Raccogliere i log del firewall Palo Alto Networks

Supportato in:

Firewall Palo Alto Networks

Panoramica

Questo documento descrive come configurare syslog e un forwarder Google SecOps per raccogliere i log del firewall Palo Alto Networks. Questo documento spiega anche come i campi dei log del firewall Palo Alto Networks vengono mappati ai campi Unified Data Model (UDM) di Google SecOps. Per una panoramica sull'importazione dati in Google SecOps, consulta Importazione dei dati in Google SecOps. Un'etichetta di importazione identifica il parser che normalizza i dati dei log non elaborati in formato UDM strutturato. Le informazioni contenute in questo documento si applicano al parser con l'etichetta di importazione PAN_FIREWALL.

Prima di iniziare

  • Assicurati che il prodotto firewall Palo Alto Networks sia implementato e configurato correttamente. Per istruzioni di configurazione dettagliate, consulta la documentazione di PAN-OS.
  • Per comprendere i componenti di cui è stato eseguito il deployment per raccogliere i log del firewall Palo Alto Networks, esamina l'architettura di deployment. Ogni implementazione del cliente potrebbe differire da questa rappresentazione e potrebbe essere più complessa. Il seguente diagramma mostra come configurare syslog su un firewall Palo Alto Networks e installare un forwarder Google SecOps su un server Linux per inoltrare i dati di log a Google SecOps. Il parser supporta i log scritti nei seguenti formati di dati: valori separati da virgole (CSV), Common Event Format (CEF) e Log Event Extended Format (LEEF).

    Architettura di deployment

  • Verifica i formati dei log e le versioni di PAN-OS supportati dal parser Google SecOps. La tabella seguente elenca i formati dei log e le versioni di PAN-OS corrispondenti supportate dal parser Google SecOps:

    Formato log Versione PAN-OS
    CSV 10.1.3
    CEF 10.0.0
    LEEF 9.1.0
  • Verifica i tipi di log del firewall Palo Alto Networks supportati dal parser Google SecOps. Il parser di Google SecOps supporta i seguenti tipi di log del firewall Palo Alto Networks:

    • Traffico
    • Minaccia
    • Invii di WildFire
    • Ispezione tunnel
    • Configurazione
    • Sistema
    • Corrispondenza HIP
    • IP-Tag
    • User-ID
    • Decriptazione
    • Autenticazione
    • Filtro degli URL
    • Filtro dei dati
    • GlobalProtect
    • Correlazione
    • GTP
    • SCTP
    • Controlla

    Per ulteriori informazioni sui tipi di log del firewall Palo Alto Networks, consulta Tipi di log PAN-OS.

  • Assicurati che tutti i sistemi nell'architettura di deployment siano configurati nel fuso orario UTC.

  • Prima di utilizzare il parser del firewall Palo Alto Networks, esamina le modifiche apportate ai mapping dei campi tra il parser precedente e quello attuale del firewall Palo Alto Networks. Nell'ambito della migrazione, assicurati che le regole, le ricerche, i dashboard o altri processi che dipendono dai campi originali utilizzino i campi aggiornati.

    Ad esempio, nella versione precedente del parser, il campo log category è mappato al campo UDM security_result.description. Nell'attuale parser del firewall Palo Alto Networks, il campo log category è mappato al campo UDM security_result.category_details. Se esegui la migrazione all'attuale parser firewall Palo Alto Networks e utilizzi il campo category nelle regole, devi modificare le regole in modo che utilizzino il campo security_result.category_details UDM del parser attuale.

Configura syslog e il forwarder Google Security Operations

Per configurare syslog e il forwarder Google SecOps, completa i seguenti passaggi:

  1. Per monitorare i log CSV, configura il profilo del server syslog. Per saperne di più, consulta Configurare il profilo del server syslog. Quando configuri il profilo del server syslog, specifica "Predefinito" come formato log personalizzato.
  2. Per monitorare i log CEF, configura il firewall Palo Alto Networks per inoltrarli. Per ulteriori informazioni, scarica la guida all'integrazione CEF di PAN-OS in formato PDF e consulta la sezione "Configurazione di Palo Alto Networks NGFW per l'output di eventi CEF".
  3. Per monitorare i log LEEF, configura il profilo del server syslog. Per saperne di più, consulta Invio personalizzato dei log in formato LEEF.
  4. Configura il forwarder Google SecOps per inviare i log a Google Security Operations. Per ulteriori informazioni, vedi Installazione e configurazione del forwarder su Linux. Di seguito è riportato un esempio di configurazione dell'agente di inoltro Google SecOps:

      - syslog:
          common:
            enabled: true
            data_type: PAN_FIREWALL
            batch_n_seconds: 10
            batch_n_bytes: 1048576
          tcp_address: 0.0.0.0:10518
          connection_timeout_sec: 60
    

Configura l'inoltro di syslog sul firewall PAN

Crea un profilo server syslog

  1. Accedi alla console di gestione del firewall Palo Alto Networks.
  2. Vai a Dispositivo > Profili server > Syslog.
  3. Fai clic su Aggiungi per creare un nuovo profilo server.
  4. Fornisci i seguenti dettagli di configurazione:
    • Nome: inserisci un nome descrittivo (ad esempio, Google SecOps BindPlane).
    • Posizione: seleziona il sistema virtuale (vsys) o Condiviso in cui sarà disponibile questo profilo.
  5. Fai clic su Server > Aggiungi per configurare il server syslog.
  6. Fornisci i seguenti dettagli di configurazione del server:
    • Nome: inserisci un nome descrittivo per il server (ad esempio, BindPlane Agent).
    • Server Syslog: inserisci l'indirizzo IP dell'agente BindPlane.
    • Trasporto: seleziona UDP o TCP, a seconda della configurazione di BindPlane Agent (UDP è l'impostazione predefinita).
    • Porta: inserisci il numero di porta dell'agente BindPlane (ad esempio, 514).
    • Formato: seleziona BSD (impostazione predefinita) o IETF, a seconda dei tuoi requisiti.
    • Struttura: seleziona LOG_USER (impostazione predefinita) o un'altra struttura, se necessario.
  7. Fai clic su OK per salvare il profilo del server syslog.

(Facoltativo) Configura il formato log personalizzato per CEF o LEEF

Se hai bisogno di log CEF (Common Event Format) o LEEF (Log Event Extended Format) anziché CSV:

  1. Nel profilo del server Syslog, seleziona la scheda Formato log personalizzato.
  2. Configura il formato log personalizzato per ogni tipo di log (Config, System, Threat, Traffic, URL, Data, WildFire, Tunnel, Authentication, User-ID, HIP Match).
  3. Per la configurazione del formato CEF, consulta la Guida alla configurazione CEF di Palo Alto Networks.
  4. Fai clic su Ok per salvare la configurazione.

Creare un profilo di inoltro dei log

  1. Vai a Oggetti > Inoltro log.
  2. Fai clic su Aggiungi per creare un nuovo profilo di inoltro dei log.
  3. Fornisci i seguenti dettagli di configurazione:
    • Nome: inserisci un nome del profilo (ad esempio Google SecOps Forwarding). Se vuoi che il firewall assegni automaticamente questo profilo a nuove regole e zone di sicurezza, chiamalo default.
  4. Per ogni tipo di log che vuoi inoltrare (traffico, minaccia, invio WildFire, filtro URL, filtro dati, tunnel, autenticazione), configura quanto segue:
    • Fai clic su Aggiungi nella sezione del tipo di log corrispondente.
    • Syslog: seleziona il profilo del server Syslog che hai creato (ad esempio, Google SecOps BindPlane).
    • Gravità log: seleziona i livelli di gravità da inoltrare (ad esempio Tutti).
  5. Fai clic su Ok per salvare il profilo di inoltro dei log.

Applica il profilo di inoltro dei log ai criteri di sicurezza

  1. Vai a Norme > Sicurezza.
  2. Seleziona le regole di sicurezza per le quali vuoi attivare l'inoltro dei log.
  3. Fai clic sulla regola per modificarla.
  4. Vai alla scheda Azioni.
  5. Nel menu Log Forwarding, seleziona il profilo di inoltro dei log che hai creato (ad esempio, Google SecOps Forwarding).
  6. Fai clic su Ok per salvare la configurazione della norma di sicurezza.

Configura le impostazioni dei log per i log di sistema

  1. Vai a Dispositivo > Impostazioni log.
  2. Per ogni tipo di log (Sistema, Configurazione, User-ID, Corrispondenza HIP, Global Protect, IP-Tag, SCTP) e livello di gravità, seleziona il profilo del server syslog che hai creato.
  3. Fai clic su Ok per salvare le impostazioni dei log.

Esegui il commit delle modifiche

  1. Fai clic su Commit nella parte superiore dell'interfaccia web del firewall.
  2. Attendi il completamento del commit.
  3. Verifica che i log vengano inviati all'agente Bindplane controllando la console Google SecOps per i log del firewall Palo Alto Networks in entrata.

Inoltrare i log a Google SecOps utilizzando l'agente Bindplane

  1. Installa e configura una macchina virtuale Linux.
  2. Installa e configura l'agente Bindplane su Linux per inoltrare i log a Google SecOps. Per saperne di più su come installare e configurare l'agente Bindplane, consulta le istruzioni di installazione e configurazione dell'agente Bindplane.

Se riscontri problemi durante la creazione dei feed, contatta l'assistenza Google SecOps.

Formati di log supportati

Il parser firewall Palo Alto Networks supporta i log in formato LEEF,CEF e CSV.

Log di esempio supportati

  • LEEF

    <14>Jan 22 02:20:19 device_host LEEF:1.0|Palo Alto Networks|PAN-OS Syslog Integration|10.2.12-h4|Microsoft MSOFFICE(52033)|ReceiveTime=2025/01/22 02:20:18|SerialNumber=01250100xxxx|cat=THREAT|Subtype=wildfire|devTime=Jan 22 2025 08:20:18 GMT|src=198.50.100.1|dst=198.50.100.2|srcPostNAT=198.50.100.3|dstPostNAT=198.50.100.4|RuleName=AZURE-US-NEW-CNF_Inbound_To_Azure-ALLOW|usrName=|SourceUser=|DestinationUser=|Application=smtp-base|VirtualSystem=vsys1|SourceZone=McD-Global-Zone|DestinationZone=Azure-Zone|IngressInterface=ae1.111|EgressInterface=ae2.409|LogForwardingProfile=Default-Traffic-Logging|SessionID=35331795|RepeatCount=1|srcPort=21578|dstPort=25|srcPostNATPort=0|dstPostNATPort=0|Flags=0x2000|proto=tcp|action=allow|Miscellaneous=\"......3...................xls\"|ThreatID=Microsoft MSOFFICE(52033)|URLCategory=malicious|sev=4|Severity=high|Direction=client-to-server|sequence=7462614601465681755|ActionFlags=0x8000000000000000|SourceLocation=198.50.100.1-198.50.100.255|DestinationLocation=United States|ContentType=|PCAP_ID=0|FileDigest=0ea04c99bf188c2e4207f60f92ca7c6f5088c7943ee63f45c50032bbd2bf7ea9|Cloud=demo.com|URLIndex=1|RequestMethod=|FileType=ms-office|Sender=sender@ab.myownpersonaldomain.com|Subject=\"............:.................................................................................-.........(Name)-2025-01-22...............:Y107202501220005, ............:........................, ...............:.........\"|Recipient=abc@demo.myownpersonaldomain.com|ReportID=117022282776|DeviceGroupHierarchyL1=143|DeviceGroupHierarchyL2=144|DeviceGroupHierarchyL3=39|DeviceGroupHierarchyL4=0|vSrcName=|DeviceName=device_host|SrcUUID=|DstUUID=|TunnelID=0|MonitorTag=|ParentSessionID=0|ParentStartTime=|TunnelType=N/A|ThreatCategory=N/A|ContentVer=WildFire-0
    
  • CEF

    14>1 2024-04-04T16:21:56+02:00 FW-PERIMETRAL-AVG-01 - - - - CEF:0|Palo Alto Networks|PAN-OS|10.1.10-h2|end|TRAFFIC|1|src=198.51.100.1 dst=198.51.100.2 srcTranslatedAddress=198.51.100.3 dstTranslatedAddress=198.51.100.4 rule=FW_USER_NATS2_APP suser= duser= app=bittorrent vs=vsys1 sz=INSIDE dz=EXTERNAL InboundInterface=ae2.2266 OutboundInterface=ae1 lp=log_forwarding sid=2935823 cnt=1 spt=6881 dpt=51413 srcTranslatedPort=0 dstTranslatedPort=0 flags=0x7a proto=udp act=allow tbytes=475 in=150 out=325 pkt=2 pktReceived=1 pktSent=1 start=Apr 04 2024 14:21:56 GMT stime=1206 urlcat=any externalId=externalId reason=aged-out DGl1=11 DGl2=161 DGl3=0 DGl4=0 VsysName=STONESOFT dvchost=FW-PERIMETRAL-AVG-01 cat=from-policy ActionFlags=0x8000000000000000 srcUUID= dstUUID= TunnelID=0 MonitorTag= ParentSessionID=0 ParentStartTime= TunnelType=N/A SCTPAssocID=0 SCTPChunks=0 SCTPChunkSent=0 SCTPChunksRcv=0 RuleUUID=746c3eb6-3d51-4679-8438-bd0e00e170a8 HTTP2Con=0 LinkChange=0 PolicyID= LinkDetail= SDWANCluster= SDWANDevice= SDWANClustype= SDWANSite= DynamicUsrgrp= XFFIP= srcDevCat= srcDevProf= srcDevModel= srcDevVendor= srcDevOS= srcDevOSv= srcHostname= srcMac= dstDevCat= dstDevProf= dstDevModel= dstDevVendor= dstDevOS= dstDevOSv= dstHostname= dstMac= ContainerName= PODNamespace= PODName= srcEDL= dstEDL= GPHostID= EPSerial= srcDAG= dstDAG= HASessionOwner= TimeHighRes=2024-04-04T16:21:56.250+02:00 ASServiceType= ASServiceDiff="
    
  • CSV

    1,2021/10/24 15:30:07,,CONFIG,0,2561,2021/10/24 15:30:07,198.51.100.0,,set,admin,Web,Succeeded, network virtual-router  VR1,,VR1  { ecmp { algorithm { ip-modulo ; } } protocol { bgp { routing-options { graceful-restart { enable yes; } } enable no; } rip { enable no; } ospf { enable no; } ospfv3 { enable no; } } routing-table { ip { static-route { vr1-log  { path-monitor { enable no; failure-condition any; hold-time 2; } nexthop { ip-address 198.51.100.0; } bfd { profile None; } interface ethernet1/1; metric 10; destination 0.0.0.0/0; route-table { unicast ; } } } } } interface [ ethernet1/1 ethernet1/2 ]; } ,7022390503849066572,0x0,0,0,0,0,,PA-VM,0,
    

Riferimento per la mappatura dei campi: campi dei log e campi UDM

Questa sezione spiega come il parser mappa i campi dei log del firewall Palo Alto Networks ai campi degli eventi UDM di Google SecOps per ogni tipo di log. La chiave dell'etichetta Google SecOps si riferisce al nome della chiave mappata al campo UDM Labels.key.

Ad esempio, nel caso del campo "Virtual System", il nome del campo è "cs3" nel formato CEF e "VirtualSystem" nel formato LEEF. Il campo UDM "about.labels.key" contiene il valore "vsys" e il campo UDM "about.labels.value" contiene il valore di questo campo. Alcuni nomi di campi CEF o LEEF non hanno un nome corrispondente ai nomi dei campi CSV. In questi casi, se aggiungi il tuo nome variabile nel formato log personalizzato nel profilo syslog, il parser non lo mappa al campo UDM.

Per il riferimento alla mappatura di ogni tipo di log, consulta le seguenti sezioni:

Sistema

La tabella seguente elenca i campi di log del tipo di log di sistema e i campi UDM corrispondenti.

Campo CSV Campo CEF Campo LEEF Chiave dell'etichetta Google Security Operations Campo UDM
Ora di ricezione (receive_time o cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" è assente)

Numero di serie (seriale) deviceExternalId SerialNumber target.asset.hardware.serial_number
Tipo (type) type (intestazione) gatto metadata.product_event_type è impostato su "%{type} - %{subtype}".
Tipo di minaccia/contenuti (sottotipo) sottotipo (intestazione) Sottotipo metadata.product_event_type è impostato su "%{type} - %{subtype}".
Ora di generazione (time_generated o cef-formatted-time_generated) metadata.event_timestamp
Sistema virtuale (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
ID evento (eventid) gatto eventid additional.fields.key e additional.fields.value.string_value
Oggetto (oggetto) fname Nome del file oggetto target.resource.name
Modulo (modulo) flexString2 Modulo modulo additional.fields.key e additional.fields.value.string_value
Gravità (severity) $number-of-severity(header) Gravità security_result.severity e security_result.severity_details
Descrizione (opaca) msg msg metadata.description
principal_user_userid (questo campo viene estratto dal campo msg) principal.user.userid
principal_ip3 (questo campo viene estratto dal campo msg) principal.ip
Motivo (questo campo viene estratto dal campo msg) security_result.description
server_address (questo campo viene estratto dal campo msg). target.ip
server_profile (questo campo viene estratto dal campo msg) additional.fields.key e additional.fields.value.string_value
Numero di sequenza (seqno) externalId sequenza metadata.product_log_id
Flag azioni (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Gerarchia dei gruppi di dispositivi (dg_hier_level_1 a dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome sistema virtuale (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
Nome dispositivo (device_name) dvchost DeviceName target.hostname
Timestamp ad alta risoluzione (high_res_timestamp) anOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value

Configurazione

La tabella seguente elenca i campi di log del tipo di log di configurazione e i relativi campi UDM.

