | security_result.action_details
security_result.action |
|
| 網址/檔案名稱 (其他) | 要求 | 其他 | target.file.names (如果子類型為「file」、「virus」、「wildfire-virus」或「wildfire」,則 `misc` 欄位會對應至 target.file.names) target.url (如果子類型為「url」,則 `misc` 欄位會對應至 target.url 和 target.hostname) |
|
| 威脅/內容名稱 (threatid) | cat | ThreatID | security_result.threat_name | |
| 類別 (類別) | cs2 | URLCategory | security_result.category_details | |
| 嚴重性 (severity) | number-of-severity(header) | 嚴重性 | security_result.severity 和 security_result.severity_details | |
| 方向 (方向) | flexString2 | 方向 | network.direction | |
| 序號 (seqno) | externalId | sequence | metadata.product_log_id | |
| 動作旗標 (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value |
| 來源國家/地區 (srcloc) | SourceLocation | principal.location.country_or_region | ||
| 目的地國家/地區 (dstloc) | DestinationLocation | target.location.country_or_region | ||
| 內容類型 (contenttype) | ContentType | contenttype | additional.fields.key 和 additional.fields.value.string_value | |
| PCAP ID (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key 和 additional.fields.value.string_value |
| 檔案摘要 (filedigest) | fileHash | FileDigest | target.file.sha1/md5/sha256 | |
| Cloud (cloud) | filePath | Cloud | cloud | additional.fields.key 和 additional.fields.value.string_value |
| 網址索引 (url_idx) | URLIndex | url_idx | additional.fields.key 和 additional.fields.value.string_value | |
| 使用者代理程式 (user_agent) | network.http.user_agent | |||
| 檔案類型 (filetype) | fileType | FileType | target.file.mime_type | |
| X-Forwarded-For (xff) | principal.ip | |||
| 參照網址 (referer) | network.http.referral_url | |||
| 寄件者 (寄件者) | suid | 寄件者 | network.email.from | |
| 主旨 (subject) | msg | 主旨 | network.email.subject | |
| 收件者 (recipient) | duid | 收件者 | network.email.to | |
| 報表 ID (reportid) | oldFileId | ReportID | reportid | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_1 至 dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value |
| 虛擬系統名稱 (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| 裝置名稱 (device_name) | dvchost | DeviceName | intermediary.hostname | |
| 來源 VM UUID (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id | |
| 目的地 VM UUID (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id | |
| HTTP 方法 (http_method) | RequestMethod | network.http.method | ||
| 通道 ID/IMSI (tunnel_id/imsi) | PanOSTunnelID | TunnelID | tunnel_id/imsi | additional.fields.key 和 additional.fields.value.string_value |
| 監控標籤/IMEI (monitortag/imei) | PanOSMonitorTag | MonitorTag | monitortag/imei | additional.fields.key 和 additional.fields.value.string_value |
| 父項工作階段 ID (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| 父項工作階段開始時間 (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key 和 additional.fields.value.string_value |
| 通道類型 (通道) | PanOSTunnelType | TunnelType | 通道 | additional.fields.key 和 additional.fields.value.string_value |
| 威脅類別 (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| 內容版本 (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key 和 additional.fields.value.string_value |
| SCTP 關聯 ID (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key 和 additional.fields.value.string_value | |
| 酬載通訊協定 ID (ppid) | PanOSPPID | ppid | additional.fields.key 和 additional.fields.value.string_value | |
| HTTP 標頭 (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| 網址類別清單 (url_category_list) | PanOSURLCatList | url_category_list | additional.fields.key 和 additional.fields.value.string_value | |
| 規則 UUID (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| HTTP/2 連線 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| 動態使用者群組名稱 (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| XFF 位址 (xff_ip) | PanXFFIP | principal.ip | ||
| 來源裝置類別 (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| 來源裝置設定檔 (src_profile) | PanSrcDeviceProf | src_profile | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| 來源裝置型號 (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| 來源裝置供應商 (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| 來源裝置 OS 系列 (src_osfamily) | PanSrcDeviceOS | src_osfamily | principal.platform | |
| 來源裝置 OS 版本 (src_osversion) | PanSrcDeviceOSv | principal.platform_version | ||
| 來源主機名稱 (src_host) | PanSrcHostname | principal.hostname | ||
| 來源 MAC 位址 (src_mac) | PanSrcMac | principal.mac | ||
| 目的地裝置類別 (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| 目的地裝置設定檔 (dst_profile) | PanDstDeviceProf | dst_profile | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| 目的地裝置型號 (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| 目的地裝置供應商 (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| 目的地裝置 OS 系列 (dst_osfamily) | PanDstDeviceOS | dst_osfamily | target.platform | |
| 目的地裝置 OS 版本 (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| 目的地主機名稱 (dst_host) | PanDstHostname | target.hostname | ||
| 目的地 MAC 位址 (dst_mac) | PanDstMac | target.mac | ||
| 容器 ID (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| POD 命名空間 (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| POD 名稱 (pod_name) | PanPODName | pod_name | target.resource.name | |
| 來源外部動態清單 (src_edl) | PanSrcEDL | src_edl | additional.fields.key 和 additional.fields.value.string_value | |
| 目標外部動態清單 (dst_edl) | PanDstEDL | dst_edl | additional.fields.key 和 additional.fields.value.string_value | |
| 主機 ID (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| 使用者裝置序號 (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| 網域 EDL (domain_edl) | PanDomainEDL | domain_edl | additional.fields.key 和 additional.fields.value.string_value | |
| 來源動態位址群組 (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| 目的地動態地址群組 (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| 部分雜湊 (partial_hash) | PanPartialHash | partial_hash | additional.fields.key 和 additional.fields.value.string_value | |
| 高解析度時間戳記 (high_res timestamp) | PanTimeHighRes | 高解析度時間戳記 | additional.fields.key 和 additional.fields.value.string_value | |
| 原因 (原因) | PanReasonFilteringAction | 原因 | security_result.summary | |
| 理由 (理由) | PanJustification | 理由 | additional.fields.key 和 additional.fields.value.string_value | |
| 區塊服務類型 (nssai_sst) | PanASServiceType | nssai_sst | additional.fields.key 和 additional.fields.value.string_value | |
| 應用程式子類別 (subcategory_of_app) | subcategory_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式類別 (category_of_app) | category_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式技術 (technology_of_app) | technology_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式風險 (risk_of_app) | risk_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式特徵 (characteristic_of_app) | characteristic_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式容器 (container_of_app) | container_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式 SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 通道應用程式 (tunneled_app) | additional.fields.key 和 additional.fields.value.string_value | |||
| 流程類型 (flow_type) | additional.fields.key 和 additional.fields.value.string_value | |||
| 叢集名稱 (cluster_name) | intermediary.resource.name | |||
| 應用程式受制裁狀態 (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key 和 additional.fields.value.string_value |
流量
下表列出流量記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|
| 序號 (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| 類型 (type) | type (Header) | cat/Type | metadata.product_event_type | |
| 威脅/內容類型 (子類型) | 子類型 (標題) | 子類型 | metadata.product_event_type | |
| 產生時間 (time_generated 或 cef-formatted-time_generated) | start | metadata.event_timestamp | ||
| 來源地址 (src) | src | src | principal.ip | |
| 目的地地址 (dst) | dst | dst | target.ip | |
| NAT 來源 IP (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| 網路位址轉譯 (NAT) 目的地 IP (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| 規則名稱 (規則) | cs1 | RuleName | security_result.rule_name | |
| 來源使用者 (srcuser) | suser | SourceUser | principal.user.userid | |
| 目的地使用者 (dstuser) | duser | DestinationUser | target.user.userid | |
| 應用程式 (app) | 應用程式 | 應用程式 | target.application | |
| 虛擬系統 (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| 來源區域 (從) | cs4 | SourceZone | 從 | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 目的地 (到) | cs5 | DestinationZone | 到 | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 傳入介面 (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 傳出介面 (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 記錄動作 (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key 和 additional.fields.value.string_value |
| 工作階段 ID (sessionid) | cn1 | SessionID | network.session_id | |
| 重複次數 (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key 和 additional.fields.value.string_value |
| 來源通訊埠 (sport) | spt | srcPort | principal.port | |
| 目的地通訊埠 (dport) | dpt | dstPort | target.port | |
| NAT 來源通訊埠 (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| NAT 目的地通訊埠 (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| 旗標 (flags) | flexString1 | 旗標 | flags | additional.fields.key 和 additional.fields.value.string_value |
| IP 通訊協定 (proto) | proto | proto | network.ip_protocol | |
| 動作 (動作) | act | action | security_result.action_details
security_result.action |
|
| 位元組 (位元組) | flexNumber1 | totalBytes | 位元組 | additional.fields.key 和 additional.fields.value.string_value |
| 傳送的位元組 (bytes_sent) | in | srcBytes | network.sent_bytes | |
| 收到的位元組 (bytes_received) | out | dstBytes | network.received_bytes | |
| 封包 (封包) | cn2 | totalPackets | 封包 | additional.fields.key 和 additional.fields.value.string_value |
| 開始時間 (開始) | StartTime | start | additional.fields.key 和 additional.fields.value.string_value | |
| 經過時間 (elapsed) | cn3 | ElapsedTime | 經過時間 | network.session_duration.seconds |
| 類別 (類別) | cs2 | URLCategory | security_result.category / security_result.category_details | |
| 序號 (seqno) | externalId | sequence | metadata.product_log_id | |
| 動作旗標 (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value |
| 來源國家/地區 (srcloc) | SourceLocation | principal.location.country_or_region | ||
| 目的地國家/地區 (dstloc) | DestinationLocation | target.location.country_or_region | ||
| 傳送的封包數 (pkts_sent) | PanOSPacketsSent | srcPackets | pkts_sent | network.sent_packets |
| 接收的封包數 (pkts_received) | PanOSPacketsReceived | dstPackets | pkts_received | network.received_packets |
| 工作階段結束原因 (session_end_reason) | 原因 | SessionEndReason | security_result.summary | |
| 裝置群組階層 1 (dg_hier_level_1 至 dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 2 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 3 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value |
| 虛擬系統名稱 (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| 裝置名稱 (device_name) | dvchost | DeviceName | intermediary.hostname | |
| 動作來源 (action_source) | cat | ActionSource | action_source | additional.fields.key 和 additional.fields.value.string_value |
| 來源 VM UUID (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id | |
| 目的地 VM UUID (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id | |
| 通道 ID/IMSI (tunnelid/imsi) | PanOSTunnelID | TunnelID | tunnelid/imsi | additional.fields.key 和 additional.fields.value.string_value |
| 監控標籤/IMEI (monitortag/imei) | PanOSMonitorTag | MonitorTag | monitortag/imei | additional.fields.key 和 additional.fields.value.string_value |
| 父項工作階段 ID (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| 父項開始時間 (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key 和 additional.fields.value.string_value |
| 通道類型 (通道) | PanOSTunnelType | TunnelType | 通道 | additional.fields.key 和 additional.fields.value.string_value |
| SCTP 關聯 ID (assoc_id) | PanOSSCTPAssocID | assoc_id | additional.fields.key 和 additional.fields.value.string_value | |
| SCTP 區塊 (區塊) | PanOSSCTPChunks | chunks | additional.fields.key 和 additional.fields.value.string_value | |
| 傳送的 SCTP 區塊 (chunks_sent) | PanOSSCTPChunkSent | chunks_sent | additional.fields.key 和 additional.fields.value.string_value | |
| 收到的 SCTP 區塊 (chunks_received) | PanOSSCTPChunksRcv | chunks_received | additional.fields.key 和 additional.fields.value.string_value | |
| 規則 UUID (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| HTTP/2 連線 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| 應用程式拍動次數 (link_change_count) | PanLinkChange | link_change_count | additional.fields.key 和 additional.fields.value.string_value | |
| 政策 ID (policy_id) | PanPolicyID | policy_id | additional.fields.key 和 additional.fields.value.string_value | |
| 連結切換 (link_switches) | PanLinkDetail | link_switches | additional.fields.key 和 additional.fields.value.string_value | |
| SD-WAN 叢集 (sdwan_cluster) | PanSDWANCluster | sdwan_cluster | additional.fields.key 和 additional.fields.value.string_value | |
| SD-WAN 裝置類型 (sdwan_device_type) | PanSDWANDevice | sdwan_device_type | additional.fields.key 和 additional.fields.value.string_value | |
| SD-WAN 叢集類型 (sdwan_cluster_type) | PanSDWANClustype | sdwan_cluster_type | additional.fields.key 和 additional.fields.value.string_value | |
| SD-WAN 網站 (sdwan_site) | PanSDWANSite | sdwan_site | additional.fields.key 和 additional.fields.value.string_value | |
| 動態使用者群組名稱 (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | additional.fields.key 和 additional.fields.value.string_value | |
| XFF 位址 (xff_ip) | PanXFFIP | principal.ip | ||
