Palo Alto Networks-Firewallprotokolle erfassen

Unterstützt in:

Palo Alto Networks-Firewall

Übersicht

In diesem Dokument wird beschrieben, wie Sie Syslog und einen Google SecOps-Forwarder konfigurieren, um Firewall-Logs von Palo Alto Networks zu erfassen. In diesem Dokument wird auch erläutert, wie Palo Alto Networks-Firewall-Logfelder den Feldern des Google SecOps Unified Data Model (UDM) zugeordnet werden. Eine Übersicht über die Datenaufnahme in Google SecOps finden Sie unter Datenaufnahme in Google SecOps. Ein Erfassungslabel identifiziert den Parser, der Logrohdaten in das strukturierte UDM-Format normalisiert. Die Informationen in diesem Dokument beziehen sich auf den Parser mit dem Aufnahme-Label „PAN_FIREWALL“.

Hinweise

  • Prüfen Sie, ob das Firewallprodukt von Palo Alto Networks richtig bereitgestellt und konfiguriert ist. Eine ausführliche Einrichtungsanleitung finden Sie in der PAN-OS-Dokumentation.
  • Sehen Sie sich die Bereitstellungsarchitektur an, um die Komponenten zu verstehen, die zum Erfassen von Palo Alto Networks-Firewall-Logs bereitgestellt werden. Die Bereitstellung bei jedem Kunden kann von dieser Darstellung abweichen und komplexer sein. Das folgende Diagramm zeigt, wie Sie Syslog auf einer Palo Alto Networks-Firewall konfigurieren und einen Google SecOps-Forwarder auf einem Linux-Server installieren, um Protokolldaten an Google SecOps weiterzuleiten. Der Parser unterstützt Protokolle in den folgenden Datenformaten: Comma Separated Values (CSV), Common Event Format (CEF) und Log Event Extended Format (LEEF).

    Bereitstellungsarchitektur

  • Prüfen Sie die Logformate und PAN-OS-Versionen, die vom Google SecOps-Parser unterstützt werden. In der folgenden Tabelle sind die Logformate und die entsprechenden PAN-OS-Versionen aufgeführt, die vom Google SecOps-Parser unterstützt werden:

    Log format PAN-OS-Version
    CSV 10.1.3
    CEF 10.0.0
    LEEF 9.1.0
  • Prüfen Sie die Palo Alto Networks-Firewall-Logtypen, die vom Google SecOps-Parser unterstützt werden. Der Google SecOps-Parser unterstützt die folgenden Palo Alto Networks-Firewall-Logtypen:

    • Traffic
    • Bedrohung
    • WildFire-Einreichungen
    • Tunnelinspektion
    • Konfiguration
    • System
    • Übereinstimmung mit dem HIP
    • IP-Tag
    • User-ID
    • Entschlüsselung
    • Authentifizierung
    • URL-Filter
    • Datenfilterung
    • GlobalProtect
    • Ergebnisse in Beziehung setzen
    • GTP
    • SCTP
    • Audit

    Weitere Informationen zu den Palo Alto Networks-Firewall-Logtypen finden Sie unter PAN-OS-Logtypen.

  • Achten Sie darauf, dass alle Systeme in der Bereitstellungsarchitektur in der UTC-Zeitzone konfiguriert sind.

  • Bevor Sie den Palo Alto Networks-Firewallparser verwenden, sollten Sie sich die Änderungen bei den Feldzuordnungen zwischen dem vorherigen Parser und dem aktuellen Palo Alto Networks-Firewallparser ansehen. Achten Sie im Rahmen der Migration darauf, dass für Regeln, Suchvorgänge, Dashboards oder andere Prozesse, die von den ursprünglichen Feldern abhängen, die aktualisierten Felder verwendet werden.

    In der vorherigen Parserversion wird das Logfeld category beispielsweise dem UDM-Feld security_result.description zugeordnet. Im aktuellen Palo Alto Networks-Firewall-Parser wird das Logfeld category dem UDM-Feld security_result.category_details zugeordnet. Wenn Sie zur aktuellen Palo Alto Networks-Firewall migrieren und das Feld category in Ihren Regeln verwenden, müssen Sie die Regeln so ändern, dass das UDM-Feld security_result.category_details des aktuellen Parsers verwendet wird.

Syslog und den Google Security Operations-Forwarder konfigurieren

Führen Sie die folgenden Schritte aus, um Syslog und den Google SecOps-Forwarder zu konfigurieren:

  1. Konfigurieren Sie das Syslog-Serverprofil, um CSV-Logs zu überwachen. Weitere Informationen finden Sie unter Syslog-Serverprofil konfigurieren. Wenn Sie das Syslog-Serverprofil konfigurieren, geben Sie „Default“ als benutzerdefiniertes Logformat an.
  2. Wenn Sie CEF-Logs überwachen möchten, konfigurieren Sie die Palo Alto Networks-Firewall so, dass CEF-Logs weitergeleitet werden. Weitere Informationen finden Sie im PAN-OS CEF Integration Guide (PDF) im Abschnitt „Configuration of Palo Alto Networks NGFW to output CEF events“.
  3. Konfigurieren Sie das Syslog-Serverprofil, um LEEF-Logs zu überwachen. Weitere Informationen finden Sie unter Benutzerdefinierte Logweiterleitung im LEEF-Format.
  4. Konfigurieren Sie den Google SecOps-Forwarder so, dass Logs an Google Security Operations gesendet werden. Weitere Informationen finden Sie unter Forwarder unter Linux installieren und konfigurieren. Das folgende Beispiel zeigt eine Google SecOps-Forwarder-Konfiguration:

      - syslog:
          common:
            enabled: true
            data_type: PAN_FIREWALL
            batch_n_seconds: 10
            batch_n_bytes: 1048576
          tcp_address: 0.0.0.0:10518
          connection_timeout_sec: 60
    

Syslog-Weiterleitung auf PAN Firewall konfigurieren

Syslog-Serverprofil erstellen

  1. Melden Sie sich in der Palo Alto Networks Firewall Management Console an.
  2. Gehen Sie zu Gerät > Serverprofile > Syslog.
  3. Klicken Sie auf Hinzufügen, um ein neues Serverprofil zu erstellen.
  4. Geben Sie die folgenden Konfigurationsdetails an:
    • Name: Geben Sie einen aussagekräftigen Namen ein, z. B. Google SecOps BindPlane.
    • Standort: Wählen Sie das virtuelle System (vsys) oder Shared (Freigegeben) aus, in dem dieses Profil verfügbar sein soll.
  5. Klicken Sie auf Servers > Add, um den Syslog-Server zu konfigurieren.
  6. Geben Sie die folgenden Details zur Serverkonfiguration an:
    • Name: Geben Sie einen aussagekräftigen Namen für den Server ein, z. B. BindPlane Agent.
    • Syslog-Server: Geben Sie die IP-Adresse des BindPlane-Agents ein.
    • Transport: Wählen Sie je nach BindPlane-Agent-Konfiguration UDP oder TCP aus (UDP ist die Standardeinstellung).
    • Port: Geben Sie die Portnummer des BindPlane-Agents ein (z. B. 514).
    • Format: Wählen Sie je nach Bedarf BSD (Standard) oder IETF aus.
    • Einrichtung: Wählen Sie LOG_USER (Standard) oder eine andere Einrichtung aus.
  7. Klicken Sie auf OK, um das Syslog-Serverprofil zu speichern.

Optional: Benutzerdefiniertes Logformat für CEF oder LEEF konfigurieren

Wenn Sie anstelle von CSV-Dateien CEF- (Common Event Format) oder LEEF-Logs (Log Event Extended Format) benötigen:

  1. Wählen Sie im Syslog-Serverprofil den Tab Benutzerdefiniertes Logformat aus.
  2. Konfigurieren Sie das benutzerdefinierte Logformat für jeden Logtyp (Konfiguration, System, Bedrohung, Traffic, URL, Daten, WildFire, Tunnel, Authentifizierung, User-ID, HIP Match).
  3. Informationen zur Konfiguration des CEF-Formats finden Sie im Palo Alto Networks CEF Configuration Guide.
  4. Klicken Sie auf OK, um die Konfiguration zu speichern.

Profil für die Logweiterleitung erstellen

  1. Rufen Sie Objekte > Log-Weiterleitung auf.
  2. Klicken Sie auf Hinzufügen, um ein neues Profil für die Protokollweiterleitung zu erstellen.
  3. Geben Sie die folgenden Konfigurationsdetails an:
    • Name: Geben Sie einen Profilnamen ein, z. B. Google SecOps Forwarding. Wenn die Firewall dieses Profil automatisch neuen Sicherheitsregeln und Zonen zuweisen soll, nennen Sie es default.
  4. Konfigurieren Sie für jeden Logtyp, den Sie weiterleiten möchten (Traffic, Threat, WildFire Submission, URL Filtering, Data Filtering, Tunnel, Authentication), Folgendes:
    • Klicken Sie im entsprechenden Protokolltyp-Abschnitt auf Hinzufügen.
    • Syslog: Wählen Sie das von Ihnen erstellte Syslog-Serverprofil aus (z. B. Google SecOps BindPlane).
    • Logschweregrad: Wählen Sie die Schweregrade aus, die weitergeleitet werden sollen, z. B. Alle.
  5. Klicken Sie auf OK, um das Profil für die Protokollweiterleitung zu speichern.

Logweiterleitungsprofil auf Sicherheitsrichtlinien anwenden

  1. Rufen Sie Richtlinien > Sicherheit auf.
  2. Wählen Sie die Sicherheitsregeln aus, für die Sie die Logweiterleitung aktivieren möchten.
  3. Klicken Sie auf die Regel, um sie zu bearbeiten.
  4. Rufen Sie den Tab Aktionen auf.
  5. Wählen Sie im Menü Log Forwarding (Log-Weiterleitung) das von Ihnen erstellte Profil für die Log-Weiterleitung aus (z. B. Google SecOps Forwarding).
  6. Klicken Sie auf OK, um die Konfiguration der Sicherheitsrichtlinie zu speichern.

Logeinstellungen für Systemlogs konfigurieren

  1. Gehen Sie zu Gerät > Protokolleinstellungen.
  2. Wählen Sie für jeden Logtyp (System, Konfiguration, Nutzer-ID, HIP-Abgleich, GlobalProtect, IP-Tag, SCTP) und jede Schweregradstufe das von Ihnen erstellte Syslog-Serverprofil aus.
  3. Klicken Sie auf OK, um die Protokolleinstellungen zu speichern.

Änderungen per Commit durchführen

  1. Klicken Sie oben in der Web-Oberfläche der Firewall auf Commit.
  2. Warten Sie, bis der Commit erfolgreich abgeschlossen ist.
  3. Prüfen Sie in der Google SecOps Console, ob Palo Alto Networks-Firewall-Logs eingehen, um zu bestätigen, dass Logs an den Bindplane-Agent gesendet werden.

Logs mit dem BindPlane-Agent an Google SecOps weiterleiten

  1. Installieren und richten Sie eine virtuelle Linux-Maschine ein.
  2. BindPlane-Agent unter Linux installieren und konfigurieren, um Logs an Google SecOps weiterzuleiten Weitere Informationen zur Installation und Konfiguration des Bindplane-Agents finden Sie in der Anleitung zur Installation und Konfiguration des Bindplane-Agents.

Wenn beim Erstellen von Feeds Probleme auftreten, wenden Sie sich an den Google SecOps-Support.

Unterstützte Logformate

Der Palo Alto Networks-Firewall-Parser unterstützt Logs im LEEF-, CEF- und CSV-Format.

Unterstützte Beispiellogs

  • LEEF

    <14>Jan 22 02:20:19 device_host LEEF:1.0|Palo Alto Networks|PAN-OS Syslog Integration|10.2.12-h4|Microsoft MSOFFICE(52033)|ReceiveTime=2025/01/22 02:20:18|SerialNumber=01250100xxxx|cat=THREAT|Subtype=wildfire|devTime=Jan 22 2025 08:20:18 GMT|src=198.50.100.1|dst=198.50.100.2|srcPostNAT=198.50.100.3|dstPostNAT=198.50.100.4|RuleName=AZURE-US-NEW-CNF_Inbound_To_Azure-ALLOW|usrName=|SourceUser=|DestinationUser=|Application=smtp-base|VirtualSystem=vsys1|SourceZone=McD-Global-Zone|DestinationZone=Azure-Zone|IngressInterface=ae1.111|EgressInterface=ae2.409|LogForwardingProfile=Default-Traffic-Logging|SessionID=35331795|RepeatCount=1|srcPort=21578|dstPort=25|srcPostNATPort=0|dstPostNATPort=0|Flags=0x2000|proto=tcp|action=allow|Miscellaneous=\"......3...................xls\"|ThreatID=Microsoft MSOFFICE(52033)|URLCategory=malicious|sev=4|Severity=high|Direction=client-to-server|sequence=7462614601465681755|ActionFlags=0x8000000000000000|SourceLocation=198.50.100.1-198.50.100.255|DestinationLocation=United States|ContentType=|PCAP_ID=0|FileDigest=0ea04c99bf188c2e4207f60f92ca7c6f5088c7943ee63f45c50032bbd2bf7ea9|Cloud=demo.com|URLIndex=1|RequestMethod=|FileType=ms-office|Sender=sender@ab.myownpersonaldomain.com|Subject=\"............:.................................................................................-.........(Name)-2025-01-22...............:Y107202501220005, ............:........................, ...............:.........\"|Recipient=abc@demo.myownpersonaldomain.com|ReportID=117022282776|DeviceGroupHierarchyL1=143|DeviceGroupHierarchyL2=144|DeviceGroupHierarchyL3=39|DeviceGroupHierarchyL4=0|vSrcName=|DeviceName=device_host|SrcUUID=|DstUUID=|TunnelID=0|MonitorTag=|ParentSessionID=0|ParentStartTime=|TunnelType=N/A|ThreatCategory=N/A|ContentVer=WildFire-0
    
  • CEF

    14>1 2024-04-04T16:21:56+02:00 FW-PERIMETRAL-AVG-01 - - - - CEF:0|Palo Alto Networks|PAN-OS|10.1.10-h2|end|TRAFFIC|1|src=198.51.100.1 dst=198.51.100.2 srcTranslatedAddress=198.51.100.3 dstTranslatedAddress=198.51.100.4 rule=FW_USER_NATS2_APP suser= duser= app=bittorrent vs=vsys1 sz=INSIDE dz=EXTERNAL InboundInterface=ae2.2266 OutboundInterface=ae1 lp=log_forwarding sid=2935823 cnt=1 spt=6881 dpt=51413 srcTranslatedPort=0 dstTranslatedPort=0 flags=0x7a proto=udp act=allow tbytes=475 in=150 out=325 pkt=2 pktReceived=1 pktSent=1 start=Apr 04 2024 14:21:56 GMT stime=1206 urlcat=any externalId=externalId reason=aged-out DGl1=11 DGl2=161 DGl3=0 DGl4=0 VsysName=STONESOFT dvchost=FW-PERIMETRAL-AVG-01 cat=from-policy ActionFlags=0x8000000000000000 srcUUID= dstUUID= TunnelID=0 MonitorTag= ParentSessionID=0 ParentStartTime= TunnelType=N/A SCTPAssocID=0 SCTPChunks=0 SCTPChunkSent=0 SCTPChunksRcv=0 RuleUUID=746c3eb6-3d51-4679-8438-bd0e00e170a8 HTTP2Con=0 LinkChange=0 PolicyID= LinkDetail= SDWANCluster= SDWANDevice= SDWANClustype= SDWANSite= DynamicUsrgrp= XFFIP= srcDevCat= srcDevProf= srcDevModel= srcDevVendor= srcDevOS= srcDevOSv= srcHostname= srcMac= dstDevCat= dstDevProf= dstDevModel= dstDevVendor= dstDevOS= dstDevOSv= dstHostname= dstMac= ContainerName= PODNamespace= PODName= srcEDL= dstEDL= GPHostID= EPSerial= srcDAG= dstDAG= HASessionOwner= TimeHighRes=2024-04-04T16:21:56.250+02:00 ASServiceType= ASServiceDiff="
    
  • CSV

    1,2021/10/24 15:30:07,,CONFIG,0,2561,2021/10/24 15:30:07,198.51.100.0,,set,admin,Web,Succeeded, network virtual-router  VR1,,VR1  { ecmp { algorithm { ip-modulo ; } } protocol { bgp { routing-options { graceful-restart { enable yes; } } enable no; } rip { enable no; } ospf { enable no; } ospfv3 { enable no; } } routing-table { ip { static-route { vr1-log  { path-monitor { enable no; failure-condition any; hold-time 2; } nexthop { ip-address 198.51.100.0; } bfd { profile None; } interface ethernet1/1; metric 10; destination 0.0.0.0/0; route-table { unicast ; } } } } } interface [ ethernet1/1 ethernet1/2 ]; } ,7022390503849066572,0x0,0,0,0,0,,PA-VM,0,
    

Referenz zur Feldzuordnung: Logfelder zu UDM-Feldern

In diesem Abschnitt wird beschrieben, wie der Parser Palo Alto Networks-Firewall-Logfelder für jeden Logtyp Google SecOps UDM-Ereignisfeldern zuordnet. Der Google SecOps-Labelschlüssel bezieht sich auf den Namen des Schlüssels, der dem UDM-Feld „Labels.key“ zugeordnet ist.

Beispiel: Für das Feld „Virtual System“ ist der Feldname im CEF-Format „cs3“ und im LEEF-Format „VirtualSystem“. Das UDM-Feld „about.labels.key“ enthält den Wert „vsys“ und das UDM-Feld „about.labels.value“ enthält den Wert dieses Felds. Einige CEF- oder LEEF-Feldnamen haben keinen Namen, der den CSV-Feldnamen entspricht. Wenn Sie in solchen Fällen einen eigenen Variablennamen im benutzerdefinierten Logformat im Syslog-Profil hinzufügen, wird er vom Parser nicht dem UDM-Feld zugeordnet.

