Mengumpulkan log firewall Palo Alto Networks

Didukung di:

Firewall Palo Alto Networks

Ringkasan

Dokumen ini menjelaskan cara mengonfigurasi syslog dan penerus Google SecOps untuk mengumpulkan log firewall Palo Alto Networks. Dokumen ini juga menjelaskan cara kolom log firewall Palo Alto Networks dipetakan ke kolom Model Data Terpadu (UDM) Google SecOps. Untuk mengetahui ringkasan tentang penyerapan data Google SecOps, lihat Penyerapan data ke Google SecOps. Label penyerapan mengidentifikasi parser yang menormalisasi data log mentah ke format UDM terstruktur. Informasi dalam dokumen ini berlaku untuk parser dengan label penyerapan PAN_FIREWALL.

Sebelum memulai

  • Pastikan produk firewall Palo Alto Networks di-deploy dan dikonfigurasi dengan benar. Untuk petunjuk penyiapan mendetail, lihat Dokumentasi PAN-OS.
  • Untuk memahami komponen yang di-deploy untuk mengumpulkan log firewall Palo Alto Networks, tinjau arsitektur deployment. Setiap deployment pelanggan mungkin berbeda dari representasi ini dan mungkin lebih kompleks. Diagram berikut menunjukkan cara mengonfigurasi syslog di firewall Palo Alto Networks dan menginstal penerus Google SecOps di server Linux untuk meneruskan data log ke Google SecOps. Parser mendukung log yang ditulis dalam format data berikut: Comma Separated Values (CSV), Common Event Format (CEF), dan Log Event Extended Format (LEEF).

    Arsitektur deployment

  • Verifikasi format log dan versi PAN-OS yang didukung parser Google SecOps. Tabel berikut mencantumkan format log dan versi PAN-OS yang sesuai yang didukung oleh parser Google SecOps:

    Format log Versi PAN-OS
    CSV 10.1.3
    CEF 10.0.0
    LEEF 9.1.0
  • Verifikasi jenis log firewall Palo Alto Networks yang didukung oleh parser Google SecOps. Parser Google SecOps mendukung jenis log firewall Palo Alto Networks berikut:

    • Traffic
    • Ancaman
    • Pengiriman WildFire
    • Pemeriksaan terowongan
    • Konfigurasi
    • Sistem
    • Pencocokan HIP
    • IP-Tag
    • User-ID
    • Dekripsi
    • Autentikasi
    • Pemfilteran URL
    • Pemfilteran data
    • GlobalProtect
    • Korelasi
    • GTP
    • SCTP
    • Audit

    Untuk mengetahui informasi selengkapnya tentang jenis log firewall Palo Alto Networks, lihat Jenis log PAN-OS.

  • Pastikan semua sistem dalam arsitektur deployment dikonfigurasi dalam zona waktu UTC.

  • Sebelum menggunakan parser firewall Palo Alto Networks, tinjau perubahan dalam pemetaan kolom antara parser sebelumnya dan parser firewall Palo Alto Networks saat ini. Sebagai bagian dari migrasi, pastikan aturan, penelusuran, dasbor, atau proses lain yang bergantung pada kolom asli menggunakan kolom yang diperbarui.

    Misalnya, pada versi parser sebelumnya, kolom log category dipetakan ke kolom UDM security_result.description. Di parser firewall Palo Alto Networks saat ini, kolom log category dipetakan ke kolom UDM security_result.category_details. Jika Anda bermigrasi ke parser firewall Palo Alto Networks saat ini dan menggunakan kolom category dalam aturan, Anda harus mengubah aturan untuk menggunakan kolom UDM security_result.category_details dari parser saat ini.

Mengonfigurasi syslog dan penerus Google Security Operations

Untuk mengonfigurasi syslog dan penerus Google SecOps, selesaikan langkah-langkah berikut:

  1. Untuk memantau log CSV, konfigurasi profil server syslog. Untuk mengetahui informasi selengkapnya, lihat Mengonfigurasi profil server syslog. Saat mengonfigurasi profil server syslog, tentukan "Default" sebagai format log kustom.
  2. Untuk memantau log CEF, konfigurasi firewall Palo Alto Networks untuk meneruskan log CEF. Untuk mengetahui informasi selengkapnya, download PDF panduan Integrasi CEF PAN-OS dan lihat bagian "Konfigurasi NGFW Palo Alto Networks untuk menghasilkan peristiwa CEF".
  3. Untuk memantau log LEEF, konfigurasi profil server syslog. Untuk mengetahui informasi selengkapnya, lihat Penerusan log kustom dalam format LEEF.
  4. Konfigurasi penerusan Google SecOps untuk mengirim log ke Google Security Operations. Untuk mengetahui informasi selengkapnya, lihat Menginstal dan mengonfigurasi penerusan di Linux. Berikut adalah contoh konfigurasi penerus Google SecOps:

      - syslog:
          common:
            enabled: true
            data_type: PAN_FIREWALL
            batch_n_seconds: 10
            batch_n_bytes: 1048576
          tcp_address: 0.0.0.0:10518
          connection_timeout_sec: 60
    

Mengonfigurasi penerusan syslog di PAN Firewall

Membuat profil server syslog

  1. Login ke Konsol Pengelolaan Firewall Palo Alto Networks.
  2. Buka Perangkat > Profil Server > Syslog.
  3. Klik Tambahkan untuk membuat profil server baru.
  4. Berikan detail konfigurasi berikut:
    • Name: Masukkan nama deskriptif (misalnya, Google SecOps BindPlane).
    • Lokasi: Pilih sistem virtual (vsys) atau Bersama tempat profil ini akan tersedia.
  5. Klik Servers > Add untuk mengonfigurasi server syslog.
  6. Berikan detail konfigurasi server berikut:
    • Name: Masukkan nama deskriptif untuk server (misalnya, BindPlane Agent).
    • Server Syslog: Masukkan alamat IP Agen BindPlane.
    • Transport: Pilih UDP atau TCP, bergantung pada konfigurasi BindPlane Agent Anda (UDP adalah default).
    • Port: Masukkan nomor port Agen BindPlane (misalnya, 514).
    • Format: Pilih BSD (default) atau IETF, bergantung pada persyaratan Anda.
    • Fasilitas: Pilih LOG_USER (default) atau fasilitas lain sesuai kebutuhan.
  7. Klik OK untuk menyimpan profil server syslog.

Opsional: Mengonfigurasi format log kustom untuk CEF atau LEEF

Jika Anda memerlukan log CEF (Common Event Format) atau LEEF (Log Event Extended Format) dan bukan CSV:

  1. Di Profil Server Syslog, pilih tab Custom Log Format.
  2. Konfigurasi format log kustom untuk setiap jenis log (Config, System, Threat, Traffic, URL, Data, WildFire, Tunnel, Authentication, User-ID, HIP Match).
  3. Untuk konfigurasi format CEF, lihat Panduan Konfigurasi CEF Palo Alto Networks.
  4. Klik OK untuk menyimpan konfigurasi.

Membuat profil penerusan log

  1. Buka Objects > Log Forwarding.
  2. Klik Tambahkan untuk membuat profil penerusan log baru.
  3. Berikan detail konfigurasi berikut:
    • Nama: Masukkan nama profil (misalnya, Google SecOps Forwarding). Jika Anda ingin firewall otomatis menetapkan profil ini ke aturan dan zona keamanan baru, beri nama default.
  4. Untuk setiap jenis log yang ingin Anda teruskan (Traffic, Threat, WildFire Submission, URL Filtering, Data Filtering, Tunnel, Authentication), konfigurasikan hal berikut:
    • Klik Tambahkan di bagian jenis log yang sesuai.
    • Syslog: Pilih profil server syslog yang Anda buat (misalnya, Google SecOps BindPlane).
    • Tingkat Keparahan Log: Pilih tingkat keparahan yang akan diteruskan (misalnya, Semua).
  5. Klik OK untuk menyimpan profil penerusan log.

Menerapkan profil penerusan log ke kebijakan keamanan

  1. Buka Kebijakan > Keamanan.
  2. Pilih aturan keamanan yang ingin Anda aktifkan penerusan log-nya.
  3. Klik aturan untuk mengeditnya.
  4. Buka tab Tindakan.
  5. Di menu Log Forwarding, pilih profil penerusan log yang Anda buat (misalnya, Google SecOps Forwarding).
  6. Klik OK untuk menyimpan konfigurasi kebijakan keamanan.

Mengonfigurasi setelan log untuk log sistem

  1. Buka Perangkat > Setelan Log.
  2. Untuk setiap jenis log (Sistem, Konfigurasi, User-ID, HIP Match, Global Protect, IP-Tag, SCTP) dan tingkat keparahan, pilih profil server syslog yang Anda buat.
  3. Klik Oke untuk menyimpan setelan log.

Lakukan commit perubahan

  1. Klik Commit di bagian atas antarmuka web firewall.
  2. Tunggu hingga commit berhasil diselesaikan.
  3. Pastikan log dikirim ke agen Bindplane dengan memeriksa konsol Google SecOps untuk log firewall Palo Alto Networks yang masuk.

Meneruskan Log ke Google SecOps menggunakan agen Bindplane

  1. Instal dan siapkan Mesin Virtual Linux.
  2. Instal dan konfigurasi agen BindPlane di Linux untuk meneruskan log ke Google SecOps. Untuk mengetahui informasi selengkapnya tentang cara menginstal dan mengonfigurasi agen BindPlane, lihat petunjuk penginstalan dan konfigurasi agen BindPlane.

Jika Anda mengalami masalah saat membuat feed, hubungi dukungan SecOps Google.

Format log yang didukung

Parser firewall Palo Alto Networks mendukung log dalam format LEEF, CEF, dan CSV.

Contoh log yang didukung

  • LEEF

    <14>Jan 22 02:20:19 device_host LEEF:1.0|Palo Alto Networks|PAN-OS Syslog Integration|10.2.12-h4|Microsoft MSOFFICE(52033)|ReceiveTime=2025/01/22 02:20:18|SerialNumber=01250100xxxx|cat=THREAT|Subtype=wildfire|devTime=Jan 22 2025 08:20:18 GMT|src=198.50.100.1|dst=198.50.100.2|srcPostNAT=198.50.100.3|dstPostNAT=198.50.100.4|RuleName=AZURE-US-NEW-CNF_Inbound_To_Azure-ALLOW|usrName=|SourceUser=|DestinationUser=|Application=smtp-base|VirtualSystem=vsys1|SourceZone=McD-Global-Zone|DestinationZone=Azure-Zone|IngressInterface=ae1.111|EgressInterface=ae2.409|LogForwardingProfile=Default-Traffic-Logging|SessionID=35331795|RepeatCount=1|srcPort=21578|dstPort=25|srcPostNATPort=0|dstPostNATPort=0|Flags=0x2000|proto=tcp|action=allow|Miscellaneous=\"......3...................xls\"|ThreatID=Microsoft MSOFFICE(52033)|URLCategory=malicious|sev=4|Severity=high|Direction=client-to-server|sequence=7462614601465681755|ActionFlags=0x8000000000000000|SourceLocation=198.50.100.1-198.50.100.255|DestinationLocation=United States|ContentType=|PCAP_ID=0|FileDigest=0ea04c99bf188c2e4207f60f92ca7c6f5088c7943ee63f45c50032bbd2bf7ea9|Cloud=demo.com|URLIndex=1|RequestMethod=|FileType=ms-office|Sender=sender@ab.myownpersonaldomain.com|Subject=\"............:.................................................................................-.........(Name)-2025-01-22...............:Y107202501220005, ............:........................, ...............:.........\"|Recipient=abc@demo.myownpersonaldomain.com|ReportID=117022282776|DeviceGroupHierarchyL1=143|DeviceGroupHierarchyL2=144|DeviceGroupHierarchyL3=39|DeviceGroupHierarchyL4=0|vSrcName=|DeviceName=device_host|SrcUUID=|DstUUID=|TunnelID=0|MonitorTag=|ParentSessionID=0|ParentStartTime=|TunnelType=N/A|ThreatCategory=N/A|ContentVer=WildFire-0
    
  • CEF

    14>1 2024-04-04T16:21:56+02:00 FW-PERIMETRAL-AVG-01 - - - - CEF:0|Palo Alto Networks|PAN-OS|10.1.10-h2|end|TRAFFIC|1|src=198.51.100.1 dst=198.51.100.2 srcTranslatedAddress=198.51.100.3 dstTranslatedAddress=198.51.100.4 rule=FW_USER_NATS2_APP suser= duser= app=bittorrent vs=vsys1 sz=INSIDE dz=EXTERNAL InboundInterface=ae2.2266 OutboundInterface=ae1 lp=log_forwarding sid=2935823 cnt=1 spt=6881 dpt=51413 srcTranslatedPort=0 dstTranslatedPort=0 flags=0x7a proto=udp act=allow tbytes=475 in=150 out=325 pkt=2 pktReceived=1 pktSent=1 start=Apr 04 2024 14:21:56 GMT stime=1206 urlcat=any externalId=externalId reason=aged-out DGl1=11 DGl2=161 DGl3=0 DGl4=0 VsysName=STONESOFT dvchost=FW-PERIMETRAL-AVG-01 cat=from-policy ActionFlags=0x8000000000000000 srcUUID= dstUUID= TunnelID=0 MonitorTag= ParentSessionID=0 ParentStartTime= TunnelType=N/A SCTPAssocID=0 SCTPChunks=0 SCTPChunkSent=0 SCTPChunksRcv=0 RuleUUID=746c3eb6-3d51-4679-8438-bd0e00e170a8 HTTP2Con=0 LinkChange=0 PolicyID= LinkDetail= SDWANCluster= SDWANDevice= SDWANClustype= SDWANSite= DynamicUsrgrp= XFFIP= srcDevCat= srcDevProf= srcDevModel= srcDevVendor= srcDevOS= srcDevOSv= srcHostname= srcMac= dstDevCat= dstDevProf= dstDevModel= dstDevVendor= dstDevOS= dstDevOSv= dstHostname= dstMac= ContainerName= PODNamespace= PODName= srcEDL= dstEDL= GPHostID= EPSerial= srcDAG= dstDAG= HASessionOwner= TimeHighRes=2024-04-04T16:21:56.250+02:00 ASServiceType= ASServiceDiff="
    
  • CSV

    1,2021/10/24 15:30:07,,CONFIG,0,2561,2021/10/24 15:30:07,198.51.100.0,,set,admin,Web,Succeeded, network virtual-router  VR1,,VR1  { ecmp { algorithm { ip-modulo ; } } protocol { bgp { routing-options { graceful-restart { enable yes; } } enable no; } rip { enable no; } ospf { enable no; } ospfv3 { enable no; } } routing-table { ip { static-route { vr1-log  { path-monitor { enable no; failure-condition any; hold-time 2; } nexthop { ip-address 198.51.100.0; } bfd { profile None; } interface ethernet1/1; metric 10; destination 0.0.0.0/0; route-table { unicast ; } } } } } interface [ ethernet1/1 ethernet1/2 ]; } ,7022390503849066572,0x0,0,0,0,0,,PA-VM,0,
    

Referensi pemetaan kolom: Kolom log ke kolom UDM

Bagian ini menjelaskan cara parser memetakan kolom log firewall Palo Alto Networks ke kolom peristiwa UDM Google SecOps untuk setiap jenis log. Kunci label Google SecOps mengacu pada nama kunci yang dipetakan ke kolom UDM Labels.key.

Misalnya, untuk kolom "Virtual System", nama kolomnya adalah "cs3" dalam format CEF dan "VirtualSystem" dalam format LEEF. Kolom UDM "about.labels.key" berisi nilai "vsys" dan kolom UDM "about.labels.value" berisi nilai kolom tersebut. Beberapa nama kolom CEF atau LEEF tidak memiliki nama yang sesuai dengan nama kolom CSV. Dalam kasus tersebut, jika Anda menambahkan nama variabel Anda sendiri dalam format log kustom di profil syslog, parser tidak akan memetakannya ke kolom UDM.

Lihat bagian berikut untuk referensi pemetaan setiap jenis log:

Sistem

Tabel berikut mencantumkan kolom log jenis log sistem dan kolom UDM yang sesuai.

Kolom CSV Kolom CEF Kolom LEEF Kunci label Google Security Operations Kolom UDM
Waktu Penerimaan (receive_time atau cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (jika "Generate Time" tidak ada)

Nomor Seri (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Jenis (type) type (Header) cat metadata.product_event_type ditetapkan ke "%{type} - %{subtype}".
Jenis Ancaman/Konten (subjenis) subjenis (Header) Subjenis metadata.product_event_type ditetapkan ke "%{type} - %{subtype}".
Waktu yang Dihasilkan (time_generated atau cef-formatted-time_generated) metadata.event_timestamp
Sistem Virtual (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
ID Acara (eventid) cat eventid additional.fields.key dan additional.fields.value.string_value
Objek (object) fname Nama file objek target.resource.name
Modul (modul) flexString2 Modul modul additional.fields.key dan additional.fields.value.string_value
Tingkat keparahan (severity) $number-of-severity(header) Keparahan security_result.severity dan security_result.severity_details
Deskripsi (buram) msg msg metadata.description
principal_user_userid (Kolom ini diekstrak dari kolom msg) principal.user.userid
principal_ip3 (Kolom ini diekstrak dari kolom msg) principal.ip
Alasan (Kolom ini diekstrak dari kolom msg) security_result.description
server_address (Kolom ini diekstrak dari kolom msg.) target.ip
server_profile (Kolom ini diekstrak dari kolom msg.) additional.fields.key dan additional.fields.value.string_value
Nomor Urut (seqno) externalId urutan metadata.product_log_id
Flag Tindakan (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_1 hingga dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key dan additional.fields.value.string_value
Nama Sistem Virtual (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
Nama Perangkat (device_name) dvchost DeviceName target.hostname
Stempel Waktu Resolusi Tinggi (high_res_timestamp) anOSTimeGeneratedHighResolution additional.fields.key dan additional.fields.value.string_value

Konfigurasi

Tabel berikut mencantumkan kolom log jenis log config dan kolom UDM yang sesuai.