| 來源裝置類別 (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| 來源裝置設定檔 (src_profile) | PanSrcDeviceProf | src_profile | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| 來源裝置型號 (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| 來源裝置供應商 (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| 來源裝置 OS 系列 (src_osfamily) | PanSrcDeviceOS | principal.platform | ||
| 來源裝置 OS 版本 (src_osversion) | PanSrcDeviceOSv | principal.asset.software.version | ||
| 來源主機名稱 (src_host) | PanSrcHostname | principal.hostname | ||
| 來源 MAC 位址 (src_mac) | PanSrcMac | principal.mac | ||
| 目的地裝置類別 (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| 目的地裝置設定檔 (dst_profile) | PanDstDeviceProf | dst_profile | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| 目的地裝置型號 (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| 目的地裝置供應商 (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| 目的地裝置 OS 系列 (dst_osfamily) | PanDstDeviceOS | dst_osfamily | target.platform | |
| 目的地裝置 OS 版本 (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| 目的地主機名稱 (dst_host) | PanDstHostname | target.hostname | ||
| 目的地 MAC 位址 (dst_mac) | PanDstMac | target.mac | ||
| 容器 ID (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| POD 命名空間 (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| POD 名稱 (pod_name) | PanPODName | pod_name | target.resource.name | |
| 來源外部動態清單 (src_edl) | PanSrcEDL | src_edl | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| 目標外部動態清單 (dst_edl) | PanDstEDL | dst_edl | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| 主機 ID (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| 使用者裝置序號 (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| 來源動態位址群組 (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| 目的地動態地址群組 (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| 工作階段擁有者 (session_owner) | PanHASessionOwner | session_owner | additional.fields.key 和 additional.fields.value.string_value | |
| 高解析度時間戳記 (high_res_timestamp) | PanTimeHighRes | additional.fields.key 和 additional.fields.value.string_value | ||
| 切片服務類型 (nsdsai_sst) | PanASServiceType | nsdsai_sst | additional.fields.key 和 additional.fields.value.string_value | |
| Slice 差異化指標 (nsdsai_sd) | PanASServiceDiff | nsdsai_sd | additional.fields.key 和 additional.fields.value.string_value | |
| 應用程式子類別 (subcategory_of_app) | subcategory_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式類別 (category_of_app) | category_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式技術 (technology_of_app) | technology_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式風險 (risk_of_app) | security_result.severity | |||
| 應用程式特徵 (characteristic_of_app) | characteristic_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式容器 (container_of_app) | container_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式 SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式受制裁狀態 (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式子類別 (subcategory_of_app) | subcategory_of_app1 | additional.fields.key 和 additional.fields.value.string_value | ||
| 嚴重性 (severity) | number-of-severity(header) | security_result.severity 和 security_result.severity_details |
User-ID
下表列出使用者 ID 記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|
| 序號 (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| 類型 (type) | type (Header) | cat | metadata.product_event_type | |
| 威脅/內容類型 (子類型) | 子類型 (標題) | 子類型 | metadata.product_event_type | |
| 產生時間 (time_generated 或 cef-formatted-time_generated) | metadata.event_timestamp | |||
| 虛擬系統 (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| 來源 IP (ip) | src | src | principal.ip | |
| 使用者 (使用者) | duser | usrName | target.user.userid
target.administrative_domain target.user.email_addresses |
|
| 資料來源名稱 (datasourcename) | cs4 | DataSourceName | datasourcename | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 事件 ID (eventid) | EventID | eventid | additional.fields.key 和 additional.fields.value.string_value | |
| 重複次數 (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key 和 additional.fields.value.string_value |
| 逾時門檻 (逾時) | cn3 | TimeoutThreshold | 逾時 | additional.fields.key 和 additional.fields.value.string_value |
| 來源通訊埠 (beginport) | spt | srcPort | principal.port | |
| 目的地通訊埠 (endport) | dpt | dstPort | target.port | |
| 資料來源 (datasource) | cs5 | DataSource | 資料來源 | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 資料來源類型 (datasourcetype) | cs6 | DataSourceType | datasourcetype | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 序號 (seqno) | externalId | sequence | metadata.product_log_id | |
| 動作旗標 (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value |
| 虛擬系統名稱 (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| 裝置名稱 (device_name) | dvchost | DeviceName | intermediary.hostname | |
| 虛擬系統 ID (vsys_id) | cn2 | VirtualSystemID | intermediary.resource.product_object_id | |
| 因素類型 (factortype) | cs1 | FactorType | factortype | additional.fields.key 和 additional.fields.value.string_value |
| 因子完成時間 (factorcompletiontime) | end | FactorCompletionTime | factorcompletiontime | additional.fields.key 和 additional.fields.value.string_value |
| 因素編號 (factorno) | cn1 | FactorNumber | factorno | additional.fields.key 和 additional.fields.value.string_value |
| 使用者群組標記 (ugflags) | PanOSUGFlags | ugflags | additional.fields.key 和 additional.fields.value.string_value | |
| 使用者 (按來源區隔) (userbysource) | PanOSUserBySource | target.user.userid
target.administrative_domain target.user.email_addresses |
||
| 高解析度時間戳記 (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key 和 additional.fields.value.string_value | ||
| 原始資料來源 (origindatasource) | additional.fields.key 和 additional.fields.value.string_value | |||
| 叢集名稱 (cluster_name) | principal.resource.name | |||
| 嚴重性 (severity) | number-of-severity(header) | security_result.severity 和 security_result.severity_details |
HIP 比對
下表列出 HIP 比對記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|
| 序號 (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number intermediary.asset.hardware.serial_number |
|
| 類型 (型別) | type (Header) | cat | metadata.product_event_type | |
| 威脅/內容類型 (子類型) | 子類型 (標題) | 子類型 | ||
| 產生時間 (time_generated 或 cef-formatted-time_generated) | start | startTime | metadata.event_timestamp | |
| 來源使用者 (srcuser) | suser | usrName | principal.user.userid | |
| 虛擬系統 (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value intermediary.asset.attribute.labels.key/value |
| 電腦名稱 (machinename) | shost | identHostName | principal.hostname | |
| 作業系統 (os) | cs2 | 作業系統 | principal.asset.platform_software.platform | |
| 來源地址 (src) | src | identsrc | principal.ip | |
| HIP (matchname) | cat | HIP | matchname | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 重複次數 (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key 和 additional.fields.value.string_value |
| HIP 類型 (matchtype) | 裝置事件類別 ID (標頭) | HIPType | matchtype | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 序號 (seqno) | externalId | sequence | metadata.product_log_id | |
| 動作旗標 (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value |
| 虛擬系統名稱 (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value intermediary.asset.attribute.labels.key/value |
|
| 裝置名稱 (device_name) | dvchost | DeviceName | target.hostname intermediary.hostname |
|
| 虛擬系統 ID (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id intermediary.resource.product_object_id |
|
| IPv6 系統位址 (srcipv6) | c6a2 | srcipv6 | principal.asset.ip | |
| 主機 ID (hostid) | PanOSHostID | principal.asset.asset_id | ||
| 使用者裝置序號 (serialnumber) | PanOSEndpointSerialNumber | principal.asset.hardware.serial_number | ||
| 裝置 MAC 位址 (mac) | PanOSEndpointMac | principal.asset.mac | ||
| 高解析度時間戳記 (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key 和 additional.fields.value.string_value | ||
| 叢集名稱 (cluster_name) | principal.resource.name | |||
| 嚴重性 (severity) | number-of-severity(header) | security_result.severity 和 security_result.severity_details |
IP 標記
下表列出 IP 標記記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|
| 序號 (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number intermediary.asset.hardware.serial_number |
|
| 類型 (型別) | type (Header) | cat | metadata.product_event_type | |
| 威脅/內容類型 (子類型) | 子類型 (標題) | 子類型 | metadata.product_event_type | |
| 產生時間 (time_generated 或 cef-formatted-time_generated) | GenerateTime | metadata.event_timestamp | ||
| 虛擬系統 (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value intermediary.asset.attribute.labels.key/value |
| 來源 IP (ip) | src | src | principal.ip | |
| 代碼名稱 (tag_name) | PanOSTagName | TagName | tag_name | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 活動 ID (event_id) | PanOSEventID | EventID | event_id | additional.fields.key 和 additional.fields.value.string_value |
| 重複次數 (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key 和 additional.fields.value.string_value |
| 逾時 (逾時) | PanOSTimeout | TimeoutThreshold | 逾時 | additional.fields.key 和 additional.fields.value.string_value |
| 資料來源名稱 (datasourcename) | PanOSDataSourceName | DataSourceName | datasourcename | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 資料來源類型 (datasource_type) | PanOSDataSourceType | DataSource | datasource_type | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 資料來源子類型 (datasource_subtype) | PanOSDataSourceSubType | DataSourceType | datasource_subtype | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 序號 (seqno) | externalId | sequence | metadata.product_log_id | |
| 動作旗標 (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value |
| 虛擬系統名稱 (vsys_name) | PanOsVsysName | vSrcName | target.asset.attribute.labels.key/value intermediary.asset.attribute.labels.key/value |
|
| 裝置名稱 (device_name) | dvchost | DeviceName | target.hostname intermediary.hostname |
|
| 虛擬系統 ID (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id intermediary.resource.product_object_id |
|
| 高解析度時間戳記 (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key 和 additional.fields.value.string_value | ||
| 嚴重性 (severity) | number-of-severity(header) | security_result.severity 和 security_result.severity_details | ||
| 叢集名稱 (cluster_name) | principal.resource.name |
解密
下表列出解密記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | rt | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
||
| 序號 (serial) | PanOSDeviceSN | intermediary.asset.hardware.serial_number | ||
| 類型 (type) | type (Header) | metadata.product_event_type | ||
| 威脅/內容類型 (子類型) | 子類型 (標題) | metadata.product_event_type | ||
| 設定版本 (config_ver) | PanOSConfigVersion | config_ver | additional.fields.key 和 additional.fields.value.string_value | |
| 產生時間 (time_generated) | PanOSLogTimeStamp | metadata.event_timestamp | ||
| 來源地址 (src) | src | principal.ip | ||
| 目的地地址 (dst) | dst | target.ip | ||
| NAT 來源 IP (natsrc) | sourceTranslatedAddress | principa.nat_ip | ||
| 網路位址轉譯 (NAT) 目的地 IP (natdst) | destinationTranslatedAddress | target.nat_ip | ||
| 規則 (規則) | cs1 | security_result.rule_name | ||
| 來源使用者 (srcuser) | suser | principal.user.userid | ||
| 目的地使用者 (dstuser) | duser | target.user.userid | ||
| 應用程式 (app) | 應用程式 | network.application_protocol | ||
| 虛擬系統 (vsys) | cs3 | vsys | intermediary.asset.attribute.labels.key/value | |
| 來源區域 (從) | cs4 | 從 | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| 目的地 (到) | cs5 | 到 | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| 傳入介面 (inbound_if) | deviceInboundInterface | inbound_if | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| 傳出介面 (outbound_if) | deviceOutboundInterface | outbound_if | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| 記錄動作 (logset) | cs6 | logset | additional.fields.key 和 additional.fields.value.string_value | |
| 記錄時間 (time_received) | PanOSTimeReceivedManagementPlane | - | ||
| 工作階段 ID (sessionid) | cn1 | network.session_id | ||
| 重複次數 (repeatcnt) | PanOSCountOfRepeats/RepeatCount | repeatcnt | additional.fields.key 和 additional.fields.value.string_value | |
| 來源通訊埠 (sport) | spt | principal.port | ||
| 目的地通訊埠 (dport) | dpt | target.port | ||
| NAT 來源通訊埠 (natsport) | sourceTranslatedPort | principal.nat_port | ||
| NAT 目的地通訊埠 (natdport) | destinationTranslatedPort | target.nat_port | ||
| 旗標 (flags) | flexString1 | flags | additional.fields.key 和 additional.fields.value.string_value | |
| IP 通訊協定 (proto) | proto | network.ip_protocol | ||
| 動作 (動作) | act | security_result.action_details
security_result.action |
||
| 隧道 (tunnel) | PanOSTunnel | 通道 | additional.fields.key 和 additional.fields.value.string_value | |
| 來源 VM UUID (src_uuid) | PanOSSourceUUID | principal.asset.product_object_id | ||
| 目的地 VM UUID (dst_uuid) | PanOSDestinationUUID | target.asset.product_object_id | ||
| 規則的 UUID (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| 客戶到防火牆階段 (hs_stage_c2f) | PanOSClientToFirewall | hs_stage_c2f | additional.fields.key 和 additional.fields.value.string_value | |
| 防火牆到伺服器階段 (hs_stage_f2s) | PanOSFirewallToServer | hs_stage_f2s | additional.fields.key 和 additional.fields.value.string_value | |
| TLS 版本 (tls_version) | PanOSTLSVersion | network.tls.version | ||
| 金鑰交換演算法 (tls_keyxchg) | PanOSTLSKeyExchange | tls_keyxchg | additional.fields.key 和 additional.fields.value.string_value | |
| 加密演算法 (tls_enc) | PanOSTLSEncryptionAlgorithm | tls_enc | additional.fields.key 和 additional.fields.value.string_value | |
| 雜湊演算法 (tls_auth) | PanOSTLSAuth | tls_auth | additional.fields.key 和 additional.fields.value.string_value | |
| 政策名稱 (policy_name) | PanOSPolicyName | policy_name | additional.fields.key 和 additional.fields.value.string_value | |