Campo CSV Campo CEF Campo LEEF Chiave dell'etichetta Google Security Operations Campo UDM
Ora di ricezione (receive_time o cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" è assente)

Numero di serie (seriale) deviceExternalId SerialNumber target.asset.hardware.serial_number
Tipo (type) type (intestazione) gatto metadata.product_event_type
Tipo di minaccia/contenuti (sottotipo) sottotipo (intestazione) metadata.product_event_type
Ora di generazione (time_generated o cef-formatted-time_generated) metadata.event_timestamp
Host (host) spettro src principal.ip/hostname
Sistema virtuale (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
Comando (cmd) atto msg cmd principal.process.command_line
Amministratore (admin) duser usrName principal.user.userid
Cliente (client) destinationServiceName client principal.application
Risultato (risultato) ID firma (intestazione)(motivo) Risultato security_result.summary
Percorso di configurazione (percorso) msg ConfigurationPath principal.process.command_line
Before Change Detail (before_change_detail) cs1 BeforeChangeDetail before_change_detail target.resource.attribute.labels.key/value
After Change Detail (after_change_detail) cs2 AfterChangeDetail after_change_detail target.resource.attribute.labels.key/value
Numero di sequenza (seqno) externalId sequenza metadata.product_log_id
Flag azioni (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Gerarchia dei gruppi di dispositivi (dg_hier_level_1 a dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome sistema virtuale (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
Nome dispositivo (device_name) dvchost DeviceName target.hostname
Gruppo di dispositivi (dg_id) PanOSFWDeviceGroup target.asset.attribute.labels.key/value dg_id principal.asset.attribute.labels.key/value
Commento di controllo (commento) PanOSPolicyAuditComment commento additional.fields.key e additional.fields.value.string_value
Timestamp ad alta risoluzione (high_res_timestamp) additional.fields.key e additional.fields.value.string_value
Gravità (severity) number-of-severity(header) security_result.severity e security_result.severity_details

Threat/WildFire

La tabella seguente elenca i campi di log del tipo di log Threat/WildFire e i relativi campi UDM.

Campo CSV Campo CEF Campo LEEF Chiave dell'etichetta Google Security Operations Campo UDM
Ora di ricezione (receive_time o cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" è assente)

Numero di serie deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Tipo (type) type (intestazione) gatto metadata.product_event_type
Tipo di minaccia/contenuti (sottotipo) cat/subtype (intestazione) Sottotipo metadata.product_event_type
Genera ora (time_generated o cef-formatted-time_generated) metadata.event_timestamp
Indirizzo di origine (src) src src principal.ip
Indirizzo di destinazione (dst) dst dst target.ip
IP di origine NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP di destinazione NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Nome regola (regola) cs1 RuleName security_result.rule_name
Utente di origine (srcuser) suser SourceUser / usrName principal.user.userid
Utente di destinazione (dstuser) duser DestinationUser target.user.userid
Applicazione (app) app Applicazione target.application
Sistema virtuale (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona di origine (da) cs4 SourceZone da

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Zona di destinazione (a) cs5 DestinationZone a

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Interfaccia in entrata (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Interfaccia in uscita (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Azione di log (logset) cs6 LogForwardingProfile logset additional.fields.key e additional.fields.value.string_value
ID sessione (sessionid) cn1 SessionID network.session_id
Ripeti conteggio (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Porta di origine (sport) spt srcPort principal.port
Porta di destinazione (dport) dpt dstPort target.port
Porta di origine NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Porta di destinazione NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Flag (flags) flexString1 Bandiere flags additional.fields.key e additional.fields.value.string_value
Protocollo IP (proto) proto proto network.ip_protocol
Azione (azione) atto azione security_result.action_details

security_result.action

URL/Nome file (varie) richiesta Vari

target.file.names (se il sottotipo è "file", "virus", "wildfire-virus" o "wildfire", il campo "misc" viene mappato su target.file.names)

target.url (se il sottotipo è "url", il campo "misc" viene mappato su target.url e target.hostname)

Nome minaccia/contenuto (threatid) gatto ThreatID security_result.threat_name
Categoria (categoria) cs2 URLCategory security_result.category_details
Gravità (severity) number-of-severity(header) Gravità security_result.severity e security_result.severity_details
Direzione (direction) flexString2 Direzione network.direction
Numero di sequenza (seqno) externalId sequenza metadata.product_log_id
Flag azioni (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Paese di origine (srcloc) SourceLocation principal.location.country_or_region
Paese di destinazione (dstloc) DestinationLocation target.location.country_or_region
Tipo di contenuti (contenttype) ContentType contenttype additional.fields.key e additional.fields.value.string_value
ID PCAP (pcap_id) fileId PCAP_ID pcap_id additional.fields.key e additional.fields.value.string_value
File Digest (filedigest) fileHash FileDigest target.file.sha1/md5/sha256
Cloud (cloud) filePath Cloud cloud additional.fields.key e additional.fields.value.string_value
Indice URL (url_idx) URLIndex url_idx additional.fields.key e additional.fields.value.string_value
User agent (user_agent) network.http.user_agent
Tipo di file (filetype) fileType FileType target.file.mime_type
X-Forwarded-For (xff) principal.ip
Referer (referer) network.http.referral_url
Mittente (mittente) suid Mittente network.email.from
Oggetto (oggetto) msg Oggetto network.email.subject
Destinatario (destinatario) duid Destinatario network.email.to
ID report (reportid) oldFileId ReportID reportid additional.fields.key e additional.fields.value.string_value
Gerarchia dei gruppi di dispositivi (dg_hier_level_1 a dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome sistema virtuale (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nome dispositivo (device_name) dvchost DeviceName intermediary.hostname
UUID VM di origine (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
UUID VM di destinazione (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
Metodo HTTP (http_method) RequestMethod network.http.method
ID tunnel/IMSI (tunnel_id/imsi) PanOSTunnelID TunnelID tunnel_id/imsi additional.fields.key e additional.fields.value.string_value
Monitor Tag/IMEI (monitortag/imei) PanOSMonitorTag MonitorTag monitortag/imei additional.fields.key e additional.fields.value.string_value
ID sessione principale (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Ora di inizio della sessione principale (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key e additional.fields.value.string_value
Tipo di tunnel (tunnel) PanOSTunnelType TunnelType tunnel additional.fields.key e additional.fields.value.string_value
Categoria minaccia (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
Versione contenuto (contentver) PanOSContentVer ContentVer contentver additional.fields.key e additional.fields.value.string_value
ID associazione SCTP (assoc_id) PanOSAssocID assoc_id additional.fields.key e additional.fields.value.string_value
ID protocollo payload (ppid) PanOSPPID ppid additional.fields.key e additional.fields.value.string_value
Intestazioni HTTP (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
Elenco categorie di URL (url_category_list) PanOSURLCatList url_category_list additional.fields.key e additional.fields.value.string_value
UUID regola (rule_uuid) PanOSRuleUUID security_result.rule_id
Connessione HTTP/2 (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
Nome gruppo di utenti dinamico (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Indirizzo XFF (xff_ip) PanXFFIP principal.ip
Categoria dispositivo di origine (src_category) PanSrcDeviceCat src_category principal.asset.category
Profilo del dispositivo di origine (src_profile) PanSrcDeviceProf src_profile

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Modello del dispositivo di origine (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
Fornitore del dispositivo di origine (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
Famiglia di sistemi operativi del dispositivo di origine (src_osfamily) PanSrcDeviceOS src_osfamily principal.platform
Versione del sistema operativo del dispositivo di origine (src_osversion) PanSrcDeviceOSv principal.platform_version
Nome host di origine (src_host) PanSrcHostname principal.hostname
Indirizzo MAC di origine (src_mac) PanSrcMac principal.mac
Categoria dispositivo di destinazione (dst_category) PanDstDeviceCat dst_category target.asset.category
Profilo del dispositivo di destinazione (dst_profile) PanDstDeviceProf dst_profile

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Modello del dispositivo di destinazione (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
Fornitore del dispositivo di destinazione (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
Famiglia di sistemi operativi del dispositivo di destinazione (dst_osfamily) PanDstDeviceOS dst_osfamily target.platform
Versione del sistema operativo del dispositivo di destinazione (dst_osversion) PanDstDeviceOSv target.platform_version
Nome host di destinazione (dst_host) PanDstHostname target.hostname
Indirizzo MAC di destinazione (dst_mac) PanDstMac target.mac
ID contenitore (container_id) PanContainerName container_id intermediary.resource.product_object_id
Spazio dei nomi POD (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
Nome POD (pod_name) PanPODName pod_name target.resource.name
Elenco dinamico esterno di origine (src_edl) PanSrcEDL src_edl additional.fields.key e additional.fields.value.string_value
Elenco dinamico esterno di destinazione (dst_edl) PanDstEDL dst_edl additional.fields.key e additional.fields.value.string_value
ID host (hostid) PanGPHostID hostid principal.asset.asset_id
Numero di serie del dispositivo utente (serialnumber) PanEPSerial principal.asset.hardware.serial_number
Elenco di domini (domain_edl) PanDomainEDL domain_edl additional.fields.key e additional.fields.value.string_value
Gruppo di indirizzi dinamici di origine (src_dag) PanSrcDAG principal.group.group_display_name
Gruppo di indirizzi dinamici di destinazione (dst_dag) PanDstDAG target.group.group_display_name
Hash parziale (partial_hash) PanPartialHash partial_hash additional.fields.key e additional.fields.value.string_value
Timestamp ad alta risoluzione (high_res timestamp) PanTimeHighRes timestamp ad alta risoluzione additional.fields.key e additional.fields.value.string_value
Motivo (motivo) PanReasonFilteringAction motivo security_result.summary
Motivazione (giustificazione) PanJustification giustificazione additional.fields.key e additional.fields.value.string_value
Un tipo di servizio di sezione (nssai_sst) PanASServiceType nssai_sst additional.fields.key e additional.fields.value.string_value
Sottocategoria dell'applicazione (subcategory_of_app) subcategory_of_app additional.fields.key e additional.fields.value.string_value
Categoria applicazione (category_of_app) category_of_app additional.fields.key e additional.fields.value.string_value
Tecnologia dell'applicazione (technology_of_app) technology_of_app additional.fields.key e additional.fields.value.string_value
Rischio applicazione (risk_of_app) risk_of_app additional.fields.key e additional.fields.value.string_value
Caratteristica dell'applicazione (characteristic_of_app) characteristic_of_app additional.fields.key e additional.fields.value.string_value
Container dell'applicazione (container_of_app) container_of_app additional.fields.key e additional.fields.value.string_value
SaaS dell'applicazione (is_saas_of_app) is_saas_of_app additional.fields.key e additional.fields.value.string_value
Applicazione sottoposta a tunneling (tunneled_app) additional.fields.key e additional.fields.value.string_value
Tipo di flusso (flow_type) additional.fields.key e additional.fields.value.string_value
Nome cluster (cluster_name) intermediary.resource.name
Stato sanzionato dell'applicazione (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key e additional.fields.value.string_value

Traffico

La tabella seguente elenca i campi di log del tipo di log del traffico e i campi UDM corrispondenti.

Campo CSV Campo CEF Campo LEEF Chiave dell'etichetta Google Security Operations Campo UDM
Ora di ricezione (receive_time o cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" è assente)

Numero di serie (seriale) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Tipo (type) type (intestazione) cat/Type metadata.product_event_type
Tipo di minaccia/contenuti (sottotipo) sottotipo (intestazione) Sottotipo metadata.product_event_type
Ora di generazione (time_generated o cef-formatted-time_generated) start metadata.event_timestamp
Indirizzo di origine (src) src src principal.ip
Indirizzo di destinazione (dst) dst dst target.ip
IP di origine NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP di destinazione NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Nome regola (regola) cs1 RuleName security_result.rule_name
Utente di origine (srcuser) suser SourceUser principal.user.userid
Utente di destinazione (dstuser) duser DestinationUser target.user.userid
Applicazione (app) app Applicazione target.application
Sistema virtuale (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona di origine (da) cs4 SourceZone da

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Zona di destinazione (a) cs5 DestinationZone a

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Interfaccia in entrata (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Interfaccia in uscita (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Azione di log (logset) cs6 LogForwardingProfile logset additional.fields.key e additional.fields.value.string_value
ID sessione (sessionid) cn1 SessionID network.session_id
Ripeti conteggio (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Porta di origine (sport) spt srcPort principal.port
Porta di destinazione (dport) dpt dstPort target.port
Porta di origine NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Porta di destinazione NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Flag (flags) flexString1 Bandiere flags additional.fields.key e additional.fields.value.string_value
Protocollo IP (proto) proto proto network.ip_protocol
Azione (azione) atto azione security_result.action_details

security_result.action

Byte (byte) flexNumber1 totalBytes byte additional.fields.key e additional.fields.value.string_value
Byte inviati (bytes_sent) in srcBytes network.sent_bytes
Byte ricevuti (bytes_received) troppo complessi per essere capiti? dstBytes network.received_bytes
Pacchetti (pacchetti) cn2 totalPackets pacchetti additional.fields.key e additional.fields.value.string_value
Ora di inizio (inizio) StartTime start additional.fields.key e additional.fields.value.string_value
Tempo trascorso (trascorso) cn3 ElapsedTime trascorso network.session_duration.seconds
Categoria (categoria) cs2 URLCategory security_result.category / security_result.category_details
Numero di sequenza (seqno) externalId sequenza metadata.product_log_id
Flag azioni (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Paese di origine (srcloc) SourceLocation principal.location.country_or_region
Paese di destinazione (dstloc) DestinationLocation target.location.country_or_region
Pacchetti inviati (pkts_sent) PanOSPacketsSent srcPackets pkts_sent network.sent_packets
Pacchetti ricevuti (pkts_received) PanOSPacketsReceived dstPackets pkts_received network.received_packets
Motivo di fine della sessione (session_end_reason) motivo SessionEndReason security_result.summary
Gerarchia del gruppo di dispositivi 1 (dg_hier_level_1 a dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Gerarchia dei gruppi di dispositivi 2 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi 3 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome sistema virtuale (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nome dispositivo (device_name) dvchost DeviceName intermediary.hostname
Origine azione (action_source) gatto ActionSource action_source additional.fields.key e additional.fields.value.string_value
UUID VM di origine (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
UUID VM di destinazione (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
Tunnel ID/IMSI (tunnelid/imsi) PanOSTunnelID TunnelID tunnelid/imsi additional.fields.key e additional.fields.value.string_value
Monitor Tag/IMEI (monitortag/imei) PanOSMonitorTag MonitorTag monitortag/imei additional.fields.key e additional.fields.value.string_value
ID sessione principale (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Ora di inizio del genitore (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key e additional.fields.value.string_value
Tipo di tunnel (tunnel) PanOSTunnelType TunnelType tunnel additional.fields.key e additional.fields.value.string_value
ID associazione SCTP (assoc_id) PanOSSCTPAssocID assoc_id additional.fields.key e additional.fields.value.string_value
Segmenti SCTP (chunk) PanOSSCTPChunks pezzi additional.fields.key e additional.fields.value.string_value
Segmenti SCTP inviati (chunks_sent) PanOSSCTPChunkSent chunks_sent additional.fields.key e additional.fields.value.string_value
Chunk SCTP ricevuti (chunks_received) PanOSSCTPChunksRcv chunks_received additional.fields.key e additional.fields.value.string_value
UUID regola (rule_uuid) PanOSRuleUUID security_result.rule_id
Connessione HTTP/2 (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
Conteggio flap app (link_change_count) PanLinkChange link_change_count additional.fields.key e additional.fields.value.string_value
ID policy (policy_id) PanPolicyID policy_id additional.fields.key e additional.fields.value.string_value
Interruttori per link (link_switches) PanLinkDetail link_switches additional.fields.key e additional.fields.value.string_value
Cluster SD-WAN (sdwan_cluster) PanSDWANCluster sdwan_cluster additional.fields.key e additional.fields.value.string_value
Tipo di dispositivo SD-WAN (sdwan_device_type) PanSDWANDevice sdwan_device_type additional.fields.key e additional.fields.value.string_value
Tipo di cluster SD-WAN (sdwan_cluster_type) PanSDWANClustype sdwan_cluster_type additional.fields.key e additional.fields.value.string_value
Sito SD-WAN (sdwan_site) PanSDWANSite sdwan_site additional.fields.key e additional.fields.value.string_value
Nome gruppo di utenti dinamico (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name additional.fields.key e additional.fields.value.string_value
Indirizzo XFF (xff_ip) PanXFFIP principal.ip
Categoria dispositivo di origine (src_category) PanSrcDeviceCat src_category principal.asset.category
Profilo del dispositivo di origine (src_profile) PanSrcDeviceProf src_profile

