Palo Alto Networks-Firewallprotokolle erfassen
Palo Alto Networks-Firewall
Übersicht
In diesem Dokument wird beschrieben, wie Sie Syslog und einen Google SecOps-Forwarder konfigurieren, um Firewall-Logs von Palo Alto Networks zu erfassen. In diesem Dokument wird auch erläutert, wie Palo Alto Networks-Firewall-Logfelder den Feldern des Google SecOps Unified Data Model (UDM) zugeordnet werden. Eine Übersicht über die Datenaufnahme in Google SecOps finden Sie unter Datenaufnahme in Google SecOps. Ein Erfassungslabel identifiziert den Parser, der Logrohdaten in das strukturierte UDM-Format normalisiert. Die Informationen in diesem Dokument beziehen sich auf den Parser mit dem Aufnahme-Label „PAN_FIREWALL“.
Hinweise
- Prüfen Sie, ob das Firewallprodukt von Palo Alto Networks richtig bereitgestellt und konfiguriert ist. Eine ausführliche Einrichtungsanleitung finden Sie in der PAN-OS-Dokumentation.
Sehen Sie sich die Bereitstellungsarchitektur an, um die Komponenten zu verstehen, die zum Erfassen von Palo Alto Networks-Firewall-Logs bereitgestellt werden. Die Bereitstellung bei jedem Kunden kann von dieser Darstellung abweichen und komplexer sein. Das folgende Diagramm zeigt, wie Sie Syslog auf einer Palo Alto Networks-Firewall konfigurieren und einen Google SecOps-Forwarder auf einem Linux-Server installieren, um Protokolldaten an Google SecOps weiterzuleiten. Der Parser unterstützt Protokolle in den folgenden Datenformaten: Comma Separated Values (CSV), Common Event Format (CEF) und Log Event Extended Format (LEEF).
Prüfen Sie die Logformate und PAN-OS-Versionen, die vom Google SecOps-Parser unterstützt werden. In der folgenden Tabelle sind die Logformate und die entsprechenden PAN-OS-Versionen aufgeführt, die vom Google SecOps-Parser unterstützt werden:
Log format PAN-OS-Version CSV 10.1.3 CEF 10.0.0 LEEF 9.1.0 Prüfen Sie die Palo Alto Networks-Firewall-Logtypen, die vom Google SecOps-Parser unterstützt werden. Der Google SecOps-Parser unterstützt die folgenden Palo Alto Networks-Firewall-Logtypen:
- Traffic
- Bedrohung
- WildFire-Einreichungen
- Tunnelinspektion
- Konfiguration
- System
- Übereinstimmung mit dem HIP
- IP-Tag
- User-ID
- Entschlüsselung
- Authentifizierung
- URL-Filter
- Datenfilterung
- GlobalProtect
- Ergebnisse in Beziehung setzen
- GTP
- SCTP
- Audit
Weitere Informationen zu den Palo Alto Networks-Firewall-Logtypen finden Sie unter PAN-OS-Logtypen.
Achten Sie darauf, dass alle Systeme in der Bereitstellungsarchitektur in der UTC-Zeitzone konfiguriert sind.
Bevor Sie den Palo Alto Networks-Firewallparser verwenden, sollten Sie sich die Änderungen bei den Feldzuordnungen zwischen dem vorherigen Parser und dem aktuellen Palo Alto Networks-Firewallparser ansehen. Achten Sie im Rahmen der Migration darauf, dass für Regeln, Suchvorgänge, Dashboards oder andere Prozesse, die von den ursprünglichen Feldern abhängen, die aktualisierten Felder verwendet werden.
In der vorherigen Parserversion wird das Logfeld
categorybeispielsweise dem UDM-Feldsecurity_result.descriptionzugeordnet. Im aktuellen Palo Alto Networks-Firewall-Parser wird das Logfeldcategorydem UDM-Feldsecurity_result.category_detailszugeordnet. Wenn Sie zur aktuellen Palo Alto Networks-Firewall migrieren und das Feldcategoryin Ihren Regeln verwenden, müssen Sie die Regeln so ändern, dass das UDM-Feldsecurity_result.category_detailsdes aktuellen Parsers verwendet wird.
Syslog und den Google Security Operations-Forwarder konfigurieren
Führen Sie die folgenden Schritte aus, um Syslog und den Google SecOps-Forwarder zu konfigurieren:
- Konfigurieren Sie das Syslog-Serverprofil, um CSV-Logs zu überwachen. Weitere Informationen finden Sie unter Syslog-Serverprofil konfigurieren. Wenn Sie das Syslog-Serverprofil konfigurieren, geben Sie „Default“ als benutzerdefiniertes Logformat an.
- Wenn Sie CEF-Logs überwachen möchten, konfigurieren Sie die Palo Alto Networks-Firewall so, dass CEF-Logs weitergeleitet werden. Weitere Informationen finden Sie im PAN-OS CEF Integration Guide (PDF) im Abschnitt „Configuration of Palo Alto Networks NGFW to output CEF events“.
- Konfigurieren Sie das Syslog-Serverprofil, um LEEF-Logs zu überwachen. Weitere Informationen finden Sie unter Benutzerdefinierte Logweiterleitung im LEEF-Format.
Konfigurieren Sie den Google SecOps-Forwarder so, dass Logs an Google Security Operations gesendet werden. Weitere Informationen finden Sie unter Forwarder unter Linux installieren und konfigurieren. Das folgende Beispiel zeigt eine Google SecOps-Forwarder-Konfiguration:
- syslog: common: enabled: true data_type: PAN_FIREWALL batch_n_seconds: 10 batch_n_bytes: 1048576 tcp_address: 0.0.0.0:10518 connection_timeout_sec: 60
Syslog-Weiterleitung auf PAN Firewall konfigurieren
Syslog-Serverprofil erstellen
- Melden Sie sich in der Palo Alto Networks Firewall Management Console an.
- Gehen Sie zu Gerät > Serverprofile > Syslog.
- Klicken Sie auf Hinzufügen, um ein neues Serverprofil zu erstellen.
- Geben Sie die folgenden Konfigurationsdetails an:
- Name: Geben Sie einen aussagekräftigen Namen ein, z. B.
Google SecOps BindPlane. - Standort: Wählen Sie das virtuelle System (vsys) oder Shared (Freigegeben) aus, in dem dieses Profil verfügbar sein soll.
- Name: Geben Sie einen aussagekräftigen Namen ein, z. B.
- Klicken Sie auf Servers > Add, um den Syslog-Server zu konfigurieren.
- Geben Sie die folgenden Details zur Serverkonfiguration an:
- Name: Geben Sie einen aussagekräftigen Namen für den Server ein, z. B.
BindPlane Agent. - Syslog-Server: Geben Sie die IP-Adresse des BindPlane-Agents ein.
- Transport: Wählen Sie je nach BindPlane-Agent-Konfiguration UDP oder TCP aus (UDP ist die Standardeinstellung).
- Port: Geben Sie die Portnummer des BindPlane-Agents ein (z. B.
514). - Format: Wählen Sie je nach Bedarf BSD (Standard) oder IETF aus.
- Einrichtung: Wählen Sie LOG_USER (Standard) oder eine andere Einrichtung aus.
- Name: Geben Sie einen aussagekräftigen Namen für den Server ein, z. B.
- Klicken Sie auf OK, um das Syslog-Serverprofil zu speichern.
Optional: Benutzerdefiniertes Logformat für CEF oder LEEF konfigurieren
Wenn Sie anstelle von CSV-Dateien CEF- (Common Event Format) oder LEEF-Logs (Log Event Extended Format) benötigen:
- Wählen Sie im Syslog-Serverprofil den Tab Benutzerdefiniertes Logformat aus.
- Konfigurieren Sie das benutzerdefinierte Logformat für jeden Logtyp (Konfiguration, System, Bedrohung, Traffic, URL, Daten, WildFire, Tunnel, Authentifizierung, User-ID, HIP Match).
- Informationen zur Konfiguration des CEF-Formats finden Sie im Palo Alto Networks CEF Configuration Guide.
- Klicken Sie auf OK, um die Konfiguration zu speichern.
Profil für die Logweiterleitung erstellen
- Rufen Sie Objekte > Log-Weiterleitung auf.
- Klicken Sie auf Hinzufügen, um ein neues Profil für die Protokollweiterleitung zu erstellen.
- Geben Sie die folgenden Konfigurationsdetails an:
- Name: Geben Sie einen Profilnamen ein, z. B.
Google SecOps Forwarding. Wenn die Firewall dieses Profil automatisch neuen Sicherheitsregeln und Zonen zuweisen soll, nennen Sie esdefault.
- Name: Geben Sie einen Profilnamen ein, z. B.
- Konfigurieren Sie für jeden Logtyp, den Sie weiterleiten möchten (Traffic, Threat, WildFire Submission, URL Filtering, Data Filtering, Tunnel, Authentication), Folgendes:
- Klicken Sie im entsprechenden Protokolltyp-Abschnitt auf Hinzufügen.
- Syslog: Wählen Sie das von Ihnen erstellte Syslog-Serverprofil aus (z. B.
Google SecOps BindPlane). - Logschweregrad: Wählen Sie die Schweregrade aus, die weitergeleitet werden sollen, z. B. Alle.
- Klicken Sie auf OK, um das Profil für die Protokollweiterleitung zu speichern.
Logweiterleitungsprofil auf Sicherheitsrichtlinien anwenden
- Rufen Sie Richtlinien > Sicherheit auf.
- Wählen Sie die Sicherheitsregeln aus, für die Sie die Logweiterleitung aktivieren möchten.
- Klicken Sie auf die Regel, um sie zu bearbeiten.
- Rufen Sie den Tab Aktionen auf.
- Wählen Sie im Menü Log Forwarding (Log-Weiterleitung) das von Ihnen erstellte Profil für die Log-Weiterleitung aus (z. B.
Google SecOps Forwarding). - Klicken Sie auf OK, um die Konfiguration der Sicherheitsrichtlinie zu speichern.
Logeinstellungen für Systemlogs konfigurieren
- Gehen Sie zu Gerät > Protokolleinstellungen.
- Wählen Sie für jeden Logtyp (System, Konfiguration, Nutzer-ID, HIP-Abgleich, GlobalProtect, IP-Tag, SCTP) und jede Schweregradstufe das von Ihnen erstellte Syslog-Serverprofil aus.
- Klicken Sie auf OK, um die Protokolleinstellungen zu speichern.
Änderungen per Commit durchführen
- Klicken Sie oben in der Web-Oberfläche der Firewall auf Commit.
- Warten Sie, bis der Commit erfolgreich abgeschlossen ist.
- Prüfen Sie in der Google SecOps Console, ob Palo Alto Networks-Firewall-Logs eingehen, um zu bestätigen, dass Logs an den Bindplane-Agent gesendet werden.
Logs mit dem BindPlane-Agent an Google SecOps weiterleiten
- Installieren und richten Sie eine virtuelle Linux-Maschine ein.
- BindPlane-Agent unter Linux installieren und konfigurieren, um Logs an Google SecOps weiterzuleiten Weitere Informationen zur Installation und Konfiguration des Bindplane-Agents finden Sie in der Anleitung zur Installation und Konfiguration des Bindplane-Agents.
Wenn beim Erstellen von Feeds Probleme auftreten, wenden Sie sich an den Google SecOps-Support.
Unterstützte Logformate
Der Palo Alto Networks-Firewall-Parser unterstützt Logs im LEEF-, CEF- und CSV-Format.
Unterstützte Beispiellogs
LEEF
<14>Jan 22 02:20:19 device_host LEEF:1.0|Palo Alto Networks|PAN-OS Syslog Integration|10.2.12-h4|Microsoft MSOFFICE(52033)|ReceiveTime=2025/01/22 02:20:18|SerialNumber=01250100xxxx|cat=THREAT|Subtype=wildfire|devTime=Jan 22 2025 08:20:18 GMT|src=198.50.100.1|dst=198.50.100.2|srcPostNAT=198.50.100.3|dstPostNAT=198.50.100.4|RuleName=AZURE-US-NEW-CNF_Inbound_To_Azure-ALLOW|usrName=|SourceUser=|DestinationUser=|Application=smtp-base|VirtualSystem=vsys1|SourceZone=McD-Global-Zone|DestinationZone=Azure-Zone|IngressInterface=ae1.111|EgressInterface=ae2.409|LogForwardingProfile=Default-Traffic-Logging|SessionID=35331795|RepeatCount=1|srcPort=21578|dstPort=25|srcPostNATPort=0|dstPostNATPort=0|Flags=0x2000|proto=tcp|action=allow|Miscellaneous=\"......3...................xls\"|ThreatID=Microsoft MSOFFICE(52033)|URLCategory=malicious|sev=4|Severity=high|Direction=client-to-server|sequence=7462614601465681755|ActionFlags=0x8000000000000000|SourceLocation=198.50.100.1-198.50.100.255|DestinationLocation=United States|ContentType=|PCAP_ID=0|FileDigest=0ea04c99bf188c2e4207f60f92ca7c6f5088c7943ee63f45c50032bbd2bf7ea9|Cloud=demo.com|URLIndex=1|RequestMethod=|FileType=ms-office|Sender=sender@ab.myownpersonaldomain.com|Subject=\"............:.................................................................................-.........(Name)-2025-01-22...............:Y107202501220005, ............:........................, ...............:.........\"|Recipient=abc@demo.myownpersonaldomain.com|ReportID=117022282776|DeviceGroupHierarchyL1=143|DeviceGroupHierarchyL2=144|DeviceGroupHierarchyL3=39|DeviceGroupHierarchyL4=0|vSrcName=|DeviceName=device_host|SrcUUID=|DstUUID=|TunnelID=0|MonitorTag=|ParentSessionID=0|ParentStartTime=|TunnelType=N/A|ThreatCategory=N/A|ContentVer=WildFire-0CEF
14>1 2024-04-04T16:21:56+02:00 FW-PERIMETRAL-AVG-01 - - - - CEF:0|Palo Alto Networks|PAN-OS|10.1.10-h2|end|TRAFFIC|1|src=198.51.100.1 dst=198.51.100.2 srcTranslatedAddress=198.51.100.3 dstTranslatedAddress=198.51.100.4 rule=FW_USER_NATS2_APP suser= duser= app=bittorrent vs=vsys1 sz=INSIDE dz=EXTERNAL InboundInterface=ae2.2266 OutboundInterface=ae1 lp=log_forwarding sid=2935823 cnt=1 spt=6881 dpt=51413 srcTranslatedPort=0 dstTranslatedPort=0 flags=0x7a proto=udp act=allow tbytes=475 in=150 out=325 pkt=2 pktReceived=1 pktSent=1 start=Apr 04 2024 14:21:56 GMT stime=1206 urlcat=any externalId=externalId reason=aged-out DGl1=11 DGl2=161 DGl3=0 DGl4=0 VsysName=STONESOFT dvchost=FW-PERIMETRAL-AVG-01 cat=from-policy ActionFlags=0x8000000000000000 srcUUID= dstUUID= TunnelID=0 MonitorTag= ParentSessionID=0 ParentStartTime= TunnelType=N/A SCTPAssocID=0 SCTPChunks=0 SCTPChunkSent=0 SCTPChunksRcv=0 RuleUUID=746c3eb6-3d51-4679-8438-bd0e00e170a8 HTTP2Con=0 LinkChange=0 PolicyID= LinkDetail= SDWANCluster= SDWANDevice= SDWANClustype= SDWANSite= DynamicUsrgrp= XFFIP= srcDevCat= srcDevProf= srcDevModel= srcDevVendor= srcDevOS= srcDevOSv= srcHostname= srcMac= dstDevCat= dstDevProf= dstDevModel= dstDevVendor= dstDevOS= dstDevOSv= dstHostname= dstMac= ContainerName= PODNamespace= PODName= srcEDL= dstEDL= GPHostID= EPSerial= srcDAG= dstDAG= HASessionOwner= TimeHighRes=2024-04-04T16:21:56.250+02:00 ASServiceType= ASServiceDiff="CSV
1,2021/10/24 15:30:07,,CONFIG,0,2561,2021/10/24 15:30:07,198.51.100.0,,set,admin,Web,Succeeded, network virtual-router VR1,,VR1 { ecmp { algorithm { ip-modulo ; } } protocol { bgp { routing-options { graceful-restart { enable yes; } } enable no; } rip { enable no; } ospf { enable no; } ospfv3 { enable no; } } routing-table { ip { static-route { vr1-log { path-monitor { enable no; failure-condition any; hold-time 2; } nexthop { ip-address 198.51.100.0; } bfd { profile None; } interface ethernet1/1; metric 10; destination 0.0.0.0/0; route-table { unicast ; } } } } } interface [ ethernet1/1 ethernet1/2 ]; } ,7022390503849066572,0x0,0,0,0,0,,PA-VM,0,
Referenz zur Feldzuordnung: Logfelder zu UDM-Feldern
In diesem Abschnitt wird beschrieben, wie der Parser Palo Alto Networks-Firewall-Logfelder für jeden Logtyp Google SecOps UDM-Ereignisfeldern zuordnet. Der Google SecOps-Labelschlüssel bezieht sich auf den Namen des Schlüssels, der dem UDM-Feld „Labels.key“ zugeordnet ist.
Beispiel: Für das Feld „Virtual System“ ist der Feldname im CEF-Format „cs3“ und im LEEF-Format „VirtualSystem“. Das UDM-Feld „about.labels.key“ enthält den Wert „vsys“ und das UDM-Feld „about.labels.value“ enthält den Wert dieses Felds. Einige CEF- oder LEEF-Feldnamen haben keinen Namen, der den CSV-Feldnamen entspricht. Wenn Sie in solchen Fällen einen eigenen Variablennamen im benutzerdefinierten Logformat im Syslog-Profil hinzufügen, wird er vom Parser nicht dem UDM-Feld zugeordnet.
