Collecter les journaux de pare-feu Palo Alto Networks
Pare-feu Palo Alto Networks
Présentation
Ce document explique comment configurer syslog et un transmetteur Google SecOps pour collecter les journaux de pare-feu Palo Alto Networks. Ce document explique également comment les champs de journaux de pare-feu Palo Alto Networks sont mappés aux champs du modèle de données unifié (UDM) Google SecOps. Pour obtenir une présentation de l'ingestion de données Google SecOps, consultez Ingestion de données dans Google SecOps. Une étiquette d'ingestion identifie l'analyseur qui normalise les données de journaux brutes au format UDM structuré. Les informations de ce document s'appliquent au parseur avec le libellé d'ingestion PAN_FIREWALL.
Avant de commencer
- Assurez-vous que le produit de pare-feu Palo Alto Networks est correctement déployé et configuré. Pour obtenir des instructions de configuration détaillées, consultez la documentation PAN-OS.
Pour comprendre les composants déployés pour collecter les journaux de pare-feu Palo Alto Networks, consultez l'architecture de déploiement. Le déploiement de chaque client peut différer de cette représentation et être plus complexe. Le schéma suivant montre comment configurer syslog sur un pare-feu Palo Alto Networks et installer un transmetteur Google SecOps sur un serveur Linux pour transférer les données de journaux vers Google SecOps. L'analyseur accepte les journaux écrits dans les formats de données suivants : valeurs séparées par une virgule (CSV), Common Event Format (CEF) et Log Event Extended Format (LEEF).
Vérifiez les formats de journaux et les versions de PAN-OS compatibles avec l'analyseur Google SecOps. Le tableau suivant répertorie les formats de journaux et les versions PAN-OS correspondantes compatibles avec l'analyseur Google SecOps :
Format du journal Version de PAN-OS CSV 10.1.3 CEF 10.0.0 LEEF 9.1.0 Vérifiez les types de journaux de pare-feu Palo Alto Networks compatibles avec l'analyseur Google SecOps. L'analyseur Google SecOps est compatible avec les types de journaux de pare-feu Palo Alto Networks suivants :
- Trafic
- Menace
- Envois WildFire
- Inspection de tunnels
- Config
- Système
- Correspondance HIP
- IP-Tag
- User-ID
- Déchiffrement
- Authentification
- Filtrage des URL
- Filtrage des données
- GlobalProtect
- Corrélation
- GTP
- SCTP
- Audit
Pour en savoir plus sur les types de journaux de pare-feu Palo Alto Networks, consultez Types de journaux PAN-OS.
Assurez-vous que tous les systèmes de l'architecture de déploiement sont configurés dans le fuseau horaire UTC.
Avant d'utiliser l'analyseur de pare-feu Palo Alto Networks, consultez les modifications apportées aux mappages de champs entre l'ancien analyseur et l'analyseur de pare-feu Palo Alto Networks actuel. Lors de la migration, assurez-vous que les règles, les recherches, les tableaux de bord ou les autres processus qui dépendent des champs d'origine utilisent les champs mis à jour.
Par exemple, dans la version précédente du parseur, le champ de journal
categoryest mappé au champ UDMsecurity_result.description. Dans l'analyseur de pare-feu Palo Alto Networks actuel, le champ de journalcategoryest mappé au champ UDMsecurity_result.category_details. Si vous migrez vers l'analyseur de pare-feu Palo Alto Networks actuel et que vous utilisez le champcategorydans vos règles, vous devez modifier les règles pour utiliser le champ UDMsecurity_result.category_detailsde l'analyseur actuel.
Configurer syslog et le redirecteur Google Security Operations
Pour configurer syslog et le transmetteur Google SecOps, procédez comme suit :
- Pour surveiller les journaux CSV, configurez le profil du serveur syslog. Pour en savoir plus, consultez Configurer le profil du serveur syslog. Lorsque vous configurez le profil du serveur syslog, spécifiez "Default" (Par défaut) comme format de journal personnalisé.
- Pour surveiller les journaux CEF, configurez le pare-feu Palo Alto Networks afin qu'il les transfère. Pour en savoir plus, téléchargez le guide d'intégration CEF de PAN-OS au format PDF et consultez la section "Configuration du NGFW Palo Alto Networks pour générer des événements CEF".
- Pour surveiller les journaux LEEF, configurez le profil du serveur syslog. Pour en savoir plus, consultez Transfert de journaux personnalisés au format LEEF.
Configurez le redirecteur Google SecOps pour envoyer les journaux à Google Security Operations. Pour en savoir plus, consultez Installer et configurer le transmetteur sur Linux. Voici un exemple de configuration d'un transmetteur Google SecOps :
- syslog: common: enabled: true data_type: PAN_FIREWALL batch_n_seconds: 10 batch_n_bytes: 1048576 tcp_address: 0.0.0.0:10518 connection_timeout_sec: 60
Configurer le transfert syslog sur le pare-feu PAN
Créer un profil de serveur syslog
- Connectez-vous à la console de gestion du pare-feu Palo Alto Networks.
- Accédez à Appareil > Profils de serveur > Syslog.
- Cliquez sur Ajouter pour créer un profil de serveur.
- Fournissez les informations de configuration suivantes :
- Nom : saisissez un nom descriptif (par exemple,
Google SecOps BindPlane). - Emplacement : sélectionnez le système virtuel (vsys) ou Partagé où ce profil sera disponible.
- Nom : saisissez un nom descriptif (par exemple,
- Cliquez sur Serveurs > Ajouter pour configurer le serveur Syslog.
- Fournissez les informations de configuration du serveur suivantes :
- Name (Nom) : saisissez un nom descriptif pour le serveur (par exemple,
BindPlane Agent). - Serveur Syslog : saisissez l'adresse IP de l'agent BindPlane.
- Transport : sélectionnez UDP ou TCP, selon la configuration de votre agent BindPlane (UDP est la valeur par défaut).
- Port : saisissez le numéro de port de l'agent BindPlane (par exemple,
514). - Format : sélectionnez BSD (par défaut) ou IETF, selon vos besoins.
- Installation : sélectionnez LOG_USER (par défaut) ou une autre installation si nécessaire.
- Name (Nom) : saisissez un nom descriptif pour le serveur (par exemple,
- Cliquez sur OK pour enregistrer le profil du serveur Syslog.
Facultatif : Configurer un format de journal personnalisé pour CEF ou LEEF
Si vous avez besoin de journaux CEF (Common Event Format) ou LEEF (Log Event Extended Format) au lieu de journaux CSV :
- Dans le profil du serveur Syslog, sélectionnez l'onglet Format de journal personnalisé.
- Configurez le format de journal personnalisé pour chaque type de journal (configuration, système, menace, trafic, URL, données, WildFire, tunnel, authentification, User-ID, correspondance HIP).
- Pour configurer le format CEF, consultez le Guide de configuration CEF de Palo Alto Networks.
- Cliquez sur OK pour enregistrer la configuration.
Créer un profil de transfert de journaux
- Accédez à Objets > Transfert de journaux.
- Cliquez sur Ajouter pour créer un profil de transfert de journaux.
- Fournissez les informations de configuration suivantes :
- Nom : saisissez un nom de profil (par exemple,
Google SecOps Forwarding). Si vous souhaitez que le pare-feu attribue automatiquement ce profil aux nouvelles règles et zones de sécurité, nommez-ledefault.
- Nom : saisissez un nom de profil (par exemple,
- Pour chaque type de journal que vous souhaitez transférer (trafic, menace, envoi WildFire, filtrage d'URL, filtrage de données, tunnel, authentification), configurez les éléments suivants :
- Cliquez sur Ajouter dans la section du type de journal concerné.
- Syslog : sélectionnez le profil de serveur syslog que vous avez créé (par exemple,
Google SecOps BindPlane). - Gravité du journal : sélectionnez les niveaux de gravité à transférer (par exemple, Tous).
- Cliquez sur OK pour enregistrer le profil de transfert des journaux.
Appliquer un profil de transfert de journaux aux règles de sécurité
- Accédez à Règles > Sécurité.
- Sélectionnez les règles de sécurité pour lesquelles vous souhaitez activer le transfert de journaux.
- Cliquez sur la règle pour la modifier.
- Accédez à l'onglet Actions.
- Dans le menu Transfert de journaux, sélectionnez le profil de transfert de journaux que vous avez créé (par exemple,
Google SecOps Forwarding). - Cliquez sur OK pour enregistrer la configuration de la stratégie de sécurité.
Configurer les paramètres de journaux pour les journaux système
- Accédez à Appareil > Paramètres du journal.
- Pour chaque type de journal (système, configuration, User-ID, HIP Match, Global Protect, IP-Tag, SCTP) et chaque niveau de gravité, sélectionnez le profil de serveur Syslog que vous avez créé.
- Cliquez sur OK pour enregistrer les paramètres de journal.
Valider les modifications
- Cliquez sur Commit (Valider) en haut de l'interface Web du pare-feu.
- Attendez que le commit se termine correctement.
- Vérifiez que les journaux sont envoyés à l'agent Bindplane en consultant la console Google SecOps pour les journaux de pare-feu Palo Alto Networks entrants.
Transférer des journaux vers Google SecOps à l'aide de l'agent Bindplane
- Installez et configurez une machine virtuelle Linux.
- Installez et configurez l'agent Bindplane sur Linux pour transférer les journaux vers Google SecOps. Pour savoir comment installer et configurer l'agent Bindplane, consultez les instructions d'installation et de configuration de l'agent Bindplane.
Si vous rencontrez des problèmes lors de la création de flux, contactez l'assistance Google SecOps.
Formats de journaux acceptés
L'analyseur de pare-feu Palo Alto Networks est compatible avec les journaux aux formats LEEF,CEF et CSV.
Exemples de journaux acceptés
LEEF
<14>Jan 22 02:20:19 device_host LEEF:1.0|Palo Alto Networks|PAN-OS Syslog Integration|10.2.12-h4|Microsoft MSOFFICE(52033)|ReceiveTime=2025/01/22 02:20:18|SerialNumber=01250100xxxx|cat=THREAT|Subtype=wildfire|devTime=Jan 22 2025 08:20:18 GMT|src=198.50.100.1|dst=198.50.100.2|srcPostNAT=198.50.100.3|dstPostNAT=198.50.100.4|RuleName=AZURE-US-NEW-CNF_Inbound_To_Azure-ALLOW|usrName=|SourceUser=|DestinationUser=|Application=smtp-base|VirtualSystem=vsys1|SourceZone=McD-Global-Zone|DestinationZone=Azure-Zone|IngressInterface=ae1.111|EgressInterface=ae2.409|LogForwardingProfile=Default-Traffic-Logging|SessionID=35331795|RepeatCount=1|srcPort=21578|dstPort=25|srcPostNATPort=0|dstPostNATPort=0|Flags=0x2000|proto=tcp|action=allow|Miscellaneous=\"......3...................xls\"|ThreatID=Microsoft MSOFFICE(52033)|URLCategory=malicious|sev=4|Severity=high|Direction=client-to-server|sequence=7462614601465681755|ActionFlags=0x8000000000000000|SourceLocation=198.50.100.1-198.50.100.255|DestinationLocation=United States|ContentType=|PCAP_ID=0|FileDigest=0ea04c99bf188c2e4207f60f92ca7c6f5088c7943ee63f45c50032bbd2bf7ea9|Cloud=demo.com|URLIndex=1|RequestMethod=|FileType=ms-office|Sender=sender@ab.myownpersonaldomain.com|Subject=\"............:.................................................................................-.........(Name)-2025-01-22...............:Y107202501220005, ............:........................, ...............:.........\"|Recipient=abc@demo.myownpersonaldomain.com|ReportID=117022282776|DeviceGroupHierarchyL1=143|DeviceGroupHierarchyL2=144|DeviceGroupHierarchyL3=39|DeviceGroupHierarchyL4=0|vSrcName=|DeviceName=device_host|SrcUUID=|DstUUID=|TunnelID=0|MonitorTag=|ParentSessionID=0|ParentStartTime=|TunnelType=N/A|ThreatCategory=N/A|ContentVer=WildFire-0CEF
14>1 2024-04-04T16:21:56+02:00 FW-PERIMETRAL-AVG-01 - - - - CEF:0|Palo Alto Networks|PAN-OS|10.1.10-h2|end|TRAFFIC|1|src=198.51.100.1 dst=198.51.100.2 srcTranslatedAddress=198.51.100.3 dstTranslatedAddress=198.51.100.4 rule=FW_USER_NATS2_APP suser= duser= app=bittorrent vs=vsys1 sz=INSIDE dz=EXTERNAL InboundInterface=ae2.2266 OutboundInterface=ae1 lp=log_forwarding sid=2935823 cnt=1 spt=6881 dpt=51413 srcTranslatedPort=0 dstTranslatedPort=0 flags=0x7a proto=udp act=allow tbytes=475 in=150 out=325 pkt=2 pktReceived=1 pktSent=1 start=Apr 04 2024 14:21:56 GMT stime=1206 urlcat=any externalId=externalId reason=aged-out DGl1=11 DGl2=161 DGl3=0 DGl4=0 VsysName=STONESOFT dvchost=FW-PERIMETRAL-AVG-01 cat=from-policy ActionFlags=0x8000000000000000 srcUUID= dstUUID= TunnelID=0 MonitorTag= ParentSessionID=0 ParentStartTime= TunnelType=N/A SCTPAssocID=0 SCTPChunks=0 SCTPChunkSent=0 SCTPChunksRcv=0 RuleUUID=746c3eb6-3d51-4679-8438-bd0e00e170a8 HTTP2Con=0 LinkChange=0 PolicyID= LinkDetail= SDWANCluster= SDWANDevice= SDWANClustype= SDWANSite= DynamicUsrgrp= XFFIP= srcDevCat= srcDevProf= srcDevModel= srcDevVendor= srcDevOS= srcDevOSv= srcHostname= srcMac= dstDevCat= dstDevProf= dstDevModel= dstDevVendor= dstDevOS= dstDevOSv= dstHostname= dstMac= ContainerName= PODNamespace= PODName= srcEDL= dstEDL= GPHostID= EPSerial= srcDAG= dstDAG= HASessionOwner= TimeHighRes=2024-04-04T16:21:56.250+02:00 ASServiceType= ASServiceDiff="CSV
1,2021/10/24 15:30:07,,CONFIG,0,2561,2021/10/24 15:30:07,198.51.100.0,,set,admin,Web,Succeeded, network virtual-router VR1,,VR1 { ecmp { algorithm { ip-modulo ; } } protocol { bgp { routing-options { graceful-restart { enable yes; } } enable no; } rip { enable no; } ospf { enable no; } ospfv3 { enable no; } } routing-table { ip { static-route { vr1-log { path-monitor { enable no; failure-condition any; hold-time 2; } nexthop { ip-address 198.51.100.0; } bfd { profile None; } interface ethernet1/1; metric 10; destination 0.0.0.0/0; route-table { unicast ; } } } } } interface [ ethernet1/1 ethernet1/2 ]; } ,7022390503849066572,0x0,0,0,0,0,,PA-VM,0,
Référence du mappage de champs : champs de journaux vers champs UDM
Cette section explique comment l'analyseur mappe les champs de journaux de pare-feu Palo Alto Networks aux champs d'événements UDM Google SecOps pour chaque type de journal. La clé de libellé Google SecOps fait référence au nom de la clé mappée au champ UDM Labels.key.
Par exemple, dans le cas du champ "Virtual System", le nom du champ est "cs3" au format CEF et "VirtualSystem" au format LEEF. Le champ UDM "about.labels.key" contient la valeur "vsys", et le champ UDM "about.labels.value" contient la valeur de ce champ. Certains noms de champs CEF ou LEEF ne correspondent pas aux noms de champs CSV. Dans ce cas, si vous ajoutez votre propre nom de variable dans le format de journal personnalisé du profil syslog, l'analyseur ne le mappe pas au champ UDM.