| 橢圓曲線 (ec_curve) | PanOSEllipticCurve | network.tls.curve | ||
| 錯誤索引 (err_index) | PanOSErrorIndex | err_index | additional.fields.key 和 additional.fields.value.string_value | |
| 根狀態 (root_status) | PanOSRootStatus | root_status | additional.fields.key 和 additional.fields.value.string_value | |
| 鏈結狀態 (chain_status) | PanOSChainStatus | chain_status | additional.fields.key 和 additional.fields.value.string_value | |
| Proxy 類型 (proxy_type) | PanOSProxyType | proxy_type | additional.fields.key 和 additional.fields.value.string_value | |
| 憑證序號 (cert_serial) | PanOSCertificateSerial | network.tls.server.certificate.serial | ||
| 憑證指紋 (指紋) | PanOSFingerprint | network.tls.server.certificate.md5/sha1/sha256 | ||
| 憑證開始日期 (notbefore) | PanOSTimeNotBefore | network.tls.server.certificate.not_before | ||
| 憑證結束日期 (notafter) | PanOSTimeNotAfter | network.tls.server.certificate.not_after | ||
| 憑證版本 (cert_ver) | PanOSCertificateVersion | network.tls.server.certificate.version | ||
| 憑證大小 (cert_size) | PanOSCertificateSize | cert_size | additional.fields.key 和 additional.fields.value.string_value | |
| 一般名稱長度 (cn_len) | PanOSCommonNameLength | cn_len | additional.fields.key 和 additional.fields.value.string_value | |
| 核發者通用名稱長度 (issuer_len) | PanOSIssuerNameLength | issuer_len | additional.fields.key 和 additional.fields.value.string_value | |
| 根通用名稱長度 (rootcn_len) | PanOSRootCNLength | rootcn_len | additional.fields.key 和 additional.fields.value.string_value | |
| SNI 長度 (sni_len) | PanOSSNILength | sni_len | additional.fields.key 和 additional.fields.value.string_value | |
| 憑證標記 (cert_flags) | PanOSCertificateFlags | cert_flags | additional.fields.key 和 additional.fields.value.string_value | |
| 主體通用名稱 (cn) | PanOSCommonName | cn | additional.fields.key 和 additional.fields.value.string_value | |
| 核發者通用名稱 (issuer_cn) | PanOSIssuerCommonName | network.tls.server.certificate.issuer | ||
| 根層級通用名稱 (root_cn) | PanOSRootCommonName | root_cn | additional.fields.key 和 additional.fields.value.string_value | |
| 伺服器名稱指示 (sni) |
network.tls.client.server_name | |||
| 錯誤 (錯誤) | PanOSErrorMessage | error | additional.fields.key 和 additional.fields.value.string_value | |
| 容器 ID (container_id) | PanOSContainerID | container_id | intermediary.resource.product_object_id | |
| POD 命名空間 (pod_namespace) | PanOSContainerNameSpace | pod_namespace | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| POD 名稱 (pod_name) | PanOSContainerName | pod_name | target.resource.name | |
| 來源外部動態清單 (src_edl) | PanOSSourceEDL | src_edl | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| 目標外部動態清單 (dst_edl) | PanOSDestinationEDL | dst_edl | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| 來源動態位址群組 (src_dag) | PanOSSourceDynamicAddressGroup | principal.group.group_display_name | ||
| 目的地動態地址群組 (dst_dag) | PanOSDestinationDynamicAddressGroup | target.group.group_display_name | ||
| 高解析度時間戳記 (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key 和 additional.fields.value.string_value | ||
| 來源裝置類別 (src_category) | PanOSSourceDeviceCategory | src_category | principal.asset.category | |
| 來源裝置設定檔 (src_profile) | PanOSSourceDeviceProfile | src_profile | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| 來源裝置型號 (src_model) | PanOSSourceDeviceModel | src_model | principal.asset.hardware.model | |
| 來源裝置供應商 (src_vendor) | PanOSSourceDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| 來源裝置 OS 系列 (src_osfamily) | PanOSSourceDeviceOSFamily | principal.platform | ||
| 來源裝置 OS 版本 (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | ||
| 來源主機名稱 (src_host) | PanOSSourceDeviceHost | principal.hostname | ||
| 來源 MAC 位址 (src_mac) | PanOSSourceDeviceMac | principal.mac | ||
| 目的地裝置類別 (dst_category) | PanOSDestinationDeviceCategory | dst_category | target.asset.category | |
| 目的地裝置設定檔 (dst_profile) | PanOSDestinationDeviceProfile | dst_profile | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| 目的地裝置型號 (dst_model) | PanOSDestinationDeviceModel | dst_model | target.asset.hardware.model | |
| 目的地裝置供應商 (dst_vendor) | PanOSDestinationDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| 目的地裝置 OS 系列 (dst_osfamily) | PanOSDestinationDeviceOSFamily | dst_osfamily | target.platform | |
| 目的地裝置 OS 版本 (dst_osversion) | PanOSDestinationDeviceOSVersion | target.platform_version | ||
| 目的地主機名稱 (dst_host) | PanOSDestinationDeviceHost | target.hostname | ||
| 目的地 MAC 位址 (dst_mac) | PanOSDestinationDeviceMac | target.mac | ||
| 序號 (seqno) | PanOSLogTypeSeqNo | metadata.product_log_id | ||
| 動作旗標 (actionflags) | PanOSActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value | |
| 裝置群組階層 (dg_hier_level_1) | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value | |
| 裝置群組階層 (dg_hier_level_2) | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value | |
| 裝置群組階層 (dg_hier_level_3) | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value | |
| 裝置群組階層 (dg_hier_level_4) | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value | |
| 虛擬系統名稱 (vsys_name) | intermediary.asset.attribute.labels.key/value | |||
| 裝置名稱 (device_name) | intermediary.hostname | |||
| 虛擬系統 ID (vsys_id) | intermediary.resource.product_object_id | |||
| 應用程式子類別 (subcategory_of_app) | subcategory_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式類別 (category_of_app) | category_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式技術 (technology_of_app) | technology_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式風險 (risk_of_app) | security_result.severity | |||
| 應用程式特徵 (characteristic_of_app) | characteristic_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式容器 (container_of_app) | container_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式 SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式受制裁狀態 (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 嚴重性 (severity) | number-of-severity(header) | security_result.severity 和 security_result.severity_details |
隧道
下表列出通道記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|
| 序號 (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| 類型 (type) | type (Header) | cat | metadata.product_event_type | |
| 威脅/內容類型 (子類型) | 子類型 (標題) | 子類型 | metadata.product_event_type | |
| 產生時間 (time_generated 或 cef-formatted-time_generated) | metadata.event_timestamp | |||
| 來源地址 (src) | src | src | principal.ip | |
| 目的地地址 (dst) | dst | dst | target.ip | |
| NAT 來源 IP (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| 網路位址轉譯 (NAT) 目的地 IP (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| 規則名稱 (規則) | cs1 | RuleName | security_result.rule_name | |
| 來源使用者 (srcuser) | suser | SourceUser / usrName | principal.user.userid | |
| 目的地使用者 (dstuser) | duser | DestinationUser | target.user.userid | |
| 應用程式 (app) | 應用程式 | 應用程式 | network.application_protocol | |
| 虛擬系統 (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| 來源區域 (從) | cs4 | SourceZone | 從 | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 目的地 (到) | cs5 | DestinationZone | 到 | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 傳入介面 (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 傳出介面 (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 記錄動作 (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key 和 additional.fields.value.string_value |
| 工作階段 ID (sessionid) | cn1 | SessionID | network.session_id | |
| 重複次數 (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key 和 additional.fields.value.string_value |
| 來源通訊埠 (sport) | spt | srcPort | principal.port | |
| 目的地通訊埠 (dport) | dpt | dstPort | target.port | |
| NAT 來源通訊埠 (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| NAT 目的地通訊埠 (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| 旗標 (flags) | flexString1 | 旗標 | flags | additional.fields.key 和 additional.fields.value.string_value |
| IP 通訊協定 (proto) | proto | proto | network.ip_protocol | |
| 動作 (動作) | act | action | security_result.action_details
security_result.action |
|
| 嚴重性 (severity) | number-of-severity(header) | security_result.severity 和 security_result.severity_details | ||
| 序號 (seqno) | externalId | sequence | metadata.product_log_id | |
| 動作旗標 (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value |
| 來源位置 (srcloc) | principal.location.country_or_region | |||
| 目的地位置 (dstloc) | target.location.country_or_region | |||
| 裝置群組階層 (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value |
| 虛擬系統名稱 (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| 裝置名稱 (device_name) | dvchost | DeviceName | intermediary.hostname | |
| 通道 ID (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key 和 additional.fields.value.string_value |
| 監控標記 (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key 和 additional.fields.value.string_value |
| 父項工作階段 ID (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| 父項開始時間 (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key 和 additional.fields.value.string_value |
| 通道類型 (通道) | cs2 | TunnelType | 通道 | additional.fields.key 和 additional.fields.value.string_value |
| 位元組 (位元組) | flexNumber1 | totalBytes | 位元組 | additional.fields.key 和 additional.fields.value.string_value |
| 傳送的位元組 (bytes_sent) | in | srcBytes | network.sent_bytes | |
| 收到的位元組 (bytes_received) | out | dstBytes | network.received_bytes | |
| 封包 (封包) | cn2 | totalPackets | 封包 | additional.fields.key 和 additional.fields.value.string_value |
| 傳送的封包數 (pkts_sent) | PanOSPacketsSent | srcPackets | pkts_sent | network.sent_packets |
| 接收的封包數 (pkts_received) | PanOSPacketsReceived | dstPackets | pkts_received | network.received_packets |
| 最大封裝 (max_encap) | flexNumber2 | MaximumEncapsulation | max_encap | additional.fields.key 和 additional.fields.value.string_value |
| 不明通訊協定 (unknown_proto) | cfp1 | UnknownProtocol | unknown_proto | additional.fields.key 和 additional.fields.value.string_value |
| 嚴格檢查 (strict_check) | cfp2 | StrictChecking | strict_check | additional.fields.key 和 additional.fields.value.string_value |
| 隧道片段 (tunnel_fragment) | PanOSTunnelFragment | TunnelFragment | tunnel_fragment | additional.fields.key 和 additional.fields.value.string_value |
| 建立的工作階段 (sessions_created) | cfp3 | SessionsCreated | sessions_created | additional.fields.key 和 additional.fields.value.string_value |
| 已關閉的工作階段 (sessions_closed) | cfp4 | SessionsClosed | sessions_closed | additional.fields.key 和 additional.fields.value.string_value |
| 工作階段結束原因 (session_end_reason) | 原因 | SessionEndReason | security_result.summary | |
| 動作來源 (action_source) | cat | ActionSource | action_source | additional.fields.key 和 additional.fields.value.string_value |
| 開始時間 (開始) | startTime | start | additional.fields.key 和 additional.fields.value.string_value | |
| 經過時間 (elapsed) | cn3 | ElapsedTime | 經過時間 | network.session_duration.seconds |
| 通道檢查規則 (tunnel_insp_rule) | PanOSTunneInspectionRule | security_result.rule_name = "Tunnel Inspection Rule: %{PanOSTunnelInspectionRule}" | ||
| 遠端使用者 IP (remote_user_ip) | PanOSRmtUserIP | principal.ip | ||
| 遠端使用者 ID (remote_user_id) | PanOSRmtUserID | remote_user_id | principal.user.userid | |
| 安全性規則 UUID (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| PCAP ID (pcap_id) | PanOSPcapID | pcap_id | additional.fields.key 和 additional.fields.value.string_value | |
| 動態使用者群組名稱 (dynusergroup_name) | PanDynamicUsrgrp | principal.group.group_display_name | ||
| 來源外部動態清單 (src_edl) | PanOSSourceEDL | src_edl | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| 目標外部動態清單 (dst_edl) | PanOSDestinationEDL | dst_edl | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| 高解析度時間戳記 (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key 和 additional.fields.value.string_value | ||
| 配量鑑別器 (nssai_sd) | nssai_sd | additional.fields.key 和 additional.fields.value.string_value | ||
| 切片服務類型 (nssai_sd) | nssai_sd1 | additional.fields.key 和 additional.fields.value.string_value | ||
| PDU 工作階段 ID (pdu_session_id) | pdu_session_id | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式子類別 (subcategory_of_app) | subcategory_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式類別 (category_of_app) | category_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式技術 (technology_of_app) | technology_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式風險 (risk_of_app) | risk_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式特徵 (characteristic_of_app) | characteristic_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式容器 (container_of_app) | container_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式 SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 通道應用程式 (tunneled_app) | additional.fields.key 和 additional.fields.value.string_value | |||
| 已卸載 (已卸載) | additional.fields.key 和 additional.fields.value.string_value | |||
| 流程類型 (flow_type) | additional.fields.key 和 additional.fields.value.string_value | |||
| 叢集名稱 (cluster_name) |
principal.resource.name |
|||
| 應用程式受制裁狀態 (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key 和 additional.fields.value.string_value |
驗證
下表列出驗證記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|
| 序號 (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| 類型 (type) | type (Header) | cat | metadata.product_event_type | |
| 威脅/內容類型 (子類型) | 子類型 (標題) | 子類型 | metadata.product_event_type | |
| 產生時間 (time_generated 或 cef-formatted-time_generated) | metadata.event_timestamp | |||
| 虛擬系統 (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| 來源 IP (ip) | src | src | principal.ip | |