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Modello del dispositivo di origine (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
Fornitore del dispositivo di origine (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
Famiglia di sistemi operativi del dispositivo di origine (src_osfamily) PanSrcDeviceOS principal.platform
Versione del sistema operativo del dispositivo di origine (src_osversion) PanSrcDeviceOSv principal.asset.software.version
Nome host di origine (src_host) PanSrcHostname principal.hostname
Indirizzo MAC di origine (src_mac) PanSrcMac principal.mac
Categoria dispositivo di destinazione (dst_category) PanDstDeviceCat dst_category target.asset.category
Profilo del dispositivo di destinazione (dst_profile) PanDstDeviceProf dst_profile

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Modello del dispositivo di destinazione (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
Fornitore del dispositivo di destinazione (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
Famiglia di sistemi operativi del dispositivo di destinazione (dst_osfamily) PanDstDeviceOS dst_osfamily target.platform
Versione del sistema operativo del dispositivo di destinazione (dst_osversion) PanDstDeviceOSv target.platform_version
Nome host di destinazione (dst_host) PanDstHostname target.hostname
Indirizzo MAC di destinazione (dst_mac) PanDstMac target.mac
ID contenitore (container_id) PanContainerName container_id intermediary.resource.product_object_id
Spazio dei nomi POD (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
Nome POD (pod_name) PanPODName pod_name target.resource.name
Elenco dinamico esterno di origine (src_edl) PanSrcEDL src_edl

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Elenco dinamico esterno di destinazione (dst_edl) PanDstEDL dst_edl

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

ID host (hostid) PanGPHostID hostid principal.asset.asset_id
Numero di serie del dispositivo utente (serialnumber) PanEPSerial principal.asset.hardware.serial_number
Gruppo di indirizzi dinamici di origine (src_dag) PanSrcDAG principal.group.group_display_name
Gruppo di indirizzi dinamici di destinazione (dst_dag) PanDstDAG target.group.group_display_name
Proprietario della sessione (session_owner) PanHASessionOwner session_owner additional.fields.key e additional.fields.value.string_value
Timestamp ad alta risoluzione (high_res_timestamp) PanTimeHighRes additional.fields.key e additional.fields.value.string_value
Un tipo di servizio di sezione (nsdsai_sst) PanASServiceType nsdsai_sst additional.fields.key e additional.fields.value.string_value
Un elemento di differenziazione della sezione (nsdsai_sd) PanASServiceDiff nsdsai_sd additional.fields.key e additional.fields.value.string_value
Sottocategoria dell'applicazione (subcategory_of_app) subcategory_of_app additional.fields.key e additional.fields.value.string_value
Categoria applicazione (category_of_app) category_of_app additional.fields.key e additional.fields.value.string_value
Tecnologia dell'applicazione (technology_of_app) technology_of_app additional.fields.key e additional.fields.value.string_value
Rischio applicazione (risk_of_app) security_result.severity
Caratteristica dell'applicazione (characteristic_of_app) characteristic_of_app additional.fields.key e additional.fields.value.string_value
Container dell'applicazione (container_of_app) container_of_app additional.fields.key e additional.fields.value.string_value
SaaS dell'applicazione (is_saas_of_app) is_saas_of_app additional.fields.key e additional.fields.value.string_value
Stato sanzionato dell'applicazione (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key e additional.fields.value.string_value
Sottocategoria dell'applicazione (subcategory_of_app) subcategory_of_app1 additional.fields.key e additional.fields.value.string_value
Gravità (severity) number-of-severity(header) security_result.severity e security_result.severity_details

User-ID

La tabella seguente elenca i campi del log del tipo di log user-id e i relativi campi UDM.

Campo CSV Campo CEF Campo LEEF Chiave dell'etichetta Google Security Operations Campo UDM
Ora di ricezione (receive_time o cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" è assente)

Numero di serie (seriale) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Tipo (type) type (intestazione) gatto metadata.product_event_type
Tipo di minaccia/contenuti (sottotipo) sottotipo (intestazione) Sottotipo metadata.product_event_type
Ora di generazione (time_generated o cef-formatted-time_generated) metadata.event_timestamp
Sistema virtuale (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
IP di origine (ip) src src principal.ip
Utente (utente) duser usrName target.user.userid

target.administrative_domain

target.user.email_addresses

Nome origine dati (datasourcename) cs4 DataSourceName datasourcename

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

ID evento (eventid) EventID eventid additional.fields.key e additional.fields.value.string_value
Ripeti conteggio (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Soglia di timeout cn3 TimeoutThreshold timeout additional.fields.key e additional.fields.value.string_value
Porta di origine (beginport) spt srcPort principal.port
Porta di destinazione (endport) dpt dstPort target.port
Origine dati cs5 DataSource origine dati

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Tipo di origine dati (datasourcetype) cs6 DataSourceType datasourcetype

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Numero di sequenza (seqno) externalId sequenza metadata.product_log_id
Flag azioni (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome sistema virtuale (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nome dispositivo (device_name) dvchost DeviceName intermediary.hostname
ID sistema virtuale (vsys_id) cn2 VirtualSystemID intermediary.resource.product_object_id
Tipo di fattore (factortype) cs1 FactorType factortype additional.fields.key e additional.fields.value.string_value
Tempo di completamento del fattore (factorcompletiontime) end FactorCompletionTime factorcompletiontime additional.fields.key e additional.fields.value.string_value
Numero fattore (factorno) cn1 FactorNumber factorno additional.fields.key e additional.fields.value.string_value
Flag dei gruppi utente (ugflags) PanOSUGFlags ugflags additional.fields.key e additional.fields.value.string_value
Utente per sorgente (userbysource) PanOSUserBySource target.user.userid

target.administrative_domain

target.user.email_addresses

Timestamp ad alta risoluzione (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value
Origine dati (origindatasource) additional.fields.key e additional.fields.value.string_value
Nome cluster (cluster_name) principal.resource.name
Gravità (severity) number-of-severity(header) security_result.severity e security_result.severity_details

Corrispondenza HIP

La seguente tabella elenca i campi di log del tipo di log di corrispondenza HIP e i relativi campi UDM.

Campo CSV Campo CEF Campo LEEF Chiave dell'etichetta Google Security Operations Campo UDM
Ora di ricezione (receive_time o cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" è assente)

Numero di serie (seriale) deviceExternalId SerialNumber target.asset.hardware.serial_number
Tipo (type) type (intestazione) gatto metadata.product_event_type
Tipo di minaccia/contenuti (sottotipo) sottotipo (intestazione) Sottotipo
Ora di generazione (time_generated o cef-formatted-time_generated) start startTime metadata.event_timestamp
Utente di origine (srcuser) suser usrName principal.user.userid
Sistema virtuale (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
Nome macchina (machinename) spettro identHostName principal.hostname
Sistema operativo cs2 Sistema operativo principal.asset.platform_software.platform
Indirizzo di origine (src) src identsrc principal.ip
HIP (matchname) gatto HIP matchname

target.resource.attribute.labels.key/value

additional.fields.key e additional.fields.value.string_value

Ripeti conteggio (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Tipo di HIP (matchtype) ID classe evento dispositivo (intestazione) HIPType matchtype

target.resource.attribute.labels.key/value

additional.fields.key e additional.fields.value.string_value

Numero di sequenza (seqno) externalId sequenza metadata.product_log_id
Flag azioni (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome sistema virtuale (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
Nome dispositivo (device_name) dvchost DeviceName target.hostname
ID sistema virtuale (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
Indirizzo di sistema IPv6 (srcipv6) c6a2 srcipv6 principal.asset.ip
ID host (hostid) PanOSHostID principal.asset.asset_id
Numero di serie del dispositivo utente (serialnumber) PanOSEndpointSerialNumber principal.asset.hardware.serial_number
Indirizzo MAC del dispositivo (mac) PanOSEndpointMac principal.asset.mac
Timestamp ad alta risoluzione (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value
Nome cluster (cluster_name) principal.resource.name
Gravità (severity) number-of-severity(header) security_result.severity e security_result.severity_details

Tag IP

La tabella seguente elenca i campi di log del tipo di log tag IP e i campi UDM corrispondenti.

Campo CSV Campo CEF Campo LEEF Chiave dell'etichetta Google Security Operations Campo UDM
Ora di ricezione (receive_time o cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" è assente)

Numero di serie (seriale) deviceExternalId SerialNumber target.asset.hardware.serial_number
Tipo (type) type (intestazione) gatto metadata.product_event_type
Tipo di minaccia/contenuti (sottotipo) sottotipo (intestazione) Sottotipo metadata.product_event_type
Ora di generazione (time_generated o cef-formatted-time_generated) GenerateTime metadata.event_timestamp
Sistema virtuale (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
IP di origine (ip) src src principal.ip
Nome tag (tag_name) PanOSTagName TagName tag_name

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

ID evento (event_id) PanOSEventID EventID event_id additional.fields.key e additional.fields.value.string_value
Ripeti conteggio (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Timeout (timeout) PanOSTimeout TimeoutThreshold timeout additional.fields.key e additional.fields.value.string_value
Nome origine dati (datasourcename) PanOSDataSourceName DataSourceName datasourcename

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Tipo di origine dati (datasource_type) PanOSDataSourceType DataSource datasource_type

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Sottotipo di origine dati (datasource_subtype) PanOSDataSourceSubType DataSourceType datasource_subtype

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Numero di sequenza (seqno) externalId sequenza metadata.product_log_id
Flag azioni (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome sistema virtuale (vsys_name) PanOsVsysName vSrcName target.asset.attribute.labels.key/value
Nome dispositivo (device_name) dvchost DeviceName target.hostname
ID sistema virtuale (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
Timestamp ad alta risoluzione (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value
Gravità (severity) number-of-severity(header) security_result.severity e security_result.severity_details
Nome cluster (cluster_name) principal.resource.name

Decriptazione

La tabella seguente elenca i campi di log del tipo di log di decriptazione e i relativi campi UDM.

Campo CSV Campo CEF Campo LEEF Chiave dell'etichetta Google Security Operations Campo UDM
Ora di ricezione (receive_time o cef-formatted-receive_time) rt metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" è assente)

Numero di serie (seriale) PanOSDeviceSN intermediary.asset.hardware.serial_number
Tipo (type) type (intestazione) metadata.product_event_type
Tipo di minaccia/contenuti (sottotipo) sottotipo (intestazione) metadata.product_event_type
Versione configurazione (config_ver) PanOSConfigVersion config_ver additional.fields.key e additional.fields.value.string_value
Generate Time (time_generated) PanOSLogTimeStamp metadata.event_timestamp
Indirizzo di origine (src) src principal.ip
Indirizzo di destinazione (dst) dst target.ip
IP di origine NAT (natsrc) sourceTranslatedAddress principa.nat_ip
IP di destinazione NAT (natdst) destinationTranslatedAddress target.nat_ip
Rule (regola) cs1 security_result.rule_name
Utente di origine (srcuser) suser principal.user.userid
Utente di destinazione (dstuser) duser target.user.userid
Applicazione (app) app network.application_protocol
Sistema virtuale (vsys) cs3 vsys intermediary.asset.attribute.labels.key/value
Zona di origine (da) cs4 da

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Zona di destinazione (a) cs5 a

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Interfaccia in entrata (inbound_if) deviceInboundInterface inbound_if

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Interfaccia in uscita (outbound_if) deviceOutboundInterface outbound_if

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Azione di log (logset) cs6 logset additional.fields.key e additional.fields.value.string_value
Orario log (time_received) PanOSTimeReceivedManagementPlane -
ID sessione (sessionid) cn1 network.session_id
Ripeti conteggio (repeatcnt) PanOSCountOfRepeats/RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Porta di origine (sport) spt principal.port
Porta di destinazione (dport) dpt target.port
Porta di origine NAT (natsport) sourceTranslatedPort principal.nat_port
Porta di destinazione NAT (natdport) destinationTranslatedPort target.nat_port
Flag (flags) flexString1 flags additional.fields.key e additional.fields.value.string_value
Protocollo IP (proto) proto network.ip_protocol
Azione (azione) atto security_result.action_details

security_result.action

Tunnel (tunnel) PanOSTunnel tunnel additional.fields.key e additional.fields.value.string_value
UUID VM di origine (src_uuid) PanOSSourceUUID principal.asset.product_object_id
UUID VM di destinazione (dst_uuid) PanOSDestinationUUID target.asset.product_object_id
UUID per la regola (rule_uuid) PanOSRuleUUID security_result.rule_id
Stage for Client to Firewall (hs_stage_c2f) PanOSClientToFirewall hs_stage_c2f additional.fields.key e additional.fields.value.string_value
Stage for Firewall to Server (hs_stage_f2s) PanOSFirewallToServer hs_stage_f2s additional.fields.key e additional.fields.value.string_value
Versione TLS (tls_version) PanOSTLSVersion network.tls.version
Algoritmo di scambio di chiavi (tls_keyxchg) PanOSTLSKeyExchange tls_keyxchg additional.fields.key e additional.fields.value.string_value
Algoritmo di crittografia (tls_enc) PanOSTLSEncryptionAlgorithm tls_enc additional.fields.key e additional.fields.value.string_value
Algoritmo di hash (tls_auth) PanOSTLSAuth tls_auth additional.fields.key e additional.fields.value.string_value
Nome della policy (policy_name) PanOSPolicyName policy_name additional.fields.key e additional.fields.value.string_value
Curva ellittica (ec_curve) PanOSEllipticCurve network.tls.curve
Indice di errori (err_index) PanOSErrorIndex err_index additional.fields.key e additional.fields.value.string_value
Stato root (root_status) PanOSRootStatus root_status additional.fields.key e additional.fields.value.string_value
Stato della catena (chain_status) PanOSChainStatus chain_status additional.fields.key e additional.fields.value.string_value
Tipo di proxy (proxy_type) PanOSProxyType proxy_type additional.fields.key e additional.fields.value.string_value
Numero di serie del certificato (cert_serial) PanOSCertificateSerial network.tls.server.certificate.serial
Impronta digitale certificato PanOSFingerprint network.tls.server.certificate.md5/sha1/sha256
Data di inizio del certificato (notbefore) PanOSTimeNotBefore network.tls.server.certificate.not_before
Data di fine validità del certificato (notafter) PanOSTimeNotAfter network.tls.server.certificate.not_after
Versione del certificato (cert_ver) PanOSCertificateVersion network.tls.server.certificate.version
Dimensioni certificato (cert_size) PanOSCertificateSize cert_size additional.fields.key e additional.fields.value.string_value
Lunghezza del nome comune (cn_len) PanOSCommonNameLength cn_len additional.fields.key e additional.fields.value.string_value
Lunghezza del nome comune dell'emittente (issuer_len) PanOSIssuerNameLength issuer_len additional.fields.key e additional.fields.value.string_value
Lunghezza del nome comune della radice (rootcn_len) PanOSRootCNLength rootcn_len additional.fields.key e additional.fields.value.string_value
Lunghezza snippet (sni_len) PanOSSNILength sni_len additional.fields.key e additional.fields.value.string_value
Flag del certificato (cert_flags) PanOSCertificateFlags cert_flags additional.fields.key e additional.fields.value.string_value
Nome comune del soggetto (cn) PanOSCommonName cn additional.fields.key e additional.fields.value.string_value
Nome comune dell'emittente (issuer_cn) PanOSIssuerCommonName network.tls.server.certificate.issuer
Nome comune della radice (root_cn) PanOSRootCommonName root_cn additional.fields.key e additional.fields.value.string_value
Server Name Indication

(sni)

network.tls.client.server_name
Errore (errore) PanOSErrorMessage errore additional.fields.key e additional.fields.value.string_value
ID contenitore (container_id) PanOSContainerID container_id intermediary.resource.product_object_id
Spazio dei nomi POD (pod_namespace) PanOSContainerNameSpace pod_namespace

target.resource.attribute.labels.key/value

additional.fields.key e additional.fields.value.string_value

Nome POD (pod_name) PanOSContainerName pod_name target.resource.name
Elenco dinamico esterno di origine (src_edl) PanOSSourceEDL src_edl