Pour obtenir des informations sur le mappage de chaque type de journal, consultez les sections suivantes :
- Système
- Config
- Menace/Incendie
- Trafic
- ID utilisateur
- Correspondance HIP
- Tag IP
- Déchiffrement
- Tunnel
- Authentification
- URL
- Données
- GlobalProtect
- Corrélation
- GTP
- SCTP
- Audit
Système
Le tableau suivant répertorie les champs de journaux du type de journal système et les champs UDM correspondants.
| Champ CSV | Champ CEF | Champ LEEF | Clé de libellé Google Security Operations | Champ UDM |
|---|---|---|---|---|
| Heure de réception (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si "Generate Time" est absent) |
|
| Numéro de série | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Type (type) | type (Header) | cat | metadata.product_event_type est défini sur "%{type} - %{subtype}". | |
| Type de menace/de contenu (sous-type) | subtype (Header) | Sous-type | metadata.product_event_type est défini sur "%{type} - %{subtype}". | |
| Heure de génération (time_generated ou cef-formatted-time_generated) | metadata.event_timestamp | |||
| Système virtuel (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| ID de l'événement (eventid) | cat | eventid | additional.fields.key et additional.fields.value.string_value | |
| Objet (objet) | fname | Nom de fichier | objet | target.resource.name |
| Module (module) | flexString2 | Module | module | additional.fields.key et additional.fields.value.string_value |
| Gravité (severity) | $number-of-severity(header) | Gravité | security_result.severity et security_result.severity_details | |
| Description (opaque) | Message | Message | metadata.description | |
| principal_user_userid (ce champ est extrait du champ "msg") | principal.user.userid | |||
| principal_ip3 (ce champ est extrait du champ "msg") | principal.ip | |||
| Motif (ce champ est extrait du champ "msg") | security_result.description | |||
| server_address (ce champ est extrait du champ "msg") | target.ip | |||
| server_profile (ce champ est extrait du champ "msg") | additional.fields.key et additional.fields.value.string_value | |||
| Numéro de séquence (seqno) | externalId | séquence | metadata.product_log_id | |
| Indicateurs d'action (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_1 à dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key et additional.fields.value.string_value |
| Nom du système virtuel (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nom de l'appareil (device_name) | dvchost | DeviceName | target.hostname | |
| Code temporel haute résolution (high_res_timestamp) | anOSTimeGeneratedHighResolution | additional.fields.key et additional.fields.value.string_value |
Config
Le tableau suivant liste les champs de journaux du type de journal de configuration et les champs UDM correspondants.
| Champ CSV | Champ CEF | Champ LEEF | Clé de libellé Google Security Operations | Champ UDM |
|---|---|---|---|---|
| Heure de réception (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si "Generate Time" est absent) |
|
| Numéro de série | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Type (type) | type (Header) | cat | metadata.product_event_type | |
| Type de menace/de contenu (sous-type) | subtype (Header) | metadata.product_event_type | ||
| Heure de génération (time_generated ou cef-formatted-time_generated) | metadata.event_timestamp | |||
| Hôte (host) | shost | src | principal.ip/hostname | |
| Système virtuel (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| Commande (cmd) | agir | Message | cmd | principal.process.command_line |
| Administrateur (admin) | duser | usrName | principal.user.userid | |
| Client (client) | destinationServiceName | Client | principal.application | |
| Résultat (result) | ID de signature (en-tête)(motif) | Résultat | security_result.summary | |
| Chemin de configuration (chemin) | Message | ConfigurationPath | principal.process.command_line | |
| Détails avant modification (before_change_detail) | cs1 | BeforeChangeDetail | before_change_detail | target.resource.attribute.labels.key/value |
| Détail après modification (after_change_detail) | cs2 | AfterChangeDetail | after_change_detail | target.resource.attribute.labels.key/value |
| Numéro de séquence (seqno) | externalId | séquence | metadata.product_log_id | |
| Indicateurs d'action (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_1 à dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key et additional.fields.value.string_value |
| Nom du système virtuel (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nom de l'appareil (device_name) | dvchost | DeviceName | target.hostname | |
| Groupe d'appareils (dg_id) | PanOSFWDeviceGroup | target.asset.attribute.labels.key/value | dg_id | principal.asset.attribute.labels.key/value |
| Commentaire d'audit (commentaire) | PanOSPolicyAuditComment | commentaire | additional.fields.key et additional.fields.value.string_value | |
| Code temporel haute résolution (high_res_timestamp) | additional.fields.key et additional.fields.value.string_value | |||
| Gravité (severity) | number-of-severity(header) | security_result.severity et security_result.severity_details |
Menace/WildFire
Le tableau suivant répertorie les champs de journaux du type de journal "Threat/WildFire" et les champs UDM correspondants.
| Champ CSV | Champ CEF | Champ LEEF | Clé de libellé Google Security Operations | Champ UDM |
|---|---|---|---|---|
| Heure de réception (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si "Generate Time" est absent) |
|
| Numéro de série | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Type (type) | type (Header) | cat | metadata.product_event_type | |
| Type de menace/de contenu (sous-type) | cat/subtype (en-tête) | Sous-type | metadata.product_event_type | |
| Heure de génération (time_generated ou cef-formatted-time_generated) | metadata.event_timestamp | |||
| Adresse source (src) | src | src | principal.ip | |
| Adresse de destination (dst) | dst | dst | target.ip | |
| Adresse IP source NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| Adresse IP de destination NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Nom de la règle (règle) | cs1 | RuleName | security_result.rule_name | |
| Utilisateur source (srcuser) | suser | SourceUser / usrName | principal.user.userid | |
| Utilisateur de destination (dstuser) | duser | DestinationUser | target.user.userid | |
| Application | application | Application | target.application | |
| Système virtuel (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zone source (de) | cs4 | SourceZone | de | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
| Zone de destination (à) | cs5 | DestinationZone | à | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
| Interface entrante (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
| Interface sortante (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
| Action de journalisation (ensemble de journaux) | cs6 | LogForwardingProfile | logset | additional.fields.key et additional.fields.value.string_value |
| ID de session (sessionid) | cn1 | SessionID | network.session_id | |
| Nombre de répétitions (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key et additional.fields.value.string_value |
| Port source (sport) | spt | srcPort | principal.port | |
| Port de destination (dport) | dpt | dstPort | target.port | |
| Port source NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Port de destination NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Indicateurs (flags) | flexString1 | Options | flags | additional.fields.key et additional.fields.value.string_value |
| Protocole IP (proto) | proto | proto | network.ip_protocol | |
| Action (action) | agir | action | security_result.action_details
security_result.action |
|
| URL/Nom de fichier (divers) | request | Autres | target.file.names (si le sous-type est "file", "virus", "wildfire-virus" ou "wildfire", le champ "misc" est mappé sur target.file.names) target.url (si le sous-type est "url", le champ "misc" est mappé sur target.url et target.hostname) |
|
| Nom de la menace/du contenu (threatid) | cat | ThreatID | security_result.threat_name | |
| Catégorie (catégorie) | cs2 | URLCategory | security_result.category_details | |
| Gravité (severity) | number-of-severity(header) | Gravité | security_result.severity et security_result.severity_details | |
| Direction (direction) | flexString2 | Direction | network.direction | |
| Numéro de séquence (seqno) | externalId | séquence | metadata.product_log_id | |
| Indicateurs d'action (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key et additional.fields.value.string_value |
| Pays source (srcloc) | SourceLocation | principal.location.country_or_region | ||
| Pays de destination (dstloc) | DestinationLocation | target.location.country_or_region | ||
| Type de contenu (contenttype) | ContentType | contenttype | additional.fields.key et additional.fields.value.string_value | |
| ID PCAP (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key et additional.fields.value.string_value |
| Condensé de fichier (filedigest) | fileHash | FileDigest | target.file.sha1/md5/sha256 | |
| Cloud (cloud) | filePath | Cloud | cloud | additional.fields.key et additional.fields.value.string_value |
| Index de l'URL (url_idx) | URLIndex | url_idx | additional.fields.key et additional.fields.value.string_value | |
| User-agent (user_agent) | network.http.user_agent | |||
| Type de fichier (filetype) | fileType | FileType | target.file.mime_type | |
| X-Forwarded-For (xff) | principal.ip | |||
| URL de provenance (referer) | network.http.referral_url | |||
| Expéditeur (sender) | suid | Expéditeur | network.email.from | |
| Objet (subject) | Message | Objet | network.email.subject | |
| Destinataire | duid | Destinataire | network.email.to | |
| ID du rapport (reportid) | oldFileId | ReportID | reportid | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_1 à dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key et additional.fields.value.string_value |
| Nom du système virtuel (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nom de l'appareil (device_name) | dvchost | DeviceName | intermediary.hostname | |
| UUID de la VM source (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id | |
| UUID de la VM de destination (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id | |
| Méthode HTTP (http_method) | RequestMethod | network.http.method | ||
| ID/IMSI du tunnel (tunnel_id/imsi) | PanOSTunnelID | TunnelID | tunnel_id/imsi | additional.fields.key et additional.fields.value.string_value |
| Surveiller le tag/l'IMEI (monitortag/imei) | PanOSMonitorTag | MonitorTag | monitortag/imei | additional.fields.key et additional.fields.value.string_value |
| ID de session parent (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Heure de début de la session parente (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key et additional.fields.value.string_value |
| Type de tunnel (tunnel) | PanOSTunnelType | TunnelType | tunnel | additional.fields.key et additional.fields.value.string_value |
| Catégorie de menace (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| Version du contenu (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key et additional.fields.value.string_value |
| ID d'association SCTP (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key et additional.fields.value.string_value | |
| ID du protocole de charge utile (ppid) | PanOSPPID | ppid | additional.fields.key et additional.fields.value.string_value | |
| En-têtes HTTP (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Liste des catégories d'URL (url_category_list) | PanOSURLCatList | url_category_list | additional.fields.key et additional.fields.value.string_value | |
| UUID de la règle (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| Connexion HTTP/2 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| Nom du groupe d'utilisateurs dynamique (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
|
| Adresse XFF (xff_ip) | PanXFFIP | principal.ip | ||
| Catégorie de l'appareil source (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Profil de l'appareil source (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
|
| Modèle de l'appareil source (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Fournisseur de l'appareil source (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Famille d'OS de l'appareil source (src_osfamily) | PanSrcDeviceOS | src_osfamily | principal.platform | |
| Version de l'OS de l'appareil source (src_osversion) | PanSrcDeviceOSv | principal.platform_version | ||
| Nom d'hôte source (src_host) | PanSrcHostname | principal.hostname | ||
| Adresse MAC source (src_mac) | PanSrcMac | principal.mac | ||
| Catégorie d'appareil de destination (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Profil de l'appareil de destination (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
|
| Modèle de l'appareil de destination (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Fournisseur de l'appareil de destination (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Famille d'OS de l'appareil de destination (dst_osfamily) | PanDstDeviceOS | dst_osfamily | target.platform | |
| Version de l'OS de l'appareil de destination (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Nom d'hôte de destination (dst_host) | PanDstHostname | target.hostname | ||
| Adresse MAC de destination (dst_mac) | PanDstMac | target.mac | ||
| ID du conteneur (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| Espace de noms du POD (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| Nom du POD (pod_name) | PanPODName | pod_name | target.resource.name | |
| Liste dynamique externe source (src_edl) | PanSrcEDL | src_edl | additional.fields.key et additional.fields.value.string_value | |
| Liste dynamique externe de destinations (dst_edl) | PanDstEDL | dst_edl | additional.fields.key et additional.fields.value.string_value | |
| ID de l'hôte (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Numéro de série de l'appareil de l'utilisateur (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| EDL de domaine (domain_edl) | PanDomainEDL | domain_edl | additional.fields.key et additional.fields.value.string_value | |
| Groupe d'adresses dynamiques sources (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Groupe d'adresses dynamiques de destination (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| Hachage partiel (partial_hash) | PanPartialHash | partial_hash | additional.fields.key et additional.fields.value.string_value | |
| Code temporel haute résolution (high_res timestamp) | PanTimeHighRes | high_res timestamp | additional.fields.key et additional.fields.value.string_value | |
| Motif (reason) | PanReasonFilteringAction | reason | security_result.summary | |
| Justification (justification) | PanJustification | justification | additional.fields.key et additional.fields.value.string_value | |
| Type de service de tranche (nssai_sst) | PanASServiceType | nssai_sst | additional.fields.key et additional.fields.value.string_value | |
| Sous-catégorie de l'application (subcategory_of_app) | subcategory_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Catégorie d'application (category_of_app) | category_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Technologie de l'application (technology_of_app) | technology_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Risque de l'application (risk_of_app) | risk_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Caractéristique de l'application (characteristic_of_app) | characteristic_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Conteneur d'application (container_of_app) | container_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Application SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Application tunnelisée (tunneled_app) | additional.fields.key et additional.fields.value.string_value | |||
| Type de flux (flow_type) | additional.fields.key et additional.fields.value.string_value | |||
| Nom du cluster (cluster_name) | intermediary.resource.name | |||
| État approuvé de l'application (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key et additional.fields.value.string_value |
Trafic
Le tableau suivant répertorie les champs de journal du type de journal de trafic et leurs champs UDM correspondants.
| Champ CSV | Champ CEF | Champ LEEF | Clé de libellé Google Security Operations | Champ UDM |
|---|---|---|---|---|
| Heure de réception (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si "Generate Time" est absent) |
|
| Numéro de série | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Type (type) | type (Header) | cat/Type | metadata.product_event_type | |
| Type de menace/de contenu (sous-type) | subtype (Header) | Sous-type | metadata.product_event_type | |
| Heure de génération (time_generated ou cef-formatted-time_generated) | start | metadata.event_timestamp | ||
| Adresse source (src) | src | src | principal.ip | |
| Adresse de destination (dst) | dst | dst | target.ip | |
| Adresse IP source NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| Adresse IP de destination NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Nom de la règle (règle) | cs1 | RuleName | security_result.rule_name | |
| Utilisateur source (srcuser) | suser | SourceUser | principal.user.userid | |
| Utilisateur de destination (dstuser) | duser | DestinationUser | target.user.userid | |
| Application | application | Application | target.application | |
| Système virtuel (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zone source (de) | cs4 | SourceZone | de | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
| Zone de destination (à) | cs5 | DestinationZone | à | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
| Interface entrante (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
| Interface sortante (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
| Action de journalisation (ensemble de journaux) | cs6 | LogForwardingProfile | logset | additional.fields.key et additional.fields.value.string_value |
| ID de session (sessionid) | cn1 | SessionID | network.session_id | |
| Nombre de répétitions (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key et additional.fields.value.string_value |
| Port source (sport) | spt | srcPort | principal.port | |
| Port de destination (dport) | dpt | dstPort | target.port | |
| Port source NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Port de destination NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Indicateurs (flags) | flexString1 | Options | flags | additional.fields.key et additional.fields.value.string_value |
| Protocole IP (proto) | proto | proto | network.ip_protocol | |
| Action (action) | agir | action | security_result.action_details
security_result.action |
|
| Octets (octets) | flexNumber1 | totalBytes | bytes | additional.fields.key et additional.fields.value.string_value |
| Octets envoyés (bytes_sent) | dans | srcBytes | network.sent_bytes | |
| Octets reçus (bytes_received) | interprétés. | dstBytes | network.received_bytes | |
| Paquets | cn2 | totalPackets | paquets | additional.fields.key et additional.fields.value.string_value |
| Heure de début (start) | StartTime | start | additional.fields.key et additional.fields.value.string_value | |
| Temps écoulé (elapsed) | cn3 | ElapsedTime | écoulé | network.session_duration.seconds |
| Catégorie (catégorie) | cs2 | URLCategory | security_result.category / security_result.category_details | |
| Numéro de séquence (seqno) | externalId | séquence | metadata.product_log_id | |
| Indicateurs d'action (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key et additional.fields.value.string_value |
| Pays source (srcloc) | SourceLocation | principal.location.country_or_region | ||
| Pays de destination (dstloc) | DestinationLocation | target.location.country_or_region | ||
| Paquets envoyés (pkts_sent) | PanOSPacketsSent | srcPackets | pkts_sent | network.sent_packets |
| Paquets reçus (pkts_received) | PanOSPacketsReceived | dstPackets | pkts_received | network.received_packets |
| Motif de fin de la session (session_end_reason) | reason | SessionEndReason | security_result.summary | |
| Hiérarchie des groupes d'appareils1 (dg_hier_level_1 à dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils 2 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils 3 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key et additional.fields.value.string_value |
| Nom du système virtuel (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nom de l'appareil (device_name) | dvchost | DeviceName | intermediary.hostname | |
| Source de l'action (action_source) | cat | ActionSource | action_source | additional.fields.key et additional.fields.value.string_value |
| UUID de la VM source (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id | |
| UUID de la VM de destination (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id | |
| ID de tunnel/IMSI (tunnelid/imsi) | PanOSTunnelID | TunnelID | tunnelid/imsi | additional.fields.key et additional.fields.value.string_value |
| Surveiller le tag/l'IMEI (monitortag/imei) | PanOSMonitorTag | MonitorTag | monitortag/imei | additional.fields.key et additional.fields.value.string_value |
| ID de session parent (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Heure de début du parent (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key et additional.fields.value.string_value |
| Type de tunnel (tunnel) | PanOSTunnelType | TunnelType | tunnel | additional.fields.key et additional.fields.value.string_value |
| ID d'association SCTP (assoc_id) | PanOSSCTPAssocID | assoc_id | additional.fields.key et additional.fields.value.string_value | |
| Blocs SCTP | PanOSSCTPChunks | chunks | additional.fields.key et additional.fields.value.string_value | |
| Blocs SCTP envoyés (chunks_sent) | PanOSSCTPChunkSent | chunks_sent | additional.fields.key et additional.fields.value.string_value | |
| Blocs SCTP reçus (chunks_received) | PanOSSCTPChunksRcv | chunks_received | additional.fields.key et additional.fields.value.string_value | |
| UUID de la règle (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| Connexion HTTP/2 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| Nombre de changements de lien dans l'application (link_change_count) | PanLinkChange | link_change_count | additional.fields.key et additional.fields.value.string_value | |
| ID de la règle (policy_id) | PanPolicyID | policy_id | additional.fields.key et additional.fields.value.string_value | |
| Commutateurs de lien (link_switches) | PanLinkDetail | link_switches | additional.fields.key et additional.fields.value.string_value | |
| Cluster SD-WAN (sdwan_cluster) | PanSDWANCluster | sdwan_cluster | additional.fields.key et additional.fields.value.string_value | |
| Type d'appareil SD-WAN (sdwan_device_type) | PanSDWANDevice | sdwan_device_type | additional.fields.key et additional.fields.value.string_value | |
| Type de cluster SD-WAN (sdwan_cluster_type) | PanSDWANClustype | sdwan_cluster_type | additional.fields.key et additional.fields.value.string_value | |
| Site SD-WAN (sdwan_site) | PanSDWANSite | sdwan_site | additional.fields.key et additional.fields.value.string_value | |
| Nom du groupe d'utilisateurs dynamique (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | additional.fields.key et additional.fields.value.string_value | |
| Adresse XFF (xff_ip) | PanXFFIP | principal.ip | ||
| Catégorie de l'appareil source (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Profil de l'appareil source (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
|
| Modèle de l'appareil source (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Fournisseur de l'appareil source (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Famille d'OS de l'appareil source (src_osfamily) | PanSrcDeviceOS | principal.platform | ||
| Version de l'OS de l'appareil source (src_osversion) | PanSrcDeviceOSv | principal.asset.software.version | ||
| Nom d'hôte source (src_host) | PanSrcHostname | principal.hostname | ||
| Adresse MAC source (src_mac) | PanSrcMac | principal.mac | ||
| Catégorie d'appareil de destination (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Profil de l'appareil de destination (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
|
| Modèle de l'appareil de destination (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Fournisseur de l'appareil de destination (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Famille d'OS de l'appareil de destination (dst_osfamily) | PanDstDeviceOS | dst_osfamily | target.platform | |
| Version de l'OS de l'appareil de destination (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Nom d'hôte de destination (dst_host) | PanDstHostname | target.hostname | ||
| Adresse MAC de destination (dst_mac) | PanDstMac | target.mac | ||
| ID du conteneur (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| Espace de noms du POD (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| Nom du POD (pod_name) | PanPODName | pod_name | target.resource.name | |
| Liste dynamique externe source (src_edl) | PanSrcEDL | src_edl | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
|
| Liste dynamique externe de destinations (dst_edl) | PanDstEDL | dst_edl | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
|
| ID de l'hôte (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Numéro de série de l'appareil de l'utilisateur (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| Groupe d'adresses dynamiques sources (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Groupe d'adresses dynamiques de destination (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| Propriétaire de la session (session_owner) | PanHASessionOwner | session_owner | additional.fields.key et additional.fields.value.string_value | |
| Code temporel haute résolution (high_res_timestamp) | PanTimeHighRes | additional.fields.key et additional.fields.value.string_value | ||
| Type de service de tranche (nsdsai_sst) | PanASServiceType | nsdsai_sst | additional.fields.key et additional.fields.value.string_value | |
| Un différenciateur de tranche (nsdsai_sd) | PanASServiceDiff | nsdsai_sd | additional.fields.key et additional.fields.value.string_value | |
| Sous-catégorie de l'application (subcategory_of_app) | subcategory_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Catégorie d'application (category_of_app) | category_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Technologie de l'application (technology_of_app) | technology_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Risque de l'application (risk_of_app) | security_result.severity | |||
| Caractéristique de l'application (characteristic_of_app) | characteristic_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Conteneur d'application (container_of_app) | container_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Application SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key et additional.fields.value.string_value | ||
| État approuvé de l'application (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Sous-catégorie de l'application (subcategory_of_app) | subcategory_of_app1 | additional.fields.key et additional.fields.value.string_value | ||
| Gravité (severity) | number-of-severity(header) | security_result.severity et security_result.severity_details |
User-ID
Le tableau suivant liste les champs de journaux du type de journal "user-id" et les champs UDM correspondants.