In den folgenden Abschnitten finden Sie eine Zuordnungsreferenz für jeden Logtyp:
- System
- Konfiguration
- Bedrohung/Waldbrand
- Traffic
- Nutzer-ID
- HIP-Abgleich
- IP-Tag
- Entschlüsselung
- Tunnel
- Authentifizierung
- URL
- Daten
- GlobalProtect
- Korrelation
- GTP
- SCTP
- Prüfung
System
In der folgenden Tabelle sind die Logfelder des Systemlogtyps und die entsprechenden UDM-Felder aufgeführt.
| CSV-Feld | CEF-Feld | LEEF-Feld | Schlüssel für Google Security Operations-Label | UDM-Feld |
|---|---|---|---|---|
| Empfangszeit (receive_time oder cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist) |
|
| Seriennummer (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Typ (type) | Typ (Header) | cat | metadata.product_event_type ist auf „%{type} – %{subtype}“ festgelegt. | |
| Bedrohungs-/Inhaltstyp (Untertyp) | Untertyp (Kopfzeile) | Subtyp | metadata.product_event_type ist auf „%{type} – %{subtype}“ festgelegt. | |
| Generierte Zeit (time_generated oder cef-formatted-time_generated) | metadata.event_timestamp | |||
| Virtuelles System (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| Ereignis-ID (eventid) | cat | eventid | additional.fields.key und additional.fields.value.string_value | |
| Objekt (Objekt) | fname | Dateiname | Objekt | target.resource.name |
| Modul (module) | flexString2 | Modul | module | additional.fields.key und additional.fields.value.string_value |
| Schweregrad (severity) | $number-of-severity(header) | Schweregrad | security_result.severity und security_result.severity_details | |
| Beschreibung (undurchsichtig) | msg | msg | metadata.description | |
| principal_user_userid (Dieses Feld wird aus dem Feld „msg“ extrahiert.) | principal.user.userid | |||
| principal_ip3 (Dieses Feld wird aus dem Feld „msg“ extrahiert.) | principal.ip | |||
| Grund (Dieses Feld wird aus dem Feld „msg“ extrahiert.) | security_result.description | |||
| server_address (Dieses Feld wird aus dem Feld „msg“ extrahiert.) | target.ip | |||
| server_profile (Dieses Feld wird aus dem Feld „msg“ extrahiert.) | additional.fields.key und additional.fields.value.string_value | |||
| Sequenznummer (seqno) | externalId | Sequenz | metadata.product_log_id | |
| Aktions-Flags (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key und additional.fields.value.string_value |
| Gerätegruppenhierarchie (dg_hier_level_1 bis dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key und additional.fields.value.string_value |
| Hierarchie der Gerätegruppen (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key und additional.fields.value.string_value |
| Gerätegruppenhierarchie (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key und additional.fields.value.string_value |
| Gerätegruppenhierarchie (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key und additional.fields.value.string_value |
| Name des virtuellen Systems (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Gerätename (device_name) | dvchost | DeviceName | target.hostname | |
| Zeitstempel mit hoher Auflösung (high_res_timestamp) | anOSTimeGeneratedHighResolution | additional.fields.key und additional.fields.value.string_value |
Konfiguration
In der folgenden Tabelle sind die Logfelder des Konfigurationslogtyps und die entsprechenden UDM-Felder aufgeführt.
| CSV-Feld | CEF-Feld | LEEF-Feld | Schlüssel für Google Security Operations-Label | UDM-Feld |
|---|---|---|---|---|
| Empfangszeit (receive_time oder cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist) |
|
| Seriennummer (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Typ (type) | Typ (Header) | cat | metadata.product_event_type | |
| Bedrohungs-/Inhaltstyp (Untertyp) | Untertyp (Kopfzeile) | metadata.product_event_type | ||
| Generierte Zeit (time_generated oder cef-formatted-time_generated) | metadata.event_timestamp | |||
| Host (host) | shost | src | principal.ip/hostname | |
| Virtuelles System (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| Befehl (cmd) | Handeln | msg | CMD | principal.process.command_line |
| Administrator (admin) | duser | usrName | principal.user.userid | |
| Client (client) | destinationServiceName | Client | principal.application | |
| Ergebnis (result) | Signatur-ID (Header)(reason) | Ergebnis | security_result.summary | |
| Konfigurationspfad (path) | msg | ConfigurationPath | principal.process.command_line | |
| Before Change Detail (before_change_detail) | cs1 | BeforeChangeDetail | before_change_detail | target.resource.attribute.labels.key/value |
| After Change Detail (after_change_detail) | cs2 | AfterChangeDetail | after_change_detail | target.resource.attribute.labels.key/value |
| Sequenznummer (seqno) | externalId | Sequenz | metadata.product_log_id | |
| Aktions-Flags (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key und additional.fields.value.string_value |
| Gerätegruppenhierarchie (dg_hier_level_1 bis dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key und additional.fields.value.string_value |
| Hierarchie der Gerätegruppen (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key und additional.fields.value.string_value |
| Gerätegruppenhierarchie (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key und additional.fields.value.string_value |
| Gerätegruppenhierarchie (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key und additional.fields.value.string_value |
| Name des virtuellen Systems (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Gerätename (device_name) | dvchost | DeviceName | target.hostname | |
| Gerätegruppe (dg_id) | PanOSFWDeviceGroup | target.asset.attribute.labels.key/value | dg_id | principal.asset.attribute.labels.key/value |
| Audit-Kommentar (comment) | PanOSPolicyAuditComment | Kommentar | additional.fields.key und additional.fields.value.string_value | |
| Zeitstempel mit hoher Auflösung (high_res_timestamp) | additional.fields.key und additional.fields.value.string_value | |||
| Schweregrad (severity) | number-of-severity(header) | security_result.severity und security_result.severity_details |
Threat/WildFire
In der folgenden Tabelle sind die Logfelder des Logtyps „Threat/WildFire“ und die entsprechenden UDM-Felder aufgeführt.
| CSV-Feld | CEF-Feld | LEEF-Feld | Schlüssel für Google Security Operations-Label | UDM-Feld |
|---|---|---|---|---|
| Empfangszeit (receive_time oder cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist) |
|
| Seriennummer | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Typ (type) | Typ (Header) | cat | metadata.product_event_type | |
| Bedrohungs-/Inhaltstyp (Untertyp) | cat/subtype (Header) | Subtyp | metadata.product_event_type | |
| Generierungszeit (time_generated oder cef-formatted-time_generated) | metadata.event_timestamp | |||
| Quelladresse (src) | src | src | principal.ip | |
| Zieladresse (dst) | dst | dst | target.ip | |
| NAT-Quell-IP-Adresse (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| NAT-Ziel-IP-Adresse (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Regelname (rule) | cs1 | RuleName | security_result.rule_name | |
| Quellnutzer (srcuser) | suser | SourceUser / usrName | principal.user.userid | |
| Zielnutzer (dstuser) | duser | DestinationUser | target.user.userid | |
| Anwendung (App) | App | Anwendung | target.application | |
| Virtuelles System (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Quellzone (von) | cs4 | SourceZone | von | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
| Zielzone (bis) | cs5 | DestinationZone | bis | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
| Eingangsschnittstelle (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
| Ausgangsschnittstelle (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
| Aktion protokollieren (Logset) | cs6 | LogForwardingProfile | logset | additional.fields.key und additional.fields.value.string_value |
| Sitzungs-ID (sessionid) | cn1 | SessionID | network.session_id | |
| Anzahl der Wiederholungen (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key und additional.fields.value.string_value |
| Quellport (sport) | spt | srcPort | principal.port | |
| Zielport (dport) | dpt | dstPort | target.port | |
| NAT-Quellport (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| NAT-Zielport (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Flags (flags) | flexString1 | Flags | flags | additional.fields.key und additional.fields.value.string_value |
| IP-Protokoll (proto) | Proto | Proto | network.ip_protocol | |
| Aktion (action) | Handeln | Aktion | security_result.action_details
security_result.action |
|
| URL/Dateiname (Sonstiges) | Anfrage | Sonstiges | target.file.names (wenn der Untertyp „file“, „virus“, „wildfire-virus“ oder „wildfire“ ist, wird das Feld „misc“ target.file.names zugeordnet) target.url (wenn der Untertyp „url“ ist, wird das Feld „misc“ target.url und target.hostname zugeordnet) |
|
| Name der Bedrohung/des Inhalts (threatid) | cat | ThreatID | security_result.threat_name | |
| Kategorie (category) | cs2 | URLCategory | security_result.category_details | |
| Schweregrad (severity) | number-of-severity(header) | Schweregrad | security_result.severity und security_result.severity_details | |
| Richtung (direction) | flexString2 | Richtung | network.direction | |
| Sequenznummer (seqno) | externalId | Sequenz | metadata.product_log_id | |
| Aktions-Flags (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key und additional.fields.value.string_value |
| Quellland (srcloc) | SourceLocation | principal.location.country_or_region | ||
| Zielland (dstloc) | DestinationLocation | target.location.country_or_region | ||
| Inhaltstyp (contenttype) | ContentType | contenttype | additional.fields.key und additional.fields.value.string_value | |
| PCAP-ID (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key und additional.fields.value.string_value |
| File Digest (filedigest) | fileHash | FileDigest | target.file.sha1/md5/sha256 | |
| Cloud (cloud) | filePath | Cloud | Cloud | additional.fields.key und additional.fields.value.string_value |
| URL-Index (url_idx) | URLIndex | url_idx | additional.fields.key und additional.fields.value.string_value | |
| User-Agent (user_agent) | network.http.user_agent | |||
| Dateityp (filetype) | fileType | FileType | target.file.mime_type | |
| X-Forwarded-For (xff) | principal.ip | |||
| Referrer (referer) | network.http.referral_url | |||
| Absender (sender) | suid | Absender | network.email.from | |
| Betreff (Subjekt) | msg | Betreff | network.email.subject | |
| Empfänger (recipient) | duid | Empfänger | network.email.to | |
| Berichts-ID (reportid) | oldFileId | ReportID | reportid | additional.fields.key und additional.fields.value.string_value |
| Gerätegruppenhierarchie (dg_hier_level_1 bis dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key und additional.fields.value.string_value |
| Hierarchie der Gerätegruppen (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key und additional.fields.value.string_value |
| Gerätegruppenhierarchie (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key und additional.fields.value.string_value |
| Gerätegruppenhierarchie (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key und additional.fields.value.string_value |
| Name des virtuellen Systems (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Gerätename (device_name) | dvchost | DeviceName | intermediary.hostname | |
| UUID der Quell-VM (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id | |
| UUID der Ziel-VM (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id | |
| HTTP-Methode (http_method) | RequestMethod | network.http.method | ||
| Tunnel-ID/IMSI (tunnel_id/imsi) | PanOSTunnelID | TunnelID | tunnel_id/imsi | additional.fields.key und additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag/imei) | PanOSMonitorTag | MonitorTag | monitortag/imei | additional.fields.key und additional.fields.value.string_value |
| ID der übergeordneten Sitzung (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Beginn der übergeordneten Sitzung (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key und additional.fields.value.string_value |
| Tunneltyp (tunnel) | PanOSTunnelType | TunnelType | Tunnel | additional.fields.key und additional.fields.value.string_value |
| Bedrohungskategorie (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| Inhaltsversion (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key und additional.fields.value.string_value |
| SCTP-Verbindungs-ID (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key und additional.fields.value.string_value | |
| Payload Protocol ID (ppid) | PanOSPPID | ppid | additional.fields.key und additional.fields.value.string_value | |
| HTTP-Header (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Liste der URL-Kategorien (url_category_list) | PanOSURLCatList | url_category_list | additional.fields.key und additional.fields.value.string_value | |
| Regel-UUID (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| HTTP/2-Verbindung (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| Name der dynamischen Nutzergruppe (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
|
| XFF-Adresse (xff_ip) | PanXFFIP | principal.ip | ||
| Gerätekategorie der Quelle (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Quellgeräteprofil (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
|
| Quellgerätemodell (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Quellgeräteanbieter (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Betriebssystemfamilie des Quellgeräts (src_osfamily) | PanSrcDeviceOS | src_osfamily | principal.platform | |
| Betriebssystemversion des Quellgeräts (src_osversion) | PanSrcDeviceOSv | principal.platform_version | ||
| Quellhostname (src_host) | PanSrcHostname | principal.hostname | ||
| Quell-MAC-Adresse (src_mac) | PanSrcMac | principal.mac | ||
| Zielgerätekategorie (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Zielgeräteprofil (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
|
| Zielgerätemodell (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Anbieter des Zielgeräts (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Betriebssystemfamilie des Zielgeräts (dst_osfamily) | PanDstDeviceOS | dst_osfamily | target.platform | |
| Betriebssystemversion des Zielgeräts (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Ziel-Hostname (dst_host) | PanDstHostname | target.hostname | ||
| MAC-Zieladresse (dst_mac) | PanDstMac | target.mac | ||
| Container-ID (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| POD Namespace (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| POD-Name (pod_name) | PanPODName | pod_name | target.resource.name | |
| Externe dynamische Quellliste (src_edl) | PanSrcEDL | src_edl | additional.fields.key und additional.fields.value.string_value | |
| Dynamische Liste für externes Ziel (dst_edl) | PanDstEDL | dst_edl | additional.fields.key und additional.fields.value.string_value | |
| Host-ID (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Seriennummer des Nutzergeräts (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| Domain-EDL (domain_edl) | PanDomainEDL | domain_edl | additional.fields.key und additional.fields.value.string_value | |
| Dynamische Quelladressengruppe (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Dynamische Zieladressengruppe (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| Teil-Hash (partial_hash) | PanPartialHash | partial_hash | additional.fields.key und additional.fields.value.string_value | |
| Zeitstempel mit hoher Auflösung (high_res timestamp) | PanTimeHighRes | Zeitstempel mit hoher Auflösung | additional.fields.key und additional.fields.value.string_value | |
| Grund (reason) | PanReasonFilteringAction | reason | security_result.summary | |
| Blocksatz (justification) | PanJustification | Begründung | additional.fields.key und additional.fields.value.string_value | |
| Ein Slice-Diensttyp (nssai_sst) | PanASServiceType | nssai_sst | additional.fields.key und additional.fields.value.string_value | |
| Unterkategorie der Anwendung (subcategory_of_app) | subcategory_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Anwendungskategorie (category_of_app) | category_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Anwendungstechnologie (technology_of_app) | technology_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Anwendungsrisiko (risk_of_app) | risk_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Anwendungsmerkmal (characteristic_of_app) | characteristic_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Anwendungscontainer (container_of_app) | container_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Application SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Getunnelte Anwendung (tunneled_app) | additional.fields.key und additional.fields.value.string_value | |||
| Vorgangstyp (flow_type) | additional.fields.key und additional.fields.value.string_value | |||
| Clustername (cluster_name) | intermediary.resource.name | |||
| Status der Genehmigung der Anwendung (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key und additional.fields.value.string_value |
Traffic
In der folgenden Tabelle sind die Logfelder des Traffic-Logtyps und die entsprechenden UDM-Felder aufgeführt.
| CSV-Feld | CEF-Feld | LEEF-Feld | Schlüssel für Google Security Operations-Label | UDM-Feld |
|---|---|---|---|---|
| Empfangszeit (receive_time oder cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist) |
|
| Seriennummer (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Typ (type) | Typ (Header) | cat/Type | metadata.product_event_type | |
| Bedrohungs-/Inhaltstyp (Untertyp) | Untertyp (Kopfzeile) | Subtyp | metadata.product_event_type | |
| Generierte Zeit (time_generated oder cef-formatted-time_generated) | start | metadata.event_timestamp | ||
| Quelladresse (src) | src | src | principal.ip | |
| Zieladresse (dst) | dst | dst | target.ip | |
| NAT-Quell-IP-Adresse (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| NAT-Ziel-IP-Adresse (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Regelname (rule) | cs1 | RuleName | security_result.rule_name | |
| Quellnutzer (srcuser) | suser | SourceUser | principal.user.userid | |
| Zielnutzer (dstuser) | duser | DestinationUser | target.user.userid | |
| Anwendung (App) | App | Anwendung | target.application | |
| Virtuelles System (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Quellzone (von) | cs4 | SourceZone | von | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
| Zielzone (bis) | cs5 | DestinationZone | bis | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
| Eingangsschnittstelle (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
| Ausgangsschnittstelle (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
| Aktion protokollieren (Logset) | cs6 | LogForwardingProfile | logset | additional.fields.key und additional.fields.value.string_value |
| Sitzungs-ID (sessionid) | cn1 | SessionID | network.session_id | |
| Anzahl der Wiederholungen (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key und additional.fields.value.string_value |
| Quellport (sport) | spt | srcPort | principal.port | |
| Zielport (dport) | dpt | dstPort | target.port | |
| NAT-Quellport (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| NAT-Zielport (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Flags (flags) | flexString1 | Flags | flags | additional.fields.key und additional.fields.value.string_value |
| IP-Protokoll (proto) | Proto | Proto | network.ip_protocol | |
| Aktion (action) | Handeln | Aktion | security_result.action_details
security_result.action |
|
| Byte (bytes) | flexNumber1 | totalBytes | Byte | additional.fields.key und additional.fields.value.string_value |
| Gesendete Bytes (bytes_sent) | in | srcBytes | network.sent_bytes | |
| Empfangene Byte (bytes_received) | out | dstBytes | network.received_bytes | |
| Pakete (packets) | cn2 | totalPackets | Pakete | additional.fields.key und additional.fields.value.string_value |
| Beginn (start) | StartTime | start | additional.fields.key und additional.fields.value.string_value | |
| Verstrichene Zeit (elapsed) | cn3 | ElapsedTime | verstrichen | network.session_duration.seconds |
| Kategorie (category) | cs2 | URLCategory | security_result.category / security_result.category_details | |
| Sequenznummer (seqno) | externalId | Sequenz | metadata.product_log_id | |
| Aktions-Flags (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key und additional.fields.value.string_value |
| Quellland (srcloc) | SourceLocation | principal.location.country_or_region | ||
| Zielland (dstloc) | DestinationLocation | target.location.country_or_region | ||
| Gesendete Pakete (pkts_sent) | PanOSPacketsSent | srcPackets | pkts_sent | network.sent_packets |
| Empfangene Pakete (pkts_received) | PanOSPacketsReceived | dstPackets | pkts_received | network.received_packets |
| Grund für das Ende der Sitzung (session_end_reason) | reason | SessionEndReason | security_result.summary | |
| Gerätegruppenhierarchie1 (dg_hier_level_1 bis dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key und additional.fields.value.string_value |
| Gerätegruppenhierarchie2 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key und additional.fields.value.string_value |
| Gerätegruppenhierarchie 3 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key und additional.fields.value.string_value |
| Gerätegruppenhierarchie (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key und additional.fields.value.string_value |
| Name des virtuellen Systems (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Gerätename (device_name) | dvchost | DeviceName | intermediary.hostname | |
| Aktionsquelle (action_source) | cat | ActionSource | action_source | additional.fields.key und additional.fields.value.string_value |
| UUID der Quell-VM (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id | |
| UUID der Ziel-VM (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id | |
| Tunnel-ID/IMSI (tunnelid/imsi) | PanOSTunnelID | TunnelID | tunnelid/imsi | additional.fields.key und additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag/imei) | PanOSMonitorTag | MonitorTag | monitortag/imei | additional.fields.key und additional.fields.value.string_value |
| ID der übergeordneten Sitzung (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Startzeit des übergeordneten Ereignisses (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key und additional.fields.value.string_value |
| Tunneltyp (tunnel) | PanOSTunnelType | TunnelType | Tunnel | additional.fields.key und additional.fields.value.string_value |
| SCTP-Verbindungs-ID (assoc_id) | PanOSSCTPAssocID | assoc_id | additional.fields.key und additional.fields.value.string_value | |
| SCTP-Chunks | PanOSSCTPChunks | Chunks | additional.fields.key und additional.fields.value.string_value | |
| Gesendete SCTP-Chunks (chunks_sent) | PanOSSCTPChunkSent | chunks_sent | additional.fields.key und additional.fields.value.string_value | |
| Empfangene SCTP-Chunks (chunks_received) | PanOSSCTPChunksRcv | chunks_received | additional.fields.key und additional.fields.value.string_value | |
| Regel-UUID (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| HTTP/2-Verbindung (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| Anzahl der App-Flips (link_change_count) | PanLinkChange | link_change_count | additional.fields.key und additional.fields.value.string_value | |
| Richtlinien-ID (policy_id) | PanPolicyID | policy_id | additional.fields.key und additional.fields.value.string_value | |
| Link-Schalter (link_switches) | PanLinkDetail | link_switches | additional.fields.key und additional.fields.value.string_value | |
| SD-WAN-Cluster (sdwan_cluster) | PanSDWANCluster | sdwan_cluster | additional.fields.key und additional.fields.value.string_value | |
| SD-WAN-Gerätetyp (sdwan_device_type) | PanSDWANDevice | sdwan_device_type | additional.fields.key und additional.fields.value.string_value | |
| SD-WAN-Clustertyp (sdwan_cluster_type) | PanSDWANClustype | sdwan_cluster_type | additional.fields.key und additional.fields.value.string_value | |
| SD-WAN-Standort (sdwan_site) | PanSDWANSite | sdwan_site | additional.fields.key und additional.fields.value.string_value | |
| Name der dynamischen Nutzergruppe (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | additional.fields.key und additional.fields.value.string_value | |
| XFF-Adresse (xff_ip) | PanXFFIP | principal.ip | ||
| Gerätekategorie der Quelle (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Quellgeräteprofil (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
|
| Quellgerätemodell (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Quellgeräteanbieter (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Betriebssystemfamilie des Quellgeräts (src_osfamily) | PanSrcDeviceOS | principal.platform | ||
| Betriebssystemversion des Quellgeräts (src_osversion) | PanSrcDeviceOSv | principal.asset.software.version | ||
| Quellhostname (src_host) | PanSrcHostname | principal.hostname | ||
| Quell-MAC-Adresse (src_mac) | PanSrcMac | principal.mac | ||
| Zielgerätekategorie (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Zielgeräteprofil (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
|
| Zielgerätemodell (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Anbieter des Zielgeräts (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Betriebssystemfamilie des Zielgeräts (dst_osfamily) | PanDstDeviceOS | dst_osfamily | target.platform | |
| Betriebssystemversion des Zielgeräts (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Ziel-Hostname (dst_host) | PanDstHostname | target.hostname | ||
| MAC-Zieladresse (dst_mac) | PanDstMac | target.mac | ||
| Container-ID (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| POD Namespace (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| POD-Name (pod_name) | PanPODName | pod_name | target.resource.name | |
| Externe dynamische Quellliste (src_edl) | PanSrcEDL | src_edl | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
|
| Dynamische Liste für externes Ziel (dst_edl) | PanDstEDL | dst_edl | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
|
| Host-ID (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Seriennummer des Nutzergeräts (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| Dynamische Quelladressengruppe (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Dynamische Zieladressengruppe (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| Sitzungsinhaber (session_owner) | PanHASessionOwner | session_owner | additional.fields.key und additional.fields.value.string_value | |
| Zeitstempel mit hoher Auflösung (high_res_timestamp) | PanTimeHighRes | additional.fields.key und additional.fields.value.string_value | ||
| Ein Slice-Diensttyp (nsdsai_sst) | PanASServiceType | nsdsai_sst | additional.fields.key und additional.fields.value.string_value | |
| Slice-Differenzierung (nsdsai_sd) | PanASServiceDiff | nsdsai_sd | additional.fields.key und additional.fields.value.string_value | |
| Unterkategorie der Anwendung (subcategory_of_app) | subcategory_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Anwendungskategorie (category_of_app) | category_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Anwendungstechnologie (technology_of_app) | technology_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Anwendungsrisiko (risk_of_app) | security_result.severity | |||
| Anwendungsmerkmal (characteristic_of_app) | characteristic_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Anwendungscontainer (container_of_app) | container_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Application SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Status der Genehmigung der Anwendung (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Unterkategorie der Anwendung (subcategory_of_app) | subcategory_of_app1 | additional.fields.key und additional.fields.value.string_value | ||
| Schweregrad (severity) | number-of-severity(header) | security_result.severity und security_result.severity_details |
User-ID
In der folgenden Tabelle sind die Logfelder des Logtyps „Nutzer-ID“ und die entsprechenden UDM-Felder aufgeführt.