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Elenco dinamico esterno di destinazione (dst_edl) PanOSDestinationEDL dst_edl

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Gruppo di indirizzi dinamici di origine (src_dag) PanOSSourceDynamicAddressGroup principal.group.group_display_name
Gruppo di indirizzi dinamici di destinazione (dst_dag) PanOSDestinationDynamicAddressGroup target.group.group_display_name
Timestamp ad alta risoluzione (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value
Categoria dispositivo di origine (src_category) PanOSSourceDeviceCategory src_category principal.asset.category
Profilo del dispositivo di origine (src_profile) PanOSSourceDeviceProfile src_profile

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Modello del dispositivo di origine (src_model) PanOSSourceDeviceModel src_model principal.asset.hardware.model
Fornitore del dispositivo di origine (src_vendor) PanOSSourceDeviceVendor src_vendor principal.asset.hardware.manufacturer
Famiglia di sistemi operativi del dispositivo di origine (src_osfamily) PanOSSourceDeviceOSFamily principal.platform
Versione del sistema operativo del dispositivo di origine (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
Nome host di origine (src_host) PanOSSourceDeviceHost principal.hostname
Indirizzo MAC di origine (src_mac) PanOSSourceDeviceMac principal.mac
Categoria dispositivo di destinazione (dst_category) PanOSDestinationDeviceCategory dst_category target.asset.category
Profilo del dispositivo di destinazione (dst_profile) PanOSDestinationDeviceProfile dst_profile

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Modello del dispositivo di destinazione (dst_model) PanOSDestinationDeviceModel dst_model target.asset.hardware.model
Fornitore del dispositivo di destinazione (dst_vendor) PanOSDestinationDeviceVendor dst_vendor target.asset.hardware.manufacturer
Famiglia di sistemi operativi del dispositivo di destinazione (dst_osfamily) PanOSDestinationDeviceOSFamily dst_osfamily target.platform
Versione del sistema operativo del dispositivo di destinazione (dst_osversion) PanOSDestinationDeviceOSVersion target.platform_version
Nome host di destinazione (dst_host) PanOSDestinationDeviceHost target.hostname
Indirizzo MAC di destinazione (dst_mac) PanOSDestinationDeviceMac target.mac
Numero di sequenza (seqno) PanOSLogTypeSeqNo metadata.product_log_id
Flag azioni (actionflags) PanOSActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_1) DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_2) DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_3) DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_4) DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome sistema virtuale (vsys_name) intermediary.asset.attribute.labels.key/value
Nome dispositivo (device_name) intermediary.hostname
ID sistema virtuale (vsys_id) intermediary.resource.product_object_id
Sottocategoria dell'applicazione (subcategory_of_app) subcategory_of_app additional.fields.key e additional.fields.value.string_value
Categoria applicazione (category_of_app) category_of_app additional.fields.key e additional.fields.value.string_value
Tecnologia dell'applicazione (technology_of_app) technology_of_app additional.fields.key e additional.fields.value.string_value
Rischio applicazione (risk_of_app) security_result.severity
Caratteristica dell'applicazione (characteristic_of_app) characteristic_of_app additional.fields.key e additional.fields.value.string_value
Container dell'applicazione (container_of_app) container_of_app additional.fields.key e additional.fields.value.string_value
SaaS dell'applicazione (is_saas_of_app) is_saas_of_app additional.fields.key e additional.fields.value.string_value
Stato sanzionato dell'applicazione (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key e additional.fields.value.string_value
Gravità (severity) number-of-severity(header) security_result.severity e security_result.severity_details

Tunnel

La tabella seguente elenca i campi di log del tipo di log del tunnel e i relativi campi UDM.

Campo CSV Campo CEF Campo LEEF Chiave dell'etichetta Google Security Operations Campo UDM
Ora di ricezione (receive_time o cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" è assente)

Numero di serie (seriale) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Tipo (type) type (intestazione) gatto metadata.product_event_type
Tipo di minaccia/contenuti (sottotipo) sottotipo (intestazione) Sottotipo metadata.product_event_type
Ora di generazione (time_generated o cef-formatted-time_generated) metadata.event_timestamp
Indirizzo di origine (src) src src principal.ip
Indirizzo di destinazione (dst) dst dst target.ip
IP di origine NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP di destinazione NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Nome regola (regola) cs1 RuleName security_result.rule_name
Utente di origine (srcuser) suser SourceUser / usrName principal.user.userid
Utente di destinazione (dstuser) duser DestinationUser target.user.userid
Applicazione (app) app Applicazione network.application_protocol
Sistema virtuale (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona di origine (da) cs4 SourceZone da

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Zona di destinazione (a) cs5 DestinationZone a

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Interfaccia in entrata (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Interfaccia in uscita (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Azione di log (logset) cs6 LogForwardingProfile logset additional.fields.key e additional.fields.value.string_value
ID sessione (sessionid) cn1 SessionID network.session_id
Ripeti conteggio (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Porta di origine (sport) spt srcPort principal.port
Porta di destinazione (dport) dpt dstPort target.port
Porta di origine NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Porta di destinazione NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Flag (flags) flexString1 Bandiere flags additional.fields.key e additional.fields.value.string_value
Protocollo IP (proto) proto proto network.ip_protocol
Azione (azione) atto azione security_result.action_details

security_result.action

Gravità (severity) number-of-severity(header) security_result.severity e security_result.severity_details
Numero di sequenza (seqno) externalId sequenza metadata.product_log_id
Flag azioni (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Posizione di origine (srcloc) principal.location.country_or_region
Località di destinazione (dstloc) target.location.country_or_region
Gerarchia del gruppo di dispositivi (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome sistema virtuale (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nome dispositivo (device_name) dvchost DeviceName intermediary.hostname
ID tunnel (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key e additional.fields.value.string_value
Monitor Tag (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key e additional.fields.value.string_value
ID sessione principale (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Ora di inizio del genitore (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key e additional.fields.value.string_value
Tipo di tunnel (tunnel) cs2 TunnelType tunnel additional.fields.key e additional.fields.value.string_value
Byte (byte) flexNumber1 totalBytes byte additional.fields.key e additional.fields.value.string_value
Byte inviati (bytes_sent) in srcBytes network.sent_bytes
Byte ricevuti (bytes_received) troppo complessi per essere capiti? dstBytes network.received_bytes
Pacchetti (pacchetti) cn2 totalPackets pacchetti additional.fields.key e additional.fields.value.string_value
Pacchetti inviati (pkts_sent) PanOSPacketsSent srcPackets pkts_sent network.sent_packets
Pacchetti ricevuti (pkts_received) PanOSPacketsReceived dstPackets pkts_received network.received_packets
Incapsulamento massimo (max_encap) flexNumber2 MaximumEncapsulation max_encap additional.fields.key e additional.fields.value.string_value
Protocollo sconosciuto (unknown_proto) cfp1 UnknownProtocol unknown_proto additional.fields.key e additional.fields.value.string_value
Controllo rigoroso (strict_check) cfp2 StrictChecking strict_check additional.fields.key e additional.fields.value.string_value
Frammento tunnel (tunnel_fragment) PanOSTunnelFragment TunnelFragment tunnel_fragment additional.fields.key e additional.fields.value.string_value
Sessioni create (sessions_created) cfp3 SessionsCreated sessions_created additional.fields.key e additional.fields.value.string_value
Sessioni chiuse (sessions_closed) cfp4 SessionsClosed sessions_closed additional.fields.key e additional.fields.value.string_value
Motivo di fine della sessione (session_end_reason) motivo SessionEndReason security_result.summary
Origine azione (action_source) gatto ActionSource action_source additional.fields.key e additional.fields.value.string_value
Ora di inizio (inizio) startTime start additional.fields.key e additional.fields.value.string_value
Tempo trascorso (trascorso) cn3 ElapsedTime trascorso network.session_duration.seconds
Regola di ispezione del tunnel (tunnel_insp_rule) PanOSTunneInspectionRule security_result.rule_name = "Tunnel Inspection Rule: %{PanOSTunnelInspectionRule}"
IP utente remoto (remote_user_ip) PanOSRmtUserIP principal.ip
ID utente remoto (remote_user_id) PanOSRmtUserID remote_user_id principal.user.userid
UUID della regola di sicurezza (rule_uuid) PanOSRuleUUID security_result.rule_id
ID PCAP (pcap_id) PanOSPcapID pcap_id additional.fields.key e additional.fields.value.string_value
Nome gruppo di utenti dinamico (dynusergroup_name) PanDynamicUsrgrp principal.group.group_display_name
Elenco dinamico esterno di origine (src_edl) PanOSSourceEDL src_edl

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Elenco dinamico esterno di destinazione (dst_edl) PanOSDestinationEDL dst_edl

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Timestamp ad alta risoluzione (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value
Un elemento di differenziazione della sezione (nssai_sd) nssai_sd additional.fields.key e additional.fields.value.string_value
Un tipo di servizio di sezione (nssai_sd) nssai_sd1 additional.fields.key e additional.fields.value.string_value
ID sessione PDU (pdu_session_id) pdu_session_id additional.fields.key e additional.fields.value.string_value
Sottocategoria dell'applicazione (subcategory_of_app) subcategory_of_app additional.fields.key e additional.fields.value.string_value
Categoria applicazione (category_of_app) category_of_app additional.fields.key e additional.fields.value.string_value
Tecnologia dell'applicazione (technology_of_app) technology_of_app additional.fields.key e additional.fields.value.string_value
Rischio applicazione (risk_of_app) risk_of_app additional.fields.key e additional.fields.value.string_value
Caratteristica dell'applicazione (characteristic_of_app) characteristic_of_app additional.fields.key e additional.fields.value.string_value
Container dell'applicazione (container_of_app) container_of_app additional.fields.key e additional.fields.value.string_value
SaaS dell'applicazione (is_saas_of_app) is_saas_of_app additional.fields.key e additional.fields.value.string_value
Applicazione sottoposta a tunneling (tunneled_app) additional.fields.key e additional.fields.value.string_value
Scaricato (offloaded) additional.fields.key e additional.fields.value.string_value
Tipo di flusso (flow_type) additional.fields.key e additional.fields.value.string_value
Nome cluster (cluster_name)

principal.resource.name

Stato sanzionato dell'applicazione (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key e additional.fields.value.string_value

Autenticazione

La tabella seguente elenca i campi di log del tipo di log di autenticazione e i relativi campi UDM.

Campo CSV Campo CEF Campo LEEF Chiave dell'etichetta Google Security Operations Campo UDM
Ora di ricezione (receive_time o cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" è assente)

Numero di serie (seriale) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Tipo (type) type (intestazione) gatto metadata.product_event_type
Tipo di minaccia/contenuti (sottotipo) sottotipo (intestazione) Sottotipo metadata.product_event_type
Ora di generazione (time_generated o cef-formatted-time_generated) metadata.event_timestamp
Sistema virtuale (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
IP di origine (ip) src src principal.ip
Utente (utente) duser usrName target.user.userid
Normalizza utente (normalize_user) cs2 NormalizeUser target.user.user_display_name
Oggetto (oggetto) fname ObjectName oggetto target.resource.name
Policy di autenticazione (authpolicy) cs4 AuthPolicy authpolicy additional.fields.key e additional.fields.value.string_value
Ripeti conteggio (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
ID autenticazione (authid) cn2 AuthenticationID authid additional.fields.key e additional.fields.value.string_value
Fornitore (vendor) flexString2 Fornitore vendor additional.fields.key e additional.fields.value.string_value
Azione di log (logset) cs6 LogForwardingProfile logset additional.fields.key e additional.fields.value.string_value
Profilo server (serverprofile) cs1 ServerProfile serverprofile additional.fields.key e additional.fields.value.string_value
Descrizione (ordine decrescente) PanOSDesc AdditionalAuthInfo security_result.description
Tipo di client (clienttype) cs5 ClientType clienttype additional.fields.key e additional.fields.value.string_value
Tipo di evento (evento) msg msg extensions.auth.auth_details
Numero fattore (factorno) cn1 FactorNumber factorno additional.fields.key e additional.fields.value.string_value
Numero di sequenza (seqno) externalId sequenza metadata.product_log_id
Flag azioni (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome sistema virtuale (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nome dispositivo (device_name) dvchost DeviceName intermediary.hostname
ID sistema virtuale (vsys_id) intermediary.resource.product_object_id
Authentication Protocol (authproto) authproto additional.fields.key e additional.fields.value.string_value
UUID per la regola (rule_uuid) PanOSRuleUUID/RuleUUID security_result.rule_id
Timestamp ad alta risoluzione (high_res _timestamp) PanOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value
Categoria dispositivo di origine (src_category) PanOSSourceDeviceCategory src_category principal.asset.category
Profilo del dispositivo di origine (src_profile) PanOSSourceDeviceProfile src_profile

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Modello del dispositivo di origine (src_model) PanOSSourceDeviceModel src_model principal.asset.hardware.model
Fornitore del dispositivo di origine (src_vendor) PanOSSourceDeviceVendor src_vendor principal.asset.hardware.manufacturer
Famiglia di sistemi operativi del dispositivo di origine (src_osfamily) PanOSSourceDeviceOSFamily

principal.asset.platform_software.platform

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Versione del sistema operativo del dispositivo di origine (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
Nome host di origine (src_host) PanOSSourceHostname principal.hostname
Indirizzo MAC di origine (src_mac) PanOSSourceMac principal.asset.mac
Regione (regione) PanOSTrafficOriginRegion principal.location.country_or_region
User agent (user_agent) PanOSHTTPUserAgent network.http.user_agent
ID sessione(sessionid) PanOSTrafficSessionID network.session_id
Gravità (severity) number-of-severity(header) security_result.severity e security_result.severity_details
Nome cluster (cluster_name) principal.resource.name

URL

La seguente tabella elenca i campi di log del tipo di log URL e i relativi campi UDM.

Campo CSV Campo CEF Campo LEEF Chiave dell'etichetta Google Security Operations Campo UDM
Ora di ricezione (cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" è assente)

N. di serie (seriale) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Tipo (type) type (intestazione) gatto metadata.product_event_type
Tipo di minaccia/contenuti (sottotipo) sottotipo (intestazione) Sottotipo metadata.product_event_type
Genera orario metadata.event_timestamp
Indirizzo di origine (src) src src principal.ip
Indirizzo di destinazione (dst) dst dst target.ip
IP di origine NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP di destinazione NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Rule (regola) cs1 RuleName security_result.rule_name
Utente di origine (srcuser) suser SourceUser principal.user.userid
Utente di destinazione (dstuser) duser DestinationUser target.user.userid
Applicazione (app) app Applicazione network.application_protocol
Sistema virtuale (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona di origine (da) cs4 SourceZone da

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Zona di destinazione (a) cs5 DestinationZone a

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Interfaccia in entrata (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Interfaccia in uscita (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Azione di log (logset) cs6 LogForwardingProfile logset additional.fields.key e additional.fields.value.string_value
Tempo registrato time_logged additional.fields.key e additional.fields.value.string_value
ID sessione (sessionid) cn1 SessionID network.session_id
Ripeti conteggio (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Porta di origine (sport) spt srcPort principal.port
Porta di destinazione (dport) dpt dstPort target.port
Porta di origine NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Porta di destinazione NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Flag (flags) flexString1 Bandiere flags additional.fields.key e additional.fields.value.string_value
Protocollo IP (proto) proto proto network.ip_protocol
Azione (azione) atto azione security_result.action_details

security_result.action

URL/Nome file (varie) Vari target.file.names

target.url

Nome minaccia/contenuto (threatid) gatto ThreatID security_result.threat_id
Categoria (categoria) cs2 URLCategory categoria security_result.category_details
Gravità (severity) number-of-severity (intestazione) Gravità security_result.severity

security_result.severity_details

Direzione (direction) flexString2 Direzione network.direction
Numero di sequenza (seqno) externalId sequenza metadata.product_log_id
Flag azioni (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Paese di origine (srcloc) SourceLocation principal.location.country_or_region
Paese di destinazione (dstloc) DestinationLocation target.location.country_or_region
contenttype (contenttype) requestContext ContentType contenttype additional.fields.key e additional.fields.value.string_value
pcap_id (pcap_id) fileId PCAP_ID pcap_id additional.fields.key e additional.fields.value.string_value
filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
cloud (cloud) Cloud cloud additional.fields.key e additional.fields.value.string_value
url_idx (url_idx) URLIndex url_idx additional.fields.key e additional.fields.value.string_value
user_agent (user_agent) requestClientApplication UserAgent network.http.user_agent
filetype (filetype) target.file.mime_type
xff (xff) PanOSXForwarderfor identSrc xff principal.ip
referer (referer) PanOSReferer Referer network.http.referral_url
mittente (sender) network.email.from
subject (subject) Oggetto network.email.subject
destinatario (destinatario) network.email.to
reportid (reportid) reportid additional.fields.key e additional.fields.value.string_value
Livello 1 della gerarchia DG (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Livello 2 della gerarchia DG (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Livello 3 della gerarchia DG (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Livello 4 della gerarchia DG (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome sistema virtuale (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nome dispositivo (device_name) dvchost DeviceName intermediary.hostname
file_url (file_url) target.url
UUID VM di origine (src_uuid) SrcUUID principal.asset.product_object_id
UUID VM di destinazione (dst_uuid) DstUUID target.asset.product_object_id
http_method (http_method) requestMethod RequestMethod network.http.method
ID tunnel/IMSI (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key e additional.fields.value.string_value
Monitor Tag/IMEI (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key e additional.fields.value.string_value
ID sessione principale (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Ora di inizio della sessione principale (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key e additional.fields.value.string_value
Tunnel (tunnel) PanOSTunnelType TunnelType tunnel additional.fields.key e additional.fields.value.string_value
thr_category (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
contentver (contentver) PanOSContentVer ContentVer contentver additional.fields.key e additional.fields.value.string_value
sig_flags (sig_flags) sig_flags additional.fields.key e additional.fields.value.string_value
ID associazione SCTP (assoc_id) PanOSAssocID assoc_id additional.fields.key e additional.fields.value.string_value
ID protocollo payload (ppid) PanOSPPID ppid additional.fields.key e additional.fields.value.string_value
http_headers (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
Elenco categorie di URL (url_category_list) PanOSURLCatList url_category_list additional.fields.key e additional.fields.value.string_value
UUID per la regola (rule_uuid) PanOSRuleUUID rule_uuid security_result.rule_id
Connessione HTTP/2 (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
dynusergroup_name (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name additional.fields.key e additional.fields.value.string_value
Indirizzo XFF (xff_ip) PanXFFIP principal.ip
Categoria dispositivo di origine (src_category) PanSrcDeviceCat src_category principal.asset.category
Profilo del dispositivo di origine (src_profile) PanSrcDeviceProf src_profile