| Champ CSV | Champ CEF | Champ LEEF | Clé de libellé Google Security Operations | Champ UDM |
|---|---|---|---|---|
| Heure de réception (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si "Generate Time" est absent) |
|
| Numéro de série | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Type (type) | type (Header) | cat | metadata.product_event_type | |
| Type de menace/de contenu (sous-type) | subtype (Header) | Sous-type | metadata.product_event_type | |
| Heure de génération (time_generated ou cef-formatted-time_generated) | metadata.event_timestamp | |||
| Système virtuel (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Adresse IP source (ip) | src | src | principal.ip | |
| Utilisateur (utilisateur) | duser | usrName | target.user.userid
target.administrative_domain target.user.email_addresses |
|
| Nom de la source de données (datasourcename) | cs4 | DataSourceName | datasourcename | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
| ID de l'événement (eventid) | EventID | eventid | additional.fields.key et additional.fields.value.string_value | |
| Nombre de répétitions (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key et additional.fields.value.string_value |
| Seuil de délai d'inactivité | cn3 | TimeoutThreshold | délai avant expiration | additional.fields.key et additional.fields.value.string_value |
| Port source (beginport) | spt | srcPort | principal.port | |
| Port de destination (endport) | dpt | dstPort | target.port | |
| Source de données | cs5 | DataSource | source de données | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
| Type de source de données (datasourcetype) | cs6 | DataSourceType | datasourcetype | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
| Numéro de séquence (seqno) | externalId | séquence | metadata.product_log_id | |
| Indicateurs d'action (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key et additional.fields.value.string_value |
| Nom du système virtuel (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nom de l'appareil (device_name) | dvchost | DeviceName | intermediary.hostname | |
| ID du système virtuel (vsys_id) | cn2 | VirtualSystemID | intermediary.resource.product_object_id | |
| Type de facteur (factortype) | cs1 | FactorType | factortype | additional.fields.key et additional.fields.value.string_value |
| Heure de fin de la factorisation (factorcompletiontime) | end | FactorCompletionTime | factorcompletiontime | additional.fields.key et additional.fields.value.string_value |
| Numéro de facteur (factorno) | cn1 | FactorNumber | factorno | additional.fields.key et additional.fields.value.string_value |
| Indicateurs de groupe d'utilisateurs (ugflags) | PanOSUGFlags | ugflags | additional.fields.key et additional.fields.value.string_value | |
| Utilisateur par source (userbysource) | PanOSUserBySource | target.user.userid
target.administrative_domain target.user.email_addresses |
||
| Code temporel haute résolution (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key et additional.fields.value.string_value | ||
| Source de données d'origine (origindatasource) | additional.fields.key et additional.fields.value.string_value | |||
| Nom du cluster (cluster_name) | principal.resource.name | |||
| Gravité (severity) | number-of-severity(header) | security_result.severity et security_result.severity_details |
Correspondance HIP
Le tableau suivant répertorie les champs de journaux du type de journal "Correspondance HIP" et les champs UDM correspondants.
| Champ CSV | Champ CEF | Champ LEEF | Clé de libellé Google Security Operations | Champ UDM |
|---|---|---|---|---|
| Heure de réception (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si "Generate Time" est absent) |
|
| Numéro de série | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Type (type) | type (Header) | cat | metadata.product_event_type | |
| Type de menace/de contenu (sous-type) | subtype (Header) | Sous-type | ||
| Heure de génération (time_generated ou cef-formatted-time_generated) | start | startTime | metadata.event_timestamp | |
| Utilisateur source (srcuser) | suser | usrName | principal.user.userid | |
| Système virtuel (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| Nom de la machine (machinename) | shost | identHostName | principal.hostname | |
| Système d'exploitation (os) | cs2 | OS | principal.asset.platform_software.platform | |
| Adresse source (src) | src | identsrc | principal.ip | |
| HIP (matchname) | cat | HIP | matchname | target.resource.attribute.labels.key/value additional.fields.key et additional.fields.value.string_value |
| Nombre de répétitions (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key et additional.fields.value.string_value |
| Type de HIP (matchtype) | ID de classe d'événement de l'appareil (en-tête) | HIPType | matchtype | target.resource.attribute.labels.key/value additional.fields.key et additional.fields.value.string_value |
| Numéro de séquence (seqno) | externalId | séquence | metadata.product_log_id | |
| Indicateurs d'action (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key et additional.fields.value.string_value |
| Nom du système virtuel (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nom de l'appareil (device_name) | dvchost | DeviceName | target.hostname | |
| ID du système virtuel (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id | |
| Adresse système IPv6 (srcipv6) | c6a2 | srcipv6 | principal.asset.ip | |
| ID de l'hôte (hostid) | PanOSHostID | principal.asset.asset_id | ||
| Numéro de série de l'appareil de l'utilisateur (serialnumber) | PanOSEndpointSerialNumber | principal.asset.hardware.serial_number | ||
| Adresse MAC de l'appareil (mac) | PanOSEndpointMac | principal.asset.mac | ||
| Code temporel haute résolution (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key et additional.fields.value.string_value | ||
| Nom du cluster (cluster_name) | principal.resource.name | |||
| Gravité (severity) | number-of-severity(header) | security_result.severity et security_result.severity_details |
Tag d'adresse IP
Le tableau suivant répertorie les champs de journaux du type de journal "Tag d'adresse IP" et les champs UDM correspondants.
| Champ CSV | Champ CEF | Champ LEEF | Clé de libellé Google Security Operations | Champ UDM |
|---|---|---|---|---|
| Heure de réception (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si "Generate Time" est absent) |
|
| Numéro de série | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Type (type) | type (Header) | cat | metadata.product_event_type | |
| Type de menace/de contenu (sous-type) | subtype (Header) | Sous-type | metadata.product_event_type | |
| Heure de génération (time_generated ou cef-formatted-time_generated) | GenerateTime | metadata.event_timestamp | ||
| Système virtuel (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| Adresse IP source (ip) | src | src | principal.ip | |
| Nom de la balise (tag_name) | PanOSTagName | TagName | tag_name | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
| ID de l'événement (event_id) | PanOSEventID | EventID | event_id | additional.fields.key et additional.fields.value.string_value |
| Nombre de répétitions (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key et additional.fields.value.string_value |
| Délai avant expiration (timeout) | PanOSTimeout | TimeoutThreshold | délai avant expiration | additional.fields.key et additional.fields.value.string_value |
| Nom de la source de données (datasourcename) | PanOSDataSourceName | DataSourceName | datasourcename | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
| Type de source de données (datasource_type) | PanOSDataSourceType | DataSource | datasource_type | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
| Sous-type de source de données (datasource_subtype) | PanOSDataSourceSubType | DataSourceType | datasource_subtype | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
| Numéro de séquence (seqno) | externalId | séquence | metadata.product_log_id | |
| Indicateurs d'action (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key et additional.fields.value.string_value |
| Nom du système virtuel (vsys_name) | PanOsVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nom de l'appareil (device_name) | dvchost | DeviceName | target.hostname | |
| ID du système virtuel (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id | |
| Code temporel haute résolution (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key et additional.fields.value.string_value | ||
| Gravité (severity) | number-of-severity(header) | security_result.severity et security_result.severity_details | ||
| Nom du cluster (cluster_name) | principal.resource.name |
Déchiffrement
Le tableau suivant répertorie les champs de journaux du type de journal de déchiffrement et les champs UDM correspondants.
| Champ CSV | Champ CEF | Champ LEEF | Clé de libellé Google Security Operations | Champ UDM |
|---|---|---|---|---|
| Heure de réception (receive_time ou cef-formatted-receive_time) | rt | metadata.collected_timestamp,
metadata.event_timestamp (si "Generate Time" est absent) |
||
| Numéro de série | PanOSDeviceSN | intermediary.asset.hardware.serial_number | ||
| Type (type) | type (Header) | metadata.product_event_type | ||
| Type de menace/de contenu (sous-type) | subtype (Header) | metadata.product_event_type | ||
| Version de configuration (config_ver) | PanOSConfigVersion | config_ver | additional.fields.key et additional.fields.value.string_value | |
| Heure de génération (time_generated) | PanOSLogTimeStamp | metadata.event_timestamp | ||
| Adresse source (src) | src | principal.ip | ||
| Adresse de destination (dst) | dst | target.ip | ||
| Adresse IP source NAT (natsrc) | sourceTranslatedAddress | principa.nat_ip | ||
| Adresse IP de destination NAT (natdst) | destinationTranslatedAddress | target.nat_ip | ||
| Règle (rule) | cs1 | security_result.rule_name | ||
| Utilisateur source (srcuser) | suser | principal.user.userid | ||
| Utilisateur de destination (dstuser) | duser | target.user.userid | ||
| Application | application | network.application_protocol | ||
| Système virtuel (vsys) | cs3 | vsys | intermediary.asset.attribute.labels.key/value | |
| Zone source (de) | cs4 | de | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
|
| Zone de destination (à) | cs5 | à | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
|
| Interface entrante (inbound_if) | deviceInboundInterface | inbound_if | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
|
| Interface sortante (outbound_if) | deviceOutboundInterface | outbound_if | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
|
| Action de journalisation (ensemble de journaux) | cs6 | logset | additional.fields.key et additional.fields.value.string_value | |
| Durée de connexion (time_received) | PanOSTimeReceivedManagementPlane | - | ||
| ID de session (sessionid) | cn1 | network.session_id | ||
| Nombre de répétitions (repeatcnt) | PanOSCountOfRepeats/RepeatCount | repeatcnt | additional.fields.key et additional.fields.value.string_value | |
| Port source (sport) | spt | principal.port | ||
| Port de destination (dport) | dpt | target.port | ||
| Port source NAT (natsport) | sourceTranslatedPort | principal.nat_port | ||
| Port de destination NAT (natdport) | destinationTranslatedPort | target.nat_port | ||
| Indicateurs (flags) | flexString1 | flags | additional.fields.key et additional.fields.value.string_value | |
| Protocole IP (proto) | proto | network.ip_protocol | ||
| Action (action) | agir | security_result.action_details
security_result.action |
||
| Tunnel (tunnel) | PanOSTunnel | tunnel | additional.fields.key et additional.fields.value.string_value | |
| UUID de la VM source (src_uuid) | PanOSSourceUUID | principal.asset.product_object_id | ||
| UUID de la VM de destination (dst_uuid) | PanOSDestinationUUID | target.asset.product_object_id | ||
| UUID de la règle (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| Étape pour le client vers le pare-feu (hs_stage_c2f) | PanOSClientToFirewall | hs_stage_c2f | additional.fields.key et additional.fields.value.string_value | |
| Étape pour le pare-feu vers le serveur (hs_stage_f2s) | PanOSFirewallToServer | hs_stage_f2s | additional.fields.key et additional.fields.value.string_value | |
| Version TLS (tls_version) | PanOSTLSVersion | network.tls.version | ||
| Algorithme d'échange de clés (tls_keyxchg) | PanOSTLSKeyExchange | tls_keyxchg | additional.fields.key et additional.fields.value.string_value | |
| Algorithme de chiffrement (tls_enc) | PanOSTLSEncryptionAlgorithm | tls_enc | additional.fields.key et additional.fields.value.string_value | |
| Algorithme de hachage (tls_auth) | PanOSTLSAuth | tls_auth | additional.fields.key et additional.fields.value.string_value | |
| Nom de la règle (policy_name) | PanOSPolicyName | policy_name | additional.fields.key et additional.fields.value.string_value | |
| Courbe elliptique (ec_curve) | PanOSEllipticCurve | network.tls.curve | ||
| Index des erreurs (err_index) | PanOSErrorIndex | err_index | additional.fields.key et additional.fields.value.string_value | |
| État de la racine (root_status) | PanOSRootStatus | root_status | additional.fields.key et additional.fields.value.string_value | |
| État de la chaîne (chain_status) | PanOSChainStatus | chain_status | additional.fields.key et additional.fields.value.string_value | |
| Type de proxy (proxy_type) | PanOSProxyType | proxy_type | additional.fields.key et additional.fields.value.string_value | |
| Numéro de série du certificat (cert_serial) | PanOSCertificateSerial | network.tls.server.certificate.serial | ||
| Empreinte du certificat | PanOSFingerprint | network.tls.server.certificate.md5/sha1/sha256 | ||
| Date de début du certificat (notbefore) | PanOSTimeNotBefore | network.tls.server.certificate.not_before | ||
| Date de fin de validité du certificat (notafter) | PanOSTimeNotAfter | network.tls.server.certificate.not_after | ||
| Version du certificat (cert_ver) | PanOSCertificateVersion | network.tls.server.certificate.version | ||
| Taille du certificat (cert_size) | PanOSCertificateSize | cert_size | additional.fields.key et additional.fields.value.string_value | |
| Longueur du nom commun (cn_len) | PanOSCommonNameLength | cn_len | additional.fields.key et additional.fields.value.string_value | |
| Longueur du nom commun de l'émetteur (issuer_len) | PanOSIssuerNameLength | issuer_len | additional.fields.key et additional.fields.value.string_value | |
| Longueur du nom commun de la racine (rootcn_len) | PanOSRootCNLength | rootcn_len | additional.fields.key et additional.fields.value.string_value | |
| Longueur du SNI (sni_len) | PanOSSNILength | sni_len | additional.fields.key et additional.fields.value.string_value | |
| Indicateurs de certificat (cert_flags) | PanOSCertificateFlags | cert_flags | additional.fields.key et additional.fields.value.string_value | |
| Nom commun de l'objet (cn) | PanOSCommonName | cn | additional.fields.key et additional.fields.value.string_value | |
| Nom commun de l'émetteur (issuer_cn) | PanOSIssuerCommonName | network.tls.server.certificate.issuer | ||
| Nom commun racine (root_cn) | PanOSRootCommonName | root_cn | additional.fields.key et additional.fields.value.string_value | |
| Indication du nom du serveur
(sni) |
network.tls.client.server_name | |||
| Erreur (erreur) | PanOSErrorMessage | erreur | additional.fields.key et additional.fields.value.string_value | |
| ID du conteneur (container_id) | PanOSContainerID | container_id | intermediary.resource.product_object_id | |
| Espace de noms du POD (pod_namespace) | PanOSContainerNameSpace | pod_namespace | target.resource.attribute.labels.key/value additional.fields.key et additional.fields.value.string_value |
|
| Nom du POD (pod_name) | PanOSContainerName | pod_name | target.resource.name | |
| Liste dynamique externe source (src_edl) | PanOSSourceEDL | src_edl | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
|
| Liste dynamique externe de destinations (dst_edl) | PanOSDestinationEDL | dst_edl | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
|
| Groupe d'adresses dynamiques sources (src_dag) | PanOSSourceDynamicAddressGroup | principal.group.group_display_name | ||
| Groupe d'adresses dynamiques de destination (dst_dag) | PanOSDestinationDynamicAddressGroup | target.group.group_display_name | ||
| Code temporel haute résolution (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key et additional.fields.value.string_value | ||
| Catégorie de l'appareil source (src_category) | PanOSSourceDeviceCategory | src_category | principal.asset.category | |
| Profil de l'appareil source (src_profile) | PanOSSourceDeviceProfile | src_profile | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
|
| Modèle de l'appareil source (src_model) | PanOSSourceDeviceModel | src_model | principal.asset.hardware.model | |
| Fournisseur de l'appareil source (src_vendor) | PanOSSourceDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Famille d'OS de l'appareil source (src_osfamily) | PanOSSourceDeviceOSFamily | principal.platform | ||
| Version de l'OS de l'appareil source (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | ||
| Nom d'hôte source (src_host) | PanOSSourceDeviceHost | principal.hostname | ||
| Adresse MAC source (src_mac) | PanOSSourceDeviceMac | principal.mac | ||
| Catégorie d'appareil de destination (dst_category) | PanOSDestinationDeviceCategory | dst_category | target.asset.category | |
| Profil de l'appareil de destination (dst_profile) | PanOSDestinationDeviceProfile | dst_profile | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
|
| Modèle de l'appareil de destination (dst_model) | PanOSDestinationDeviceModel | dst_model | target.asset.hardware.model | |
| Fournisseur de l'appareil de destination (dst_vendor) | PanOSDestinationDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Famille d'OS de l'appareil de destination (dst_osfamily) | PanOSDestinationDeviceOSFamily | dst_osfamily | target.platform | |
| Version de l'OS de l'appareil de destination (dst_osversion) | PanOSDestinationDeviceOSVersion | target.platform_version | ||
| Nom d'hôte de destination (dst_host) | PanOSDestinationDeviceHost | target.hostname | ||
| Adresse MAC de destination (dst_mac) | PanOSDestinationDeviceMac | target.mac | ||
| Numéro de séquence (seqno) | PanOSLogTypeSeqNo | metadata.product_log_id | ||
| Indicateurs d'action (actionflags) | PanOSActionFlags | actionflags | additional.fields.key et additional.fields.value.string_value | |
| Hiérarchie des groupes d'appareils (dg_hier_level_1) | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key et additional.fields.value.string_value | |
| Hiérarchie des groupes d'appareils (dg_hier_level_2) | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key et additional.fields.value.string_value | |
| Hiérarchie des groupes d'appareils (dg_hier_level_3) | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key et additional.fields.value.string_value | |
| Hiérarchie des groupes d'appareils (dg_hier_level_4) | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key et additional.fields.value.string_value | |
| Nom du système virtuel (vsys_name) | intermediary.asset.attribute.labels.key/value | |||
| Nom de l'appareil (device_name) | intermediary.hostname | |||
| ID du système virtuel (vsys_id) | intermediary.resource.product_object_id | |||
| Sous-catégorie de l'application (subcategory_of_app) | subcategory_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Catégorie d'application (category_of_app) | category_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Technologie de l'application (technology_of_app) | technology_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Risque de l'application (risk_of_app) | security_result.severity | |||
| Caractéristique de l'application (characteristic_of_app) | characteristic_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Conteneur d'application (container_of_app) | container_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Application SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key et additional.fields.value.string_value | ||
| État approuvé de l'application (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Gravité (severity) | number-of-severity(header) | security_result.severity et security_result.severity_details |
Tunnel
Le tableau suivant répertorie les champs de journaux du type de journal de tunnel et les champs UDM correspondants.