Kolom CSV Kolom CEF Kolom LEEF Kunci label Google Security Operations Kolom UDM
Waktu Penerimaan (receive_time atau cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (jika "Generate Time" tidak ada)

Nomor Seri (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Jenis (type) type (Header) cat metadata.product_event_type
Jenis Ancaman/Konten (subjenis) subjenis (Header) metadata.product_event_type
Waktu yang Dihasilkan (time_generated atau cef-formatted-time_generated) metadata.event_timestamp
Host (host) shost src principal.ip/hostname
Sistem Virtual (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
Perintah (cmd) act msg cmd principal.process.command_line
Admin (admin) duser usrName principal.user.userid
Klien (client) destinationServiceName klien principal.application
Hasil (result) ID Tanda Tangan (Header)(alasan) Hasil security_result.summary
Jalur Konfigurasi (path) msg ConfigurationPath principal.process.command_line
Detail Sebelum Perubahan (before_change_detail) cs1 BeforeChangeDetail before_change_detail target.resource.attribute.labels.key/value
Detail Perubahan Setelah (after_change_detail) cs2 AfterChangeDetail after_change_detail target.resource.attribute.labels.key/value
Nomor Urut (seqno) externalId urutan metadata.product_log_id
Flag Tindakan (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_1 hingga dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key dan additional.fields.value.string_value
Nama Sistem Virtual (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
Nama Perangkat (device_name) dvchost DeviceName target.hostname
Grup Perangkat (dg_id) PanOSFWDeviceGroup target.asset.attribute.labels.key/value dg_id principal.asset.attribute.labels.key/value
Komentar Audit (comment) PanOSPolicyAuditComment komentar additional.fields.key dan additional.fields.value.string_value
Stempel Waktu Resolusi Tinggi (high_res_timestamp) additional.fields.key dan additional.fields.value.string_value
Tingkat keparahan (severity) number-of-severity(header) security_result.severity dan security_result.severity_details

Ancaman/WildFire

Tabel berikut mencantumkan kolom log jenis log Threat/WildFire dan kolom UDM yang sesuai.

Kolom CSV Kolom CEF Kolom LEEF Kunci label Google Security Operations Kolom UDM
Waktu Penerimaan (receive_time atau cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (jika "Generate Time" tidak ada)

Nomor Seri (serial #) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Jenis (type) type (Header) cat metadata.product_event_type
Jenis Ancaman/Konten (subjenis) cat/subtype (Header) Subjenis metadata.product_event_type
Waktu Pembuatan (time_generated atau cef-formatted-time_generated) metadata.event_timestamp
Alamat sumber (src) src src principal.ip
Alamat tujuan (dst) dst dst target.ip
IP Sumber NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP Tujuan NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Nama Aturan (rule) cs1 RuleName security_result.rule_name
Pengguna Sumber (srcuser) suser SourceUser / usrName principal.user.userid
Pengguna Tujuan (dstuser) duser DestinationUser target.user.userid
Aplikasi (aplikasi) aplikasi Aplikasi target.application
Sistem Virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona Sumber (dari) cs4 SourceZone dari

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Zona Tujuan (ke) cs5 DestinationZone sampai

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

Antarmuka Masuk (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Antarmuka Keluar (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

Tindakan Log (logset) cs6 LogForwardingProfile logset additional.fields.key dan additional.fields.value.string_value
ID Sesi (sessionid) cn1 SessionID network.session_id
Jumlah Pengulangan (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key dan additional.fields.value.string_value
Port Sumber (sport) spt srcPort principal.port
Port Tujuan (dport) dpt dstPort target.port
Port Sumber NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Port Tujuan NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Tanda (flags) flexString1 Flag flag additional.fields.key dan additional.fields.value.string_value
Protokol IP (proto) proto proto network.ip_protocol
Tindakan (action) act tindakan security_result.action_details

security_result.action

URL/Nama file (lain-lain) permintaan Lain-lain

target.file.names (jika subjenisnya adalah 'file', 'virus', 'wildfire-virus', atau 'wildfire', maka kolom `misc` dipetakan ke target.file.names)

target.url (jika subjenisnya adalah 'url', kolom `misc` dipetakan ke target.url dan target.hostname)

Nama Ancaman/Konten (threatid) cat ThreatID security_result.threat_name
Kategori (category) cs2 URLCategory security_result.category_details
Tingkat keparahan (severity) number-of-severity(header) Keparahan security_result.severity dan security_result.severity_details
Arah (direction) flexString2 Arah network.direction
Nomor Urut (seqno) externalId urutan metadata.product_log_id
Flag Tindakan (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key dan additional.fields.value.string_value
Negara Sumber (srcloc) SourceLocation principal.location.country_or_region
Negara Tujuan (dstloc) DestinationLocation target.location.country_or_region
Jenis Konten (contenttype) ContentType contenttype additional.fields.key dan additional.fields.value.string_value
ID PCAP (pcap_id) fileId PCAP_ID pcap_id additional.fields.key dan additional.fields.value.string_value
Ringkasan File (filedigest) fileHash FileDigest target.file.sha1/md5/sha256
Cloud (cloud) filePath Cloud cloud additional.fields.key dan additional.fields.value.string_value
Indeks URL (url_idx) URLIndex url_idx additional.fields.key dan additional.fields.value.string_value
Agen Pengguna (user_agent) network.http.user_agent
Jenis File (filetype) fileType FileType target.file.mime_type
X-Forwarded-For (xff) principal.ip
Perujuk (referer) network.http.referral_url
Pengirim (sender) suid Pengirim network.email.from
Subjek (subject) msg Subjek network.email.subject
Penerima (recipient) duid Penerima network.email.to
ID Laporan (reportid) oldFileId ReportID reportid additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_1 hingga dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key dan additional.fields.value.string_value
Nama Sistem Virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nama Perangkat (device_name) dvchost DeviceName intermediary.hostname
UUID VM Sumber (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
UUID VM tujuan (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
Metode HTTP (http_method) RequestMethod network.http.method
ID/IMSI tunnel (tunnel_id/imsi) PanOSTunnelID TunnelID tunnel_id/imsi additional.fields.key dan additional.fields.value.string_value
Monitor Tag/IMEI (monitortag/imei) PanOSMonitorTag MonitorTag monitortag/imei additional.fields.key dan additional.fields.value.string_value
ID Sesi Induk (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Waktu Mulai Sesi Orang Tua (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key dan additional.fields.value.string_value
Jenis Tunnel (tunnel) PanOSTunnelType TunnelType tunnel additional.fields.key dan additional.fields.value.string_value
Kategori Ancaman (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
Versi Konten (contentver) PanOSContentVer ContentVer contentver additional.fields.key dan additional.fields.value.string_value
ID Asosiasi SCTP (assoc_id) PanOSAssocID assoc_id additional.fields.key dan additional.fields.value.string_value
ID Protokol Payload (ppid) PanOSPPID ppid additional.fields.key dan additional.fields.value.string_value
Header HTTP (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
Daftar Kategori URL (url_category_list) PanOSURLCatList url_category_list additional.fields.key dan additional.fields.value.string_value
UUID Aturan (rule_uuid) PanOSRuleUUID security_result.rule_id
Koneksi HTTP/2 (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
Nama Grup Pengguna Dinamis (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Alamat XFF (xff_ip) PanXFFIP principal.ip
Kategori Perangkat Sumber (src_category) PanSrcDeviceCat src_category principal.asset.category
Profil Perangkat Sumber (src_profile) PanSrcDeviceProf src_profile

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Model Perangkat Sumber (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
Vendor Perangkat Sumber (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
Grup OS Perangkat Sumber (src_osfamily) PanSrcDeviceOS src_osfamily principal.platform
Versi OS Perangkat Sumber (src_osversion) PanSrcDeviceOSv principal.platform_version
Nama Host Sumber (src_host) PanSrcHostname principal.hostname
Alamat MAC Sumber (src_mac) PanSrcMac principal.mac
Kategori Perangkat Tujuan (dst_category) PanDstDeviceCat dst_category target.asset.category
Profil Perangkat Tujuan (dst_profile) PanDstDeviceProf dst_profile

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

Model Perangkat Tujuan (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
Vendor Perangkat Tujuan (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
Keluarga OS Perangkat Tujuan (dst_osfamily) PanDstDeviceOS dst_osfamily target.platform
Versi OS Perangkat Tujuan (dst_osversion) PanDstDeviceOSv target.platform_version
Nama Host Tujuan (dst_host) PanDstHostname target.hostname
Alamat MAC Tujuan (dst_mac) PanDstMac target.mac
ID Penampung (container_id) PanContainerName container_id intermediary.resource.product_object_id
Namespace POD (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
Nama POD (pod_name) PanPODName pod_name target.resource.name
Daftar Dinamis Eksternal Sumber (src_edl) PanSrcEDL src_edl additional.fields.key dan additional.fields.value.string_value
Daftar Dinamis Eksternal Tujuan (dst_edl) PanDstEDL dst_edl additional.fields.key dan additional.fields.value.string_value
ID Host (hostid) PanGPHostID hostid principal.asset.asset_id
Nomor Seri Perangkat Pengguna (serialnumber) PanEPSerial principal.asset.hardware.serial_number
EDL domain (domain_edl) PanDomainEDL domain_edl additional.fields.key dan additional.fields.value.string_value
Grup Alamat Dinamis Sumber (src_dag) PanSrcDAG principal.group.group_display_name
Grup Alamat Dinamis Tujuan (dst_dag) PanDstDAG target.group.group_display_name
Hash Parsial (partial_hash) PanPartialHash partial_hash additional.fields.key dan additional.fields.value.string_value
Stempel Waktu Resolusi Tinggi (high_res timestamp) PanTimeHighRes stempel waktu resolusi tinggi additional.fields.key dan additional.fields.value.string_value
Alasan (reason) PanReasonFilteringAction alasan security_result.summary
Justifikasi (justifikasi) PanJustification perataan kanan kiri additional.fields.key dan additional.fields.value.string_value
Jenis Layanan Slice (nssai_sst) PanASServiceType nssai_sst additional.fields.key dan additional.fields.value.string_value
Subkategori Aplikasi (subcategory_of_app) subcategory_of_app additional.fields.key dan additional.fields.value.string_value
Kategori Aplikasi (category_of_app) category_of_app additional.fields.key dan additional.fields.value.string_value
Teknologi Aplikasi (technology_of_app) technology_of_app additional.fields.key dan additional.fields.value.string_value
Risiko Aplikasi (risk_of_app) risk_of_app additional.fields.key dan additional.fields.value.string_value
Karakteristik Aplikasi (characteristic_of_app) characteristic_of_app additional.fields.key dan additional.fields.value.string_value
Penampung Aplikasi (container_of_app) container_of_app additional.fields.key dan additional.fields.value.string_value
SaaS Aplikasi (is_saas_of_app) is_saas_of_app additional.fields.key dan additional.fields.value.string_value
Aplikasi yang Ditunnelkan (tunneled_app) additional.fields.key dan additional.fields.value.string_value
Jenis Alur (flow_type) additional.fields.key dan additional.fields.value.string_value
Nama Cluster (cluster_name) intermediary.resource.name
Status Aplikasi yang Tidak Diizinkan (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key dan additional.fields.value.string_value

Traffic

Tabel berikut mencantumkan kolom log jenis log traffic dan kolom UDM yang sesuai.

Kolom CSV Kolom CEF Kolom LEEF Kunci label Google Security Operations Kolom UDM
Waktu Penerimaan (receive_time atau cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (jika "Generate Time" tidak ada)

Nomor Seri (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Jenis (type) type (Header) cat/Type metadata.product_event_type
Jenis Ancaman/Konten (subjenis) subjenis (Header) Subjenis metadata.product_event_type
Waktu yang Dihasilkan (time_generated atau cef-formatted-time_generated) mulai metadata.event_timestamp
Alamat Sumber (src) src src principal.ip
Alamat Tujuan (dst) dst dst target.ip
IP Sumber NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP Tujuan NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Nama Aturan (rule) cs1 RuleName security_result.rule_name
Pengguna Sumber (srcuser) suser SourceUser principal.user.userid
Pengguna Tujuan (dstuser) duser DestinationUser target.user.userid
Aplikasi (aplikasi) aplikasi Aplikasi target.application
Sistem Virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona Sumber (dari) cs4 SourceZone dari

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Zona Tujuan (ke) cs5 DestinationZone sampai

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

Antarmuka Masuk (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Antarmuka Keluar (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

Tindakan Log (logset) cs6 LogForwardingProfile logset additional.fields.key dan additional.fields.value.string_value
ID Sesi (sessionid) cn1 SessionID network.session_id
Jumlah Pengulangan (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key dan additional.fields.value.string_value
Port Sumber (sport) spt srcPort principal.port
Port Tujuan (dport) dpt dstPort target.port
Port Sumber NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Port Tujuan NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Tanda (flags) flexString1 Flag flag additional.fields.key dan additional.fields.value.string_value
Protokol IP (proto) proto proto network.ip_protocol
Tindakan (action) act tindakan security_result.action_details

security_result.action

Byte (byte) flexNumber1 totalBytes byte additional.fields.key dan additional.fields.value.string_value
Byte Terkirim (bytes_sent) di srcBytes network.sent_bytes
Byte Diterima (bytes_received) keluar dstBytes network.received_bytes
Paket (packets) cn2 totalPackets paket additional.fields.key dan additional.fields.value.string_value
Waktu Mulai (start) StartTime mulai additional.fields.key dan additional.fields.value.string_value
Waktu Berlalu (elapsed) cn3 ElapsedTime berlalu network.session_duration.seconds
Kategori (category) cs2 URLCategory security_result.category / security_result.category_details
Nomor Urut (seqno) externalId urutan metadata.product_log_id
Flag Tindakan (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key dan additional.fields.value.string_value
Negara Sumber (srcloc) SourceLocation principal.location.country_or_region
Negara Tujuan (dstloc) DestinationLocation target.location.country_or_region
Paket Terkirim (pkts_sent) PanOSPacketsSent srcPackets pkts_sent network.sent_packets
Paket Diterima (pkts_received) PanOSPacketsReceived dstPackets pkts_received network.received_packets
Alasan Akhir Sesi (session_end_reason) alasan SessionEndReason security_result.summary
Hierarki Grup Perangkat1 (dg_hier_level_1 hingga dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat2 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat3 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key dan additional.fields.value.string_value
Nama Sistem Virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nama Perangkat (device_name) dvchost DeviceName intermediary.hostname
Sumber Tindakan (action_source) cat ActionSource action_source additional.fields.key dan additional.fields.value.string_value
UUID VM Sumber (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
UUID VM tujuan (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
ID Tunnel/IMSI (tunnelid/imsi) PanOSTunnelID TunnelID tunnelid/imsi additional.fields.key dan additional.fields.value.string_value
Monitor Tag/IMEI (monitortag/imei) PanOSMonitorTag MonitorTag monitortag/imei additional.fields.key dan additional.fields.value.string_value
ID Sesi Induk (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Waktu Mulai Induk (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key dan additional.fields.value.string_value
Jenis Tunnel (tunnel) PanOSTunnelType TunnelType tunnel additional.fields.key dan additional.fields.value.string_value
ID Asosiasi SCTP (assoc_id) PanOSSCTPAssocID assoc_id additional.fields.key dan additional.fields.value.string_value
Potongan SCTP (chunks) PanOSSCTPChunks potongan additional.fields.key dan additional.fields.value.string_value
SCTP Chunks Sent (chunks_sent) PanOSSCTPChunkSent chunks_sent additional.fields.key dan additional.fields.value.string_value
SCTP Chunks yang Diterima (chunks_received) PanOSSCTPChunksRcv chunks_received additional.fields.key dan additional.fields.value.string_value
UUID Aturan (rule_uuid) PanOSRuleUUID security_result.rule_id
Koneksi HTTP/2 (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
Jumlah Penutup Aplikasi (link_change_count) PanLinkChange link_change_count additional.fields.key dan additional.fields.value.string_value
ID Kebijakan (policy_id) PanPolicyID policy_id additional.fields.key dan additional.fields.value.string_value
Sakelar Link (link_switches) PanLinkDetail link_switches additional.fields.key dan additional.fields.value.string_value
Cluster SD-WAN (sdwan_cluster) PanSDWANCluster sdwan_cluster additional.fields.key dan additional.fields.value.string_value
Jenis Perangkat SD-WAN (sdwan_device_type) PanSDWANDevice sdwan_device_type additional.fields.key dan additional.fields.value.string_value
Jenis Cluster SD-WAN (sdwan_cluster_type) PanSDWANClustype sdwan_cluster_type additional.fields.key dan additional.fields.value.string_value
Situs SD-WAN (sdwan_site) PanSDWANSite sdwan_site additional.fields.key dan additional.fields.value.string_value
Nama Grup Pengguna Dinamis (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name additional.fields.key dan additional.fields.value.string_value
Alamat XFF (xff_ip) PanXFFIP principal.ip
Kategori Perangkat Sumber (src_category) PanSrcDeviceCat src_category principal.asset.category
Profil Perangkat Sumber (src_profile) PanSrcDeviceProf src_profile