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Modello del dispositivo di origine (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
Fornitore del dispositivo di origine (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
Famiglia di sistemi operativi del dispositivo di origine (src_osfamily) PanSrcDeviceOS principal.platform
Versione del sistema operativo del dispositivo di origine (src_osversion) PanSrcDeviceOSv principal.platform_version
Nome host di origine (src_host) PanSrcHostname src_host principal.hostname
Indirizzo MAC di origine (src_mac) PanSrcMac principal.mac
Categoria dispositivo di destinazione (dst_category) PanDstDeviceCat dst_category target.asset.category
Profilo del dispositivo di destinazione (dst_profile) PanDstDeviceProf dst_profile

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Modello del dispositivo di destinazione (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
Fornitore del dispositivo di destinazione (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
Famiglia di sistemi operativi del dispositivo di destinazione (dst_osfamily) PanDstDeviceOS target.platform
Versione del sistema operativo del dispositivo di destinazione (dst_osversion) PanDstDeviceOSv target.platform_version
Nome host di destinazione (dst_host) PanPODNamespace target.hostname
Indirizzo MAC di destinazione (dst_mac) PanDstMac target.mac
ID contenitore (container_id) PanContainerName container_id intermediary.resource.product_object_id
Spazio dei nomi POD (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
Nome POD (pod_name) PanPODName pod_name target.resource.name
Elenco dinamico esterno di origine (src_edl) PanSrcEDL src_edl

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Elenco dinamico esterno di destinazione (dst_edl) PanDstEDL dst_edl

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

ID host (hostid) PanGPHostID hostid principal.asset.asset_id
Numero di serie (serialnumber) PanEPSerial principal.asset.hardware.serial_number
domain_edl (domain_edl) PanDomainEDL domain_edl additional.fields.key e additional.fields.value.string_value
Gruppo di indirizzi dinamici di origine (src_dag) PanSrcDAG principal.group.group_display_name
Gruppo di indirizzi dinamici di destinazione (dst_dag) PanDstDAG target.group.group_display_name
partial_hash (partial_hash) PanPartialHash partial_hash additional.fields.key e additional.fields.value.string_value
Timestamp ad alta risoluzione (high_res_timestamp) PanTimeHighRes additional.fields.key e additional.fields.value.string_value
Motivo (motivo) PanReasonFilteringAction motivo security_result.summary
motivazione (giustificazione) PanJustification giustificazione additional.fields.key e additional.fields.value.string_value
nssai_sst (nssai_sst) PanASServiceType nssai_sst additional.fields.key e additional.fields.value.string_value
Sottocategoria dell'app (subcategory_of_app) subcategory_of_app additional.fields.key e additional.fields.value.string_value
Categoria di app (category_of_app) category_of_app additional.fields.key e additional.fields.value.string_value
Tecnologia dell'app (technology_of_app) technology_of_app additional.fields.key e additional.fields.value.string_value
Rischio app (risk_of_app) risk_of_app additional.fields.key e additional.fields.value.string_value
Caratteristica dell'app (characteristic_of_app) characteristic_of_app additional.fields.key e additional.fields.value.string_value
Container dell'app (container_of_app) container_of_app additional.fields.key e additional.fields.value.string_value
App con tunnel (tunneled_app) tunneled_app additional.fields.key e additional.fields.value.string_value
SaaS dell'app (is_saas_of_app) is_saas_of_app additional.fields.key e additional.fields.value.string_value
Stato sanzionato dell'app (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key e additional.fields.value.string_value
ID report cloud (cloud_reportid) additional.fields.key e additional.fields.value.string_value
Nome cluster (cluster_name)

principal.resource.name

Tipo di flusso (flow_type) additional.fields.key e additional.fields.value.string_value

Dati

La tabella seguente elenca i campi di log del tipo di log dei dati e i campi UDM corrispondenti.

Campo CSV Campo CEF Campo LEEF Chiave dell'etichetta Google Security Operations Campo UDM
Ora di ricezione (cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" è assente)

N. di serie (seriale) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Tipo (type) type (intestazione) gatto metadata.product_event_type
Tipo di minaccia/contenuti (sottotipo) sottotipo (intestazione) Sottotipo metadata.product_event_type
Genera orario metadata.event_timestamp
Indirizzo di origine (src) src src principal.ip
Indirizzo di destinazione (dst) dst dst target.ip
IP di origine NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP di destinazione NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Rule (regola) cs1 RuleName security_result.rule_name
Utente di origine (srcuser) suser SourceUser principal.user.userid
Utente di destinazione (dstuser) duser DestinationUser target.user.userid
Applicazione (app) app Applicazione network.application_protocol
Sistema virtuale (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona di origine (da) cs4 SourceZone da

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Zona di destinazione (a) cs5 DestinationZone a

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Interfaccia in entrata (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Interfaccia in uscita (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Azione di log (logset) cs6 LogForwardingProfile logset additional.fields.key e additional.fields.value.string_value
Tempo registrato time_logged additional.fields.key e additional.fields.value.string_value
ID sessione (sessionid) cn1 SessionID network.session_id
Ripeti conteggio (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Porta di origine (sport) spt srcPort principal.port
Porta di destinazione (dport) dpt dstPort target.port
Porta di origine NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Porta di destinazione NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Flag (flags) flexString1 Bandiere flags additional.fields.key e additional.fields.value.string_value
Protocollo IP (proto) proto proto network.ip_protocol
Azione (azione) atto azione security_result.action_details

security_result.action

URL/Nome file (varie) Vari target.file.names

target.url

Nome minaccia/contenuto (threatid) gatto ThreatID security_result.threat_id
Categoria (categoria) cs2 URLCategory categoria security_result.category_details
Gravità (severity) number-of-severity (intestazione) Gravità security_result.severity

security_result.severity_details

Direzione (direction) flexString2 Direzione network.direction
Numero di sequenza (seqno) externalId sequenza metadata.product_log_id
Flag azioni (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Paese di origine (srcloc) SourceLocation principal.location.country_or_region
Paese di destinazione (dstloc) DestinationLocation target.location.country_or_region
contenttype (contenttype) ContentType contenttype additional.fields.key e additional.fields.value.string_value
pcap_id (pcap_id) fileId PCAP_ID pcap_id additional.fields.key e additional.fields.value.string_value
filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
cloud (cloud) Cloud cloud additional.fields.key e additional.fields.value.string_value
url_idx (url_idx) URLIndex url_idx additional.fields.key e additional.fields.value.string_value
user_agent (user_agent) network.http.user_agent
filetype (filetype) target.file.mime_type
xff (xff) xff principal.ip
referer (referer) network.http.referral_url
mittente (sender) network.email.from
subject (subject) Oggetto network.email.subject
destinatario (destinatario) network.email.to
reportid (reportid) reportid additional.fields.key e additional.fields.value.string_value
Livello 1 della gerarchia DG (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Livello 2 della gerarchia DG (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Livello 3 della gerarchia DG (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Livello 4 della gerarchia DG (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome sistema virtuale (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nome dispositivo (device_name) dvchost DeviceName intermediary.hostname
file_url (file_url) target.url
UUID VM di origine (src_uuid) SrcUUID principal.asset.product_object_id
UUID VM di destinazione (dst_uuid) DstUUID target.asset.product_object_id
http_method (http_method) RequestMethod network.http.method
ID tunnel/IMSI (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key e additional.fields.value.string_value
Monitor Tag/IMEI (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key e additional.fields.value.string_value
ID sessione principale (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Ora di inizio della sessione principale (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key e additional.fields.value.string_value
Tunnel (tunnel) PanOSTunnelType TunnelType tunnel additional.fields.key e additional.fields.value.string_value
thr_category (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
contentver (contentver) PanOSContentVer ContentVer contentver additional.fields.key e additional.fields.value.string_value
sig_flags (sig_flags) sig_flags additional.fields.key e additional.fields.value.string_value
ID associazione SCTP (assoc_id) PanOSAssocID assoc_id additional.fields.key e additional.fields.value.string_value
ID protocollo payload (ppid) PanOSPPID ppid additional.fields.key e additional.fields.value.string_value
http_headers (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
Elenco categorie di URL (url_category_list) url_category_list additional.fields.key e additional.fields.value.string_value
UUID per la regola (rule_uuid) PanOSRuleUUID rule_uuid security_result.rule_id
Connessione HTTP/2 (http2_connection) http2_connection network.application_protocol_version
dynusergroup_name (dynusergroup_name) dynusergroup_name

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Indirizzo XFF (xff_ip) principal.ip
Categoria dispositivo di origine (src_category) src_category principal.asset.category
Profilo del dispositivo di origine (src_profile) src_profile

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Modello del dispositivo di origine (src_model) src_model principal.asset.hardware.model
Fornitore del dispositivo di origine (src_vendor) src_vendor principal.asset.hardware.manufacturer
Famiglia di sistemi operativi del dispositivo di origine (src_osfamily) principal.platform
Versione del sistema operativo del dispositivo di origine (src_osversion) principal.platform_version
Nome host di origine (src_host) src_host principal.hostname
Indirizzo MAC di origine (src_mac) principal.mac
Categoria dispositivo di destinazione (dst_category) dst_category target.asset.category
Profilo del dispositivo di destinazione (dst_profile) dst_profile

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Modello del dispositivo di destinazione (dst_model) dst_model target.asset.hardware.model
Fornitore del dispositivo di destinazione (dst_vendor) dst_vendor target.asset.hardware.manufacturer
Famiglia di sistemi operativi del dispositivo di destinazione (dst_osfamily) target.platform
Versione del sistema operativo del dispositivo di destinazione (dst_osversion) target.platform_version
Nome host di destinazione (dst_host) target.hostname
Indirizzo MAC di destinazione (dst_mac) target.mac
ID contenitore (container_id) container_id intermediary.resource.product_object_id
Spazio dei nomi POD (pod_namespace) pod_namespace target.resource.attribute.labels.key/value
Nome POD (pod_name) pod_name target.resource.name
Elenco dinamico esterno di origine (src_edl) src_edl

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Elenco dinamico esterno di destinazione (dst_edl) dst_edl

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

ID host (hostid) hostid principal.asset.asset_id
Numero di serie (serialnumber) principal.asset.hardware.serial_number
domain_edl (domain_edl) domain_edl additional.fields.key e additional.fields.value.string_value
Gruppo di indirizzi dinamici di origine (src_dag) principal.group.group_display_name
Gruppo di indirizzi dinamici di destinazione (dst_dag) target.group.group_display_name
partial_hash (partial_hash) partial_hash additional.fields.key e additional.fields.value.string_value
Timestamp ad alta risoluzione (high_res_timestamp) additional.fields.key e additional.fields.value.string_value
Motivo (motivo) motivo security_result.summary
motivazione (giustificazione) giustificazione additional.fields.key e additional.fields.value.string_value
nssai_sst (nssai_sst) nssai_sst additional.fields.key e additional.fields.value.string_value
Sottocategoria dell'app (subcategory_of_app) subcategory_of_app additional.fields.key e additional.fields.value.string_value
Categoria di app (category_of_app) category_of_app additional.fields.key e additional.fields.value.string_value
Tecnologia dell'app (technology_of_app) technology_of_app additional.fields.key e additional.fields.value.string_value
Rischio app (risk_of_app) risk_of_app additional.fields.key e additional.fields.value.string_value
Caratteristica dell'app (characteristic_of_app) characteristic_of_app additional.fields.key e additional.fields.value.string_value
Container dell'app (container_of_app) container_of_app additional.fields.key e additional.fields.value.string_value
App con tunnel (tunneled_app) tunneled_app additional.fields.key e additional.fields.value.string_value
SaaS dell'app (is_saas_of_app) is_saas_of_app additional.fields.key e additional.fields.value.string_value
Stato sanzionato dell'app (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key e additional.fields.value.string_value
ID report cloud (cloud_reportid) additional.fields.key e additional.fields.value.string_value
Nome cluster (cluster_name) principal.resource.name
Tipo di flusso (flow_type) additional.fields.key e additional.fields.value.string_value

GlobalProtect

La tabella seguente elenca i campi di log del tipo di log GlobalProtect e i relativi campi UDM.

Campo CSV Campo CEF Campo LEEF Chiave dell'etichetta Google Security Operations Campo UDM
Ora di ricezione (receive_time) rt received_time metadata.event_timestamp
N. di serie (seriale) PanOSDeviceSN intermediary_asset_hardware_serial_number intermediary.asset.hardware.serial_number
Tipo (type) type (intestazione) metadata.product_event_type
Tipo di minaccia/contenuti (sottotipo) sottotipo (intestazione) Sottotipo metadata.product_event_type
Generate Time (time_generated) PanOSLogTimeStamp generated_timestamp metadata.event_timestamp
Sistema virtuale (vsys) PanOSVirtualSystem vsys intermediary.asset.attribute.labels.key/value
ID evento (eventid) PanOSEventID event_id additional.fields.key e additional.fields.value.string_value
Stage (stage) PanOSStage fase additional.fields.key e additional.fields.value.string_value
Metodo di autenticazione (auth_method) PanOSAuthMethod extension_auth_auth_details extensions.auth.auth_details
Tipo di tunnel (tunnel_type) PanOSTunnelType tunnel additional.fields.key e additional.fields.value.string_value
Utente di origine (srcuser) PanOSSourceUserName src_user principal.user.email_address

principal.user.userid

principal.administrative_domain

Regione di origine (srcregion) PanOSSourceRegion src_region principal.location.country_or_region
Nome macchina (machinename) PanOSEndpointDeviceName machine_name principal.hostname
IP pubblico (public_ip) PanOSPublicIPv4 principal.nat_ip
IPv6 pubblico (public_ipv6) PanOSPublicIPv6 principal.nat_ip
IP privato (private_ip) PanOSPrivateIPv4 principal.ip
IPv6 privato (private_ipv6) PanOSPrivateIPv6 principal.ip
ID host (hostid) PanOSHostID hostid principal.asset.asset_id
Numero di serie (serialnumber) PanOSDeviceSN principal.asset.hardware.serial_number
Versione client (client_ver) PanOSGlobalProtectClientVersion client_ver additional.fields.key e additional.fields.value.string_value
Sistema operativo client (client_os) PanOSEndpointOSType principal.platform
Versione del sistema operativo client (client_os_ver) PanOSEndpointOSVersion principal.platform_version
Ripeti conteggio (repeatcnt) PanOSCountOfRepeats repeatcnt additional.fields.key e additional.fields.value.string_value
Motivo (motivo) PanOSQuarantineReason security_result.summary
Errore (errore) PanOSConnectionError errore security_result.description
Descrizione (opaca) PanOSDescription security_result.description
Stato (stato) PanOSEventStatus stato additional.fields.key e additional.fields.value.string_value
Località (posizione) PanOSGPGatewayLocation target.location.country_or_region
Durata dell'accesso (login_duration) PanOSLoginDuration network.session_duration
Metodo di connessione (connect_method) PanOSConnectionMethod connect_method additional.fields.key e additional.fields.value.string_value
Codice di errore (error_code) PanOSConnectionErrorID error_code additional.fields.key e additional.fields.value.string_value
Portale (portale) PanOSPortal portale additional.fields.key e additional.fields.value.string_value
Numero di sequenza (seqno) PanOSSequenceNo metadata.product_log_id
Flag azioni (actionflags) PanOSActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Timestamp ad alta risoluzione (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value
Metodo di selezione del gateway (selection_type) PanOSGatewaySelectionType selection_type additional.fields.key e additional.fields.value.string_value
Tempo di risposta SSL (response_time) PanOSSSLResponseTime response_time additional.fields.key e additional.fields.value.string_value
Priorità gateway (priorità) PanOSGatewayPriority priorità additional.fields.key e additional.fields.value.string_value
Tentativi di gateway (attempted_gateways) PanOSAttemptedGateways attempted_gateways additional.fields.key e additional.fields.value.string_value
Nome gateway (gateway) PanOSAttemptedGateways gateway target.resource.name
Gerarchia del gruppo di dispositivi (dg_hier_level_1) dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_2) dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_3) dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Gerarchia del gruppo di dispositivi (dg_hier_level_4) dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome sistema virtuale (vsys_name) intermediary.asset.attribute.labels.key/value
Nome dispositivo (device_name) intermediary.hostname
ID sistema virtuale (vsys_id) intermediary.resource.product_object_id
Gravità (severity) number-of-severity(header) security_result.severity e security_result.severity_details
Nome cluster (cluster_name) principal.resource.name

Correlazione

La tabella seguente elenca i campi di log del tipo di log di correlazione e i campi UDM corrispondenti.