| CSV-Feld | CEF-Feld | LEEF-Feld | Schlüssel für Google Security Operations-Label | UDM-Feld |
|---|---|---|---|---|
| Empfangszeit (receive_time oder cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist) |
|
| Seriennummer (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Typ (type) | Typ (Header) | cat | metadata.product_event_type | |
| Bedrohungs-/Inhaltstyp (Untertyp) | Untertyp (Kopfzeile) | Subtyp | metadata.product_event_type | |
| Generierte Zeit (time_generated oder cef-formatted-time_generated) | metadata.event_timestamp | |||
| Virtuelles System (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Quell-IP-Adresse (ip) | src | src | principal.ip | |
| Nutzer (user) | duser | usrName | target.user.userid
target.administrative_domain target.user.email_addresses |
|
| Name der Datenquelle (datasourcename) | cs4 | DataSourceName | datasourcename | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
| Ereignis-ID (eventid) | EventID | eventid | additional.fields.key und additional.fields.value.string_value | |
| Anzahl der Wiederholungen (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key und additional.fields.value.string_value |
| Grenzwert für Zeitüberschreitung (timeout) | cn3 | TimeoutThreshold | Zeitüberschreitung | additional.fields.key und additional.fields.value.string_value |
| Quellport (beginport) | spt | srcPort | principal.port | |
| Zielport (Endport) | dpt | dstPort | target.port | |
| Datenquelle (datasource) | cs5 | DataSource | Datenquelle | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
| Typ der Datenquelle (datasourcetype) | cs6 | DataSourceType | datasourcetype | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
| Sequenznummer (seqno) | externalId | Sequenz | metadata.product_log_id | |
| Aktions-Flags (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key und additional.fields.value.string_value |
| Hierarchie der Gerätegruppen (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key und additional.fields.value.string_value |
| Hierarchie der Gerätegruppen (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key und additional.fields.value.string_value |
| Gerätegruppenhierarchie (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key und additional.fields.value.string_value |
| Gerätegruppenhierarchie (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key und additional.fields.value.string_value |
| Name des virtuellen Systems (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Gerätename (device_name) | dvchost | DeviceName | intermediary.hostname | |
| ID des virtuellen Systems (vsys_id) | cn2 | VirtualSystemID | intermediary.resource.product_object_id | |
| Faktortyp (factortype) | cs1 | FactorType | factortype | additional.fields.key und additional.fields.value.string_value |
| Faktor „Abschlusszeit“ (factorcompletiontime) | Ende | FactorCompletionTime | factorcompletiontime | additional.fields.key und additional.fields.value.string_value |
| Faktornummer (factorno) | cn1 | FactorNumber | factorno | additional.fields.key und additional.fields.value.string_value |
| Nutzergruppen-Flags (ugflags) | PanOSUGFlags | ugflags | additional.fields.key und additional.fields.value.string_value | |
| Nutzer nach Quelle (userbysource) | PanOSUserBySource | target.user.userid
target.administrative_domain target.user.email_addresses |
||
| Zeitstempel mit hoher Auflösung (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key und additional.fields.value.string_value | ||
| Ursprüngliche Datenquelle (origindatasource) | additional.fields.key und additional.fields.value.string_value | |||
| Clustername (cluster_name) | principal.resource.name | |||
| Schweregrad (severity) | number-of-severity(header) | security_result.severity und security_result.severity_details |
Übereinstimmung mit dem HIP
In der folgenden Tabelle sind die Logfelder des Logtyps „HIP-Abgleich“ und die entsprechenden UDM-Felder aufgeführt.
| CSV-Feld | CEF-Feld | LEEF-Feld | Schlüssel für Google Security Operations-Label | UDM-Feld |
|---|---|---|---|---|
| Empfangszeit (receive_time oder cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist) |
|
| Seriennummer (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Typ (type) | Typ (Header) | cat | metadata.product_event_type | |
| Bedrohungs-/Inhaltstyp (Untertyp) | Untertyp (Kopfzeile) | Subtyp | ||
| Generierte Zeit (time_generated oder cef-formatted-time_generated) | start | startTime | metadata.event_timestamp | |
| Quellnutzer (srcuser) | suser | usrName | principal.user.userid | |
| Virtuelles System (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| Computername (machinename) | shost | identHostName | principal.hostname | |
| Betriebssystem | cs2 | Betriebssystem | principal.asset.platform_software.platform | |
| Quelladresse (src) | src | identsrc | principal.ip | |
| HIP (matchname) | cat | HIP | matchname | target.resource.attribute.labels.key/value additional.fields.key und additional.fields.value.string_value |
| Anzahl der Wiederholungen (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key und additional.fields.value.string_value |
| HIP-Typ (matchtype) | Geräteereignisklassen-ID (Header) | HIPType | matchtype | target.resource.attribute.labels.key/value additional.fields.key und additional.fields.value.string_value |
| Sequenznummer (seqno) | externalId | Sequenz | metadata.product_log_id | |
| Aktions-Flags (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key und additional.fields.value.string_value |
| Hierarchie der Gerätegruppen (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key und additional.fields.value.string_value |
| Hierarchie der Gerätegruppen (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key und additional.fields.value.string_value |
| Gerätegruppenhierarchie (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key und additional.fields.value.string_value |
| Gerätegruppenhierarchie (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key und additional.fields.value.string_value |
| Name des virtuellen Systems (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Gerätename (device_name) | dvchost | DeviceName | target.hostname | |
| ID des virtuellen Systems (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id | |
| IPv6-Systemadresse (srcipv6) | c6a2 | srcipv6 | principal.asset.ip | |
| Host-ID (hostid) | PanOSHostID | principal.asset.asset_id | ||
| Seriennummer des Nutzergeräts (serialnumber) | PanOSEndpointSerialNumber | principal.asset.hardware.serial_number | ||
| MAC-Adresse des Geräts (mac) | PanOSEndpointMac | principal.asset.mac | ||
| Zeitstempel mit hoher Auflösung (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key und additional.fields.value.string_value | ||
| Clustername (cluster_name) | principal.resource.name | |||
| Schweregrad (severity) | number-of-severity(header) | security_result.severity und security_result.severity_details |
IP-Tag
In der folgenden Tabelle sind die Logfelder des Logtyps „IP-Tag“ und die entsprechenden UDM-Felder aufgeführt.
| CSV-Feld | CEF-Feld | LEEF-Feld | Schlüssel für Google Security Operations-Label | UDM-Feld |
|---|---|---|---|---|
| Empfangszeit (receive_time oder cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist) |
|
| Seriennummer (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Typ (type) | Typ (Header) | cat | metadata.product_event_type | |
| Bedrohungs-/Inhaltstyp (Untertyp) | Untertyp (Kopfzeile) | Subtyp | metadata.product_event_type | |
| Generierte Zeit (time_generated oder cef-formatted-time_generated) | GenerateTime | metadata.event_timestamp | ||
| Virtuelles System (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| Quell-IP-Adresse (ip) | src | src | principal.ip | |
| Tag-Name (tag_name) | PanOSTagName | TagName | tag_name | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
| Ereignis-ID (event_id) | PanOSEventID | EventID | event_id | additional.fields.key und additional.fields.value.string_value |
| Anzahl der Wiederholungen (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key und additional.fields.value.string_value |
| Zeitüberschreitung (timeout) | PanOSTimeout | TimeoutThreshold | Zeitüberschreitung | additional.fields.key und additional.fields.value.string_value |
| Name der Datenquelle (datasourcename) | PanOSDataSourceName | DataSourceName | datasourcename | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
| Typ der Datenquelle (datasource_type) | PanOSDataSourceType | DataSource | datasource_type | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
| Untertyp der Datenquelle (datasource_subtype) | PanOSDataSourceSubType | DataSourceType | datasource_subtype | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
| Sequenznummer (seqno) | externalId | Sequenz | metadata.product_log_id | |
| Aktions-Flags (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key und additional.fields.value.string_value |
| Hierarchie der Gerätegruppen (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key und additional.fields.value.string_value |
| Hierarchie der Gerätegruppen (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key und additional.fields.value.string_value |
| Gerätegruppenhierarchie (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key und additional.fields.value.string_value |
| Gerätegruppenhierarchie (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key und additional.fields.value.string_value |
| Name des virtuellen Systems (vsys_name) | PanOsVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Gerätename (device_name) | dvchost | DeviceName | target.hostname | |
| ID des virtuellen Systems (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id | |
| Zeitstempel mit hoher Auflösung (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key und additional.fields.value.string_value | ||
| Schweregrad (severity) | number-of-severity(header) | security_result.severity und security_result.severity_details | ||
| Clustername (cluster_name) | principal.resource.name |
Entschlüsselung
In der folgenden Tabelle sind die Logfelder des Entschlüsselungslogtyps und die entsprechenden UDM-Felder aufgeführt.
| CSV-Feld | CEF-Feld | LEEF-Feld | Schlüssel für Google Security Operations-Label | UDM-Feld |
|---|---|---|---|---|
| Empfangszeit (receive_time oder cef-formatted-receive_time) | rt | metadata.collected_timestamp,
metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist) |
||
| Seriennummer (serial) | PanOSDeviceSN | intermediary.asset.hardware.serial_number | ||
| Typ (type) | Typ (Header) | metadata.product_event_type | ||
| Bedrohungs-/Inhaltstyp (Untertyp) | Untertyp (Kopfzeile) | metadata.product_event_type | ||
| Konfigurationsversion (config_ver) | PanOSConfigVersion | config_ver | additional.fields.key und additional.fields.value.string_value | |
| Erstellungszeit (time_generated) | PanOSLogTimeStamp | metadata.event_timestamp | ||
| Quelladresse (src) | src | principal.ip | ||
| Zieladresse (dst) | dst | target.ip | ||
| NAT-Quell-IP-Adresse (natsrc) | sourceTranslatedAddress | principa.nat_ip | ||
| NAT-Ziel-IP-Adresse (natdst) | destinationTranslatedAddress | target.nat_ip | ||
| Regel (rule) | cs1 | security_result.rule_name | ||
| Quellnutzer (srcuser) | suser | principal.user.userid | ||
| Zielnutzer (dstuser) | duser | target.user.userid | ||
| Anwendung (App) | App | network.application_protocol | ||
| Virtuelles System (vsys) | cs3 | vsys | intermediary.asset.attribute.labels.key/value | |
| Quellzone (von) | cs4 | von | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
|
| Zielzone (bis) | cs5 | bis | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
|
| Eingangsschnittstelle (inbound_if) | deviceInboundInterface | inbound_if | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
|
| Ausgangsschnittstelle (outbound_if) | deviceOutboundInterface | outbound_if | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
|
| Aktion protokollieren (Logset) | cs6 | logset | additional.fields.key und additional.fields.value.string_value | |
| Protokollierte Zeit (time_received) | PanOSTimeReceivedManagementPlane | - | ||
| Sitzungs-ID (sessionid) | cn1 | network.session_id | ||
| Anzahl der Wiederholungen (repeatcnt) | PanOSCountOfRepeats/RepeatCount | repeatcnt | additional.fields.key und additional.fields.value.string_value | |
| Quellport (sport) | spt | principal.port | ||
| Zielport (dport) | dpt | target.port | ||
| NAT-Quellport (natsport) | sourceTranslatedPort | principal.nat_port | ||
| NAT-Zielport (natdport) | destinationTranslatedPort | target.nat_port | ||
| Flags (flags) | flexString1 | flags | additional.fields.key und additional.fields.value.string_value | |
| IP-Protokoll (proto) | Proto | network.ip_protocol | ||
| Aktion (action) | Handeln | security_result.action_details
security_result.action |
||
| Tunnel (tunnel) | PanOSTunnel | Tunnel | additional.fields.key und additional.fields.value.string_value | |
| UUID der Quell-VM (src_uuid) | PanOSSourceUUID | principal.asset.product_object_id | ||
| UUID der Ziel-VM (dst_uuid) | PanOSDestinationUUID | target.asset.product_object_id | ||
| UUID für Regel (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| Phase für Client zu Firewall (hs_stage_c2f) | PanOSClientToFirewall | hs_stage_c2f | additional.fields.key und additional.fields.value.string_value | |
| Phase für Firewall-zu-Server (hs_stage_f2s) | PanOSFirewallToServer | hs_stage_f2s | additional.fields.key und additional.fields.value.string_value | |
| TLS-Version (tls_version) | PanOSTLSVersion | network.tls.version | ||
| Algorithmus für Schlüsselaustausch (tls_keyxchg) | PanOSTLSKeyExchange | tls_keyxchg | additional.fields.key und additional.fields.value.string_value | |
| Verschlüsselungsalgorithmus (tls_enc) | PanOSTLSEncryptionAlgorithm | tls_enc | additional.fields.key und additional.fields.value.string_value | |
| Hash-Algorithmus (tls_auth) | PanOSTLSAuth | tls_auth | additional.fields.key und additional.fields.value.string_value | |
| Richtlinienname (policy_name) | PanOSPolicyName | policy_name | additional.fields.key und additional.fields.value.string_value | |
| Elliptische Kurve (ec_curve) | PanOSEllipticCurve | network.tls.curve | ||
| Fehlerindex (err_index) | PanOSErrorIndex | err_index | additional.fields.key und additional.fields.value.string_value | |
| Root-Status (root_status) | PanOSRootStatus | root_status | additional.fields.key und additional.fields.value.string_value | |
| Kettenstatus (chain_status) | PanOSChainStatus | chain_status | additional.fields.key und additional.fields.value.string_value | |
| Proxy-Typ (proxy_type) | PanOSProxyType | proxy_type | additional.fields.key und additional.fields.value.string_value | |
| Seriennummer des Zertifikats (cert_serial) | PanOSCertificateSerial | network.tls.server.certificate.serial | ||
| Zertifikat-Fingerabdruck (Fingerabdruck) | PanOSFingerprint | network.tls.server.certificate.md5/sha1/sha256 | ||
| Startdatum des Zertifikats (notbefore) | PanOSTimeNotBefore | network.tls.server.certificate.not_before | ||
| Enddatum des Zertifikats (notafter) | PanOSTimeNotAfter | network.tls.server.certificate.not_after | ||
| Zertifikatsversion (cert_ver) | PanOSCertificateVersion | network.tls.server.certificate.version | ||
| Zertifikatgröße (cert_size) | PanOSCertificateSize | cert_size | additional.fields.key und additional.fields.value.string_value | |
| Länge des allgemeinen Namens (cn_len) | PanOSCommonNameLength | cn_len | additional.fields.key und additional.fields.value.string_value | |
| Länge des allgemeinen Namens des Ausstellers (issuer_len) | PanOSIssuerNameLength | issuer_len | additional.fields.key und additional.fields.value.string_value | |
| Länge des gemeinsamen Namens des Root-Zertifikats (rootcn_len) | PanOSRootCNLength | rootcn_len | additional.fields.key und additional.fields.value.string_value | |
| SNI-Länge (sni_len) | PanOSSNILength | sni_len | additional.fields.key und additional.fields.value.string_value | |
| Zertifikats-Flags (cert_flags) | PanOSCertificateFlags | cert_flags | additional.fields.key und additional.fields.value.string_value | |
| Allgemeiner Name des Inhabers (cn) | PanOSCommonName | cn | additional.fields.key und additional.fields.value.string_value | |
| Allgemeiner Name des Ausstellers (issuer_cn) | PanOSIssuerCommonName | network.tls.server.certificate.issuer | ||
| Allgemeiner Name des Root-Zertifikats (root_cn) | PanOSRootCommonName | root_cn | additional.fields.key und additional.fields.value.string_value | |
| Server Name Indication
(sni) |
network.tls.client.server_name | |||
| Fehler (error) | PanOSErrorMessage | Fehler | additional.fields.key und additional.fields.value.string_value | |
| Container-ID (container_id) | PanOSContainerID | container_id | intermediary.resource.product_object_id | |
| POD Namespace (pod_namespace) | PanOSContainerNameSpace | pod_namespace | target.resource.attribute.labels.key/value additional.fields.key und additional.fields.value.string_value |
|
| POD-Name (pod_name) | PanOSContainerName | pod_name | target.resource.name | |
| Externe dynamische Quellliste (src_edl) | PanOSSourceEDL | src_edl | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
|
| Dynamische Liste für externes Ziel (dst_edl) | PanOSDestinationEDL | dst_edl | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
|
| Dynamische Quelladressengruppe (src_dag) | PanOSSourceDynamicAddressGroup | principal.group.group_display_name | ||
| Dynamische Zieladressengruppe (dst_dag) | PanOSDestinationDynamicAddressGroup | target.group.group_display_name | ||
| Zeitstempel mit hoher Auflösung (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key und additional.fields.value.string_value | ||
| Gerätekategorie der Quelle (src_category) | PanOSSourceDeviceCategory | src_category | principal.asset.category | |
| Quellgeräteprofil (src_profile) | PanOSSourceDeviceProfile | src_profile | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
|
| Quellgerätemodell (src_model) | PanOSSourceDeviceModel | src_model | principal.asset.hardware.model | |
| Quellgeräteanbieter (src_vendor) | PanOSSourceDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Betriebssystemfamilie des Quellgeräts (src_osfamily) | PanOSSourceDeviceOSFamily | principal.platform | ||
| Betriebssystemversion des Quellgeräts (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | ||
| Quellhostname (src_host) | PanOSSourceDeviceHost | principal.hostname | ||
| Quell-MAC-Adresse (src_mac) | PanOSSourceDeviceMac | principal.mac | ||
| Zielgerätekategorie (dst_category) | PanOSDestinationDeviceCategory | dst_category | target.asset.category | |
| Zielgeräteprofil (dst_profile) | PanOSDestinationDeviceProfile | dst_profile | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
|
| Zielgerätemodell (dst_model) | PanOSDestinationDeviceModel | dst_model | target.asset.hardware.model | |
| Anbieter des Zielgeräts (dst_vendor) | PanOSDestinationDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Betriebssystemfamilie des Zielgeräts (dst_osfamily) | PanOSDestinationDeviceOSFamily | dst_osfamily | target.platform | |
| Betriebssystemversion des Zielgeräts (dst_osversion) | PanOSDestinationDeviceOSVersion | target.platform_version | ||
| Ziel-Hostname (dst_host) | PanOSDestinationDeviceHost | target.hostname | ||
| MAC-Zieladresse (dst_mac) | PanOSDestinationDeviceMac | target.mac | ||
| Sequenznummer (seqno) | PanOSLogTypeSeqNo | metadata.product_log_id | ||
| Aktions-Flags (actionflags) | PanOSActionFlags | actionflags | additional.fields.key und additional.fields.value.string_value | |
| Hierarchie der Gerätegruppen (dg_hier_level_1) | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key und additional.fields.value.string_value | |
| Hierarchie der Gerätegruppen (dg_hier_level_2) | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key und additional.fields.value.string_value | |
| Gerätegruppenhierarchie (dg_hier_level_3) | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key und additional.fields.value.string_value | |
| Gerätegruppenhierarchie (dg_hier_level_4) | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key und additional.fields.value.string_value | |
| Name des virtuellen Systems (vsys_name) | intermediary.asset.attribute.labels.key/value | |||
| Gerätename (device_name) | intermediary.hostname | |||
| ID des virtuellen Systems (vsys_id) | intermediary.resource.product_object_id | |||
| Unterkategorie der Anwendung (subcategory_of_app) | subcategory_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Anwendungskategorie (category_of_app) | category_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Anwendungstechnologie (technology_of_app) | technology_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Anwendungsrisiko (risk_of_app) | security_result.severity | |||
| Anwendungsmerkmal (characteristic_of_app) | characteristic_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Anwendungscontainer (container_of_app) | container_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Application SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Status der Genehmigung der Anwendung (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Schweregrad (severity) | number-of-severity(header) | security_result.severity und security_result.severity_details |
Tunnel
In der folgenden Tabelle sind die Logfelder des Tunnel-Logtyps und die entsprechenden UDM-Felder aufgeführt.