| Champ CSV | Champ CEF | Champ LEEF | Clé de libellé Google Security Operations | Champ UDM |
|---|---|---|---|---|
| Heure de réception (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si "Generate Time" est absent) |
|
| Numéro de série | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Type (type) | type (Header) | cat | metadata.product_event_type | |
| Type de menace/de contenu (sous-type) | subtype (Header) | Sous-type | metadata.product_event_type | |
| Heure de génération (time_generated ou cef-formatted-time_generated) | metadata.event_timestamp | |||
| Adresse source (src) | src | src | principal.ip | |
| Adresse de destination (dst) | dst | dst | target.ip | |
| Adresse IP source NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| Adresse IP de destination NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Nom de la règle (règle) | cs1 | RuleName | security_result.rule_name | |
| Utilisateur source (srcuser) | suser | SourceUser / usrName | principal.user.userid | |
| Utilisateur de destination (dstuser) | duser | DestinationUser | target.user.userid | |
| Application | application | Application | network.application_protocol | |
| Système virtuel (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zone source (de) | cs4 | SourceZone | de | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
| Zone de destination (à) | cs5 | DestinationZone | à | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
| Interface entrante (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
| Interface sortante (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
| Action de journalisation (ensemble de journaux) | cs6 | LogForwardingProfile | logset | additional.fields.key et additional.fields.value.string_value |
| ID de session (sessionid) | cn1 | SessionID | network.session_id | |
| Nombre de répétitions (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key et additional.fields.value.string_value |
| Port source (sport) | spt | srcPort | principal.port | |
| Port de destination (dport) | dpt | dstPort | target.port | |
| Port source NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Port de destination NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Indicateurs (flags) | flexString1 | Options | flags | additional.fields.key et additional.fields.value.string_value |
| Protocole IP (proto) | proto | proto | network.ip_protocol | |
| Action (action) | agir | action | security_result.action_details
security_result.action |
|
| Gravité (severity) | number-of-severity(header) | security_result.severity et security_result.severity_details | ||
| Numéro de séquence (seqno) | externalId | séquence | metadata.product_log_id | |
| Indicateurs d'action (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key et additional.fields.value.string_value |
| Emplacement source (srcloc) | principal.location.country_or_region | |||
| Lieu de destination (dstloc) | target.location.country_or_region | |||
| Hiérarchie des groupes d'appareils (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key et additional.fields.value.string_value |
| Nom du système virtuel (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nom de l'appareil (device_name) | dvchost | DeviceName | intermediary.hostname | |
| ID du tunnel (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key et additional.fields.value.string_value |
| Tag Monitor (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key et additional.fields.value.string_value |
| ID de session parent (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Heure de début du parent (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key et additional.fields.value.string_value |
| Type de tunnel (tunnel) | cs2 | TunnelType | tunnel | additional.fields.key et additional.fields.value.string_value |
| Octets (octets) | flexNumber1 | totalBytes | bytes | additional.fields.key et additional.fields.value.string_value |
| Octets envoyés (bytes_sent) | dans | srcBytes | network.sent_bytes | |
| Octets reçus (bytes_received) | interprétés. | dstBytes | network.received_bytes | |
| Paquets | cn2 | totalPackets | paquets | additional.fields.key et additional.fields.value.string_value |
| Paquets envoyés (pkts_sent) | PanOSPacketsSent | srcPackets | pkts_sent | network.sent_packets |
| Paquets reçus (pkts_received) | PanOSPacketsReceived | dstPackets | pkts_received | network.received_packets |
| Encapsulation maximale (max_encap) | flexNumber2 | MaximumEncapsulation | max_encap | additional.fields.key et additional.fields.value.string_value |
| Protocole inconnu (unknown_proto) | cfp1 | UnknownProtocol | unknown_proto | additional.fields.key et additional.fields.value.string_value |
| Vérification stricte (strict_check) | cfp2 | StrictChecking | strict_check | additional.fields.key et additional.fields.value.string_value |
| Fragment de tunnel (tunnel_fragment) | PanOSTunnelFragment | TunnelFragment | tunnel_fragment | additional.fields.key et additional.fields.value.string_value |
| Sessions créées (sessions_created) | cfp3 | SessionsCreated | sessions_created | additional.fields.key et additional.fields.value.string_value |
| Sessions fermées (sessions_closed) | cfp4 | SessionsClosed | sessions_closed | additional.fields.key et additional.fields.value.string_value |
| Motif de fin de la session (session_end_reason) | reason | SessionEndReason | security_result.summary | |
| Source de l'action (action_source) | cat | ActionSource | action_source | additional.fields.key et additional.fields.value.string_value |
| Heure de début (start) | startTime | start | additional.fields.key et additional.fields.value.string_value | |
| Temps écoulé (elapsed) | cn3 | ElapsedTime | écoulé | network.session_duration.seconds |
| Règle d'inspection du tunnel (tunnel_insp_rule) | PanOSTunneInspectionRule | security_result.rule_name = "Tunnel Inspection Rule: %{PanOSTunnelInspectionRule}" | ||
| Adresse IP de l'utilisateur distant (remote_user_ip) | PanOSRmtUserIP | principal.ip | ||
| ID utilisateur distant (remote_user_id) | PanOSRmtUserID | remote_user_id | principal.user.userid | |
| UUID de la règle de sécurité (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| ID PCAP (pcap_id) | PanOSPcapID | pcap_id | additional.fields.key et additional.fields.value.string_value | |
| Nom du groupe d'utilisateurs dynamique (dynusergroup_name) | PanDynamicUsrgrp | principal.group.group_display_name | ||
| Liste dynamique externe source (src_edl) | PanOSSourceEDL | src_edl | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
|
| Liste dynamique externe de destinations (dst_edl) | PanOSDestinationEDL | dst_edl | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
|
| Code temporel haute résolution (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key et additional.fields.value.string_value | ||
| Un différenciateur de tranche (nssai_sd) | nssai_sd | additional.fields.key et additional.fields.value.string_value | ||
| Type de service de tranche (nssai_sd) | nssai_sd1 | additional.fields.key et additional.fields.value.string_value | ||
| ID de session PDU (pdu_session_id) | pdu_session_id | additional.fields.key et additional.fields.value.string_value | ||
| Sous-catégorie de l'application (subcategory_of_app) | subcategory_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Catégorie d'application (category_of_app) | category_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Technologie de l'application (technology_of_app) | technology_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Risque de l'application (risk_of_app) | risk_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Caractéristique de l'application (characteristic_of_app) | characteristic_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Conteneur d'application (container_of_app) | container_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Application SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Application tunnelisée (tunneled_app) | additional.fields.key et additional.fields.value.string_value | |||
| Déchargé (déchargé) | additional.fields.key et additional.fields.value.string_value | |||
| Type de flux (flow_type) | additional.fields.key et additional.fields.value.string_value | |||
| Nom du cluster (cluster_name) |
principal.resource.name |
|||
| État approuvé de l'application (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key et additional.fields.value.string_value |
Authentification
Le tableau suivant répertorie les champs de journal du type de journal d'authentification et les champs UDM correspondants.
| Champ CSV | Champ CEF | Champ LEEF | Clé de libellé Google Security Operations | Champ UDM |
|---|---|---|---|---|
| Heure de réception (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si "Generate Time" est absent) |
|
| Numéro de série | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Type (type) | type (Header) | cat | metadata.product_event_type | |
| Type de menace/de contenu (sous-type) | subtype (Header) | Sous-type | metadata.product_event_type | |
| Heure de génération (time_generated ou cef-formatted-time_generated) | metadata.event_timestamp | |||
| Système virtuel (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Adresse IP source (ip) | src | src | principal.ip | |
| Utilisateur (utilisateur) | duser | usrName | target.user.userid | |
| Normaliser l'utilisateur (normalize_user) | cs2 | NormalizeUser | target.user.user_display_name | |
| Objet (objet) | fname | ObjectName | objet | target.resource.name |
| Règle d'authentification (authpolicy) | cs4 | AuthPolicy | authpolicy | additional.fields.key et additional.fields.value.string_value |
| Nombre de répétitions (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key et additional.fields.value.string_value |
| ID d'authentification (authid) | cn2 | AuthenticationID | authid | additional.fields.key et additional.fields.value.string_value |
| Fournisseur | flexString2 | Fournisseur | vendor | additional.fields.key et additional.fields.value.string_value |
| Action de journalisation (ensemble de journaux) | cs6 | LogForwardingProfile | logset | additional.fields.key et additional.fields.value.string_value |
| Profil du serveur (serverprofile) | cs1 | ServerProfile | serverprofile | additional.fields.key et additional.fields.value.string_value |
| Description (décroissant) | PanOSDesc | AdditionalAuthInfo | security_result.description | |
| Type de client (clienttype) | cs5 | ClientType | clienttype | additional.fields.key et additional.fields.value.string_value |
| Type d'événement (event) | Message | Message | extensions.auth.auth_details | |
| Numéro de facteur (factorno) | cn1 | FactorNumber | factorno | additional.fields.key et additional.fields.value.string_value |
| Numéro de séquence (seqno) | externalId | séquence | metadata.product_log_id | |
| Indicateurs d'action (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key et additional.fields.value.string_value |
| Hiérarchie des groupes d'appareils (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key et additional.fields.value.string_value |
| Nom du système virtuel (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nom de l'appareil (device_name) | dvchost | DeviceName | intermediary.hostname | |
| ID du système virtuel (vsys_id) | intermediary.resource.product_object_id | |||
| Protocole d'authentification (authproto) | authproto | additional.fields.key et additional.fields.value.string_value | ||
| UUID de la règle (rule_uuid) | PanOSRuleUUID/RuleUUID | security_result.rule_id | ||
| Code temporel haute résolution (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key et additional.fields.value.string_value | ||
| Catégorie de l'appareil source (src_category) | PanOSSourceDeviceCategory | src_category | principal.asset.category | |
| Profil de l'appareil source (src_profile) | PanOSSourceDeviceProfile | src_profile | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
|
| Modèle de l'appareil source (src_model) | PanOSSourceDeviceModel | src_model | principal.asset.hardware.model | |
| Fournisseur de l'appareil source (src_vendor) | PanOSSourceDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Famille d'OS de l'appareil source (src_osfamily) | PanOSSourceDeviceOSFamily | principal.asset.platform_software.platform principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
||
| Version de l'OS de l'appareil source (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | ||
| Nom d'hôte source (src_host) | PanOSSourceHostname | principal.hostname | ||
| Adresse MAC source (src_mac) | PanOSSourceMac | principal.asset.mac | ||
| Région (région) | PanOSTrafficOriginRegion | principal.location.country_or_region | ||
| User-agent (user_agent) | PanOSHTTPUserAgent | network.http.user_agent | ||
| ID de session(sessionid) | PanOSTrafficSessionID | network.session_id | ||
| Gravité (severity) | number-of-severity(header) | security_result.severity et security_result.severity_details | ||
| Nom du cluster (cluster_name) | principal.resource.name |
URL
Le tableau suivant répertorie les champs de journal du type de journal "URL" et les champs UDM correspondants.
| Champ CSV | Champ CEF | Champ LEEF | Clé de libellé Google Security Operations | Champ UDM |
|---|---|---|---|---|
| Heure de réception (cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si "Generate Time" est absent) |
|
| N° de série | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Type (type) | type (Header) | cat | metadata.product_event_type | |
| Type de menace/de contenu (sous-type) | subtype (Header) | Sous-type | metadata.product_event_type | |
| Heure de génération | metadata.event_timestamp | |||
| Adresse source (src) | src | src | principal.ip | |
| Adresse de destination (dst) | dst | dst | target.ip | |
| Adresse IP source NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| Adresse IP de destination NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Règle (rule) | cs1 | RuleName | security_result.rule_name | |
| Utilisateur source (srcuser) | suser | SourceUser | principal.user.userid | |
| Utilisateur de destination (dstuser) | duser | DestinationUser | target.user.userid | |
| Application | application | Application | network.application_protocol | |
| Système virtuel (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zone source (de) | cs4 | SourceZone | de | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
| Zone de destination (à) | cs5 | DestinationZone | à | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
| Interface entrante (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
| Interface sortante (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
| Action de journalisation (ensemble de journaux) | cs6 | LogForwardingProfile | logset | additional.fields.key et additional.fields.value.string_value |
| Durée de connexion | time_logged | additional.fields.key et additional.fields.value.string_value | ||
| ID de session (sessionid) | cn1 | SessionID | network.session_id | |
| Nombre de répétitions (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key et additional.fields.value.string_value |
| Port source (sport) | spt | srcPort | principal.port | |
| Port de destination (dport) | dpt | dstPort | target.port | |
| Port source NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Port de destination NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Indicateurs (flags) | flexString1 | Options | flags | additional.fields.key et additional.fields.value.string_value |
| Protocole IP (proto) | proto | proto | network.ip_protocol | |
| Action (action) | agir | action | security_result.action_details
security_result.action |
|
| URL/Nom de fichier (divers) | Autres | target.file.names
target.url |
||
| Nom de la menace/du contenu (threatid) | cat | ThreatID | security_result.threat_id | |
| Catégorie (catégorie) | cs2 | URLCategory | category | security_result.category_details |
| Gravité (severity) | number-of-severity (en-tête) | Gravité | security_result.severity
security_result.severity_details |
|
| Direction (direction) | flexString2 | Direction | network.direction | |
| Numéro de séquence (seqno) | externalId | séquence | metadata.product_log_id | |
| Indicateurs d'action (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key et additional.fields.value.string_value |
| Pays source (srcloc) | SourceLocation | principal.location.country_or_region | ||
| Pays de destination (dstloc) | DestinationLocation | target.location.country_or_region | ||
| contenttype (contenttype) | requestContext | ContentType | contenttype | additional.fields.key et additional.fields.value.string_value |
| pcap_id (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key et additional.fields.value.string_value |
| filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | ||
| cloud (cloud) | Cloud | cloud | additional.fields.key et additional.fields.value.string_value | |
| url_idx (url_idx) | URLIndex | url_idx | additional.fields.key et additional.fields.value.string_value | |
| user_agent (user_agent) | requestClientApplication | UserAgent | network.http.user_agent | |
| filetype (filetype) | target.file.mime_type | |||
| xff (xff) | PanOSXForwarderfor | identSrc | xff | principal.ip |
| URL de provenance (referer) | PanOSReferer | Référent | network.http.referral_url | |
| sender (sender) | network.email.from | |||
| sujet (sujet) | Objet | network.email.subject | ||
| destinataire (recipient) | network.email.to | |||
| reportid (reportid) | reportid | additional.fields.key et additional.fields.value.string_value | ||
| Niveau 1 de la hiérarchie des groupes de données (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key et additional.fields.value.string_value |
| Niveau 2 de la hiérarchie DG (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key et additional.fields.value.string_value |
| Niveau 3 de la hiérarchie des groupes de produits (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key et additional.fields.value.string_value |
| Niveau 4 de la hiérarchie DG (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key et additional.fields.value.string_value |
| Nom du système virtuel (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nom de l'appareil (device_name) | dvchost | DeviceName | intermediary.hostname | |
| file_url (file_url) | target.url | |||
| UUID de la VM source (src_uuid) | SrcUUID | principal.asset.product_object_id | ||
| UUID de la VM de destination (dst_uuid) | DstUUID | target.asset.product_object_id | ||
| http_method (http_method) | requestMethod | RequestMethod | network.http.method | |
| ID/IMSI du tunnel (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key et additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key et additional.fields.value.string_value |
| ID de session parent (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Heure de début de la session parente (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key et additional.fields.value.string_value |
| Tunnel (tunnel) | PanOSTunnelType | TunnelType | tunnel | additional.fields.key et additional.fields.value.string_value |
| thr_category (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| contentver (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key et additional.fields.value.string_value |
| sig_flags (sig_flags) | sig_flags | additional.fields.key et additional.fields.value.string_value | ||
| ID d'association SCTP (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key et additional.fields.value.string_value | |
| ID du protocole de charge utile (ppid) | PanOSPPID | ppid | additional.fields.key et additional.fields.value.string_value | |
| http_headers (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Liste des catégories d'URL (url_category_list) | PanOSURLCatList | url_category_list | additional.fields.key et additional.fields.value.string_value | |
| UUID de la règle (rule_uuid) | PanOSRuleUUID | rule_uuid | security_result.rule_id | |
| Connexion HTTP/2 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| dynusergroup_name (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | additional.fields.key et additional.fields.value.string_value | |
| Adresse XFF (xff_ip) | PanXFFIP | principal.ip | ||
| Catégorie de l'appareil source (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Profil de l'appareil source (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
|
| Modèle de l'appareil source (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Fournisseur de l'appareil source (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Famille d'OS de l'appareil source (src_osfamily) | PanSrcDeviceOS | principal.platform | ||
| Version de l'OS de l'appareil source (src_osversion) | PanSrcDeviceOSv | principal.platform_version | ||
| Nom d'hôte source (src_host) | PanSrcHostname | src_host | principal.hostname | |
| Adresse MAC source (src_mac) | PanSrcMac | principal.mac | ||
| Catégorie d'appareil de destination (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Profil de l'appareil de destination (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
|
| Modèle de l'appareil de destination (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Fournisseur de l'appareil de destination (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Famille d'OS de l'appareil de destination (dst_osfamily) | PanDstDeviceOS | target.platform | ||
| Version de l'OS de l'appareil de destination (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Nom d'hôte de destination (dst_host) | PanPODNamespace | target.hostname | ||
| Adresse MAC de destination (dst_mac) | PanDstMac | target.mac | ||
| ID du conteneur (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| Espace de noms du POD (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| Nom du POD (pod_name) | PanPODName | pod_name | target.resource.name | |
| Liste dynamique externe source (src_edl) | PanSrcEDL | src_edl | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
|
| Liste dynamique externe de destinations (dst_edl) | PanDstEDL | dst_edl | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
|
| ID de l'hôte (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Numéro de série (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| domain_edl (domain_edl) | PanDomainEDL | domain_edl | additional.fields.key et additional.fields.value.string_value | |
| Groupe d'adresses dynamiques sources (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Groupe d'adresses dynamiques de destination (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| partial_hash (partial_hash) | PanPartialHash | partial_hash | additional.fields.key et additional.fields.value.string_value | |
| Code temporel haute résolution (high_res_timestamp) | PanTimeHighRes | additional.fields.key et additional.fields.value.string_value | ||
| Motif (reason) | PanReasonFilteringAction | reason | security_result.summary | |
| justification | PanJustification | justification | additional.fields.key et additional.fields.value.string_value | |
| nssai_sst (nssai_sst) | PanASServiceType | nssai_sst | additional.fields.key et additional.fields.value.string_value | |
| Sous-catégorie de l'application (subcategory_of_app) | subcategory_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Catégorie de l'application (category_of_app) | category_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Technologie de l'application (technology_of_app) | technology_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Risque de l'application (risk_of_app) | risk_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Caractéristique de l'application (characteristic_of_app) | characteristic_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Conteneur de l'application (container_of_app) | container_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Application tunnelée (tunneled_app) | tunneled_app | additional.fields.key et additional.fields.value.string_value | ||
| SaaS de l'application (is_saas_of_app) | is_saas_of_app | additional.fields.key et additional.fields.value.string_value | ||
| État de sanction de l'application (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key et additional.fields.value.string_value | ||
| ID du rapport cloud (cloud_reportid) | additional.fields.key et additional.fields.value.string_value | |||
| Nom du cluster (cluster_name) |
principal.resource.name |
|||
| Type de flux (flow_type) | additional.fields.key et additional.fields.value.string_value |
Données
Le tableau suivant liste les champs de journaux du type de journal de données et les champs UDM correspondants.