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Model Perangkat Sumber (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
Vendor Perangkat Sumber (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
Grup OS Perangkat Sumber (src_osfamily) PanSrcDeviceOS principal.platform
Versi OS Perangkat Sumber (src_osversion) PanSrcDeviceOSv principal.asset.software.version
Nama Host Sumber (src_host) PanSrcHostname principal.hostname
Alamat MAC Sumber (src_mac) PanSrcMac principal.mac
Kategori Perangkat Tujuan (dst_category) PanDstDeviceCat dst_category target.asset.category
Profil Perangkat Tujuan (dst_profile) PanDstDeviceProf dst_profile

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

Model Perangkat Tujuan (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
Vendor Perangkat Tujuan (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
Keluarga OS Perangkat Tujuan (dst_osfamily) PanDstDeviceOS dst_osfamily target.platform
Versi OS Perangkat Tujuan (dst_osversion) PanDstDeviceOSv target.platform_version
Nama Host Tujuan (dst_host) PanDstHostname target.hostname
Alamat MAC Tujuan (dst_mac) PanDstMac target.mac
ID Penampung (container_id) PanContainerName container_id intermediary.resource.product_object_id
Namespace POD (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
Nama POD (pod_name) PanPODName pod_name target.resource.name
Daftar Dinamis Eksternal Sumber (src_edl) PanSrcEDL src_edl

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Daftar Dinamis Eksternal Tujuan (dst_edl) PanDstEDL dst_edl

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

ID Host (hostid) PanGPHostID hostid principal.asset.asset_id
Nomor Seri Perangkat Pengguna (serialnumber) PanEPSerial principal.asset.hardware.serial_number
Grup Alamat Dinamis Sumber (src_dag) PanSrcDAG principal.group.group_display_name
Grup Alamat Dinamis Tujuan (dst_dag) PanDstDAG target.group.group_display_name
Pemilik Sesi (session_owner) PanHASessionOwner session_owner additional.fields.key dan additional.fields.value.string_value
Stempel Waktu Resolusi Tinggi (high_res_timestamp) PanTimeHighRes additional.fields.key dan additional.fields.value.string_value
Jenis Layanan Slice (nsdsai_sst) PanASServiceType nsdsai_sst additional.fields.key dan additional.fields.value.string_value
Pembeda Slice (nsdsai_sd) PanASServiceDiff nsdsai_sd additional.fields.key dan additional.fields.value.string_value
Subkategori Aplikasi (subcategory_of_app) subcategory_of_app additional.fields.key dan additional.fields.value.string_value
Kategori Aplikasi (category_of_app) category_of_app additional.fields.key dan additional.fields.value.string_value
Teknologi Aplikasi (technology_of_app) technology_of_app additional.fields.key dan additional.fields.value.string_value
Risiko Aplikasi (risk_of_app) security_result.severity
Karakteristik Aplikasi (characteristic_of_app) characteristic_of_app additional.fields.key dan additional.fields.value.string_value
Penampung Aplikasi (container_of_app) container_of_app additional.fields.key dan additional.fields.value.string_value
SaaS Aplikasi (is_saas_of_app) is_saas_of_app additional.fields.key dan additional.fields.value.string_value
Status Aplikasi yang Tidak Diizinkan (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key dan additional.fields.value.string_value
Subkategori Aplikasi (subcategory_of_app) subcategory_of_app1 additional.fields.key dan additional.fields.value.string_value
Tingkat keparahan (severity) number-of-severity(header) security_result.severity dan security_result.severity_details

User-ID

Tabel berikut mencantumkan kolom log jenis log user-id dan kolom UDM yang sesuai.

Kolom CSV Kolom CEF Kolom LEEF Kunci label Google Security Operations Kolom UDM
Waktu Penerimaan (receive_time atau cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (jika "Generate Time" tidak ada)

Nomor Seri (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Jenis (type) type (Header) cat metadata.product_event_type
Jenis Ancaman/Konten (subjenis) subjenis (Header) Subjenis metadata.product_event_type
Waktu yang Dihasilkan (time_generated atau cef-formatted-time_generated) metadata.event_timestamp
Sistem Virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
IP Sumber (ip) src src principal.ip
Pengguna (user) duser usrName target.user.userid

target.administrative_domain

target.user.email_addresses

Nama Sumber Data (datasourcename) cs4 DataSourceName datasourcename

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

ID Acara (eventid) EventID eventid additional.fields.key dan additional.fields.value.string_value
Jumlah Pengulangan (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key dan additional.fields.value.string_value
Batas Waktu Tunggu (waktu tunggu) cn3 TimeoutThreshold timeout additional.fields.key dan additional.fields.value.string_value
Port Sumber (beginport) spt srcPort principal.port
Port Tujuan (endport) dpt dstPort target.port
Sumber Data (datasource) cs5 DataSource sumber data

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Jenis Sumber Data (datasourcetype) cs6 DataSourceType datasourcetype

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Nomor Urut (seqno) externalId urutan metadata.product_log_id
Flag Tindakan (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key dan additional.fields.value.string_value
Nama Sistem Virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nama Perangkat (device_name) dvchost DeviceName intermediary.hostname
ID Sistem Virtual (vsys_id) cn2 VirtualSystemID intermediary.resource.product_object_id
Jenis Faktor (factortype) cs1 FactorType factortype additional.fields.key dan additional.fields.value.string_value
Waktu Penyelesaian Faktor (factorcompletiontime) selesai FactorCompletionTime factorcompletiontime additional.fields.key dan additional.fields.value.string_value
Nomor Faktor (factorno) cn1 FactorNumber factorno additional.fields.key dan additional.fields.value.string_value
Flag Grup Pengguna (ugflags) PanOSUGFlags ugflags additional.fields.key dan additional.fields.value.string_value
Pengguna menurut Sumber (userbysource) PanOSUserBySource target.user.userid

target.administrative_domain

target.user.email_addresses

Stempel Waktu Resolusi Tinggi (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key dan additional.fields.value.string_value
Sumber Data Asal (origindatasource) additional.fields.key dan additional.fields.value.string_value
Nama Cluster (cluster_name) principal.resource.name
Tingkat keparahan (severity) number-of-severity(header) security_result.severity dan security_result.severity_details

Pencocokan HIP

Tabel berikut mencantumkan kolom log jenis log kecocokan HIP dan kolom UDM yang sesuai.

Kolom CSV Kolom CEF Kolom LEEF Kunci label Google Security Operations Kolom UDM
Waktu Penerimaan (receive_time atau cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (jika "Generate Time" tidak ada)

Nomor Seri (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Jenis (type) type (Header) cat metadata.product_event_type
Jenis Ancaman/Konten (subjenis) subjenis (Header) Subjenis
Waktu yang Dihasilkan (time_generated atau cef-formatted-time_generated) mulai startTime metadata.event_timestamp
Pengguna Sumber (srcuser) suser usrName principal.user.userid
Sistem Virtual (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
Nama Perangkat (machinename) shost identHostName principal.hostname
Sistem Operasi (os) cs2 OS principal.asset.platform_software.platform
Alamat Sumber (src) src identsrc principal.ip
HIP (matchname) cat HIP matchname

target.resource.attribute.labels.key/value

additional.fields.key dan additional.fields.value.string_value

Jumlah Pengulangan (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key dan additional.fields.value.string_value
Jenis HIP (matchtype) ID Class Peristiwa Perangkat (Header) HIPType matchtype

target.resource.attribute.labels.key/value

additional.fields.key dan additional.fields.value.string_value

Nomor Urut (seqno) externalId urutan metadata.product_log_id
Flag Tindakan (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key dan additional.fields.value.string_value
Nama Sistem Virtual (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
Nama Perangkat (device_name) dvchost DeviceName target.hostname
ID Sistem Virtual (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
Alamat Sistem IPv6 (srcipv6) c6a2 srcipv6 principal.asset.ip
ID Host (hostid) PanOSHostID principal.asset.asset_id
Nomor Seri Perangkat Pengguna (serialnumber) PanOSEndpointSerialNumber principal.asset.hardware.serial_number
Alamat MAC Perangkat (mac) PanOSEndpointMac principal.asset.mac
Stempel Waktu Resolusi Tinggi (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key dan additional.fields.value.string_value
Nama Cluster (cluster_name) principal.resource.name
Tingkat keparahan (severity) number-of-severity(header) security_result.severity dan security_result.severity_details

Tag IP

Tabel berikut mencantumkan kolom log jenis log tag IP dan kolom UDM yang sesuai.

Kolom CSV Kolom CEF Kolom LEEF Kunci label Google Security Operations Kolom UDM
Waktu Penerimaan (receive_time atau cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (jika "Generate Time" tidak ada)

Nomor Seri (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Jenis (type) type (Header) cat metadata.product_event_type
Jenis Ancaman/Konten (subjenis) subjenis (Header) Subjenis metadata.product_event_type
Waktu yang Dihasilkan (time_generated atau cef-formatted-time_generated) GenerateTime metadata.event_timestamp
Sistem Virtual (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
IP Sumber (ip) src src principal.ip
Nama Tag (tag_name) PanOSTagName TagName tag_name

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

ID Acara (event_id) PanOSEventID EventID event_id additional.fields.key dan additional.fields.value.string_value
Jumlah Pengulangan (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key dan additional.fields.value.string_value
Waktu tunggu (timeout) PanOSTimeout TimeoutThreshold timeout additional.fields.key dan additional.fields.value.string_value
Nama Sumber Data (datasourcename) PanOSDataSourceName DataSourceName datasourcename

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Jenis Sumber Data (datasource_type) PanOSDataSourceType DataSource datasource_type

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Subjenis Sumber Data (datasource_subtype) PanOSDataSourceSubType DataSourceType datasource_subtype

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Nomor Urut (seqno) externalId urutan metadata.product_log_id
Flag Tindakan (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key dan additional.fields.value.string_value
Nama Sistem Virtual (vsys_name) PanOsVsysName vSrcName target.asset.attribute.labels.key/value
Nama Perangkat (device_name) dvchost DeviceName target.hostname
ID Sistem Virtual (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
Stempel Waktu Resolusi Tinggi (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key dan additional.fields.value.string_value
Tingkat keparahan (severity) number-of-severity(header) security_result.severity dan security_result.severity_details
Nama Cluster (cluster_name) principal.resource.name

Dekripsi

Tabel berikut mencantumkan kolom log jenis log dekripsi dan kolom UDM yang sesuai.

Kolom CSV Kolom CEF Kolom LEEF Kunci label Google Security Operations Kolom UDM
Waktu Penerimaan (receive_time atau cef-formatted-receive_time) rt metadata.collected_timestamp,

metadata.event_timestamp (jika "Generate Time" tidak ada)

Nomor Seri (serial) PanOSDeviceSN intermediary.asset.hardware.serial_number
Jenis (type) type (Header) metadata.product_event_type
Jenis Ancaman/Konten (subjenis) subjenis (Header) metadata.product_event_type
Versi Konfigurasi (config_ver) PanOSConfigVersion config_ver additional.fields.key dan additional.fields.value.string_value
Waktu Pembuatan (time_generated) PanOSLogTimeStamp metadata.event_timestamp
Alamat Sumber (src) src principal.ip
Alamat Tujuan (dst) dst target.ip
IP Sumber NAT (natsrc) sourceTranslatedAddress principa.nat_ip
IP Tujuan NAT (natdst) destinationTranslatedAddress target.nat_ip
Aturan (rule) cs1 security_result.rule_name
Pengguna Sumber (srcuser) suser principal.user.userid
Pengguna Tujuan (dstuser) duser target.user.userid
Aplikasi (aplikasi) aplikasi network.application_protocol
Sistem Virtual (vsys) cs3 vsys intermediary.asset.attribute.labels.key/value
Zona Sumber (dari) cs4 dari

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Zona Tujuan (ke) cs5 sampai

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

Antarmuka Masuk (inbound_if) deviceInboundInterface inbound_if

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Antarmuka Keluar (outbound_if) deviceOutboundInterface outbound_if

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

Tindakan Log (logset) cs6 logset additional.fields.key dan additional.fields.value.string_value
Waktu Dicatat (time_received) PanOSTimeReceivedManagementPlane -
ID Sesi (sessionid) cn1 network.session_id
Jumlah Pengulangan (repeatcnt) PanOSCountOfRepeats/RepeatCount repeatcnt additional.fields.key dan additional.fields.value.string_value
Port Sumber (sport) spt principal.port
Port Tujuan (dport) dpt target.port
Port Sumber NAT (natsport) sourceTranslatedPort principal.nat_port
Port Tujuan NAT (natdport) destinationTranslatedPort target.nat_port
Tanda (flags) flexString1 flag additional.fields.key dan additional.fields.value.string_value
Protokol IP (proto) proto network.ip_protocol
Tindakan (action) act security_result.action_details

security_result.action

Tunnel (tunnel) PanOSTunnel tunnel additional.fields.key dan additional.fields.value.string_value
UUID VM Sumber (src_uuid) PanOSSourceUUID principal.asset.product_object_id
UUID VM tujuan (dst_uuid) PanOSDestinationUUID target.asset.product_object_id
UUID untuk aturan (rule_uuid) PanOSRuleUUID security_result.rule_id
Tahap Client to Firewall (hs_stage_c2f) PanOSClientToFirewall hs_stage_c2f additional.fields.key dan additional.fields.value.string_value
Tahap Firewall ke Server (hs_stage_f2s) PanOSFirewallToServer hs_stage_f2s additional.fields.key dan additional.fields.value.string_value
Versi TLS (tls_version) PanOSTLSVersion network.tls.version
Algoritma Pertukaran Kunci (tls_keyxchg) PanOSTLSKeyExchange tls_keyxchg additional.fields.key dan additional.fields.value.string_value
Algoritma Enkripsi (tls_enc) PanOSTLSEncryptionAlgorithm tls_enc additional.fields.key dan additional.fields.value.string_value
Algoritma Hash (tls_auth) PanOSTLSAuth tls_auth additional.fields.key dan additional.fields.value.string_value
Nama Kebijakan (policy_name) PanOSPolicyName policy_name additional.fields.key dan additional.fields.value.string_value
Kurva Eliptik (ec_curve) PanOSEllipticCurve network.tls.curve
Indeks Error (err_index) PanOSErrorIndex err_index additional.fields.key dan additional.fields.value.string_value
Status Root (root_status) PanOSRootStatus root_status additional.fields.key dan additional.fields.value.string_value
Status Rantai (chain_status) PanOSChainStatus chain_status additional.fields.key dan additional.fields.value.string_value
Jenis Proxy (proxy_type) PanOSProxyType proxy_type additional.fields.key dan additional.fields.value.string_value
Nomor Seri Sertifikat (cert_serial) PanOSCertificateSerial network.tls.server.certificate.serial
Sidik Jari Sertifikat (sidik jari) PanOSFingerprint network.tls.server.certificate.md5/sha1/sha256
Tanggal Mulai Sertifikat (notbefore) PanOSTimeNotBefore network.tls.server.certificate.not_before
Tanggal Akhir Sertifikat (notafter) PanOSTimeNotAfter network.tls.server.certificate.not_after
Versi Sertifikat (cert_ver) PanOSCertificateVersion network.tls.server.certificate.version
Ukuran Sertifikat (cert_size) PanOSCertificateSize cert_size additional.fields.key dan additional.fields.value.string_value
Panjang Nama Umum (cn_len) PanOSCommonNameLength cn_len additional.fields.key dan additional.fields.value.string_value
Panjang Nama Umum Penerbit (issuer_len) PanOSIssuerNameLength issuer_len additional.fields.key dan additional.fields.value.string_value
Panjang Nama Umum Root (rootcn_len) PanOSRootCNLength rootcn_len additional.fields.key dan additional.fields.value.string_value
Panjang SNI (sni_len) PanOSSNILength sni_len additional.fields.key dan additional.fields.value.string_value
Tanda Sertifikat (cert_flags) PanOSCertificateFlags cert_flags additional.fields.key dan additional.fields.value.string_value
Nama Umum Subjek (cn) PanOSCommonName cn additional.fields.key dan additional.fields.value.string_value
Nama Umum Penerbit (issuer_cn) PanOSIssuerCommonName network.tls.server.certificate.issuer
Nama Umum Root (root_cn) PanOSRootCommonName root_cn additional.fields.key dan additional.fields.value.string_value
Indikasi Nama Server

(sni)

network.tls.client.server_name
Error (error) PanOSErrorMessage error additional.fields.key dan additional.fields.value.string_value
ID Penampung (container_id) PanOSContainerID container_id intermediary.resource.product_object_id
Namespace POD (pod_namespace) PanOSContainerNameSpace pod_namespace

target.resource.attribute.labels.key/value

additional.fields.key dan additional.fields.value.string_value

Nama POD (pod_name) PanOSContainerName pod_name target.resource.name
Daftar Dinamis Eksternal Sumber (src_edl) PanOSSourceEDL src_edl

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Daftar Dinamis Eksternal Tujuan (dst_edl) PanOSDestinationEDL dst_edl

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

Grup Alamat Dinamis Sumber (src_dag) PanOSSourceDynamicAddressGroup principal.group.group_display_name
Grup Alamat Dinamis Tujuan (dst_dag) PanOSDestinationDynamicAddressGroup target.group.group_display_name
Stempel Waktu Resolusi Tinggi (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key dan additional.fields.value.string_value
Kategori Perangkat Sumber (src_category) PanOSSourceDeviceCategory src_category principal.asset.category
Profil Perangkat Sumber (src_profile) PanOSSourceDeviceProfile src_profile