| CSV-Feld | CEF-Feld | LEEF-Feld | Schlüssel für Google Security Operations-Label | UDM-Feld |
|---|---|---|---|---|
| Empfangszeit (receive_time oder cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist) |
|
| Seriennummer (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Typ (type) | Typ (Header) | cat | metadata.product_event_type | |
| Bedrohungs-/Inhaltstyp (Untertyp) | Untertyp (Kopfzeile) | Subtyp | metadata.product_event_type | |
| Generierte Zeit (time_generated oder cef-formatted-time_generated) | metadata.event_timestamp | |||
| Quelladresse (src) | src | src | principal.ip | |
| Zieladresse (dst) | dst | dst | target.ip | |
| NAT-Quell-IP-Adresse (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| NAT-Ziel-IP-Adresse (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Regelname (rule) | cs1 | RuleName | security_result.rule_name | |
| Quellnutzer (srcuser) | suser | SourceUser / usrName | principal.user.userid | |
| Zielnutzer (dstuser) | duser | DestinationUser | target.user.userid | |
| Anwendung (App) | App | Anwendung | network.application_protocol | |
| Virtuelles System (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Quellzone (von) | cs4 | SourceZone | von | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
| Zielzone (bis) | cs5 | DestinationZone | bis | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
| Eingangsschnittstelle (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
| Ausgangsschnittstelle (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
| Aktion protokollieren (Logset) | cs6 | LogForwardingProfile | logset | additional.fields.key und additional.fields.value.string_value |
| Sitzungs-ID (sessionid) | cn1 | SessionID | network.session_id | |
| Anzahl der Wiederholungen (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key und additional.fields.value.string_value |
| Quellport (sport) | spt | srcPort | principal.port | |
| Zielport (dport) | dpt | dstPort | target.port | |
| NAT-Quellport (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| NAT-Zielport (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Flags (flags) | flexString1 | Flags | flags | additional.fields.key und additional.fields.value.string_value |
| IP-Protokoll (proto) | Proto | Proto | network.ip_protocol | |
| Aktion (action) | Handeln | Aktion | security_result.action_details
security_result.action |
|
| Schweregrad (severity) | number-of-severity(header) | security_result.severity und security_result.severity_details | ||
| Sequenznummer (seqno) | externalId | Sequenz | metadata.product_log_id | |
| Aktions-Flags (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key und additional.fields.value.string_value |
| Quellort (srcloc) | principal.location.country_or_region | |||
| Zielort (dstloc) | target.location.country_or_region | |||
| Hierarchie der Gerätegruppen (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key und additional.fields.value.string_value |
| Hierarchie der Gerätegruppen (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key und additional.fields.value.string_value |
| Gerätegruppenhierarchie (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key und additional.fields.value.string_value |
| Gerätegruppenhierarchie (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key und additional.fields.value.string_value |
| Name des virtuellen Systems (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Gerätename (device_name) | dvchost | DeviceName | intermediary.hostname | |
| Tunnel-ID (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key und additional.fields.value.string_value |
| Monitor-Tag (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key und additional.fields.value.string_value |
| ID der übergeordneten Sitzung (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Startzeit des übergeordneten Ereignisses (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key und additional.fields.value.string_value |
| Tunneltyp (tunnel) | cs2 | TunnelType | Tunnel | additional.fields.key und additional.fields.value.string_value |
| Byte (bytes) | flexNumber1 | totalBytes | Byte | additional.fields.key und additional.fields.value.string_value |
| Gesendete Bytes (bytes_sent) | in | srcBytes | network.sent_bytes | |
| Empfangene Byte (bytes_received) | out | dstBytes | network.received_bytes | |
| Pakete (packets) | cn2 | totalPackets | Pakete | additional.fields.key und additional.fields.value.string_value |
| Gesendete Pakete (pkts_sent) | PanOSPacketsSent | srcPackets | pkts_sent | network.sent_packets |
| Empfangene Pakete (pkts_received) | PanOSPacketsReceived | dstPackets | pkts_received | network.received_packets |
| Maximale Kapselung (max_encap) | flexNumber2 | MaximumEncapsulation | max_encap | additional.fields.key und additional.fields.value.string_value |
| Unbekanntes Protokoll (unknown_proto) | cfp1 | UnknownProtocol | unknown_proto | additional.fields.key und additional.fields.value.string_value |
| Strikte Überprüfung (strict_check) | cfp2 | StrictChecking | strict_check | additional.fields.key und additional.fields.value.string_value |
| Tunnel-Fragment (tunnel_fragment) | PanOSTunnelFragment | TunnelFragment | tunnel_fragment | additional.fields.key und additional.fields.value.string_value |
| Erstellte Sitzungen (sessions_created) | cfp3 | SessionsCreated | sessions_created | additional.fields.key und additional.fields.value.string_value |
| Geschlossene Sitzungen (sessions_closed) | cfp4 | SessionsClosed | sessions_closed | additional.fields.key und additional.fields.value.string_value |
| Grund für das Ende der Sitzung (session_end_reason) | reason | SessionEndReason | security_result.summary | |
| Aktionsquelle (action_source) | cat | ActionSource | action_source | additional.fields.key und additional.fields.value.string_value |
| Beginn (start) | startTime | start | additional.fields.key und additional.fields.value.string_value | |
| Verstrichene Zeit (elapsed) | cn3 | ElapsedTime | verstrichen | network.session_duration.seconds |
| Tunnel Inspection Rule (tunnel_insp_rule) | PanOSTunneInspectionRule | security_result.rule_name = "Tunnel Inspection Rule: %{PanOSTunnelInspectionRule}" | ||
| Remote-Nutzer-IP (remote_user_ip) | PanOSRmtUserIP | principal.ip | ||
| Remote-Nutzer-ID (remote_user_id) | PanOSRmtUserID | remote_user_id | principal.user.userid | |
| UUID der Sicherheitsregel (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| PCAP-ID (pcap_id) | PanOSPcapID | pcap_id | additional.fields.key und additional.fields.value.string_value | |
| Name der dynamischen Nutzergruppe (dynusergroup_name) | PanDynamicUsrgrp | principal.group.group_display_name | ||
| Externe dynamische Quellliste (src_edl) | PanOSSourceEDL | src_edl | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
|
| Dynamische Liste für externes Ziel (dst_edl) | PanOSDestinationEDL | dst_edl | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
|
| Zeitstempel mit hoher Auflösung (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key und additional.fields.value.string_value | ||
| Slice-Differenzierung (nssai_sd) | nssai_sd | additional.fields.key und additional.fields.value.string_value | ||
| Ein Slice-Diensttyp (nssai_sd) | nssai_sd1 | additional.fields.key und additional.fields.value.string_value | ||
| PDU-Sitzungs-ID (pdu_session_id) | pdu_session_id | additional.fields.key und additional.fields.value.string_value | ||
| Unterkategorie der Anwendung (subcategory_of_app) | subcategory_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Anwendungskategorie (category_of_app) | category_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Anwendungstechnologie (technology_of_app) | technology_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Anwendungsrisiko (risk_of_app) | risk_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Anwendungsmerkmal (characteristic_of_app) | characteristic_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Anwendungscontainer (container_of_app) | container_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Application SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Getunnelte Anwendung (tunneled_app) | additional.fields.key und additional.fields.value.string_value | |||
| Ausgelagert (offloaded) | additional.fields.key und additional.fields.value.string_value | |||
| Vorgangstyp (flow_type) | additional.fields.key und additional.fields.value.string_value | |||
| Clustername (cluster_name) |
principal.resource.name |
|||
| Status der Genehmigung der Anwendung (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key und additional.fields.value.string_value |
Authentifizierung
In der folgenden Tabelle sind die Logfelder des Authentifizierungslogtyps und die entsprechenden UDM-Felder aufgeführt.
| CSV-Feld | CEF-Feld | LEEF-Feld | Schlüssel für Google Security Operations-Label | UDM-Feld |
|---|---|---|---|---|
| Empfangszeit (receive_time oder cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist) |
|
| Seriennummer (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Typ (type) | Typ (Header) | cat | metadata.product_event_type | |
| Bedrohungs-/Inhaltstyp (Untertyp) | Untertyp (Kopfzeile) | Subtyp | metadata.product_event_type | |
| Generierte Zeit (time_generated oder cef-formatted-time_generated) | metadata.event_timestamp | |||
| Virtuelles System (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Quell-IP-Adresse (ip) | src | src | principal.ip | |
| Nutzer (user) | duser | usrName | target.user.userid | |
| Nutzer normalisieren (normalize_user) | cs2 | NormalizeUser | target.user.user_display_name | |
| Objekt (Objekt) | fname | ObjectName | Objekt | target.resource.name |
| Authentifizierungsrichtlinie (authpolicy) | cs4 | AuthPolicy | authpolicy | additional.fields.key und additional.fields.value.string_value |
| Anzahl der Wiederholungen (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key und additional.fields.value.string_value |
| Authentifizierungs-ID (authid) | cn2 | AuthenticationID | authid | additional.fields.key und additional.fields.value.string_value |
| Anbieter (vendor) | flexString2 | Anbieter | vendor | additional.fields.key und additional.fields.value.string_value |
| Aktion protokollieren (Logset) | cs6 | LogForwardingProfile | logset | additional.fields.key und additional.fields.value.string_value |
| Serverprofil (serverprofile) | cs1 | ServerProfile | serverprofile | additional.fields.key und additional.fields.value.string_value |
| Beschreibung (absteigend) | PanOSDesc | AdditionalAuthInfo | security_result.description | |
| Clienttyp (clienttype) | cs5 | ClientType | clienttype | additional.fields.key und additional.fields.value.string_value |
| Ereignistyp (event) | msg | msg | extensions.auth.auth_details | |
| Faktornummer (factorno) | cn1 | FactorNumber | factorno | additional.fields.key und additional.fields.value.string_value |
| Sequenznummer (seqno) | externalId | Sequenz | metadata.product_log_id | |
| Aktions-Flags (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key und additional.fields.value.string_value |
| Hierarchie der Gerätegruppen (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key und additional.fields.value.string_value |
| Hierarchie der Gerätegruppen (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key und additional.fields.value.string_value |
| Gerätegruppenhierarchie (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key und additional.fields.value.string_value |
| Gerätegruppenhierarchie (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key und additional.fields.value.string_value |
| Name des virtuellen Systems (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Gerätename (device_name) | dvchost | DeviceName | intermediary.hostname | |
| ID des virtuellen Systems (vsys_id) | intermediary.resource.product_object_id | |||
| Authentifizierungsprotokoll (authproto) | authproto | additional.fields.key und additional.fields.value.string_value | ||
| UUID für Regel (rule_uuid) | PanOSRuleUUID/RuleUUID | security_result.rule_id | ||
| Zeitstempel mit hoher Auflösung (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key und additional.fields.value.string_value | ||
| Gerätekategorie der Quelle (src_category) | PanOSSourceDeviceCategory | src_category | principal.asset.category | |
| Quellgeräteprofil (src_profile) | PanOSSourceDeviceProfile | src_profile | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
|
| Quellgerätemodell (src_model) | PanOSSourceDeviceModel | src_model | principal.asset.hardware.model | |
| Quellgeräteanbieter (src_vendor) | PanOSSourceDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Betriebssystemfamilie des Quellgeräts (src_osfamily) | PanOSSourceDeviceOSFamily | principal.asset.platform_software.platform principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
||
| Betriebssystemversion des Quellgeräts (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | ||
| Quellhostname (src_host) | PanOSSourceHostname | principal.hostname | ||
| Quell-MAC-Adresse (src_mac) | PanOSSourceMac | principal.asset.mac | ||
| Region | PanOSTrafficOriginRegion | principal.location.country_or_region | ||
| User-Agent (user_agent) | PanOSHTTPUserAgent | network.http.user_agent | ||
| Sitzungs-ID(sessionid) | PanOSTrafficSessionID | network.session_id | ||
| Schweregrad (severity) | number-of-severity(header) | security_result.severity und security_result.severity_details | ||
| Clustername (cluster_name) | principal.resource.name |
URL
In der folgenden Tabelle sind die Logfelder des URL-Logtyps und die entsprechenden UDM-Felder aufgeführt.