Campo CSV Campo CEF Campo LEEF Chiave dell'etichetta Google Security Operations Campo UDM
Ora di generazione (time_generated o cef-formatted-time_generated) startTime generated_timestamp metadata.event_timestamp
Indirizzo di origine (src) src principal.ip
Utente di origine (srcuser) SourceUser / usrName principal.user.userid
Sistema virtuale (vsys) VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Categoria (categoria) security_result.category_details
Gravità (severity) Gravità security_result.severity e security_result.severity_details
Livello 1 della gerarchia del gruppo di dispositivi DeviceGroupHierarchyL1 additional.fields.key e additional.fields.value.string_value
Livello 2 della gerarchia del gruppo di dispositivi DeviceGroupHierarchyL2 additional.fields.key e additional.fields.value.string_value
Livello 3 della gerarchia del gruppo di dispositivi DeviceGroupHierarchyL3 additional.fields.key e additional.fields.value.string_value
Livello 4 della gerarchia dei gruppi di dispositivi DeviceGroupHierarchyL4 additional.fields.key e additional.fields.value.string_value
Nome sistema virtuale (vsys_name) vSrcName intermediary.asset.attribute.labels.key/value
Nome dispositivo (device_name) DeviceName intermediary.hostname
ID sistema virtuale (vsys_id) VirtualSystemID intermediary.resource.product_object_id
Nome oggetto (objectname) ObjectName target.resource.name
ID oggetto (object_id) ObjectID target.resource.product_object_id
Prove (evidence) msg security_result.summary

GTP

La tabella seguente elenca i campi di log del tipo di log gtp e i relativi campi UDM.

Campo CSV Campo CEF Campo LEEF Chiave dell'etichetta Google Security Operations Campo UDM
Ora di ricezione (receive_time o cef-formatted-receive_time) metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" è assente)

Numero di serie (seriale) intermediary.asset.hardware.serial_number
Tipo (type) metadata.product_event_type
Tipo di minaccia/contenuti (sottotipo) metadata.product_event_type
Ora di generazione (time_generated o cef-formatted-time_generated) metadata.event_timestamp
Indirizzo di origine (src) principal.ip
Indirizzo di destinazione (dst) target.ip
Nome regola (regola) security_result.rule_name
Applicazione (app) network.application_protocol
Sistema virtuale (vsys) vsys intermediary.asset.attribute.labels.key/value
Zona di origine (da) da

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Zona di destinazione (a) a

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Interfaccia in entrata (inbound_if) inbound_if

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Interfaccia in uscita (outbound_if) outbound_if

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Azione di log (logset) logset additional.fields.key e additional.fields.value.string_value
ID sessione (sessionid) network.session_id
Porta di origine (sport) principal.port
Porta di destinazione (dport) target.port
Protocollo IP (proto) network.ip_protocol
Azione (azione) security_result.action_details

security_result.action

Tipo di evento GTP (event_type) gtp_event_type additional.fields.key e additional.fields.value.string_value
MSISDN (msisdn) msisdn additional.fields.key e additional.fields.value.string_value
Nome punto di accesso (APN) apn additional.fields.key e additional.fields.value.string_value
Tecnologia di accesso radio (RAT) topo additional.fields.key e additional.fields.value.string_value
Tipo di messaggio GTP (msg_type) gtp_msg_type additional.fields.key e additional.fields.value.string_value
Indirizzo IP finale (end_ip_adr) principal.ip
Tunnel Endpoint Identifier1 (teid1) teid1 additional.fields.key e additional.fields.value.string_value
Identificatore endpoint tunnel 2 (teid2) teid2 additional.fields.key e additional.fields.value.string_value
Interfaccia GTP (gtp_interface) gtp_interface additional.fields.key e additional.fields.value.string_value
Causa GTP (cause_code) gtp_cause_code additional.fields.key e additional.fields.value.string_value
Gravità (severity) security_result.severity e security_result.severity_details
Codice MCC di rete (mcc) mcc additional.fields.key e additional.fields.value.string_value
Serving Network MNC (mnc) mnc additional.fields.key e additional.fields.value.string_value
Prefisso (area_code) area_code additional.fields.key e additional.fields.value.string_value
ID cella (cell_id) cell_id additional.fields.key e additional.fields.value.string_value
Codice evento GTP (event_code) event_code additional.fields.key e additional.fields.value.string_value
Posizione di origine (srcloc) principal.location.country_or_region
Località di destinazione (dstloc) target.location.country_or_region
ID tunnel/IMSI (imsi) tunnelid additional.fields.key e additional.fields.value.string_value
Monitor Tag/IMEI (imei) monitortag additional.fields.key e additional.fields.value.string_value
Ora di inizio (inizio) start additional.fields.key e additional.fields.value.string_value
Tempo trascorso (trascorso) network.session_duration.seconds
Tunnel Inspection RuleTunnel (tunnel_insp_rule) tunnel_insp_rule security_result.detection_fields.key/value
IP utente remoto (remote_user_ip) principal.ip
ID utente remoto (remote_user_id) remote_user_id principal.user.userid
UUID per la regola (rule_uuid) security_result.rule_id
ID PCAP (pcap_id) pcap_id additional.fields.key e additional.fields.value.string_value
Timestamp ad alta risoluzione (high_res_timestamp) additional.fields.key e additional.fields.value.string_value
Un tipo di servizio di sezione (nsdsai_sst) nsdsai_sst additional.fields.key e additional.fields.value.string_value
Un elemento di differenziazione della sezione (nsdsai_sd) nsdsai_sd additional.fields.key e additional.fields.value.string_value
Sottocategoria dell'applicazione (subcategory_of_app) subcategory_of_app additional.fields.key e additional.fields.value.string_value
Categoria applicazione (category_of_app) category_of_app additional.fields.key e additional.fields.value.string_value
Tecnologia dell'applicazione (technology_of_app) technology_of_app additional.fields.key e additional.fields.value.string_value
Rischio applicazione (risk_of_app) risk_of_app additional.fields.key e additional.fields.value.string_value
Caratteristica dell'applicazione (characteristic_of_app) characteristic_of_app additional.fields.key e additional.fields.value.string_value
Container dell'applicazione (container_of_app) container_of_app additional.fields.key e additional.fields.value.string_value
SaaS dell'applicazione (is_saas_of_app) is_saas_of_app additional.fields.key e additional.fields.value.string_value
Stato sanzionato dell'applicazione (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key e additional.fields.value.string_value

SCTP

Campo CSV Campo CEF Campo LEEF Chiave dell'etichetta Google Security Operations Campo UDM
Ora di ricezione (receive_time o cef-formatted-receive_time) receive_time o cef-formatted-receive_time metadata.collected_timestamp
Numero di serie (seriale) serial intermediary.asset.hardware.serial_number
Tipo (type) tipo metadata.product_event_type
Ora di generazione (time_generated o cef-formatted-time_generated) time_generated o cef-formatted-time_generated metadata.event_timestamp
Indirizzo di origine (src) src principal.ip
Indirizzo di destinazione (dst) dst target.ip
Nome regola (regola) regola security_result.rule_name
Zona di origine (da) da additional.fields.key e additional.fields.value.string_value
Zona di destinazione (a) a additional.fields.key e additional.fields.value.string_value
Interfaccia in entrata (inbound_if) inbound_if additional.fields.key e additional.fields.value.string_value
Interfaccia in uscita (outbound_if) outbound_if additional.fields.key e additional.fields.value.string_value
Azione di log (logset) logset additional.fields.key e additional.fields.value.string_value
ID sessione (sessionid) sessionid network.session_id
Ripeti conteggio (repeatcnt) repeatcnt additional.fields.key e additional.fields.value.string_value
Porta di origine (sport) sport principal.port
Porta di destinazione (dport) dport target.port
Protocollo IP (proto) proto network.ip_protocol (enum)
Azione (azione) azione security_result.action_details
security_result.action
Gerarchia dei gruppi di dispositivi (dg_hier_level_1 a dg_hier_level_4) dg_hier_level_1 to dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome dispositivo (device_name) device_name intermediary.hostname
Numero di sequenza (seqno) seqno metadata.product_log_id
ID associazione SCTP (assoc_id) assoc_id additional.fields.key e additional.fields.value.string_value
ID protocollo payload (ppid) ppid additional.fields.key e additional.fields.value.string_value
Gravità (severity) gravità security_result.severity e security_result.severity_details
Tipo di chunk SCTP (sctp_chunk_type) sctp_chunk_type additional.fields.key e additional.fields.value.string_value
Tipo di evento SCTP (sctp_event_type) sctp_event_type additional.fields.key e additional.fields.value.string_value
Tag di verifica SCTP 1 (verif_tag_1) verif_tag_1 additional.fields.key e additional.fields.value.string_value
Tag di verifica SCTP 2 (verif_tag_2) verif_tag_2 additional.fields.key e additional.fields.value.string_value
Codice di causa SCTP (sctp_cause_code) sctp_cause_code additional.fields.key e additional.fields.value.string_value
ID app diametro (diam_app_id) diam_app_id additional.fields.key e additional.fields.value.string_value
Codice comando diametro (diam_cmd_code) diam_cmd_code additional.fields.key e additional.fields.value.string_value
Diameter AVP Code (diam_avp_code) diam_avp_code additional.fields.key e additional.fields.value.string_value
ID stream SCTP (stream_id) stream_id additional.fields.key e additional.fields.value.string_value
Motivo di fine dell'associazione SCTP (assoc_end_reason) assoc_end_reason additional.fields.key e additional.fields.value.string_value
Codice operativo (op_code) op_code additional.fields.key e additional.fields.value.string_value
SCCP Calling Party SSN (sccp_calling_ssn) sccp_calling_ssn additional.fields.key e additional.fields.value.string_value
SCCP Calling Party Global Title (sccp_calling_gt) sccp_calling_gt additional.fields.key e additional.fields.value.string_value
Filtro SCTP (sctp_filter) sctp_filter additional.fields.key e additional.fields.value.string_value
Segmenti SCTP (chunk) pezzi additional.fields.key e additional.fields.value.string_value
Segmenti SCTP inviati (chunks_sent) chunks_sent additional.fields.key e additional.fields.value.string_value
Chunk SCTP ricevuti (chunks_received) chunks_received additional.fields.key e additional.fields.value.string_value
Pacchetti (pacchetti) pacchetti additional.fields.key e additional.fields.value.string_value
UUID per la regola (rule_uuid) rule_uuid security_result.rule_id
Sistema virtuale (vsys) vsys intermediary.asset.attribute.labels.key/value
Nome sistema virtuale (vsys_name) vsys_name intermediary.asset.attribute.labels.key/value
Pacchetti inviati (pkts_sent) pkts_sent network.sent_packets
Pacchetti ricevuti (pkts_received) pkts_received network.received_packets

Controlla

Campo CSV Campo CEF Campo LEEF Chiave dell'etichetta Google Security Operations Campo UDM
Genera orario metadata.event_timestamp
Tipo di minaccia/contenuti (sottotipo) metadata.product_event_type
ID evento principal.application
Oggetto principal.user.userid
Comando CLI principal.process.command_line
Gravità security_result.severity
Numero di serie intermediary.asset.hardware.serial_number

Riferimento per la mappatura dei campi: tipi di log e tipo di evento UDM

La tabella seguente elenca i tipi di log del firewall Palo Alto Networks e i relativi tipi di eventi UDM.

Tipo di log Tipo di evento UDM
Traffico NETWORK_CONNECTION
Minaccia NETWORK_CONNECTION
Filtro degli URL NETWORK_CONNECTION
WildFire NETWORK_CONNECTION

I log di invio di WildFire sono un sottotipo del tipo di log delle minacce e utilizzano lo stesso formato syslog.

Filtro dei dati NETWORK_CONNECTION
Tunnel NETWORK_CONNECTION
GTP NETWORK_CONNECTION
Configurazione SETTING_MODIFICATION/SETTING_CREATION/SETTING_DELETION/SETTING_UNCATEGORIZED

Il valore del campo "Command (cmd)" determina la mappatura del tipo di evento UDM. Se il valore del campo cmd è add o clone, viene impostato SETTING_CREATION.

Se il valore del campo cmd è delete, viene impostato SETTING_DELETION.

Se il valore del campo cmd è edit, move, rename, set o commit, SETTING_MODIFICATION è impostato.

Se il valore del campo cmd non contiene valori, viene impostato SETTING_UNCATEGORIZED.

Sistema

Se il valore del sottotipo è "dhcp", viene impostato NETWORK_DHCP.

Se il valore del sottotipo è "auth", viene impostato USER_LOGIN.

Se il valore della descrizione è "logged in", viene impostato USER_LOGIN.

Se il valore della descrizione è "logged out", viene impostato USER_LOGOUT.

Per gli altri valori del sottotipo, viene impostato GENERIC_EVENT.

HIP Match NETWORK_CONNECTION
Tag IP GENERIC_EVENT
User-ID USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED

Se il valore del sottotipo è "login", viene impostato USER_LOGIN.

Se il valore del sottotipo è "logout", viene impostato USER_LOGOUT.

Se il sottotipo non contiene alcun valore, viene impostato USER_UNCATEGORIZED.

Decriptazione NETWORK_CONNECTION
Autenticazione GENERIC_EVENT
SCTP NETWORK_CONNECTION
Controlla GENERIC_EVENT

Delta di mappatura UDM

Riferimento delta mappatura UDM: firewall Palo Alto Networks

La tabella seguente elenca la differenza tra la vecchia mappatura UDM di Palo Alto Networks Firewall e la nuova mappatura UDM di Palo Alto Networks Firewall.