In den folgenden Abschnitten finden Sie eine Zuordnungsreferenz für jeden Logtyp:

System

In der folgenden Tabelle sind die Logfelder des Systemlogtyps und die entsprechenden UDM-Felder aufgeführt.

CSV-Feld CEF-Feld LEEF-Feld Schlüssel für Google Security Operations-Label UDM-Feld
Empfangszeit (receive_time oder cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist)

Seriennummer (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Typ (type) Typ (Header) cat metadata.product_event_type ist auf „%{type} – %{subtype}“ festgelegt.
Bedrohungs-/Inhaltstyp (Untertyp) Untertyp (Kopfzeile) Subtyp metadata.product_event_type ist auf „%{type} – %{subtype}“ festgelegt.
Generierte Zeit (time_generated oder cef-formatted-time_generated) metadata.event_timestamp
Virtuelles System (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
Ereignis-ID (eventid) cat eventid additional.fields.key und additional.fields.value.string_value
Objekt (Objekt) fname Dateiname Objekt target.resource.name
Modul (module) flexString2 Modul module additional.fields.key und additional.fields.value.string_value
Schweregrad (severity) $number-of-severity(header) Schweregrad security_result.severity und security_result.severity_details
Beschreibung (undurchsichtig) msg msg metadata.description
principal_user_userid (Dieses Feld wird aus dem Feld „msg“ extrahiert.) principal.user.userid
principal_ip3 (Dieses Feld wird aus dem Feld „msg“ extrahiert.) principal.ip
Grund (Dieses Feld wird aus dem Feld „msg“ extrahiert.) security_result.description
server_address (Dieses Feld wird aus dem Feld „msg“ extrahiert.) target.ip
server_profile (Dieses Feld wird aus dem Feld „msg“ extrahiert.) additional.fields.key und additional.fields.value.string_value
Sequenznummer (seqno) externalId Sequenz metadata.product_log_id
Aktions-Flags (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_1 bis dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key und additional.fields.value.string_value
Hierarchie der Gerätegruppen (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key und additional.fields.value.string_value
Name des virtuellen Systems (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
Gerätename (device_name) dvchost DeviceName target.hostname
Zeitstempel mit hoher Auflösung (high_res_timestamp) anOSTimeGeneratedHighResolution additional.fields.key und additional.fields.value.string_value

Konfiguration

In der folgenden Tabelle sind die Logfelder des Konfigurationslogtyps und die entsprechenden UDM-Felder aufgeführt.

CSV-Feld CEF-Feld LEEF-Feld Schlüssel für Google Security Operations-Label UDM-Feld
Empfangszeit (receive_time oder cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist)

Seriennummer (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Typ (type) Typ (Header) cat metadata.product_event_type
Bedrohungs-/Inhaltstyp (Untertyp) Untertyp (Kopfzeile) metadata.product_event_type
Generierte Zeit (time_generated oder cef-formatted-time_generated) metadata.event_timestamp
Host (host) shost src principal.ip/hostname
Virtuelles System (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
Befehl (cmd) Handeln msg CMD principal.process.command_line
Administrator (admin) duser usrName principal.user.userid
Client (client) destinationServiceName Client principal.application
Ergebnis (result) Signatur-ID (Header)(reason) Ergebnis security_result.summary
Konfigurationspfad (path) msg ConfigurationPath principal.process.command_line
Before Change Detail (before_change_detail) cs1 BeforeChangeDetail before_change_detail target.resource.attribute.labels.key/value
After Change Detail (after_change_detail) cs2 AfterChangeDetail after_change_detail target.resource.attribute.labels.key/value
Sequenznummer (seqno) externalId Sequenz metadata.product_log_id
Aktions-Flags (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_1 bis dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key und additional.fields.value.string_value
Hierarchie der Gerätegruppen (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key und additional.fields.value.string_value
Name des virtuellen Systems (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
Gerätename (device_name) dvchost DeviceName target.hostname
Gerätegruppe (dg_id) PanOSFWDeviceGroup target.asset.attribute.labels.key/value dg_id principal.asset.attribute.labels.key/value
Audit-Kommentar (comment) PanOSPolicyAuditComment Kommentar additional.fields.key und additional.fields.value.string_value
Zeitstempel mit hoher Auflösung (high_res_timestamp) additional.fields.key und additional.fields.value.string_value
Schweregrad (severity) number-of-severity(header) security_result.severity und security_result.severity_details

Threat/WildFire

In der folgenden Tabelle sind die Logfelder des Logtyps „Threat/WildFire“ und die entsprechenden UDM-Felder aufgeführt.

CSV-Feld CEF-Feld LEEF-Feld Schlüssel für Google Security Operations-Label UDM-Feld
Empfangszeit (receive_time oder cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist)

Seriennummer deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Typ (type) Typ (Header) cat metadata.product_event_type
Bedrohungs-/Inhaltstyp (Untertyp) cat/subtype (Header) Subtyp metadata.product_event_type
Generierungszeit (time_generated oder cef-formatted-time_generated) metadata.event_timestamp
Quelladresse (src) src src principal.ip
Zieladresse (dst) dst dst target.ip
NAT-Quell-IP-Adresse (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
NAT-Ziel-IP-Adresse (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Regelname (rule) cs1 RuleName security_result.rule_name
Quellnutzer (srcuser) suser SourceUser / usrName principal.user.userid
Zielnutzer (dstuser) duser DestinationUser target.user.userid
Anwendung (App) App Anwendung target.application
Virtuelles System (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Quellzone (von) cs4 SourceZone von

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Zielzone (bis) cs5 DestinationZone bis

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Eingangsschnittstelle (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Ausgangsschnittstelle (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Aktion protokollieren (Logset) cs6 LogForwardingProfile logset additional.fields.key und additional.fields.value.string_value
Sitzungs-ID (sessionid) cn1 SessionID network.session_id
Anzahl der Wiederholungen (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key und additional.fields.value.string_value
Quellport (sport) spt srcPort principal.port
Zielport (dport) dpt dstPort target.port
NAT-Quellport (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
NAT-Zielport (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Flags (flags) flexString1 Flags flags additional.fields.key und additional.fields.value.string_value
IP-Protokoll (proto) Proto Proto network.ip_protocol
Aktion (action) Handeln Aktion security_result.action_details

security_result.action

URL/Dateiname (Sonstiges) Anfrage Sonstiges

target.file.names (wenn der Untertyp „file“, „virus“, „wildfire-virus“ oder „wildfire“ ist, wird das Feld „misc“ target.file.names zugeordnet)

target.url (wenn der Untertyp „url“ ist, wird das Feld „misc“ target.url und target.hostname zugeordnet)

Name der Bedrohung/des Inhalts (threatid) cat ThreatID security_result.threat_name
Kategorie (category) cs2 URLCategory security_result.category_details
Schweregrad (severity) number-of-severity(header) Schweregrad security_result.severity und security_result.severity_details
Richtung (direction) flexString2 Richtung network.direction
Sequenznummer (seqno) externalId Sequenz metadata.product_log_id
Aktions-Flags (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key und additional.fields.value.string_value
Quellland (srcloc) SourceLocation principal.location.country_or_region
Zielland (dstloc) DestinationLocation target.location.country_or_region
Inhaltstyp (contenttype) ContentType contenttype additional.fields.key und additional.fields.value.string_value
PCAP-ID (pcap_id) fileId PCAP_ID pcap_id additional.fields.key und additional.fields.value.string_value
File Digest (filedigest) fileHash FileDigest target.file.sha1/md5/sha256
Cloud (cloud) filePath Cloud Cloud additional.fields.key und additional.fields.value.string_value
URL-Index (url_idx) URLIndex url_idx additional.fields.key und additional.fields.value.string_value
User-Agent (user_agent) network.http.user_agent
Dateityp (filetype) fileType FileType target.file.mime_type
X-Forwarded-For (xff) principal.ip
Referrer (referer) network.http.referral_url
Absender (sender) suid Absender network.email.from
Betreff (Subjekt) msg Betreff network.email.subject
Empfänger (recipient) duid Empfänger network.email.to
Berichts-ID (reportid) oldFileId ReportID reportid additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_1 bis dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key und additional.fields.value.string_value
Hierarchie der Gerätegruppen (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key und additional.fields.value.string_value
Name des virtuellen Systems (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Gerätename (device_name) dvchost DeviceName intermediary.hostname
UUID der Quell-VM (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
UUID der Ziel-VM (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
HTTP-Methode (http_method) RequestMethod network.http.method
Tunnel-ID/IMSI (tunnel_id/imsi) PanOSTunnelID TunnelID tunnel_id/imsi additional.fields.key und additional.fields.value.string_value
Monitor Tag/IMEI (monitortag/imei) PanOSMonitorTag MonitorTag monitortag/imei additional.fields.key und additional.fields.value.string_value
ID der übergeordneten Sitzung (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Beginn der übergeordneten Sitzung (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key und additional.fields.value.string_value
Tunneltyp (tunnel) PanOSTunnelType TunnelType Tunnel additional.fields.key und additional.fields.value.string_value
Bedrohungskategorie (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
Inhaltsversion (contentver) PanOSContentVer ContentVer contentver additional.fields.key und additional.fields.value.string_value
SCTP-Verbindungs-ID (assoc_id) PanOSAssocID assoc_id additional.fields.key und additional.fields.value.string_value
Payload Protocol ID (ppid) PanOSPPID ppid additional.fields.key und additional.fields.value.string_value
HTTP-Header (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
Liste der URL-Kategorien (url_category_list) PanOSURLCatList url_category_list additional.fields.key und additional.fields.value.string_value
Regel-UUID (rule_uuid) PanOSRuleUUID security_result.rule_id
HTTP/2-Verbindung (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
Name der dynamischen Nutzergruppe (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

XFF-Adresse (xff_ip) PanXFFIP principal.ip
Gerätekategorie der Quelle (src_category) PanSrcDeviceCat src_category principal.asset.category
Quellgeräteprofil (src_profile) PanSrcDeviceProf src_profile

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Quellgerätemodell (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
Quellgeräteanbieter (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
Betriebssystemfamilie des Quellgeräts (src_osfamily) PanSrcDeviceOS src_osfamily principal.platform
Betriebssystemversion des Quellgeräts (src_osversion) PanSrcDeviceOSv principal.platform_version
Quellhostname (src_host) PanSrcHostname principal.hostname
Quell-MAC-Adresse (src_mac) PanSrcMac principal.mac
Zielgerätekategorie (dst_category) PanDstDeviceCat dst_category target.asset.category
Zielgeräteprofil (dst_profile) PanDstDeviceProf dst_profile

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Zielgerätemodell (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
Anbieter des Zielgeräts (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
Betriebssystemfamilie des Zielgeräts (dst_osfamily) PanDstDeviceOS dst_osfamily target.platform
Betriebssystemversion des Zielgeräts (dst_osversion) PanDstDeviceOSv target.platform_version
Ziel-Hostname (dst_host) PanDstHostname target.hostname
MAC-Zieladresse (dst_mac) PanDstMac target.mac
Container-ID (container_id) PanContainerName container_id intermediary.resource.product_object_id
POD Namespace (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
POD-Name (pod_name) PanPODName pod_name target.resource.name
Externe dynamische Quellliste (src_edl) PanSrcEDL src_edl additional.fields.key und additional.fields.value.string_value
Dynamische Liste für externes Ziel (dst_edl) PanDstEDL dst_edl additional.fields.key und additional.fields.value.string_value
Host-ID (hostid) PanGPHostID hostid principal.asset.asset_id
Seriennummer des Nutzergeräts (serialnumber) PanEPSerial principal.asset.hardware.serial_number
Domain-EDL (domain_edl) PanDomainEDL domain_edl additional.fields.key und additional.fields.value.string_value
Dynamische Quelladressengruppe (src_dag) PanSrcDAG principal.group.group_display_name
Dynamische Zieladressengruppe (dst_dag) PanDstDAG target.group.group_display_name
Teil-Hash (partial_hash) PanPartialHash partial_hash additional.fields.key und additional.fields.value.string_value
Zeitstempel mit hoher Auflösung (high_res timestamp) PanTimeHighRes Zeitstempel mit hoher Auflösung additional.fields.key und additional.fields.value.string_value
Grund (reason) PanReasonFilteringAction reason security_result.summary
Blocksatz (justification) PanJustification Begründung additional.fields.key und additional.fields.value.string_value
Ein Slice-Diensttyp (nssai_sst) PanASServiceType nssai_sst additional.fields.key und additional.fields.value.string_value
Unterkategorie der Anwendung (subcategory_of_app) subcategory_of_app additional.fields.key und additional.fields.value.string_value
Anwendungskategorie (category_of_app) category_of_app additional.fields.key und additional.fields.value.string_value
Anwendungstechnologie (technology_of_app) technology_of_app additional.fields.key und additional.fields.value.string_value
Anwendungsrisiko (risk_of_app) risk_of_app additional.fields.key und additional.fields.value.string_value
Anwendungsmerkmal (characteristic_of_app) characteristic_of_app additional.fields.key und additional.fields.value.string_value
Anwendungscontainer (container_of_app) container_of_app additional.fields.key und additional.fields.value.string_value
Application SaaS (is_saas_of_app) is_saas_of_app additional.fields.key und additional.fields.value.string_value
Getunnelte Anwendung (tunneled_app) additional.fields.key und additional.fields.value.string_value
Vorgangstyp (flow_type) additional.fields.key und additional.fields.value.string_value
Clustername (cluster_name) intermediary.resource.name
Status der Genehmigung der Anwendung (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key und additional.fields.value.string_value

Traffic

In der folgenden Tabelle sind die Logfelder des Traffic-Logtyps und die entsprechenden UDM-Felder aufgeführt.

CSV-Feld CEF-Feld LEEF-Feld Schlüssel für Google Security Operations-Label UDM-Feld
Empfangszeit (receive_time oder cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist)

Seriennummer (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Typ (type) Typ (Header) cat/Type metadata.product_event_type
Bedrohungs-/Inhaltstyp (Untertyp) Untertyp (Kopfzeile) Subtyp metadata.product_event_type
Generierte Zeit (time_generated oder cef-formatted-time_generated) start metadata.event_timestamp
Quelladresse (src) src src principal.ip
Zieladresse (dst) dst dst target.ip
NAT-Quell-IP-Adresse (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
NAT-Ziel-IP-Adresse (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Regelname (rule) cs1 RuleName security_result.rule_name
Quellnutzer (srcuser) suser SourceUser principal.user.userid
Zielnutzer (dstuser) duser DestinationUser target.user.userid
Anwendung (App) App Anwendung target.application
Virtuelles System (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Quellzone (von) cs4 SourceZone von

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Zielzone (bis) cs5 DestinationZone bis

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Eingangsschnittstelle (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Ausgangsschnittstelle (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Aktion protokollieren (Logset) cs6 LogForwardingProfile logset additional.fields.key und additional.fields.value.string_value
Sitzungs-ID (sessionid) cn1 SessionID network.session_id
Anzahl der Wiederholungen (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key und additional.fields.value.string_value
Quellport (sport) spt srcPort principal.port
Zielport (dport) dpt dstPort target.port
NAT-Quellport (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
NAT-Zielport (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Flags (flags) flexString1 Flags flags additional.fields.key und additional.fields.value.string_value
IP-Protokoll (proto) Proto Proto network.ip_protocol
Aktion (action) Handeln Aktion security_result.action_details

security_result.action

Byte (bytes) flexNumber1 totalBytes Byte additional.fields.key und additional.fields.value.string_value
Gesendete Bytes (bytes_sent) in srcBytes network.sent_bytes
Empfangene Byte (bytes_received) out dstBytes network.received_bytes
Pakete (packets) cn2 totalPackets Pakete additional.fields.key und additional.fields.value.string_value
Beginn (start) StartTime start additional.fields.key und additional.fields.value.string_value
Verstrichene Zeit (elapsed) cn3 ElapsedTime verstrichen network.session_duration.seconds
Kategorie (category) cs2 URLCategory security_result.category / security_result.category_details
Sequenznummer (seqno) externalId Sequenz metadata.product_log_id
Aktions-Flags (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key und additional.fields.value.string_value
Quellland (srcloc) SourceLocation principal.location.country_or_region
Zielland (dstloc) DestinationLocation target.location.country_or_region
Gesendete Pakete (pkts_sent) PanOSPacketsSent srcPackets pkts_sent network.sent_packets
Empfangene Pakete (pkts_received) PanOSPacketsReceived dstPackets pkts_received network.received_packets
Grund für das Ende der Sitzung (session_end_reason) reason SessionEndReason security_result.summary
Gerätegruppenhierarchie1 (dg_hier_level_1 bis dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie2 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie 3 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key und additional.fields.value.string_value
Name des virtuellen Systems (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Gerätename (device_name) dvchost DeviceName intermediary.hostname
Aktionsquelle (action_source) cat ActionSource action_source additional.fields.key und additional.fields.value.string_value
UUID der Quell-VM (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
UUID der Ziel-VM (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
Tunnel-ID/IMSI (tunnelid/imsi) PanOSTunnelID TunnelID tunnelid/imsi additional.fields.key und additional.fields.value.string_value
Monitor Tag/IMEI (monitortag/imei) PanOSMonitorTag MonitorTag monitortag/imei additional.fields.key und additional.fields.value.string_value
ID der übergeordneten Sitzung (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Startzeit des übergeordneten Ereignisses (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key und additional.fields.value.string_value
Tunneltyp (tunnel) PanOSTunnelType TunnelType Tunnel additional.fields.key und additional.fields.value.string_value
SCTP-Verbindungs-ID (assoc_id) PanOSSCTPAssocID assoc_id additional.fields.key und additional.fields.value.string_value
SCTP-Chunks PanOSSCTPChunks Chunks additional.fields.key und additional.fields.value.string_value
Gesendete SCTP-Chunks (chunks_sent) PanOSSCTPChunkSent chunks_sent additional.fields.key und additional.fields.value.string_value
Empfangene SCTP-Chunks (chunks_received) PanOSSCTPChunksRcv chunks_received additional.fields.key und additional.fields.value.string_value
Regel-UUID (rule_uuid) PanOSRuleUUID security_result.rule_id
HTTP/2-Verbindung (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
Anzahl der App-Flips (link_change_count) PanLinkChange link_change_count additional.fields.key und additional.fields.value.string_value
Richtlinien-ID (policy_id) PanPolicyID policy_id additional.fields.key und additional.fields.value.string_value
Link-Schalter (link_switches) PanLinkDetail link_switches additional.fields.key und additional.fields.value.string_value
SD-WAN-Cluster (sdwan_cluster) PanSDWANCluster sdwan_cluster additional.fields.key und additional.fields.value.string_value
SD-WAN-Gerätetyp (sdwan_device_type) PanSDWANDevice sdwan_device_type additional.fields.key und additional.fields.value.string_value
SD-WAN-Clustertyp (sdwan_cluster_type) PanSDWANClustype sdwan_cluster_type additional.fields.key und additional.fields.value.string_value
SD-WAN-Standort (sdwan_site) PanSDWANSite sdwan_site additional.fields.key und additional.fields.value.string_value
Name der dynamischen Nutzergruppe (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name additional.fields.key und additional.fields.value.string_value
XFF-Adresse (xff_ip) PanXFFIP principal.ip
Gerätekategorie der Quelle (src_category) PanSrcDeviceCat src_category principal.asset.category
Quellgeräteprofil (src_profile) PanSrcDeviceProf src_profile