| 使用者 (使用者) | duser | usrName | target.user.userid | |
| Normalize User (normalize_user) | cs2 | NormalizeUser | target.user.user_display_name | |
| 物件 (物件) | fname | ObjectName | object | target.resource.name |
| 驗證政策 (authpolicy) | cs4 | AuthPolicy | authpolicy | additional.fields.key 和 additional.fields.value.string_value |
| 重複次數 (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key 和 additional.fields.value.string_value |
| 驗證 ID (authid) | cn2 | AuthenticationID | authid | additional.fields.key 和 additional.fields.value.string_value |
| 供應商 (供應商) | flexString2 | 供應商 | 供應商 | additional.fields.key 和 additional.fields.value.string_value |
| 記錄動作 (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key 和 additional.fields.value.string_value |
| 伺服器設定檔 (serverprofile) | cs1 | ServerProfile | serverprofile | additional.fields.key 和 additional.fields.value.string_value |
| 說明 (desc) | PanOSDesc | AdditionalAuthInfo | security_result.description | |
| 用戶端類型 (clienttype) | cs5 | ClientType | clienttype | additional.fields.key 和 additional.fields.value.string_value |
| 事件類型 (事件) | msg | msg | extensions.auth.auth_details | |
| 因素編號 (factorno) | cn1 | FactorNumber | factorno | additional.fields.key 和 additional.fields.value.string_value |
| 序號 (seqno) | externalId | sequence | metadata.product_log_id | |
| 動作旗標 (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value |
| 虛擬系統名稱 (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| 裝置名稱 (device_name) | dvchost | DeviceName | intermediary.hostname | |
| 虛擬系統 ID (vsys_id) | intermediary.resource.product_object_id | |||
| 驗證通訊協定 (authproto) | authproto | additional.fields.key 和 additional.fields.value.string_value | ||
| 規則的 UUID (rule_uuid) | PanOSRuleUUID/RuleUUID | security_result.rule_id | ||
| 高解析度時間戳記 (high_res _timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key 和 additional.fields.value.string_value | ||
| 來源裝置類別 (src_category) | PanOSSourceDeviceCategory | src_category | principal.asset.category | |
| 來源裝置設定檔 (src_profile) | PanOSSourceDeviceProfile | src_profile | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| 來源裝置型號 (src_model) | PanOSSourceDeviceModel | src_model | principal.asset.hardware.model | |
| 來源裝置供應商 (src_vendor) | PanOSSourceDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| 來源裝置 OS 系列 (src_osfamily) | PanOSSourceDeviceOSFamily | principal.platform |
||
| 來源裝置 OS 版本 (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | ||
| 來源主機名稱 (src_host) | PanOSSourceHostname | principal.hostname | ||
| 來源 MAC 位址 (src_mac) | PanOSSourceMac | principal.asset.mac | ||
| 區域 (區域) | PanOSTrafficOriginRegion | principal.location.country_or_region | ||
| 使用者代理程式 (user_agent) | PanOSHTTPUserAgent | network.http.user_agent | ||
| 工作階段 ID(sessionid) | PanOSTrafficSessionID | network.session_id | ||
| 嚴重性 (severity) | number-of-severity(header) | security_result.severity 和 security_result.severity_details | ||
| 叢集名稱 (cluster_name) | principal.resource.name |
網址
下表列出網址記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|
| 序號 (序號) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| 類型 (type) | type (Header) | cat | metadata.product_event_type | |
| 威脅/內容類型 (子類型) | 子類型 (標題) | 子類型 | metadata.product_event_type | |
| 生成時間 | metadata.event_timestamp | |||
| 來源地址 (src) | src | src | principal.ip | |
| 目的地地址 (dst) | dst | dst | target.ip | |
| NAT 來源 IP (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| 網路位址轉譯 (NAT) 目的地 IP (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| 規則 (規則) | cs1 | RuleName | security_result.rule_name | |
| 來源使用者 (srcuser) | suser | SourceUser | principal.user.userid | |
| 目的地使用者 (dstuser) | duser | DestinationUser | target.user.userid | |
| 應用程式 (app) | 應用程式 | 應用程式 | network.application_protocol | |
| 虛擬系統 (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| 來源區域 (從) | cs4 | SourceZone | 從 | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 目的地 (到) | cs5 | DestinationZone | 到 | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 傳入介面 (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 傳出介面 (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 記錄動作 (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key 和 additional.fields.value.string_value |
| 記錄時間 | time_logged | additional.fields.key 和 additional.fields.value.string_value | ||
| 工作階段 ID (sessionid) | cn1 | SessionID | network.session_id | |
| 重複次數 (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key 和 additional.fields.value.string_value |
| 來源通訊埠 (sport) | spt | srcPort | principal.port | |
| 目的地通訊埠 (dport) | dpt | dstPort | target.port | |
| NAT 來源通訊埠 (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| NAT 目的地通訊埠 (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| 旗標 (flags) | flexString1 | 旗標 | flags | additional.fields.key 和 additional.fields.value.string_value |
| IP 通訊協定 (proto) | proto | proto | network.ip_protocol | |
| 動作 (動作) | act | action | security_result.action_details
security_result.action |
|
| 網址/檔案名稱 (其他) | 其他 | target.file.names
target.url |
||
| 威脅/內容名稱 (threatid) | cat | ThreatID | security_result.threat_id | |
| 類別 (類別) | cs2 | URLCategory | 類別 | security_result.category_details |
| 嚴重性 (severity) | number-of-severity (標頭) | 嚴重性 | security_result.severity
security_result.severity_details |
|
| 方向 (方向) | flexString2 | 方向 | network.direction | |
| 序號 (seqno) | externalId | sequence | metadata.product_log_id | |
| 動作旗標 (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value |
| 來源國家/地區 (srcloc) | SourceLocation | principal.location.country_or_region | ||
| 目的地國家/地區 (dstloc) | DestinationLocation | target.location.country_or_region | ||
| contenttype (contenttype) | requestContext | ContentType | contenttype | additional.fields.key 和 additional.fields.value.string_value |
| pcap_id (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key 和 additional.fields.value.string_value |
| filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | ||
| cloud (cloud) | Cloud | cloud | additional.fields.key 和 additional.fields.value.string_value | |
| url_idx (url_idx) | URLIndex | url_idx | additional.fields.key 和 additional.fields.value.string_value | |
| user_agent (user_agent) | requestClientApplication | UserAgent | network.http.user_agent | |
| 檔案類型 (filetype) | target.file.mime_type | |||
| xff (xff) | PanOSXForwarderfor | identSrc | xff | principal.ip |
| 參照網址 (referer) | PanOSReferer | 參照網址 | network.http.referral_url | |
| 寄件者 (寄件者) | network.email.from | |||
| 主旨 (主旨) | 主旨 | network.email.subject | ||
| 收件者 (recipient) | network.email.to | |||
| reportid (reportid) | reportid | additional.fields.key 和 additional.fields.value.string_value | ||
| DG Hierarchy Level 1 (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value |
| 需求開發廣告活動階層第 2 層 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value |
| 需求開發廣告活動階層第 3 層 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value |
| 需求開發廣告活動階層第 4 層 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value |
| 虛擬系統名稱 (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| 裝置名稱 (device_name) | dvchost | DeviceName | intermediary.hostname | |
| file_url (file_url) | target.url | |||
| 來源 VM UUID (src_uuid) | SrcUUID | principal.asset.product_object_id | ||
| 目的地 VM UUID (dst_uuid) | DstUUID | target.asset.product_object_id | ||
| http_method (http_method) | requestMethod | RequestMethod | network.http.method | |
| 通道 ID/IMSI (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key 和 additional.fields.value.string_value |
| 監控標籤/IMEI (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key 和 additional.fields.value.string_value |
| 父項工作階段 ID (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| 父項工作階段開始時間 (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key 和 additional.fields.value.string_value |
| 隧道 (tunnel) | PanOSTunnelType | TunnelType | 通道 | additional.fields.key 和 additional.fields.value.string_value |
| thr_category (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| contentver (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key 和 additional.fields.value.string_value |
| sig_flags (sig_flags) | sig_flags | additional.fields.key 和 additional.fields.value.string_value | ||
| SCTP 關聯 ID (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key 和 additional.fields.value.string_value | |
| 酬載通訊協定 ID (ppid) | PanOSPPID | ppid | additional.fields.key 和 additional.fields.value.string_value | |
| http_headers (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| 網址類別清單 (url_category_list) | PanOSURLCatList | url_category_list | additional.fields.key 和 additional.fields.value.string_value | |
| 規則的 UUID (rule_uuid) | PanOSRuleUUID | rule_uuid | security_result.rule_id | |
| HTTP/2 連線 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| dynusergroup_name (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | additional.fields.key 和 additional.fields.value.string_value | |
| XFF 位址 (xff_ip) | PanXFFIP | principal.ip | ||
| 來源裝置類別 (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| 來源裝置設定檔 (src_profile) | PanSrcDeviceProf | src_profile | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| 來源裝置型號 (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| 來源裝置供應商 (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| 來源裝置 OS 系列 (src_osfamily) | PanSrcDeviceOS | principal.platform | ||
| 來源裝置 OS 版本 (src_osversion) | PanSrcDeviceOSv | principal.platform_version | ||
| 來源主機名稱 (src_host) | PanSrcHostname | src_host | principal.hostname | |
| 來源 MAC 位址 (src_mac) | PanSrcMac | principal.mac | ||
| 目的地裝置類別 (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| 目的地裝置設定檔 (dst_profile) | PanDstDeviceProf | dst_profile | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| 目的地裝置型號 (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| 目的地裝置供應商 (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| 目的地裝置 OS 系列 (dst_osfamily) | PanDstDeviceOS | target.platform | ||
| 目的地裝置 OS 版本 (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| 目的地主機名稱 (dst_host) | PanPODNamespace | target.hostname | ||
| 目的地 MAC 位址 (dst_mac) | PanDstMac | target.mac | ||
| 容器 ID (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| POD 命名空間 (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| POD 名稱 (pod_name) | PanPODName | pod_name | target.resource.name | |
| 來源外部動態清單 (src_edl) | PanSrcEDL | src_edl | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| 目標外部動態清單 (dst_edl) | PanDstEDL | dst_edl | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| 主機 ID (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| 序號 (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| domain_edl (domain_edl) | PanDomainEDL | domain_edl | additional.fields.key 和 additional.fields.value.string_value | |
| 來源動態位址群組 (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| 目的地動態地址群組 (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| partial_hash (partial_hash) | PanPartialHash | partial_hash | additional.fields.key 和 additional.fields.value.string_value | |
| 高解析度時間戳記 (high_res_timestamp) | PanTimeHighRes | additional.fields.key 和 additional.fields.value.string_value | ||
| 原因 (原因) | PanReasonFilteringAction | 原因 | security_result.summary | |
| 理由 (理由) | PanJustification | 理由 | additional.fields.key 和 additional.fields.value.string_value | |
| nssai_sst (nssai_sst) | PanASServiceType | nssai_sst | additional.fields.key 和 additional.fields.value.string_value | |
| 應用程式子類別 (subcategory_of_app) | subcategory_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式類別 (category_of_app) | category_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式技術 (technology_of_app) | technology_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式風險 (risk_of_app) | risk_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式特徵 (characteristic_of_app) | characteristic_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式容器 (container_of_app) | container_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 通道化應用程式 (tunneled_app) | tunneled_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式的軟體即服務 (is_saas_of_app) | is_saas_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式的受制裁狀態 (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 雲端報告 ID (cloud_reportid) | additional.fields.key 和 additional.fields.value.string_value | |||
| 叢集名稱 (cluster_name) |
principal.resource.name |
|||
| 流程類型 (flow_type) | additional.fields.key 和 additional.fields.value.string_value |
資料
下表列出資料記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|
| 序號 (序號) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| 類型 (type) | type (Header) | cat | metadata.product_event_type | |
| 威脅/內容類型 (子類型) | 子類型 (標題) | 子類型 | metadata.product_event_type | |
| 生成時間 | metadata.event_timestamp | |||
| 來源地址 (src) | src | src | principal.ip | |
| 目的地地址 (dst) | dst | dst | target.ip | |
| NAT 來源 IP (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| 網路位址轉譯 (NAT) 目的地 IP (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| 規則 (規則) | cs1 | RuleName | security_result.rule_name | |
| 來源使用者 (srcuser) | suser | SourceUser | principal.user.userid | |
| 目的地使用者 (dstuser) | duser | DestinationUser | target.user.userid | |
| 應用程式 (app) | 應用程式 | 應用程式 | network.application_protocol | |