UDM Event Type Delta

Log type Old UDM Event Type New UDM Event Type
WildFire NETWORK_CONNECTION SCAN_UNCATEGORIZED
Data Filtering NETWORK_CONNECTION NETWORK_UNCATEGORIZED
Authentication STATUS_UPDATE STATUS_UNCATEGORIZED

UDM Field Mapping Delta

Log Type Old UDM Mapping CSV Log Field CEF Log Field LEEF Log Field New UDM Mapping
System intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
System about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
System about.labels.key/value additional.fields.key/value.string_value Object (object) fname Filename target.resource.name
System Description (opaque) msg msg metadata.description
System principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
System intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
Config intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Config about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
Config principal.process.command_line Configuration Path (path) msg ConfigurationPath principal.process.command_line
Config principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
Config intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
Config principal.asset.attribute.labels.key/value Device Group (dg_id) PanOSFWDeviceGroup target.asset.attribute.labels
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Threat/Wildfire target.file.full_path target.url target.hostname URL/Filename (misc) request Miscellaneous target.file.names target.url
Threat/Wildfire about.file.sha1/md5/sha256 File Digest (filedigest) fileHash FileDigest target.file.sha1/md5/sha256
Threat/Wildfire about.file.mime_type File Type (filetype) fileType FileType target.file.mime_type
Threat/Wildfire principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Threat/Wildfire principal.user.product_object_id Source VM UUID (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
Threat/Wildfire target.user.product_object_id Destination VM UUID (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value HTTP Headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
Threat/Wildfire principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
Threat/Wildfire principal.asset.software.version Source Device OS Version (src_osversion) PanSrcDeviceOSv principal.platform_version
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
Threat/Wildfire target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
Threat/Wildfire metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Reason (reason) PanReasonFilteringAction security_result.summary
Traffic about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value Packets Sent (pkts_sent) PanOSPacketsSent srcPackets network.sent_packets
Traffic about.labels.key/value additional.fields.key/value.string_value Packets Received (pkts_received) PanOSPacketsReceived dstPackets network.received_packets
Traffic principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
Traffic principal.asset.platform_software.platform(enum) principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
Traffic target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
Traffic about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
Traffic about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
Traffic about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
Traffic metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
User-ID about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
User-ID principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
User-ID principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID intermediary.resource.product_object_id
User-ID principal.user.userid principal.administrative_domain principal.user.email_addresses User by Source (userbysource) PanOSUserBySource target.user.userid target.user.email_addresses
User-ID metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
HIP Match intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
HIP Match about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
HIP Match about.labels.key/value additional.fields.key/value.string_value HIP (matchname) cat HIP target.resource.attribute.labels
HIP Match about.labels.key/value additional.fields.key/value.string_value HIP Type (matchtype) Device Event Class ID (Header) HIPType target.resource.attribute.labels
HIP Match principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
HIP Match intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
HIP Match principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
HIP Match principal.asset.product_object_id Host ID (hostid) PanOSHostID principal.asset.asset_id
HIP Match metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
IP-Tag intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
IP-Tag about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
IP-Tag principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOsVsysName vSrcName target.asset.attribute.labels
IP-Tag intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
IP-Tag principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
IP-Tag metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Decryption target.application Application (app) app network.application_protocol
Decryption about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 intermediary.asset.attribute.labels
Decryption principal.asset.asset_id Source VM UUID (src_uuid) PanOSSourceUUID principal.asset.product_object_id
Decryption target.asset.asset_id Destination VM UUID (dst_uuid) PanOSDestinationUUID target.asset.product_object_id
Decryption about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanOSContainerID intermediary.resource.product_object_id
Decryption about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanOSContainerNameSpace target.resource.attribute.labels additional.fields.key/value.string_value
Decryption about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanOSContainerName target.resource.name
Decryption metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanOSSourceDeviceCategory principal.asset.category
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanOSSourceDeviceModel principal.asset.hardware.model
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanOSSourceDeviceVendor principal.asset.hardware.manufacturer
Decryption principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanOSSourceDeviceOSFamily principal.platform
Decryption principal.asset.software.version Source Device OS Version (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanOSDestinationDeviceCategory target.asset.category
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanOSDestinationDeviceModel target.asset.hardware.model
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanOSDestinationDeviceVendor target.asset.hardware.manufacturer
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanOSDestinationDeviceOSFamily target.platform
Decryption target.asset.software.version Destination Device OS Version (dst_osversion) PanOSDestinationDeviceOSVersion target.platform_version
Decryption principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) intermediary.asset.attribute.labels
Decryption principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
Tunnel about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Tunnel principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Tunnel about.labels.key/value additional.fields.key/value.string_value Packets Sent (pkts_sent) PanOSPacketsSent srcPackets network.sent_packets
Tunnel about.labels.key/value additional.fields.key/value.string_value Packets Received (pkts_received) PanOSPacketsReceived dstPackets network.received_packets
Tunnel target.ip Remote User IP (remote_user_ip) PanOSRmtUserIP principal.ip
Tunnel target.labels.key/value additional.fields.key/value.string_value Remote User ID (remote_user_id) PanOSRmtUserID principal.user.userid
Tunnel metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Authentication about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Authentication target.user.user_display_name Normalize User (normalize_user) cs2 NormalizeUser target.user.user_display_name
Authentication about.labels.key/value additional.fields.key/value.string_value Object (object) fname ObjectName target.resource.name
Authentication about.labels.key/value additional.fields.key/value.string_value Authentication Policy (authpolicy) cs4 AuthPolicy additional.fields.key/value.string_value
Authentication principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Authentication principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
Authentication metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res _timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanOSSourceDeviceCategory principal.asset.category
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanOSSourceDeviceModel principal.asset.hardware.model
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanOSSourceDeviceVendor principal.asset.hardware.manufacturer
Authentication principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanOSSourceDeviceOSFamily principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value
Authentication principal.asset.software.version Source Device OS Version (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
URL about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
URL target.file.full_path target.url URL/Filename (misc) Miscellaneous target.file.names target.url
URL about.labels.key/value additional.fields.key/value.string_value Category (category) cs2 URLCategory security_result.category_details
URL about.file.sha1/md5/sha256 filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
URL about.file.mime_type filetype (filetype) target.file.mime_type
URL about.labels.key/value additional.fields.key/value.string_value xff (xff) PanOSXForwarderfor identSrc principal.ip
URL principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
URL about.url file_url (file_url) target.url
URL principal.asset.asset_id Source VM UUID (src_uuid) SrcUUID principal.asset.product_object_id
URL target.asset.asset_id Destination VM UUID (dst_uuid) DstUUID target.asset.product_object_id
URL about.labels.key/value additional.fields.key/value.string_value http_headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
URL about.labels.key/value additional.fields.key/value.string_value UUID for rule (rule_uuid) PanOSRuleUUID security_result.rule_id
URL about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
URL principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
URL principal.asset.software.version Source Device OS Version (src_osversion) PanSrcDeviceOSv principal.platform_version
URL principal.labels.key/value additional.fields.key/value.string_value Source Hostname (src_host) PanSrcHostname principal.hostname
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
URL target.asset.platform_software.platform target.labels.key/value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
URL target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
URL about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
URL about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
URL about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
URL about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
URL metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Res Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
URL about.labels.key/value additional.fields.key/value.string_value Reason (reason) PanReasonFilteringAction security_result.summary
Data about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Data target.file.full_path target.url URL/Filename (misc) Miscellaneous target.file.names target.url
Data about.labels.key/value additional.fields.key/value.string_value Category (category) cs2 URLCategory security_result.category_details
Data about.file.sha1/md5/sha256 filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
Data about.file.mime_type filetype (filetype) target.file.mime_type
Data about.labels.key/value additional.fields.key/value.string_value xff (xff) principal.ip
Data principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Data about.url file_url (file_url) target.url
Data principal.asset.asset_id Source VM UUID (src_uuid) SrcUUID principal.asset.product_object_id
Data target.asset.asset_id Destination VM UUID (dst_uuid) DstUUID target.asset.product_object_id
Data about.labels.key/value additional.fields.key/value.string_value http_headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
Data about.labels.key/value additional.fields.key/value.string_value UUID for rule (rule_uuid) PanOSRuleUUID security_result.rule_id
Data about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) network.application_protocol_version
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) principal.asset.category
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) principal.asset.hardware.model
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) principal.asset.hardware.manufacturer
Data principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) principal.platform
Data principal.asset.software.version Source Device OS Version (src_osversion) principal.platform_version
Data principal.labels.key/value additional.fields.key/value.string_value Source Hostname (src_host) principal.hostname
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) target.asset.category
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) target.asset.hardware.model
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) target.asset.hardware.manufacturer
Data target.asset.platform_software.platform target.labels.key/value Destination Device OS Family (dst_osfamily) target.platform
Data target.asset.software.version Destination Device OS Version (dst_osversion) target.platform_version
Data about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) intermediary.resource.product_object_id
Data about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) target.resource.attribute.labels
Data about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) target.resource.name
Data about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) principal.asset.asset_id
Data metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Res Timestamp (high_res_timestamp) additional.fields.key/value.string_value
Data about.labels.key/value additional.fields.key/value.string_value Reason (reason) security_result.summary
GlobalProtect about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) PanOSVirtualSystem intermediary.asset.attribute.labels
GlobalProtect principal.user.email_address principal.user.userid principal.administrative_domain Source User (srcuser) PanOSSourceUserName target.user.email_address target.user.userid
GlobalProtect principal.asset.platform_software.platform(enum) Client OS (client_os) PanOSEndpointOSType principal.platform
GlobalProtect principal.asset.platform_software.platform_version Client OS Version (client_os_ver) PanOSEndpointOSVersion principal.platform_version
GlobalProtect metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
GlobalProtect about.labels.key/value additional.fields.key/value.string_value Gateway Name (gateway) PanOSAttemptedGateways target.resource.name
GlobalProtect principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) intermediary.asset.attribute.labels
GlobalProtect target.hostname Device Name (device_name) intermediary.hostname
GlobalProtect principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
CORRELATION about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) VirtualSystem intermediary.asset.attribute.labels
CORRELATION principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) vSrcName intermediary.asset.attribute.labels
CORRELATION principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) VirtualSystemID intermediary.resource.product_object_id
GTP additional.fields.key/value.string_value Virtual System (vsys) intermediary.asset.attribute.labels
GTP target.ip Remote User IP (remote_user_ip) principal.ip
GTP additional.fields.key/value.string_value Remote User ID (remote_user_id) principal.user.userid
GTP metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) additional.fields.key/value.string_value

Servizio di logging di Palo Alto Networks Firewall Strata

Panoramica

Palo Alto Networks® Strata Logging Service fornisce archiviazione e aggregazione centralizzate dei log basate su cloud per i firewall on-premise, virtuali (cloud privato e cloud pubblico), per Prisma Access e per i servizi forniti dal cloud come Cortex XDR.Strata Logging Service è sicuro, resiliente e tollerante agli errori e garantisce che i dati di logging siano aggiornati e disponibili quando ne hai bisogno. Fornisce un'infrastruttura di logging scalabile che elimina la necessità di pianificare e implementare raccoglitori di log per soddisfare le tue esigenze di conservazione dei log. Se hai già raccoglitori di log on-premise, il nuovo servizio di logging Strata può integrare la configurazione esistente. Puoi ampliare l'infrastruttura di raccolta dei log esistente con il servizio Strata Logging basato sul cloud per espandere la capacità operativa man mano che la tua attività cresce o per soddisfare le esigenze di capacità per le nuove sedi.Con questo servizio, Palo Alto Networks si occupa della manutenzione e del monitoraggio continui dell'infrastruttura di logging, in modo che tu possa concentrarti sulla tua attività.

  • Verifica i formati dei log e le versioni di PAN-OS supportati dal parser del servizio di logging Strata. La tabella seguente elenca i formati dei log e le versioni di PAN-OS corrispondenti supportate dal parser del servizio di logging Strata:

    Formato log Versione PAN-OS
    JSON 12.1
  • Verifica i tipi di log del firewall Palo Alto Networks supportati dal parser Google SecOps. Il parser di Google SecOps supporta i seguenti tipi di log del firewall Palo Alto Networks:

    • Traffico
    • Minaccia
    • Ispezione tunnel
    • Sistema
    • Corrispondenza HIP
    • IP-Tag
    • User-ID
    • Decriptazione
    • Autenticazione
    • Filtro degli URL
    • GlobalProtect

Deployment del servizio di logging di Strata

Inizia a inviare log al servizio di logging Strata:

Per iniziare a inviare i log al servizio di logging Strata, segui questi passaggi:

  1. Installare una versione supportata di PAN-OS®
  2. Attiva il servizio di logging Strata: l'attivazione del servizio di logging Strata include il provisioning del certificato necessario ai firewall per connettersi in modo sicuro al servizio di logging Strata.
  3. Esegui l'onboarding dei firewall in Strata Logging Service con o senza Panorama

Per la procedura di onboarding dettagliata, consulta la documentazione.

Inoltra i log dal servizio Strata Logging

Per soddisfare le esigenze di archiviazione, generazione di report e monitoraggio a lungo termine o legali e di conformità, puoi configurare Strata Logging Service per inoltrare i log a un server HTTPS o ai seguenti SIEM:

  1. Exabeam
  2. Google Chronicle
  3. Microsoft Sentinel
  4. Raccolta eventi HTTP (HEC) Splunk

Utilizza il metodo di inoltro HTTPS per inoltrare i log utilizzando il servizio di logging Strata. Per informazioni dettagliate, consulta questa documentazione.

Formati di log supportati

Il parser firewall del servizio di logging Strata di Palo Alto Networks supporta i log in formato JSON.

Log di esempio supportati

  • JSON

    {"source": "Palo Alto Networks FLS LF", "host": "dummy-loghost", "time": "1730265996460", "event": {"TimeReceived": "2024-10-30T05:25:50.000000Z", "DeviceSN": "no-serial", "LogType": "TRAFFIC", "Subtype": "end", "ConfigVersion": "10.2", "TimeGenerated": "2024-10-30T05:25:40.000000Z", "SourceAddress": "198.51.100.6", "DestinationAddress": "198.51.100.6", "NATSource": "", "NATDestination": "", "Rule": "egress-dns-ping-traceroute", "SourceUser": null, "DestinationUser": null, "Application": "dns-base", "VirtualLocation": "vsys1", "FromZone": "VA8280-RN", "ToZone": "inter-fw", "InboundInterface": "tunnel.101", "OutboundInterface": "tunnel.4005", "LogSetting": "Cortex Data Lake", "SessionID": 754194, "RepeatCount": 1, "SourcePort": 53578, "DestinationPort": 53, "NATSourcePort": 0, "NATDestinationPort": 0, "Protocol": "udp", "Action": "allow", "Bytes": 214, "BytesSent": 72, "BytesReceived": 142, "PacketsTotal": 2, "SessionStartTime": "2024-10-30T05:25:10.000000Z", "SessionDuration": 0, "URLCategory": "any", "SequenceNo": 7382192512716388639, "SourceLocation": "198.51.100.6-198.51.255.255", "DestinationLocation": "198.51.100.6-198.51.255.255", "PacketsSent": 1, "PacketsReceived": 1, "SessionEndReason": "aged-out", "DGHierarchyLevel1": 65537, "DGHierarchyLevel2": 65538, "DGHierarchyLevel3": 65541, "DGHierarchyLevel4": 0, "VirtualSystemName": "", "DeviceName": "VA8280-RN", "ActionSource": "from-policy", "SourceUUID": null, "DestinationUUID": null, "IMSI": 0, "IMEI": null, "ParentSessionID": 0, "ParentStarttime": "1970-01-01T00:00:00.000000Z", "Tunnel": "N/A", "EndpointAssociationID": 72057594037927936, "ChunksTotal": 0, "ChunksSent": 0, "ChunksReceived": 0, "RuleUUID": "95cfc3cc-cb00-4758-af1d-de9ab5f07f97", "HTTP2Connection": 0, "LinkChangeCount": 0, "SDWANPolicyName": null, "LinkSwitches": null, "SDWANCluster": null, "SDWANDeviceType": null, "SDWANClusterType": null, "SDWANSite": null, "DynamicUserGroupName": null, "X-Forwarded-ForIP": null, "SourceDeviceCategory": null, "SourceDeviceProfile": null, "SourceDeviceModel": null, "SourceDeviceVendor": null, "SourceDeviceOSFamily": null, "SourceDeviceOSVersion": null, "SourceDeviceHost": null, "SourceDeviceMac": null, "DestinationDeviceCategory": null, "DestinationDeviceProfile": null, "DestinationDeviceModel": null, "DestinationDeviceVendor": null, "DestinationDeviceOSFamily": null, "DestinationDeviceOSVersion": null, "DestinationDeviceHost": null, "DestinationDeviceMac": null, "ContainerID": null, "ContainerNameSpace": null, "ContainerName": null, "SourceEDL": null, "DestinationEDL": null, "GPHostID": null, "EndpointSerialNumber": null, "SourceDynamicAddressGroup": null, "DestinationDynamicAddressGroup": null, "HASessionOwner": null, "TimeGeneratedHighResolution": "2024-10-30T05:25:41.009000Z", "NSSAINetworkSliceType": null, "NSSAINetworkSliceDifferentiator": null}}"
    

Riferimento per la mappatura dei campi: campi dei log e campi UDM

Questa sezione spiega come il parser mappa i campi dei log del firewall di Palo Alto Networks Strata Logging Service ai campi degli eventi UDM di Google per ogni tipo di log.

Per il riferimento alla mappatura di ogni tipo di log, consulta le seguenti sezioni:

Sistema

La tabella seguente elenca i campi di log del tipo di log di sistema e i campi UDM corrispondenti.

Log field UDM mapping
AgentContentVersion additional.fields.key/value.string_value
AgentDataCollectionStatus target.resource.attribute.labels
AgentID target.resource.attribute.labels
AgentIsolationStatus target.resource.attribute.labels
AgentStatus target.resource.attribute.labels
AgentVersion target.asset.software.version
ConfigVersion additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DeviceGroup target.group.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EndpointCPUArchitecture target.asset.hardware.cpu_platform
EndpointDeviceDomain target.asset.administrative_domain
EndpointDeviceName target.asset.hostname
EndpointIPaddress target.asset.ip
VDIEndpoint target.asset.attribute.labels
EndpointOSType additional.fields.key/value.string_value
EndpointOSVersion target.platform_version
AgentTimeZoneOffset additional.fields.key/value.string_value
EndpointUserDomain additional.fields.key/value.string_value
EndpointUserName target.user.user_display_name
EndpointUserUUID target.user.userid
EventComponent additional.fields.key/value.string_value
EventDescription metadata.description
EventName additional.fields.key/value.string_value
EventTime metadata.event_timestamp
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogCategory security_result.category_details
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
LogSourceID target.resource.attribute.labels
LogSourceName observer.asset.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
LogTime metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Severity security_result.severity
Subtype metadata.product_event_type
Template target.resource.attribute.labels
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

Minaccia

La tabella seguente elenca i campi di log del tipo di log Minaccia e i relativi campi UDM.