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Model Perangkat Sumber (src_model) PanOSSourceDeviceModel src_model principal.asset.hardware.model
Vendor Perangkat Sumber (src_vendor) PanOSSourceDeviceVendor src_vendor principal.asset.hardware.manufacturer
Grup OS Perangkat Sumber (src_osfamily) PanOSSourceDeviceOSFamily principal.platform
Versi OS Perangkat Sumber (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
Nama Host Sumber (src_host) PanOSSourceDeviceHost principal.hostname
Alamat MAC Sumber (src_mac) PanOSSourceDeviceMac principal.mac
Kategori Perangkat Tujuan (dst_category) PanOSDestinationDeviceCategory dst_category target.asset.category
Profil Perangkat Tujuan (dst_profile) PanOSDestinationDeviceProfile dst_profile

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

Model Perangkat Tujuan (dst_model) PanOSDestinationDeviceModel dst_model target.asset.hardware.model
Vendor Perangkat Tujuan (dst_vendor) PanOSDestinationDeviceVendor dst_vendor target.asset.hardware.manufacturer
Keluarga OS Perangkat Tujuan (dst_osfamily) PanOSDestinationDeviceOSFamily dst_osfamily target.platform
Versi OS Perangkat Tujuan (dst_osversion) PanOSDestinationDeviceOSVersion target.platform_version
Nama Host Tujuan (dst_host) PanOSDestinationDeviceHost target.hostname
Alamat MAC Tujuan (dst_mac) PanOSDestinationDeviceMac target.mac
Nomor Urut (seqno) PanOSLogTypeSeqNo metadata.product_log_id
Flag Tindakan (actionflags) PanOSActionFlags actionflags additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_1) DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_2) DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_3) DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_4) DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key dan additional.fields.value.string_value
Nama Sistem Virtual (vsys_name) intermediary.asset.attribute.labels.key/value
Nama Perangkat (device_name) intermediary.hostname
ID Sistem Virtual (vsys_id) intermediary.resource.product_object_id
Subkategori Aplikasi (subcategory_of_app) subcategory_of_app additional.fields.key dan additional.fields.value.string_value
Kategori Aplikasi (category_of_app) category_of_app additional.fields.key dan additional.fields.value.string_value
Teknologi Aplikasi (technology_of_app) technology_of_app additional.fields.key dan additional.fields.value.string_value
Risiko Aplikasi (risk_of_app) security_result.severity
Karakteristik Aplikasi (characteristic_of_app) characteristic_of_app additional.fields.key dan additional.fields.value.string_value
Penampung Aplikasi (container_of_app) container_of_app additional.fields.key dan additional.fields.value.string_value
SaaS Aplikasi (is_saas_of_app) is_saas_of_app additional.fields.key dan additional.fields.value.string_value
Status Aplikasi yang Tidak Diizinkan (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key dan additional.fields.value.string_value
Tingkat keparahan (severity) number-of-severity(header) security_result.severity dan security_result.severity_details

Terowongan

Tabel berikut mencantumkan kolom log jenis log tunnel dan kolom UDM yang sesuai.

Kolom CSV Kolom CEF Kolom LEEF Kunci label Google Security Operations Kolom UDM
Waktu Penerimaan (receive_time atau cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (jika "Generate Time" tidak ada)

Nomor Seri (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Jenis (type) type (Header) cat metadata.product_event_type
Jenis Ancaman/Konten (subjenis) subjenis (Header) Subjenis metadata.product_event_type
Waktu yang Dihasilkan (time_generated atau cef-formatted-time_generated) metadata.event_timestamp
Alamat Sumber (src) src src principal.ip
Alamat Tujuan (dst) dst dst target.ip
IP Sumber NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP Tujuan NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Nama Aturan (rule) cs1 RuleName security_result.rule_name
Pengguna Sumber (srcuser) suser SourceUser / usrName principal.user.userid
Pengguna Tujuan (dstuser) duser DestinationUser target.user.userid
Aplikasi (aplikasi) aplikasi Aplikasi network.application_protocol
Sistem Virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona Sumber (dari) cs4 SourceZone dari

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Zona Tujuan (ke) cs5 DestinationZone sampai

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

Antarmuka Masuk (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Antarmuka Keluar (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

Tindakan Log (logset) cs6 LogForwardingProfile logset additional.fields.key dan additional.fields.value.string_value
ID Sesi (sessionid) cn1 SessionID network.session_id
Jumlah Pengulangan (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key dan additional.fields.value.string_value
Port Sumber (sport) spt srcPort principal.port
Port Tujuan (dport) dpt dstPort target.port
Port Sumber NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Port Tujuan NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Tanda (flags) flexString1 Flag flag additional.fields.key dan additional.fields.value.string_value
Protokol IP (proto) proto proto network.ip_protocol
Tindakan (action) act tindakan security_result.action_details

security_result.action

Tingkat keparahan (severity) number-of-severity(header) security_result.severity dan security_result.severity_details
Nomor Urut (seqno) externalId urutan metadata.product_log_id
Flag Tindakan (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key dan additional.fields.value.string_value
Lokasi Sumber (srcloc) principal.location.country_or_region
Lokasi Tujuan (dstloc) target.location.country_or_region
Hierarki Grup Perangkat (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key dan additional.fields.value.string_value
Nama Sistem Virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nama Perangkat (device_name) dvchost DeviceName intermediary.hostname
ID Tunnel (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key dan additional.fields.value.string_value
Tag Monitor (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key dan additional.fields.value.string_value
ID Sesi Induk (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Waktu Mulai Induk (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key dan additional.fields.value.string_value
Jenis Tunnel (tunnel) cs2 TunnelType tunnel additional.fields.key dan additional.fields.value.string_value
Byte (byte) flexNumber1 totalBytes byte additional.fields.key dan additional.fields.value.string_value
Byte Terkirim (bytes_sent) di srcBytes network.sent_bytes
Byte Diterima (bytes_received) keluar dstBytes network.received_bytes
Paket (packets) cn2 totalPackets paket additional.fields.key dan additional.fields.value.string_value
Paket Terkirim (pkts_sent) PanOSPacketsSent srcPackets pkts_sent network.sent_packets
Paket Diterima (pkts_received) PanOSPacketsReceived dstPackets pkts_received network.received_packets
Enkapsulasi Maksimum (max_encap) flexNumber2 MaximumEncapsulation max_encap additional.fields.key dan additional.fields.value.string_value
Protokol Tidak Dikenal (unknown_proto) cfp1 UnknownProtocol unknown_proto additional.fields.key dan additional.fields.value.string_value
Pemeriksaan Ketat (strict_check) cfp2 StrictChecking strict_check additional.fields.key dan additional.fields.value.string_value
Fragmen Tunnel (tunnel_fragment) PanOSTunnelFragment TunnelFragment tunnel_fragment additional.fields.key dan additional.fields.value.string_value
Sesi Dibuat (sessions_created) cfp3 SessionsCreated sessions_created additional.fields.key dan additional.fields.value.string_value
Sesi Ditutup (sessions_closed) cfp4 SessionsClosed sessions_closed additional.fields.key dan additional.fields.value.string_value
Alasan Akhir Sesi (session_end_reason) alasan SessionEndReason security_result.summary
Sumber Tindakan (action_source) cat ActionSource action_source additional.fields.key dan additional.fields.value.string_value
Waktu Mulai (start) startTime mulai additional.fields.key dan additional.fields.value.string_value
Waktu Berlalu (elapsed) cn3 ElapsedTime berlalu network.session_duration.seconds
Aturan Inspeksi Tunnel (tunnel_insp_rule) PanOSTunneInspectionRule security_result.rule_name = "Tunnel Inspection Rule: %{PanOSTunnelInspectionRule}"
IP Pengguna Jarak Jauh (remote_user_ip) PanOSRmtUserIP principal.ip
ID Pengguna Jarak Jauh (remote_user_id) PanOSRmtUserID remote_user_id principal.user.userid
UUID Aturan Keamanan (rule_uuid) PanOSRuleUUID security_result.rule_id
ID PCAP (pcap_id) PanOSPcapID pcap_id additional.fields.key dan additional.fields.value.string_value
Nama Grup Pengguna Dinamis (dynusergroup_name) PanDynamicUsrgrp principal.group.group_display_name
Daftar Dinamis Eksternal Sumber (src_edl) PanOSSourceEDL src_edl

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Daftar Dinamis Eksternal Tujuan (dst_edl) PanOSDestinationEDL dst_edl

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

Stempel Waktu Resolusi Tinggi (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key dan additional.fields.value.string_value
Pembeda Slice (nssai_sd) nssai_sd additional.fields.key dan additional.fields.value.string_value
Jenis Layanan Slice (nssai_sd) nssai_sd1 additional.fields.key dan additional.fields.value.string_value
ID Sesi PDU (pdu_session_id) pdu_session_id additional.fields.key dan additional.fields.value.string_value
Subkategori Aplikasi (subcategory_of_app) subcategory_of_app additional.fields.key dan additional.fields.value.string_value
Kategori Aplikasi (category_of_app) category_of_app additional.fields.key dan additional.fields.value.string_value
Teknologi Aplikasi (technology_of_app) technology_of_app additional.fields.key dan additional.fields.value.string_value
Risiko Aplikasi (risk_of_app) risk_of_app additional.fields.key dan additional.fields.value.string_value
Karakteristik Aplikasi (characteristic_of_app) characteristic_of_app additional.fields.key dan additional.fields.value.string_value
Penampung Aplikasi (container_of_app) container_of_app additional.fields.key dan additional.fields.value.string_value
SaaS Aplikasi (is_saas_of_app) is_saas_of_app additional.fields.key dan additional.fields.value.string_value
Aplikasi yang Ditunnelkan (tunneled_app) additional.fields.key dan additional.fields.value.string_value
Dikeluarkan (dikeluarkan) additional.fields.key dan additional.fields.value.string_value
Jenis Alur (flow_type) additional.fields.key dan additional.fields.value.string_value
Nama Cluster (cluster_name)

principal.resource.name

Status Aplikasi yang Tidak Diizinkan (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key dan additional.fields.value.string_value

Autentikasi

Tabel berikut mencantumkan kolom log jenis log autentikasi dan kolom UDM yang sesuai.

Kolom CSV Kolom CEF Kolom LEEF Kunci label Google Security Operations Kolom UDM
Waktu Penerimaan (receive_time atau cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (jika "Generate Time" tidak ada)

Nomor Seri (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Jenis (type) type (Header) cat metadata.product_event_type
Jenis Ancaman/Konten (subjenis) subjenis (Header) Subjenis metadata.product_event_type
Waktu yang Dihasilkan (time_generated atau cef-formatted-time_generated) metadata.event_timestamp
Sistem Virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
IP Sumber (ip) src src principal.ip
Pengguna (user) duser usrName target.user.userid
Normalisasi Pengguna (normalize_user) cs2 NormalizeUser target.user.user_display_name
Objek (object) fname ObjectName objek target.resource.name
Kebijakan Autentikasi (authpolicy) cs4 AuthPolicy authpolicy additional.fields.key dan additional.fields.value.string_value
Jumlah Pengulangan (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key dan additional.fields.value.string_value
ID autentikasi (authid) cn2 AuthenticationID authid additional.fields.key dan additional.fields.value.string_value
Vendor (vendor) flexString2 Vendor vendor additional.fields.key dan additional.fields.value.string_value
Tindakan Log (logset) cs6 LogForwardingProfile logset additional.fields.key dan additional.fields.value.string_value
Profil Server (serverprofile) cs1 ServerProfile serverprofile additional.fields.key dan additional.fields.value.string_value
Deskripsi (turun) PanOSDesc AdditionalAuthInfo security_result.description
Jenis Klien (clienttype) cs5 ClientType clienttype additional.fields.key dan additional.fields.value.string_value
Jenis Peristiwa (event) msg msg extensions.auth.auth_details
Nomor Faktor (factorno) cn1 FactorNumber factorno additional.fields.key dan additional.fields.value.string_value
Nomor Urut (seqno) externalId urutan metadata.product_log_id
Flag Tindakan (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key dan additional.fields.value.string_value
Nama Sistem Virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nama Perangkat (device_name) dvchost DeviceName intermediary.hostname
ID Sistem Virtual (vsys_id) intermediary.resource.product_object_id
Authentication Protocol (authproto) authproto additional.fields.key dan additional.fields.value.string_value
UUID untuk aturan (rule_uuid) PanOSRuleUUID/RuleUUID security_result.rule_id
Stempel Waktu Resolusi Tinggi (high_res _timestamp) PanOSTimeGeneratedHighResolution additional.fields.key dan additional.fields.value.string_value
Kategori Perangkat Sumber (src_category) PanOSSourceDeviceCategory src_category principal.asset.category
Profil Perangkat Sumber (src_profile) PanOSSourceDeviceProfile src_profile

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Model Perangkat Sumber (src_model) PanOSSourceDeviceModel src_model principal.asset.hardware.model
Vendor Perangkat Sumber (src_vendor) PanOSSourceDeviceVendor src_vendor principal.asset.hardware.manufacturer
Grup OS Perangkat Sumber (src_osfamily) PanOSSourceDeviceOSFamily

principal.asset.platform_software.platform

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Versi OS Perangkat Sumber (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
Nama Host Sumber (src_host) PanOSSourceHostname principal.hostname
Alamat MAC Sumber (src_mac) PanOSSourceMac principal.asset.mac
Wilayah (region) PanOSTrafficOriginRegion principal.location.country_or_region
Agen Pengguna (user_agent) PanOSHTTPUserAgent network.http.user_agent
ID Sesi(sessionid) PanOSTrafficSessionID network.session_id
Tingkat keparahan (severity) number-of-severity(header) security_result.severity dan security_result.severity_details
Nama Cluster (cluster_name) principal.resource.name

URL

Tabel berikut mencantumkan kolom log jenis log URL dan kolom UDM yang sesuai.

Kolom CSV Kolom CEF Kolom LEEF Kunci label Google Security Operations Kolom UDM
Waktu Penerimaan (cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (jika "Generate Time" tidak ada)

Nomor seri (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Jenis (type) type (Header) cat metadata.product_event_type
Jenis Ancaman/Konten (subjenis) subjenis (Header) Subjenis metadata.product_event_type
Buat Waktu metadata.event_timestamp
Alamat sumber (src) src src principal.ip
Alamat tujuan (dst) dst dst target.ip
IP Sumber NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP Tujuan NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Aturan (rule) cs1 RuleName security_result.rule_name
Pengguna Sumber (srcuser) suser SourceUser principal.user.userid
Pengguna Tujuan (dstuser) duser DestinationUser target.user.userid
Aplikasi (aplikasi) aplikasi Aplikasi network.application_protocol
Sistem Virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona Sumber (dari) cs4 SourceZone dari

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Zona Tujuan (ke) cs5 DestinationZone sampai

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

Antarmuka Masuk (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Antarmuka Keluar (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

Tindakan Log (logset) cs6 LogForwardingProfile logset additional.fields.key dan additional.fields.value.string_value
Waktu yang Dicatat time_logged additional.fields.key dan additional.fields.value.string_value
ID Sesi (sessionid) cn1 SessionID network.session_id
Jumlah Pengulangan (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key dan additional.fields.value.string_value
Port Sumber (sport) spt srcPort principal.port
Port Tujuan (dport) dpt dstPort target.port
Port Sumber NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Port Tujuan NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Tanda (flags) flexString1 Flag flag additional.fields.key dan additional.fields.value.string_value
Protokol IP (proto) proto proto network.ip_protocol
Tindakan (action) act tindakan security_result.action_details

security_result.action

URL/Nama file (lain-lain) Lain-lain target.file.names

target.url

Nama Ancaman/Konten (threatid) cat ThreatID security_result.threat_id
Kategori (category) cs2 URLCategory category security_result.category_details
Tingkat keparahan (severity) number-of-severity (Header) Keparahan security_result.severity

security_result.severity_details

Arah (direction) flexString2 Arah network.direction
Nomor Urut (seqno) externalId urutan metadata.product_log_id
Flag Tindakan (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key dan additional.fields.value.string_value
Negara Sumber (srcloc) SourceLocation principal.location.country_or_region
Negara Tujuan (dstloc) DestinationLocation target.location.country_or_region
contenttype (contenttype) requestContext ContentType contenttype additional.fields.key dan additional.fields.value.string_value
pcap_id (pcap_id) fileId PCAP_ID pcap_id additional.fields.key dan additional.fields.value.string_value
filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
cloud (cloud) Cloud cloud additional.fields.key dan additional.fields.value.string_value
url_idx (url_idx) URLIndex url_idx additional.fields.key dan additional.fields.value.string_value
user_agent (user_agent) requestClientApplication UserAgent network.http.user_agent
filetype (jenis file) target.file.mime_type
xff (xff) PanOSXForwarderfor identSrc xff principal.ip
perujuk (referer) PanOSReferer Referer network.http.referral_url
pengirim (sender) network.email.from
subjek (subject) Subjek network.email.subject
penerima (penerima) network.email.to
reportid (reportid) reportid additional.fields.key dan additional.fields.value.string_value
Tingkat Hierarki DG 1 (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key dan additional.fields.value.string_value
Level Hierarki DG 2 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key dan additional.fields.value.string_value
Level Hierarki DG 3 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key dan additional.fields.value.string_value
Level Hierarki DG 4 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key dan additional.fields.value.string_value
Nama Sistem Virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nama Perangkat (device_name) dvchost DeviceName intermediary.hostname
file_url (file_url) target.url
UUID VM Sumber (src_uuid) SrcUUID principal.asset.product_object_id
UUID VM tujuan (dst_uuid) DstUUID target.asset.product_object_id
http_method (http_method) requestMethod RequestMethod network.http.method
ID/IMSI Tunnel (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key dan additional.fields.value.string_value
Monitor Tag/IMEI (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key dan additional.fields.value.string_value
ID Sesi Induk (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Waktu Mulai Sesi Orang Tua (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key dan additional.fields.value.string_value
Tunnel (tunnel) PanOSTunnelType TunnelType tunnel additional.fields.key dan additional.fields.value.string_value
thr_category (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
contentver (contentver) PanOSContentVer ContentVer contentver additional.fields.key dan additional.fields.value.string_value
sig_flags (sig_flags) sig_flags additional.fields.key dan additional.fields.value.string_value
ID Asosiasi SCTP (assoc_id) PanOSAssocID assoc_id additional.fields.key dan additional.fields.value.string_value
ID Protokol Payload (ppid) PanOSPPID ppid additional.fields.key dan additional.fields.value.string_value
http_headers (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
Daftar Kategori URL (url_category_list) PanOSURLCatList url_category_list additional.fields.key dan additional.fields.value.string_value
UUID untuk aturan (rule_uuid) PanOSRuleUUID rule_uuid security_result.rule_id
Koneksi HTTP/2 (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
dynusergroup_name (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name additional.fields.key dan additional.fields.value.string_value
Alamat XFF (xff_ip) PanXFFIP principal.ip
Kategori Perangkat Sumber (src_category) PanSrcDeviceCat src_category principal.asset.category
Profil Perangkat Sumber (src_profile) PanSrcDeviceProf src_profile