| CSV-Feld | CEF-Feld | LEEF-Feld | Schlüssel für Google Security Operations-Label | UDM-Feld |
|---|---|---|---|---|
| Empfangszeit (cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist) |
|
| Seriennummer (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Typ (type) | Typ (Header) | cat | metadata.product_event_type | |
| Bedrohungs-/Inhaltstyp (Untertyp) | Untertyp (Kopfzeile) | Subtyp | metadata.product_event_type | |
| Generierungszeit | metadata.event_timestamp | |||
| Quelladresse (src) | src | src | principal.ip | |
| Zieladresse (dst) | dst | dst | target.ip | |
| NAT-Quell-IP-Adresse (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| NAT-Ziel-IP-Adresse (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Regel (rule) | cs1 | RuleName | security_result.rule_name | |
| Quellnutzer (srcuser) | suser | SourceUser | principal.user.userid | |
| Zielnutzer (dstuser) | duser | DestinationUser | target.user.userid | |
| Anwendung (App) | App | Anwendung | network.application_protocol | |
| Virtuelles System (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Quellzone (von) | cs4 | SourceZone | von | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
| Zielzone (bis) | cs5 | DestinationZone | bis | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
| Eingangsschnittstelle (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
| Ausgangsschnittstelle (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
| Aktion protokollieren (Logset) | cs6 | LogForwardingProfile | logset | additional.fields.key und additional.fields.value.string_value |
| Zeit der Protokollierung | time_logged | additional.fields.key und additional.fields.value.string_value | ||
| Sitzungs-ID (sessionid) | cn1 | SessionID | network.session_id | |
| Anzahl der Wiederholungen (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key und additional.fields.value.string_value |
| Quellport (sport) | spt | srcPort | principal.port | |
| Zielport (dport) | dpt | dstPort | target.port | |
| NAT-Quellport (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| NAT-Zielport (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Flags (flags) | flexString1 | Flags | flags | additional.fields.key und additional.fields.value.string_value |
| IP-Protokoll (proto) | Proto | Proto | network.ip_protocol | |
| Aktion (action) | Handeln | Aktion | security_result.action_details
security_result.action |
|
| URL/Dateiname (Sonstiges) | Sonstiges | target.file.names
target.url |
||
| Name der Bedrohung/des Inhalts (threatid) | cat | ThreatID | security_result.threat_id | |
| Kategorie (category) | cs2 | URLCategory | Kategorie | security_result.category_details |
| Schweregrad (severity) | number-of-severity (Header) | Schweregrad | security_result.severity
security_result.severity_details |
|
| Richtung (direction) | flexString2 | Richtung | network.direction | |
| Sequenznummer (seqno) | externalId | Sequenz | metadata.product_log_id | |
| Aktions-Flags (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key und additional.fields.value.string_value |
| Quellland (srcloc) | SourceLocation | principal.location.country_or_region | ||
| Zielland (dstloc) | DestinationLocation | target.location.country_or_region | ||
| contenttype (contenttype) | requestContext | ContentType | contenttype | additional.fields.key und additional.fields.value.string_value |
| pcap_id (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key und additional.fields.value.string_value |
| filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | ||
| cloud (cloud) | Cloud | Cloud | additional.fields.key und additional.fields.value.string_value | |
| url_idx (url_idx) | URLIndex | url_idx | additional.fields.key und additional.fields.value.string_value | |
| user_agent (user_agent) | requestClientApplication | User-Agent | network.http.user_agent | |
| Dateityp (filetype) | target.file.mime_type | |||
| xff (xff) | PanOSXForwarderfor | identSrc | xff | principal.ip |
| Referrer (referer) | PanOSReferer | Verwiesen von: | network.http.referral_url | |
| Absender (sender) | network.email.from | |||
| Betreff (subject) | Betreff | network.email.subject | ||
| Empfänger (recipient) | network.email.to | |||
| reportid (reportid) | reportid | additional.fields.key und additional.fields.value.string_value | ||
| DG Hierarchy Level 1 (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key und additional.fields.value.string_value |
| DG Hierarchy Level 2 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key und additional.fields.value.string_value |
| DG Hierarchy Level 3 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key und additional.fields.value.string_value |
| Demand Gen-Hierarchieebene 4 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key und additional.fields.value.string_value |
| Name des virtuellen Systems (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Gerätename (device_name) | dvchost | DeviceName | intermediary.hostname | |
| file_url (file_url) | target.url | |||
| UUID der Quell-VM (src_uuid) | SrcUUID | principal.asset.product_object_id | ||
| UUID der Ziel-VM (dst_uuid) | DstUUID | target.asset.product_object_id | ||
| http_method (http_method) | requestMethod | RequestMethod | network.http.method | |
| Tunnel-ID/IMSI (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key und additional.fields.value.string_value |
| Monitor-Tag/IMEI (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key und additional.fields.value.string_value |
| ID der übergeordneten Sitzung (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Beginn der übergeordneten Sitzung (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key und additional.fields.value.string_value |
| Tunnel (tunnel) | PanOSTunnelType | TunnelType | Tunnel | additional.fields.key und additional.fields.value.string_value |
| thr_category (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| contentver (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key und additional.fields.value.string_value |
| sig_flags (sig_flags) | sig_flags | additional.fields.key und additional.fields.value.string_value | ||
| SCTP-Verbindungs-ID (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key und additional.fields.value.string_value | |
| Payload Protocol ID (ppid) | PanOSPPID | ppid | additional.fields.key und additional.fields.value.string_value | |
| http_headers (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Liste der URL-Kategorien (url_category_list) | PanOSURLCatList | url_category_list | additional.fields.key und additional.fields.value.string_value | |
| UUID für Regel (rule_uuid) | PanOSRuleUUID | rule_uuid | security_result.rule_id | |
| HTTP/2-Verbindung (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| dynusergroup_name (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | additional.fields.key und additional.fields.value.string_value | |
| XFF-Adresse (xff_ip) | PanXFFIP | principal.ip | ||
| Gerätekategorie der Quelle (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Quellgeräteprofil (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
|
| Quellgerätemodell (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Quellgeräteanbieter (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Betriebssystemfamilie des Quellgeräts (src_osfamily) | PanSrcDeviceOS | principal.platform | ||
| Betriebssystemversion des Quellgeräts (src_osversion) | PanSrcDeviceOSv | principal.platform_version | ||
| Quellhostname (src_host) | PanSrcHostname | src_host | principal.hostname | |
| Quell-MAC-Adresse (src_mac) | PanSrcMac | principal.mac | ||
| Zielgerätekategorie (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Zielgeräteprofil (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
|
| Zielgerätemodell (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Anbieter des Zielgeräts (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Betriebssystemfamilie des Zielgeräts (dst_osfamily) | PanDstDeviceOS | target.platform | ||
| Betriebssystemversion des Zielgeräts (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Ziel-Hostname (dst_host) | PanPODNamespace | target.hostname | ||
| MAC-Zieladresse (dst_mac) | PanDstMac | target.mac | ||
| Container-ID (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| POD Namespace (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| POD-Name (pod_name) | PanPODName | pod_name | target.resource.name | |
| Externe dynamische Quellliste (src_edl) | PanSrcEDL | src_edl | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
|
| Dynamische Liste für externes Ziel (dst_edl) | PanDstEDL | dst_edl | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
|
| Host-ID (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Seriennummer (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| domain_edl (domain_edl) | PanDomainEDL | domain_edl | additional.fields.key und additional.fields.value.string_value | |
| Dynamische Quelladressengruppe (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Dynamische Zieladressengruppe (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| partial_hash (partial_hash) | PanPartialHash | partial_hash | additional.fields.key und additional.fields.value.string_value | |
| Zeitstempel mit hoher Auflösung (high_res_timestamp) | PanTimeHighRes | additional.fields.key und additional.fields.value.string_value | ||
| Grund (reason) | PanReasonFilteringAction | reason | security_result.summary | |
| Blocksatz (justification) | PanJustification | Begründung | additional.fields.key und additional.fields.value.string_value | |
| nssai_sst (nssai_sst) | PanASServiceType | nssai_sst | additional.fields.key und additional.fields.value.string_value | |
| Unterkategorie der App (subcategory_of_app) | subcategory_of_app | additional.fields.key und additional.fields.value.string_value | ||
| App-Kategorie (category_of_app) | category_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Technologie der App (technology_of_app) | technology_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Risiko der App (risk_of_app) | risk_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Merkmal der App (characteristic_of_app) | characteristic_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Container der App (container_of_app) | container_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Getunnelte App (tunneled_app) | tunneled_app | additional.fields.key und additional.fields.value.string_value | ||
| SaaS der App (is_saas_of_app) | is_saas_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Genehmigter Status der App (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Cloud-Bericht-ID (cloud_reportid) | additional.fields.key und additional.fields.value.string_value | |||
| Clustername (cluster_name) |
principal.resource.name |
|||
| Vorgangstyp (flow_type) | additional.fields.key und additional.fields.value.string_value |
Daten
In der folgenden Tabelle sind die Logfelder des Datenlogtyps und die entsprechenden UDM-Felder aufgeführt.
| CSV-Feld | CEF-Feld | LEEF-Feld | Schlüssel für Google Security Operations-Label | UDM-Feld |
|---|---|---|---|---|
| Empfangszeit (cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist) |
|
| Seriennummer (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Typ (type) | Typ (Header) | cat | metadata.product_event_type | |
| Bedrohungs-/Inhaltstyp (Untertyp) | Untertyp (Kopfzeile) | Subtyp | metadata.product_event_type | |
| Generierungszeit | metadata.event_timestamp | |||
| Quelladresse (src) | src | src | principal.ip | |
| Zieladresse (dst) | dst | dst | target.ip | |
| NAT-Quell-IP-Adresse (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| NAT-Ziel-IP-Adresse (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Regel (rule) | cs1 | RuleName | security_result.rule_name | |
| Quellnutzer (srcuser) | suser | SourceUser | principal.user.userid | |
| Zielnutzer (dstuser) | duser | DestinationUser | target.user.userid | |
| Anwendung (App) | App | Anwendung | network.application_protocol | |
| Virtuelles System (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Quellzone (von) | cs4 | SourceZone | von | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
| Zielzone (bis) | cs5 | DestinationZone | bis | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
| Eingangsschnittstelle (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
| Ausgangsschnittstelle (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
| Aktion protokollieren (Logset) | cs6 | LogForwardingProfile | logset | additional.fields.key und additional.fields.value.string_value |
| Zeit der Protokollierung | time_logged | additional.fields.key und additional.fields.value.string_value | ||
| Sitzungs-ID (sessionid) | cn1 | SessionID | network.session_id | |
| Anzahl der Wiederholungen (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key und additional.fields.value.string_value |
| Quellport (sport) | spt | srcPort | principal.port | |
| Zielport (dport) | dpt | dstPort | target.port | |
| NAT-Quellport (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| NAT-Zielport (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Flags (flags) | flexString1 | Flags | flags | additional.fields.key und additional.fields.value.string_value |
| IP-Protokoll (proto) | Proto | Proto | network.ip_protocol | |
| Aktion (action) | Handeln | Aktion | security_result.action_details
security_result.action |
|
| URL/Dateiname (Sonstiges) | Sonstiges | target.file.names
target.url |
||
| Name der Bedrohung/des Inhalts (threatid) | cat | ThreatID | security_result.threat_id | |
| Kategorie (category) | cs2 | URLCategory | Kategorie | security_result.category_details |
| Schweregrad (severity) | number-of-severity (Header) | Schweregrad | security_result.severity
security_result.severity_details |
|
| Richtung (direction) | flexString2 | Richtung | network.direction | |
| Sequenznummer (seqno) | externalId | Sequenz | metadata.product_log_id | |
| Aktions-Flags (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key und additional.fields.value.string_value |
| Quellland (srcloc) | SourceLocation | principal.location.country_or_region | ||
| Zielland (dstloc) | DestinationLocation | target.location.country_or_region | ||
| contenttype (contenttype) | ContentType | contenttype | additional.fields.key und additional.fields.value.string_value | |
| pcap_id (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key und additional.fields.value.string_value |
| filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | ||
| cloud (cloud) | Cloud | Cloud | additional.fields.key und additional.fields.value.string_value | |
| url_idx (url_idx) | URLIndex | url_idx | additional.fields.key und additional.fields.value.string_value | |
| user_agent (user_agent) | network.http.user_agent | |||
| Dateityp (filetype) | target.file.mime_type | |||
| xff (xff) | xff | principal.ip | ||
| Referrer (referer) | network.http.referral_url | |||
| Absender (sender) | network.email.from | |||
| Betreff (subject) | Betreff | network.email.subject | ||
| Empfänger (recipient) | network.email.to | |||
| reportid (reportid) | reportid | additional.fields.key und additional.fields.value.string_value | ||
| DG Hierarchy Level 1 (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key und additional.fields.value.string_value |
| DG Hierarchy Level 2 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key und additional.fields.value.string_value |
| DG Hierarchy Level 3 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key und additional.fields.value.string_value |
| Demand Gen-Hierarchieebene 4 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key und additional.fields.value.string_value |
| Name des virtuellen Systems (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Gerätename (device_name) | dvchost | DeviceName | intermediary.hostname | |
| file_url (file_url) | target.url | |||
| UUID der Quell-VM (src_uuid) | SrcUUID | principal.asset.product_object_id | ||
| UUID der Ziel-VM (dst_uuid) | DstUUID | target.asset.product_object_id | ||
| http_method (http_method) | RequestMethod | network.http.method | ||
| Tunnel-ID/IMSI (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key und additional.fields.value.string_value |
| Monitor-Tag/IMEI (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key und additional.fields.value.string_value |
| ID der übergeordneten Sitzung (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Beginn der übergeordneten Sitzung (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key und additional.fields.value.string_value |
| Tunnel (tunnel) | PanOSTunnelType | TunnelType | Tunnel | additional.fields.key und additional.fields.value.string_value |
| thr_category (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| contentver (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key und additional.fields.value.string_value |
| sig_flags (sig_flags) | sig_flags | additional.fields.key und additional.fields.value.string_value | ||
| SCTP-Verbindungs-ID (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key und additional.fields.value.string_value | |
| Payload Protocol ID (ppid) | PanOSPPID | ppid | additional.fields.key und additional.fields.value.string_value | |
| http_headers (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Liste der URL-Kategorien (url_category_list) | url_category_list | additional.fields.key und additional.fields.value.string_value | ||
| UUID für Regel (rule_uuid) | PanOSRuleUUID | rule_uuid | security_result.rule_id | |
| HTTP/2-Verbindung (http2_connection) | http2_connection | network.application_protocol_version | ||
| dynusergroup_name (dynusergroup_name) | dynusergroup_name | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
||
| XFF-Adresse (xff_ip) | principal.ip | |||
| Gerätekategorie der Quelle (src_category) | src_category | principal.asset.category | ||
| Quellgeräteprofil (src_profile) | src_profile | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
||
| Quellgerätemodell (src_model) | src_model | principal.asset.hardware.model | ||
| Quellgeräteanbieter (src_vendor) | src_vendor | principal.asset.hardware.manufacturer | ||
| Betriebssystemfamilie des Quellgeräts (src_osfamily) | principal.platform | |||
| Betriebssystemversion des Quellgeräts (src_osversion) | principal.platform_version | |||
| Quellhostname (src_host) | src_host | principal.hostname | ||
| Quell-MAC-Adresse (src_mac) | principal.mac | |||
| Zielgerätekategorie (dst_category) | dst_category | target.asset.category | ||
| Zielgeräteprofil (dst_profile) | dst_profile | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
||
| Zielgerätemodell (dst_model) | dst_model | target.asset.hardware.model | ||
| Anbieter des Zielgeräts (dst_vendor) | dst_vendor | target.asset.hardware.manufacturer | ||
| Betriebssystemfamilie des Zielgeräts (dst_osfamily) | target.platform | |||
| Betriebssystemversion des Zielgeräts (dst_osversion) | target.platform_version | |||
| Ziel-Hostname (dst_host) | target.hostname | |||
| MAC-Zieladresse (dst_mac) | target.mac | |||
| Container-ID (container_id) | container_id | intermediary.resource.product_object_id | ||
| POD Namespace (pod_namespace) | pod_namespace | target.resource.attribute.labels.key/value | ||
| POD-Name (pod_name) | pod_name | target.resource.name | ||
| Externe dynamische Quellliste (src_edl) | src_edl | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
||
| Dynamische Liste für externes Ziel (dst_edl) | dst_edl | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
||
| Host-ID (hostid) | hostid | principal.asset.asset_id | ||
| Seriennummer (serialnumber) | principal.asset.hardware.serial_number | |||
| domain_edl (domain_edl) | domain_edl | additional.fields.key und additional.fields.value.string_value | ||
| Dynamische Quelladressengruppe (src_dag) | principal.group.group_display_name | |||
| Dynamische Zieladressengruppe (dst_dag) | target.group.group_display_name | |||
| partial_hash (partial_hash) | partial_hash | additional.fields.key und additional.fields.value.string_value | ||
| Zeitstempel mit hoher Auflösung (high_res_timestamp) | additional.fields.key und additional.fields.value.string_value | |||
| Grund (reason) | reason | security_result.summary | ||
| Blocksatz (justification) | Begründung | additional.fields.key und additional.fields.value.string_value | ||
| nssai_sst (nssai_sst) | nssai_sst | additional.fields.key und additional.fields.value.string_value | ||
| Unterkategorie der App (subcategory_of_app) | subcategory_of_app | additional.fields.key und additional.fields.value.string_value | ||
| App-Kategorie (category_of_app) | category_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Technologie der App (technology_of_app) | technology_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Risiko der App (risk_of_app) | risk_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Merkmal der App (characteristic_of_app) | characteristic_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Container der App (container_of_app) | container_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Getunnelte App (tunneled_app) | tunneled_app | additional.fields.key und additional.fields.value.string_value | ||
| SaaS der App (is_saas_of_app) | is_saas_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Genehmigter Status der App (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Cloud-Bericht-ID (cloud_reportid) | additional.fields.key und additional.fields.value.string_value | |||
| Clustername (cluster_name) | principal.resource.name | |||
| Vorgangstyp (flow_type) | additional.fields.key und additional.fields.value.string_value |
GlobalProtect
In der folgenden Tabelle sind die Logfelder des GlobalProtect-Logtyps und die entsprechenden UDM-Felder aufgeführt.
| CSV-Feld | CEF-Feld | LEEF-Feld | Schlüssel für Google Security Operations-Label | UDM-Feld |
|---|---|---|---|---|
| Empfangszeit (receive_time) | rt | received_time | metadata.event_timestamp | |
| Seriennummer (serial) | PanOSDeviceSN | intermediary_asset_hardware_serial_number | intermediary.asset.hardware.serial_number | |
| Typ (type) | Typ (Header) | metadata.product_event_type | ||
| Bedrohungs-/Inhaltstyp (Untertyp) | Untertyp (Kopfzeile) | Subtyp | metadata.product_event_type | |
| Erstellungszeit (time_generated) | PanOSLogTimeStamp | generated_timestamp | metadata.event_timestamp | |
| Virtuelles System (vsys) | PanOSVirtualSystem | vsys | intermediary.asset.attribute.labels.key/value | |
| Ereignis-ID (eventid) | PanOSEventID | event_id | additional.fields.key und additional.fields.value.string_value | |
| Phase (stage) | PanOSStage | Phase | additional.fields.key und additional.fields.value.string_value | |
| Authentifizierungsmethode (auth_method) | PanOSAuthMethod | extension_auth_auth_details | extensions.auth.auth_details | |
| Tunneltyp (tunnel_type) | PanOSTunnelType | Tunnel | additional.fields.key und additional.fields.value.string_value | |
| Quellnutzer (srcuser) | PanOSSourceUserName | src_user | principal.user.email_address
principal.user.userid principal.administrative_domain |
|
| Quellregion (srcregion) | PanOSSourceRegion | src_region | principal.location.country_or_region | |
| Computername (machinename) | PanOSEndpointDeviceName | machine_name | principal.hostname | |
| Öffentliche IP-Adresse (public_ip) | PanOSPublicIPv4 | principal.nat_ip | ||
| Öffentliches IPv6 (public_ipv6) | PanOSPublicIPv6 | principal.nat_ip | ||
| Private IP-Adresse (private_ip) | PanOSPrivateIPv4 | principal.ip | ||
| Private IPv6 (private_ipv6) | PanOSPrivateIPv6 | principal.ip | ||
| Host-ID (hostid) | PanOSHostID | hostid | principal.asset.asset_id | |
| Seriennummer (serialnumber) | PanOSDeviceSN | principal.asset.hardware.serial_number | ||
| Clientversion (client_ver) | PanOSGlobalProtectClientVersion | client_ver | additional.fields.key und additional.fields.value.string_value | |
| Clientbetriebssystem (client_os) | PanOSEndpointOSType | principal.platform | ||
| Client-Betriebssystemversion (client_os_ver) | PanOSEndpointOSVersion | principal.platform_version | ||
| Anzahl der Wiederholungen (repeatcnt) | PanOSCountOfRepeats | repeatcnt | additional.fields.key und additional.fields.value.string_value | |
| Grund (reason) | PanOSQuarantineReason | security_result.summary | ||
| Fehler (error) | PanOSConnectionError | Fehler | security_result.description | |
| Beschreibung (undurchsichtig) | PanOSDescription | security_result.description | ||
| Status (status) | PanOSEventStatus | Status | additional.fields.key und additional.fields.value.string_value | |
| Standort (location) | PanOSGPGatewayLocation | target.location.country_or_region | ||
| Anmeldedauer (login_duration) | PanOSLoginDuration | network.session_duration | ||
| Verbindungsmethode (connect_method) | PanOSConnectionMethod | connect_method | additional.fields.key und additional.fields.value.string_value | |
| Fehlercode (error_code) | PanOSConnectionErrorID | error_code | additional.fields.key und additional.fields.value.string_value | |
| Portal (portal) | PanOSPortal | Portal | additional.fields.key und additional.fields.value.string_value | |
| Sequenznummer (seqno) | PanOSSequenceNo | metadata.product_log_id | ||
| Aktions-Flags (actionflags) | PanOSActionFlags | actionflags | additional.fields.key und additional.fields.value.string_value | |
| Zeitstempel mit hoher Auflösung (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key und additional.fields.value.string_value | ||
| Methode zur Gateway-Auswahl (selection_type) | PanOSGatewaySelectionType | selection_type | additional.fields.key und additional.fields.value.string_value | |
| SSL-Reaktionszeit (response_time) | PanOSSSLResponseTime | response_time | additional.fields.key und additional.fields.value.string_value | |
| Gateway-Priorität (priority) | PanOSGatewayPriority | Priorität | additional.fields.key und additional.fields.value.string_value | |
| Versuchte Gateways (attempted_gateways) | PanOSAttemptedGateways | attempted_gateways | additional.fields.key und additional.fields.value.string_value | |
| Name des Gateways (gateway) | PanOSAttemptedGateways | Gateway | target.resource.name | |
| Hierarchie der Gerätegruppen (dg_hier_level_1) | dg_hier_level_1 | additional.fields.key und additional.fields.value.string_value | ||
| Hierarchie der Gerätegruppen (dg_hier_level_2) | dg_hier_level_2 | additional.fields.key und additional.fields.value.string_value | ||
| Gerätegruppenhierarchie (dg_hier_level_3) | dg_hier_level_3 | additional.fields.key und additional.fields.value.string_value | ||
| Gerätegruppenhierarchie (dg_hier_level_4) | dg_hier_level_4 | additional.fields.key und additional.fields.value.string_value | ||
| Name des virtuellen Systems (vsys_name) | intermediary.asset.attribute.labels.key/value | |||
| Gerätename (device_name) | intermediary.hostname | |||
| ID des virtuellen Systems (vsys_id) | intermediary.resource.product_object_id | |||
| Schweregrad (severity) | number-of-severity(header) | security_result.severity und security_result.severity_details | ||
| Clustername (cluster_name) | principal.resource.name |
Ergebnisse in Beziehung setzen
In der folgenden Tabelle sind die Logfelder des Typs „Korrelation“ und die entsprechenden UDM-Felder aufgeführt.