| Champ CSV | Champ CEF | Champ LEEF | Clé de libellé Google Security Operations | Champ UDM |
|---|---|---|---|---|
| Heure de réception (cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si "Generate Time" est absent) |
|
| N° de série | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Type (type) | type (Header) | cat | metadata.product_event_type | |
| Type de menace/de contenu (sous-type) | subtype (Header) | Sous-type | metadata.product_event_type | |
| Heure de génération | metadata.event_timestamp | |||
| Adresse source (src) | src | src | principal.ip | |
| Adresse de destination (dst) | dst | dst | target.ip | |
| Adresse IP source NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| Adresse IP de destination NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Règle (rule) | cs1 | RuleName | security_result.rule_name | |
| Utilisateur source (srcuser) | suser | SourceUser | principal.user.userid | |
| Utilisateur de destination (dstuser) | duser | DestinationUser | target.user.userid | |
| Application | application | Application | network.application_protocol | |
| Système virtuel (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zone source (de) | cs4 | SourceZone | de | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
| Zone de destination (à) | cs5 | DestinationZone | à | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
| Interface entrante (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
| Interface sortante (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
| Action de journalisation (ensemble de journaux) | cs6 | LogForwardingProfile | logset | additional.fields.key et additional.fields.value.string_value |
| Durée de connexion | time_logged | additional.fields.key et additional.fields.value.string_value | ||
| ID de session (sessionid) | cn1 | SessionID | network.session_id | |
| Nombre de répétitions (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key et additional.fields.value.string_value |
| Port source (sport) | spt | srcPort | principal.port | |
| Port de destination (dport) | dpt | dstPort | target.port | |
| Port source NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Port de destination NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Indicateurs (flags) | flexString1 | Options | flags | additional.fields.key et additional.fields.value.string_value |
| Protocole IP (proto) | proto | proto | network.ip_protocol | |
| Action (action) | agir | action | security_result.action_details
security_result.action |
|
| URL/Nom de fichier (divers) | Autres | target.file.names
target.url |
||
| Nom de la menace/du contenu (threatid) | cat | ThreatID | security_result.threat_id | |
| Catégorie (catégorie) | cs2 | URLCategory | category | security_result.category_details |
| Gravité (severity) | number-of-severity (en-tête) | Gravité | security_result.severity
security_result.severity_details |
|
| Direction (direction) | flexString2 | Direction | network.direction | |
| Numéro de séquence (seqno) | externalId | séquence | metadata.product_log_id | |
| Indicateurs d'action (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key et additional.fields.value.string_value |
| Pays source (srcloc) | SourceLocation | principal.location.country_or_region | ||
| Pays de destination (dstloc) | DestinationLocation | target.location.country_or_region | ||
| contenttype (contenttype) | ContentType | contenttype | additional.fields.key et additional.fields.value.string_value | |
| pcap_id (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key et additional.fields.value.string_value |
| filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | ||
| cloud (cloud) | Cloud | cloud | additional.fields.key et additional.fields.value.string_value | |
| url_idx (url_idx) | URLIndex | url_idx | additional.fields.key et additional.fields.value.string_value | |
| user_agent (user_agent) | network.http.user_agent | |||
| filetype (filetype) | target.file.mime_type | |||
| xff (xff) | xff | principal.ip | ||
| URL de provenance (referer) | network.http.referral_url | |||
| sender (sender) | network.email.from | |||
| sujet (sujet) | Objet | network.email.subject | ||
| destinataire (recipient) | network.email.to | |||
| reportid (reportid) | reportid | additional.fields.key et additional.fields.value.string_value | ||
| Niveau 1 de la hiérarchie des groupes de données (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key et additional.fields.value.string_value |
| Niveau 2 de la hiérarchie DG (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key et additional.fields.value.string_value |
| Niveau 3 de la hiérarchie des groupes de produits (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key et additional.fields.value.string_value |
| Niveau 4 de la hiérarchie DG (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key et additional.fields.value.string_value |
| Nom du système virtuel (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nom de l'appareil (device_name) | dvchost | DeviceName | intermediary.hostname | |
| file_url (file_url) | target.url | |||
| UUID de la VM source (src_uuid) | SrcUUID | principal.asset.product_object_id | ||
| UUID de la VM de destination (dst_uuid) | DstUUID | target.asset.product_object_id | ||
| http_method (http_method) | RequestMethod | network.http.method | ||
| ID/IMSI du tunnel (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key et additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key et additional.fields.value.string_value |
| ID de session parent (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Heure de début de la session parente (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key et additional.fields.value.string_value |
| Tunnel (tunnel) | PanOSTunnelType | TunnelType | tunnel | additional.fields.key et additional.fields.value.string_value |
| thr_category (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| contentver (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key et additional.fields.value.string_value |
| sig_flags (sig_flags) | sig_flags | additional.fields.key et additional.fields.value.string_value | ||
| ID d'association SCTP (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key et additional.fields.value.string_value | |
| ID du protocole de charge utile (ppid) | PanOSPPID | ppid | additional.fields.key et additional.fields.value.string_value | |
| http_headers (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Liste des catégories d'URL (url_category_list) | url_category_list | additional.fields.key et additional.fields.value.string_value | ||
| UUID de la règle (rule_uuid) | PanOSRuleUUID | rule_uuid | security_result.rule_id | |
| Connexion HTTP/2 (http2_connection) | http2_connection | network.application_protocol_version | ||
| dynusergroup_name (dynusergroup_name) | dynusergroup_name | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
||
| Adresse XFF (xff_ip) | principal.ip | |||
| Catégorie de l'appareil source (src_category) | src_category | principal.asset.category | ||
| Profil de l'appareil source (src_profile) | src_profile | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
||
| Modèle de l'appareil source (src_model) | src_model | principal.asset.hardware.model | ||
| Fournisseur de l'appareil source (src_vendor) | src_vendor | principal.asset.hardware.manufacturer | ||
| Famille d'OS de l'appareil source (src_osfamily) | principal.platform | |||
| Version de l'OS de l'appareil source (src_osversion) | principal.platform_version | |||
| Nom d'hôte source (src_host) | src_host | principal.hostname | ||
| Adresse MAC source (src_mac) | principal.mac | |||
| Catégorie d'appareil de destination (dst_category) | dst_category | target.asset.category | ||
| Profil de l'appareil de destination (dst_profile) | dst_profile | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
||
| Modèle de l'appareil de destination (dst_model) | dst_model | target.asset.hardware.model | ||
| Fournisseur de l'appareil de destination (dst_vendor) | dst_vendor | target.asset.hardware.manufacturer | ||
| Famille d'OS de l'appareil de destination (dst_osfamily) | target.platform | |||
| Version de l'OS de l'appareil de destination (dst_osversion) | target.platform_version | |||
| Nom d'hôte de destination (dst_host) | target.hostname | |||
| Adresse MAC de destination (dst_mac) | target.mac | |||
| ID du conteneur (container_id) | container_id | intermediary.resource.product_object_id | ||
| Espace de noms du POD (pod_namespace) | pod_namespace | target.resource.attribute.labels.key/value | ||
| Nom du POD (pod_name) | pod_name | target.resource.name | ||
| Liste dynamique externe source (src_edl) | src_edl | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
||
| Liste dynamique externe de destinations (dst_edl) | dst_edl | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
||
| ID de l'hôte (hostid) | hostid | principal.asset.asset_id | ||
| Numéro de série (serialnumber) | principal.asset.hardware.serial_number | |||
| domain_edl (domain_edl) | domain_edl | additional.fields.key et additional.fields.value.string_value | ||
| Groupe d'adresses dynamiques sources (src_dag) | principal.group.group_display_name | |||
| Groupe d'adresses dynamiques de destination (dst_dag) | target.group.group_display_name | |||
| partial_hash (partial_hash) | partial_hash | additional.fields.key et additional.fields.value.string_value | ||
| Code temporel haute résolution (high_res_timestamp) | additional.fields.key et additional.fields.value.string_value | |||
| Motif (reason) | reason | security_result.summary | ||
| justification | justification | additional.fields.key et additional.fields.value.string_value | ||
| nssai_sst (nssai_sst) | nssai_sst | additional.fields.key et additional.fields.value.string_value | ||
| Sous-catégorie de l'application (subcategory_of_app) | subcategory_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Catégorie de l'application (category_of_app) | category_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Technologie de l'application (technology_of_app) | technology_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Risque de l'application (risk_of_app) | risk_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Caractéristique de l'application (characteristic_of_app) | characteristic_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Conteneur de l'application (container_of_app) | container_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Application tunnelée (tunneled_app) | tunneled_app | additional.fields.key et additional.fields.value.string_value | ||
| SaaS de l'application (is_saas_of_app) | is_saas_of_app | additional.fields.key et additional.fields.value.string_value | ||
| État de sanction de l'application (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key et additional.fields.value.string_value | ||
| ID du rapport cloud (cloud_reportid) | additional.fields.key et additional.fields.value.string_value | |||
| Nom du cluster (cluster_name) | principal.resource.name | |||
| Type de flux (flow_type) | additional.fields.key et additional.fields.value.string_value |
GlobalProtect
Le tableau suivant répertorie les champs de journaux du type de journal GlobalProtect et les champs UDM correspondants.
| Champ CSV | Champ CEF | Champ LEEF | Clé de libellé Google Security Operations | Champ UDM |
|---|---|---|---|---|
| Heure de réception (receive_time) | rt | received_time | metadata.event_timestamp | |
| N° de série | PanOSDeviceSN | intermediary_asset_hardware_serial_number | intermediary.asset.hardware.serial_number | |
| Type (type) | type (Header) | metadata.product_event_type | ||
| Type de menace/de contenu (sous-type) | subtype (Header) | Sous-type | metadata.product_event_type | |
| Heure de génération (time_generated) | PanOSLogTimeStamp | generated_timestamp | metadata.event_timestamp | |
| Système virtuel (vsys) | PanOSVirtualSystem | vsys | intermediary.asset.attribute.labels.key/value | |
| ID de l'événement (eventid) | PanOSEventID | event_id | additional.fields.key et additional.fields.value.string_value | |
| Étape (stage) | PanOSStage | étape | additional.fields.key et additional.fields.value.string_value | |
| Méthode d'authentification (auth_method) | PanOSAuthMethod | extension_auth_auth_details | extensions.auth.auth_details | |
| Type de tunnel (tunnel_type) | PanOSTunnelType | tunnel | additional.fields.key et additional.fields.value.string_value | |
| Utilisateur source (srcuser) | PanOSSourceUserName | src_user | principal.user.email_address
principal.user.userid principal.administrative_domain |
|
| Région source (srcregion) | PanOSSourceRegion | src_region | principal.location.country_or_region | |
| Nom de la machine (machinename) | PanOSEndpointDeviceName | machine_name | principal.hostname | |
| Adresse IP publique (public_ip) | PanOSPublicIPv4 | principal.nat_ip | ||
| Adresse IPv6 publique (public_ipv6) | PanOSPublicIPv6 | principal.nat_ip | ||
| Adresse IP privée (private_ip) | PanOSPrivateIPv4 | principal.ip | ||
| Adresse IPv6 privée (private_ipv6) | PanOSPrivateIPv6 | principal.ip | ||
| ID de l'hôte (hostid) | PanOSHostID | hostid | principal.asset.asset_id | |
| Numéro de série (serialnumber) | PanOSDeviceSN | principal.asset.hardware.serial_number | ||
| Version du client (client_ver) | PanOSGlobalProtectClientVersion | client_ver | additional.fields.key et additional.fields.value.string_value | |
| OS du client (client_os) | PanOSEndpointOSType | principal.platform | ||
| Version de l'OS du client (client_os_ver) | PanOSEndpointOSVersion | principal.platform_version | ||
| Nombre de répétitions (repeatcnt) | PanOSCountOfRepeats | repeatcnt | additional.fields.key et additional.fields.value.string_value | |
| Motif (reason) | PanOSQuarantineReason | security_result.summary | ||
| Erreur (erreur) | PanOSConnectionError | erreur | security_result.description | |
| Description (opaque) | PanOSDescription | security_result.description | ||
| État (status) | PanOSEventStatus | état | additional.fields.key et additional.fields.value.string_value | |
| Emplacement (emplacement) | PanOSGPGatewayLocation | target.location.country_or_region | ||
| Durée de connexion (login_duration) | PanOSLoginDuration | network.session_duration | ||
| Méthode de connexion (connect_method) | PanOSConnectionMethod | connect_method | additional.fields.key et additional.fields.value.string_value | |
| Code d'erreur (error_code) | PanOSConnectionErrorID | error_code | additional.fields.key et additional.fields.value.string_value | |
| Portal (portail) | PanOSPortal | portail | additional.fields.key et additional.fields.value.string_value | |
| Numéro de séquence (seqno) | PanOSSequenceNo | metadata.product_log_id | ||
| Indicateurs d'action (actionflags) | PanOSActionFlags | actionflags | additional.fields.key et additional.fields.value.string_value | |
| Code temporel haute résolution (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key et additional.fields.value.string_value | ||
| Méthode de sélection de la passerelle (selection_type) | PanOSGatewaySelectionType | selection_type | additional.fields.key et additional.fields.value.string_value | |
| Temps de réponse SSL (response_time) | PanOSSSLResponseTime | response_time | additional.fields.key et additional.fields.value.string_value | |
| Priorité de la passerelle (priority) | PanOSGatewayPriority | priorité | additional.fields.key et additional.fields.value.string_value | |
| Passerelles tentées (attempted_gateways) | PanOSAttemptedGateways | attempted_gateways | additional.fields.key et additional.fields.value.string_value | |
| Nom de la passerelle (gateway) | PanOSAttemptedGateways | passerelle | target.resource.name | |
| Hiérarchie des groupes d'appareils (dg_hier_level_1) | dg_hier_level_1 | additional.fields.key et additional.fields.value.string_value | ||
| Hiérarchie des groupes d'appareils (dg_hier_level_2) | dg_hier_level_2 | additional.fields.key et additional.fields.value.string_value | ||
| Hiérarchie des groupes d'appareils (dg_hier_level_3) | dg_hier_level_3 | additional.fields.key et additional.fields.value.string_value | ||
| Hiérarchie des groupes d'appareils (dg_hier_level_4) | dg_hier_level_4 | additional.fields.key et additional.fields.value.string_value | ||
| Nom du système virtuel (vsys_name) | intermediary.asset.attribute.labels.key/value | |||
| Nom de l'appareil (device_name) | intermediary.hostname | |||
| ID du système virtuel (vsys_id) | intermediary.resource.product_object_id | |||
| Gravité (severity) | number-of-severity(header) | security_result.severity et security_result.severity_details | ||
| Nom du cluster (cluster_name) | principal.resource.name |
Corrélation
Le tableau suivant répertorie les champs de journaux du type de journal "Corrélation" et les champs UDM correspondants.