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Model Perangkat Sumber (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
Vendor Perangkat Sumber (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
Grup OS Perangkat Sumber (src_osfamily) PanSrcDeviceOS principal.platform
Versi OS Perangkat Sumber (src_osversion) PanSrcDeviceOSv principal.platform_version
Nama Host Sumber (src_host) PanSrcHostname src_host principal.hostname
Alamat Mac Sumber (src_mac) PanSrcMac principal.mac
Kategori Perangkat Tujuan (dst_category) PanDstDeviceCat dst_category target.asset.category
Profil Perangkat Tujuan (dst_profile) PanDstDeviceProf dst_profile

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

Model Perangkat Tujuan (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
Vendor Perangkat Tujuan (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
Keluarga OS Perangkat Tujuan (dst_osfamily) PanDstDeviceOS target.platform
Versi OS Perangkat Tujuan (dst_osversion) PanDstDeviceOSv target.platform_version
Nama Host Tujuan (dst_host) PanPODNamespace target.hostname
Alamat Mac Tujuan (dst_mac) PanDstMac target.mac
ID Penampung (container_id) PanContainerName container_id intermediary.resource.product_object_id
Namespace POD (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
Nama POD (pod_name) PanPODName pod_name target.resource.name
Daftar Dinamis Eksternal Sumber (src_edl) PanSrcEDL src_edl

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Daftar Dinamis Eksternal Tujuan (dst_edl) PanDstEDL dst_edl

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

ID Host (hostid) PanGPHostID hostid principal.asset.asset_id
Nomor Seri (serialnumber) PanEPSerial principal.asset.hardware.serial_number
domain_edl (domain_edl) PanDomainEDL domain_edl additional.fields.key dan additional.fields.value.string_value
Grup Alamat Dinamis Sumber (src_dag) PanSrcDAG principal.group.group_display_name
Grup Alamat Dinamis Tujuan (dst_dag) PanDstDAG target.group.group_display_name
partial_hash (partial_hash) PanPartialHash partial_hash additional.fields.key dan additional.fields.value.string_value
Stempel Waktu Resolusi Tinggi (high_res_timestamp) PanTimeHighRes additional.fields.key dan additional.fields.value.string_value
Alasan (reason) PanReasonFilteringAction alasan security_result.summary
justifikasi (justifikasi) PanJustification perataan kanan kiri additional.fields.key dan additional.fields.value.string_value
nssai_sst (nssai_sst) PanASServiceType nssai_sst additional.fields.key dan additional.fields.value.string_value
Subkategori aplikasi (subcategory_of_app) subcategory_of_app additional.fields.key dan additional.fields.value.string_value
Kategori aplikasi (category_of_app) category_of_app additional.fields.key dan additional.fields.value.string_value
Teknologi aplikasi (technology_of_app) technology_of_app additional.fields.key dan additional.fields.value.string_value
Risiko aplikasi (risk_of_app) risk_of_app additional.fields.key dan additional.fields.value.string_value
Karakteristik aplikasi (characteristic_of_app) characteristic_of_app additional.fields.key dan additional.fields.value.string_value
Container aplikasi (container_of_app) container_of_app additional.fields.key dan additional.fields.value.string_value
Aplikasi yang di-tunnel (tunneled_app) tunneled_app additional.fields.key dan additional.fields.value.string_value
SaaS aplikasi (is_saas_of_app) is_saas_of_app additional.fields.key dan additional.fields.value.string_value
Status aplikasi yang tidak diizinkan (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key dan additional.fields.value.string_value
ID Laporan Cloud (cloud_reportid) additional.fields.key dan additional.fields.value.string_value
Nama Cluster (cluster_name)

principal.resource.name

Jenis Alur (flow_type) additional.fields.key dan additional.fields.value.string_value

Data

Tabel berikut mencantumkan kolom log jenis log data dan kolom UDM yang sesuai.

Kolom CSV Kolom CEF Kolom LEEF Kunci label Google Security Operations Kolom UDM
Waktu Penerimaan (cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (jika "Generate Time" tidak ada)

Nomor seri (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Jenis (type) type (Header) cat metadata.product_event_type
Jenis Ancaman/Konten (subjenis) subjenis (Header) Subjenis metadata.product_event_type
Buat Waktu metadata.event_timestamp
Alamat sumber (src) src src principal.ip
Alamat tujuan (dst) dst dst target.ip
IP Sumber NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP Tujuan NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Aturan (rule) cs1 RuleName security_result.rule_name
Pengguna Sumber (srcuser) suser SourceUser principal.user.userid
Pengguna Tujuan (dstuser) duser DestinationUser target.user.userid
Aplikasi (aplikasi) aplikasi Aplikasi network.application_protocol
Sistem Virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona Sumber (dari) cs4 SourceZone dari

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Zona Tujuan (ke) cs5 DestinationZone sampai

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

Antarmuka Masuk (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Antarmuka Keluar (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

Tindakan Log (logset) cs6 LogForwardingProfile logset additional.fields.key dan additional.fields.value.string_value
Waktu yang Dicatat time_logged additional.fields.key dan additional.fields.value.string_value
ID Sesi (sessionid) cn1 SessionID network.session_id
Jumlah Pengulangan (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key dan additional.fields.value.string_value
Port Sumber (sport) spt srcPort principal.port
Port Tujuan (dport) dpt dstPort target.port
Port Sumber NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Port Tujuan NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Tanda (flags) flexString1 Flag flag additional.fields.key dan additional.fields.value.string_value
Protokol IP (proto) proto proto network.ip_protocol
Tindakan (action) act tindakan security_result.action_details

security_result.action

URL/Nama file (lain-lain) Lain-lain target.file.names

target.url

Nama Ancaman/Konten (threatid) cat ThreatID security_result.threat_id
Kategori (category) cs2 URLCategory category security_result.category_details
Tingkat keparahan (severity) number-of-severity (Header) Keparahan security_result.severity

security_result.severity_details

Arah (direction) flexString2 Arah network.direction
Nomor Urut (seqno) externalId urutan metadata.product_log_id
Flag Tindakan (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key dan additional.fields.value.string_value
Negara Sumber (srcloc) SourceLocation principal.location.country_or_region
Negara Tujuan (dstloc) DestinationLocation target.location.country_or_region
contenttype (contenttype) ContentType contenttype additional.fields.key dan additional.fields.value.string_value
pcap_id (pcap_id) fileId PCAP_ID pcap_id additional.fields.key dan additional.fields.value.string_value
filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
cloud (cloud) Cloud cloud additional.fields.key dan additional.fields.value.string_value
url_idx (url_idx) URLIndex url_idx additional.fields.key dan additional.fields.value.string_value
user_agent (user_agent) network.http.user_agent
filetype (jenis file) target.file.mime_type
xff (xff) xff principal.ip
perujuk (referer) network.http.referral_url
pengirim (sender) network.email.from
subjek (subject) Subjek network.email.subject
penerima (penerima) network.email.to
reportid (reportid) reportid additional.fields.key dan additional.fields.value.string_value
Tingkat Hierarki DG 1 (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key dan additional.fields.value.string_value
Level Hierarki DG 2 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key dan additional.fields.value.string_value
Level Hierarki DG 3 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key dan additional.fields.value.string_value
Level Hierarki DG 4 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key dan additional.fields.value.string_value
Nama Sistem Virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nama Perangkat (device_name) dvchost DeviceName intermediary.hostname
file_url (file_url) target.url
UUID VM Sumber (src_uuid) SrcUUID principal.asset.product_object_id
UUID VM tujuan (dst_uuid) DstUUID target.asset.product_object_id
http_method (http_method) RequestMethod network.http.method
ID/IMSI Tunnel (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key dan additional.fields.value.string_value
Monitor Tag/IMEI (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key dan additional.fields.value.string_value
ID Sesi Induk (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Waktu Mulai Sesi Orang Tua (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key dan additional.fields.value.string_value
Tunnel (tunnel) PanOSTunnelType TunnelType tunnel additional.fields.key dan additional.fields.value.string_value
thr_category (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
contentver (contentver) PanOSContentVer ContentVer contentver additional.fields.key dan additional.fields.value.string_value
sig_flags (sig_flags) sig_flags additional.fields.key dan additional.fields.value.string_value
ID Asosiasi SCTP (assoc_id) PanOSAssocID assoc_id additional.fields.key dan additional.fields.value.string_value
ID Protokol Payload (ppid) PanOSPPID ppid additional.fields.key dan additional.fields.value.string_value
http_headers (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
Daftar Kategori URL (url_category_list) url_category_list additional.fields.key dan additional.fields.value.string_value
UUID untuk aturan (rule_uuid) PanOSRuleUUID rule_uuid security_result.rule_id
Koneksi HTTP/2 (http2_connection) http2_connection network.application_protocol_version
dynusergroup_name (dynusergroup_name) dynusergroup_name

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Alamat XFF (xff_ip) principal.ip
Kategori Perangkat Sumber (src_category) src_category principal.asset.category
Profil Perangkat Sumber (src_profile) src_profile

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Model Perangkat Sumber (src_model) src_model principal.asset.hardware.model
Vendor Perangkat Sumber (src_vendor) src_vendor principal.asset.hardware.manufacturer
Grup OS Perangkat Sumber (src_osfamily) principal.platform
Versi OS Perangkat Sumber (src_osversion) principal.platform_version
Nama Host Sumber (src_host) src_host principal.hostname
Alamat Mac Sumber (src_mac) principal.mac
Kategori Perangkat Tujuan (dst_category) dst_category target.asset.category
Profil Perangkat Tujuan (dst_profile) dst_profile

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

Model Perangkat Tujuan (dst_model) dst_model target.asset.hardware.model
Vendor Perangkat Tujuan (dst_vendor) dst_vendor target.asset.hardware.manufacturer
Keluarga OS Perangkat Tujuan (dst_osfamily) target.platform
Versi OS Perangkat Tujuan (dst_osversion) target.platform_version
Nama Host Tujuan (dst_host) target.hostname
Alamat Mac Tujuan (dst_mac) target.mac
ID Penampung (container_id) container_id intermediary.resource.product_object_id
Namespace POD (pod_namespace) pod_namespace target.resource.attribute.labels.key/value
Nama POD (pod_name) pod_name target.resource.name
Daftar Dinamis Eksternal Sumber (src_edl) src_edl

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Daftar Dinamis Eksternal Tujuan (dst_edl) dst_edl

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

ID Host (hostid) hostid principal.asset.asset_id
Nomor Seri (serialnumber) principal.asset.hardware.serial_number
domain_edl (domain_edl) domain_edl additional.fields.key dan additional.fields.value.string_value
Grup Alamat Dinamis Sumber (src_dag) principal.group.group_display_name
Grup Alamat Dinamis Tujuan (dst_dag) target.group.group_display_name
partial_hash (partial_hash) partial_hash additional.fields.key dan additional.fields.value.string_value
Stempel Waktu Resolusi Tinggi (high_res_timestamp) additional.fields.key dan additional.fields.value.string_value
Alasan (reason) alasan security_result.summary
justifikasi (justifikasi) perataan kanan kiri additional.fields.key dan additional.fields.value.string_value
nssai_sst (nssai_sst) nssai_sst additional.fields.key dan additional.fields.value.string_value
Subkategori aplikasi (subcategory_of_app) subcategory_of_app additional.fields.key dan additional.fields.value.string_value
Kategori aplikasi (category_of_app) category_of_app additional.fields.key dan additional.fields.value.string_value
Teknologi aplikasi (technology_of_app) technology_of_app additional.fields.key dan additional.fields.value.string_value
Risiko aplikasi (risk_of_app) risk_of_app additional.fields.key dan additional.fields.value.string_value
Karakteristik aplikasi (characteristic_of_app) characteristic_of_app additional.fields.key dan additional.fields.value.string_value
Container aplikasi (container_of_app) container_of_app additional.fields.key dan additional.fields.value.string_value
Aplikasi yang di-tunnel (tunneled_app) tunneled_app additional.fields.key dan additional.fields.value.string_value
SaaS aplikasi (is_saas_of_app) is_saas_of_app additional.fields.key dan additional.fields.value.string_value
Status aplikasi yang tidak diizinkan (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key dan additional.fields.value.string_value
ID Laporan Cloud (cloud_reportid) additional.fields.key dan additional.fields.value.string_value
Nama Cluster (cluster_name) principal.resource.name
Jenis Alur (flow_type) additional.fields.key dan additional.fields.value.string_value

GlobalProtect

Tabel berikut mencantumkan kolom log jenis log GlobalProtect dan kolom UDM yang sesuai.

Kolom CSV Kolom CEF Kolom LEEF Kunci label Google Security Operations Kolom UDM
Waktu Diterima (receive_time) rt received_time metadata.event_timestamp
Nomor seri (serial) PanOSDeviceSN intermediary_asset_hardware_serial_number intermediary.asset.hardware.serial_number
Jenis (type) type (Header) metadata.product_event_type
Jenis Ancaman/Konten (subjenis) subjenis (Header) Subjenis metadata.product_event_type
Waktu Pembuatan (time_generated) PanOSLogTimeStamp generated_timestamp metadata.event_timestamp
Sistem Virtual (vsys) PanOSVirtualSystem vsys intermediary.asset.attribute.labels.key/value
ID Acara (eventid) PanOSEventID event_id additional.fields.key dan additional.fields.value.string_value
Tahap (stage) PanOSStage tahap additional.fields.key dan additional.fields.value.string_value
Metode Autentikasi (auth_method) PanOSAuthMethod extension_auth_auth_details extensions.auth.auth_details
Jenis Tunnel (tunnel_type) PanOSTunnelType tunnel additional.fields.key dan additional.fields.value.string_value
Pengguna Sumber (srcuser) PanOSSourceUserName src_user principal.user.email_address

principal.user.userid

principal.administrative_domain

Wilayah Sumber (srcregion) PanOSSourceRegion src_region principal.location.country_or_region
Nama Perangkat (machinename) PanOSEndpointDeviceName machine_name principal.hostname
IP Publik (public_ip) PanOSPublicIPv4 principal.nat_ip
IPv6 publik (public_ipv6) PanOSPublicIPv6 principal.nat_ip
IP Pribadi (private_ip) PanOSPrivateIPv4 principal.ip
IPv6 pribadi (private_ipv6) PanOSPrivateIPv6 principal.ip
ID Host (hostid) PanOSHostID hostid principal.asset.asset_id
Nomor Seri (serialnumber) PanOSDeviceSN principal.asset.hardware.serial_number
Versi Klien (client_ver) PanOSGlobalProtectClientVersion client_ver additional.fields.key dan additional.fields.value.string_value
OS Klien (client_os) PanOSEndpointOSType principal.platform
Versi OS Klien (client_os_ver) PanOSEndpointOSVersion principal.platform_version
Jumlah Pengulangan (repeatcnt) PanOSCountOfRepeats repeatcnt additional.fields.key dan additional.fields.value.string_value
Alasan (reason) PanOSQuarantineReason security_result.summary
Error (error) PanOSConnectionError error security_result.description
Deskripsi (buram) PanOSDescription security_result.description
Status (status) PanOSEventStatus status additional.fields.key dan additional.fields.value.string_value
Lokasi (location) PanOSGPGatewayLocation target.location.country_or_region
Durasi Login (login_duration) PanOSLoginDuration network.session_duration
Metode Koneksi (connect_method) PanOSConnectionMethod connect_method additional.fields.key dan additional.fields.value.string_value
Kode Error (error_code) PanOSConnectionErrorID error_code additional.fields.key dan additional.fields.value.string_value
Portal (portal) PanOSPortal portal additional.fields.key dan additional.fields.value.string_value
Nomor Urut (seqno) PanOSSequenceNo metadata.product_log_id
Flag Tindakan (actionflags) PanOSActionFlags actionflags additional.fields.key dan additional.fields.value.string_value
Stempel Waktu Resolusi Tinggi (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key dan additional.fields.value.string_value
Metode Pemilihan Gateway (selection_type) PanOSGatewaySelectionType selection_type additional.fields.key dan additional.fields.value.string_value
Waktu Respons SSL (response_time) PanOSSSLResponseTime response_time additional.fields.key dan additional.fields.value.string_value
Prioritas Gateway (prioritas) PanOSGatewayPriority priority additional.fields.key dan additional.fields.value.string_value
Gateway yang Dicoba (attempted_gateways) PanOSAttemptedGateways attempted_gateways additional.fields.key dan additional.fields.value.string_value
Nama Gateway (gateway) PanOSAttemptedGateways gateway target.resource.name
Hierarki Grup Perangkat (dg_hier_level_1) dg_hier_level_1 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_2) dg_hier_level_2 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_3) dg_hier_level_3 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat (dg_hier_level_4) dg_hier_level_4 additional.fields.key dan additional.fields.value.string_value
Nama Sistem Virtual (vsys_name) intermediary.asset.attribute.labels.key/value
Nama Perangkat (device_name) intermediary.hostname
ID Sistem Virtual (vsys_id) intermediary.resource.product_object_id
Tingkat keparahan (severity) number-of-severity(header) security_result.severity dan security_result.severity_details
Nama Cluster (cluster_name) principal.resource.name

Korelasi

Tabel berikut mencantumkan kolom log jenis log Korelasi dan kolom UDM yang sesuai.