| 虛擬系統 (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| 來源區域 (從) | cs4 | SourceZone | 從 | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 目的地 (到) | cs5 | DestinationZone | 到 | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 傳入介面 (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 傳出介面 (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 記錄動作 (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key 和 additional.fields.value.string_value |
| 記錄時間 | time_logged | additional.fields.key 和 additional.fields.value.string_value | ||
| 工作階段 ID (sessionid) | cn1 | SessionID | network.session_id | |
| 重複次數 (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key 和 additional.fields.value.string_value |
| 來源通訊埠 (sport) | spt | srcPort | principal.port | |
| 目的地通訊埠 (dport) | dpt | dstPort | target.port | |
| NAT 來源通訊埠 (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| NAT 目的地通訊埠 (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| 旗標 (flags) | flexString1 | 旗標 | flags | additional.fields.key 和 additional.fields.value.string_value |
| IP 通訊協定 (proto) | proto | proto | network.ip_protocol | |
| 動作 (動作) | act | action | security_result.action_details
security_result.action |
|
| 網址/檔案名稱 (其他) | 其他 | target.file.names
target.url |
||
| 威脅/內容名稱 (threatid) | cat | ThreatID | security_result.threat_id | |
| 類別 (類別) | cs2 | URLCategory | 類別 | security_result.category_details |
| 嚴重性 (severity) | number-of-severity (標頭) | 嚴重性 | security_result.severity
security_result.severity_details |
|
| 方向 (方向) | flexString2 | 方向 | network.direction | |
| 序號 (seqno) | externalId | sequence | metadata.product_log_id | |
| 動作旗標 (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value |
| 來源國家/地區 (srcloc) | SourceLocation | principal.location.country_or_region | ||
| 目的地國家/地區 (dstloc) | DestinationLocation | target.location.country_or_region | ||
| contenttype (contenttype) | ContentType | contenttype | additional.fields.key 和 additional.fields.value.string_value | |
| pcap_id (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key 和 additional.fields.value.string_value |
| filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | ||
| cloud (cloud) | Cloud | cloud | additional.fields.key 和 additional.fields.value.string_value | |
| url_idx (url_idx) | URLIndex | url_idx | additional.fields.key 和 additional.fields.value.string_value | |
| user_agent (user_agent) | network.http.user_agent | |||
| 檔案類型 (filetype) | target.file.mime_type | |||
| xff (xff) | xff | principal.ip | ||
| 參照網址 (referer) | network.http.referral_url | |||
| 寄件者 (寄件者) | network.email.from | |||
| 主旨 (主旨) | 主旨 | network.email.subject | ||
| 收件者 (recipient) | network.email.to | |||
| reportid (reportid) | reportid | additional.fields.key 和 additional.fields.value.string_value | ||
| DG Hierarchy Level 1 (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value |
| 需求開發廣告活動階層第 2 層 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value |
| 需求開發廣告活動階層第 3 層 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value |
| 需求開發廣告活動階層第 4 層 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value |
| 虛擬系統名稱 (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| 裝置名稱 (device_name) | dvchost | DeviceName | intermediary.hostname | |
| file_url (file_url) | target.url | |||
| 來源 VM UUID (src_uuid) | SrcUUID | principal.asset.product_object_id | ||
| 目的地 VM UUID (dst_uuid) | DstUUID | target.asset.product_object_id | ||
| http_method (http_method) | RequestMethod | network.http.method | ||
| 通道 ID/IMSI (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key 和 additional.fields.value.string_value |
| 監控標籤/IMEI (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key 和 additional.fields.value.string_value |
| 父項工作階段 ID (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| 父項工作階段開始時間 (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key 和 additional.fields.value.string_value |
| 隧道 (tunnel) | PanOSTunnelType | TunnelType | 通道 | additional.fields.key 和 additional.fields.value.string_value |
| thr_category (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| contentver (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key 和 additional.fields.value.string_value |
| sig_flags (sig_flags) | sig_flags | additional.fields.key 和 additional.fields.value.string_value | ||
| SCTP 關聯 ID (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key 和 additional.fields.value.string_value | |
| 酬載通訊協定 ID (ppid) | PanOSPPID | ppid | additional.fields.key 和 additional.fields.value.string_value | |
| http_headers (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| 網址類別清單 (url_category_list) | url_category_list | additional.fields.key 和 additional.fields.value.string_value | ||
| 規則的 UUID (rule_uuid) | PanOSRuleUUID | rule_uuid | security_result.rule_id | |
| HTTP/2 連線 (http2_connection) | http2_connection | network.application_protocol_version | ||
| dynusergroup_name (dynusergroup_name) | dynusergroup_name | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
||
| XFF 位址 (xff_ip) | principal.ip | |||
| 來源裝置類別 (src_category) | src_category | principal.asset.category | ||
| 來源裝置設定檔 (src_profile) | src_profile | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
||
| 來源裝置型號 (src_model) | src_model | principal.asset.hardware.model | ||
| 來源裝置供應商 (src_vendor) | src_vendor | principal.asset.hardware.manufacturer | ||
| 來源裝置 OS 系列 (src_osfamily) | principal.platform | |||
| 來源裝置 OS 版本 (src_osversion) | principal.platform_version | |||
| 來源主機名稱 (src_host) | src_host | principal.hostname | ||
| 來源 MAC 位址 (src_mac) | principal.mac | |||
| 目的地裝置類別 (dst_category) | dst_category | target.asset.category | ||
| 目的地裝置設定檔 (dst_profile) | dst_profile | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
||
| 目的地裝置型號 (dst_model) | dst_model | target.asset.hardware.model | ||
| 目的地裝置供應商 (dst_vendor) | dst_vendor | target.asset.hardware.manufacturer | ||
| 目的地裝置 OS 系列 (dst_osfamily) | target.platform | |||
| 目的地裝置 OS 版本 (dst_osversion) | target.platform_version | |||
| 目的地主機名稱 (dst_host) | target.hostname | |||
| 目的地 MAC 位址 (dst_mac) | target.mac | |||
| 容器 ID (container_id) | container_id | intermediary.resource.product_object_id | ||
| POD 命名空間 (pod_namespace) | pod_namespace | target.resource.attribute.labels.key/value | ||
| POD 名稱 (pod_name) | pod_name | target.resource.name | ||
| 來源外部動態清單 (src_edl) | src_edl | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
||
| 目標外部動態清單 (dst_edl) | dst_edl | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
||
| 主機 ID (hostid) | hostid | principal.asset.asset_id | ||
| 序號 (serialnumber) | principal.asset.hardware.serial_number | |||
| domain_edl (domain_edl) | domain_edl | additional.fields.key 和 additional.fields.value.string_value | ||
| 來源動態位址群組 (src_dag) | principal.group.group_display_name | |||
| 目的地動態地址群組 (dst_dag) | target.group.group_display_name | |||
| partial_hash (partial_hash) | partial_hash | additional.fields.key 和 additional.fields.value.string_value | ||
| 高解析度時間戳記 (high_res_timestamp) | additional.fields.key 和 additional.fields.value.string_value | |||
| 原因 (原因) | 原因 | security_result.summary | ||
| 理由 (理由) | 理由 | additional.fields.key 和 additional.fields.value.string_value | ||
| nssai_sst (nssai_sst) | nssai_sst | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式子類別 (subcategory_of_app) | subcategory_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式類別 (category_of_app) | category_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式技術 (technology_of_app) | technology_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式風險 (risk_of_app) | risk_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式特徵 (characteristic_of_app) | characteristic_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式容器 (container_of_app) | container_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 通道化應用程式 (tunneled_app) | tunneled_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式的軟體即服務 (is_saas_of_app) | is_saas_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式的受制裁狀態 (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 雲端報告 ID (cloud_reportid) | additional.fields.key 和 additional.fields.value.string_value | |||
| 叢集名稱 (cluster_name) | principal.resource.name | |||
| 流程類型 (flow_type) | additional.fields.key 和 additional.fields.value.string_value |
GlobalProtect
下表列出 GlobalProtect 記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time) | rt | received_time | metadata.event_timestamp | |
| 序號 (序號) | PanOSDeviceSN | intermediary_asset_hardware_serial_number | intermediary.asset.hardware.serial_number | |
| 類型 (type) | type (Header) | metadata.product_event_type | ||
| 威脅/內容類型 (子類型) | 子類型 (標題) | 子類型 | metadata.product_event_type | |
| 產生時間 (time_generated) | PanOSLogTimeStamp | generated_timestamp | metadata.event_timestamp | |
| 虛擬系統 (vsys) | PanOSVirtualSystem | vsys | intermediary.asset.attribute.labels.key/value | |
| 事件 ID (eventid) | PanOSEventID | event_id | additional.fields.key 和 additional.fields.value.string_value | |
| 階段 (階段) | PanOSStage | 階段 | additional.fields.key 和 additional.fields.value.string_value | |
| 驗證方式 (auth_method) | PanOSAuthMethod | extension_auth_auth_details | extensions.auth.auth_details | |
| 通道類型 (tunnel_type) | PanOSTunnelType | 通道 | additional.fields.key 和 additional.fields.value.string_value | |
| 來源使用者 (srcuser) | PanOSSourceUserName | src_user | principal.user.email_address
principal.user.userid principal.administrative_domain |
|
| 來源區域 (srcregion) | PanOSSourceRegion | src_region | principal.location.country_or_region | |
| 電腦名稱 (machinename) | PanOSEndpointDeviceName | machine_name | principal.hostname | |
| 公開 IP (public_ip) | PanOSPublicIPv4 | principal.nat_ip | ||
| 公開 IPv6 (public_ipv6) | PanOSPublicIPv6 | principal.nat_ip | ||
| 私人 IP (private_ip) | PanOSPrivateIPv4 | principal.ip | ||
| 私人 IPv6 (private_ipv6) | PanOSPrivateIPv6 | principal.ip | ||
| 主機 ID (hostid) | PanOSHostID | hostid | principal.asset.asset_id | |
| 序號 (serialnumber) | PanOSDeviceSN | principal.asset.hardware.serial_number | ||
| 用戶端版本 (client_ver) | PanOSGlobalProtectClientVersion | client_ver | additional.fields.key 和 additional.fields.value.string_value | |
| 用戶端作業系統 (client_os) | PanOSEndpointOSType | principal.platform | ||
| 用戶端作業系統版本 (client_os_ver) | PanOSEndpointOSVersion | principal.platform_version | ||
| 重複次數 (repeatcnt) | PanOSCountOfRepeats | repeatcnt | additional.fields.key 和 additional.fields.value.string_value | |
| 原因 (原因) | PanOSQuarantineReason | security_result.summary | ||
| 錯誤 (錯誤) | PanOSConnectionError | error | security_result.description | |
| 說明 (不透明) | PanOSDescription | security_result.description | ||
| 狀態 (狀態) | PanOSEventStatus | 狀態 | additional.fields.key 和 additional.fields.value.string_value | |
| 位置 (位置) | PanOSGPGatewayLocation | target.location.country_or_region | ||
| 登入時間長度 (login_duration) | PanOSLoginDuration | network.session_duration | ||
| 連線方法 (connect_method) | PanOSConnectionMethod | connect_method | additional.fields.key 和 additional.fields.value.string_value | |
| 錯誤代碼 (error_code) | PanOSConnectionErrorID | error_code | additional.fields.key 和 additional.fields.value.string_value | |
| 入口網站 (入口網站) | PanOSPortal | 入口網站 | additional.fields.key 和 additional.fields.value.string_value | |
| 序號 (seqno) | PanOSSequenceNo | metadata.product_log_id | ||
| 動作旗標 (actionflags) | PanOSActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value | |
| 高解析度時間戳記 (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key 和 additional.fields.value.string_value | ||
| 閘道選取方法 (selection_type) | PanOSGatewaySelectionType | selection_type | additional.fields.key 和 additional.fields.value.string_value | |
| 安全資料傳輸層 (SSL) 回應時間 (response_time) | PanOSSSLResponseTime | response_time | additional.fields.key 和 additional.fields.value.string_value | |
| 閘道優先順序 (優先順序) | PanOSGatewayPriority | 優先順序 | additional.fields.key 和 additional.fields.value.string_value | |
| 嘗試使用的閘道 (attempted_gateways) | PanOSAttemptedGateways | attempted_gateways | additional.fields.key 和 additional.fields.value.string_value | |
| 閘道名稱 (閘道) | PanOSAttemptedGateways | 閘道 | target.resource.name | |
| 裝置群組階層 (dg_hier_level_1) | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value | ||
| 裝置群組階層 (dg_hier_level_2) | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value | ||
| 裝置群組階層 (dg_hier_level_3) | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value | ||
| 裝置群組階層 (dg_hier_level_4) | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value | ||
| 虛擬系統名稱 (vsys_name) | intermediary.asset.attribute.labels.key/value | |||
| 裝置名稱 (device_name) | intermediary.hostname | |||
| 虛擬系統 ID (vsys_id) | intermediary.resource.product_object_id | |||
| 嚴重性 (severity) | number-of-severity(header) | security_result.severity 和 security_result.severity_details | ||
| 叢集名稱 (cluster_name) | principal.resource.name |
關聯性
下表列出關聯記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 產生時間 (time_generated 或 cef-formatted-time_generated) | startTime | generated_timestamp | metadata.event_timestamp | |
| 來源地址 (src) | src | principal.ip | ||
| 來源使用者 (srcuser) | SourceUser / usrName | principal.user.userid | ||
| 虛擬系統 (vsys) | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value | |
| 類別 (類別) | security_result.category_details | |||
| 嚴重性 (severity) | 嚴重性 | security_result.severity 和 security_result.severity_details | ||
| 裝置群組階層層級 1 | DeviceGroupHierarchyL1 | additional.fields.key 和 additional.fields.value.string_value | ||