| Champ CSV | Champ CEF | Champ LEEF | Clé de libellé Google Security Operations | Champ UDM |
|---|---|---|---|---|
| Heure de génération (time_generated ou cef-formatted-time_generated) | startTime | generated_timestamp | metadata.event_timestamp | |
| Adresse source (src) | src | principal.ip | ||
| Utilisateur source (srcuser) | SourceUser / usrName | principal.user.userid | ||
| Système virtuel (vsys) | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value | |
| Catégorie (catégorie) | security_result.category_details | |||
| Gravité (severity) | Gravité | security_result.severity et security_result.severity_details | ||
| Niveau 1 de la hiérarchie des groupes d'appareils | DeviceGroupHierarchyL1 | additional.fields.key et additional.fields.value.string_value | ||
| Niveau 2 de la hiérarchie des groupes d'appareils | DeviceGroupHierarchyL2 | additional.fields.key et additional.fields.value.string_value | ||
| Niveau 3 de la hiérarchie des groupes d'appareils | DeviceGroupHierarchyL3 | additional.fields.key et additional.fields.value.string_value | ||
| Niveau 4 de la hiérarchie des groupes d'appareils | DeviceGroupHierarchyL4 | additional.fields.key et additional.fields.value.string_value | ||
| Nom du système virtuel (vsys_name) | vSrcName | intermediary.asset.attribute.labels.key/value | ||
| Nom de l'appareil (device_name) | DeviceName | intermediary.hostname | ||
| ID du système virtuel (vsys_id) | VirtualSystemID | intermediary.resource.product_object_id | ||
| Nom de l'objet (objectname) | ObjectName | target.resource.name | ||
| ID de l'objet (object_id) | ObjectID | target.resource.product_object_id | ||
| Preuve (preuve) | Message | security_result.summary |
GTP
Le tableau suivant répertorie les champs de journaux du type de journal GTP et les champs UDM correspondants.
| Champ CSV | Champ CEF | Champ LEEF | Clé de libellé Google Security Operations | Champ UDM |
|---|---|---|---|---|
| Heure de réception (receive_time ou cef-formatted-receive_time) | metadata.collected_timestamp,
metadata.event_timestamp (si "Generate Time" est absent) |
|||
| Numéro de série | intermediary.asset.hardware.serial_number | |||
| Type (type) | metadata.product_event_type | |||
| Type de menace/de contenu (sous-type) | metadata.product_event_type | |||
| Heure de génération (time_generated ou cef-formatted-time_generated) | metadata.event_timestamp | |||
| Adresse source (src) | principal.ip | |||
| Adresse de destination (dst) | target.ip | |||
| Nom de la règle (règle) | security_result.rule_name | |||
| Application | network.application_protocol | |||
| Système virtuel (vsys) | vsys | intermediary.asset.attribute.labels.key/value | ||
| Zone source (de) | de | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
||
| Zone de destination (à) | à | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
||
| Interface entrante (inbound_if) | inbound_if | principal.labels.key et principal.labels.value additional.fields.key et additional.fields.value.string_value |
||
| Interface sortante (outbound_if) | outbound_if | target.labels.key et target.labels.value additional.fields.key et additional.fields.value.string_value |
||
| Action de journalisation (ensemble de journaux) | logset | additional.fields.key et additional.fields.value.string_value | ||
| ID de session (sessionid) | network.session_id | |||
| Port source (sport) | principal.port | |||
| Port de destination (dport) | target.port | |||
| Protocole IP (proto) | network.ip_protocol | |||
| Action (action) | security_result.action_details
security_result.action |
|||
| Type d'événement GTP (event_type) | gtp_event_type | additional.fields.key et additional.fields.value.string_value | ||
| MSISDN (msisdn) | msisdn | additional.fields.key et additional.fields.value.string_value | ||
| Nom du point d'accès (APN) | apn | additional.fields.key et additional.fields.value.string_value | ||
| Technologie d'accès radio (rat) | rat | additional.fields.key et additional.fields.value.string_value | ||
| Type de message GTP (msg_type) | gtp_msg_type | additional.fields.key et additional.fields.value.string_value | ||
| Adresse IP de fin (end_ip_adr) | principal.ip | |||
| Identifiant du point de terminaison du tunnel 1 (teid1) | teid1 | additional.fields.key et additional.fields.value.string_value | ||
| Identifiant du point de terminaison du tunnel 2 (teid2) | teid2 | additional.fields.key et additional.fields.value.string_value | ||
| Interface GTP (gtp_interface) | gtp_interface | additional.fields.key et additional.fields.value.string_value | ||
| Cause GTP (cause_code) | gtp_cause_code | additional.fields.key et additional.fields.value.string_value | ||
| Gravité (severity) | security_result.severity et security_result.severity_details | |||
| Code MCC du réseau de diffusion (mcc) | mcc | additional.fields.key et additional.fields.value.string_value | ||
| MNC (mnc) du réseau de diffusion | mnc | additional.fields.key et additional.fields.value.string_value | ||
| Indicatif régional (area_code) | area_code | additional.fields.key et additional.fields.value.string_value | ||
| ID de cellule (cell_id) | cell_id | additional.fields.key et additional.fields.value.string_value | ||
| Code d'événement GTP (event_code) | event_code | additional.fields.key et additional.fields.value.string_value | ||
| Emplacement source (srcloc) | principal.location.country_or_region | |||
| Lieu de destination (dstloc) | target.location.country_or_region | |||
| ID/IMSI du tunnel (imsi) | tunnelid | additional.fields.key et additional.fields.value.string_value | ||
| Tag/IMEI du moniteur (imei) | monitortag | additional.fields.key et additional.fields.value.string_value | ||
| Heure de début (start) | start | additional.fields.key et additional.fields.value.string_value | ||
| Temps écoulé (elapsed) | network.session_duration.seconds | |||
| Règle d'inspection du tunnel (tunnel_insp_rule) | tunnel_insp_rule | security_result.detection_fields.key/value | ||
| Adresse IP de l'utilisateur distant (remote_user_ip) | principal.ip | |||
| ID utilisateur distant (remote_user_id) | remote_user_id | principal.user.userid | ||
| UUID de la règle (rule_uuid) | security_result.rule_id | |||
| ID PCAP (pcap_id) | pcap_id | additional.fields.key et additional.fields.value.string_value | ||
| Code temporel haute résolution (high_res_timestamp) | additional.fields.key et additional.fields.value.string_value | |||
| Type de service de tranche (nsdsai_sst) | nsdsai_sst | additional.fields.key et additional.fields.value.string_value | ||
| Un différenciateur de tranche (nsdsai_sd) | nsdsai_sd | additional.fields.key et additional.fields.value.string_value | ||
| Sous-catégorie de l'application (subcategory_of_app) | subcategory_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Catégorie d'application (category_of_app) | category_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Technologie de l'application (technology_of_app) | technology_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Risque de l'application (risk_of_app) | risk_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Caractéristique de l'application (characteristic_of_app) | characteristic_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Conteneur d'application (container_of_app) | container_of_app | additional.fields.key et additional.fields.value.string_value | ||
| Application SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key et additional.fields.value.string_value | ||
| État approuvé de l'application (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key et additional.fields.value.string_value |
SCTP
| Champ CSV | Champ CEF | Champ LEEF | Clé de libellé Google Security Operations | Champ UDM |
|---|---|---|---|---|
| Heure de réception (receive_time ou cef-formatted-receive_time) | receive_time ou cef-formatted-receive_time | metadata.collected_timestamp | ||
| Numéro de série | serial | intermediary.asset.hardware.serial_number | ||
| Type (type) | type | metadata.product_event_type | ||
| Heure de génération (time_generated ou cef-formatted-time_generated) | time_generated ou cef-formatted-time_generated | metadata.event_timestamp | ||
| Adresse source (src) | src | principal.ip | ||
| Adresse de destination (dst) | dst | target.ip | ||
| Nom de la règle (règle) | règle | security_result.rule_name | ||
| Zone source (de) | de | additional.fields.key et additional.fields.value.string_value | ||
| Zone de destination (à) | à | additional.fields.key et additional.fields.value.string_value | ||
| Interface entrante (inbound_if) | inbound_if | additional.fields.key et additional.fields.value.string_value | ||
| Interface sortante (outbound_if) | outbound_if | additional.fields.key et additional.fields.value.string_value | ||
| Action de journalisation (ensemble de journaux) | logset | additional.fields.key et additional.fields.value.string_value | ||
| ID de session (sessionid) | sessionid | network.session_id | ||
| Nombre de répétitions (repeatcnt) | repeatcnt | additional.fields.key et additional.fields.value.string_value | ||
| Port source (sport) | sport | principal.port | ||
| Port de destination (dport) | dport | target.port | ||
| Protocole IP (proto) | proto | network.ip_protocol (enum) | ||
| Action (action) | action | security_result.action_details security_result.action |
||
| Hiérarchie des groupes d'appareils (dg_hier_level_1 à dg_hier_level_4) | dg_hier_level_1 à dg_hier_level_4 | additional.fields.key et additional.fields.value.string_value | ||
| Nom de l'appareil (device_name) | device_name | intermediary.hostname | ||
| Numéro de séquence (seqno) | seqno | metadata.product_log_id | ||
| ID d'association SCTP (assoc_id) | assoc_id | additional.fields.key et additional.fields.value.string_value | ||
| ID du protocole de charge utile (ppid) | ppid | additional.fields.key et additional.fields.value.string_value | ||
| Gravité (severity) | de gravité, | security_result.severity et security_result.severity_details | ||
| Type de bloc SCTP (sctp_chunk_type) | sctp_chunk_type | additional.fields.key et additional.fields.value.string_value | ||
| Type d'événement SCTP (sctp_event_type) | sctp_event_type | additional.fields.key et additional.fields.value.string_value | ||
| Tag de validation SCTP 1 (verif_tag_1) | verif_tag_1 | additional.fields.key et additional.fields.value.string_value | ||
| Tag de validation SCTP 2 (verif_tag_2) | verif_tag_2 | additional.fields.key et additional.fields.value.string_value | ||
| Code de cause SCTP (sctp_cause_code) | sctp_cause_code | additional.fields.key et additional.fields.value.string_value | ||
| ID de l'application Diameter (diam_app_id) | diam_app_id | additional.fields.key et additional.fields.value.string_value | ||
| Code de commande du diamètre (diam_cmd_code) | diam_cmd_code | additional.fields.key et additional.fields.value.string_value | ||
| Code AVP Diameter (diam_avp_code) | diam_avp_code | additional.fields.key et additional.fields.value.string_value | ||
| ID de flux SCTP (stream_id) | stream_id | additional.fields.key et additional.fields.value.string_value | ||
| Motif de fin de l'association SCTP (assoc_end_reason) | assoc_end_reason | additional.fields.key et additional.fields.value.string_value | ||
| Code opération (op_code) | op_code | additional.fields.key et additional.fields.value.string_value | ||
| SSN de l'appelant SCCP (sccp_calling_ssn) | sccp_calling_ssn | additional.fields.key et additional.fields.value.string_value | ||
| Titre global de l'appelant SCCP (sccp_calling_gt) | sccp_calling_gt | additional.fields.key et additional.fields.value.string_value | ||
| Filtre SCTP (sctp_filter) | sctp_filter | additional.fields.key et additional.fields.value.string_value | ||
| Blocs SCTP | chunks | additional.fields.key et additional.fields.value.string_value | ||
| Blocs SCTP envoyés (chunks_sent) | chunks_sent | additional.fields.key et additional.fields.value.string_value | ||
| Blocs SCTP reçus (chunks_received) | chunks_received | additional.fields.key et additional.fields.value.string_value | ||
| Paquets | paquets | additional.fields.key et additional.fields.value.string_value | ||
| UUID de la règle (rule_uuid) | rule_uuid | security_result.rule_id | ||
| Système virtuel (vsys) | vsys | intermediary.asset.attribute.labels.key/value | ||
| Nom du système virtuel (vsys_name) | vsys_name | intermediary.asset.attribute.labels.key/value | ||
| Paquets envoyés (pkts_sent) | pkts_sent | network.sent_packets | ||
| Paquets reçus (pkts_received) | pkts_received | network.received_packets |
Audit
| Champ CSV | Champ CEF | Champ LEEF | Clé de libellé Google Security Operations | Champ UDM |
|---|---|---|---|---|
| Heure de génération | metadata.event_timestamp | |||
| Type de menace/de contenu (sous-type) | metadata.product_event_type | |||
| ID de l'événement | principal.application | |||
| Objet | principal.user.userid | |||
| Commande CLI | principal.process.command_line | |||
| Gravité | security_result.severity | |||
| Numéro de série | intermediary.asset.hardware.serial_number |
Référence de mappage des champs : types de journaux et types d'événements UDM
Le tableau suivant liste les types de journaux de pare-feu Palo Alto Networks et leurs types d'événements UDM correspondants.
| Type de journal | Type d'événement UDM |
| Trafic | NETWORK_CONNECTION |
| Menace | NETWORK_CONNECTION |
| Filtrage des URL | NETWORK_CONNECTION |
| WildFire | NETWORK_CONNECTION
Les journaux d'envoi WildFire sont un sous-type du type de journal "Menace" et utilisent le même format syslog. |
| Filtrage des données | NETWORK_CONNECTION |
| Tunnel | NETWORK_CONNECTION |
| GTP | NETWORK_CONNECTION |
| Config | SETTING_MODIFICATION/SETTING_CREATION/SETTING_DELETION/SETTING_UNCATEGORIZED
La valeur du champ "Command (cmd)" détermine le mappage du type d'événement UDM. Si la valeur du champ "cmd" est "add" ou "clone", SETTING_CREATION est défini. Si la valeur du champ "cmd" est "delete", SETTING_DELETION est défini. Si la valeur du champ "cmd" est "edit", "move", "rename", "set" ou "commit", SETTING_MODIFICATION est défini. Si la valeur du champ "cmd" ne contient aucune valeur, SETTING_UNCATEGORIZED est défini. |
| Système |
Si la valeur du sous-type est "dhcp", NETWORK_DHCP est défini. Si la valeur du sous-type est "auth", USER_LOGIN est défini. Si la valeur de la description est "logged in" (connecté), USER_LOGIN est défini. Si la valeur de la description est "logged out", USER_LOGOUT est défini. Pour les autres valeurs du sous-type, GENERIC_EVENT est défini. |
| HIP Match | NETWORK_CONNECTION |
| Balise IP | GENERIC_EVENT |
| User-ID | USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED
Si la valeur du sous-type est "login", USER_LOGIN est défini. Si la valeur du sous-type est "logout", USER_LOGOUT est défini. Si le sous-type ne contient aucune valeur, USER_UNCATEGORIZED est défini. |
| Déchiffrement | NETWORK_CONNECTION |
| Authentification | GENERIC_EVENT |
| SCTP | NETWORK_CONNECTION |
| Audit | GENERIC_EVENT |
Delta de mappage UDM
Référence du delta de mappage UDM : pare-feu Palo Alto Networks
Le tableau suivant liste le delta entre l'ancien mappage UDM de Palo Alto Networks Firewall et le nouveau mappage UDM de Palo Alto Networks Firewall.