Kolom CSV Kolom CEF Kolom LEEF Kunci label Google Security Operations Kolom UDM
Waktu yang Dihasilkan (time_generated atau cef-formatted-time_generated) startTime generated_timestamp metadata.event_timestamp
Alamat Sumber (src) src principal.ip
Pengguna Sumber (srcuser) SourceUser / usrName principal.user.userid
Sistem Virtual (vsys) VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Kategori (category) security_result.category_details
Tingkat keparahan (severity) Keparahan security_result.severity dan security_result.severity_details
Hierarki Grup Perangkat Level 1 DeviceGroupHierarchyL1 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat Level 2 DeviceGroupHierarchyL2 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat Level 3 DeviceGroupHierarchyL3 additional.fields.key dan additional.fields.value.string_value
Hierarki Grup Perangkat Level 4 DeviceGroupHierarchyL4 additional.fields.key dan additional.fields.value.string_value
Nama Sistem Virtual (vsys_name) vSrcName intermediary.asset.attribute.labels.key/value
Nama Perangkat (device_name) DeviceName intermediary.hostname
ID Sistem Virtual (vsys_id) VirtualSystemID intermediary.resource.product_object_id
Nama Objek (objectname) ObjectName target.resource.name
ID Objek (object_id) ObjectID target.resource.product_object_id
Bukti (evidence) msg security_result.summary

GTP

Tabel berikut mencantumkan kolom log jenis log gtp dan kolom UDM yang sesuai.

Kolom CSV Kolom CEF Kolom LEEF Kunci label Google Security Operations Kolom UDM
Waktu Penerimaan (receive_time atau cef-formatted-receive_time) metadata.collected_timestamp,

metadata.event_timestamp (jika "Generate Time" tidak ada)

Nomor Seri (serial) intermediary.asset.hardware.serial_number
Jenis (type) metadata.product_event_type
Jenis Ancaman/Konten (subjenis) metadata.product_event_type
Waktu yang Dihasilkan (time_generated atau cef-formatted-time_generated) metadata.event_timestamp
Alamat Sumber (src) principal.ip
Alamat Tujuan (dst) target.ip
Nama Aturan (rule) security_result.rule_name
Aplikasi (aplikasi) network.application_protocol
Sistem Virtual (vsys) vsys intermediary.asset.attribute.labels.key/value
Zona Sumber (dari) dari

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Zona Tujuan (ke) sampai

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

Antarmuka Masuk (inbound_if) inbound_if

principal.labels.key dan principal.labels.value

additional.fields.key dan additional.fields.value.string_value

Antarmuka Keluar (outbound_if) outbound_if

target.labels.key dan target.labels.value

additional.fields.key dan additional.fields.value.string_value

Tindakan Log (logset) logset additional.fields.key dan additional.fields.value.string_value
ID Sesi (sessionid) network.session_id
Port Sumber (sport) principal.port
Port Tujuan (dport) target.port
Protokol IP (proto) network.ip_protocol
Tindakan (action) security_result.action_details

security_result.action

Jenis Peristiwa GTP (event_type) gtp_event_type additional.fields.key dan additional.fields.value.string_value
MSISDN (msisdn) msisdn additional.fields.key dan additional.fields.value.string_value
Nama Poin Akses (apn) apn additional.fields.key dan additional.fields.value.string_value
Teknologi Akses Radio (rat) tikus additional.fields.key dan additional.fields.value.string_value
Jenis Pesan GTP (msg_type) gtp_msg_type additional.fields.key dan additional.fields.value.string_value
Alamat IP Akhir (end_ip_adr) principal.ip
Tunnel Endpoint Identifier1 (teid1) teid1 additional.fields.key dan additional.fields.value.string_value
Tunnel Endpoint Identifier2 (teid2) teid2 additional.fields.key dan additional.fields.value.string_value
Antarmuka GTP (gtp_interface) gtp_interface additional.fields.key dan additional.fields.value.string_value
Penyebab GTP (cause_code) gtp_cause_code additional.fields.key dan additional.fields.value.string_value
Tingkat keparahan (severity) security_result.severity dan security_result.severity_details
MCC Jaringan Penayangan (mcc) mcc additional.fields.key dan additional.fields.value.string_value
Menyajikan MNC Jaringan (mnc) mnc additional.fields.key dan additional.fields.value.string_value
Kode Area (area_code) area_code additional.fields.key dan additional.fields.value.string_value
ID Sel (cell_id) cell_id additional.fields.key dan additional.fields.value.string_value
Kode Acara GTP (event_code) event_code additional.fields.key dan additional.fields.value.string_value
Lokasi Sumber (srcloc) principal.location.country_or_region
Lokasi Tujuan (dstloc) target.location.country_or_region
ID/IMSI Tunnel (imsi) tunnelid additional.fields.key dan additional.fields.value.string_value
Tag/IMEI Monitor (imei) monitortag additional.fields.key dan additional.fields.value.string_value
Waktu Mulai (start) mulai additional.fields.key dan additional.fields.value.string_value
Waktu Berlalu (elapsed) network.session_duration.seconds
Aturan Inspeksi Tunnel (tunnel_insp_rule) tunnel_insp_rule security_result.detection_fields.key/value
IP Pengguna Jarak Jauh (remote_user_ip) principal.ip
ID Pengguna Jarak Jauh (remote_user_id) remote_user_id principal.user.userid
UUID untuk aturan (rule_uuid) security_result.rule_id
ID PCAP (pcap_id) pcap_id additional.fields.key dan additional.fields.value.string_value
Stempel Waktu Resolusi Tinggi (high_res_timestamp) additional.fields.key dan additional.fields.value.string_value
Jenis Layanan Slice (nsdsai_sst) nsdsai_sst additional.fields.key dan additional.fields.value.string_value
Pembeda Slice (nsdsai_sd) nsdsai_sd additional.fields.key dan additional.fields.value.string_value
Subkategori Aplikasi (subcategory_of_app) subcategory_of_app additional.fields.key dan additional.fields.value.string_value
Kategori Aplikasi (category_of_app) category_of_app additional.fields.key dan additional.fields.value.string_value
Teknologi Aplikasi (technology_of_app) technology_of_app additional.fields.key dan additional.fields.value.string_value
Risiko Aplikasi (risk_of_app) risk_of_app additional.fields.key dan additional.fields.value.string_value
Karakteristik Aplikasi (characteristic_of_app) characteristic_of_app additional.fields.key dan additional.fields.value.string_value
Penampung Aplikasi (container_of_app) container_of_app additional.fields.key dan additional.fields.value.string_value
SaaS Aplikasi (is_saas_of_app) is_saas_of_app additional.fields.key dan additional.fields.value.string_value
Status Aplikasi yang Tidak Diizinkan (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key dan additional.fields.value.string_value

SCTP

Kolom CSV Kolom CEF Kolom LEEF Kunci label Google Security Operations Kolom UDM
Waktu Penerimaan (receive_time atau cef-formatted-receive_time) receive_time atau cef-formatted-receive_time metadata.collected_timestamp
Nomor Seri (serial) serial intermediary.asset.hardware.serial_number
Jenis (type) jenis metadata.product_event_type
Waktu yang Dihasilkan (time_generated atau cef-formatted-time_generated) time_generated atau cef-formatted-time_generated metadata.event_timestamp
Alamat Sumber (src) src principal.ip
Alamat Tujuan (dst) dst target.ip
Nama Aturan (rule) aturan security_result.rule_name
Zona Sumber (dari) dari additional.fields.key dan additional.fields.value.string_value
Zona Tujuan (ke) sampai additional.fields.key dan additional.fields.value.string_value
Antarmuka Masuk (inbound_if) inbound_if additional.fields.key dan additional.fields.value.string_value
Antarmuka Keluar (outbound_if) outbound_if additional.fields.key dan additional.fields.value.string_value
Tindakan Log (logset) logset additional.fields.key dan additional.fields.value.string_value
ID Sesi (sessionid) sessionid network.session_id
Jumlah Pengulangan (repeatcnt) repeatcnt additional.fields.key dan additional.fields.value.string_value
Port Sumber (sport) olahraga principal.port
Port Tujuan (dport) dport target.port
Protokol IP (proto) proto network.ip_protocol (enum)
Tindakan (action) tindakan security_result.action_details
security_result.action
Hierarki Grup Perangkat (dg_hier_level_1 hingga dg_hier_level_4) dg_hier_level_1 hingga dg_hier_level_4 additional.fields.key dan additional.fields.value.string_value
Nama Perangkat (device_name) device_name intermediary.hostname
Nomor Urut (seqno) seqno metadata.product_log_id
ID Asosiasi SCTP (assoc_id) assoc_id additional.fields.key dan additional.fields.value.string_value
ID Protokol Payload (ppid) ppid additional.fields.key dan additional.fields.value.string_value
Tingkat keparahan (severity) tingkat keseriusan, security_result.severity dan security_result.severity_details
Jenis Chunk SCTP (sctp_chunk_type) sctp_chunk_type additional.fields.key dan additional.fields.value.string_value
Jenis Peristiwa SCTP (sctp_event_type) sctp_event_type additional.fields.key dan additional.fields.value.string_value
Tag Verifikasi SCTP 1 (verif_tag_1) verif_tag_1 additional.fields.key dan additional.fields.value.string_value
Tag Verifikasi SCTP 2 (verif_tag_2) verif_tag_2 additional.fields.key dan additional.fields.value.string_value
Kode Penyebab SCTP (sctp_cause_code) sctp_cause_code additional.fields.key dan additional.fields.value.string_value
ID Aplikasi Diameter (diam_app_id) diam_app_id additional.fields.key dan additional.fields.value.string_value
Kode Perintah Diameter (diam_cmd_code) diam_cmd_code additional.fields.key dan additional.fields.value.string_value
Kode AVP Diameter (diam_avp_code) diam_avp_code additional.fields.key dan additional.fields.value.string_value
ID Aliran SCTP (stream_id) stream_id additional.fields.key dan additional.fields.value.string_value
Alasan Berakhirnya Asosiasi SCTP (assoc_end_reason) assoc_end_reason additional.fields.key dan additional.fields.value.string_value
Kode Operasi (op_code) op_code additional.fields.key dan additional.fields.value.string_value
SSN Pihak Pemanggil SCCP (sccp_calling_ssn) sccp_calling_ssn additional.fields.key dan additional.fields.value.string_value
Judul Global Pihak Pemanggil SCCP (sccp_calling_gt) sccp_calling_gt additional.fields.key dan additional.fields.value.string_value
Filter SCTP (sctp_filter) sctp_filter additional.fields.key dan additional.fields.value.string_value
Potongan SCTP (chunks) potongan additional.fields.key dan additional.fields.value.string_value
SCTP Chunks Sent (chunks_sent) chunks_sent additional.fields.key dan additional.fields.value.string_value
SCTP Chunks yang Diterima (chunks_received) chunks_received additional.fields.key dan additional.fields.value.string_value
Paket (packets) paket additional.fields.key dan additional.fields.value.string_value
UUID untuk aturan (rule_uuid) rule_uuid security_result.rule_id
Sistem Virtual (vsys) vsys intermediary.asset.attribute.labels.key/value
Nama Sistem Virtual (vsys_name) vsys_name intermediary.asset.attribute.labels.key/value
Paket Terkirim (pkts_sent) pkts_sent network.sent_packets
Paket Diterima (pkts_received) pkts_received network.received_packets

Audit

Kolom CSV Kolom CEF Kolom LEEF Kunci label Google Security Operations Kolom UDM
Buat Waktu metadata.event_timestamp
Jenis Ancaman/Konten (subjenis) metadata.product_event_type
ID acara principal.application
Objek principal.user.userid
Perintah CLI principal.process.command_line
Keparahan security_result.severity
Nomor Seri intermediary.asset.hardware.serial_number

Referensi pemetaan kolom: Jenis log ke jenis peristiwa UDM

Tabel berikut mencantumkan jenis log firewall Palo Alto Networks dan jenis peristiwa UDM yang sesuai.

Jenis log Jenis peristiwa UDM
Traffic NETWORK_CONNECTION
Ancaman NETWORK_CONNECTION
Pemfilteran URL NETWORK_CONNECTION
WildFire NETWORK_CONNECTION

Log pengiriman WildFire adalah subtipe dari jenis log Ancaman dan menggunakan format syslog yang sama.

Pemfilteran Data NETWORK_CONNECTION
Terowongan NETWORK_CONNECTION
GTP NETWORK_CONNECTION
Konfigurasi SETTING_MODIFICATION/SETTING_CREATION/SETTING_DELETION/SETTING_UNCATEGORIZED

Nilai kolom "Command (cmd)" menentukan pemetaan jenis peristiwa UDM. Jika nilai kolom cmd adalah add atau clone, SETTING_CREATION akan disetel.

Jika nilai kolom cmd adalah delete, SETTING_DELETION akan disetel.

Jika nilai kolom cmd adalah edit, move, rename, set, atau commit, SETTING_MODIFICATION akan ditetapkan.

Jika nilai kolom cmd tidak berisi nilai apa pun, SETTING_UNCATEGORIZED akan ditetapkan.

Sistem

Jika nilai subjenis adalah "dhcp", maka NETWORK_DHCP akan disetel.

Jika nilai subjenis adalah "auth", USER_LOGIN akan disetel.

Jika nilai deskripsi adalah "logged in", maka USER_LOGIN akan ditetapkan.

Jika nilai deskripsi adalah "logged out", maka USER_LOGOUT akan disetel.

Untuk nilai subtype lainnya, GENERIC_EVENT ditetapkan.

Pencocokan HIP NETWORK_CONNECTION
Tag IP GENERIC_EVENT
User-ID USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED

Jika nilai subjenis adalah "login", USER_LOGIN akan disetel.

Jika nilai subjenis adalah "logout", USER_LOGOUT akan disetel.

Jika subtipe tidak berisi nilai apa pun, USER_UNCATEGORIZED akan ditetapkan.

Dekripsi NETWORK_CONNECTION
Authentication GENERIC_EVENT
SCTP NETWORK_CONNECTION
Audit GENERIC_EVENT

Delta Pemetaan UDM

Referensi Perbedaan Pemetaan UDM: Firewall Palo Alto Networks

Tabel berikut mencantumkan perbedaan antara Pemetaan UDM Lama Palo Alto Networks Firewall dan Pemetaan UDM Baru Palo Alto Networks Firewall.