| 裝置群組階層層級 2 | DeviceGroupHierarchyL2 | additional.fields.key 和 additional.fields.value.string_value | ||
| 裝置群組階層層級 3 | DeviceGroupHierarchyL3 | additional.fields.key 和 additional.fields.value.string_value | ||
| 裝置群組階層層級 4 | DeviceGroupHierarchyL4 | additional.fields.key 和 additional.fields.value.string_value | ||
| 虛擬系統名稱 (vsys_name) | vSrcName | intermediary.asset.attribute.labels.key/value | ||
| 裝置名稱 (device_name) | DeviceName | intermediary.hostname | ||
| 虛擬系統 ID (vsys_id) | VirtualSystemID | intermediary.resource.product_object_id | ||
| 物件名稱 (objectname) | ObjectName | target.resource.name | ||
| 物件 ID (object_id) | ObjectID | target.resource.product_object_id | ||
| 證據 (evidence) | msg | security_result.summary |
GTP
下表列出 gtp 記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|||
| 序號 (serial) | intermediary.asset.hardware.serial_number | |||
| 類型 (type) | metadata.product_event_type | |||
| 威脅/內容類型 (子類型) | metadata.product_event_type | |||
| 產生時間 (time_generated 或 cef-formatted-time_generated) | metadata.event_timestamp | |||
| 來源地址 (src) | principal.ip | |||
| 目的地地址 (dst) | target.ip | |||
| 規則名稱 (規則) | security_result.rule_name | |||
| 應用程式 | network.application_protocol | |||
| 虛擬系統 (vsys) | vsys | intermediary.asset.attribute.labels.key/value | ||
| 來源區域 (從) | 從 | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
||
| 目的地 (到) | 到 | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
||
| 傳入介面 (inbound_if) | inbound_if | principal.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
||
| 傳出介面 (outbound_if) | outbound_if | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
||
| 記錄動作 (logset) | logset | additional.fields.key 和 additional.fields.value.string_value | ||
| 工作階段 ID (sessionid) | network.session_id | |||
| 來源通訊埠 (sport) | principal.port | |||
| 目的地通訊埠 (dport) | target.port | |||
| IP 通訊協定 (proto) | network.ip_protocol | |||
| 動作 (動作) | security_result.action_details
security_result.action |
|||
| GTP 事件類型 (event_type) | gtp_event_type | additional.fields.key 和 additional.fields.value.string_value | ||
| MSISDN (msisdn) | msisdn | additional.fields.key 和 additional.fields.value.string_value | ||
| 存取點名稱 (apn) | apn | additional.fields.key 和 additional.fields.value.string_value | ||
| 無線電存取技術 (RAT) | rat | additional.fields.key 和 additional.fields.value.string_value | ||
| GTP 訊息類型 (msg_type) | gtp_msg_type | additional.fields.key 和 additional.fields.value.string_value | ||
| 結束 IP 位址 (end_ip_adr) | principal.ip | |||
| 通道端點 ID 1 (teid1) | teid1 | additional.fields.key 和 additional.fields.value.string_value | ||
| 通道端點 ID 2 (teid2) | teid2 | additional.fields.key 和 additional.fields.value.string_value | ||
| GTP 介面 (gtp_interface) | gtp_interface | additional.fields.key 和 additional.fields.value.string_value | ||
| GTP Cause (cause_code) | gtp_cause_code | additional.fields.key 和 additional.fields.value.string_value | ||
| 嚴重性 (severity) | security_result.severity 和 security_result.severity_details | |||
| 放送聯播網 MCC (mcc) | mcc | additional.fields.key 和 additional.fields.value.string_value | ||
| 服務網路 MNC (mnc) | mnc | additional.fields.key 和 additional.fields.value.string_value | ||
| 區碼 (area_code) | area_code | additional.fields.key 和 additional.fields.value.string_value | ||
| 儲存格 ID (cell_id) | cell_id | additional.fields.key 和 additional.fields.value.string_value | ||
| GTP 事件代碼 (event_code) | event_code | additional.fields.key 和 additional.fields.value.string_value | ||
| 來源位置 (srcloc) | principal.location.country_or_region | |||
| 目的地位置 (dstloc) | target.location.country_or_region | |||
| 通道 ID/IMSI (imsi) | tunnelid | additional.fields.key 和 additional.fields.value.string_value | ||
| 監視器標籤/IMEI (imei) | monitortag | additional.fields.key 和 additional.fields.value.string_value | ||
| 開始時間 (開始) | start | additional.fields.key 和 additional.fields.value.string_value | ||
| 經過時間 (elapsed) | network.session_duration.seconds | |||
| 隧道檢查規則 (tunnel_insp_rule) | tunnel_insp_rule | security_result.detection_fields.key/value | ||
| 遠端使用者 IP (remote_user_ip) | principal.ip | |||
| 遠端使用者 ID (remote_user_id) | remote_user_id | principal.user.userid | ||
| 規則的 UUID (rule_uuid) | security_result.rule_id | |||
| PCAP ID (pcap_id) | pcap_id | additional.fields.key 和 additional.fields.value.string_value | ||
| 高解析度時間戳記 (high_res_timestamp) | additional.fields.key 和 additional.fields.value.string_value | |||
| 切片服務類型 (nsdsai_sst) | nsdsai_sst | additional.fields.key 和 additional.fields.value.string_value | ||
| Slice 差異化指標 (nsdsai_sd) | nsdsai_sd | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式子類別 (subcategory_of_app) | subcategory_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式類別 (category_of_app) | category_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式技術 (technology_of_app) | technology_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式風險 (risk_of_app) | risk_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式特徵 (characteristic_of_app) | characteristic_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式容器 (container_of_app) | container_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式 SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式受制裁狀態 (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key 和 additional.fields.value.string_value |
SCTP
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | receive_time 或 cef-formatted-receive_time | metadata.collected_timestamp | ||
| 序號 (serial) | serial | intermediary.asset.hardware.serial_number | ||
| 類型 (型別) | 類型 | metadata.product_event_type | ||
| 產生時間 (time_generated 或 cef-formatted-time_generated) | time_generated 或 cef-formatted-time_generated | metadata.event_timestamp | ||
| 來源地址 (src) | src | principal.ip | ||
| 目的地地址 (dst) | dst | target.ip | ||
| 規則名稱 (規則) | 規則 | security_result.rule_name | ||
| 來源可用區 (從) | 來自 | additional.fields.key 和 additional.fields.value.string_value | ||
| 目的地時區 (到) | 至 | additional.fields.key 和 additional.fields.value.string_value | ||
| 傳入介面 (inbound_if) | inbound_if | additional.fields.key 和 additional.fields.value.string_value | ||
| 傳出介面 (outbound_if) | outbound_if | additional.fields.key 和 additional.fields.value.string_value | ||
| 記錄動作 (記錄集) | 記錄集 | additional.fields.key 和 additional.fields.value.string_value | ||
| 工作階段 ID (sessionid) | sessionid | network.session_id | ||
| 重複次數 (repeatcnt) | repeatcnt | additional.fields.key 和 additional.fields.value.string_value | ||
| 來源通訊埠 (sport) | 運動 | principal.port | ||
| 目的地通訊埠 (dport) | dport | target.port | ||
| IP 通訊協定 (proto) | proto | network.ip_protocol (列舉) | ||
| 動作 (action) | 動作 | security_result.action_details security_result.action |
||
| 裝置群組階層 (dg_hier_level_1 至 dg_hier_level_4) | dg_hier_level_1 至 dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value | ||
| 裝置名稱 (device_name) | device_name | intermediary.hostname | ||
| 序號 (seqno) | seqno | metadata.product_log_id | ||
| SCTP 關聯 ID (assoc_id) | assoc_id | additional.fields.key 和 additional.fields.value.string_value | ||
| 酬載通訊協定 ID (ppid) | ppid | additional.fields.key 和 additional.fields.value.string_value | ||
| 嚴重性 (severity) | 嚴重性 | security_result.severity 和 security_result.severity_details | ||
| SCTP 區塊類型 (sctp_chunk_type) | sctp_chunk_type | additional.fields.key 和 additional.fields.value.string_value | ||
| SCTP 事件類型 (sctp_event_type) | sctp_event_type | additional.fields.key 和 additional.fields.value.string_value | ||
| SCTP 驗證廣告代碼 1 (verif_tag_1) | verif_tag_1 | additional.fields.key 和 additional.fields.value.string_value | ||
| SCTP 驗證廣告代碼 2 (verif_tag_2) | verif_tag_2 | additional.fields.key 和 additional.fields.value.string_value | ||
| SCTP 原因代碼 (sctp_cause_code) | sctp_cause_code | additional.fields.key 和 additional.fields.value.string_value | ||
| Diameter 應用程式 ID (diam_app_id) | diam_app_id | additional.fields.key 和 additional.fields.value.string_value | ||
| Diameter 指令代碼 (diam_cmd_code) | diam_cmd_code | additional.fields.key 和 additional.fields.value.string_value | ||
| Diameter AVP 代碼 (diam_avp_code) | diam_avp_code | additional.fields.key 和 additional.fields.value.string_value | ||
| SCTP 串流 ID (stream_id) | stream_id | additional.fields.key 和 additional.fields.value.string_value | ||
| SCTP 關聯結束原因 (assoc_end_reason) | assoc_end_reason | additional.fields.key 和 additional.fields.value.string_value | ||
| 運算碼 (op_code) | op_code | additional.fields.key 和 additional.fields.value.string_value | ||
| SCCP Calling Party SSN (sccp_calling_ssn) | sccp_calling_ssn | additional.fields.key 和 additional.fields.value.string_value | ||
| SCCP Calling Party Global Title (sccp_calling_gt) | sccp_calling_gt | additional.fields.key 和 additional.fields.value.string_value | ||
| SCTP 篩選器 (sctp_filter) | sctp_filter | additional.fields.key 和 additional.fields.value.string_value | ||
| SCTP 區塊 (區塊) | chunks | additional.fields.key 和 additional.fields.value.string_value | ||
| 傳送的 SCTP 區塊 (chunks_sent) | chunks_sent | additional.fields.key 和 additional.fields.value.string_value | ||
| 收到的 SCTP 區塊 (chunks_received) | chunks_received | additional.fields.key 和 additional.fields.value.string_value | ||
| 封包 (封包) | 封包 | additional.fields.key 和 additional.fields.value.string_value | ||
| 規則的 UUID (rule_uuid) | rule_uuid | security_result.rule_id | ||
| 虛擬系統 (vsys) | vsys | intermediary.asset.attribute.labels.key/value | ||
| 虛擬系統名稱 (vsys_name) | vsys_name | intermediary.asset.attribute.labels.key/value | ||
| 傳送的封包數 (pkts_sent) | pkts_sent | network.sent_packets | ||
| 接收的封包數 (pkts_received) | pkts_received | network.received_packets |
稽核
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 生成時間 | metadata.event_timestamp | |||
| 類型 | metadata.product_event_type | |||
| 內容類型 (子類型) | metadata.product_event_type | |||
| 事件 ID | additional.fields.key 和 additional.fields.value.string_value | |||
| 物件 | principal.user.userid | |||
| 說明 | metadata.description | |||
| 狀態 | additional.fields.key 和 additional.fields.value.string_value | |||
| 序號 | intermediary.asset.hardware.serial_number |
欄位對應參考資料:記錄類型至 UDM 事件類型
下表列出 Palo Alto Networks 防火牆記錄類型,以及對應的 UDM 事件類型。
| 記錄類型 | UDM 事件類型 |
| 流量 | NETWORK_CONNECTION |
| 威脅 | NETWORK_CONNECTION |
| 網址篩選 | NETWORK_CONNECTION |
| WildFire | SCAN_UNCATEGORIZED
WildFire 提交記錄是威脅記錄類型的子類型,且使用相同的系統記錄格式。 |
| 資料篩選 | NETWORK_UNCATEGORIZED |
| Globalprotect | USER_LOGIN/USER_LOGOUT/USER_RESOURCE_ACCESS
如果子類型值為「auth」,系統會設定 USER_LOGIN。 如果子類型值為「logout」,系統會設定 USER_LOGOUT。 如果子類型不含任何值,系統會設定 USER_RESOURCE_ACCESS。 |
| 通道 | NETWORK_CONNECTION |
| GTP | NETWORK_CONNECTION |
| 設定 | SETTING_MODIFICATION/SETTING_CREATION/SETTING_DELETION/SETTING_UNCATEGORIZED
「Command (cmd)」欄位的值會決定 UDM 事件類型對應。 如果 cmd 欄位值為 add 或 clone,系統會設定 SETTING_CREATION。 如果 cmd 欄位值為 delete,系統會設定 SETTING_DELETION。 如果 cmd 欄位值為 edit、move、rename、set 或 commit,系統會設定 SETTING_MODIFICATION。 如果 cmd 欄位值不含任何值,系統會設定 SETTING_UNCATEGORIZED。 |
| 系統 |
如果子類型值為「dhcp」,系統會設定 NETWORK_DHCP。 如果子類型值為「auth」,系統就會設定 USER_LOGIN。 如果說明值為「logged in」,系統就會設定 USER_LOGIN。 如果說明值為「logged out」,系統會設定 USER_LOGOUT。 如果是子類型的其他值,則會設定為 GENERIC_EVENT。 |
| HIP Match | NETWORK_CONNECTION |
| IP 代碼 | GENERIC_EVENT |
| User-ID | USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED
如果子類型值為「login」,系統就會設定 USER_LOGIN。 如果子類型值為「logout」,系統會設定 USER_LOGOUT。 如果子類型不含任何值,系統會設定 USER_UNCATEGORIZED。 |
| 解密 | NETWORK_CONNECTION |
| 驗證 | STATUS_UNCATEGORIZED |
| SCTP | NETWORK_CONNECTION |
| 稽核 | GENERIC_EVENT |
Palo Alto Networks 防火牆 Strata 記錄服務
總覽
Palo Alto Networks Strata Logging Service 提供雲端式集中記錄儲存和彙整功能,適用於地端部署、虛擬 (私有雲和公有雲) 防火牆、Prisma Access,以及 Cortex XDR 等雲端服務。Strata Logging Service 安全無虞、具備復原能力且容錯,可確保記錄資料保持最新狀態,並在您需要時隨時可用。這項服務提供可擴充的記錄基礎架構,讓您不必規劃及部署記錄收集器,即可滿足記錄保留需求。如果您已有內部部署的記錄收集器,新的 Strata Logging Service 可做為現有設定的輔助工具。您可以透過雲端 Strata Logging Service 擴充現有的記錄檔收集基礎架構,在業務成長時擴大作業容量,或滿足新地點的容量需求。有了這項服務,Palo Alto Networks 會負責記錄檔基礎架構的持續維護和監控作業,讓您專注於業務。
確認 Strata Logging Service 剖析器支援的記錄格式和 PAN-OS 版本。下表列出 Strata Logging Service 剖析器支援的記錄格式和對應的 PAN-OS 版本:
記錄格式 PAN-OS 版本 JSON 12.1 確認 Google SecOps 剖析器支援的 Palo Alto Networks 防火牆記錄檔類型。 Google SecOps 剖析器支援下列 Palo Alto Networks 防火牆記錄類型:
- 流量
- 威脅
- 隧道檢查
- 系統
- HIP 比對
- IP-Tag
- User-ID
- 解密
- 驗證
- 網址篩選
- GlobalProtect
部署 Strata Logging 服務
- 確認 Palo Alto Networks 防火牆產品已正確部署及設定。如需詳細設定說明,請參閱 PAN-OS 說明文件,然後按照這份部署文件操作,再將記錄傳送至 Strata Logging Service Strata Logging Service 部署作業必要條件
開始將記錄檔傳送至 Strata Logging 服務:
如要開始將記錄檔傳送至 Strata Logging Service,請按照下列步驟操作:
- 安裝支援的 PAN-OS 版本
- 啟用 Strata Logging Service:啟用 Strata Logging Service 時,系統會佈建防火牆安全連線至 Strata Logging Service 時所需的憑證。
- 將防火牆加入 Strata Logging Service,可選擇是否使用 Panorama
如需詳細的啟用步驟,請參閱說明文件。
轉送 Strata Logging Service 的記錄
為滿足長期儲存、報表和監控,或法律和法規遵循需求,您可以設定 Strata Logging Service,將記錄檔轉送至 Google Chronicle。
使用 HTTPS 轉送方法,透過 Strata Logging Service 轉送記錄。如需詳細資訊,請參閱這份文件。
支援的記錄格式
Palo Alto Networks Strata Logging Service 防火牆剖析器支援 JSON 格式的記錄。
支援的範例記錄
JSON