| CSV-Feld | CEF-Feld | LEEF-Feld | Schlüssel für Google Security Operations-Label | UDM-Feld |
|---|---|---|---|---|
| Generierte Zeit (time_generated oder cef-formatted-time_generated) | startTime | generated_timestamp | metadata.event_timestamp | |
| Quelladresse (src) | src | principal.ip | ||
| Quellnutzer (srcuser) | SourceUser / usrName | principal.user.userid | ||
| Virtuelles System (vsys) | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value | |
| Kategorie (category) | security_result.category_details | |||
| Schweregrad (severity) | Schweregrad | security_result.severity und security_result.severity_details | ||
| Gerätegruppenhierarchie – Ebene 1 | DeviceGroupHierarchyL1 | additional.fields.key und additional.fields.value.string_value | ||
| Gerätegruppenhierarchie – Stufe 2 | DeviceGroupHierarchyL2 | additional.fields.key und additional.fields.value.string_value | ||
| Gerätegruppenhierarchie – Ebene 3 | DeviceGroupHierarchyL3 | additional.fields.key und additional.fields.value.string_value | ||
| Hierarchieebene 4 der Gerätegruppe | DeviceGroupHierarchyL4 | additional.fields.key und additional.fields.value.string_value | ||
| Name des virtuellen Systems (vsys_name) | vSrcName | intermediary.asset.attribute.labels.key/value | ||
| Gerätename (device_name) | DeviceName | intermediary.hostname | ||
| ID des virtuellen Systems (vsys_id) | VirtualSystemID | intermediary.resource.product_object_id | ||
| Objektname (objectname) | ObjectName | target.resource.name | ||
| Objekt-ID (object_id) | ObjectID | target.resource.product_object_id | ||
| Nachweis | msg | security_result.summary |
GTP
In der folgenden Tabelle sind die Logfelder des Logtyps „gtp“ und die entsprechenden UDM-Felder aufgeführt.
| CSV-Feld | CEF-Feld | LEEF-Feld | Schlüssel für Google Security Operations-Label | UDM-Feld |
|---|---|---|---|---|
| Empfangszeit (receive_time oder cef-formatted-receive_time) | metadata.collected_timestamp,
metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist) |
|||
| Seriennummer (serial) | intermediary.asset.hardware.serial_number | |||
| Typ (type) | metadata.product_event_type | |||
| Bedrohungs-/Inhaltstyp (Untertyp) | metadata.product_event_type | |||
| Generierte Zeit (time_generated oder cef-formatted-time_generated) | metadata.event_timestamp | |||
| Quelladresse (src) | principal.ip | |||
| Zieladresse (dst) | target.ip | |||
| Regelname (rule) | security_result.rule_name | |||
| Anwendung (App) | network.application_protocol | |||
| Virtuelles System (vsys) | vsys | intermediary.asset.attribute.labels.key/value | ||
| Quellzone (von) | von | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
||
| Zielzone (bis) | bis | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
||
| Eingangsschnittstelle (inbound_if) | inbound_if | principal.labels.key und principal.labels.value additional.fields.key und additional.fields.value.string_value |
||
| Ausgangsschnittstelle (outbound_if) | outbound_if | target.labels.key und target.labels.value additional.fields.key und additional.fields.value.string_value |
||
| Aktion protokollieren (Logset) | logset | additional.fields.key und additional.fields.value.string_value | ||
| Sitzungs-ID (sessionid) | network.session_id | |||
| Quellport (sport) | principal.port | |||
| Zielport (dport) | target.port | |||
| IP-Protokoll (proto) | network.ip_protocol | |||
| Aktion (action) | security_result.action_details
security_result.action |
|||
| GTP-Ereignistyp (event_type) | gtp_event_type | additional.fields.key und additional.fields.value.string_value | ||
| MSISDN (msisdn) | msisdn | additional.fields.key und additional.fields.value.string_value | ||
| Name des Zugangspunkts (APN) | apn | additional.fields.key und additional.fields.value.string_value | ||
| Radio Access Technology (RAT) | Ratte | additional.fields.key und additional.fields.value.string_value | ||
| GTP-Nachrichtentyp (msg_type) | gtp_msg_type | additional.fields.key und additional.fields.value.string_value | ||
| End-IP-Adresse (end_ip_adr) | principal.ip | |||
| Tunnelendpunkt-ID1 (teid1) | teid1 | additional.fields.key und additional.fields.value.string_value | ||
| Tunnelendpunkt-ID2 (teid2) | teid2 | additional.fields.key und additional.fields.value.string_value | ||
| GTP-Schnittstelle (gtp_interface) | gtp_interface | additional.fields.key und additional.fields.value.string_value | ||
| GTP-Ursache (cause_code) | gtp_cause_code | additional.fields.key und additional.fields.value.string_value | ||
| Schweregrad (severity) | security_result.severity und security_result.severity_details | |||
| MCC des bereitstellenden Mobilfunknetzes (mcc) | mcc | additional.fields.key und additional.fields.value.string_value | ||
| MNC des Bereitstellungsnetzwerks (mnc) | mnc | additional.fields.key und additional.fields.value.string_value | ||
| Vorwahl (area_code) | area_code | additional.fields.key und additional.fields.value.string_value | ||
| Zellen-ID (cell_id) | cell_id | additional.fields.key und additional.fields.value.string_value | ||
| GTP-Ereigniscode (event_code) | event_code | additional.fields.key und additional.fields.value.string_value | ||
| Quellort (srcloc) | principal.location.country_or_region | |||
| Zielort (dstloc) | target.location.country_or_region | |||
| Tunnel-ID/IMSI (imsi) | tunnelid | additional.fields.key und additional.fields.value.string_value | ||
| Monitor Tag/IMEI (imei) | monitortag | additional.fields.key und additional.fields.value.string_value | ||
| Beginn (start) | start | additional.fields.key und additional.fields.value.string_value | ||
| Verstrichene Zeit (elapsed) | network.session_duration.seconds | |||
| Tunnel Inspection RuleTunnel (tunnel_insp_rule) | tunnel_insp_rule | security_result.detection_fields.key/value | ||
| Remote-Nutzer-IP (remote_user_ip) | principal.ip | |||
| Remote-Nutzer-ID (remote_user_id) | remote_user_id | principal.user.userid | ||
| UUID für Regel (rule_uuid) | security_result.rule_id | |||
| PCAP-ID (pcap_id) | pcap_id | additional.fields.key und additional.fields.value.string_value | ||
| Zeitstempel mit hoher Auflösung (high_res_timestamp) | additional.fields.key und additional.fields.value.string_value | |||
| Ein Slice-Diensttyp (nsdsai_sst) | nsdsai_sst | additional.fields.key und additional.fields.value.string_value | ||
| Slice-Differenzierung (nsdsai_sd) | nsdsai_sd | additional.fields.key und additional.fields.value.string_value | ||
| Unterkategorie der Anwendung (subcategory_of_app) | subcategory_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Anwendungskategorie (category_of_app) | category_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Anwendungstechnologie (technology_of_app) | technology_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Anwendungsrisiko (risk_of_app) | risk_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Anwendungsmerkmal (characteristic_of_app) | characteristic_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Anwendungscontainer (container_of_app) | container_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Application SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key und additional.fields.value.string_value | ||
| Status der Genehmigung der Anwendung (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key und additional.fields.value.string_value |
SCTP
| CSV-Feld | CEF-Feld | LEEF-Feld | Schlüssel für Google Security Operations-Label | UDM-Feld |
|---|---|---|---|---|
| Empfangszeit (receive_time oder cef-formatted-receive_time) | receive_time oder cef-formatted-receive_time | metadata.collected_timestamp | ||
| Seriennummer (serial) | serial | intermediary.asset.hardware.serial_number | ||
| Typ (type) | Typ | metadata.product_event_type | ||
| Generierte Zeit (time_generated oder cef-formatted-time_generated) | time_generated oder cef-formatted-time_generated | metadata.event_timestamp | ||
| Quelladresse (src) | src | principal.ip | ||
| Zieladresse (dst) | dst | target.ip | ||
| Regelname (rule) | Regel | security_result.rule_name | ||
| Quellzone (von) | von | additional.fields.key und additional.fields.value.string_value | ||
| Zielzone (bis) | bis | additional.fields.key und additional.fields.value.string_value | ||
| Eingangsschnittstelle (inbound_if) | inbound_if | additional.fields.key und additional.fields.value.string_value | ||
| Ausgangsschnittstelle (outbound_if) | outbound_if | additional.fields.key und additional.fields.value.string_value | ||
| Aktion protokollieren (Logset) | logset | additional.fields.key und additional.fields.value.string_value | ||
| Sitzungs-ID (sessionid) | sessionid | network.session_id | ||
| Anzahl der Wiederholungen (repeatcnt) | repeatcnt | additional.fields.key und additional.fields.value.string_value | ||
| Quellport (sport) | sport | principal.port | ||
| Zielport (dport) | dport | target.port | ||
| IP-Protokoll (proto) | Proto | network.ip_protocol (enum) | ||
| Aktion (action) | Aktion | security_result.action_details security_result.action |
||
| Gerätegruppenhierarchie (dg_hier_level_1 bis dg_hier_level_4) | dg_hier_level_1 bis dg_hier_level_4 | additional.fields.key und additional.fields.value.string_value | ||
| Gerätename (device_name) | device_name | intermediary.hostname | ||
| Sequenznummer (seqno) | seqno | metadata.product_log_id | ||
| SCTP-Verbindungs-ID (assoc_id) | assoc_id | additional.fields.key und additional.fields.value.string_value | ||
| Payload Protocol ID (ppid) | ppid | additional.fields.key und additional.fields.value.string_value | ||
| Schweregrad (severity) | die Ausprägung | security_result.severity und security_result.severity_details | ||
| SCTP-Chunk-Typ (sctp_chunk_type) | sctp_chunk_type | additional.fields.key und additional.fields.value.string_value | ||
| SCTP-Ereignistyp (sctp_event_type) | sctp_event_type | additional.fields.key und additional.fields.value.string_value | ||
| SCTP-Bestätigungs-Tag 1 (verif_tag_1) | verif_tag_1 | additional.fields.key und additional.fields.value.string_value | ||
| SCTP-Bestätigungs-Tag 2 (verif_tag_2) | verif_tag_2 | additional.fields.key und additional.fields.value.string_value | ||
| SCTP-Ursachencode (sctp_cause_code) | sctp_cause_code | additional.fields.key und additional.fields.value.string_value | ||
| Diameter-App-ID (diam_app_id) | diam_app_id | additional.fields.key und additional.fields.value.string_value | ||
| Befehlscode für Durchmesser (diam_cmd_code) | diam_cmd_code | additional.fields.key und additional.fields.value.string_value | ||
| AVP-Code für Durchmesser (diam_avp_code) | diam_avp_code | additional.fields.key und additional.fields.value.string_value | ||
| SCTP-Stream-ID (stream_id) | stream_id | additional.fields.key und additional.fields.value.string_value | ||
| Grund für das Ende der SCTP-Verbindung (assoc_end_reason) | assoc_end_reason | additional.fields.key und additional.fields.value.string_value | ||
| Op-Code (op_code) | op_code | additional.fields.key und additional.fields.value.string_value | ||
| SCCP-SSN des Anrufers (sccp_calling_ssn) | sccp_calling_ssn | additional.fields.key und additional.fields.value.string_value | ||
| SCCP Calling Party Global Title (sccp_calling_gt) | sccp_calling_gt | additional.fields.key und additional.fields.value.string_value | ||
| SCTP-Filter (sctp_filter) | sctp_filter | additional.fields.key und additional.fields.value.string_value | ||
| SCTP-Chunks | Chunks | additional.fields.key und additional.fields.value.string_value | ||
| Gesendete SCTP-Chunks (chunks_sent) | chunks_sent | additional.fields.key und additional.fields.value.string_value | ||
| Empfangene SCTP-Chunks (chunks_received) | chunks_received | additional.fields.key und additional.fields.value.string_value | ||
| Pakete (packets) | Pakete | additional.fields.key und additional.fields.value.string_value | ||
| UUID für Regel (rule_uuid) | rule_uuid | security_result.rule_id | ||
| Virtuelles System (vsys) | vsys | intermediary.asset.attribute.labels.key/value | ||
| Name des virtuellen Systems (vsys_name) | vsys_name | intermediary.asset.attribute.labels.key/value | ||
| Gesendete Pakete (pkts_sent) | pkts_sent | network.sent_packets | ||
| Empfangene Pakete (pkts_received) | pkts_received | network.received_packets |
Audit
| CSV-Feld | CEF-Feld | LEEF-Feld | Schlüssel für Google Security Operations-Label | UDM-Feld |
|---|---|---|---|---|
| Generierungszeit | metadata.event_timestamp | |||
| Bedrohungs-/Inhaltstyp (Untertyp) | metadata.product_event_type | |||
| Ereignis-ID | principal.application | |||
| Objekt | principal.user.userid | |||
| CLI-Befehl | principal.process.command_line | |||
| Schweregrad | security_result.severity | |||
| Seriennummer | intermediary.asset.hardware.serial_number |
Feldzuordnung – Referenz: Protokolltypen zu UDM-Ereignistyp
In der folgenden Tabelle sind die Palo Alto Networks-Firewall-Logtypen und die entsprechenden UDM-Ereignistypen aufgeführt.
| Logtyp | UDM-Ereignistyp |
| Traffic | NETWORK_CONNECTION |
| Bedrohung | NETWORK_CONNECTION |
| URL-Filter | NETWORK_CONNECTION |
| WildFire | NETWORK_CONNECTION
WildFire-Übermittlungsprotokolle sind ein Untertyp des Threat-Protokolltyps und verwenden dasselbe Syslog-Format. |
| Datenfilterung | NETWORK_CONNECTION |
| Tunnel | NETWORK_CONNECTION |
| GTP | NETWORK_CONNECTION |
| Konfiguration | SETTING_MODIFICATION/SETTING_CREATION/SETTING_DELETION/SETTING_UNCATEGORIZED
Der Wert des Felds „Befehl (cmd)“ bestimmt die Zuordnung des UDM-Ereignistyps. Wenn der Wert des Felds „cmd“ „add“ oder „clone“ ist, wird „SETTING_CREATION“ festgelegt. Wenn der Wert des Felds „cmd“ „delete“ ist, wird „SETTING_DELETION“ festgelegt. Wenn der Wert des Felds „cmd“ „edit“, „move“, „rename“, „set“ oder „commit“ ist, wird SETTING_MODIFICATION festgelegt. Wenn der Wert des Felds „cmd“ keine Werte enthält, wird SETTING_UNCATEGORIZED festgelegt. |
| System |
Wenn der Untertypwert „dhcp“ ist, wird NETWORK_DHCP festgelegt. Wenn der Untertypwert „auth“ ist, wird USER_LOGIN festgelegt. Wenn der Wert für „description“ „logged in“ lautet, wird USER_LOGIN festgelegt. Wenn der Wert der Beschreibung „logged out“ lautet, wird USER_LOGOUT festgelegt. Für andere Werte des Subtyps wird GENERIC_EVENT festgelegt. |
| HIP-Abgleich | NETWORK_CONNECTION |
| IP-Tag | GENERIC_EVENT |
| User-ID | USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED
Wenn der Untertypwert „login“ ist, wird USER_LOGIN festgelegt. Wenn der Untertypwert „logout“ ist, wird USER_LOGOUT festgelegt. Wenn der Untertyp keinen Wert enthält, wird USER_UNCATEGORIZED festgelegt. |
| Entschlüsselung | NETWORK_CONNECTION |
| Authentifizierung | GENERIC_EVENT |
| SCTP | NETWORK_CONNECTION |
| Audit | GENERIC_EVENT |
UDM-Zuordnungsdelta
UDM-Mapping-Delta-Referenz: Palo Alto Networks Firewall
In der folgenden Tabelle sind die Unterschiede zwischen der alten UDM-Zuordnung von Palo Alto Networks Firewall und der neuen UDM-Zuordnung von Palo Alto Networks Firewall aufgeführt.