UDM Event Type Delta

Log type Old UDM Event Type New UDM Event Type
WildFire NETWORK_CONNECTION SCAN_UNCATEGORIZED
Data Filtering NETWORK_CONNECTION NETWORK_UNCATEGORIZED
Authentication STATUS_UPDATE STATUS_UNCATEGORIZED

UDM Field Mapping Delta

Log Type Old UDM Mapping CSV Log Field CEF Log Field LEEF Log Field New UDM Mapping
System intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
System about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
System about.labels.key/value additional.fields.key/value.string_value Object (object) fname Filename target.resource.name
System Description (opaque) msg msg metadata.description
System principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
System intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
Config intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Config about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
Config principal.process.command_line Configuration Path (path) msg ConfigurationPath principal.process.command_line
Config principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
Config intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
Config principal.asset.attribute.labels.key/value Device Group (dg_id) PanOSFWDeviceGroup target.asset.attribute.labels
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Threat/Wildfire target.file.full_path target.url target.hostname URL/Filename (misc) request Miscellaneous target.file.names target.url
Threat/Wildfire about.file.sha1/md5/sha256 File Digest (filedigest) fileHash FileDigest target.file.sha1/md5/sha256
Threat/Wildfire about.file.mime_type File Type (filetype) fileType FileType target.file.mime_type
Threat/Wildfire principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Threat/Wildfire principal.user.product_object_id Source VM UUID (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
Threat/Wildfire target.user.product_object_id Destination VM UUID (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value HTTP Headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
Threat/Wildfire principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
Threat/Wildfire principal.asset.software.version Source Device OS Version (src_osversion) PanSrcDeviceOSv principal.platform_version
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
Threat/Wildfire target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
Threat/Wildfire metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Reason (reason) PanReasonFilteringAction security_result.summary
Traffic about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value Packets Sent (pkts_sent) PanOSPacketsSent srcPackets network.sent_packets
Traffic about.labels.key/value additional.fields.key/value.string_value Packets Received (pkts_received) PanOSPacketsReceived dstPackets network.received_packets
Traffic principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
Traffic principal.asset.platform_software.platform(enum) principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
Traffic target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
Traffic about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
Traffic about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
Traffic about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
Traffic metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
User-ID about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
User-ID principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
User-ID principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID intermediary.resource.product_object_id
User-ID principal.user.userid principal.administrative_domain principal.user.email_addresses User by Source (userbysource) PanOSUserBySource target.user.userid target.user.email_addresses
User-ID metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
HIP Match intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
HIP Match about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
HIP Match about.labels.key/value additional.fields.key/value.string_value HIP (matchname) cat HIP target.resource.attribute.labels
HIP Match about.labels.key/value additional.fields.key/value.string_value HIP Type (matchtype) Device Event Class ID (Header) HIPType target.resource.attribute.labels
HIP Match principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
HIP Match intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
HIP Match principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
HIP Match principal.asset.product_object_id Host ID (hostid) PanOSHostID principal.asset.asset_id
HIP Match metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
IP-Tag intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
IP-Tag about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
IP-Tag principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOsVsysName vSrcName target.asset.attribute.labels
IP-Tag intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
IP-Tag principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
IP-Tag metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Decryption target.application Application (app) app network.application_protocol
Decryption about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 intermediary.asset.attribute.labels
Decryption principal.asset.asset_id Source VM UUID (src_uuid) PanOSSourceUUID principal.asset.product_object_id
Decryption target.asset.asset_id Destination VM UUID (dst_uuid) PanOSDestinationUUID target.asset.product_object_id
Decryption about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanOSContainerID intermediary.resource.product_object_id
Decryption about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanOSContainerNameSpace target.resource.attribute.labels additional.fields.key/value.string_value
Decryption about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanOSContainerName target.resource.name
Decryption metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanOSSourceDeviceCategory principal.asset.category
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanOSSourceDeviceModel principal.asset.hardware.model
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanOSSourceDeviceVendor principal.asset.hardware.manufacturer
Decryption principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanOSSourceDeviceOSFamily principal.platform
Decryption principal.asset.software.version Source Device OS Version (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanOSDestinationDeviceCategory target.asset.category
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanOSDestinationDeviceModel target.asset.hardware.model
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanOSDestinationDeviceVendor target.asset.hardware.manufacturer
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanOSDestinationDeviceOSFamily target.platform
Decryption target.asset.software.version Destination Device OS Version (dst_osversion) PanOSDestinationDeviceOSVersion target.platform_version
Decryption principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) intermediary.asset.attribute.labels
Decryption principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
Tunnel about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Tunnel principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Tunnel about.labels.key/value additional.fields.key/value.string_value Packets Sent (pkts_sent) PanOSPacketsSent srcPackets network.sent_packets
Tunnel about.labels.key/value additional.fields.key/value.string_value Packets Received (pkts_received) PanOSPacketsReceived dstPackets network.received_packets
Tunnel target.ip Remote User IP (remote_user_ip) PanOSRmtUserIP principal.ip
Tunnel target.labels.key/value additional.fields.key/value.string_value Remote User ID (remote_user_id) PanOSRmtUserID principal.user.userid
Tunnel metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Authentication about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Authentication target.user.user_display_name Normalize User (normalize_user) cs2 NormalizeUser target.user.user_display_name
Authentication about.labels.key/value additional.fields.key/value.string_value Object (object) fname ObjectName target.resource.name
Authentication about.labels.key/value additional.fields.key/value.string_value Authentication Policy (authpolicy) cs4 AuthPolicy additional.fields.key/value.string_value
Authentication principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Authentication principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
Authentication metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res _timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanOSSourceDeviceCategory principal.asset.category
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanOSSourceDeviceModel principal.asset.hardware.model
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanOSSourceDeviceVendor principal.asset.hardware.manufacturer
Authentication principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanOSSourceDeviceOSFamily principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value
Authentication principal.asset.software.version Source Device OS Version (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
URL about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
URL target.file.full_path target.url URL/Filename (misc) Miscellaneous target.file.names target.url
URL about.labels.key/value additional.fields.key/value.string_value Category (category) cs2 URLCategory security_result.category_details
URL about.file.sha1/md5/sha256 filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
URL about.file.mime_type filetype (filetype) target.file.mime_type
URL about.labels.key/value additional.fields.key/value.string_value xff (xff) PanOSXForwarderfor identSrc principal.ip
URL principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
URL about.url file_url (file_url) target.url
URL principal.asset.asset_id Source VM UUID (src_uuid) SrcUUID principal.asset.product_object_id
URL target.asset.asset_id Destination VM UUID (dst_uuid) DstUUID target.asset.product_object_id
URL about.labels.key/value additional.fields.key/value.string_value http_headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
URL about.labels.key/value additional.fields.key/value.string_value UUID for rule (rule_uuid) PanOSRuleUUID security_result.rule_id
URL about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
URL principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
URL principal.asset.software.version Source Device OS Version (src_osversion) PanSrcDeviceOSv principal.platform_version
URL principal.labels.key/value additional.fields.key/value.string_value Source Hostname (src_host) PanSrcHostname principal.hostname
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
URL target.asset.platform_software.platform target.labels.key/value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
URL target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
URL about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
URL about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
URL about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
URL about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
URL metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Res Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
URL about.labels.key/value additional.fields.key/value.string_value Reason (reason) PanReasonFilteringAction security_result.summary
Data about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Data target.file.full_path target.url URL/Filename (misc) Miscellaneous target.file.names target.url
Data about.labels.key/value additional.fields.key/value.string_value Category (category) cs2 URLCategory security_result.category_details
Data about.file.sha1/md5/sha256 filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
Data about.file.mime_type filetype (filetype) target.file.mime_type
Data about.labels.key/value additional.fields.key/value.string_value xff (xff) principal.ip
Data principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Data about.url file_url (file_url) target.url
Data principal.asset.asset_id Source VM UUID (src_uuid) SrcUUID principal.asset.product_object_id
Data target.asset.asset_id Destination VM UUID (dst_uuid) DstUUID target.asset.product_object_id
Data about.labels.key/value additional.fields.key/value.string_value http_headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
Data about.labels.key/value additional.fields.key/value.string_value UUID for rule (rule_uuid) PanOSRuleUUID security_result.rule_id
Data about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) network.application_protocol_version
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) principal.asset.category
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) principal.asset.hardware.model
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) principal.asset.hardware.manufacturer
Data principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) principal.platform
Data principal.asset.software.version Source Device OS Version (src_osversion) principal.platform_version
Data principal.labels.key/value additional.fields.key/value.string_value Source Hostname (src_host) principal.hostname
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) target.asset.category
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) target.asset.hardware.model
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) target.asset.hardware.manufacturer
Data target.asset.platform_software.platform target.labels.key/value Destination Device OS Family (dst_osfamily) target.platform
Data target.asset.software.version Destination Device OS Version (dst_osversion) target.platform_version
Data about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) intermediary.resource.product_object_id
Data about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) target.resource.attribute.labels
Data about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) target.resource.name
Data about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) principal.asset.asset_id
Data metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Res Timestamp (high_res_timestamp) additional.fields.key/value.string_value
Data about.labels.key/value additional.fields.key/value.string_value Reason (reason) security_result.summary
GlobalProtect about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) PanOSVirtualSystem intermediary.asset.attribute.labels
GlobalProtect principal.user.email_address principal.user.userid principal.administrative_domain Source User (srcuser) PanOSSourceUserName target.user.email_address target.user.userid
GlobalProtect principal.asset.platform_software.platform(enum) Client OS (client_os) PanOSEndpointOSType principal.platform
GlobalProtect principal.asset.platform_software.platform_version Client OS Version (client_os_ver) PanOSEndpointOSVersion principal.platform_version
GlobalProtect metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
GlobalProtect about.labels.key/value additional.fields.key/value.string_value Gateway Name (gateway) PanOSAttemptedGateways target.resource.name
GlobalProtect principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) intermediary.asset.attribute.labels
GlobalProtect target.hostname Device Name (device_name) intermediary.hostname
GlobalProtect principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
CORRELATION about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) VirtualSystem intermediary.asset.attribute.labels
CORRELATION principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) vSrcName intermediary.asset.attribute.labels
CORRELATION principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) VirtualSystemID intermediary.resource.product_object_id
GTP additional.fields.key/value.string_value Virtual System (vsys) intermediary.asset.attribute.labels
GTP target.ip Remote User IP (remote_user_ip) principal.ip
GTP additional.fields.key/value.string_value Remote User ID (remote_user_id) principal.user.userid
GTP metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) additional.fields.key/value.string_value

Palo Alto Networks Firewall Strata Logging Service

Ringkasan

Strata Logging Service dari Palo Alto Networks® menyediakan penyimpanan dan penggabungan log terpusat berbasis cloud untuk firewall lokal, virtual (cloud pribadi dan cloud publik), untuk Prisma Access, dan untuk layanan yang disediakan cloud seperti Cortex XDR.Strata Logging Service aman, tangguh, dan toleran terhadap kesalahan, serta memastikan data logging Anda selalu terbaru dan tersedia saat Anda membutuhkannya. Layanan ini menyediakan infrastruktur logging yang skalabel sehingga Anda tidak perlu merencanakan dan men-deploy Pengumpul Log untuk memenuhi kebutuhan retensi log Anda. Jika Anda sudah memiliki Pengumpul Log on-premise, Strata Logging Service baru dapat melengkapi penyiapan yang ada. Anda dapat meningkatkan infrastruktur pengumpulan log yang ada dengan Strata Logging Service berbasis cloud untuk memperluas kapasitas operasional seiring pertumbuhan bisnis Anda, atau untuk memenuhi kebutuhan kapasitas lokasi baru.Dengan layanan ini, Palo Alto Networks menangani pemeliharaan dan pemantauan infrastruktur logging yang berkelanjutan sehingga Anda dapat berfokus pada bisnis Anda.

  • Verifikasi format log dan versi PAN-OS yang didukung oleh parser Strata Logging Service. Tabel berikut mencantumkan format log dan versi PAN-OS yang sesuai yang didukung oleh parser Strata Logging Service:

    Format log Versi PAN-OS
    JSON 12.1
  • Verifikasi jenis log firewall Palo Alto Networks yang didukung oleh parser Google SecOps. Parser Google SecOps mendukung jenis log firewall Palo Alto Networks berikut:

    • Traffic
    • Ancaman
    • Pemeriksaan terowongan
    • Sistem
    • Pencocokan HIP
    • IP-Tag
    • User-ID
    • Dekripsi
    • Autentikasi
    • Pemfilteran URL
    • GlobalProtect

Deployment Layanan Logging Strata

Mulai Mengirim Log ke Strata Logging Service:

Untuk Mulai Mengirim Log ke Strata Logging Service, ikuti langkah-langkah berikut:

  1. Menginstal versi PAN-OS® yang didukung
  2. Aktifkan Strata Logging Service- Mengaktifkan Strata Logging Service mencakup penyediaan sertifikat yang diperlukan firewall untuk terhubung secara aman ke Strata Logging Service.
  3. Mengaktifkan firewall ke Strata Logging Service dengan atau tanpa Panorama

Untuk mengetahui langkah-langkah aktivasi yang mendetail, lihat Dokumentasi.

Meneruskan Log dari Strata Logging Service

Untuk memenuhi kebutuhan penyimpanan, pelaporan, dan pemantauan jangka panjang, atau kebutuhan hukum dan kepatuhan, Anda dapat mengonfigurasi Strata Logging Service untuk meneruskan log ke server HTTPS atau ke SIEM berikut:

  1. Exabeam
  2. Google Chronicle
  3. Microsoft Sentinel
  4. Splunk HTTP Event Collector (HEC)

Gunakan metode penerusan HTTPS untuk meneruskan log menggunakan Strata Logging Service. Untuk informasi mendetail, baca Dokumentasi ini.

Format log yang didukung

Parser firewall Palo Alto Networks Strata Logging Service mendukung log dalam format JSON.

Contoh log yang didukung

  • JSON

    {"source": "Palo Alto Networks FLS LF", "host": "dummy-loghost", "time": "1730265996460", "event": {"TimeReceived": "2024-10-30T05:25:50.000000Z", "DeviceSN": "no-serial", "LogType": "TRAFFIC", "Subtype": "end", "ConfigVersion": "10.2", "TimeGenerated": "2024-10-30T05:25:40.000000Z", "SourceAddress": "198.51.100.6", "DestinationAddress": "198.51.100.6", "NATSource": "", "NATDestination": "", "Rule": "egress-dns-ping-traceroute", "SourceUser": null, "DestinationUser": null, "Application": "dns-base", "VirtualLocation": "vsys1", "FromZone": "VA8280-RN", "ToZone": "inter-fw", "InboundInterface": "tunnel.101", "OutboundInterface": "tunnel.4005", "LogSetting": "Cortex Data Lake", "SessionID": 754194, "RepeatCount": 1, "SourcePort": 53578, "DestinationPort": 53, "NATSourcePort": 0, "NATDestinationPort": 0, "Protocol": "udp", "Action": "allow", "Bytes": 214, "BytesSent": 72, "BytesReceived": 142, "PacketsTotal": 2, "SessionStartTime": "2024-10-30T05:25:10.000000Z", "SessionDuration": 0, "URLCategory": "any", "SequenceNo": 7382192512716388639, "SourceLocation": "198.51.100.6-198.51.255.255", "DestinationLocation": "198.51.100.6-198.51.255.255", "PacketsSent": 1, "PacketsReceived": 1, "SessionEndReason": "aged-out", "DGHierarchyLevel1": 65537, "DGHierarchyLevel2": 65538, "DGHierarchyLevel3": 65541, "DGHierarchyLevel4": 0, "VirtualSystemName": "", "DeviceName": "VA8280-RN", "ActionSource": "from-policy", "SourceUUID": null, "DestinationUUID": null, "IMSI": 0, "IMEI": null, "ParentSessionID": 0, "ParentStarttime": "1970-01-01T00:00:00.000000Z", "Tunnel": "N/A", "EndpointAssociationID": 72057594037927936, "ChunksTotal": 0, "ChunksSent": 0, "ChunksReceived": 0, "RuleUUID": "95cfc3cc-cb00-4758-af1d-de9ab5f07f97", "HTTP2Connection": 0, "LinkChangeCount": 0, "SDWANPolicyName": null, "LinkSwitches": null, "SDWANCluster": null, "SDWANDeviceType": null, "SDWANClusterType": null, "SDWANSite": null, "DynamicUserGroupName": null, "X-Forwarded-ForIP": null, "SourceDeviceCategory": null, "SourceDeviceProfile": null, "SourceDeviceModel": null, "SourceDeviceVendor": null, "SourceDeviceOSFamily": null, "SourceDeviceOSVersion": null, "SourceDeviceHost": null, "SourceDeviceMac": null, "DestinationDeviceCategory": null, "DestinationDeviceProfile": null, "DestinationDeviceModel": null, "DestinationDeviceVendor": null, "DestinationDeviceOSFamily": null, "DestinationDeviceOSVersion": null, "DestinationDeviceHost": null, "DestinationDeviceMac": null, "ContainerID": null, "ContainerNameSpace": null, "ContainerName": null, "SourceEDL": null, "DestinationEDL": null, "GPHostID": null, "EndpointSerialNumber": null, "SourceDynamicAddressGroup": null, "DestinationDynamicAddressGroup": null, "HASessionOwner": null, "TimeGeneratedHighResolution": "2024-10-30T05:25:41.009000Z", "NSSAINetworkSliceType": null, "NSSAINetworkSliceDifferentiator": null}}"
    

Referensi pemetaan kolom: Kolom log ke kolom UDM

Bagian ini menjelaskan cara parser memetakan kolom log firewall Palo Alto Networks Strata Logging Service ke kolom peristiwa Google UDM untuk setiap jenis log.

Lihat bagian berikut untuk referensi pemetaan setiap jenis log:

Sistem

Tabel berikut mencantumkan kolom log jenis log Sistem dan kolom UDM yang sesuai.

Log field UDM mapping
AgentContentVersion additional.fields.key/value.string_value
AgentDataCollectionStatus target.resource.attribute.labels
AgentID target.resource.attribute.labels
AgentIsolationStatus target.resource.attribute.labels
AgentStatus target.resource.attribute.labels
AgentVersion target.asset.software.version
ConfigVersion additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DeviceGroup target.group.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EndpointCPUArchitecture target.asset.hardware.cpu_platform
EndpointDeviceDomain target.asset.administrative_domain
EndpointDeviceName target.asset.hostname
EndpointIPaddress target.asset.ip
VDIEndpoint target.asset.attribute.labels
EndpointOSType additional.fields.key/value.string_value
EndpointOSVersion target.platform_version
AgentTimeZoneOffset additional.fields.key/value.string_value
EndpointUserDomain additional.fields.key/value.string_value
EndpointUserName target.user.user_display_name
EndpointUserUUID target.user.userid
EventComponent additional.fields.key/value.string_value
EventDescription metadata.description
EventName additional.fields.key/value.string_value
EventTime metadata.event_timestamp
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogCategory security_result.category_details
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
LogSourceID target.resource.attribute.labels
LogSourceName observer.asset.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
LogTime metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Severity security_result.severity
Subtype metadata.product_event_type
Template target.resource.attribute.labels
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

Ancaman

Tabel berikut mencantumkan kolom log jenis log Ancaman dan kolom UDM yang sesuai.