{"source": "Palo Alto Networks FLS LF", "host": "dummy-loghost", "time": "1730265996460", "event": {"TimeReceived": "2024-10-30T05:25:50.000000Z", "DeviceSN": "no-serial", "LogType": "TRAFFIC", "Subtype": "end", "ConfigVersion": "10.2", "TimeGenerated": "2024-10-30T05:25:40.000000Z", "SourceAddress": "198.51.100.6", "DestinationAddress": "198.51.100.6", "NATSource": "", "NATDestination": "", "Rule": "egress-dns-ping-traceroute", "SourceUser": null, "DestinationUser": null, "Application": "dns-base", "VirtualLocation": "vsys1", "FromZone": "VA8280-RN", "ToZone": "inter-fw", "InboundInterface": "tunnel.101", "OutboundInterface": "tunnel.4005", "LogSetting": "Cortex Data Lake", "SessionID": 754194, "RepeatCount": 1, "SourcePort": 53578, "DestinationPort": 53, "NATSourcePort": 0, "NATDestinationPort": 0, "Protocol": "udp", "Action": "allow", "Bytes": 214, "BytesSent": 72, "BytesReceived": 142, "PacketsTotal": 2, "SessionStartTime": "2024-10-30T05:25:10.000000Z", "SessionDuration": 0, "URLCategory": "any", "SequenceNo": 7382192512716388639, "SourceLocation": "198.51.100.6-198.51.255.255", "DestinationLocation": "198.51.100.6-198.51.255.255", "PacketsSent": 1, "PacketsReceived": 1, "SessionEndReason": "aged-out", "DGHierarchyLevel1": 65537, "DGHierarchyLevel2": 65538, "DGHierarchyLevel3": 65541, "DGHierarchyLevel4": 0, "VirtualSystemName": "", "DeviceName": "VA8280-RN", "ActionSource": "from-policy", "SourceUUID": null, "DestinationUUID": null, "IMSI": 0, "IMEI": null, "ParentSessionID": 0, "ParentStarttime": "1970-01-01T00:00:00.000000Z", "Tunnel": "N/A", "EndpointAssociationID": 72057594037927936, "ChunksTotal": 0, "ChunksSent": 0, "ChunksReceived": 0, "RuleUUID": "95cfc3cc-cb00-4758-af1d-de9ab5f07f97", "HTTP2Connection": 0, "LinkChangeCount": 0, "SDWANPolicyName": null, "LinkSwitches": null, "SDWANCluster": null, "SDWANDeviceType": null, "SDWANClusterType": null, "SDWANSite": null, "DynamicUserGroupName": null, "X-Forwarded-ForIP": null, "SourceDeviceCategory": null, "SourceDeviceProfile": null, "SourceDeviceModel": null, "SourceDeviceVendor": null, "SourceDeviceOSFamily": null, "SourceDeviceOSVersion": null, "SourceDeviceHost": null, "SourceDeviceMac": null, "DestinationDeviceCategory": null, "DestinationDeviceProfile": null, "DestinationDeviceModel": null, "DestinationDeviceVendor": null, "DestinationDeviceOSFamily": null, "DestinationDeviceOSVersion": null, "DestinationDeviceHost": null, "DestinationDeviceMac": null, "ContainerID": null, "ContainerNameSpace": null, "ContainerName": null, "SourceEDL": null, "DestinationEDL": null, "GPHostID": null, "EndpointSerialNumber": null, "SourceDynamicAddressGroup": null, "DestinationDynamicAddressGroup": null, "HASessionOwner": null, "TimeGeneratedHighResolution": "2024-10-30T05:25:41.009000Z", "NSSAINetworkSliceType": null, "NSSAINetworkSliceDifferentiator": null}}"
欄位對應參考資料:記錄欄位對應至 UDM 欄位
本節說明剖析器如何將 Palo Alto Networks Strata Logging Service 防火牆記錄欄位,對應至各記錄類型的 Google UDM 事件欄位。
如需各記錄類型的對應參考資料,請參閱下列章節:
系統
下表列出「系統」記錄類型中的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| AgentContentVersion | additional.fields.key/value.string_value |
| AgentDataCollectionStatus | target.resource.attribute.labels |
| AgentID | target.resource.attribute.labels |
| AgentIsolationStatus | target.resource.attribute.labels |
| AgentStatus | target.resource.attribute.labels |
| AgentVersion | target.asset.software.version |
| ConfigVersion | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DeviceGroup | target.group.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EndpointCPUArchitecture | target.asset.hardware.cpu_platform |
| EndpointDeviceDomain | target.asset.administrative_domain |
| EndpointDeviceName | target.asset.hostname |
| EndpointIPaddress | target.asset.ip |
| VDIEndpoint | target.asset.attribute.labels |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointOSVersion | target.platform_version |
| AgentTimeZoneOffset | additional.fields.key/value.string_value |
| EndpointUserDomain | additional.fields.key/value.string_value |
| EndpointUserName | target.user.user_display_name |
| EndpointUserUUID | target.user.userid |
| EventComponent | additional.fields.key/value.string_value |
| EventDescription | metadata.description |
| EventName | additional.fields.key/value.string_value |
| EventTime | metadata.event_timestamp |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogCategory | security_result.category_details |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| LogSourceID | target.resource.attribute.labels |
| LogSourceName | target.resource.attribute.labels |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| LogTime | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Severity | security_result.severity |
| Subtype | metadata.product_event_type |
| Template | target.resource.attribute.labels |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
威脅
下表列出「威脅」記錄類型中的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| ApplianceOrCloud | additional.fields.key/value.string_value |
| CloudHostname | additional.fields.key/value.string_value |
| CloudReportID | security_result.detection_fields.key/value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DirectionOfAttack | security_result.detection_fields.key/value |
| DomainEDL | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| FileName | target.file.names |
| FileHash | target.file.sha1 |
| FileType | additional.fields.key/value.string_value |
| FileURL | target.url |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HostID | principal.asset.asset_id |
| HTTP2Connection | network.application_protocol_version |
| HTTPMethod | network.http.method |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| LocalDeepLearningAnalyzed | additional.fields.key/value.string_value |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| PartialHash | additional.fields.key/value.string_value |
| PayloadProtocolID | additional.fields.key/value.string_value |
| Packet | additional.fields.key/value.string_value |
| PacketID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| RecipientEmail | target.user.email_addresses |
| ReportID | security_result.detection_fields.key/value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SenderEmail | principal.user.email_addresses |
| SequenceNo | metadata.product_log_id |
| SessionID | network.session_id |
| Severity | security_result.severity |
| SigFlags | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| EmailSubject | network.email.subject |
| ApplicationTechnology | additional.fields.key/value.string_value |
| ThreatCategory | security_result.detection_fields.key/value.key/value |
| ThreatID | security_result.threat_id |
| ThreatName | security_result.threat_name |
| ThreatNameFirewall | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLDomain | target.domain.name |
| URLCounter | additional.fields.key/value.string_value |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| Verdict | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-ForIP | principal.ip |
流量
下表列出「流量」記錄類型的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| ActionSource | additional.fields.key/value.string_value |
| AIFwdError | additional.fields.key/value.string_value |
| AITraffic | additional.fields.key/value.string_value |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| BytesReceived | network.received_bytes |
| BytesSent | network.sent_bytes |
| Bytes | additional.fields.key/value.string_value |
| ChunksReceived | additional.fields.key/value.string_value |
| ChunksSent | additional.fields.key/value.string_value |
| ChunksTotal | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| EndpointAssociationID | additional.fields.key/value.string_value |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HASessionOwner | additional.fields.key/value.string_value |
| GPHostID | additional.fields.key/value.string_value |
| HTTP2Connection | network.application_protocol_version |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsOffloaded | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| LinkChangeCount | additional.fields.key/value.string_value |
| LinkSwitches | additional.fields.key/value.string_value |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| SDWANPolicyName | additional.fields.key/value.string_value |
| Protocol | network.ip_protocol |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SDWANFECRatio | additional.fields.key/value.string_value |
| SDWANCluster | additional.fields.key/value.string_value |
| SDWANClusterType | additional.fields.key/value.string_value |
| SDWANDeviceType | additional.fields.key/value.string_value |
| SDWANSite | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionStartTime | additional.fields.key/value.string_value |
| SessionTracker | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| SessionDuration | network.session_duration |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLCategory | target.url_metadata.categories |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-ForIP | principal.ip |
User-ID
下表列出 User-ID 記錄類型的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| AuthFactorNo | security_result.detection_fields.key/value |
| AuthenticatedUserDomain | target.user.administrative_domain |
| AuthenticatedUserName | target.user.userid |
| AuthenticatedUserUUID | target.user.product_object_id |
| ConfigVersion | additional.fields.key/value.string_value |
| CountofRepeats | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationPort | target.port |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EventID | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsDuplicateUser | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MappingDataSource | additional.fields.key/value.string_value |
| MappingDataSourceName | additional.fields.key/value.string_value |
| MappingDataSourceType | additional.fields.key/value.string_value |
| MappingTimeout | additional.fields.key/value.string_value |
| MFAFactorType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SourceIP | principal.ip |
| SourcePort | principal.port |
| Subtype | metadata.product_event_type |
| Tag | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| UGFlags | additional.fields.key/value.string_value |
| User | target.user.userid |
| UserGroupFound | additional.fields.key/value.string_value |
| UserIdentifiedBySource | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
HIP 比對
下表列出 HIP 比對記錄類型的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| ConfigVersion | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EndpointDeviceName | principal.asset.hostname |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| HipMatchName | target.resource.attribute.labels |
| HipMatchType | target.resource.attribute.labels |
| HostID | principal.asset.asset_id |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | metadata.product_event_type |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Source | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceIP | principal.ip |
| SourceIPv6 | principal.ip |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| TimestampDeviceIdentification | principal.asset.first_seen_time |
| UUID | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
IP 標記
下表列出 IP 標記記錄類型的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| ConfigVersion | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EventID | additional.fields.key/value.string_value |
| IPSubnetRange | network.ip_subnet_range |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSetting | target.resource.attribute.labels |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MappingDataSource | additional.fields.key/value.string_value |
| MappingDataSourceSubType | additional.fields.key/value.string_value |
| MappingDataSourceType | additional.fields.key/value.string_value |
| MappingTimeout | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| RuleMatched | security_result.rule_name |
| RuleMatchedUUID | security_result.rule_id |
| SequenceNo | metadata.product_log_id |
| SourceIP | principal.ip |
| Subtype | metadata.product_event_type |
| TagName | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
解密
下表列出「解密」記錄類型的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| CertificateFlags | additional.fields.key/value.string_value |
| CertificateSerial | network.tls.server.certificate.serial |
| CertificateSize | additional.fields.key/value.string_value |
| CertificateVersion | network.tls.server.certificate.version |
| ChainStatus | additional.fields.key/value.string_value |
| ApplicationCharacteristics | additional.fields.key/value.string_value |
| ClientToFirewall | additional.fields.key/value.string_value |
| CommonName | additional.fields.key/value.string_value |
| CommonNameLength | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| Cpadding | additional.fields.key/value.string_value |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| Domain | target.hostname |
| EllipticCurve | network.tls.curve |
| ErrorIndex | additional.fields.key/value.string_value |
| ErrorMessage | additional.fields.key/value.string_value |
| Fingerprint | network.tls.server.certificate.md5/sha1/sha256 |
| FirewallToClient | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsCertECDSA | additional.fields.key/value.string_value |
| IsCertRSA | additional.fields.key/value.string_value |
| IsCertCNTruncated | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| IsForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsIssuerCNTruncated | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| IsNAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| PacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsResumeSession | additional.fields.key/value.string_value |
| IsRootCNTruncated | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSNITruncated | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| IssuerCommonName | network.tls.server.certificate.issuer |