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Quellgerätemodell (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
Quellgeräteanbieter (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
Betriebssystemfamilie des Quellgeräts (src_osfamily) PanSrcDeviceOS principal.platform
Betriebssystemversion des Quellgeräts (src_osversion) PanSrcDeviceOSv principal.asset.software.version
Quellhostname (src_host) PanSrcHostname principal.hostname
Quell-MAC-Adresse (src_mac) PanSrcMac principal.mac
Zielgerätekategorie (dst_category) PanDstDeviceCat dst_category target.asset.category
Zielgeräteprofil (dst_profile) PanDstDeviceProf dst_profile

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Zielgerätemodell (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
Anbieter des Zielgeräts (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
Betriebssystemfamilie des Zielgeräts (dst_osfamily) PanDstDeviceOS dst_osfamily target.platform
Betriebssystemversion des Zielgeräts (dst_osversion) PanDstDeviceOSv target.platform_version
Ziel-Hostname (dst_host) PanDstHostname target.hostname
MAC-Zieladresse (dst_mac) PanDstMac target.mac
Container-ID (container_id) PanContainerName container_id intermediary.resource.product_object_id
POD Namespace (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
POD-Name (pod_name) PanPODName pod_name target.resource.name
Externe dynamische Quellliste (src_edl) PanSrcEDL src_edl

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Dynamische Liste für externes Ziel (dst_edl) PanDstEDL dst_edl

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Host-ID (hostid) PanGPHostID hostid principal.asset.asset_id
Seriennummer des Nutzergeräts (serialnumber) PanEPSerial principal.asset.hardware.serial_number
Dynamische Quelladressengruppe (src_dag) PanSrcDAG principal.group.group_display_name
Dynamische Zieladressengruppe (dst_dag) PanDstDAG target.group.group_display_name
Sitzungsinhaber (session_owner) PanHASessionOwner session_owner additional.fields.key und additional.fields.value.string_value
Zeitstempel mit hoher Auflösung (high_res_timestamp) PanTimeHighRes additional.fields.key und additional.fields.value.string_value
Ein Slice-Diensttyp (nsdsai_sst) PanASServiceType nsdsai_sst additional.fields.key und additional.fields.value.string_value
Slice-Differenzierung (nsdsai_sd) PanASServiceDiff nsdsai_sd additional.fields.key und additional.fields.value.string_value
Unterkategorie der Anwendung (subcategory_of_app) subcategory_of_app additional.fields.key und additional.fields.value.string_value
Anwendungskategorie (category_of_app) category_of_app additional.fields.key und additional.fields.value.string_value
Anwendungstechnologie (technology_of_app) technology_of_app additional.fields.key und additional.fields.value.string_value
Anwendungsrisiko (risk_of_app) security_result.severity
Anwendungsmerkmal (characteristic_of_app) characteristic_of_app additional.fields.key und additional.fields.value.string_value
Anwendungscontainer (container_of_app) container_of_app additional.fields.key und additional.fields.value.string_value
Application SaaS (is_saas_of_app) is_saas_of_app additional.fields.key und additional.fields.value.string_value
Status der Genehmigung der Anwendung (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key und additional.fields.value.string_value
Unterkategorie der Anwendung (subcategory_of_app) subcategory_of_app1 additional.fields.key und additional.fields.value.string_value
Schweregrad (severity) number-of-severity(header) security_result.severity und security_result.severity_details

User-ID

In der folgenden Tabelle sind die Logfelder des Logtyps „Nutzer-ID“ und die entsprechenden UDM-Felder aufgeführt.

CSV-Feld CEF-Feld LEEF-Feld Schlüssel für Google Security Operations-Label UDM-Feld
Empfangszeit (receive_time oder cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist)

Seriennummer (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Typ (type) Typ (Header) cat metadata.product_event_type
Bedrohungs-/Inhaltstyp (Untertyp) Untertyp (Kopfzeile) Subtyp metadata.product_event_type
Generierte Zeit (time_generated oder cef-formatted-time_generated) metadata.event_timestamp
Virtuelles System (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Quell-IP-Adresse (ip) src src principal.ip
Nutzer (user) duser usrName target.user.userid

target.administrative_domain

target.user.email_addresses

Name der Datenquelle (datasourcename) cs4 DataSourceName datasourcename

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Ereignis-ID (eventid) EventID eventid additional.fields.key und additional.fields.value.string_value
Anzahl der Wiederholungen (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key und additional.fields.value.string_value
Grenzwert für Zeitüberschreitung (timeout) cn3 TimeoutThreshold Zeitüberschreitung additional.fields.key und additional.fields.value.string_value
Quellport (beginport) spt srcPort principal.port
Zielport (Endport) dpt dstPort target.port
Datenquelle (datasource) cs5 DataSource Datenquelle

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Typ der Datenquelle (datasourcetype) cs6 DataSourceType datasourcetype

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Sequenznummer (seqno) externalId Sequenz metadata.product_log_id
Aktions-Flags (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key und additional.fields.value.string_value
Hierarchie der Gerätegruppen (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key und additional.fields.value.string_value
Hierarchie der Gerätegruppen (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key und additional.fields.value.string_value
Name des virtuellen Systems (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Gerätename (device_name) dvchost DeviceName intermediary.hostname
ID des virtuellen Systems (vsys_id) cn2 VirtualSystemID intermediary.resource.product_object_id
Faktortyp (factortype) cs1 FactorType factortype additional.fields.key und additional.fields.value.string_value
Faktor „Abschlusszeit“ (factorcompletiontime) Ende FactorCompletionTime factorcompletiontime additional.fields.key und additional.fields.value.string_value
Faktornummer (factorno) cn1 FactorNumber factorno additional.fields.key und additional.fields.value.string_value
Nutzergruppen-Flags (ugflags) PanOSUGFlags ugflags additional.fields.key und additional.fields.value.string_value
Nutzer nach Quelle (userbysource) PanOSUserBySource target.user.userid

target.administrative_domain

target.user.email_addresses

Zeitstempel mit hoher Auflösung (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key und additional.fields.value.string_value
Ursprüngliche Datenquelle (origindatasource) additional.fields.key und additional.fields.value.string_value
Clustername (cluster_name) principal.resource.name
Schweregrad (severity) number-of-severity(header) security_result.severity und security_result.severity_details

Übereinstimmung mit dem HIP

In der folgenden Tabelle sind die Logfelder des Logtyps „HIP-Abgleich“ und die entsprechenden UDM-Felder aufgeführt.

CSV-Feld CEF-Feld LEEF-Feld Schlüssel für Google Security Operations-Label UDM-Feld
Empfangszeit (receive_time oder cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist)

Seriennummer (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Typ (type) Typ (Header) cat metadata.product_event_type
Bedrohungs-/Inhaltstyp (Untertyp) Untertyp (Kopfzeile) Subtyp
Generierte Zeit (time_generated oder cef-formatted-time_generated) start startTime metadata.event_timestamp
Quellnutzer (srcuser) suser usrName principal.user.userid
Virtuelles System (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
Computername (machinename) shost identHostName principal.hostname
Betriebssystem cs2 Betriebssystem principal.asset.platform_software.platform
Quelladresse (src) src identsrc principal.ip
HIP (matchname) cat HIP matchname

target.resource.attribute.labels.key/value

additional.fields.key und additional.fields.value.string_value

Anzahl der Wiederholungen (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key und additional.fields.value.string_value
HIP-Typ (matchtype) Geräteereignisklassen-ID (Header) HIPType matchtype

target.resource.attribute.labels.key/value

additional.fields.key und additional.fields.value.string_value

Sequenznummer (seqno) externalId Sequenz metadata.product_log_id
Aktions-Flags (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key und additional.fields.value.string_value
Hierarchie der Gerätegruppen (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key und additional.fields.value.string_value
Hierarchie der Gerätegruppen (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key und additional.fields.value.string_value
Name des virtuellen Systems (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
Gerätename (device_name) dvchost DeviceName target.hostname
ID des virtuellen Systems (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
IPv6-Systemadresse (srcipv6) c6a2 srcipv6 principal.asset.ip
Host-ID (hostid) PanOSHostID principal.asset.asset_id
Seriennummer des Nutzergeräts (serialnumber) PanOSEndpointSerialNumber principal.asset.hardware.serial_number
MAC-Adresse des Geräts (mac) PanOSEndpointMac principal.asset.mac
Zeitstempel mit hoher Auflösung (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key und additional.fields.value.string_value
Clustername (cluster_name) principal.resource.name
Schweregrad (severity) number-of-severity(header) security_result.severity und security_result.severity_details

IP-Tag

In der folgenden Tabelle sind die Logfelder des Logtyps „IP-Tag“ und die entsprechenden UDM-Felder aufgeführt.

CSV-Feld CEF-Feld LEEF-Feld Schlüssel für Google Security Operations-Label UDM-Feld
Empfangszeit (receive_time oder cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist)

Seriennummer (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Typ (type) Typ (Header) cat metadata.product_event_type
Bedrohungs-/Inhaltstyp (Untertyp) Untertyp (Kopfzeile) Subtyp metadata.product_event_type
Generierte Zeit (time_generated oder cef-formatted-time_generated) GenerateTime metadata.event_timestamp
Virtuelles System (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
Quell-IP-Adresse (ip) src src principal.ip
Tag-Name (tag_name) PanOSTagName TagName tag_name

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Ereignis-ID (event_id) PanOSEventID EventID event_id additional.fields.key und additional.fields.value.string_value
Anzahl der Wiederholungen (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key und additional.fields.value.string_value
Zeitüberschreitung (timeout) PanOSTimeout TimeoutThreshold Zeitüberschreitung additional.fields.key und additional.fields.value.string_value
Name der Datenquelle (datasourcename) PanOSDataSourceName DataSourceName datasourcename

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Typ der Datenquelle (datasource_type) PanOSDataSourceType DataSource datasource_type

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Untertyp der Datenquelle (datasource_subtype) PanOSDataSourceSubType DataSourceType datasource_subtype

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Sequenznummer (seqno) externalId Sequenz metadata.product_log_id
Aktions-Flags (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key und additional.fields.value.string_value
Hierarchie der Gerätegruppen (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key und additional.fields.value.string_value
Hierarchie der Gerätegruppen (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key und additional.fields.value.string_value
Name des virtuellen Systems (vsys_name) PanOsVsysName vSrcName target.asset.attribute.labels.key/value
Gerätename (device_name) dvchost DeviceName target.hostname
ID des virtuellen Systems (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
Zeitstempel mit hoher Auflösung (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key und additional.fields.value.string_value
Schweregrad (severity) number-of-severity(header) security_result.severity und security_result.severity_details
Clustername (cluster_name) principal.resource.name

Entschlüsselung

In der folgenden Tabelle sind die Logfelder des Entschlüsselungslogtyps und die entsprechenden UDM-Felder aufgeführt.

CSV-Feld CEF-Feld LEEF-Feld Schlüssel für Google Security Operations-Label UDM-Feld
Empfangszeit (receive_time oder cef-formatted-receive_time) rt metadata.collected_timestamp,

metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist)

Seriennummer (serial) PanOSDeviceSN intermediary.asset.hardware.serial_number
Typ (type) Typ (Header) metadata.product_event_type
Bedrohungs-/Inhaltstyp (Untertyp) Untertyp (Kopfzeile) metadata.product_event_type
Konfigurationsversion (config_ver) PanOSConfigVersion config_ver additional.fields.key und additional.fields.value.string_value
Erstellungszeit (time_generated) PanOSLogTimeStamp metadata.event_timestamp
Quelladresse (src) src principal.ip
Zieladresse (dst) dst target.ip
NAT-Quell-IP-Adresse (natsrc) sourceTranslatedAddress principa.nat_ip
NAT-Ziel-IP-Adresse (natdst) destinationTranslatedAddress target.nat_ip
Regel (rule) cs1 security_result.rule_name
Quellnutzer (srcuser) suser principal.user.userid
Zielnutzer (dstuser) duser target.user.userid
Anwendung (App) App network.application_protocol
Virtuelles System (vsys) cs3 vsys intermediary.asset.attribute.labels.key/value
Quellzone (von) cs4 von

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Zielzone (bis) cs5 bis

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Eingangsschnittstelle (inbound_if) deviceInboundInterface inbound_if

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Ausgangsschnittstelle (outbound_if) deviceOutboundInterface outbound_if

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Aktion protokollieren (Logset) cs6 logset additional.fields.key und additional.fields.value.string_value
Protokollierte Zeit (time_received) PanOSTimeReceivedManagementPlane -
Sitzungs-ID (sessionid) cn1 network.session_id
Anzahl der Wiederholungen (repeatcnt) PanOSCountOfRepeats/RepeatCount repeatcnt additional.fields.key und additional.fields.value.string_value
Quellport (sport) spt principal.port
Zielport (dport) dpt target.port
NAT-Quellport (natsport) sourceTranslatedPort principal.nat_port
NAT-Zielport (natdport) destinationTranslatedPort target.nat_port
Flags (flags) flexString1 flags additional.fields.key und additional.fields.value.string_value
IP-Protokoll (proto) Proto network.ip_protocol
Aktion (action) Handeln security_result.action_details

security_result.action

Tunnel (tunnel) PanOSTunnel Tunnel additional.fields.key und additional.fields.value.string_value
UUID der Quell-VM (src_uuid) PanOSSourceUUID principal.asset.product_object_id
UUID der Ziel-VM (dst_uuid) PanOSDestinationUUID target.asset.product_object_id
UUID für Regel (rule_uuid) PanOSRuleUUID security_result.rule_id
Phase für Client zu Firewall (hs_stage_c2f) PanOSClientToFirewall hs_stage_c2f additional.fields.key und additional.fields.value.string_value
Phase für Firewall-zu-Server (hs_stage_f2s) PanOSFirewallToServer hs_stage_f2s additional.fields.key und additional.fields.value.string_value
TLS-Version (tls_version) PanOSTLSVersion network.tls.version
Algorithmus für Schlüsselaustausch (tls_keyxchg) PanOSTLSKeyExchange tls_keyxchg additional.fields.key und additional.fields.value.string_value
Verschlüsselungsalgorithmus (tls_enc) PanOSTLSEncryptionAlgorithm tls_enc additional.fields.key und additional.fields.value.string_value
Hash-Algorithmus (tls_auth) PanOSTLSAuth tls_auth additional.fields.key und additional.fields.value.string_value
Richtlinienname (policy_name) PanOSPolicyName policy_name additional.fields.key und additional.fields.value.string_value
Elliptische Kurve (ec_curve) PanOSEllipticCurve network.tls.curve
Fehlerindex (err_index) PanOSErrorIndex err_index additional.fields.key und additional.fields.value.string_value
Root-Status (root_status) PanOSRootStatus root_status additional.fields.key und additional.fields.value.string_value
Kettenstatus (chain_status) PanOSChainStatus chain_status additional.fields.key und additional.fields.value.string_value
Proxy-Typ (proxy_type) PanOSProxyType proxy_type additional.fields.key und additional.fields.value.string_value
Seriennummer des Zertifikats (cert_serial) PanOSCertificateSerial network.tls.server.certificate.serial
Zertifikat-Fingerabdruck (Fingerabdruck) PanOSFingerprint network.tls.server.certificate.md5/sha1/sha256
Startdatum des Zertifikats (notbefore) PanOSTimeNotBefore network.tls.server.certificate.not_before
Enddatum des Zertifikats (notafter) PanOSTimeNotAfter network.tls.server.certificate.not_after
Zertifikatsversion (cert_ver) PanOSCertificateVersion network.tls.server.certificate.version
Zertifikatgröße (cert_size) PanOSCertificateSize cert_size additional.fields.key und additional.fields.value.string_value
Länge des allgemeinen Namens (cn_len) PanOSCommonNameLength cn_len additional.fields.key und additional.fields.value.string_value
Länge des allgemeinen Namens des Ausstellers (issuer_len) PanOSIssuerNameLength issuer_len additional.fields.key und additional.fields.value.string_value
Länge des gemeinsamen Namens des Root-Zertifikats (rootcn_len) PanOSRootCNLength rootcn_len additional.fields.key und additional.fields.value.string_value
SNI-Länge (sni_len) PanOSSNILength sni_len additional.fields.key und additional.fields.value.string_value
Zertifikats-Flags (cert_flags) PanOSCertificateFlags cert_flags additional.fields.key und additional.fields.value.string_value
Allgemeiner Name des Inhabers (cn) PanOSCommonName cn additional.fields.key und additional.fields.value.string_value
Allgemeiner Name des Ausstellers (issuer_cn) PanOSIssuerCommonName network.tls.server.certificate.issuer
Allgemeiner Name des Root-Zertifikats (root_cn) PanOSRootCommonName root_cn additional.fields.key und additional.fields.value.string_value
Server Name Indication