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
ApplianceOrCloud additional.fields.key/value.string_value
CloudHostname additional.fields.key/value.string_value
CloudReportID security_result.detection_fields.key/value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DirectionOfAttack security_result.detection_fields.key/value
DomainEDL additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
FileName target.file.names
FileHash target.file.sha1
FileType additional.fields.key/value.string_value
FileURL target.url
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HostID principal.asset.asset_id
HTTP2Connection network.application_protocol_version
HTTPMethod network.http.method
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
LocalDeepLearningAnalyzed additional.fields.key/value.string_value
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
PartialHash additional.fields.key/value.string_value
PayloadProtocolID additional.fields.key/value.string_value
Packet additional.fields.key/value.string_value
PacketID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
RecipientEmail target.user.email_addresses
ReportID security_result.detection_fields.key/value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SenderEmail principal.user.email_addresses
SequenceNo metadata.product_log_id
SessionID network.session_id
Severity security_result.severity
SigFlags additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
EmailSubject network.email.subject
ApplicationTechnology additional.fields.key/value.string_value
ThreatCategory security_result.detection_fields.key/value.key/value
ThreatID security_result.threat_id
ThreatName security_result.threat_name
ThreatNameFirewall additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLDomain target.domain.name
URLCounter additional.fields.key/value.string_value
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
Verdict additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-ForIP principal.ip

Traffic

Tabel berikut mencantumkan kolom log jenis Log traffic dan kolom UDM yang sesuai.

Log field UDM mapping
Action security_result.action
ActionSource additional.fields.key/value.string_value
AIFwdError additional.fields.key/value.string_value
AITraffic additional.fields.key/value.string_value
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
BytesReceived network.received_bytes
BytesSent network.sent_bytes
Bytes additional.fields.key/value.string_value
ChunksReceived additional.fields.key/value.string_value
ChunksSent additional.fields.key/value.string_value
ChunksTotal additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
EndpointAssociationID additional.fields.key/value.string_value
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HASessionOwner additional.fields.key/value.string_value
GPHostID additional.fields.key/value.string_value
HTTP2Connection network.application_protocol_version
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsOffloaded additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
LinkChangeCount additional.fields.key/value.string_value
LinkSwitches additional.fields.key/value.string_value
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
SDWANPolicyName additional.fields.key/value.string_value
Protocol network.ip_protocol
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SDWANFECRatio additional.fields.key/value.string_value
SDWANCluster additional.fields.key/value.string_value
SDWANClusterType additional.fields.key/value.string_value
SDWANDeviceType additional.fields.key/value.string_value
SDWANSite additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionStartTime additional.fields.key/value.string_value
SessionTracker additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
SessionDuration network.session_duration
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLCategory target.url_metadata.categories
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-ForIP principal.ip

User-ID

Tabel berikut mencantumkan kolom log jenis log User-ID dan kolom UDM yang sesuai.

Log field UDM mapping
AuthFactorNo security_result.detection_fields.key/value
AuthenticatedUserDomain target.user.administrative_domain
AuthenticatedUserName target.user.userid
AuthenticatedUserUUID target.user.product_object_id
ConfigVersion additional.fields.key/value.string_value
CountofRepeats additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationPort target.port
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EventID additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsDuplicateUser additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MappingDataSource additional.fields.key/value.string_value
MappingDataSourceName additional.fields.key/value.string_value
MappingDataSourceType additional.fields.key/value.string_value
MappingTimeout additional.fields.key/value.string_value
MFAFactorType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SourceIP principal.ip
SourcePort principal.port
Subtype metadata.product_event_type
Tag additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
UGFlags additional.fields.key/value.string_value
User target.user.userid
UserGroupFound additional.fields.key/value.string_value
UserIdentifiedBySource additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Pencocokan HIP

Tabel berikut mencantumkan kolom log jenis log kecocokan HIP dan kolom UDM yang sesuai.

Log field UDM mapping
ConfigVersion additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EndpointDeviceName principal.asset.hostname
EndpointOSType additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
HipMatchName target.resource.attribute.labels
HipMatchType target.resource.attribute.labels
HostID principal.asset.asset_id
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType metadata.product_event_type
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Source additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceIP principal.ip
SourceIPv6 principal.ip
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
TimestampDeviceIdentification principal.asset.first_seen_time
UUID additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

Tag IP

Tabel berikut mencantumkan kolom log jenis log tag IP dan kolom UDM yang sesuai.

Log field UDM mapping
ConfigVersion additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EventID additional.fields.key/value.string_value
IPSubnetRange network.ip_subnet_range
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSetting target.resource.attribute.labels
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MappingDataSource additional.fields.key/value.string_value
MappingDataSourceSubType additional.fields.key/value.string_value
MappingDataSourceType additional.fields.key/value.string_value
MappingTimeout additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
RuleMatched security_result.rule_name
RuleMatchedUUID security_result.rule_id
SequenceNo metadata.product_log_id
SourceIP principal.ip
Subtype metadata.product_event_type
TagName additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

Dekripsi

Tabel berikut mencantumkan kolom log jenis log Dekripsi dan kolom UDM yang sesuai.

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
CertificateFlags additional.fields.key/value.string_value
CertificateSerial network.tls.server.certificate.serial
CertificateSize additional.fields.key/value.string_value
CertificateVersion network.tls.server.certificate.version
ChainStatus additional.fields.key/value.string_value
ApplicationCharacteristics additional.fields.key/value.string_value
ClientToFirewall additional.fields.key/value.string_value
CommonName additional.fields.key/value.string_value
CommonNameLength additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
Cpadding additional.fields.key/value.string_value
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
Domain target.hostname
EllipticCurve network.tls.curve
ErrorIndex additional.fields.key/value.string_value
ErrorMessage additional.fields.key/value.string_value
Fingerprint network.tls.server.certificate.md5/sha1/sha256
FirewallToClient additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsCertECDSA additional.fields.key/value.string_value
IsCertRSA additional.fields.key/value.string_value
IsCertCNTruncated additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
IsForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsIssuerCNTruncated additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
IsNAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
PacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsResumeSession additional.fields.key/value.string_value
IsRootCNTruncated additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSNITruncated additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
IssuerCommonName network.tls.server.certificate.issuer
IssuerNameLength additional.fields.key/value.string_value
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
TimeNotAfter additional.fields.key/value.string_value
TimeNotBefore additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
Padding additional.fields.key/value.string_value
Padding3 additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
PolicyName additional.fields.key/value.string_value
Protocol network.ip_protocol
ProxyType additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
RootCommonName additional.fields.key/value.string_value
RootCNLength additional.fields.key/value.string_value
RootStatus additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SessionID network.session_id
ServerNameIndication network.tls.client.server_name
SNILength additional.fields.key/value.string_value
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceOS additional.fields.key/value.string_value
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
ApplicationTechnology additional.fields.key/value.string_value
TimeReceivedManagementPlane additional.fields.key/value.string_value
TLSAuth additional.fields.key/value.string_value
TLSEncryptionAlgorithm additional.fields.key/value.string_value
TLSKeyExchange additional.fields.key/value.string_value
TLSVersion network.tls.version
ToZone additional.fields.key/value.string_value
Tpadding additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
Vpadding additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SourceDeviceCategory principal.asset.category
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Terowongan

Tabel berikut mencantumkan kolom log jenis log Tunnel dan kolom UDM yang sesuai.

Log field UDM mapping
AccessPointName additional.fields.key/value.string_value
Action security_result.action
ActionSource additional.fields.key/value.string_value
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
BytesReceived network.received_bytes
BytesSent network.sent_bytes
Bytes additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
LoggingServiceID additional.fields.key/value.string_value
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MobileAreaCode additional.fields.key/value.string_value
MobileBaseStationCode additional.fields.key/value.string_value
MobileCountryCode additional.fields.key/value.string_value
MobileIP additional.fields.key/value.string_value
MobileNetworkCode additional.fields.key/value.string_value
MobileSubscriberISDN additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceDifferentiator additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsDroppedMax additional.fields.key/value.string_value
PacketsDroppedStrict additional.fields.key/value.string_value
PacketsDroppedTunnel additional.fields.key/value.string_value
PacketsDroppedProtocol additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
ProtocolDataUnitsessionID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
RadioAccessTechnology additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionStartTime additional.fields.key/value.string_value
SessionTracker additional.fields.key/value.string_value
Severity security_result.severity
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
StandardPortsOfApp additional.fields.key/value.string_value
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
SessionDuration network.session_duration
Tunnel additional.fields.key/value.string_value
TunnelCauseCode additional.fields.key/value.string_value
TunnelEndpointID1 additional.fields.key/value.string_value
TunnelEndpointID2 additional.fields.key/value.string_value
TunnelEventCode additional.fields.key/value.string_value
TunnelEventType additional.fields.key/value.string_value
TunnelInspectionRule additional.fields.key/value.string_value
TunnelInterface additional.fields.key/value.string_value
TunnelMessageType additional.fields.key/value.string_value
TunnelRemoteIMSIID additional.fields.key/value.string_value
TunnelRemoteUserIP principal.ip
TunnelSessionsClosed additional.fields.key/value.string_value
TunnelSessionsCreated additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLCategory target.url_metadata.categories
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Autentikasi

Tabel berikut mencantumkan kolom log jenis log Autentikasi dan kolom UDM yang sesuai.

Log field UDM mapping
AuthenticationDescription security_result.description
AuthEvent metadata.description
AuthFactorNo security_result.detection_fields.key/value
AuthenticationPolicy security_result.detection_fields.key/value
AuthenticationProtocol additional.fields.key/value.string_value
AuthServerProfile additional.fields.key/value.string_value
AuthenticatedUserDomain target.administrative_domain
AuthenticatedUserName target.user.userid
AuthenticatedUserUUID target.user.product_object_id
ClientType additional.fields.key/value.string_value
ClientTypeName additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
IsPrismaNetworks additional.fields.key/value.string_value
Location target.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogType additional.fields.key/value.string_value
MFAAuthenticationID additional.fields.key/value.string_value
MFAVendor additional.fields.key/value.string_value
NormalizeUser target.user.user_display_name
Object target.resource.name
RuleMatched security_result.rule_name
RuleMatchedUUID security_result.rule_id
AuthCacheServiceRegion additional.fields.key/value.string_value
SessionID network.session_id
SourceDeviceCategory principal.asset.category
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceIP principal.ip
TimeGenerated metadata.event_timestamp
User target.user.userid
UserAgentString network.http.user_agent
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Subtype metadata.product_event_type
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

URL

Tabel berikut mencantumkan kolom log jenis log URL dan kolom UDM yang sesuai.

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
CloudHostname additional.fields.key/value.string_value
CloudReportID security_result.detection_fields.key/value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentType additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DirectionOfAttack security_result.detection_fields.key/value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
FileURL target.url
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HostID principal.asset.asset_id
HTTP2Connection network.application_protocol_version
HTTPHeaders additional.fields.key/value.string_value
HTTPMethod network.http.method
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
InlineMLVerdict additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
Packet additional.fields.key/value.string_value
PacketID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
Referer network.http.referral_url
HTTPRefererFQDN additional.fields.key/value.string_value
HTTPRefererPort additional.fields.key/value.string_value
HTTPRefererProtocol additional.fields.key/value.string_value
HTTPRefererURLPath additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionID network.session_id
Severity security_result.severity
SigFlags additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URL target.url_metadata.URL
URLCategory target.url_metadata.categories
URLCategoryList additional.fields.key/value.string_value
URLDomain target.domain.name
URLCounter additional.fields.key/value.string_value
UserAgent network.http.user_agent
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-For additional.fields.key/value.string_value
X-Forwarded-ForIP principal.ip

GlobalProtect

Tabel berikut mencantumkan kolom log jenis log GlobalProtect dan kolom UDM yang sesuai.

Log field UDM mapping
AttemptedGateways additional.fields.key/value.string_value
AuthMethod extensions.auth.auth_details
ConnectionMethod additional.fields.key/value.string_value
ConnectionErrorID additional.fields.key/value.string_value
ConnectionError additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
EndpointDeviceName principal.asset.hostname
GlobalProtectClientVersion additional.fields.key/value.string_value
EndpointOSType additional.fields.key/value.string_value
EndpointSN principal.asset.hardware.serial_number
EventIDValue additional.fields.key/value.string_value
Gateway target.resource.name
GatewayPriority additional.fields.key/value.string_value
GatewaySelectionType additional.fields.key/value.string_value
GlobalProtectGatewayLocation target.location.country_or_region
HostID principal.asset.asset_id
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LoginDuration network.session_duration
Description security_result.description
Portal target.hostname
PrivateIPv4 principal.ip
PrivateIPv6 principal.ip
ProjectName additional.fields.key/value.string_value
PublicIPv4 principal.nat_ip
PublicIPv6 principal.nat_ip
QuarantineReason security_result.summary
SequenceNo metadata.product_log_id
SourceRegion principal.location.country_or_region
SourceUserName principal.user.user_display_name
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SSLResponseTime additional.fields.key/value.string_value
Stage additional.fields.key/value.string_value
EventStatus additional.fields.key/value.string_value
LogSubtype metadata.product_event_type
TunnelType additional.fields.key/value.string_value
VirtualSystem intermediary.asset.attribute.labels
VirtualSystemName intermediary.asset.attribute.labels
EndpointOSVersion principal.platform_version
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType metadata.product_event_type
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualSystemID intermediary.resource.product_object_id

SCTP

Tabel berikut mencantumkan kolom log jenis log SCTP dan kolom UDM yang sesuai.

Log field UDM mapping
Action security_result.action
Application target.application
AssocationEndReason additional.fields.key/value.string_value
ChunksReceived additional.fields.key/value.string_value
ChunksSent additional.fields.key/value.string_value
ChunksTotal additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceClass target.asset.category
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationIP target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DiamAppID additional.fields.key/value.string_value
DiamAvpCode additional.fields.key/value.string_value
DiameterCommandCode additional.fields.key/value.string_value
DiameterRequestFlag additional.fields.key/value.string_value
DeviceName principal.asset.hostname
SCTPEventType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLFiltering additional.fields.key/value.string_value
IsWildfire additional.fields.key/value.string_value
LogAction additional.fields.key/value.string_value
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MapAppCode additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PayloadProtocolID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
Rule security_result.rule_name
RuleUUID security_result.rule_id
SccpCallingGt additional.fields.key/value.string_value
SccpCallingSSN additional.fields.key/value.string_value
SctpCauseCode additional.fields.key/value.string_value
SctpChunkType additional.fields.key/value.string_value
SctpFilter additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionTracker additional.fields.key/value.string_value
Severity security_result.severity
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceIP principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VerificationTag1 additional.fields.key/value.string_value
VerificationTag2 additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Audit

Tabel berikut mencantumkan kolom log jenis Log audit dan kolom UDM yang sesuai.

Log field UDM mapping
EventCategory network.http.method
EventDescription metadata.description
EventDestinationURL target.url
EventDestinationUserUserID target.user.userid
DestinationVendor additional.fields.key/value.string_value
EventDetails additional.fields.key/value.string_value
EventID metadata.product_log_id
EventName additional.fields.key/value.string_value
EventResult security_result.summary
EventSourceUserUserID principal.user.userid
EventTime metadata.event_timestamp
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
Subtype metadata.product_event_type
TSGID additional.fields.key/value.string_value
Vendor additional.fields.key/value.string_value
VendorSeverity security_result.severity_details

Referensi pemetaan kolom: Jenis log ke jenis peristiwa UDM

Tabel berikut mencantumkan jenis log firewall Palo Alto Networks Strata Logging Service dan jenis peristiwa UDM yang sesuai.

Jenis log Jenis peristiwa UDM
Traffic NETWORK_CONNECTION
Ancaman NETWORK_CONNECTION
Pemfilteran URL NETWORK_CONNECTION
Terowongan NETWORK_CONNECTION
Sistem

Jika nilai subjenis adalah "dhcp", maka NETWORK_DHCP akan disetel.

Jika nilai subjenis adalah "auth", USER_LOGIN akan disetel.

Jika nilai deskripsi adalah "logged in", maka USER_LOGIN akan ditetapkan.

Jika nilai deskripsi adalah "logged out", maka USER_LOGOUT akan disetel.

Untuk nilai subtype lainnya, GENERIC_EVENT ditetapkan.

Pencocokan HIP NETWORK_CONNECTION
Tag IP GENERIC_EVENT
User-ID USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED

Jika nilai subjenis adalah "login", USER_LOGIN akan disetel.

Jika nilai subjenis adalah "logout", USER_LOGOUT akan disetel.

Jika subtipe tidak berisi nilai apa pun, USER_UNCATEGORIZED akan ditetapkan.

Dekripsi NETWORK_CONNECTION
Authentication STATUS_UNCATEGORIZED
Globalprotect USER_LOGIN/USER_LOGOUT/USER_RESOURCE_ACCESS

Jika nilai subjenis adalah "auth", maka USER_LOGIN akan disetel.

Jika nilai subjenis adalah "logout", USER_LOGOUT akan disetel.

Jika subtype tidak berisi nilai apa pun, USER_RESOURCE_ACCESS akan ditetapkan.

SCTP NETWORK_CONNECTION
Audit NETWORK_CONNECTION

Langkah berikutnya

Perlu bantuan lain? Dapatkan jawaban dari anggota Komunitas dan profesional Google SecOps.