UDM Event Type Delta
| Log type | Old UDM Event Type | New UDM Event Type |
| WildFire | NETWORK_CONNECTION | SCAN_UNCATEGORIZED |
| Data Filtering | NETWORK_CONNECTION | NETWORK_UNCATEGORIZED |
| Authentication | STATUS_UPDATE | STATUS_UNCATEGORIZED |
UDM Field Mapping Delta
| Log Type | Old UDM Mapping | CSV Log Field | CEF Log Field | LEEF Log Field | New UDM Mapping |
|---|---|---|---|---|---|
| System | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| System | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| System | about.labels.key/value additional.fields.key/value.string_value | Object (object) | fname | Filename | target.resource.name |
| System | Description (opaque) | msg | msg | metadata.description | |
| System | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| System | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| Config | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| Config | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| Config | principal.process.command_line | Configuration Path (path) | msg | ConfigurationPath | principal.process.command_line |
| Config | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| Config | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| Config | principal.asset.attribute.labels.key/value | Device Group (dg_id) | PanOSFWDeviceGroup | target.asset.attribute.labels | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Threat/Wildfire | target.file.full_path target.url target.hostname | URL/Filename (misc) | request | Miscellaneous | target.file.names target.url |
| Threat/Wildfire | about.file.sha1/md5/sha256 | File Digest (filedigest) | fileHash | FileDigest | target.file.sha1/md5/sha256 |
| Threat/Wildfire | about.file.mime_type | File Type (filetype) | fileType | FileType | target.file.mime_type |
| Threat/Wildfire | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Threat/Wildfire | principal.user.product_object_id | Source VM UUID (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id |
| Threat/Wildfire | target.user.product_object_id | Destination VM UUID (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | HTTP Headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| Threat/Wildfire | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| Threat/Wildfire | principal.asset.software.version | Source Device OS Version (src_osversion) | PanSrcDeviceOSv | principal.platform_version | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| Threat/Wildfire | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| Threat/Wildfire | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | PanReasonFilteringAction | security_result.summary | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Packets Sent (pkts_sent) | PanOSPacketsSent | srcPackets | network.sent_packets |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Packets Received (pkts_received) | PanOSPacketsReceived | dstPackets | network.received_packets |
| Traffic | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| Traffic | principal.asset.platform_software.platform(enum) principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| Traffic | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| Traffic | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| User-ID | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| User-ID | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| User-ID | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | intermediary.resource.product_object_id |
| User-ID | principal.user.userid principal.administrative_domain principal.user.email_addresses | User by Source (userbysource) | PanOSUserBySource | target.user.userid target.user.email_addresses | |
| User-ID | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| HIP Match | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | HIP (matchname) | cat | HIP | target.resource.attribute.labels |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | HIP Type (matchtype) | Device Event Class ID (Header) | HIPType | target.resource.attribute.labels |
| HIP Match | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| HIP Match | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| HIP Match | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id |
| HIP Match | principal.asset.product_object_id | Host ID (hostid) | PanOSHostID | principal.asset.asset_id | |
| HIP Match | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| IP-Tag | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| IP-Tag | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| IP-Tag | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOsVsysName | vSrcName | target.asset.attribute.labels |
| IP-Tag | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| IP-Tag | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id |
| IP-Tag | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Decryption | target.application | Application (app) | app | network.application_protocol | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | intermediary.asset.attribute.labels | |
| Decryption | principal.asset.asset_id | Source VM UUID (src_uuid) | PanOSSourceUUID | principal.asset.product_object_id | |
| Decryption | target.asset.asset_id | Destination VM UUID (dst_uuid) | PanOSDestinationUUID | target.asset.product_object_id | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanOSContainerID | intermediary.resource.product_object_id | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanOSContainerNameSpace | target.resource.attribute.labels additional.fields.key/value.string_value | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanOSContainerName | target.resource.name | |
| Decryption | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanOSSourceDeviceCategory | principal.asset.category | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanOSSourceDeviceModel | principal.asset.hardware.model | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanOSSourceDeviceVendor | principal.asset.hardware.manufacturer | |
| Decryption | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanOSSourceDeviceOSFamily | principal.platform | |
| Decryption | principal.asset.software.version | Source Device OS Version (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanOSDestinationDeviceCategory | target.asset.category | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanOSDestinationDeviceModel | target.asset.hardware.model | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanOSDestinationDeviceVendor | target.asset.hardware.manufacturer | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanOSDestinationDeviceOSFamily | target.platform | |
| Decryption | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanOSDestinationDeviceOSVersion | target.platform_version | |
| Decryption | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | intermediary.asset.attribute.labels | ||
| Decryption | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Tunnel | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Packets Sent (pkts_sent) | PanOSPacketsSent | srcPackets | network.sent_packets |
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Packets Received (pkts_received) | PanOSPacketsReceived | dstPackets | network.received_packets |
| Tunnel | target.ip | Remote User IP (remote_user_ip) | PanOSRmtUserIP | principal.ip | |
| Tunnel | target.labels.key/value additional.fields.key/value.string_value | Remote User ID (remote_user_id) | PanOSRmtUserID | principal.user.userid | |
| Tunnel | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Authentication | target.user.user_display_name | Normalize User (normalize_user) | cs2 | NormalizeUser | target.user.user_display_name |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Object (object) | fname | ObjectName | target.resource.name |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Authentication Policy (authpolicy) | cs4 | AuthPolicy | additional.fields.key/value.string_value |
| Authentication | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Authentication | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| Authentication | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res _timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanOSSourceDeviceCategory | principal.asset.category | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanOSSourceDeviceModel | principal.asset.hardware.model | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanOSSourceDeviceVendor | principal.asset.hardware.manufacturer | |
| Authentication | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanOSSourceDeviceOSFamily | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | |
| Authentication | principal.asset.software.version | Source Device OS Version (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| URL | target.file.full_path target.url | URL/Filename (misc) | Miscellaneous | target.file.names target.url | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Category (category) | cs2 | URLCategory | security_result.category_details |
| URL | about.file.sha1/md5/sha256 | filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | |
| URL | about.file.mime_type | filetype (filetype) | target.file.mime_type | ||
| URL | about.labels.key/value additional.fields.key/value.string_value | xff (xff) | PanOSXForwarderfor | identSrc | principal.ip |
| URL | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| URL | about.url | file_url (file_url) | target.url | ||
| URL | principal.asset.asset_id | Source VM UUID (src_uuid) | SrcUUID | principal.asset.product_object_id | |
| URL | target.asset.asset_id | Destination VM UUID (dst_uuid) | DstUUID | target.asset.product_object_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | http_headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| URL | about.labels.key/value additional.fields.key/value.string_value | UUID for rule (rule_uuid) | PanOSRuleUUID | security_result.rule_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| URL | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| URL | principal.asset.software.version | Source Device OS Version (src_osversion) | PanSrcDeviceOSv | principal.platform_version | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Hostname (src_host) | PanSrcHostname | principal.hostname | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| URL | target.asset.platform_software.platform target.labels.key/value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| URL | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| URL | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| URL | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Res Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | PanReasonFilteringAction | security_result.summary | |
| Data | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Data | target.file.full_path target.url | URL/Filename (misc) | Miscellaneous | target.file.names target.url | |
| Data | about.labels.key/value additional.fields.key/value.string_value | Category (category) | cs2 | URLCategory | security_result.category_details |
| Data | about.file.sha1/md5/sha256 | filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | |
| Data | about.file.mime_type | filetype (filetype) | target.file.mime_type | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | xff (xff) | principal.ip | ||
| Data | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Data | about.url | file_url (file_url) | target.url | ||
| Data | principal.asset.asset_id | Source VM UUID (src_uuid) | SrcUUID | principal.asset.product_object_id | |
| Data | target.asset.asset_id | Destination VM UUID (dst_uuid) | DstUUID | target.asset.product_object_id | |
| Data | about.labels.key/value additional.fields.key/value.string_value | http_headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| Data | about.labels.key/value additional.fields.key/value.string_value | UUID for rule (rule_uuid) | PanOSRuleUUID | security_result.rule_id | |
| Data | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | network.application_protocol_version | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | principal.asset.category | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | principal.asset.hardware.model | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | principal.asset.hardware.manufacturer | ||
| Data | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | principal.platform | ||
| Data | principal.asset.software.version | Source Device OS Version (src_osversion) | principal.platform_version | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Hostname (src_host) | principal.hostname | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | target.asset.category | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | target.asset.hardware.model | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | target.asset.hardware.manufacturer | ||
| Data | target.asset.platform_software.platform target.labels.key/value | Destination Device OS Family (dst_osfamily) | target.platform | ||
| Data | target.asset.software.version | Destination Device OS Version (dst_osversion) | target.platform_version | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | intermediary.resource.product_object_id | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | target.resource.attribute.labels | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | target.resource.name | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | principal.asset.asset_id | ||
| Data | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Res Timestamp (high_res_timestamp) | additional.fields.key/value.string_value | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | security_result.summary | ||
| GlobalProtect | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | PanOSVirtualSystem | intermediary.asset.attribute.labels | |
| GlobalProtect | principal.user.email_address principal.user.userid principal.administrative_domain | Source User (srcuser) | PanOSSourceUserName | target.user.email_address target.user.userid | |
| GlobalProtect | principal.asset.platform_software.platform(enum) | Client OS (client_os) | PanOSEndpointOSType | principal.platform | |
| GlobalProtect | principal.asset.platform_software.platform_version | Client OS Version (client_os_ver) | PanOSEndpointOSVersion | principal.platform_version | |
| GlobalProtect | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| GlobalProtect | about.labels.key/value additional.fields.key/value.string_value | Gateway Name (gateway) | PanOSAttemptedGateways | target.resource.name | |
| GlobalProtect | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | intermediary.asset.attribute.labels | ||
| GlobalProtect | target.hostname | Device Name (device_name) | intermediary.hostname | ||
| GlobalProtect | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| CORRELATION | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | VirtualSystem | intermediary.asset.attribute.labels | |
| CORRELATION | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | vSrcName | intermediary.asset.attribute.labels | |
| CORRELATION | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | VirtualSystemID | intermediary.resource.product_object_id | |
| GTP | additional.fields.key/value.string_value | Virtual System (vsys) | intermediary.asset.attribute.labels | ||
| GTP | target.ip | Remote User IP (remote_user_ip) | principal.ip | ||
| GTP | additional.fields.key/value.string_value | Remote User ID (remote_user_id) | principal.user.userid | ||
| GTP | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | additional.fields.key/value.string_value |
Service de journalisation Strata Firewall de Palo Alto Networks
Présentation
Le service de journalisation Strata de Palo Alto Networks® fournit un stockage et une agrégation centralisés des journaux basés dans le cloud pour vos pare-feu sur site, virtuels (cloud privé et cloud public), pour Prisma Access et pour les services fournis dans le cloud tels que Cortex XDR. Le service de journalisation Strata est sécurisé, résilient et tolérant aux pannes. Il garantit que vos données de journalisation sont à jour et disponibles lorsque vous en avez besoin. Elle fournit une infrastructure de journalisation évolutive qui vous évite de planifier et de déployer des collecteurs de journaux pour répondre à vos besoins de conservation des journaux. Si vous disposez déjà de collecteurs de journaux sur site, le nouveau service de journalisation Strata peut compléter votre configuration existante. Vous pouvez augmenter la capacité opérationnelle de votre infrastructure de collecte de journaux existante à l'aide du service de journalisation Strata basé dans le cloud à mesure que votre activité se développe, ou pour répondre aux besoins de capacité de nouveaux sites.Avec ce service, Palo Alto Networks s'occupe de la maintenance et de la surveillance continues de l'infrastructure de journalisation afin que vous puissiez vous concentrer sur votre activité.
Vérifiez les formats de journaux et les versions de PAN-OS compatibles avec l'analyseur Strata Logging Service. Le tableau suivant répertorie les formats de journaux et les versions PAN-OS correspondantes compatibles avec l'analyseur du service de journalisation Strata :
Format du journal Version de PAN-OS JSON 12.1 Vérifiez les types de journaux de pare-feu Palo Alto Networks compatibles avec l'analyseur Google SecOps. L'analyseur Google SecOps est compatible avec les types de journaux de pare-feu Palo Alto Networks suivants :
- Trafic
- Menace
- Inspection de tunnels
- Système
- Correspondance HIP
- IP-Tag
- User-ID
- Déchiffrement
- Authentification
- Filtrage des URL
- GlobalProtect
Déploiement du service de journalisation Strata
- Assurez-vous que le produit de pare-feu Palo Alto Networks est correctement déployé et configuré. Pour obtenir des instructions de configuration détaillées, consultez la documentation PAN-OS, puis suivez ce document de déploiement avant d'envoyer les journaux au service de journalisation Strata Conditions préalables au déploiement du service de journalisation Strata.
Commencez à envoyer des journaux au service de journalisation Strata :
Pour commencer à envoyer des journaux au service de journalisation Strata, procédez comme suit :
- Installer une version PAN-OS® compatible
- Activez le service de journalisation Strata. L'activation du service de journalisation Strata inclut le provisionnement du certificat dont les pare-feu ont besoin pour se connecter de manière sécurisée au service de journalisation Strata.
- Intégrer des pare-feu au service de journalisation Strata avec ou sans Panorama
Pour connaître la procédure d'intégration détaillée, consultez la documentation.
Transférer les journaux du service de journalisation Strata
Pour répondre à vos besoins à long terme en matière de stockage, de reporting, de surveillance, ou de conformité et de légalité, vous pouvez configurer le service Strata Logging pour qu'il transfère les journaux vers un serveur HTTPS ou vers les SIEM suivants :
- Exabeam
- Google Chronicle
- Microsoft Sentinel
- Splunk HTTP Event Collector (HEC)
Utilisez la méthode de transfert HTTPS pour transférer les journaux à l'aide du service de journalisation Strata. Pour en savoir plus, consultez cette documentation.
Formats de journaux acceptés
L'analyseur de pare-feu Palo Alto Networks Strata Logging Service est compatible avec les journaux au format JSON.
Exemples de journaux acceptés
JSON
{"source": "Palo Alto Networks FLS LF", "host": "dummy-loghost", "time": "1730265996460", "event": {"TimeReceived": "2024-10-30T05:25:50.000000Z", "DeviceSN": "no-serial", "LogType": "TRAFFIC", "Subtype": "end", "ConfigVersion": "10.2", "TimeGenerated": "2024-10-30T05:25:40.000000Z", "SourceAddress": "198.51.100.6", "DestinationAddress": "198.51.100.6", "NATSource": "", "NATDestination": "", "Rule": "egress-dns-ping-traceroute", "SourceUser": null, "DestinationUser": null, "Application": "dns-base", "VirtualLocation": "vsys1", "FromZone": "VA8280-RN", "ToZone": "inter-fw", "InboundInterface": "tunnel.101", "OutboundInterface": "tunnel.4005", "LogSetting": "Cortex Data Lake", "SessionID": 754194, "RepeatCount": 1, "SourcePort": 53578, "DestinationPort": 53, "NATSourcePort": 0, "NATDestinationPort": 0, "Protocol": "udp", "Action": "allow", "Bytes": 214, "BytesSent": 72, "BytesReceived": 142, "PacketsTotal": 2, "SessionStartTime": "2024-10-30T05:25:10.000000Z", "SessionDuration": 0, "URLCategory": "any", "SequenceNo": 7382192512716388639, "SourceLocation": "198.51.100.6-198.51.255.255", "DestinationLocation": "198.51.100.6-198.51.255.255", "PacketsSent": 1, "PacketsReceived": 1, "SessionEndReason": "aged-out", "DGHierarchyLevel1": 65537, "DGHierarchyLevel2": 65538, "DGHierarchyLevel3": 65541, "DGHierarchyLevel4": 0, "VirtualSystemName": "", "DeviceName": "VA8280-RN", "ActionSource": "from-policy", "SourceUUID": null, "DestinationUUID": null, "IMSI": 0, "IMEI": null, "ParentSessionID": 0, "ParentStarttime": "1970-01-01T00:00:00.000000Z", "Tunnel": "N/A", "EndpointAssociationID": 72057594037927936, "ChunksTotal": 0, "ChunksSent": 0, "ChunksReceived": 0, "RuleUUID": "95cfc3cc-cb00-4758-af1d-de9ab5f07f97", "HTTP2Connection": 0, "LinkChangeCount": 0, "SDWANPolicyName": null, "LinkSwitches": null, "SDWANCluster": null, "SDWANDeviceType": null, "SDWANClusterType": null, "SDWANSite": null, "DynamicUserGroupName": null, "X-Forwarded-ForIP": null, "SourceDeviceCategory": null, "SourceDeviceProfile": null, "SourceDeviceModel": null, "SourceDeviceVendor": null, "SourceDeviceOSFamily": null, "SourceDeviceOSVersion": null, "SourceDeviceHost": null, "SourceDeviceMac": null, "DestinationDeviceCategory": null, "DestinationDeviceProfile": null, "DestinationDeviceModel": null, "DestinationDeviceVendor": null, "DestinationDeviceOSFamily": null, "DestinationDeviceOSVersion": null, "DestinationDeviceHost": null, "DestinationDeviceMac": null, "ContainerID": null, "ContainerNameSpace": null, "ContainerName": null, "SourceEDL": null, "DestinationEDL": null, "GPHostID": null, "EndpointSerialNumber": null, "SourceDynamicAddressGroup": null, "DestinationDynamicAddressGroup": null, "HASessionOwner": null, "TimeGeneratedHighResolution": "2024-10-30T05:25:41.009000Z", "NSSAINetworkSliceType": null, "NSSAINetworkSliceDifferentiator": null}}"
Référence du mappage de champs : champs de journaux vers champs UDM
Cette section explique comment l'analyseur mappe les champs de journaux de pare-feu Palo Alto Networks Strata Logging Service aux champs d'événements Google UDM pour chaque type de journal.