(sni)

network.tls.client.server_name
Fehler (error) PanOSErrorMessage Fehler additional.fields.key und additional.fields.value.string_value
Container-ID (container_id) PanOSContainerID container_id intermediary.resource.product_object_id
POD Namespace (pod_namespace) PanOSContainerNameSpace pod_namespace

target.resource.attribute.labels.key/value

additional.fields.key und additional.fields.value.string_value

POD-Name (pod_name) PanOSContainerName pod_name target.resource.name
Externe dynamische Quellliste (src_edl) PanOSSourceEDL src_edl

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Dynamische Liste für externes Ziel (dst_edl) PanOSDestinationEDL dst_edl

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Dynamische Quelladressengruppe (src_dag) PanOSSourceDynamicAddressGroup principal.group.group_display_name
Dynamische Zieladressengruppe (dst_dag) PanOSDestinationDynamicAddressGroup target.group.group_display_name
Zeitstempel mit hoher Auflösung (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key und additional.fields.value.string_value
Gerätekategorie der Quelle (src_category) PanOSSourceDeviceCategory src_category principal.asset.category
Quellgeräteprofil (src_profile) PanOSSourceDeviceProfile src_profile

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Quellgerätemodell (src_model) PanOSSourceDeviceModel src_model principal.asset.hardware.model
Quellgeräteanbieter (src_vendor) PanOSSourceDeviceVendor src_vendor principal.asset.hardware.manufacturer
Betriebssystemfamilie des Quellgeräts (src_osfamily) PanOSSourceDeviceOSFamily principal.platform
Betriebssystemversion des Quellgeräts (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
Quellhostname (src_host) PanOSSourceDeviceHost principal.hostname
Quell-MAC-Adresse (src_mac) PanOSSourceDeviceMac principal.mac
Zielgerätekategorie (dst_category) PanOSDestinationDeviceCategory dst_category target.asset.category
Zielgeräteprofil (dst_profile) PanOSDestinationDeviceProfile dst_profile

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Zielgerätemodell (dst_model) PanOSDestinationDeviceModel dst_model target.asset.hardware.model
Anbieter des Zielgeräts (dst_vendor) PanOSDestinationDeviceVendor dst_vendor target.asset.hardware.manufacturer
Betriebssystemfamilie des Zielgeräts (dst_osfamily) PanOSDestinationDeviceOSFamily dst_osfamily target.platform
Betriebssystemversion des Zielgeräts (dst_osversion) PanOSDestinationDeviceOSVersion target.platform_version
Ziel-Hostname (dst_host) PanOSDestinationDeviceHost target.hostname
MAC-Zieladresse (dst_mac) PanOSDestinationDeviceMac target.mac
Sequenznummer (seqno) PanOSLogTypeSeqNo metadata.product_log_id
Aktions-Flags (actionflags) PanOSActionFlags actionflags additional.fields.key und additional.fields.value.string_value
Hierarchie der Gerätegruppen (dg_hier_level_1) DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key und additional.fields.value.string_value
Hierarchie der Gerätegruppen (dg_hier_level_2) DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_3) DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_4) DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key und additional.fields.value.string_value
Name des virtuellen Systems (vsys_name) intermediary.asset.attribute.labels.key/value
Gerätename (device_name) intermediary.hostname
ID des virtuellen Systems (vsys_id) intermediary.resource.product_object_id
Unterkategorie der Anwendung (subcategory_of_app) subcategory_of_app additional.fields.key und additional.fields.value.string_value
Anwendungskategorie (category_of_app) category_of_app additional.fields.key und additional.fields.value.string_value
Anwendungstechnologie (technology_of_app) technology_of_app additional.fields.key und additional.fields.value.string_value
Anwendungsrisiko (risk_of_app) security_result.severity
Anwendungsmerkmal (characteristic_of_app) characteristic_of_app additional.fields.key und additional.fields.value.string_value
Anwendungscontainer (container_of_app) container_of_app additional.fields.key und additional.fields.value.string_value
Application SaaS (is_saas_of_app) is_saas_of_app additional.fields.key und additional.fields.value.string_value
Status der Genehmigung der Anwendung (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key und additional.fields.value.string_value
Schweregrad (severity) number-of-severity(header) security_result.severity und security_result.severity_details

Tunnel

In der folgenden Tabelle sind die Logfelder des Tunnel-Logtyps und die entsprechenden UDM-Felder aufgeführt.

CSV-Feld CEF-Feld LEEF-Feld Schlüssel für Google Security Operations-Label UDM-Feld
Empfangszeit (receive_time oder cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist)

Seriennummer (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Typ (type) Typ (Header) cat metadata.product_event_type
Bedrohungs-/Inhaltstyp (Untertyp) Untertyp (Kopfzeile) Subtyp metadata.product_event_type
Generierte Zeit (time_generated oder cef-formatted-time_generated) metadata.event_timestamp
Quelladresse (src) src src principal.ip
Zieladresse (dst) dst dst target.ip
NAT-Quell-IP-Adresse (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
NAT-Ziel-IP-Adresse (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Regelname (rule) cs1 RuleName security_result.rule_name
Quellnutzer (srcuser) suser SourceUser / usrName principal.user.userid
Zielnutzer (dstuser) duser DestinationUser target.user.userid
Anwendung (App) App Anwendung network.application_protocol
Virtuelles System (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Quellzone (von) cs4 SourceZone von

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Zielzone (bis) cs5 DestinationZone bis

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Eingangsschnittstelle (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Ausgangsschnittstelle (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Aktion protokollieren (Logset) cs6 LogForwardingProfile logset additional.fields.key und additional.fields.value.string_value
Sitzungs-ID (sessionid) cn1 SessionID network.session_id
Anzahl der Wiederholungen (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key und additional.fields.value.string_value
Quellport (sport) spt srcPort principal.port
Zielport (dport) dpt dstPort target.port
NAT-Quellport (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
NAT-Zielport (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Flags (flags) flexString1 Flags flags additional.fields.key und additional.fields.value.string_value
IP-Protokoll (proto) Proto Proto network.ip_protocol
Aktion (action) Handeln Aktion security_result.action_details

security_result.action

Schweregrad (severity) number-of-severity(header) security_result.severity und security_result.severity_details
Sequenznummer (seqno) externalId Sequenz metadata.product_log_id
Aktions-Flags (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key und additional.fields.value.string_value
Quellort (srcloc) principal.location.country_or_region
Zielort (dstloc) target.location.country_or_region
Hierarchie der Gerätegruppen (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key und additional.fields.value.string_value
Hierarchie der Gerätegruppen (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key und additional.fields.value.string_value
Name des virtuellen Systems (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Gerätename (device_name) dvchost DeviceName intermediary.hostname
Tunnel-ID (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key und additional.fields.value.string_value
Monitor-Tag (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key und additional.fields.value.string_value
ID der übergeordneten Sitzung (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Startzeit des übergeordneten Ereignisses (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key und additional.fields.value.string_value
Tunneltyp (tunnel) cs2 TunnelType Tunnel additional.fields.key und additional.fields.value.string_value
Byte (bytes) flexNumber1 totalBytes Byte additional.fields.key und additional.fields.value.string_value
Gesendete Bytes (bytes_sent) in srcBytes network.sent_bytes
Empfangene Byte (bytes_received) out dstBytes network.received_bytes
Pakete (packets) cn2 totalPackets Pakete additional.fields.key und additional.fields.value.string_value
Gesendete Pakete (pkts_sent) PanOSPacketsSent srcPackets pkts_sent network.sent_packets
Empfangene Pakete (pkts_received) PanOSPacketsReceived dstPackets pkts_received network.received_packets
Maximale Kapselung (max_encap) flexNumber2 MaximumEncapsulation max_encap additional.fields.key und additional.fields.value.string_value
Unbekanntes Protokoll (unknown_proto) cfp1 UnknownProtocol unknown_proto additional.fields.key und additional.fields.value.string_value
Strikte Überprüfung (strict_check) cfp2 StrictChecking strict_check additional.fields.key und additional.fields.value.string_value
Tunnel-Fragment (tunnel_fragment) PanOSTunnelFragment TunnelFragment tunnel_fragment additional.fields.key und additional.fields.value.string_value
Erstellte Sitzungen (sessions_created) cfp3 SessionsCreated sessions_created additional.fields.key und additional.fields.value.string_value
Geschlossene Sitzungen (sessions_closed) cfp4 SessionsClosed sessions_closed additional.fields.key und additional.fields.value.string_value
Grund für das Ende der Sitzung (session_end_reason) reason SessionEndReason security_result.summary
Aktionsquelle (action_source) cat ActionSource action_source additional.fields.key und additional.fields.value.string_value
Beginn (start) startTime start additional.fields.key und additional.fields.value.string_value
Verstrichene Zeit (elapsed) cn3 ElapsedTime verstrichen network.session_duration.seconds
Tunnel Inspection Rule (tunnel_insp_rule) PanOSTunneInspectionRule security_result.rule_name = "Tunnel Inspection Rule: %{PanOSTunnelInspectionRule}"
Remote-Nutzer-IP (remote_user_ip) PanOSRmtUserIP principal.ip
Remote-Nutzer-ID (remote_user_id) PanOSRmtUserID remote_user_id principal.user.userid
UUID der Sicherheitsregel (rule_uuid) PanOSRuleUUID security_result.rule_id
PCAP-ID (pcap_id) PanOSPcapID pcap_id additional.fields.key und additional.fields.value.string_value
Name der dynamischen Nutzergruppe (dynusergroup_name) PanDynamicUsrgrp principal.group.group_display_name
Externe dynamische Quellliste (src_edl) PanOSSourceEDL src_edl

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Dynamische Liste für externes Ziel (dst_edl) PanOSDestinationEDL dst_edl

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Zeitstempel mit hoher Auflösung (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key und additional.fields.value.string_value
Slice-Differenzierung (nssai_sd) nssai_sd additional.fields.key und additional.fields.value.string_value
Ein Slice-Diensttyp (nssai_sd) nssai_sd1 additional.fields.key und additional.fields.value.string_value
PDU-Sitzungs-ID (pdu_session_id) pdu_session_id additional.fields.key und additional.fields.value.string_value
Unterkategorie der Anwendung (subcategory_of_app) subcategory_of_app additional.fields.key und additional.fields.value.string_value
Anwendungskategorie (category_of_app) category_of_app additional.fields.key und additional.fields.value.string_value
Anwendungstechnologie (technology_of_app) technology_of_app additional.fields.key und additional.fields.value.string_value
Anwendungsrisiko (risk_of_app) risk_of_app additional.fields.key und additional.fields.value.string_value
Anwendungsmerkmal (characteristic_of_app) characteristic_of_app additional.fields.key und additional.fields.value.string_value
Anwendungscontainer (container_of_app) container_of_app additional.fields.key und additional.fields.value.string_value
Application SaaS (is_saas_of_app) is_saas_of_app additional.fields.key und additional.fields.value.string_value
Getunnelte Anwendung (tunneled_app) additional.fields.key und additional.fields.value.string_value
Ausgelagert (offloaded) additional.fields.key und additional.fields.value.string_value
Vorgangstyp (flow_type) additional.fields.key und additional.fields.value.string_value
Clustername (cluster_name)

principal.resource.name

Status der Genehmigung der Anwendung (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key und additional.fields.value.string_value

Authentifizierung

In der folgenden Tabelle sind die Logfelder des Authentifizierungslogtyps und die entsprechenden UDM-Felder aufgeführt.

CSV-Feld CEF-Feld LEEF-Feld Schlüssel für Google Security Operations-Label UDM-Feld
Empfangszeit (receive_time oder cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist)

Seriennummer (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Typ (type) Typ (Header) cat metadata.product_event_type
Bedrohungs-/Inhaltstyp (Untertyp) Untertyp (Kopfzeile) Subtyp metadata.product_event_type
Generierte Zeit (time_generated oder cef-formatted-time_generated) metadata.event_timestamp
Virtuelles System (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Quell-IP-Adresse (ip) src src principal.ip
Nutzer (user) duser usrName target.user.userid
Nutzer normalisieren (normalize_user) cs2 NormalizeUser target.user.user_display_name
Objekt (Objekt) fname ObjectName Objekt target.resource.name
Authentifizierungsrichtlinie (authpolicy) cs4 AuthPolicy authpolicy additional.fields.key und additional.fields.value.string_value
Anzahl der Wiederholungen (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key und additional.fields.value.string_value
Authentifizierungs-ID (authid) cn2 AuthenticationID authid additional.fields.key und additional.fields.value.string_value
Anbieter (vendor) flexString2 Anbieter vendor additional.fields.key und additional.fields.value.string_value
Aktion protokollieren (Logset) cs6 LogForwardingProfile logset additional.fields.key und additional.fields.value.string_value
Serverprofil (serverprofile) cs1 ServerProfile serverprofile additional.fields.key und additional.fields.value.string_value
Beschreibung (absteigend) PanOSDesc AdditionalAuthInfo security_result.description
Clienttyp (clienttype) cs5 ClientType clienttype additional.fields.key und additional.fields.value.string_value
Ereignistyp (event) msg msg extensions.auth.auth_details
Faktornummer (factorno) cn1 FactorNumber factorno additional.fields.key und additional.fields.value.string_value
Sequenznummer (seqno) externalId Sequenz metadata.product_log_id
Aktions-Flags (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key und additional.fields.value.string_value
Hierarchie der Gerätegruppen (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key und additional.fields.value.string_value
Hierarchie der Gerätegruppen (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key und additional.fields.value.string_value
Name des virtuellen Systems (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Gerätename (device_name) dvchost DeviceName intermediary.hostname
ID des virtuellen Systems (vsys_id) intermediary.resource.product_object_id
Authentifizierungsprotokoll (authproto) authproto additional.fields.key und additional.fields.value.string_value
UUID für Regel (rule_uuid) PanOSRuleUUID/RuleUUID security_result.rule_id
Zeitstempel mit hoher Auflösung (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key und additional.fields.value.string_value
Gerätekategorie der Quelle (src_category) PanOSSourceDeviceCategory src_category principal.asset.category
Quellgeräteprofil (src_profile) PanOSSourceDeviceProfile src_profile

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Quellgerätemodell (src_model) PanOSSourceDeviceModel src_model principal.asset.hardware.model
Quellgeräteanbieter (src_vendor) PanOSSourceDeviceVendor src_vendor principal.asset.hardware.manufacturer
Betriebssystemfamilie des Quellgeräts (src_osfamily) PanOSSourceDeviceOSFamily

principal.asset.platform_software.platform

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Betriebssystemversion des Quellgeräts (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
Quellhostname (src_host) PanOSSourceHostname principal.hostname
Quell-MAC-Adresse (src_mac) PanOSSourceMac principal.asset.mac
Region PanOSTrafficOriginRegion principal.location.country_or_region
User-Agent (user_agent) PanOSHTTPUserAgent network.http.user_agent
Sitzungs-ID(sessionid) PanOSTrafficSessionID network.session_id
Schweregrad (severity) number-of-severity(header) security_result.severity und security_result.severity_details
Clustername (cluster_name) principal.resource.name

URL

In der folgenden Tabelle sind die Logfelder des URL-Logtyps und die entsprechenden UDM-Felder aufgeführt.