| IssuerNameLength | additional.fields.key/value.string_value |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| TimeNotAfter | additional.fields.key/value.string_value |
| TimeNotBefore | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| Padding | additional.fields.key/value.string_value |
| Padding3 | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| PolicyName | additional.fields.key/value.string_value |
| Protocol | network.ip_protocol |
| ProxyType | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| RootCommonName | additional.fields.key/value.string_value |
| RootCNLength | additional.fields.key/value.string_value |
| RootStatus | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SessionID | network.session_id |
| ServerNameIndication | network.tls.client.server_name |
| SNILength | additional.fields.key/value.string_value |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeReceivedManagementPlane | additional.fields.key/value.string_value |
| TLSAuth | additional.fields.key/value.string_value |
| TLSEncryptionAlgorithm | additional.fields.key/value.string_value |
| TLSKeyExchange | additional.fields.key/value.string_value |
| TLSVersion | network.tls.version |
| ToZone | additional.fields.key/value.string_value |
| Tpadding | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| Vpadding | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
隧道
下表列出 Tunnel 記錄類型的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| AccessPointName | additional.fields.key/value.string_value |
| Action | security_result.action |
| ActionSource | additional.fields.key/value.string_value |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| BytesReceived | network.received_bytes |
| BytesSent | network.sent_bytes |
| Bytes | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| LoggingServiceID | additional.fields.key/value.string_value |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MobileAreaCode | additional.fields.key/value.string_value |
| MobileBaseStationCode | additional.fields.key/value.string_value |
| MobileCountryCode | additional.fields.key/value.string_value |
| MobileIP | additional.fields.key/value.string_value |
| MobileNetworkCode | additional.fields.key/value.string_value |
| MobileSubscriberISDN | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceDifferentiator | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsDroppedMax | additional.fields.key/value.string_value |
| PacketsDroppedStrict | additional.fields.key/value.string_value |
| PacketsDroppedTunnel | additional.fields.key/value.string_value |
| PacketsDroppedProtocol | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| ProtocolDataUnitsessionID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| RadioAccessTechnology | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionStartTime | additional.fields.key/value.string_value |
| SessionTracker | additional.fields.key/value.string_value |
| Severity | security_result.severity |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| StandardPortsOfApp | additional.fields.key/value.string_value |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| SessionDuration | network.session_duration |
| Tunnel | additional.fields.key/value.string_value |
| TunnelCauseCode | additional.fields.key/value.string_value |
| TunnelEndpointID1 | additional.fields.key/value.string_value |
| TunnelEndpointID2 | additional.fields.key/value.string_value |
| TunnelEventCode | additional.fields.key/value.string_value |
| TunnelEventType | additional.fields.key/value.string_value |
| TunnelInspectionRule | additional.fields.key/value.string_value |
| TunnelInterface | additional.fields.key/value.string_value |
| TunnelMessageType | additional.fields.key/value.string_value |
| TunnelRemoteIMSIID | additional.fields.key/value.string_value |
| TunnelRemoteUserIP | principal.ip |
| TunnelSessionsClosed | additional.fields.key/value.string_value |
| TunnelSessionsCreated | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLCategory | target.url_metadata.categories |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
驗證
下表列出「驗證」記錄類型的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| AuthenticationDescription | security_result.description |
| AuthEvent | metadata.description |
| AuthFactorNo | security_result.detection_fields.key/value |
| AuthenticationPolicy | security_result.detection_fields.key/value |
| AuthenticationProtocol | additional.fields.key/value.string_value |
| AuthServerProfile | additional.fields.key/value.string_value |
| AuthenticatedUserDomain | target.administrative_domain |
| AuthenticatedUserName | target.user.userid |
| AuthenticatedUserUUID | target.user.product_object_id |
| ClientType | additional.fields.key/value.string_value |
| ClientTypeName | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| Location | target.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogType | additional.fields.key/value.string_value |
| MFAAuthenticationID | additional.fields.key/value.string_value |
| MFAVendor | additional.fields.key/value.string_value |
| NormalizeUser | target.user.user_display_name |
| Object | target.resource.name |
| RuleMatched | security_result.rule_name |
| RuleMatchedUUID | security_result.rule_id |
| AuthCacheServiceRegion | additional.fields.key/value.string_value |
| SessionID | network.session_id |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceIP | principal.ip |
| TimeGenerated | metadata.event_timestamp |
| User | target.user.userid |
| UserAgentString | network.http.user_agent |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Subtype | metadata.product_event_type |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
網址
下表列出網址記錄類型的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| CloudHostname | additional.fields.key/value.string_value |
| CloudReportID | security_result.detection_fields.key/value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentType | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DirectionOfAttack | security_result.detection_fields.key/value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| FileURL | target.url |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HostID | principal.asset.asset_id |
| HTTP2Connection | network.application_protocol_version |
| HTTPHeaders | additional.fields.key/value.string_value |
| HTTPMethod | network.http.method |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| InlineMLVerdict | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| Packet | additional.fields.key/value.string_value |
| PacketID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| Referer | network.http.referral_url |
| HTTPRefererFQDN | additional.fields.key/value.string_value |
| HTTPRefererPort | additional.fields.key/value.string_value |
| HTTPRefererProtocol | additional.fields.key/value.string_value |
| HTTPRefererURLPath | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionID | network.session_id |
| Severity | security_result.severity |
| SigFlags | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URL | target.url_metadata.URL |
| URLCategory | target.url_metadata.categories |
| URLCategoryList | additional.fields.key/value.string_value |
| URLDomain | target.domain.name |
| URLCounter | additional.fields.key/value.string_value |
| UserAgent | network.http.user_agent |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-For | additional.fields.key/value.string_value |
| X-Forwarded-ForIP | principal.ip |
GlobalProtect
下表列出 GlobalProtect 記錄類型的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| AttemptedGateways | additional.fields.key/value.string_value |
| AuthMethod | extensions.auth.auth_details |
| ConnectionMethod | additional.fields.key/value.string_value |
| ConnectionErrorID | additional.fields.key/value.string_value |
| ConnectionError | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| EndpointDeviceName | principal.asset.hostname |
| GlobalProtectClientVersion | additional.fields.key/value.string_value |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointSN | principal.asset.hardware.serial_number |
| EventIDValue | additional.fields.key/value.string_value |
| Gateway | target.resource.name |
| GatewayPriority | additional.fields.key/value.string_value |
| GatewaySelectionType | additional.fields.key/value.string_value |
| GlobalProtectGatewayLocation | target.location.country_or_region |
| HostID | principal.asset.asset_id |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LoginDuration | network.session_duration |
| Description | security_result.description |
| Portal | target.hostname |
| PrivateIPv4 | principal.ip |
| PrivateIPv6 | principal.ip |
| ProjectName | additional.fields.key/value.string_value |
| PublicIPv4 | principal.nat_ip |
| PublicIPv6 | principal.nat_ip |
| QuarantineReason | security_result.summary |
| SequenceNo | metadata.product_log_id |
| SourceRegion | principal.location.country_or_region |
| SourceUserName | principal.user.user_display_name |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SSLResponseTime | additional.fields.key/value.string_value |
| Stage | additional.fields.key/value.string_value |
| EventStatus | additional.fields.key/value.string_value |
| LogSubtype | metadata.product_event_type |
| TunnelType | additional.fields.key/value.string_value |
| VirtualSystem | intermediary.asset.attribute.labels |
| VirtualSystemName | intermediary.asset.attribute.labels |
| EndpointOSVersion | principal.platform_version |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | metadata.product_event_type |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualSystemID | intermediary.resource.product_object_id |
SCTP
下表列出 SCTP 記錄類型的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| AssocationEndReason | additional.fields.key/value.string_value |
| ChunksReceived | additional.fields.key/value.string_value |
| ChunksSent | additional.fields.key/value.string_value |
| ChunksTotal | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceClass | target.asset.category |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationIP | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DiamAppID | additional.fields.key/value.string_value |
| DiamAvpCode | additional.fields.key/value.string_value |
| DiameterCommandCode | additional.fields.key/value.string_value |
| DiameterRequestFlag | additional.fields.key/value.string_value |
| DeviceName | principal.asset.hostname |
| SCTPEventType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLFiltering | additional.fields.key/value.string_value |
| IsWildfire | additional.fields.key/value.string_value |
| LogAction | additional.fields.key/value.string_value |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MapAppCode | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PayloadProtocolID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SccpCallingGt | additional.fields.key/value.string_value |
| SccpCallingSSN | additional.fields.key/value.string_value |
| SctpCauseCode | additional.fields.key/value.string_value |
| SctpChunkType | additional.fields.key/value.string_value |
| SctpFilter | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionTracker | additional.fields.key/value.string_value |
| Severity | security_result.severity |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceIP | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VerificationTag1 | additional.fields.key/value.string_value |
| VerificationTag2 | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
稽核
下表列出稽核記錄類型和對應 UDM 欄位的記錄檔欄位。
| Log field | UDM mapping |
|---|---|
| EventCategory | network.http.method |
| EventDescription | metadata.description |
| EventDestinationURL | target.url |
| EventDestinationUserUserID | target.user.userid |
| DestinationVendor | additional.fields.key/value.string_value |
| EventDetails | additional.fields.key/value.string_value |
| EventID | metadata.product_log_id |
| EventName | additional.fields.key/value.string_value |
| EventResult | security_result.summary |
| EventSourceUserUserID | principal.user.userid |
| EventTime | metadata.event_timestamp |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| Subtype | metadata.product_event_type |
| TSGID | additional.fields.key/value.string_value |
| Vendor | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
欄位對應參考資料:記錄類型至 UDM 事件類型
下表列出 Palo Alto Networks Strata Logging Service 防火牆記錄類型,以及對應的 UDM 事件類型。
| 記錄類型 | UDM 事件類型 |
| 流量 | NETWORK_CONNECTION |
| 威脅 | NETWORK_CONNECTION |
| 網址篩選 | NETWORK_CONNECTION |
| 通道 | NETWORK_CONNECTION |
| 系統 |
如果子類型值為「dhcp」,系統會設定 NETWORK_DHCP。 如果子類型值為「auth」,系統就會設定 USER_LOGIN。 如果說明值為「logged in」,系統就會設定 USER_LOGIN。 如果說明值為「logged out」,系統會設定 USER_LOGOUT。 如果是子類型的其他值,則會設定為 GENERIC_EVENT。 |
| HIP Match | NETWORK_CONNECTION |
| IP 代碼 | GENERIC_EVENT |
| User-ID | USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED
如果子類型值為「login」,系統就會設定 USER_LOGIN。 如果子類型值為「logout」,系統會設定 USER_LOGOUT。 如果子類型不含任何值,系統會設定 USER_UNCATEGORIZED。 |
| 解密 | NETWORK_CONNECTION |
| 驗證 | STATUS_UNCATEGORIZED |
| Globalprotect | USER_LOGIN/USER_LOGOUT/USER_RESOURCE_ACCESS
如果子類型值為「auth」,系統會設定 USER_LOGIN。 如果子類型值為「logout」,系統會設定 USER_LOGOUT。 如果子類型不含任何值,系統會設定 USER_RESOURCE_ACCESS。 |
| SCTP | NETWORK_CONNECTION |
| 稽核 | GENERIC_EVENT |
後續步驟
還有其他問題嗎?向社群成員和 Google SecOps 專業人員尋求答案。