UDM Event Type Delta
| Log type | Old UDM Event Type | New UDM Event Type |
| WildFire | NETWORK_CONNECTION | SCAN_UNCATEGORIZED |
| Data Filtering | NETWORK_CONNECTION | NETWORK_UNCATEGORIZED |
| Authentication | STATUS_UPDATE | STATUS_UNCATEGORIZED |
UDM Field Mapping Delta
| Log Type | Old UDM Mapping | CSV Log Field | CEF Log Field | LEEF Log Field | New UDM Mapping |
|---|---|---|---|---|---|
| System | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| System | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| System | about.labels.key/value additional.fields.key/value.string_value | Object (object) | fname | Filename | target.resource.name |
| System | Description (opaque) | msg | msg | metadata.description | |
| System | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| System | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| Config | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| Config | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| Config | principal.process.command_line | Configuration Path (path) | msg | ConfigurationPath | principal.process.command_line |
| Config | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| Config | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| Config | principal.asset.attribute.labels.key/value | Device Group (dg_id) | PanOSFWDeviceGroup | target.asset.attribute.labels | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Threat/Wildfire | target.file.full_path target.url target.hostname | URL/Filename (misc) | request | Miscellaneous | target.file.names target.url |
| Threat/Wildfire | about.file.sha1/md5/sha256 | File Digest (filedigest) | fileHash | FileDigest | target.file.sha1/md5/sha256 |
| Threat/Wildfire | about.file.mime_type | File Type (filetype) | fileType | FileType | target.file.mime_type |
| Threat/Wildfire | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Threat/Wildfire | principal.user.product_object_id | Source VM UUID (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id |
| Threat/Wildfire | target.user.product_object_id | Destination VM UUID (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | HTTP Headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| Threat/Wildfire | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| Threat/Wildfire | principal.asset.software.version | Source Device OS Version (src_osversion) | PanSrcDeviceOSv | principal.platform_version | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| Threat/Wildfire | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| Threat/Wildfire | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | PanReasonFilteringAction | security_result.summary | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Packets Sent (pkts_sent) | PanOSPacketsSent | srcPackets | network.sent_packets |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Packets Received (pkts_received) | PanOSPacketsReceived | dstPackets | network.received_packets |
| Traffic | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| Traffic | principal.asset.platform_software.platform(enum) principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| Traffic | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| Traffic | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| User-ID | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| User-ID | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| User-ID | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | intermediary.resource.product_object_id |
| User-ID | principal.user.userid principal.administrative_domain principal.user.email_addresses | User by Source (userbysource) | PanOSUserBySource | target.user.userid target.user.email_addresses | |
| User-ID | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| HIP Match | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | HIP (matchname) | cat | HIP | target.resource.attribute.labels |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | HIP Type (matchtype) | Device Event Class ID (Header) | HIPType | target.resource.attribute.labels |
| HIP Match | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| HIP Match | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| HIP Match | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id |
| HIP Match | principal.asset.product_object_id | Host ID (hostid) | PanOSHostID | principal.asset.asset_id | |
| HIP Match | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| IP-Tag | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| IP-Tag | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| IP-Tag | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOsVsysName | vSrcName | target.asset.attribute.labels |
| IP-Tag | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| IP-Tag | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id |
| IP-Tag | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Decryption | target.application | Application (app) | app | network.application_protocol | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | intermediary.asset.attribute.labels | |
| Decryption | principal.asset.asset_id | Source VM UUID (src_uuid) | PanOSSourceUUID | principal.asset.product_object_id | |
| Decryption | target.asset.asset_id | Destination VM UUID (dst_uuid) | PanOSDestinationUUID | target.asset.product_object_id | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanOSContainerID | intermediary.resource.product_object_id | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanOSContainerNameSpace | target.resource.attribute.labels additional.fields.key/value.string_value | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanOSContainerName | target.resource.name | |
| Decryption | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanOSSourceDeviceCategory | principal.asset.category | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanOSSourceDeviceModel | principal.asset.hardware.model | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanOSSourceDeviceVendor | principal.asset.hardware.manufacturer | |
| Decryption | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanOSSourceDeviceOSFamily | principal.platform | |
| Decryption | principal.asset.software.version | Source Device OS Version (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanOSDestinationDeviceCategory | target.asset.category | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanOSDestinationDeviceModel | target.asset.hardware.model | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanOSDestinationDeviceVendor | target.asset.hardware.manufacturer | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanOSDestinationDeviceOSFamily | target.platform | |
| Decryption | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanOSDestinationDeviceOSVersion | target.platform_version | |
| Decryption | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | intermediary.asset.attribute.labels | ||
| Decryption | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Tunnel | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Packets Sent (pkts_sent) | PanOSPacketsSent | srcPackets | network.sent_packets |
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Packets Received (pkts_received) | PanOSPacketsReceived | dstPackets | network.received_packets |
| Tunnel | target.ip | Remote User IP (remote_user_ip) | PanOSRmtUserIP | principal.ip | |
| Tunnel | target.labels.key/value additional.fields.key/value.string_value | Remote User ID (remote_user_id) | PanOSRmtUserID | principal.user.userid | |
| Tunnel | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Authentication | target.user.user_display_name | Normalize User (normalize_user) | cs2 | NormalizeUser | target.user.user_display_name |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Object (object) | fname | ObjectName | target.resource.name |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Authentication Policy (authpolicy) | cs4 | AuthPolicy | additional.fields.key/value.string_value |
| Authentication | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Authentication | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| Authentication | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res _timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanOSSourceDeviceCategory | principal.asset.category | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanOSSourceDeviceModel | principal.asset.hardware.model | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanOSSourceDeviceVendor | principal.asset.hardware.manufacturer | |
| Authentication | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanOSSourceDeviceOSFamily | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | |
| Authentication | principal.asset.software.version | Source Device OS Version (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| URL | target.file.full_path target.url | URL/Filename (misc) | Miscellaneous | target.file.names target.url | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Category (category) | cs2 | URLCategory | security_result.category_details |
| URL | about.file.sha1/md5/sha256 | filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | |
| URL | about.file.mime_type | filetype (filetype) | target.file.mime_type | ||
| URL | about.labels.key/value additional.fields.key/value.string_value | xff (xff) | PanOSXForwarderfor | identSrc | principal.ip |
| URL | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| URL | about.url | file_url (file_url) | target.url | ||
| URL | principal.asset.asset_id | Source VM UUID (src_uuid) | SrcUUID | principal.asset.product_object_id | |
| URL | target.asset.asset_id | Destination VM UUID (dst_uuid) | DstUUID | target.asset.product_object_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | http_headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| URL | about.labels.key/value additional.fields.key/value.string_value | UUID for rule (rule_uuid) | PanOSRuleUUID | security_result.rule_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| URL | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| URL | principal.asset.software.version | Source Device OS Version (src_osversion) | PanSrcDeviceOSv | principal.platform_version | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Hostname (src_host) | PanSrcHostname | principal.hostname | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| URL | target.asset.platform_software.platform target.labels.key/value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| URL | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| URL | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| URL | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Res Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | PanReasonFilteringAction | security_result.summary | |
| Data | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Data | target.file.full_path target.url | URL/Filename (misc) | Miscellaneous | target.file.names target.url | |
| Data | about.labels.key/value additional.fields.key/value.string_value | Category (category) | cs2 | URLCategory | security_result.category_details |
| Data | about.file.sha1/md5/sha256 | filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | |
| Data | about.file.mime_type | filetype (filetype) | target.file.mime_type | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | xff (xff) | principal.ip | ||
| Data | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Data | about.url | file_url (file_url) | target.url | ||
| Data | principal.asset.asset_id | Source VM UUID (src_uuid) | SrcUUID | principal.asset.product_object_id | |
| Data | target.asset.asset_id | Destination VM UUID (dst_uuid) | DstUUID | target.asset.product_object_id | |
| Data | about.labels.key/value additional.fields.key/value.string_value | http_headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| Data | about.labels.key/value additional.fields.key/value.string_value | UUID for rule (rule_uuid) | PanOSRuleUUID | security_result.rule_id | |
| Data | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | network.application_protocol_version | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | principal.asset.category | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | principal.asset.hardware.model | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | principal.asset.hardware.manufacturer | ||
| Data | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | principal.platform | ||
| Data | principal.asset.software.version | Source Device OS Version (src_osversion) | principal.platform_version | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Hostname (src_host) | principal.hostname | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | target.asset.category | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | target.asset.hardware.model | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | target.asset.hardware.manufacturer | ||
| Data | target.asset.platform_software.platform target.labels.key/value | Destination Device OS Family (dst_osfamily) | target.platform | ||
| Data | target.asset.software.version | Destination Device OS Version (dst_osversion) | target.platform_version | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | intermediary.resource.product_object_id | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | target.resource.attribute.labels | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | target.resource.name | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | principal.asset.asset_id | ||
| Data | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Res Timestamp (high_res_timestamp) | additional.fields.key/value.string_value | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | security_result.summary | ||
| GlobalProtect | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | PanOSVirtualSystem | intermediary.asset.attribute.labels | |
| GlobalProtect | principal.user.email_address principal.user.userid principal.administrative_domain | Source User (srcuser) | PanOSSourceUserName | target.user.email_address target.user.userid | |
| GlobalProtect | principal.asset.platform_software.platform(enum) | Client OS (client_os) | PanOSEndpointOSType | principal.platform | |
| GlobalProtect | principal.asset.platform_software.platform_version | Client OS Version (client_os_ver) | PanOSEndpointOSVersion | principal.platform_version | |
| GlobalProtect | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| GlobalProtect | about.labels.key/value additional.fields.key/value.string_value | Gateway Name (gateway) | PanOSAttemptedGateways | target.resource.name | |
| GlobalProtect | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | intermediary.asset.attribute.labels | ||
| GlobalProtect | target.hostname | Device Name (device_name) | intermediary.hostname | ||
| GlobalProtect | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| CORRELATION | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | VirtualSystem | intermediary.asset.attribute.labels | |
| CORRELATION | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | vSrcName | intermediary.asset.attribute.labels | |
| CORRELATION | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | VirtualSystemID | intermediary.resource.product_object_id | |
| GTP | additional.fields.key/value.string_value | Virtual System (vsys) | intermediary.asset.attribute.labels | ||
| GTP | target.ip | Remote User IP (remote_user_ip) | principal.ip | ||
| GTP | additional.fields.key/value.string_value | Remote User ID (remote_user_id) | principal.user.userid | ||
| GTP | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | additional.fields.key/value.string_value |
Palo Alto Networks Firewall Strata Logging Service
Übersicht
Der Palo Alto Networks® Strata Logging Service bietet cloudbasierten, zentralen Protokollspeicher und ‑aggregation für Ihre lokalen, virtuellen (private Cloud und öffentliche Cloud) Firewalls, für Prisma Access und für cloudbasierte Dienste wie Cortex XDR.Der Strata Logging Service ist sicher, robust und fehlertolerant und sorgt dafür, dass Ihre Protokolldaten aktuell und verfügbar sind, wenn Sie sie benötigen. Sie bietet eine skalierbare Logging-Infrastruktur, sodass Sie keine Log Collectors planen und bereitstellen müssen, um Ihre Anforderungen an die Logaufbewahrung zu erfüllen. Wenn Sie bereits lokale Log Collectors haben, kann der neue Strata Logging Service Ihre vorhandene Einrichtung ergänzen. Sie können Ihre vorhandene Infrastruktur für die Protokollerfassung mit dem cloudbasierten Strata Logging Service erweitern, um die Betriebskapazität mit dem Wachstum Ihres Unternehmens zu steigern oder den Kapazitätsbedarf für neue Standorte zu decken.Mit diesem Dienst übernimmt Palo Alto Networks die laufende Wartung und Überwachung der Protokollinfrastruktur, sodass Sie sich auf Ihr Unternehmen konzentrieren können.
Prüfen Sie die Logformate und PAN-OS-Versionen, die vom Strata Logging Service-Parser unterstützt werden. In der folgenden Tabelle sind die Protokollformate und die entsprechenden PAN-OS-Versionen aufgeführt, die vom Strata Logging Service-Parser unterstützt werden:
Log format PAN-OS-Version JSON 12.1 Prüfen Sie die Palo Alto Networks-Firewall-Logtypen, die vom Google SecOps-Parser unterstützt werden. Der Google SecOps-Parser unterstützt die folgenden Palo Alto Networks-Firewall-Logtypen:
- Traffic
- Bedrohung
- Tunnelinspektion
- System
- Übereinstimmung mit dem HIP
- IP-Tag
- User-ID
- Entschlüsselung
- Authentifizierung
- URL-Filter
- GlobalProtect
Bereitstellung des Strata Logging-Dienstes
- Prüfen Sie, ob das Firewallprodukt von Palo Alto Networks richtig bereitgestellt und konfiguriert ist. Eine detaillierte Einrichtungsanleitung finden Sie in der PAN-OS-Dokumentation. Folgen Sie dann dieser Bereitstellungsanleitung, bevor Sie Logs an den Strata Logging Service senden: Voraussetzungen für die Bereitstellung des Strata Logging Service.
Senden von Logs an den Strata Logging Service starten:
So senden Sie Logs an den Strata Logging Service:
- Installieren einer unterstützten PAN‑OS®-Version
- Strata Logging Service aktivieren: Bei der Aktivierung von Strata Logging Service wird das Zertifikat bereitgestellt, das die Firewalls für eine sichere Verbindung zu Strata Logging Service benötigen.
- Firewalls in Strata Logging Service einbinden – mit oder ohne Panorama
Eine ausführliche Anleitung finden Sie in der Dokumentation.
Logs vom Strata Logging Service weiterleiten
Um Ihre Anforderungen an die langfristige Speicherung, Berichterstellung und Überwachung oder an rechtliche und Compliance-Anforderungen zu erfüllen, können Sie den Strata Logging Service so konfigurieren, dass Logs an einen HTTPS-Server oder an die folgenden SIEMs weitergeleitet werden:
- Exabeam
- Google Chronicle
- Microsoft Sentinel
- Splunk HTTP Event Collector (HEC)
Verwenden Sie die HTTPS-Weiterleitungsmethode, um die Logs über den Strata Logging Service weiterzuleiten. Weitere Informationen finden Sie in dieser Dokumentation.
Unterstützte Logformate
Der Firewall-Parser für den Palo Alto Networks Strata Logging Service unterstützt Logs im JSON-Format.
Unterstützte Beispiellogs
JSON
{"source": "Palo Alto Networks FLS LF", "host": "dummy-loghost", "time": "1730265996460", "event": {"TimeReceived": "2024-10-30T05:25:50.000000Z", "DeviceSN": "no-serial", "LogType": "TRAFFIC", "Subtype": "end", "ConfigVersion": "10.2", "TimeGenerated": "2024-10-30T05:25:40.000000Z", "SourceAddress": "198.51.100.6", "DestinationAddress": "198.51.100.6", "NATSource": "", "NATDestination": "", "Rule": "egress-dns-ping-traceroute", "SourceUser": null, "DestinationUser": null, "Application": "dns-base", "VirtualLocation": "vsys1", "FromZone": "VA8280-RN", "ToZone": "inter-fw", "InboundInterface": "tunnel.101", "OutboundInterface": "tunnel.4005", "LogSetting": "Cortex Data Lake", "SessionID": 754194, "RepeatCount": 1, "SourcePort": 53578, "DestinationPort": 53, "NATSourcePort": 0, "NATDestinationPort": 0, "Protocol": "udp", "Action": "allow", "Bytes": 214, "BytesSent": 72, "BytesReceived": 142, "PacketsTotal": 2, "SessionStartTime": "2024-10-30T05:25:10.000000Z", "SessionDuration": 0, "URLCategory": "any", "SequenceNo": 7382192512716388639, "SourceLocation": "198.51.100.6-198.51.255.255", "DestinationLocation": "198.51.100.6-198.51.255.255", "PacketsSent": 1, "PacketsReceived": 1, "SessionEndReason": "aged-out", "DGHierarchyLevel1": 65537, "DGHierarchyLevel2": 65538, "DGHierarchyLevel3": 65541, "DGHierarchyLevel4": 0, "VirtualSystemName": "", "DeviceName": "VA8280-RN", "ActionSource": "from-policy", "SourceUUID": null, "DestinationUUID": null, "IMSI": 0, "IMEI": null, "ParentSessionID": 0, "ParentStarttime": "1970-01-01T00:00:00.000000Z", "Tunnel": "N/A", "EndpointAssociationID": 72057594037927936, "ChunksTotal": 0, "ChunksSent": 0, "ChunksReceived": 0, "RuleUUID": "95cfc3cc-cb00-4758-af1d-de9ab5f07f97", "HTTP2Connection": 0, "LinkChangeCount": 0, "SDWANPolicyName": null, "LinkSwitches": null, "SDWANCluster": null, "SDWANDeviceType": null, "SDWANClusterType": null, "SDWANSite": null, "DynamicUserGroupName": null, "X-Forwarded-ForIP": null, "SourceDeviceCategory": null, "SourceDeviceProfile": null, "SourceDeviceModel": null, "SourceDeviceVendor": null, "SourceDeviceOSFamily": null, "SourceDeviceOSVersion": null, "SourceDeviceHost": null, "SourceDeviceMac": null, "DestinationDeviceCategory": null, "DestinationDeviceProfile": null, "DestinationDeviceModel": null, "DestinationDeviceVendor": null, "DestinationDeviceOSFamily": null, "DestinationDeviceOSVersion": null, "DestinationDeviceHost": null, "DestinationDeviceMac": null, "ContainerID": null, "ContainerNameSpace": null, "ContainerName": null, "SourceEDL": null, "DestinationEDL": null, "GPHostID": null, "EndpointSerialNumber": null, "SourceDynamicAddressGroup": null, "DestinationDynamicAddressGroup": null, "HASessionOwner": null, "TimeGeneratedHighResolution": "2024-10-30T05:25:41.009000Z", "NSSAINetworkSliceType": null, "NSSAINetworkSliceDifferentiator": null}}"
Referenz zur Feldzuordnung: Logfelder zu UDM-Feldern
In diesem Abschnitt wird beschrieben, wie der Parser Firewall-Logfelder des Palo Alto Networks Strata Logging Service für jeden Logtyp Google UDM-Ereignisfeldern zuordnet.