CSV-Feld CEF-Feld LEEF-Feld Schlüssel für Google Security Operations-Label UDM-Feld
Empfangszeit (cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist)

Seriennummer (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Typ (type) Typ (Header) cat metadata.product_event_type
Bedrohungs-/Inhaltstyp (Untertyp) Untertyp (Kopfzeile) Subtyp metadata.product_event_type
Generierungszeit metadata.event_timestamp
Quelladresse (src) src src principal.ip
Zieladresse (dst) dst dst target.ip
NAT-Quell-IP-Adresse (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
NAT-Ziel-IP-Adresse (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Regel (rule) cs1 RuleName security_result.rule_name
Quellnutzer (srcuser) suser SourceUser principal.user.userid
Zielnutzer (dstuser) duser DestinationUser target.user.userid
Anwendung (App) App Anwendung network.application_protocol
Virtuelles System (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Quellzone (von) cs4 SourceZone von

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Zielzone (bis) cs5 DestinationZone bis

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Eingangsschnittstelle (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Ausgangsschnittstelle (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Aktion protokollieren (Logset) cs6 LogForwardingProfile logset additional.fields.key und additional.fields.value.string_value
Zeit der Protokollierung time_logged additional.fields.key und additional.fields.value.string_value
Sitzungs-ID (sessionid) cn1 SessionID network.session_id
Anzahl der Wiederholungen (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key und additional.fields.value.string_value
Quellport (sport) spt srcPort principal.port
Zielport (dport) dpt dstPort target.port
NAT-Quellport (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
NAT-Zielport (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Flags (flags) flexString1 Flags flags additional.fields.key und additional.fields.value.string_value
IP-Protokoll (proto) Proto Proto network.ip_protocol
Aktion (action) Handeln Aktion security_result.action_details

security_result.action

URL/Dateiname (Sonstiges) Sonstiges target.file.names

target.url

Name der Bedrohung/des Inhalts (threatid) cat ThreatID security_result.threat_id
Kategorie (category) cs2 URLCategory Kategorie security_result.category_details
Schweregrad (severity) number-of-severity (Header) Schweregrad security_result.severity

security_result.severity_details

Richtung (direction) flexString2 Richtung network.direction
Sequenznummer (seqno) externalId Sequenz metadata.product_log_id
Aktions-Flags (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key und additional.fields.value.string_value
Quellland (srcloc) SourceLocation principal.location.country_or_region
Zielland (dstloc) DestinationLocation target.location.country_or_region
contenttype (contenttype) requestContext ContentType contenttype additional.fields.key und additional.fields.value.string_value
pcap_id (pcap_id) fileId PCAP_ID pcap_id additional.fields.key und additional.fields.value.string_value
filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
cloud (cloud) Cloud Cloud additional.fields.key und additional.fields.value.string_value
url_idx (url_idx) URLIndex url_idx additional.fields.key und additional.fields.value.string_value
user_agent (user_agent) requestClientApplication User-Agent network.http.user_agent
Dateityp (filetype) target.file.mime_type
xff (xff) PanOSXForwarderfor identSrc xff principal.ip
Referrer (referer) PanOSReferer Verwiesen von: network.http.referral_url
Absender (sender) network.email.from
Betreff (subject) Betreff network.email.subject
Empfänger (recipient) network.email.to
reportid (reportid) reportid additional.fields.key und additional.fields.value.string_value
DG Hierarchy Level 1 (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key und additional.fields.value.string_value
DG Hierarchy Level 2 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key und additional.fields.value.string_value
DG Hierarchy Level 3 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key und additional.fields.value.string_value
Demand Gen-Hierarchieebene 4 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key und additional.fields.value.string_value
Name des virtuellen Systems (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Gerätename (device_name) dvchost DeviceName intermediary.hostname
file_url (file_url) target.url
UUID der Quell-VM (src_uuid) SrcUUID principal.asset.product_object_id
UUID der Ziel-VM (dst_uuid) DstUUID target.asset.product_object_id
http_method (http_method) requestMethod RequestMethod network.http.method
Tunnel-ID/IMSI (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key und additional.fields.value.string_value
Monitor-Tag/IMEI (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key und additional.fields.value.string_value
ID der übergeordneten Sitzung (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Beginn der übergeordneten Sitzung (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key und additional.fields.value.string_value
Tunnel (tunnel) PanOSTunnelType TunnelType Tunnel additional.fields.key und additional.fields.value.string_value
thr_category (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
contentver (contentver) PanOSContentVer ContentVer contentver additional.fields.key und additional.fields.value.string_value
sig_flags (sig_flags) sig_flags additional.fields.key und additional.fields.value.string_value
SCTP-Verbindungs-ID (assoc_id) PanOSAssocID assoc_id additional.fields.key und additional.fields.value.string_value
Payload Protocol ID (ppid) PanOSPPID ppid additional.fields.key und additional.fields.value.string_value
http_headers (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
Liste der URL-Kategorien (url_category_list) PanOSURLCatList url_category_list additional.fields.key und additional.fields.value.string_value
UUID für Regel (rule_uuid) PanOSRuleUUID rule_uuid security_result.rule_id
HTTP/2-Verbindung (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
dynusergroup_name (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name additional.fields.key und additional.fields.value.string_value
XFF-Adresse (xff_ip) PanXFFIP principal.ip
Gerätekategorie der Quelle (src_category) PanSrcDeviceCat src_category principal.asset.category
Quellgeräteprofil (src_profile) PanSrcDeviceProf src_profile

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Quellgerätemodell (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
Quellgeräteanbieter (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
Betriebssystemfamilie des Quellgeräts (src_osfamily) PanSrcDeviceOS principal.platform
Betriebssystemversion des Quellgeräts (src_osversion) PanSrcDeviceOSv principal.platform_version
Quellhostname (src_host) PanSrcHostname src_host principal.hostname
Quell-MAC-Adresse (src_mac) PanSrcMac principal.mac
Zielgerätekategorie (dst_category) PanDstDeviceCat dst_category target.asset.category
Zielgeräteprofil (dst_profile) PanDstDeviceProf dst_profile

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Zielgerätemodell (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
Anbieter des Zielgeräts (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
Betriebssystemfamilie des Zielgeräts (dst_osfamily) PanDstDeviceOS target.platform
Betriebssystemversion des Zielgeräts (dst_osversion) PanDstDeviceOSv target.platform_version
Ziel-Hostname (dst_host) PanPODNamespace target.hostname
MAC-Zieladresse (dst_mac) PanDstMac target.mac
Container-ID (container_id) PanContainerName container_id intermediary.resource.product_object_id
POD Namespace (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
POD-Name (pod_name) PanPODName pod_name target.resource.name
Externe dynamische Quellliste (src_edl) PanSrcEDL src_edl

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Dynamische Liste für externes Ziel (dst_edl) PanDstEDL dst_edl

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Host-ID (hostid) PanGPHostID hostid principal.asset.asset_id
Seriennummer (serialnumber) PanEPSerial principal.asset.hardware.serial_number
domain_edl (domain_edl) PanDomainEDL domain_edl additional.fields.key und additional.fields.value.string_value
Dynamische Quelladressengruppe (src_dag) PanSrcDAG principal.group.group_display_name
Dynamische Zieladressengruppe (dst_dag) PanDstDAG target.group.group_display_name
partial_hash (partial_hash) PanPartialHash partial_hash additional.fields.key und additional.fields.value.string_value
Zeitstempel mit hoher Auflösung (high_res_timestamp) PanTimeHighRes additional.fields.key und additional.fields.value.string_value
Grund (reason) PanReasonFilteringAction reason security_result.summary
Blocksatz (justification) PanJustification Begründung additional.fields.key und additional.fields.value.string_value
nssai_sst (nssai_sst) PanASServiceType nssai_sst additional.fields.key und additional.fields.value.string_value
Unterkategorie der App (subcategory_of_app) subcategory_of_app additional.fields.key und additional.fields.value.string_value
App-Kategorie (category_of_app) category_of_app additional.fields.key und additional.fields.value.string_value
Technologie der App (technology_of_app) technology_of_app additional.fields.key und additional.fields.value.string_value
Risiko der App (risk_of_app) risk_of_app additional.fields.key und additional.fields.value.string_value
Merkmal der App (characteristic_of_app) characteristic_of_app additional.fields.key und additional.fields.value.string_value
Container der App (container_of_app) container_of_app additional.fields.key und additional.fields.value.string_value
Getunnelte App (tunneled_app) tunneled_app additional.fields.key und additional.fields.value.string_value
SaaS der App (is_saas_of_app) is_saas_of_app additional.fields.key und additional.fields.value.string_value
Genehmigter Status der App (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key und additional.fields.value.string_value
Cloud-Bericht-ID (cloud_reportid) additional.fields.key und additional.fields.value.string_value
Clustername (cluster_name)

principal.resource.name

Vorgangstyp (flow_type) additional.fields.key und additional.fields.value.string_value

Daten

In der folgenden Tabelle sind die Logfelder des Datenlogtyps und die entsprechenden UDM-Felder aufgeführt.

CSV-Feld CEF-Feld LEEF-Feld Schlüssel für Google Security Operations-Label UDM-Feld
Empfangszeit (cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist)

Seriennummer (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Typ (type) Typ (Header) cat metadata.product_event_type
Bedrohungs-/Inhaltstyp (Untertyp) Untertyp (Kopfzeile) Subtyp metadata.product_event_type
Generierungszeit metadata.event_timestamp
Quelladresse (src) src src principal.ip
Zieladresse (dst) dst dst target.ip
NAT-Quell-IP-Adresse (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
NAT-Ziel-IP-Adresse (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Regel (rule) cs1 RuleName security_result.rule_name
Quellnutzer (srcuser) suser SourceUser principal.user.userid
Zielnutzer (dstuser) duser DestinationUser target.user.userid
Anwendung (App) App Anwendung network.application_protocol
Virtuelles System (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Quellzone (von) cs4 SourceZone von

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Zielzone (bis) cs5 DestinationZone bis

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Eingangsschnittstelle (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Ausgangsschnittstelle (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Aktion protokollieren (Logset) cs6 LogForwardingProfile logset additional.fields.key und additional.fields.value.string_value
Zeit der Protokollierung time_logged additional.fields.key und additional.fields.value.string_value
Sitzungs-ID (sessionid) cn1 SessionID network.session_id
Anzahl der Wiederholungen (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key und additional.fields.value.string_value
Quellport (sport) spt srcPort principal.port
Zielport (dport) dpt dstPort target.port
NAT-Quellport (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
NAT-Zielport (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Flags (flags) flexString1 Flags flags additional.fields.key und additional.fields.value.string_value
IP-Protokoll (proto) Proto Proto network.ip_protocol
Aktion (action) Handeln Aktion security_result.action_details

security_result.action

URL/Dateiname (Sonstiges) Sonstiges target.file.names

target.url

Name der Bedrohung/des Inhalts (threatid) cat ThreatID security_result.threat_id
Kategorie (category) cs2 URLCategory Kategorie security_result.category_details
Schweregrad (severity) number-of-severity (Header) Schweregrad security_result.severity

security_result.severity_details

Richtung (direction) flexString2 Richtung network.direction
Sequenznummer (seqno) externalId Sequenz metadata.product_log_id
Aktions-Flags (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key und additional.fields.value.string_value
Quellland (srcloc) SourceLocation principal.location.country_or_region
Zielland (dstloc) DestinationLocation target.location.country_or_region
contenttype (contenttype) ContentType contenttype additional.fields.key und additional.fields.value.string_value
pcap_id (pcap_id) fileId PCAP_ID pcap_id additional.fields.key und additional.fields.value.string_value
filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
cloud (cloud) Cloud Cloud additional.fields.key und additional.fields.value.string_value
url_idx (url_idx) URLIndex url_idx additional.fields.key und additional.fields.value.string_value
user_agent (user_agent) network.http.user_agent
Dateityp (filetype) target.file.mime_type
xff (xff) xff principal.ip
Referrer (referer) network.http.referral_url
Absender (sender) network.email.from
Betreff (subject) Betreff network.email.subject
Empfänger (recipient) network.email.to
reportid (reportid) reportid additional.fields.key und additional.fields.value.string_value
DG Hierarchy Level 1 (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key und additional.fields.value.string_value
DG Hierarchy Level 2 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key und additional.fields.value.string_value
DG Hierarchy Level 3 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key und additional.fields.value.string_value
Demand Gen-Hierarchieebene 4 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key und additional.fields.value.string_value
Name des virtuellen Systems (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Gerätename (device_name) dvchost DeviceName intermediary.hostname
file_url (file_url) target.url
UUID der Quell-VM (src_uuid) SrcUUID principal.asset.product_object_id
UUID der Ziel-VM (dst_uuid) DstUUID target.asset.product_object_id
http_method (http_method) RequestMethod network.http.method
Tunnel-ID/IMSI (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key und additional.fields.value.string_value
Monitor-Tag/IMEI (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key und additional.fields.value.string_value
ID der übergeordneten Sitzung (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Beginn der übergeordneten Sitzung (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key und additional.fields.value.string_value
Tunnel (tunnel) PanOSTunnelType TunnelType Tunnel additional.fields.key und additional.fields.value.string_value
thr_category (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
contentver (contentver) PanOSContentVer ContentVer contentver additional.fields.key und additional.fields.value.string_value
sig_flags (sig_flags) sig_flags additional.fields.key und additional.fields.value.string_value
SCTP-Verbindungs-ID (assoc_id) PanOSAssocID assoc_id additional.fields.key und additional.fields.value.string_value
Payload Protocol ID (ppid) PanOSPPID ppid additional.fields.key und additional.fields.value.string_value
http_headers (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
Liste der URL-Kategorien (url_category_list) url_category_list additional.fields.key und additional.fields.value.string_value
UUID für Regel (rule_uuid) PanOSRuleUUID rule_uuid security_result.rule_id
HTTP/2-Verbindung (http2_connection) http2_connection network.application_protocol_version
dynusergroup_name (dynusergroup_name) dynusergroup_name

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

XFF-Adresse (xff_ip) principal.ip
Gerätekategorie der Quelle (src_category) src_category principal.asset.category
Quellgeräteprofil (src_profile) src_profile

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Quellgerätemodell (src_model) src_model principal.asset.hardware.model
Quellgeräteanbieter (src_vendor) src_vendor principal.asset.hardware.manufacturer
Betriebssystemfamilie des Quellgeräts (src_osfamily) principal.platform
Betriebssystemversion des Quellgeräts (src_osversion) principal.platform_version
Quellhostname (src_host) src_host principal.hostname
Quell-MAC-Adresse (src_mac) principal.mac
Zielgerätekategorie (dst_category) dst_category target.asset.category
Zielgeräteprofil (dst_profile) dst_profile

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Zielgerätemodell (dst_model) dst_model target.asset.hardware.model
Anbieter des Zielgeräts (dst_vendor) dst_vendor target.asset.hardware.manufacturer
Betriebssystemfamilie des Zielgeräts (dst_osfamily) target.platform
Betriebssystemversion des Zielgeräts (dst_osversion) target.platform_version
Ziel-Hostname (dst_host) target.hostname
MAC-Zieladresse (dst_mac) target.mac
Container-ID (container_id) container_id intermediary.resource.product_object_id
POD Namespace (pod_namespace) pod_namespace target.resource.attribute.labels.key/value
POD-Name (pod_name) pod_name target.resource.name
Externe dynamische Quellliste (src_edl) src_edl

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Dynamische Liste für externes Ziel (dst_edl) dst_edl

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Host-ID (hostid) hostid principal.asset.asset_id
Seriennummer (serialnumber) principal.asset.hardware.serial_number
domain_edl (domain_edl) domain_edl additional.fields.key und additional.fields.value.string_value
Dynamische Quelladressengruppe (src_dag) principal.group.group_display_name
Dynamische Zieladressengruppe (dst_dag) target.group.group_display_name
partial_hash (partial_hash) partial_hash additional.fields.key und additional.fields.value.string_value
Zeitstempel mit hoher Auflösung (high_res_timestamp) additional.fields.key und additional.fields.value.string_value
Grund (reason) reason security_result.summary
Blocksatz (justification) Begründung additional.fields.key und additional.fields.value.string_value
nssai_sst (nssai_sst) nssai_sst additional.fields.key und additional.fields.value.string_value
Unterkategorie der App (subcategory_of_app) subcategory_of_app additional.fields.key und additional.fields.value.string_value
App-Kategorie (category_of_app) category_of_app additional.fields.key und additional.fields.value.string_value
Technologie der App (technology_of_app) technology_of_app additional.fields.key und additional.fields.value.string_value
Risiko der App (risk_of_app) risk_of_app additional.fields.key und additional.fields.value.string_value
Merkmal der App (characteristic_of_app) characteristic_of_app additional.fields.key und additional.fields.value.string_value
Container der App (container_of_app) container_of_app additional.fields.key und additional.fields.value.string_value
Getunnelte App (tunneled_app) tunneled_app additional.fields.key und additional.fields.value.string_value
SaaS der App (is_saas_of_app) is_saas_of_app additional.fields.key und additional.fields.value.string_value
Genehmigter Status der App (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key und additional.fields.value.string_value
Cloud-Bericht-ID (cloud_reportid) additional.fields.key und additional.fields.value.string_value
Clustername (cluster_name) principal.resource.name
Vorgangstyp (flow_type) additional.fields.key und additional.fields.value.string_value

GlobalProtect

In der folgenden Tabelle sind die Logfelder des GlobalProtect-Logtyps und die entsprechenden UDM-Felder aufgeführt.

CSV-Feld CEF-Feld LEEF-Feld Schlüssel für Google Security Operations-Label UDM-Feld
Empfangszeit (receive_time) rt received_time metadata.event_timestamp
Seriennummer (serial) PanOSDeviceSN intermediary_asset_hardware_serial_number intermediary.asset.hardware.serial_number
Typ (type) Typ (Header) metadata.product_event_type
Bedrohungs-/Inhaltstyp (Untertyp) Untertyp (Kopfzeile) Subtyp metadata.product_event_type
Erstellungszeit (time_generated) PanOSLogTimeStamp generated_timestamp metadata.event_timestamp
Virtuelles System (vsys) PanOSVirtualSystem vsys intermediary.asset.attribute.labels.key/value
Ereignis-ID (eventid) PanOSEventID event_id additional.fields.key und additional.fields.value.string_value
Phase (stage) PanOSStage Phase additional.fields.key und additional.fields.value.string_value
Authentifizierungsmethode (auth_method) PanOSAuthMethod extension_auth_auth_details extensions.auth.auth_details
Tunneltyp (tunnel_type) PanOSTunnelType Tunnel additional.fields.key und additional.fields.value.string_value
Quellnutzer (srcuser) PanOSSourceUserName src_user principal.user.email_address

principal.user.userid

principal.administrative_domain

Quellregion (srcregion) PanOSSourceRegion src_region principal.location.country_or_region
Computername (machinename) PanOSEndpointDeviceName machine_name principal.hostname
Öffentliche IP-Adresse (public_ip) PanOSPublicIPv4 principal.nat_ip
Öffentliches IPv6 (public_ipv6) PanOSPublicIPv6 principal.nat_ip
Private IP-Adresse (private_ip) PanOSPrivateIPv4 principal.ip
Private IPv6 (private_ipv6) PanOSPrivateIPv6 principal.ip
Host-ID (hostid) PanOSHostID hostid principal.asset.asset_id
Seriennummer (serialnumber) PanOSDeviceSN principal.asset.hardware.serial_number
Clientversion (client_ver) PanOSGlobalProtectClientVersion client_ver additional.fields.key und additional.fields.value.string_value
Clientbetriebssystem (client_os) PanOSEndpointOSType principal.platform
Client-Betriebssystemversion (client_os_ver) PanOSEndpointOSVersion principal.platform_version
Anzahl der Wiederholungen (repeatcnt) PanOSCountOfRepeats repeatcnt additional.fields.key und additional.fields.value.string_value
Grund (reason) PanOSQuarantineReason security_result.summary
Fehler (error) PanOSConnectionError Fehler security_result.description
Beschreibung (undurchsichtig) PanOSDescription security_result.description
Status (status) PanOSEventStatus Status additional.fields.key und additional.fields.value.string_value
Standort (location) PanOSGPGatewayLocation target.location.country_or_region
Anmeldedauer (login_duration) PanOSLoginDuration network.session_duration
Verbindungsmethode (connect_method) PanOSConnectionMethod connect_method additional.fields.key und additional.fields.value.string_value
Fehlercode (error_code) PanOSConnectionErrorID error_code additional.fields.key und additional.fields.value.string_value
Portal (portal) PanOSPortal Portal additional.fields.key und additional.fields.value.string_value
Sequenznummer (seqno) PanOSSequenceNo metadata.product_log_id
Aktions-Flags (actionflags) PanOSActionFlags actionflags additional.fields.key und additional.fields.value.string_value
Zeitstempel mit hoher Auflösung (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key und additional.fields.value.string_value
Methode zur Gateway-Auswahl (selection_type) PanOSGatewaySelectionType selection_type additional.fields.key und additional.fields.value.string_value
SSL-Reaktionszeit (response_time) PanOSSSLResponseTime response_time additional.fields.key und additional.fields.value.string_value
Gateway-Priorität (priority) PanOSGatewayPriority Priorität additional.fields.key und additional.fields.value.string_value
Versuchte Gateways (attempted_gateways) PanOSAttemptedGateways attempted_gateways additional.fields.key und additional.fields.value.string_value
Name des Gateways (gateway) PanOSAttemptedGateways Gateway target.resource.name
Hierarchie der Gerätegruppen (dg_hier_level_1) dg_hier_level_1 additional.fields.key und additional.fields.value.string_value
Hierarchie der Gerätegruppen (dg_hier_level_2) dg_hier_level_2 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_3) dg_hier_level_3 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie (dg_hier_level_4) dg_hier_level_4 additional.fields.key und additional.fields.value.string_value
Name des virtuellen Systems (vsys_name) intermediary.asset.attribute.labels.key/value
Gerätename (device_name) intermediary.hostname
ID des virtuellen Systems (vsys_id) intermediary.resource.product_object_id
Schweregrad (severity) number-of-severity(header) security_result.severity und security_result.severity_details
Clustername (cluster_name) principal.resource.name

Ergebnisse in Beziehung setzen

In der folgenden Tabelle sind die Logfelder des Typs „Korrelation“ und die entsprechenden UDM-Felder aufgeführt.