Pour obtenir des informations sur le mappage de chaque type de journal, consultez les sections suivantes :
- Système
- Menace
- Trafic
- ID utilisateur
- Correspondance HIP
- Tag IP
- Déchiffrement
- Tunnel
- Authentification
- URL
- GlobalProtect
- SCTP
- Audit
Système
Le tableau suivant répertorie les champs de journaux du type de journal "Système" et les champs UDM correspondants.
| Log field | UDM mapping |
|---|---|
| AgentContentVersion | additional.fields.key/value.string_value |
| AgentDataCollectionStatus | target.resource.attribute.labels |
| AgentID | target.resource.attribute.labels |
| AgentIsolationStatus | target.resource.attribute.labels |
| AgentStatus | target.resource.attribute.labels |
| AgentVersion | target.asset.software.version |
| ConfigVersion | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DeviceGroup | target.group.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EndpointCPUArchitecture | target.asset.hardware.cpu_platform |
| EndpointDeviceDomain | target.asset.administrative_domain |
| EndpointDeviceName | target.asset.hostname |
| EndpointIPaddress | target.asset.ip |
| VDIEndpoint | target.asset.attribute.labels |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointOSVersion | target.platform_version |
| AgentTimeZoneOffset | additional.fields.key/value.string_value |
| EndpointUserDomain | additional.fields.key/value.string_value |
| EndpointUserName | target.user.user_display_name |
| EndpointUserUUID | target.user.userid |
| EventComponent | additional.fields.key/value.string_value |
| EventDescription | metadata.description |
| EventName | additional.fields.key/value.string_value |
| EventTime | metadata.event_timestamp |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogCategory | security_result.category_details |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| LogSourceID | target.resource.attribute.labels |
| LogSourceName | observer.asset.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| LogTime | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Severity | security_result.severity |
| Subtype | metadata.product_event_type |
| Template | target.resource.attribute.labels |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
Menace
Le tableau suivant répertorie les champs de journaux du type de journal "Menace" et les champs UDM correspondants.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| ApplianceOrCloud | additional.fields.key/value.string_value |
| CloudHostname | additional.fields.key/value.string_value |
| CloudReportID | security_result.detection_fields.key/value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DirectionOfAttack | security_result.detection_fields.key/value |
| DomainEDL | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| FileName | target.file.names |
| FileHash | target.file.sha1 |
| FileType | additional.fields.key/value.string_value |
| FileURL | target.url |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HostID | principal.asset.asset_id |
| HTTP2Connection | network.application_protocol_version |
| HTTPMethod | network.http.method |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| LocalDeepLearningAnalyzed | additional.fields.key/value.string_value |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| PartialHash | additional.fields.key/value.string_value |
| PayloadProtocolID | additional.fields.key/value.string_value |
| Packet | additional.fields.key/value.string_value |
| PacketID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| RecipientEmail | target.user.email_addresses |
| ReportID | security_result.detection_fields.key/value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SenderEmail | principal.user.email_addresses |
| SequenceNo | metadata.product_log_id |
| SessionID | network.session_id |
| Severity | security_result.severity |
| SigFlags | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| EmailSubject | network.email.subject |
| ApplicationTechnology | additional.fields.key/value.string_value |
| ThreatCategory | security_result.detection_fields.key/value.key/value |
| ThreatID | security_result.threat_id |
| ThreatName | security_result.threat_name |
| ThreatNameFirewall | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLDomain | target.domain.name |
| URLCounter | additional.fields.key/value.string_value |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| Verdict | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-ForIP | principal.ip |
Trafic
Le tableau suivant répertorie les champs de journal du type de journal "Trafic" et leurs champs UDM correspondants.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| ActionSource | additional.fields.key/value.string_value |
| AIFwdError | additional.fields.key/value.string_value |
| AITraffic | additional.fields.key/value.string_value |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| BytesReceived | network.received_bytes |
| BytesSent | network.sent_bytes |
| Bytes | additional.fields.key/value.string_value |
| ChunksReceived | additional.fields.key/value.string_value |
| ChunksSent | additional.fields.key/value.string_value |
| ChunksTotal | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| EndpointAssociationID | additional.fields.key/value.string_value |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HASessionOwner | additional.fields.key/value.string_value |
| GPHostID | additional.fields.key/value.string_value |
| HTTP2Connection | network.application_protocol_version |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsOffloaded | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| LinkChangeCount | additional.fields.key/value.string_value |
| LinkSwitches | additional.fields.key/value.string_value |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| SDWANPolicyName | additional.fields.key/value.string_value |
| Protocol | network.ip_protocol |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SDWANFECRatio | additional.fields.key/value.string_value |
| SDWANCluster | additional.fields.key/value.string_value |
| SDWANClusterType | additional.fields.key/value.string_value |
| SDWANDeviceType | additional.fields.key/value.string_value |
| SDWANSite | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionStartTime | additional.fields.key/value.string_value |
| SessionTracker | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| SessionDuration | network.session_duration |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLCategory | target.url_metadata.categories |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-ForIP | principal.ip |
User-ID
Le tableau suivant liste les champs de journaux du type de journal "User-ID" et les champs UDM correspondants.
| Log field | UDM mapping |
|---|---|
| AuthFactorNo | security_result.detection_fields.key/value |
| AuthenticatedUserDomain | target.user.administrative_domain |
| AuthenticatedUserName | target.user.userid |
| AuthenticatedUserUUID | target.user.product_object_id |
| ConfigVersion | additional.fields.key/value.string_value |
| CountofRepeats | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationPort | target.port |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EventID | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsDuplicateUser | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MappingDataSource | additional.fields.key/value.string_value |
| MappingDataSourceName | additional.fields.key/value.string_value |
| MappingDataSourceType | additional.fields.key/value.string_value |
| MappingTimeout | additional.fields.key/value.string_value |
| MFAFactorType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SourceIP | principal.ip |
| SourcePort | principal.port |
| Subtype | metadata.product_event_type |
| Tag | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| UGFlags | additional.fields.key/value.string_value |
| User | target.user.userid |
| UserGroupFound | additional.fields.key/value.string_value |
| UserIdentifiedBySource | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Correspondance HIP
Le tableau suivant répertorie les champs de journaux du type de journal "Correspondance HIP" et les champs UDM correspondants.
| Log field | UDM mapping |
|---|---|
| ConfigVersion | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EndpointDeviceName | principal.asset.hostname |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| HipMatchName | target.resource.attribute.labels |
| HipMatchType | target.resource.attribute.labels |
| HostID | principal.asset.asset_id |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | metadata.product_event_type |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Source | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceIP | principal.ip |
| SourceIPv6 | principal.ip |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| TimestampDeviceIdentification | principal.asset.first_seen_time |
| UUID | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
Tag d'adresse IP
Le tableau suivant répertorie les champs de journaux du type de journal "Tag d'adresse IP" et les champs UDM correspondants.
| Log field | UDM mapping |
|---|---|
| ConfigVersion | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EventID | additional.fields.key/value.string_value |
| IPSubnetRange | network.ip_subnet_range |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSetting | target.resource.attribute.labels |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MappingDataSource | additional.fields.key/value.string_value |
| MappingDataSourceSubType | additional.fields.key/value.string_value |
| MappingDataSourceType | additional.fields.key/value.string_value |
| MappingTimeout | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| RuleMatched | security_result.rule_name |
| RuleMatchedUUID | security_result.rule_id |
| SequenceNo | metadata.product_log_id |
| SourceIP | principal.ip |
| Subtype | metadata.product_event_type |
| TagName | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
Déchiffrement
Le tableau suivant répertorie les champs de journaux du type de journal "Déchiffrement" et les champs UDM correspondants.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| CertificateFlags | additional.fields.key/value.string_value |
| CertificateSerial | network.tls.server.certificate.serial |
| CertificateSize | additional.fields.key/value.string_value |
| CertificateVersion | network.tls.server.certificate.version |
| ChainStatus | additional.fields.key/value.string_value |
| ApplicationCharacteristics | additional.fields.key/value.string_value |
| ClientToFirewall | additional.fields.key/value.string_value |
| CommonName | additional.fields.key/value.string_value |
| CommonNameLength | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| Cpadding | additional.fields.key/value.string_value |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| Domain | target.hostname |
| EllipticCurve | network.tls.curve |
| ErrorIndex | additional.fields.key/value.string_value |
| ErrorMessage | additional.fields.key/value.string_value |
| Fingerprint | network.tls.server.certificate.md5/sha1/sha256 |
| FirewallToClient | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsCertECDSA | additional.fields.key/value.string_value |
| IsCertRSA | additional.fields.key/value.string_value |
| IsCertCNTruncated | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| IsForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsIssuerCNTruncated | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| IsNAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| PacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsResumeSession | additional.fields.key/value.string_value |
| IsRootCNTruncated | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSNITruncated | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| IssuerCommonName | network.tls.server.certificate.issuer |
| IssuerNameLength | additional.fields.key/value.string_value |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| TimeNotAfter | additional.fields.key/value.string_value |
| TimeNotBefore | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| Padding | additional.fields.key/value.string_value |
| Padding3 | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| PolicyName | additional.fields.key/value.string_value |
| Protocol | network.ip_protocol |
| ProxyType | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| RootCommonName | additional.fields.key/value.string_value |
| RootCNLength | additional.fields.key/value.string_value |
| RootStatus | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SessionID | network.session_id |
| ServerNameIndication | network.tls.client.server_name |
| SNILength | additional.fields.key/value.string_value |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeReceivedManagementPlane | additional.fields.key/value.string_value |
| TLSAuth | additional.fields.key/value.string_value |
| TLSEncryptionAlgorithm | additional.fields.key/value.string_value |
| TLSKeyExchange | additional.fields.key/value.string_value |
| TLSVersion | network.tls.version |
| ToZone | additional.fields.key/value.string_value |
| Tpadding | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| Vpadding | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Tunnel
Le tableau suivant répertorie les champs de journaux du type de journal "Tunnel" et les champs UDM correspondants.
| Log field | UDM mapping |
|---|---|
| AccessPointName | additional.fields.key/value.string_value |
| Action | security_result.action |
| ActionSource | additional.fields.key/value.string_value |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| BytesReceived | network.received_bytes |
| BytesSent | network.sent_bytes |
| Bytes | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| LoggingServiceID | additional.fields.key/value.string_value |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MobileAreaCode | additional.fields.key/value.string_value |
| MobileBaseStationCode | additional.fields.key/value.string_value |
| MobileCountryCode | additional.fields.key/value.string_value |
| MobileIP | additional.fields.key/value.string_value |
| MobileNetworkCode | additional.fields.key/value.string_value |
| MobileSubscriberISDN | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceDifferentiator | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsDroppedMax | additional.fields.key/value.string_value |
| PacketsDroppedStrict | additional.fields.key/value.string_value |
| PacketsDroppedTunnel | additional.fields.key/value.string_value |
| PacketsDroppedProtocol | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| ProtocolDataUnitsessionID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| RadioAccessTechnology | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionStartTime | additional.fields.key/value.string_value |
| SessionTracker | additional.fields.key/value.string_value |
| Severity | security_result.severity |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| StandardPortsOfApp | additional.fields.key/value.string_value |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| SessionDuration | network.session_duration |
| Tunnel | additional.fields.key/value.string_value |
| TunnelCauseCode | additional.fields.key/value.string_value |
| TunnelEndpointID1 | additional.fields.key/value.string_value |
| TunnelEndpointID2 | additional.fields.key/value.string_value |
| TunnelEventCode | additional.fields.key/value.string_value |
| TunnelEventType | additional.fields.key/value.string_value |
| TunnelInspectionRule | additional.fields.key/value.string_value |
| TunnelInterface | additional.fields.key/value.string_value |
| TunnelMessageType | additional.fields.key/value.string_value |
| TunnelRemoteIMSIID | additional.fields.key/value.string_value |
| TunnelRemoteUserIP | principal.ip |
| TunnelSessionsClosed | additional.fields.key/value.string_value |
| TunnelSessionsCreated | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLCategory | target.url_metadata.categories |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Authentification
Le tableau suivant répertorie les champs de journaux du type de journal "Authentification" et les champs UDM correspondants.
| Log field | UDM mapping |
|---|---|
| AuthenticationDescription | security_result.description |
| AuthEvent | metadata.description |
| AuthFactorNo | security_result.detection_fields.key/value |
| AuthenticationPolicy | security_result.detection_fields.key/value |
| AuthenticationProtocol | additional.fields.key/value.string_value |
| AuthServerProfile | additional.fields.key/value.string_value |
| AuthenticatedUserDomain | target.administrative_domain |
| AuthenticatedUserName | target.user.userid |
| AuthenticatedUserUUID | target.user.product_object_id |
| ClientType | additional.fields.key/value.string_value |
| ClientTypeName | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| Location | target.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogType | additional.fields.key/value.string_value |
| MFAAuthenticationID | additional.fields.key/value.string_value |
| MFAVendor | additional.fields.key/value.string_value |
| NormalizeUser | target.user.user_display_name |
| Object | target.resource.name |
| RuleMatched | security_result.rule_name |
| RuleMatchedUUID | security_result.rule_id |
| AuthCacheServiceRegion | additional.fields.key/value.string_value |
| SessionID | network.session_id |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceIP | principal.ip |
| TimeGenerated | metadata.event_timestamp |
| User | target.user.userid |
| UserAgentString | network.http.user_agent |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Subtype | metadata.product_event_type |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
URL
Le tableau suivant répertorie les champs de journal du type de journal "URL" et les champs UDM correspondants.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| CloudHostname | additional.fields.key/value.string_value |
| CloudReportID | security_result.detection_fields.key/value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentType | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DirectionOfAttack | security_result.detection_fields.key/value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| FileURL | target.url |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HostID | principal.asset.asset_id |
| HTTP2Connection | network.application_protocol_version |
| HTTPHeaders | additional.fields.key/value.string_value |
| HTTPMethod | network.http.method |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| InlineMLVerdict | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| Packet | additional.fields.key/value.string_value |
| PacketID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| Referer | network.http.referral_url |
| HTTPRefererFQDN | additional.fields.key/value.string_value |
| HTTPRefererPort | additional.fields.key/value.string_value |
| HTTPRefererProtocol | additional.fields.key/value.string_value |
| HTTPRefererURLPath | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionID | network.session_id |
| Severity | security_result.severity |
| SigFlags | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URL | target.url_metadata.URL |
| URLCategory | target.url_metadata.categories |
| URLCategoryList | additional.fields.key/value.string_value |
| URLDomain | target.domain.name |
| URLCounter | additional.fields.key/value.string_value |
| UserAgent | network.http.user_agent |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-For | additional.fields.key/value.string_value |
| X-Forwarded-ForIP | principal.ip |
GlobalProtect
Le tableau suivant répertorie les champs de journaux du type de journal GlobalProtect et les champs UDM correspondants.
| Log field | UDM mapping |
|---|---|
| AttemptedGateways | additional.fields.key/value.string_value |
| AuthMethod | extensions.auth.auth_details |
| ConnectionMethod | additional.fields.key/value.string_value |
| ConnectionErrorID | additional.fields.key/value.string_value |
| ConnectionError | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| EndpointDeviceName | principal.asset.hostname |
| GlobalProtectClientVersion | additional.fields.key/value.string_value |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointSN | principal.asset.hardware.serial_number |
| EventIDValue | additional.fields.key/value.string_value |
| Gateway | target.resource.name |
| GatewayPriority | additional.fields.key/value.string_value |
| GatewaySelectionType | additional.fields.key/value.string_value |
| GlobalProtectGatewayLocation | target.location.country_or_region |
| HostID | principal.asset.asset_id |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LoginDuration | network.session_duration |
| Description | security_result.description |
| Portal | target.hostname |
| PrivateIPv4 | principal.ip |
| PrivateIPv6 | principal.ip |
| ProjectName | additional.fields.key/value.string_value |
| PublicIPv4 | principal.nat_ip |
| PublicIPv6 | principal.nat_ip |
| QuarantineReason | security_result.summary |
| SequenceNo | metadata.product_log_id |
| SourceRegion | principal.location.country_or_region |
| SourceUserName | principal.user.user_display_name |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SSLResponseTime | additional.fields.key/value.string_value |
| Stage | additional.fields.key/value.string_value |
| EventStatus | additional.fields.key/value.string_value |
| LogSubtype | metadata.product_event_type |
| TunnelType | additional.fields.key/value.string_value |
| VirtualSystem | intermediary.asset.attribute.labels |
| VirtualSystemName | intermediary.asset.attribute.labels |
| EndpointOSVersion | principal.platform_version |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | metadata.product_event_type |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualSystemID | intermediary.resource.product_object_id |
SCTP
Le tableau suivant répertorie les champs de journaux du type de journal SCTP et les champs UDM correspondants.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| AssocationEndReason | additional.fields.key/value.string_value |
| ChunksReceived | additional.fields.key/value.string_value |
| ChunksSent | additional.fields.key/value.string_value |
| ChunksTotal | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceClass | target.asset.category |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationIP | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DiamAppID | additional.fields.key/value.string_value |
| DiamAvpCode | additional.fields.key/value.string_value |
| DiameterCommandCode | additional.fields.key/value.string_value |
| DiameterRequestFlag | additional.fields.key/value.string_value |
| DeviceName | principal.asset.hostname |
| SCTPEventType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLFiltering | additional.fields.key/value.string_value |
| IsWildfire | additional.fields.key/value.string_value |
| LogAction | additional.fields.key/value.string_value |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MapAppCode | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PayloadProtocolID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SccpCallingGt | additional.fields.key/value.string_value |
| SccpCallingSSN | additional.fields.key/value.string_value |
| SctpCauseCode | additional.fields.key/value.string_value |
| SctpChunkType | additional.fields.key/value.string_value |
| SctpFilter | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionTracker | additional.fields.key/value.string_value |
| Severity | security_result.severity |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceIP | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VerificationTag1 | additional.fields.key/value.string_value |
| VerificationTag2 | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Audit
Le tableau suivant répertorie les champs de journaux du type de journal d'audit et les champs UDM correspondants.
| Log field | UDM mapping |
|---|---|
| EventCategory | network.http.method |
| EventDescription | metadata.description |
| EventDestinationURL | target.url |
| EventDestinationUserUserID | target.user.userid |
| DestinationVendor | additional.fields.key/value.string_value |
| EventDetails | additional.fields.key/value.string_value |
| EventID | metadata.product_log_id |
| EventName | additional.fields.key/value.string_value |
| EventResult | security_result.summary |
| EventSourceUserUserID | principal.user.userid |
| EventTime | metadata.event_timestamp |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| Subtype | metadata.product_event_type |
| TSGID | additional.fields.key/value.string_value |
| Vendor | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
Référence de mappage des champs : types de journaux et types d'événements UDM
Le tableau suivant répertorie les types de journaux de pare-feu Palo Alto Networks Strata Logging Service et leurs types d'événements UDM correspondants.
| Type de journal | Type d'événement UDM |
| Trafic | NETWORK_CONNECTION |
| Menace | NETWORK_CONNECTION |
| Filtrage des URL | NETWORK_CONNECTION |
| Tunnel | NETWORK_CONNECTION |
| Système |
Si la valeur du sous-type est "dhcp", NETWORK_DHCP est défini. Si la valeur du sous-type est "auth", USER_LOGIN est défini. Si la valeur de la description est "logged in" (connecté), USER_LOGIN est défini. Si la valeur de la description est "logged out", USER_LOGOUT est défini. Pour les autres valeurs du sous-type, GENERIC_EVENT est défini. |
| HIP Match | NETWORK_CONNECTION |
| Balise IP | GENERIC_EVENT |
| User-ID | USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED
Si la valeur du sous-type est "login", USER_LOGIN est défini. Si la valeur du sous-type est "logout", USER_LOGOUT est défini. Si le sous-type ne contient aucune valeur, USER_UNCATEGORIZED est défini. |
| Déchiffrement | NETWORK_CONNECTION |
| Authentification | STATUS_UNCATEGORIZED |
| Globalprotect | USER_LOGIN/USER_LOGOUT/USER_RESOURCE_ACCESS
Si la valeur du sous-type est "auth", USER_LOGIN est défini. Si la valeur du sous-type est "logout", USER_LOGOUT est défini. Si le sous-type ne contient aucune valeur, USER_RESOURCE_ACCESS est défini. |
| SCTP | NETWORK_CONNECTION |
| Audit | NETWORK_CONNECTION |
Étapes suivantes
Vous avez encore besoin d'aide ? Obtenez des réponses de membres de la communauté et de professionnels Google SecOps.