In den folgenden Abschnitten finden Sie eine Zuordnungsreferenz für jeden Logtyp:
- System
- Bedrohung
- Traffic
- Nutzer-ID
- HIP-Abgleich
- IP-Tag
- Entschlüsselung
- Tunnel
- Authentifizierung
- URL
- GlobalProtect
- SCTP
- Prüfung
System
In der folgenden Tabelle sind die Logfelder des Systemlogtyps und die entsprechenden UDM-Felder aufgeführt.
| Log field | UDM mapping |
|---|---|
| AgentContentVersion | additional.fields.key/value.string_value |
| AgentDataCollectionStatus | target.resource.attribute.labels |
| AgentID | target.resource.attribute.labels |
| AgentIsolationStatus | target.resource.attribute.labels |
| AgentStatus | target.resource.attribute.labels |
| AgentVersion | target.asset.software.version |
| ConfigVersion | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DeviceGroup | target.group.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EndpointCPUArchitecture | target.asset.hardware.cpu_platform |
| EndpointDeviceDomain | target.asset.administrative_domain |
| EndpointDeviceName | target.asset.hostname |
| EndpointIPaddress | target.asset.ip |
| VDIEndpoint | target.asset.attribute.labels |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointOSVersion | target.platform_version |
| AgentTimeZoneOffset | additional.fields.key/value.string_value |
| EndpointUserDomain | additional.fields.key/value.string_value |
| EndpointUserName | target.user.user_display_name |
| EndpointUserUUID | target.user.userid |
| EventComponent | additional.fields.key/value.string_value |
| EventDescription | metadata.description |
| EventName | additional.fields.key/value.string_value |
| EventTime | metadata.event_timestamp |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogCategory | security_result.category_details |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| LogSourceID | target.resource.attribute.labels |
| LogSourceName | observer.asset.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| LogTime | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Severity | security_result.severity |
| Subtype | metadata.product_event_type |
| Template | target.resource.attribute.labels |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
Bedrohung
In der folgenden Tabelle sind die Logfelder des Logtyps „Threat“ und die entsprechenden UDM-Felder aufgeführt.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| ApplianceOrCloud | additional.fields.key/value.string_value |
| CloudHostname | additional.fields.key/value.string_value |
| CloudReportID | security_result.detection_fields.key/value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DirectionOfAttack | security_result.detection_fields.key/value |
| DomainEDL | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| FileName | target.file.names |
| FileHash | target.file.sha1 |
| FileType | additional.fields.key/value.string_value |
| FileURL | target.url |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HostID | principal.asset.asset_id |
| HTTP2Connection | network.application_protocol_version |
| HTTPMethod | network.http.method |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| LocalDeepLearningAnalyzed | additional.fields.key/value.string_value |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| PartialHash | additional.fields.key/value.string_value |
| PayloadProtocolID | additional.fields.key/value.string_value |
| Packet | additional.fields.key/value.string_value |
| PacketID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| RecipientEmail | target.user.email_addresses |
| ReportID | security_result.detection_fields.key/value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SenderEmail | principal.user.email_addresses |
| SequenceNo | metadata.product_log_id |
| SessionID | network.session_id |
| Severity | security_result.severity |
| SigFlags | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| EmailSubject | network.email.subject |
| ApplicationTechnology | additional.fields.key/value.string_value |
| ThreatCategory | security_result.detection_fields.key/value.key/value |
| ThreatID | security_result.threat_id |
| ThreatName | security_result.threat_name |
| ThreatNameFirewall | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLDomain | target.domain.name |
| URLCounter | additional.fields.key/value.string_value |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| Verdict | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-ForIP | principal.ip |
Traffic
In der folgenden Tabelle sind die Logfelder des Logtyps „Traffic“ und die entsprechenden UDM-Felder aufgeführt.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| ActionSource | additional.fields.key/value.string_value |
| AIFwdError | additional.fields.key/value.string_value |
| AITraffic | additional.fields.key/value.string_value |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| BytesReceived | network.received_bytes |
| BytesSent | network.sent_bytes |
| Bytes | additional.fields.key/value.string_value |
| ChunksReceived | additional.fields.key/value.string_value |
| ChunksSent | additional.fields.key/value.string_value |
| ChunksTotal | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| EndpointAssociationID | additional.fields.key/value.string_value |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HASessionOwner | additional.fields.key/value.string_value |
| GPHostID | additional.fields.key/value.string_value |
| HTTP2Connection | network.application_protocol_version |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsOffloaded | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| LinkChangeCount | additional.fields.key/value.string_value |
| LinkSwitches | additional.fields.key/value.string_value |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| SDWANPolicyName | additional.fields.key/value.string_value |
| Protocol | network.ip_protocol |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SDWANFECRatio | additional.fields.key/value.string_value |
| SDWANCluster | additional.fields.key/value.string_value |
| SDWANClusterType | additional.fields.key/value.string_value |
| SDWANDeviceType | additional.fields.key/value.string_value |
| SDWANSite | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionStartTime | additional.fields.key/value.string_value |
| SessionTracker | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| SessionDuration | network.session_duration |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLCategory | target.url_metadata.categories |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-ForIP | principal.ip |
User-ID
In der folgenden Tabelle sind die Logfelder des Logtyps „User-ID“ und die entsprechenden UDM-Felder aufgeführt.
| Log field | UDM mapping |
|---|---|
| AuthFactorNo | security_result.detection_fields.key/value |
| AuthenticatedUserDomain | target.user.administrative_domain |
| AuthenticatedUserName | target.user.userid |
| AuthenticatedUserUUID | target.user.product_object_id |
| ConfigVersion | additional.fields.key/value.string_value |
| CountofRepeats | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationPort | target.port |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EventID | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsDuplicateUser | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MappingDataSource | additional.fields.key/value.string_value |
| MappingDataSourceName | additional.fields.key/value.string_value |
| MappingDataSourceType | additional.fields.key/value.string_value |
| MappingTimeout | additional.fields.key/value.string_value |
| MFAFactorType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SourceIP | principal.ip |
| SourcePort | principal.port |
| Subtype | metadata.product_event_type |
| Tag | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| UGFlags | additional.fields.key/value.string_value |
| User | target.user.userid |
| UserGroupFound | additional.fields.key/value.string_value |
| UserIdentifiedBySource | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Übereinstimmung mit dem HIP
In der folgenden Tabelle sind die Logfelder des Logtyps „HIP-Abgleich“ und die entsprechenden UDM-Felder aufgeführt.
| Log field | UDM mapping |
|---|---|
| ConfigVersion | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EndpointDeviceName | principal.asset.hostname |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| HipMatchName | target.resource.attribute.labels |
| HipMatchType | target.resource.attribute.labels |
| HostID | principal.asset.asset_id |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | metadata.product_event_type |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Source | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceIP | principal.ip |
| SourceIPv6 | principal.ip |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| TimestampDeviceIdentification | principal.asset.first_seen_time |
| UUID | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
IP-Tag
In der folgenden Tabelle sind die Logfelder des Logtyps „IP-Tag“ und die entsprechenden UDM-Felder aufgeführt.
| Log field | UDM mapping |
|---|---|
| ConfigVersion | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EventID | additional.fields.key/value.string_value |
| IPSubnetRange | network.ip_subnet_range |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSetting | target.resource.attribute.labels |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MappingDataSource | additional.fields.key/value.string_value |
| MappingDataSourceSubType | additional.fields.key/value.string_value |
| MappingDataSourceType | additional.fields.key/value.string_value |
| MappingTimeout | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| RuleMatched | security_result.rule_name |
| RuleMatchedUUID | security_result.rule_id |
| SequenceNo | metadata.product_log_id |
| SourceIP | principal.ip |
| Subtype | metadata.product_event_type |
| TagName | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
Entschlüsselung
In der folgenden Tabelle sind die Logfelder des Logtyps „Entschlüsselung“ und die entsprechenden UDM-Felder aufgeführt.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| CertificateFlags | additional.fields.key/value.string_value |
| CertificateSerial | network.tls.server.certificate.serial |
| CertificateSize | additional.fields.key/value.string_value |
| CertificateVersion | network.tls.server.certificate.version |
| ChainStatus | additional.fields.key/value.string_value |
| ApplicationCharacteristics | additional.fields.key/value.string_value |
| ClientToFirewall | additional.fields.key/value.string_value |
| CommonName | additional.fields.key/value.string_value |
| CommonNameLength | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| Cpadding | additional.fields.key/value.string_value |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| Domain | target.hostname |
| EllipticCurve | network.tls.curve |
| ErrorIndex | additional.fields.key/value.string_value |
| ErrorMessage | additional.fields.key/value.string_value |
| Fingerprint | network.tls.server.certificate.md5/sha1/sha256 |
| FirewallToClient | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsCertECDSA | additional.fields.key/value.string_value |
| IsCertRSA | additional.fields.key/value.string_value |
| IsCertCNTruncated | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| IsForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsIssuerCNTruncated | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| IsNAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| PacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsResumeSession | additional.fields.key/value.string_value |
| IsRootCNTruncated | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSNITruncated | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| IssuerCommonName | network.tls.server.certificate.issuer |
| IssuerNameLength | additional.fields.key/value.string_value |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| TimeNotAfter | additional.fields.key/value.string_value |
| TimeNotBefore | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| Padding | additional.fields.key/value.string_value |
| Padding3 | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| PolicyName | additional.fields.key/value.string_value |
| Protocol | network.ip_protocol |
| ProxyType | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| RootCommonName | additional.fields.key/value.string_value |
| RootCNLength | additional.fields.key/value.string_value |
| RootStatus | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SessionID | network.session_id |
| ServerNameIndication | network.tls.client.server_name |
| SNILength | additional.fields.key/value.string_value |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeReceivedManagementPlane | additional.fields.key/value.string_value |
| TLSAuth | additional.fields.key/value.string_value |
| TLSEncryptionAlgorithm | additional.fields.key/value.string_value |
| TLSKeyExchange | additional.fields.key/value.string_value |
| TLSVersion | network.tls.version |
| ToZone | additional.fields.key/value.string_value |
| Tpadding | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| Vpadding | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Tunnel
In der folgenden Tabelle sind die Logfelder des Tunnel-Logtyps und die entsprechenden UDM-Felder aufgeführt.
| Log field | UDM mapping |
|---|---|
| AccessPointName | additional.fields.key/value.string_value |
| Action | security_result.action |
| ActionSource | additional.fields.key/value.string_value |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| BytesReceived | network.received_bytes |
| BytesSent | network.sent_bytes |
| Bytes | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| LoggingServiceID | additional.fields.key/value.string_value |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MobileAreaCode | additional.fields.key/value.string_value |
| MobileBaseStationCode | additional.fields.key/value.string_value |
| MobileCountryCode | additional.fields.key/value.string_value |
| MobileIP | additional.fields.key/value.string_value |
| MobileNetworkCode | additional.fields.key/value.string_value |
| MobileSubscriberISDN | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceDifferentiator | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsDroppedMax | additional.fields.key/value.string_value |
| PacketsDroppedStrict | additional.fields.key/value.string_value |
| PacketsDroppedTunnel | additional.fields.key/value.string_value |
| PacketsDroppedProtocol | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| ProtocolDataUnitsessionID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| RadioAccessTechnology | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionStartTime | additional.fields.key/value.string_value |
| SessionTracker | additional.fields.key/value.string_value |
| Severity | security_result.severity |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| StandardPortsOfApp | additional.fields.key/value.string_value |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| SessionDuration | network.session_duration |
| Tunnel | additional.fields.key/value.string_value |
| TunnelCauseCode | additional.fields.key/value.string_value |
| TunnelEndpointID1 | additional.fields.key/value.string_value |
| TunnelEndpointID2 | additional.fields.key/value.string_value |
| TunnelEventCode | additional.fields.key/value.string_value |
| TunnelEventType | additional.fields.key/value.string_value |
| TunnelInspectionRule | additional.fields.key/value.string_value |
| TunnelInterface | additional.fields.key/value.string_value |
| TunnelMessageType | additional.fields.key/value.string_value |
| TunnelRemoteIMSIID | additional.fields.key/value.string_value |
| TunnelRemoteUserIP | principal.ip |
| TunnelSessionsClosed | additional.fields.key/value.string_value |
| TunnelSessionsCreated | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLCategory | target.url_metadata.categories |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Authentifizierung
In der folgenden Tabelle sind die Logfelder des Logtyps „Authentifizierung“ und die entsprechenden UDM-Felder aufgeführt.
| Log field | UDM mapping |
|---|---|
| AuthenticationDescription | security_result.description |
| AuthEvent | metadata.description |
| AuthFactorNo | security_result.detection_fields.key/value |
| AuthenticationPolicy | security_result.detection_fields.key/value |
| AuthenticationProtocol | additional.fields.key/value.string_value |
| AuthServerProfile | additional.fields.key/value.string_value |
| AuthenticatedUserDomain | target.administrative_domain |
| AuthenticatedUserName | target.user.userid |
| AuthenticatedUserUUID | target.user.product_object_id |
| ClientType | additional.fields.key/value.string_value |
| ClientTypeName | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| Location | target.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogType | additional.fields.key/value.string_value |
| MFAAuthenticationID | additional.fields.key/value.string_value |
| MFAVendor | additional.fields.key/value.string_value |
| NormalizeUser | target.user.user_display_name |
| Object | target.resource.name |
| RuleMatched | security_result.rule_name |
| RuleMatchedUUID | security_result.rule_id |
| AuthCacheServiceRegion | additional.fields.key/value.string_value |
| SessionID | network.session_id |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceIP | principal.ip |
| TimeGenerated | metadata.event_timestamp |
| User | target.user.userid |
| UserAgentString | network.http.user_agent |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Subtype | metadata.product_event_type |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
URL
In der folgenden Tabelle sind die Logfelder des URL-Logtyps und die entsprechenden UDM-Felder aufgeführt.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| CloudHostname | additional.fields.key/value.string_value |
| CloudReportID | security_result.detection_fields.key/value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentType | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DirectionOfAttack | security_result.detection_fields.key/value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| FileURL | target.url |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HostID | principal.asset.asset_id |
| HTTP2Connection | network.application_protocol_version |
| HTTPHeaders | additional.fields.key/value.string_value |
| HTTPMethod | network.http.method |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| InlineMLVerdict | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| Packet | additional.fields.key/value.string_value |
| PacketID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| Referer | network.http.referral_url |
| HTTPRefererFQDN | additional.fields.key/value.string_value |
| HTTPRefererPort | additional.fields.key/value.string_value |
| HTTPRefererProtocol | additional.fields.key/value.string_value |
| HTTPRefererURLPath | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionID | network.session_id |
| Severity | security_result.severity |
| SigFlags | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URL | target.url_metadata.URL |
| URLCategory | target.url_metadata.categories |
| URLCategoryList | additional.fields.key/value.string_value |
| URLDomain | target.domain.name |
| URLCounter | additional.fields.key/value.string_value |
| UserAgent | network.http.user_agent |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-For | additional.fields.key/value.string_value |
| X-Forwarded-ForIP | principal.ip |
GlobalProtect
In der folgenden Tabelle sind die Logfelder des GlobalProtect-Logtyps und die entsprechenden UDM-Felder aufgeführt.
| Log field | UDM mapping |
|---|---|
| AttemptedGateways | additional.fields.key/value.string_value |
| AuthMethod | extensions.auth.auth_details |
| ConnectionMethod | additional.fields.key/value.string_value |
| ConnectionErrorID | additional.fields.key/value.string_value |
| ConnectionError | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| EndpointDeviceName | principal.asset.hostname |
| GlobalProtectClientVersion | additional.fields.key/value.string_value |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointSN | principal.asset.hardware.serial_number |
| EventIDValue | additional.fields.key/value.string_value |
| Gateway | target.resource.name |
| GatewayPriority | additional.fields.key/value.string_value |
| GatewaySelectionType | additional.fields.key/value.string_value |
| GlobalProtectGatewayLocation | target.location.country_or_region |
| HostID | principal.asset.asset_id |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LoginDuration | network.session_duration |
| Description | security_result.description |
| Portal | target.hostname |
| PrivateIPv4 | principal.ip |
| PrivateIPv6 | principal.ip |
| ProjectName | additional.fields.key/value.string_value |
| PublicIPv4 | principal.nat_ip |
| PublicIPv6 | principal.nat_ip |
| QuarantineReason | security_result.summary |
| SequenceNo | metadata.product_log_id |
| SourceRegion | principal.location.country_or_region |
| SourceUserName | principal.user.user_display_name |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SSLResponseTime | additional.fields.key/value.string_value |
| Stage | additional.fields.key/value.string_value |
| EventStatus | additional.fields.key/value.string_value |
| LogSubtype | metadata.product_event_type |
| TunnelType | additional.fields.key/value.string_value |
| VirtualSystem | intermediary.asset.attribute.labels |
| VirtualSystemName | intermediary.asset.attribute.labels |
| EndpointOSVersion | principal.platform_version |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | metadata.product_event_type |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualSystemID | intermediary.resource.product_object_id |
SCTP
In der folgenden Tabelle sind die Logfelder des SCTP-Logtyps und die entsprechenden UDM-Felder aufgeführt.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| AssocationEndReason | additional.fields.key/value.string_value |
| ChunksReceived | additional.fields.key/value.string_value |
| ChunksSent | additional.fields.key/value.string_value |
| ChunksTotal | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceClass | target.asset.category |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationIP | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DiamAppID | additional.fields.key/value.string_value |
| DiamAvpCode | additional.fields.key/value.string_value |
| DiameterCommandCode | additional.fields.key/value.string_value |
| DiameterRequestFlag | additional.fields.key/value.string_value |
| DeviceName | principal.asset.hostname |
| SCTPEventType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLFiltering | additional.fields.key/value.string_value |
| IsWildfire | additional.fields.key/value.string_value |
| LogAction | additional.fields.key/value.string_value |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MapAppCode | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PayloadProtocolID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SccpCallingGt | additional.fields.key/value.string_value |
| SccpCallingSSN | additional.fields.key/value.string_value |
| SctpCauseCode | additional.fields.key/value.string_value |
| SctpChunkType | additional.fields.key/value.string_value |
| SctpFilter | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionTracker | additional.fields.key/value.string_value |
| Severity | security_result.severity |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceIP | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VerificationTag1 | additional.fields.key/value.string_value |
| VerificationTag2 | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Audit
In der folgenden Tabelle sind die Logfelder des Audit-Logtyps und die entsprechenden UDM-Felder aufgeführt.
| Log field | UDM mapping |
|---|---|
| EventCategory | network.http.method |
| EventDescription | metadata.description |
| EventDestinationURL | target.url |
| EventDestinationUserUserID | target.user.userid |
| DestinationVendor | additional.fields.key/value.string_value |
| EventDetails | additional.fields.key/value.string_value |
| EventID | metadata.product_log_id |
| EventName | additional.fields.key/value.string_value |
| EventResult | security_result.summary |
| EventSourceUserUserID | principal.user.userid |
| EventTime | metadata.event_timestamp |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| Subtype | metadata.product_event_type |
| TSGID | additional.fields.key/value.string_value |
| Vendor | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
Feldzuordnung – Referenz: Protokolltypen zu UDM-Ereignistyp
In der folgenden Tabelle sind die Firewall-Logtypen von Palo Alto Networks Strata Logging Service und die entsprechenden UDM-Ereignistypen aufgeführt.
| Logtyp | UDM-Ereignistyp |
| Traffic | NETWORK_CONNECTION |
| Bedrohung | NETWORK_CONNECTION |
| URL-Filter | NETWORK_CONNECTION |
| Tunnel | NETWORK_CONNECTION |
| System |
Wenn der Untertypwert „dhcp“ ist, wird NETWORK_DHCP festgelegt. Wenn der Untertypwert „auth“ ist, wird USER_LOGIN festgelegt. Wenn der Wert für „description“ „logged in“ lautet, wird USER_LOGIN festgelegt. Wenn der Wert der Beschreibung „logged out“ lautet, wird USER_LOGOUT festgelegt. Für andere Werte des Subtyps wird GENERIC_EVENT festgelegt. |
| HIP-Abgleich | NETWORK_CONNECTION |
| IP-Tag | GENERIC_EVENT |
| User-ID | USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED
Wenn der Untertypwert „login“ ist, wird USER_LOGIN festgelegt. Wenn der Untertypwert „logout“ ist, wird USER_LOGOUT festgelegt. Wenn der Untertyp keinen Wert enthält, wird USER_UNCATEGORIZED festgelegt. |
| Entschlüsselung | NETWORK_CONNECTION |
| Authentifizierung | STATUS_UNCATEGORIZED |
| Globalprotect | USER_LOGIN/USER_LOGOUT/USER_RESOURCE_ACCESS
Wenn der Untertypwert „auth“ ist, wird USER_LOGIN festgelegt. Wenn der Untertypwert „logout“ ist, wird USER_LOGOUT festgelegt. Wenn der Untertyp keinen Wert enthält, wird USER_RESOURCE_ACCESS festgelegt. |
| SCTP | NETWORK_CONNECTION |
| Audit | NETWORK_CONNECTION |
Nächste Schritte
Benötigen Sie weitere Hilfe? Antworten von Community-Mitgliedern und Google SecOps-Experten erhalten