CSV-Feld CEF-Feld LEEF-Feld Schlüssel für Google Security Operations-Label UDM-Feld
Generierte Zeit (time_generated oder cef-formatted-time_generated) startTime generated_timestamp metadata.event_timestamp
Quelladresse (src) src principal.ip
Quellnutzer (srcuser) SourceUser / usrName principal.user.userid
Virtuelles System (vsys) VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Kategorie (category) security_result.category_details
Schweregrad (severity) Schweregrad security_result.severity und security_result.severity_details
Gerätegruppenhierarchie – Ebene 1 DeviceGroupHierarchyL1 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie – Stufe 2 DeviceGroupHierarchyL2 additional.fields.key und additional.fields.value.string_value
Gerätegruppenhierarchie – Ebene 3 DeviceGroupHierarchyL3 additional.fields.key und additional.fields.value.string_value
Hierarchieebene 4 der Gerätegruppe DeviceGroupHierarchyL4 additional.fields.key und additional.fields.value.string_value
Name des virtuellen Systems (vsys_name) vSrcName intermediary.asset.attribute.labels.key/value
Gerätename (device_name) DeviceName intermediary.hostname
ID des virtuellen Systems (vsys_id) VirtualSystemID intermediary.resource.product_object_id
Objektname (objectname) ObjectName target.resource.name
Objekt-ID (object_id) ObjectID target.resource.product_object_id
Nachweis msg security_result.summary

GTP

In der folgenden Tabelle sind die Logfelder des Logtyps „gtp“ und die entsprechenden UDM-Felder aufgeführt.

CSV-Feld CEF-Feld LEEF-Feld Schlüssel für Google Security Operations-Label UDM-Feld
Empfangszeit (receive_time oder cef-formatted-receive_time) metadata.collected_timestamp,

metadata.event_timestamp (wenn „Generate Time“ nicht vorhanden ist)

Seriennummer (serial) intermediary.asset.hardware.serial_number
Typ (type) metadata.product_event_type
Bedrohungs-/Inhaltstyp (Untertyp) metadata.product_event_type
Generierte Zeit (time_generated oder cef-formatted-time_generated) metadata.event_timestamp
Quelladresse (src) principal.ip
Zieladresse (dst) target.ip
Regelname (rule) security_result.rule_name
Anwendung (App) network.application_protocol
Virtuelles System (vsys) vsys intermediary.asset.attribute.labels.key/value
Quellzone (von) von

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Zielzone (bis) bis

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Eingangsschnittstelle (inbound_if) inbound_if

principal.labels.key und principal.labels.value

additional.fields.key und additional.fields.value.string_value

Ausgangsschnittstelle (outbound_if) outbound_if

target.labels.key und target.labels.value

additional.fields.key und additional.fields.value.string_value

Aktion protokollieren (Logset) logset additional.fields.key und additional.fields.value.string_value
Sitzungs-ID (sessionid) network.session_id
Quellport (sport) principal.port
Zielport (dport) target.port
IP-Protokoll (proto) network.ip_protocol
Aktion (action) security_result.action_details

security_result.action

GTP-Ereignistyp (event_type) gtp_event_type additional.fields.key und additional.fields.value.string_value
MSISDN (msisdn) msisdn additional.fields.key und additional.fields.value.string_value
Name des Zugangspunkts (APN) apn additional.fields.key und additional.fields.value.string_value
Radio Access Technology (RAT) Ratte additional.fields.key und additional.fields.value.string_value
GTP-Nachrichtentyp (msg_type) gtp_msg_type additional.fields.key und additional.fields.value.string_value
End-IP-Adresse (end_ip_adr) principal.ip
Tunnelendpunkt-ID1 (teid1) teid1 additional.fields.key und additional.fields.value.string_value
Tunnelendpunkt-ID2 (teid2) teid2 additional.fields.key und additional.fields.value.string_value
GTP-Schnittstelle (gtp_interface) gtp_interface additional.fields.key und additional.fields.value.string_value
GTP-Ursache (cause_code) gtp_cause_code additional.fields.key und additional.fields.value.string_value
Schweregrad (severity) security_result.severity und security_result.severity_details
MCC des bereitstellenden Mobilfunknetzes (mcc) mcc additional.fields.key und additional.fields.value.string_value
MNC des Bereitstellungsnetzwerks (mnc) mnc additional.fields.key und additional.fields.value.string_value
Vorwahl (area_code) area_code additional.fields.key und additional.fields.value.string_value
Zellen-ID (cell_id) cell_id additional.fields.key und additional.fields.value.string_value
GTP-Ereigniscode (event_code) event_code additional.fields.key und additional.fields.value.string_value
Quellort (srcloc) principal.location.country_or_region
Zielort (dstloc) target.location.country_or_region
Tunnel-ID/IMSI (imsi) tunnelid additional.fields.key und additional.fields.value.string_value
Monitor Tag/IMEI (imei) monitortag additional.fields.key und additional.fields.value.string_value
Beginn (start) start additional.fields.key und additional.fields.value.string_value
Verstrichene Zeit (elapsed) network.session_duration.seconds
Tunnel Inspection RuleTunnel (tunnel_insp_rule) tunnel_insp_rule security_result.detection_fields.key/value
Remote-Nutzer-IP (remote_user_ip) principal.ip
Remote-Nutzer-ID (remote_user_id) remote_user_id principal.user.userid
UUID für Regel (rule_uuid) security_result.rule_id
PCAP-ID (pcap_id) pcap_id additional.fields.key und additional.fields.value.string_value
Zeitstempel mit hoher Auflösung (high_res_timestamp) additional.fields.key und additional.fields.value.string_value
Ein Slice-Diensttyp (nsdsai_sst) nsdsai_sst additional.fields.key und additional.fields.value.string_value
Slice-Differenzierung (nsdsai_sd) nsdsai_sd additional.fields.key und additional.fields.value.string_value
Unterkategorie der Anwendung (subcategory_of_app) subcategory_of_app additional.fields.key und additional.fields.value.string_value
Anwendungskategorie (category_of_app) category_of_app additional.fields.key und additional.fields.value.string_value
Anwendungstechnologie (technology_of_app) technology_of_app additional.fields.key und additional.fields.value.string_value
Anwendungsrisiko (risk_of_app) risk_of_app additional.fields.key und additional.fields.value.string_value
Anwendungsmerkmal (characteristic_of_app) characteristic_of_app additional.fields.key und additional.fields.value.string_value
Anwendungscontainer (container_of_app) container_of_app additional.fields.key und additional.fields.value.string_value
Application SaaS (is_saas_of_app) is_saas_of_app additional.fields.key und additional.fields.value.string_value
Status der Genehmigung der Anwendung (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key und additional.fields.value.string_value

SCTP

CSV-Feld CEF-Feld LEEF-Feld Schlüssel für Google Security Operations-Label UDM-Feld
Empfangszeit (receive_time oder cef-formatted-receive_time) receive_time oder cef-formatted-receive_time metadata.collected_timestamp
Seriennummer (serial) serial intermediary.asset.hardware.serial_number
Typ (type) Typ metadata.product_event_type
Generierte Zeit (time_generated oder cef-formatted-time_generated) time_generated oder cef-formatted-time_generated metadata.event_timestamp
Quelladresse (src) src principal.ip
Zieladresse (dst) dst target.ip
Regelname (rule) Regel security_result.rule_name
Quellzone (von) von additional.fields.key und additional.fields.value.string_value
Zielzone (bis) bis additional.fields.key und additional.fields.value.string_value
Eingangsschnittstelle (inbound_if) inbound_if additional.fields.key und additional.fields.value.string_value
Ausgangsschnittstelle (outbound_if) outbound_if additional.fields.key und additional.fields.value.string_value
Aktion protokollieren (Logset) logset additional.fields.key und additional.fields.value.string_value
Sitzungs-ID (sessionid) sessionid network.session_id
Anzahl der Wiederholungen (repeatcnt) repeatcnt additional.fields.key und additional.fields.value.string_value
Quellport (sport) sport principal.port
Zielport (dport) dport target.port
IP-Protokoll (proto) Proto network.ip_protocol (enum)
Aktion (action) Aktion security_result.action_details
security_result.action
Gerätegruppenhierarchie (dg_hier_level_1 bis dg_hier_level_4) dg_hier_level_1 bis dg_hier_level_4 additional.fields.key und additional.fields.value.string_value
Gerätename (device_name) device_name intermediary.hostname
Sequenznummer (seqno) seqno metadata.product_log_id
SCTP-Verbindungs-ID (assoc_id) assoc_id additional.fields.key und additional.fields.value.string_value
Payload Protocol ID (ppid) ppid additional.fields.key und additional.fields.value.string_value
Schweregrad (severity) die Ausprägung security_result.severity und security_result.severity_details
SCTP-Chunk-Typ (sctp_chunk_type) sctp_chunk_type additional.fields.key und additional.fields.value.string_value
SCTP-Ereignistyp (sctp_event_type) sctp_event_type additional.fields.key und additional.fields.value.string_value
SCTP-Bestätigungs-Tag 1 (verif_tag_1) verif_tag_1 additional.fields.key und additional.fields.value.string_value
SCTP-Bestätigungs-Tag 2 (verif_tag_2) verif_tag_2 additional.fields.key und additional.fields.value.string_value
SCTP-Ursachencode (sctp_cause_code) sctp_cause_code additional.fields.key und additional.fields.value.string_value
Diameter-App-ID (diam_app_id) diam_app_id additional.fields.key und additional.fields.value.string_value
Befehlscode für Durchmesser (diam_cmd_code) diam_cmd_code additional.fields.key und additional.fields.value.string_value
AVP-Code für Durchmesser (diam_avp_code) diam_avp_code additional.fields.key und additional.fields.value.string_value
SCTP-Stream-ID (stream_id) stream_id additional.fields.key und additional.fields.value.string_value
Grund für das Ende der SCTP-Verbindung (assoc_end_reason) assoc_end_reason additional.fields.key und additional.fields.value.string_value
Op-Code (op_code) op_code additional.fields.key und additional.fields.value.string_value
SCCP-SSN des Anrufers (sccp_calling_ssn) sccp_calling_ssn additional.fields.key und additional.fields.value.string_value
SCCP Calling Party Global Title (sccp_calling_gt) sccp_calling_gt additional.fields.key und additional.fields.value.string_value
SCTP-Filter (sctp_filter) sctp_filter additional.fields.key und additional.fields.value.string_value
SCTP-Chunks Chunks additional.fields.key und additional.fields.value.string_value
Gesendete SCTP-Chunks (chunks_sent) chunks_sent additional.fields.key und additional.fields.value.string_value
Empfangene SCTP-Chunks (chunks_received) chunks_received additional.fields.key und additional.fields.value.string_value
Pakete (packets) Pakete additional.fields.key und additional.fields.value.string_value
UUID für Regel (rule_uuid) rule_uuid security_result.rule_id
Virtuelles System (vsys) vsys intermediary.asset.attribute.labels.key/value
Name des virtuellen Systems (vsys_name) vsys_name intermediary.asset.attribute.labels.key/value
Gesendete Pakete (pkts_sent) pkts_sent network.sent_packets
Empfangene Pakete (pkts_received) pkts_received network.received_packets

Audit

CSV-Feld CEF-Feld LEEF-Feld Schlüssel für Google Security Operations-Label UDM-Feld
Generierungszeit metadata.event_timestamp
Bedrohungs-/Inhaltstyp (Untertyp) metadata.product_event_type
Ereignis-ID principal.application
Objekt principal.user.userid
CLI-Befehl principal.process.command_line
Schweregrad security_result.severity
Seriennummer intermediary.asset.hardware.serial_number

Feldzuordnung – Referenz: Protokolltypen zu UDM-Ereignistyp

In der folgenden Tabelle sind die Palo Alto Networks-Firewall-Logtypen und die entsprechenden UDM-Ereignistypen aufgeführt.

Logtyp UDM-Ereignistyp
Traffic NETWORK_CONNECTION
Bedrohung NETWORK_CONNECTION
URL-Filter NETWORK_CONNECTION
WildFire NETWORK_CONNECTION

WildFire-Übermittlungsprotokolle sind ein Untertyp des Threat-Protokolltyps und verwenden dasselbe Syslog-Format.

Datenfilterung NETWORK_CONNECTION
Tunnel NETWORK_CONNECTION
GTP NETWORK_CONNECTION
Konfiguration SETTING_MODIFICATION/SETTING_CREATION/SETTING_DELETION/SETTING_UNCATEGORIZED

Der Wert des Felds „Befehl (cmd)“ bestimmt die Zuordnung des UDM-Ereignistyps. Wenn der Wert des Felds „cmd“ „add“ oder „clone“ ist, wird „SETTING_CREATION“ festgelegt.

Wenn der Wert des Felds „cmd“ „delete“ ist, wird „SETTING_DELETION“ festgelegt.

Wenn der Wert des Felds „cmd“ „edit“, „move“, „rename“, „set“ oder „commit“ ist, wird SETTING_MODIFICATION festgelegt.

Wenn der Wert des Felds „cmd“ keine Werte enthält, wird SETTING_UNCATEGORIZED festgelegt.

System

Wenn der Untertypwert „dhcp“ ist, wird NETWORK_DHCP festgelegt.

Wenn der Untertypwert „auth“ ist, wird USER_LOGIN festgelegt.

Wenn der Wert für „description“ „logged in“ lautet, wird USER_LOGIN festgelegt.

Wenn der Wert der Beschreibung „logged out“ lautet, wird USER_LOGOUT festgelegt.

Für andere Werte des Subtyps wird GENERIC_EVENT festgelegt.

HIP-Abgleich NETWORK_CONNECTION
IP-Tag GENERIC_EVENT
User-ID USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED

Wenn der Untertypwert „login“ ist, wird USER_LOGIN festgelegt.

Wenn der Untertypwert „logout“ ist, wird USER_LOGOUT festgelegt.

Wenn der Untertyp keinen Wert enthält, wird USER_UNCATEGORIZED festgelegt.

Entschlüsselung NETWORK_CONNECTION
Authentifizierung GENERIC_EVENT
SCTP NETWORK_CONNECTION
Audit GENERIC_EVENT

UDM-Zuordnungsdelta

UDM-Mapping-Delta-Referenz: Palo Alto Networks Firewall

In der folgenden Tabelle sind die Unterschiede zwischen der alten UDM-Zuordnung von Palo Alto Networks Firewall und der neuen UDM-Zuordnung von Palo Alto Networks Firewall aufgeführt.

UDM Event Type Delta

Log type Old UDM Event Type New UDM Event Type
WildFire NETWORK_CONNECTION SCAN_UNCATEGORIZED
Data Filtering NETWORK_CONNECTION NETWORK_UNCATEGORIZED
Authentication STATUS_UPDATE STATUS_UNCATEGORIZED

UDM Field Mapping Delta

Log Type Old UDM Mapping CSV Log Field CEF Log Field LEEF Log Field New UDM Mapping
System intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
System about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
System about.labels.key/value additional.fields.key/value.string_value Object (object) fname Filename target.resource.name
System Description (opaque) msg msg metadata.description
System principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
System intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
Config intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Config about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
Config principal.process.command_line Configuration Path (path) msg ConfigurationPath principal.process.command_line
Config principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
Config intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
Config principal.asset.attribute.labels.key/value Device Group (dg_id) PanOSFWDeviceGroup target.asset.attribute.labels
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Threat/Wildfire target.file.full_path target.url target.hostname URL/Filename (misc) request Miscellaneous target.file.names target.url
Threat/Wildfire about.file.sha1/md5/sha256 File Digest (filedigest) fileHash FileDigest target.file.sha1/md5/sha256
Threat/Wildfire about.file.mime_type File Type (filetype) fileType FileType target.file.mime_type
Threat/Wildfire principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Threat/Wildfire principal.user.product_object_id Source VM UUID (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
Threat/Wildfire target.user.product_object_id Destination VM UUID (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value HTTP Headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
Threat/Wildfire principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
Threat/Wildfire principal.asset.software.version Source Device OS Version (src_osversion) PanSrcDeviceOSv principal.platform_version
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
Threat/Wildfire target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
Threat/Wildfire metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Reason (reason) PanReasonFilteringAction security_result.summary
Traffic about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value Packets Sent (pkts_sent) PanOSPacketsSent srcPackets network.sent_packets
Traffic about.labels.key/value additional.fields.key/value.string_value Packets Received (pkts_received) PanOSPacketsReceived dstPackets network.received_packets
Traffic principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
Traffic principal.asset.platform_software.platform(enum) principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
Traffic target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
Traffic about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
Traffic about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
Traffic about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
Traffic metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
User-ID about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
User-ID principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
User-ID principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID intermediary.resource.product_object_id
User-ID principal.user.userid principal.administrative_domain principal.user.email_addresses User by Source (userbysource) PanOSUserBySource target.user.userid target.user.email_addresses
User-ID metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
HIP Match intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
HIP Match about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
HIP Match about.labels.key/value additional.fields.key/value.string_value HIP (matchname) cat HIP target.resource.attribute.labels
HIP Match about.labels.key/value additional.fields.key/value.string_value HIP Type (matchtype) Device Event Class ID (Header) HIPType target.resource.attribute.labels
HIP Match principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
HIP Match intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
HIP Match principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
HIP Match principal.asset.product_object_id Host ID (hostid) PanOSHostID principal.asset.asset_id
HIP Match metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
IP-Tag intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
IP-Tag about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
IP-Tag principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOsVsysName vSrcName target.asset.attribute.labels
IP-Tag intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
IP-Tag principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
IP-Tag metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Decryption target.application Application (app) app network.application_protocol
Decryption about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 intermediary.asset.attribute.labels
Decryption principal.asset.asset_id Source VM UUID (src_uuid) PanOSSourceUUID principal.asset.product_object_id
Decryption target.asset.asset_id Destination VM UUID (dst_uuid) PanOSDestinationUUID target.asset.product_object_id
Decryption about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanOSContainerID intermediary.resource.product_object_id
Decryption about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanOSContainerNameSpace target.resource.attribute.labels additional.fields.key/value.string_value
Decryption about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanOSContainerName target.resource.name
Decryption metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanOSSourceDeviceCategory principal.asset.category
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanOSSourceDeviceModel principal.asset.hardware.model
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanOSSourceDeviceVendor principal.asset.hardware.manufacturer
Decryption principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanOSSourceDeviceOSFamily principal.platform
Decryption principal.asset.software.version Source Device OS Version (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanOSDestinationDeviceCategory target.asset.category
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanOSDestinationDeviceModel target.asset.hardware.model
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanOSDestinationDeviceVendor target.asset.hardware.manufacturer
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanOSDestinationDeviceOSFamily target.platform
Decryption target.asset.software.version Destination Device OS Version (dst_osversion) PanOSDestinationDeviceOSVersion target.platform_version
Decryption principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) intermediary.asset.attribute.labels
Decryption principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
Tunnel about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Tunnel principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Tunnel about.labels.key/value additional.fields.key/value.string_value Packets Sent (pkts_sent) PanOSPacketsSent srcPackets network.sent_packets
Tunnel about.labels.key/value additional.fields.key/value.string_value Packets Received (pkts_received) PanOSPacketsReceived dstPackets network.received_packets
Tunnel target.ip Remote User IP (remote_user_ip) PanOSRmtUserIP principal.ip
Tunnel target.labels.key/value additional.fields.key/value.string_value Remote User ID (remote_user_id) PanOSRmtUserID principal.user.userid
Tunnel metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Authentication about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Authentication target.user.user_display_name Normalize User (normalize_user) cs2 NormalizeUser target.user.user_display_name
Authentication about.labels.key/value additional.fields.key/value.string_value Object (object) fname ObjectName target.resource.name
Authentication about.labels.key/value additional.fields.key/value.string_value Authentication Policy (authpolicy) cs4 AuthPolicy additional.fields.key/value.string_value
Authentication principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Authentication principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
Authentication metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res _timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanOSSourceDeviceCategory principal.asset.category
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanOSSourceDeviceModel principal.asset.hardware.model
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanOSSourceDeviceVendor principal.asset.hardware.manufacturer
Authentication principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanOSSourceDeviceOSFamily principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value
Authentication principal.asset.software.version Source Device OS Version (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
URL about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
URL target.file.full_path target.url URL/Filename (misc) Miscellaneous target.file.names target.url
URL about.labels.key/value additional.fields.key/value.string_value Category (category) cs2 URLCategory security_result.category_details
URL about.file.sha1/md5/sha256 filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
URL about.file.mime_type filetype (filetype) target.file.mime_type
URL about.labels.key/value additional.fields.key/value.string_value xff (xff) PanOSXForwarderfor identSrc principal.ip
URL principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
URL about.url file_url (file_url) target.url
URL principal.asset.asset_id Source VM UUID (src_uuid) SrcUUID principal.asset.product_object_id
URL target.asset.asset_id Destination VM UUID (dst_uuid) DstUUID target.asset.product_object_id
URL about.labels.key/value additional.fields.key/value.string_value http_headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
URL about.labels.key/value additional.fields.key/value.string_value UUID for rule (rule_uuid) PanOSRuleUUID security_result.rule_id
URL about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
URL principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
URL principal.asset.software.version Source Device OS Version (src_osversion) PanSrcDeviceOSv principal.platform_version
URL principal.labels.key/value additional.fields.key/value.string_value Source Hostname (src_host) PanSrcHostname principal.hostname
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
URL target.asset.platform_software.platform target.labels.key/value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
URL target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
URL about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
URL about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
URL about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
URL about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
URL metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Res Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
URL about.labels.key/value additional.fields.key/value.string_value Reason (reason) PanReasonFilteringAction security_result.summary
Data about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Data target.file.full_path target.url URL/Filename (misc) Miscellaneous target.file.names target.url
Data about.labels.key/value additional.fields.key/value.string_value Category (category) cs2 URLCategory security_result.category_details
Data about.file.sha1/md5/sha256 filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
Data about.file.mime_type filetype (filetype) target.file.mime_type
Data about.labels.key/value additional.fields.key/value.string_value xff (xff) principal.ip
Data principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Data about.url file_url (file_url) target.url
Data principal.asset.asset_id Source VM UUID (src_uuid) SrcUUID principal.asset.product_object_id
Data target.asset.asset_id Destination VM UUID (dst_uuid) DstUUID target.asset.product_object_id
Data about.labels.key/value additional.fields.key/value.string_value http_headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
Data about.labels.key/value additional.fields.key/value.string_value UUID for rule (rule_uuid) PanOSRuleUUID security_result.rule_id
Data about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) network.application_protocol_version
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) principal.asset.category
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) principal.asset.hardware.model
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) principal.asset.hardware.manufacturer
Data principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) principal.platform
Data principal.asset.software.version Source Device OS Version (src_osversion) principal.platform_version
Data principal.labels.key/value additional.fields.key/value.string_value Source Hostname (src_host) principal.hostname
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) target.asset.category
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) target.asset.hardware.model
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) target.asset.hardware.manufacturer
Data target.asset.platform_software.platform target.labels.key/value Destination Device OS Family (dst_osfamily) target.platform
Data target.asset.software.version Destination Device OS Version (dst_osversion) target.platform_version
Data about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) intermediary.resource.product_object_id
Data about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) target.resource.attribute.labels
Data about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) target.resource.name
Data about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) principal.asset.asset_id
Data metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Res Timestamp (high_res_timestamp) additional.fields.key/value.string_value
Data about.labels.key/value additional.fields.key/value.string_value Reason (reason) security_result.summary
GlobalProtect about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) PanOSVirtualSystem intermediary.asset.attribute.labels
GlobalProtect principal.user.email_address principal.user.userid principal.administrative_domain Source User (srcuser) PanOSSourceUserName target.user.email_address target.user.userid
GlobalProtect principal.asset.platform_software.platform(enum) Client OS (client_os) PanOSEndpointOSType principal.platform
GlobalProtect principal.asset.platform_software.platform_version Client OS Version (client_os_ver) PanOSEndpointOSVersion principal.platform_version
GlobalProtect metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
GlobalProtect about.labels.key/value additional.fields.key/value.string_value Gateway Name (gateway) PanOSAttemptedGateways target.resource.name
GlobalProtect principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) intermediary.asset.attribute.labels
GlobalProtect target.hostname Device Name (device_name) intermediary.hostname
GlobalProtect principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
CORRELATION about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) VirtualSystem intermediary.asset.attribute.labels
CORRELATION principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) vSrcName intermediary.asset.attribute.labels
CORRELATION principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) VirtualSystemID intermediary.resource.product_object_id
GTP additional.fields.key/value.string_value Virtual System (vsys) intermediary.asset.attribute.labels
GTP target.ip Remote User IP (remote_user_ip) principal.ip
GTP additional.fields.key/value.string_value Remote User ID (remote_user_id) principal.user.userid
GTP metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) additional.fields.key/value.string_value

Palo Alto Networks Firewall Strata Logging Service

Übersicht

Der Palo Alto Networks® Strata Logging Service bietet cloudbasierten, zentralen Protokollspeicher und ‑aggregation für Ihre lokalen, virtuellen (private Cloud und öffentliche Cloud) Firewalls, für Prisma Access und für cloudbasierte Dienste wie Cortex XDR.Der Strata Logging Service ist sicher, robust und fehlertolerant und sorgt dafür, dass Ihre Protokolldaten aktuell und verfügbar sind, wenn Sie sie benötigen. Sie bietet eine skalierbare Logging-Infrastruktur, sodass Sie keine Log Collectors planen und bereitstellen müssen, um Ihre Anforderungen an die Logaufbewahrung zu erfüllen. Wenn Sie bereits lokale Log Collectors haben, kann der neue Strata Logging Service Ihre vorhandene Einrichtung ergänzen. Sie können Ihre vorhandene Infrastruktur für die Protokollerfassung mit dem cloudbasierten Strata Logging Service erweitern, um die Betriebskapazität mit dem Wachstum Ihres Unternehmens zu steigern oder den Kapazitätsbedarf für neue Standorte zu decken.Mit diesem Dienst übernimmt Palo Alto Networks die laufende Wartung und Überwachung der Protokollinfrastruktur, sodass Sie sich auf Ihr Unternehmen konzentrieren können.

  • Prüfen Sie die Logformate und PAN-OS-Versionen, die vom Strata Logging Service-Parser unterstützt werden. In der folgenden Tabelle sind die Protokollformate und die entsprechenden PAN-OS-Versionen aufgeführt, die vom Strata Logging Service-Parser unterstützt werden:

    Log format PAN-OS-Version
    JSON 12.1
  • Prüfen Sie die Palo Alto Networks-Firewall-Logtypen, die vom Google SecOps-Parser unterstützt werden. Der Google SecOps-Parser unterstützt die folgenden Palo Alto Networks-Firewall-Logtypen:

    • Traffic
    • Bedrohung
    • Tunnelinspektion
    • System
    • Übereinstimmung mit dem HIP
    • IP-Tag
    • User-ID
    • Entschlüsselung
    • Authentifizierung
    • URL-Filter
    • GlobalProtect

Bereitstellung des Strata Logging-Dienstes

Senden von Logs an den Strata Logging Service starten:

So senden Sie Logs an den Strata Logging Service:

  1. Installieren einer unterstützten PAN‑OS®-Version
  2. Strata Logging Service aktivieren: Bei der Aktivierung von Strata Logging Service wird das Zertifikat bereitgestellt, das die Firewalls für eine sichere Verbindung zu Strata Logging Service benötigen.
  3. Firewalls in Strata Logging Service einbinden – mit oder ohne Panorama

Eine ausführliche Anleitung finden Sie in der Dokumentation.

Logs vom Strata Logging Service weiterleiten

Um Ihre Anforderungen an die langfristige Speicherung, Berichterstellung und Überwachung oder an rechtliche und Compliance-Anforderungen zu erfüllen, können Sie den Strata Logging Service so konfigurieren, dass Logs an einen HTTPS-Server oder an die folgenden SIEMs weitergeleitet werden:

  1. Exabeam
  2. Google Chronicle
  3. Microsoft Sentinel
  4. Splunk HTTP Event Collector (HEC)

Verwenden Sie die HTTPS-Weiterleitungsmethode, um die Logs über den Strata Logging Service weiterzuleiten. Weitere Informationen finden Sie in dieser Dokumentation.

Unterstützte Logformate

Der Firewall-Parser für den Palo Alto Networks Strata Logging Service unterstützt Logs im JSON-Format.

Unterstützte Beispiellogs

  • JSON

    {"source": "Palo Alto Networks FLS LF", "host": "dummy-loghost", "time": "1730265996460", "event": {"TimeReceived": "2024-10-30T05:25:50.000000Z", "DeviceSN": "no-serial", "LogType": "TRAFFIC", "Subtype": "end", "ConfigVersion": "10.2", "TimeGenerated": "2024-10-30T05:25:40.000000Z", "SourceAddress": "198.51.100.6", "DestinationAddress": "198.51.100.6", "NATSource": "", "NATDestination": "", "Rule": "egress-dns-ping-traceroute", "SourceUser": null, "DestinationUser": null, "Application": "dns-base", "VirtualLocation": "vsys1", "FromZone": "VA8280-RN", "ToZone": "inter-fw", "InboundInterface": "tunnel.101", "OutboundInterface": "tunnel.4005", "LogSetting": "Cortex Data Lake", "SessionID": 754194, "RepeatCount": 1, "SourcePort": 53578, "DestinationPort": 53, "NATSourcePort": 0, "NATDestinationPort": 0, "Protocol": "udp", "Action": "allow", "Bytes": 214, "BytesSent": 72, "BytesReceived": 142, "PacketsTotal": 2, "SessionStartTime": "2024-10-30T05:25:10.000000Z", "SessionDuration": 0, "URLCategory": "any", "SequenceNo": 7382192512716388639, "SourceLocation": "198.51.100.6-198.51.255.255", "DestinationLocation": "198.51.100.6-198.51.255.255", "PacketsSent": 1, "PacketsReceived": 1, "SessionEndReason": "aged-out", "DGHierarchyLevel1": 65537, "DGHierarchyLevel2": 65538, "DGHierarchyLevel3": 65541, "DGHierarchyLevel4": 0, "VirtualSystemName": "", "DeviceName": "VA8280-RN", "ActionSource": "from-policy", "SourceUUID": null, "DestinationUUID": null, "IMSI": 0, "IMEI": null, "ParentSessionID": 0, "ParentStarttime": "1970-01-01T00:00:00.000000Z", "Tunnel": "N/A", "EndpointAssociationID": 72057594037927936, "ChunksTotal": 0, "ChunksSent": 0, "ChunksReceived": 0, "RuleUUID": "95cfc3cc-cb00-4758-af1d-de9ab5f07f97", "HTTP2Connection": 0, "LinkChangeCount": 0, "SDWANPolicyName": null, "LinkSwitches": null, "SDWANCluster": null, "SDWANDeviceType": null, "SDWANClusterType": null, "SDWANSite": null, "DynamicUserGroupName": null, "X-Forwarded-ForIP": null, "SourceDeviceCategory": null, "SourceDeviceProfile": null, "SourceDeviceModel": null, "SourceDeviceVendor": null, "SourceDeviceOSFamily": null, "SourceDeviceOSVersion": null, "SourceDeviceHost": null, "SourceDeviceMac": null, "DestinationDeviceCategory": null, "DestinationDeviceProfile": null, "DestinationDeviceModel": null, "DestinationDeviceVendor": null, "DestinationDeviceOSFamily": null, "DestinationDeviceOSVersion": null, "DestinationDeviceHost": null, "DestinationDeviceMac": null, "ContainerID": null, "ContainerNameSpace": null, "ContainerName": null, "SourceEDL": null, "DestinationEDL": null, "GPHostID": null, "EndpointSerialNumber": null, "SourceDynamicAddressGroup": null, "DestinationDynamicAddressGroup": null, "HASessionOwner": null, "TimeGeneratedHighResolution": "2024-10-30T05:25:41.009000Z", "NSSAINetworkSliceType": null, "NSSAINetworkSliceDifferentiator": null}}"
    

Referenz zur Feldzuordnung: Logfelder zu UDM-Feldern

In diesem Abschnitt wird beschrieben, wie der Parser Firewall-Logfelder des Palo Alto Networks Strata Logging Service für jeden Logtyp Google UDM-Ereignisfeldern zuordnet.

In den folgenden Abschnitten finden Sie eine Zuordnungsreferenz für jeden Logtyp:

System

In der folgenden Tabelle sind die Logfelder des Systemlogtyps und die entsprechenden UDM-Felder aufgeführt.

Log field UDM mapping
AgentContentVersion additional.fields.key/value.string_value
AgentDataCollectionStatus target.resource.attribute.labels
AgentID target.resource.attribute.labels
AgentIsolationStatus target.resource.attribute.labels
AgentStatus target.resource.attribute.labels
AgentVersion target.asset.software.version
ConfigVersion additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DeviceGroup target.group.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EndpointCPUArchitecture target.asset.hardware.cpu_platform
EndpointDeviceDomain target.asset.administrative_domain
EndpointDeviceName target.asset.hostname
EndpointIPaddress target.asset.ip
VDIEndpoint target.asset.attribute.labels
EndpointOSType additional.fields.key/value.string_value
EndpointOSVersion target.platform_version
AgentTimeZoneOffset additional.fields.key/value.string_value
EndpointUserDomain additional.fields.key/value.string_value
EndpointUserName target.user.user_display_name
EndpointUserUUID target.user.userid
EventComponent additional.fields.key/value.string_value
EventDescription metadata.description
EventName additional.fields.key/value.string_value
EventTime metadata.event_timestamp
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogCategory security_result.category_details
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
LogSourceID target.resource.attribute.labels
LogSourceName observer.asset.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
LogTime metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Severity security_result.severity
Subtype metadata.product_event_type
Template target.resource.attribute.labels
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

Bedrohung

In der folgenden Tabelle sind die Logfelder des Logtyps „Threat“ und die entsprechenden UDM-Felder aufgeführt.

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
ApplianceOrCloud additional.fields.key/value.string_value
CloudHostname additional.fields.key/value.string_value
CloudReportID security_result.detection_fields.key/value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DirectionOfAttack security_result.detection_fields.key/value
DomainEDL additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
FileName target.file.names
FileHash target.file.sha1
FileType additional.fields.key/value.string_value
FileURL target.url
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HostID principal.asset.asset_id
HTTP2Connection network.application_protocol_version
HTTPMethod network.http.method
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
LocalDeepLearningAnalyzed additional.fields.key/value.string_value
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
PartialHash additional.fields.key/value.string_value
PayloadProtocolID additional.fields.key/value.string_value
Packet additional.fields.key/value.string_value
PacketID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
RecipientEmail target.user.email_addresses
ReportID security_result.detection_fields.key/value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SenderEmail principal.user.email_addresses
SequenceNo metadata.product_log_id
SessionID network.session_id
Severity security_result.severity
SigFlags additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
EmailSubject network.email.subject
ApplicationTechnology additional.fields.key/value.string_value
ThreatCategory security_result.detection_fields.key/value.key/value
ThreatID security_result.threat_id
ThreatName security_result.threat_name
ThreatNameFirewall additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLDomain target.domain.name
URLCounter additional.fields.key/value.string_value
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
Verdict additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-ForIP principal.ip

Traffic

In der folgenden Tabelle sind die Logfelder des Logtyps „Traffic“ und die entsprechenden UDM-Felder aufgeführt.

Log field UDM mapping
Action security_result.action
ActionSource additional.fields.key/value.string_value
AIFwdError additional.fields.key/value.string_value
AITraffic additional.fields.key/value.string_value
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
BytesReceived network.received_bytes
BytesSent network.sent_bytes
Bytes additional.fields.key/value.string_value
ChunksReceived additional.fields.key/value.string_value
ChunksSent additional.fields.key/value.string_value
ChunksTotal additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
EndpointAssociationID additional.fields.key/value.string_value
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HASessionOwner additional.fields.key/value.string_value
GPHostID additional.fields.key/value.string_value
HTTP2Connection network.application_protocol_version
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsOffloaded additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
LinkChangeCount additional.fields.key/value.string_value
LinkSwitches additional.fields.key/value.string_value
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
SDWANPolicyName additional.fields.key/value.string_value
Protocol network.ip_protocol
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SDWANFECRatio additional.fields.key/value.string_value
SDWANCluster additional.fields.key/value.string_value
SDWANClusterType additional.fields.key/value.string_value
SDWANDeviceType additional.fields.key/value.string_value
SDWANSite additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionStartTime additional.fields.key/value.string_value
SessionTracker additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
SessionDuration network.session_duration
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLCategory target.url_metadata.categories
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-ForIP principal.ip

User-ID

In der folgenden Tabelle sind die Logfelder des Logtyps „User-ID“ und die entsprechenden UDM-Felder aufgeführt.

Log field UDM mapping
AuthFactorNo security_result.detection_fields.key/value
AuthenticatedUserDomain target.user.administrative_domain
AuthenticatedUserName target.user.userid
AuthenticatedUserUUID target.user.product_object_id
ConfigVersion additional.fields.key/value.string_value
CountofRepeats additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationPort target.port
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EventID additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsDuplicateUser additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MappingDataSource additional.fields.key/value.string_value
MappingDataSourceName additional.fields.key/value.string_value
MappingDataSourceType additional.fields.key/value.string_value
MappingTimeout additional.fields.key/value.string_value
MFAFactorType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SourceIP principal.ip
SourcePort principal.port
Subtype metadata.product_event_type
Tag additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
UGFlags additional.fields.key/value.string_value
User target.user.userid
UserGroupFound additional.fields.key/value.string_value
UserIdentifiedBySource additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Übereinstimmung mit dem HIP

In der folgenden Tabelle sind die Logfelder des Logtyps „HIP-Abgleich“ und die entsprechenden UDM-Felder aufgeführt.

Log field UDM mapping
ConfigVersion additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EndpointDeviceName principal.asset.hostname
EndpointOSType additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
HipMatchName target.resource.attribute.labels
HipMatchType target.resource.attribute.labels
HostID principal.asset.asset_id
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType metadata.product_event_type
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Source additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceIP principal.ip
SourceIPv6 principal.ip
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
TimestampDeviceIdentification principal.asset.first_seen_time
UUID additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

IP-Tag

In der folgenden Tabelle sind die Logfelder des Logtyps „IP-Tag“ und die entsprechenden UDM-Felder aufgeführt.

Log field UDM mapping
ConfigVersion additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EventID additional.fields.key/value.string_value
IPSubnetRange network.ip_subnet_range
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSetting target.resource.attribute.labels
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MappingDataSource additional.fields.key/value.string_value
MappingDataSourceSubType additional.fields.key/value.string_value
MappingDataSourceType additional.fields.key/value.string_value
MappingTimeout additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
RuleMatched security_result.rule_name
RuleMatchedUUID security_result.rule_id
SequenceNo metadata.product_log_id
SourceIP principal.ip
Subtype metadata.product_event_type
TagName additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

Entschlüsselung

In der folgenden Tabelle sind die Logfelder des Logtyps „Entschlüsselung“ und die entsprechenden UDM-Felder aufgeführt.

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
CertificateFlags additional.fields.key/value.string_value
CertificateSerial network.tls.server.certificate.serial
CertificateSize additional.fields.key/value.string_value
CertificateVersion network.tls.server.certificate.version
ChainStatus additional.fields.key/value.string_value
ApplicationCharacteristics additional.fields.key/value.string_value
ClientToFirewall additional.fields.key/value.string_value
CommonName additional.fields.key/value.string_value
CommonNameLength additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
Cpadding additional.fields.key/value.string_value
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
Domain target.hostname
EllipticCurve network.tls.curve
ErrorIndex additional.fields.key/value.string_value
ErrorMessage additional.fields.key/value.string_value
Fingerprint network.tls.server.certificate.md5/sha1/sha256
FirewallToClient additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsCertECDSA additional.fields.key/value.string_value
IsCertRSA additional.fields.key/value.string_value
IsCertCNTruncated additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
IsForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsIssuerCNTruncated additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
IsNAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
PacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsResumeSession additional.fields.key/value.string_value
IsRootCNTruncated additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSNITruncated additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
IssuerCommonName network.tls.server.certificate.issuer
IssuerNameLength additional.fields.key/value.string_value
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
TimeNotAfter additional.fields.key/value.string_value
TimeNotBefore additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
Padding additional.fields.key/value.string_value
Padding3 additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
PolicyName additional.fields.key/value.string_value
Protocol network.ip_protocol
ProxyType additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
RootCommonName additional.fields.key/value.string_value
RootCNLength additional.fields.key/value.string_value
RootStatus additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SessionID network.session_id
ServerNameIndication network.tls.client.server_name
SNILength additional.fields.key/value.string_value
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceOS additional.fields.key/value.string_value
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
ApplicationTechnology additional.fields.key/value.string_value
TimeReceivedManagementPlane additional.fields.key/value.string_value
TLSAuth additional.fields.key/value.string_value
TLSEncryptionAlgorithm additional.fields.key/value.string_value
TLSKeyExchange additional.fields.key/value.string_value
TLSVersion network.tls.version
ToZone additional.fields.key/value.string_value
Tpadding additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
Vpadding additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SourceDeviceCategory principal.asset.category
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Tunnel

In der folgenden Tabelle sind die Logfelder des Tunnel-Logtyps und die entsprechenden UDM-Felder aufgeführt.

Log field UDM mapping
AccessPointName additional.fields.key/value.string_value
Action security_result.action
ActionSource additional.fields.key/value.string_value
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
BytesReceived network.received_bytes
BytesSent network.sent_bytes
Bytes additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
LoggingServiceID additional.fields.key/value.string_value
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MobileAreaCode additional.fields.key/value.string_value
MobileBaseStationCode additional.fields.key/value.string_value
MobileCountryCode additional.fields.key/value.string_value
MobileIP additional.fields.key/value.string_value
MobileNetworkCode additional.fields.key/value.string_value
MobileSubscriberISDN additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceDifferentiator additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsDroppedMax additional.fields.key/value.string_value
PacketsDroppedStrict additional.fields.key/value.string_value
PacketsDroppedTunnel additional.fields.key/value.string_value
PacketsDroppedProtocol additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
ProtocolDataUnitsessionID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
RadioAccessTechnology additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionStartTime additional.fields.key/value.string_value
SessionTracker additional.fields.key/value.string_value
Severity security_result.severity
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
StandardPortsOfApp additional.fields.key/value.string_value
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
SessionDuration network.session_duration
Tunnel additional.fields.key/value.string_value
TunnelCauseCode additional.fields.key/value.string_value
TunnelEndpointID1 additional.fields.key/value.string_value
TunnelEndpointID2 additional.fields.key/value.string_value
TunnelEventCode additional.fields.key/value.string_value
TunnelEventType additional.fields.key/value.string_value
TunnelInspectionRule additional.fields.key/value.string_value
TunnelInterface additional.fields.key/value.string_value
TunnelMessageType additional.fields.key/value.string_value
TunnelRemoteIMSIID additional.fields.key/value.string_value
TunnelRemoteUserIP principal.ip
TunnelSessionsClosed additional.fields.key/value.string_value
TunnelSessionsCreated additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLCategory target.url_metadata.categories
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Authentifizierung

In der folgenden Tabelle sind die Logfelder des Logtyps „Authentifizierung“ und die entsprechenden UDM-Felder aufgeführt.

Log field UDM mapping
AuthenticationDescription security_result.description
AuthEvent metadata.description
AuthFactorNo security_result.detection_fields.key/value
AuthenticationPolicy security_result.detection_fields.key/value
AuthenticationProtocol additional.fields.key/value.string_value
AuthServerProfile additional.fields.key/value.string_value
AuthenticatedUserDomain target.administrative_domain
AuthenticatedUserName target.user.userid
AuthenticatedUserUUID target.user.product_object_id
ClientType additional.fields.key/value.string_value
ClientTypeName additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
IsPrismaNetworks additional.fields.key/value.string_value
Location target.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogType additional.fields.key/value.string_value
MFAAuthenticationID additional.fields.key/value.string_value
MFAVendor additional.fields.key/value.string_value
NormalizeUser target.user.user_display_name
Object target.resource.name
RuleMatched security_result.rule_name
RuleMatchedUUID security_result.rule_id
AuthCacheServiceRegion additional.fields.key/value.string_value
SessionID network.session_id
SourceDeviceCategory principal.asset.category
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceIP principal.ip
TimeGenerated metadata.event_timestamp
User target.user.userid
UserAgentString network.http.user_agent
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Subtype metadata.product_event_type
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

URL

In der folgenden Tabelle sind die Logfelder des URL-Logtyps und die entsprechenden UDM-Felder aufgeführt.

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
CloudHostname additional.fields.key/value.string_value
CloudReportID security_result.detection_fields.key/value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentType additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DirectionOfAttack security_result.detection_fields.key/value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
FileURL target.url
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HostID principal.asset.asset_id
HTTP2Connection network.application_protocol_version
HTTPHeaders additional.fields.key/value.string_value
HTTPMethod network.http.method
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
InlineMLVerdict additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
Packet additional.fields.key/value.string_value
PacketID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
Referer network.http.referral_url
HTTPRefererFQDN additional.fields.key/value.string_value
HTTPRefererPort additional.fields.key/value.string_value
HTTPRefererProtocol additional.fields.key/value.string_value
HTTPRefererURLPath additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionID network.session_id
Severity security_result.severity
SigFlags additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URL target.url_metadata.URL
URLCategory target.url_metadata.categories
URLCategoryList additional.fields.key/value.string_value
URLDomain target.domain.name
URLCounter additional.fields.key/value.string_value
UserAgent network.http.user_agent
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-For additional.fields.key/value.string_value
X-Forwarded-ForIP principal.ip

GlobalProtect

In der folgenden Tabelle sind die Logfelder des GlobalProtect-Logtyps und die entsprechenden UDM-Felder aufgeführt.

Log field UDM mapping
AttemptedGateways additional.fields.key/value.string_value
AuthMethod extensions.auth.auth_details
ConnectionMethod additional.fields.key/value.string_value
ConnectionErrorID additional.fields.key/value.string_value
ConnectionError additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
EndpointDeviceName principal.asset.hostname
GlobalProtectClientVersion additional.fields.key/value.string_value
EndpointOSType additional.fields.key/value.string_value
EndpointSN principal.asset.hardware.serial_number
EventIDValue additional.fields.key/value.string_value
Gateway target.resource.name
GatewayPriority additional.fields.key/value.string_value
GatewaySelectionType additional.fields.key/value.string_value
GlobalProtectGatewayLocation target.location.country_or_region
HostID principal.asset.asset_id
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LoginDuration network.session_duration
Description security_result.description
Portal target.hostname
PrivateIPv4 principal.ip
PrivateIPv6 principal.ip
ProjectName additional.fields.key/value.string_value
PublicIPv4 principal.nat_ip
PublicIPv6 principal.nat_ip
QuarantineReason security_result.summary
SequenceNo metadata.product_log_id
SourceRegion principal.location.country_or_region
SourceUserName principal.user.user_display_name
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SSLResponseTime additional.fields.key/value.string_value
Stage additional.fields.key/value.string_value
EventStatus additional.fields.key/value.string_value
LogSubtype metadata.product_event_type
TunnelType additional.fields.key/value.string_value
VirtualSystem intermediary.asset.attribute.labels
VirtualSystemName intermediary.asset.attribute.labels
EndpointOSVersion principal.platform_version
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType metadata.product_event_type
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualSystemID intermediary.resource.product_object_id

SCTP

In der folgenden Tabelle sind die Logfelder des SCTP-Logtyps und die entsprechenden UDM-Felder aufgeführt.

Log field UDM mapping
Action security_result.action
Application target.application
AssocationEndReason additional.fields.key/value.string_value
ChunksReceived additional.fields.key/value.string_value
ChunksSent additional.fields.key/value.string_value
ChunksTotal additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceClass target.asset.category
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationIP target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DiamAppID additional.fields.key/value.string_value
DiamAvpCode additional.fields.key/value.string_value
DiameterCommandCode additional.fields.key/value.string_value
DiameterRequestFlag additional.fields.key/value.string_value
DeviceName principal.asset.hostname
SCTPEventType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLFiltering additional.fields.key/value.string_value
IsWildfire additional.fields.key/value.string_value
LogAction additional.fields.key/value.string_value
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MapAppCode additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PayloadProtocolID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
Rule security_result.rule_name
RuleUUID security_result.rule_id
SccpCallingGt additional.fields.key/value.string_value
SccpCallingSSN additional.fields.key/value.string_value
SctpCauseCode additional.fields.key/value.string_value
SctpChunkType additional.fields.key/value.string_value
SctpFilter additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionTracker additional.fields.key/value.string_value
Severity security_result.severity
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceIP principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VerificationTag1 additional.fields.key/value.string_value
VerificationTag2 additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Audit

In der folgenden Tabelle sind die Logfelder des Audit-Logtyps und die entsprechenden UDM-Felder aufgeführt.

Log field UDM mapping
EventCategory network.http.method
EventDescription metadata.description
EventDestinationURL target.url
EventDestinationUserUserID target.user.userid
DestinationVendor additional.fields.key/value.string_value
EventDetails additional.fields.key/value.string_value
EventID metadata.product_log_id
EventName additional.fields.key/value.string_value
EventResult security_result.summary
EventSourceUserUserID principal.user.userid
EventTime metadata.event_timestamp
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
Subtype metadata.product_event_type
TSGID additional.fields.key/value.string_value
Vendor additional.fields.key/value.string_value
VendorSeverity security_result.severity_details

Feldzuordnung – Referenz: Protokolltypen zu UDM-Ereignistyp

In der folgenden Tabelle sind die Firewall-Logtypen von Palo Alto Networks Strata Logging Service und die entsprechenden UDM-Ereignistypen aufgeführt.

Logtyp UDM-Ereignistyp
Traffic NETWORK_CONNECTION
Bedrohung NETWORK_CONNECTION
URL-Filter NETWORK_CONNECTION
Tunnel NETWORK_CONNECTION
System

Wenn der Untertypwert „dhcp“ ist, wird NETWORK_DHCP festgelegt.

Wenn der Untertypwert „auth“ ist, wird USER_LOGIN festgelegt.

Wenn der Wert für „description“ „logged in“ lautet, wird USER_LOGIN festgelegt.

Wenn der Wert der Beschreibung „logged out“ lautet, wird USER_LOGOUT festgelegt.

Für andere Werte des Subtyps wird GENERIC_EVENT festgelegt.

HIP-Abgleich NETWORK_CONNECTION
IP-Tag GENERIC_EVENT
User-ID USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED

Wenn der Untertypwert „login“ ist, wird USER_LOGIN festgelegt.

Wenn der Untertypwert „logout“ ist, wird USER_LOGOUT festgelegt.

Wenn der Untertyp keinen Wert enthält, wird USER_UNCATEGORIZED festgelegt.

Entschlüsselung NETWORK_CONNECTION
Authentifizierung STATUS_UNCATEGORIZED
Globalprotect USER_LOGIN/USER_LOGOUT/USER_RESOURCE_ACCESS

Wenn der Untertypwert „auth“ ist, wird USER_LOGIN festgelegt.

Wenn der Untertypwert „logout“ ist, wird USER_LOGOUT festgelegt.

Wenn der Untertyp keinen Wert enthält, wird USER_RESOURCE_ACCESS festgelegt.

SCTP NETWORK_CONNECTION
Audit NETWORK_CONNECTION

Nächste Schritte

Benötigen Sie weitere Hilfe? Antworten von Community-Mitgliedern und Google SecOps-Experten erhalten