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
ApplianceOrCloud additional.fields.key/value.string_value
CloudHostname additional.fields.key/value.string_value
CloudReportID security_result.detection_fields.key/value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DirectionOfAttack security_result.detection_fields.key/value
DomainEDL additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
FileName target.file.names
FileHash target.file.sha1
FileType additional.fields.key/value.string_value
FileURL target.url
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HostID principal.asset.asset_id
HTTP2Connection network.application_protocol_version
HTTPMethod network.http.method
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
LocalDeepLearningAnalyzed additional.fields.key/value.string_value
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
PartialHash additional.fields.key/value.string_value
PayloadProtocolID additional.fields.key/value.string_value
Packet additional.fields.key/value.string_value
PacketID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
RecipientEmail target.user.email_addresses
ReportID security_result.detection_fields.key/value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SenderEmail principal.user.email_addresses
SequenceNo metadata.product_log_id
SessionID network.session_id
Severity security_result.severity
SigFlags additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
EmailSubject network.email.subject
ApplicationTechnology additional.fields.key/value.string_value
ThreatCategory security_result.detection_fields.key/value.key/value
ThreatID security_result.threat_id
ThreatName security_result.threat_name
ThreatNameFirewall additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLDomain target.domain.name
URLCounter additional.fields.key/value.string_value
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
Verdict additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-ForIP principal.ip

Traffico

La tabella seguente elenca i campi di log del tipo di log sul traffico e i campi UDM corrispondenti.

Log field UDM mapping
Action security_result.action
ActionSource additional.fields.key/value.string_value
AIFwdError additional.fields.key/value.string_value
AITraffic additional.fields.key/value.string_value
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
BytesReceived network.received_bytes
BytesSent network.sent_bytes
Bytes additional.fields.key/value.string_value
ChunksReceived additional.fields.key/value.string_value
ChunksSent additional.fields.key/value.string_value
ChunksTotal additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
EndpointAssociationID additional.fields.key/value.string_value
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HASessionOwner additional.fields.key/value.string_value
GPHostID additional.fields.key/value.string_value
HTTP2Connection network.application_protocol_version
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsOffloaded additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
LinkChangeCount additional.fields.key/value.string_value
LinkSwitches additional.fields.key/value.string_value
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
SDWANPolicyName additional.fields.key/value.string_value
Protocol network.ip_protocol
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SDWANFECRatio additional.fields.key/value.string_value
SDWANCluster additional.fields.key/value.string_value
SDWANClusterType additional.fields.key/value.string_value
SDWANDeviceType additional.fields.key/value.string_value
SDWANSite additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionStartTime additional.fields.key/value.string_value
SessionTracker additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
SessionDuration network.session_duration
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLCategory target.url_metadata.categories
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-ForIP principal.ip

User-ID

La tabella seguente elenca i campi di log del tipo di log User-ID e i relativi campi UDM.

Log field UDM mapping
AuthFactorNo security_result.detection_fields.key/value
AuthenticatedUserDomain target.user.administrative_domain
AuthenticatedUserName target.user.userid
AuthenticatedUserUUID target.user.product_object_id
ConfigVersion additional.fields.key/value.string_value
CountofRepeats additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationPort target.port
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EventID additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsDuplicateUser additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MappingDataSource additional.fields.key/value.string_value
MappingDataSourceName additional.fields.key/value.string_value
MappingDataSourceType additional.fields.key/value.string_value
MappingTimeout additional.fields.key/value.string_value
MFAFactorType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SourceIP principal.ip
SourcePort principal.port
Subtype metadata.product_event_type
Tag additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
UGFlags additional.fields.key/value.string_value
User target.user.userid
UserGroupFound additional.fields.key/value.string_value
UserIdentifiedBySource additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Corrispondenza HIP

La seguente tabella elenca i campi di log del tipo di log di corrispondenza HIP e i relativi campi UDM.

Log field UDM mapping
ConfigVersion additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EndpointDeviceName principal.asset.hostname
EndpointOSType additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
HipMatchName target.resource.attribute.labels
HipMatchType target.resource.attribute.labels
HostID principal.asset.asset_id
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType metadata.product_event_type
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Source additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceIP principal.ip
SourceIPv6 principal.ip
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
TimestampDeviceIdentification principal.asset.first_seen_time
UUID additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

Tag IP

La tabella seguente elenca i campi di log del tipo di log tag IP e i campi UDM corrispondenti.

Log field UDM mapping
ConfigVersion additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EventID additional.fields.key/value.string_value
IPSubnetRange network.ip_subnet_range
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSetting target.resource.attribute.labels
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MappingDataSource additional.fields.key/value.string_value
MappingDataSourceSubType additional.fields.key/value.string_value
MappingDataSourceType additional.fields.key/value.string_value
MappingTimeout additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
RuleMatched security_result.rule_name
RuleMatchedUUID security_result.rule_id
SequenceNo metadata.product_log_id
SourceIP principal.ip
Subtype metadata.product_event_type
TagName additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

Decriptazione

La tabella seguente elenca i campi di log del tipo di log Decryption e i relativi campi UDM.

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
CertificateFlags additional.fields.key/value.string_value
CertificateSerial network.tls.server.certificate.serial
CertificateSize additional.fields.key/value.string_value
CertificateVersion network.tls.server.certificate.version
ChainStatus additional.fields.key/value.string_value
ApplicationCharacteristics additional.fields.key/value.string_value
ClientToFirewall additional.fields.key/value.string_value
CommonName additional.fields.key/value.string_value
CommonNameLength additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
Cpadding additional.fields.key/value.string_value
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
Domain target.hostname
EllipticCurve network.tls.curve
ErrorIndex additional.fields.key/value.string_value
ErrorMessage additional.fields.key/value.string_value
Fingerprint network.tls.server.certificate.md5/sha1/sha256
FirewallToClient additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsCertECDSA additional.fields.key/value.string_value
IsCertRSA additional.fields.key/value.string_value
IsCertCNTruncated additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
IsForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsIssuerCNTruncated additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
IsNAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
PacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsResumeSession additional.fields.key/value.string_value
IsRootCNTruncated additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSNITruncated additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
IssuerCommonName network.tls.server.certificate.issuer
IssuerNameLength additional.fields.key/value.string_value
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
TimeNotAfter additional.fields.key/value.string_value
TimeNotBefore additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
Padding additional.fields.key/value.string_value
Padding3 additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
PolicyName additional.fields.key/value.string_value
Protocol network.ip_protocol
ProxyType additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
RootCommonName additional.fields.key/value.string_value
RootCNLength additional.fields.key/value.string_value
RootStatus additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SessionID network.session_id
ServerNameIndication network.tls.client.server_name
SNILength additional.fields.key/value.string_value
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceOS additional.fields.key/value.string_value
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
ApplicationTechnology additional.fields.key/value.string_value
TimeReceivedManagementPlane additional.fields.key/value.string_value
TLSAuth additional.fields.key/value.string_value
TLSEncryptionAlgorithm additional.fields.key/value.string_value
TLSKeyExchange additional.fields.key/value.string_value
TLSVersion network.tls.version
ToZone additional.fields.key/value.string_value
Tpadding additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
Vpadding additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SourceDeviceCategory principal.asset.category
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Tunnel

La tabella seguente elenca i campi di log del tipo di log Tunnel e i relativi campi UDM.

Log field UDM mapping
AccessPointName additional.fields.key/value.string_value
Action security_result.action
ActionSource additional.fields.key/value.string_value
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
BytesReceived network.received_bytes
BytesSent network.sent_bytes
Bytes additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
LoggingServiceID additional.fields.key/value.string_value
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MobileAreaCode additional.fields.key/value.string_value
MobileBaseStationCode additional.fields.key/value.string_value
MobileCountryCode additional.fields.key/value.string_value
MobileIP additional.fields.key/value.string_value
MobileNetworkCode additional.fields.key/value.string_value
MobileSubscriberISDN additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceDifferentiator additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsDroppedMax additional.fields.key/value.string_value
PacketsDroppedStrict additional.fields.key/value.string_value
PacketsDroppedTunnel additional.fields.key/value.string_value
PacketsDroppedProtocol additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
ProtocolDataUnitsessionID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
RadioAccessTechnology additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionStartTime additional.fields.key/value.string_value
SessionTracker additional.fields.key/value.string_value
Severity security_result.severity
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
StandardPortsOfApp additional.fields.key/value.string_value
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
SessionDuration network.session_duration
Tunnel additional.fields.key/value.string_value
TunnelCauseCode additional.fields.key/value.string_value
TunnelEndpointID1 additional.fields.key/value.string_value
TunnelEndpointID2 additional.fields.key/value.string_value
TunnelEventCode additional.fields.key/value.string_value
TunnelEventType additional.fields.key/value.string_value
TunnelInspectionRule additional.fields.key/value.string_value
TunnelInterface additional.fields.key/value.string_value
TunnelMessageType additional.fields.key/value.string_value
TunnelRemoteIMSIID additional.fields.key/value.string_value
TunnelRemoteUserIP principal.ip
TunnelSessionsClosed additional.fields.key/value.string_value
TunnelSessionsCreated additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLCategory target.url_metadata.categories
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Autenticazione

La tabella seguente elenca i campi di log del tipo di log di autenticazione e i relativi campi UDM corrispondenti.

Log field UDM mapping
AuthenticationDescription security_result.description
AuthEvent metadata.description
AuthFactorNo security_result.detection_fields.key/value
AuthenticationPolicy security_result.detection_fields.key/value
AuthenticationProtocol additional.fields.key/value.string_value
AuthServerProfile additional.fields.key/value.string_value
AuthenticatedUserDomain target.administrative_domain
AuthenticatedUserName target.user.userid
AuthenticatedUserUUID target.user.product_object_id
ClientType additional.fields.key/value.string_value
ClientTypeName additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
IsPrismaNetworks additional.fields.key/value.string_value
Location target.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogType additional.fields.key/value.string_value
MFAAuthenticationID additional.fields.key/value.string_value
MFAVendor additional.fields.key/value.string_value
NormalizeUser target.user.user_display_name
Object target.resource.name
RuleMatched security_result.rule_name
RuleMatchedUUID security_result.rule_id
AuthCacheServiceRegion additional.fields.key/value.string_value
SessionID network.session_id
SourceDeviceCategory principal.asset.category
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceIP principal.ip
TimeGenerated metadata.event_timestamp
User target.user.userid
UserAgentString network.http.user_agent
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Subtype metadata.product_event_type
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

URL

La seguente tabella elenca i campi di log del tipo di log URL e i relativi campi UDM.

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
CloudHostname additional.fields.key/value.string_value
CloudReportID security_result.detection_fields.key/value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentType additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DirectionOfAttack security_result.detection_fields.key/value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
FileURL target.url
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HostID principal.asset.asset_id
HTTP2Connection network.application_protocol_version
HTTPHeaders additional.fields.key/value.string_value
HTTPMethod network.http.method
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
InlineMLVerdict additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
Packet additional.fields.key/value.string_value
PacketID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
Referer network.http.referral_url
HTTPRefererFQDN additional.fields.key/value.string_value
HTTPRefererPort additional.fields.key/value.string_value
HTTPRefererProtocol additional.fields.key/value.string_value
HTTPRefererURLPath additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionID network.session_id
Severity security_result.severity
SigFlags additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URL target.url_metadata.URL
URLCategory target.url_metadata.categories
URLCategoryList additional.fields.key/value.string_value
URLDomain target.domain.name
URLCounter additional.fields.key/value.string_value
UserAgent network.http.user_agent
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-For additional.fields.key/value.string_value
X-Forwarded-ForIP principal.ip

GlobalProtect

La tabella seguente elenca i campi di log del tipo di log GlobalProtect e i relativi campi UDM.

Log field UDM mapping
AttemptedGateways additional.fields.key/value.string_value
AuthMethod extensions.auth.auth_details
ConnectionMethod additional.fields.key/value.string_value
ConnectionErrorID additional.fields.key/value.string_value
ConnectionError additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
EndpointDeviceName principal.asset.hostname
GlobalProtectClientVersion additional.fields.key/value.string_value
EndpointOSType additional.fields.key/value.string_value
EndpointSN principal.asset.hardware.serial_number
EventIDValue additional.fields.key/value.string_value
Gateway target.resource.name
GatewayPriority additional.fields.key/value.string_value
GatewaySelectionType additional.fields.key/value.string_value
GlobalProtectGatewayLocation target.location.country_or_region
HostID principal.asset.asset_id
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LoginDuration network.session_duration
Description security_result.description
Portal target.hostname
PrivateIPv4 principal.ip
PrivateIPv6 principal.ip
ProjectName additional.fields.key/value.string_value
PublicIPv4 principal.nat_ip
PublicIPv6 principal.nat_ip
QuarantineReason security_result.summary
SequenceNo metadata.product_log_id
SourceRegion principal.location.country_or_region
SourceUserName principal.user.user_display_name
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SSLResponseTime additional.fields.key/value.string_value
Stage additional.fields.key/value.string_value
EventStatus additional.fields.key/value.string_value
LogSubtype metadata.product_event_type
TunnelType additional.fields.key/value.string_value
VirtualSystem intermediary.asset.attribute.labels
VirtualSystemName intermediary.asset.attribute.labels
EndpointOSVersion principal.platform_version
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType metadata.product_event_type
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualSystemID intermediary.resource.product_object_id

SCTP

La tabella seguente elenca i campi di log del tipo di log SCTP e i relativi campi UDM.

Log field UDM mapping
Action security_result.action
Application target.application
AssocationEndReason additional.fields.key/value.string_value
ChunksReceived additional.fields.key/value.string_value
ChunksSent additional.fields.key/value.string_value
ChunksTotal additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceClass target.asset.category
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationIP target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DiamAppID additional.fields.key/value.string_value
DiamAvpCode additional.fields.key/value.string_value
DiameterCommandCode additional.fields.key/value.string_value
DiameterRequestFlag additional.fields.key/value.string_value
DeviceName principal.asset.hostname
SCTPEventType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLFiltering additional.fields.key/value.string_value
IsWildfire additional.fields.key/value.string_value
LogAction additional.fields.key/value.string_value
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MapAppCode additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PayloadProtocolID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
Rule security_result.rule_name
RuleUUID security_result.rule_id
SccpCallingGt additional.fields.key/value.string_value
SccpCallingSSN additional.fields.key/value.string_value
SctpCauseCode additional.fields.key/value.string_value
SctpChunkType additional.fields.key/value.string_value
SctpFilter additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionTracker additional.fields.key/value.string_value
Severity security_result.severity
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceIP principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VerificationTag1 additional.fields.key/value.string_value
VerificationTag2 additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Controlla

La tabella seguente elenca i campi di log del tipo Audit log e i relativi campi UDM corrispondenti.

Log field UDM mapping
EventCategory network.http.method
EventDescription metadata.description
EventDestinationURL target.url
EventDestinationUserUserID target.user.userid
DestinationVendor additional.fields.key/value.string_value
EventDetails additional.fields.key/value.string_value
EventID metadata.product_log_id
EventName additional.fields.key/value.string_value
EventResult security_result.summary
EventSourceUserUserID principal.user.userid
EventTime metadata.event_timestamp
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
Subtype metadata.product_event_type
TSGID additional.fields.key/value.string_value
Vendor additional.fields.key/value.string_value
VendorSeverity security_result.severity_details

Riferimento per la mappatura dei campi: tipi di log e tipo di evento UDM

La tabella seguente elenca i tipi di log firewall del servizio di logging Strata di Palo Alto Networks e i tipi di eventi UDM corrispondenti.

Tipo di log Tipo di evento UDM
Traffico NETWORK_CONNECTION
Minaccia NETWORK_CONNECTION
Filtro degli URL NETWORK_CONNECTION
Tunnel NETWORK_CONNECTION
Sistema

Se il valore del sottotipo è "dhcp", viene impostato NETWORK_DHCP.

Se il valore del sottotipo è "auth", viene impostato USER_LOGIN.

Se il valore della descrizione è "logged in", viene impostato USER_LOGIN.

Se il valore della descrizione è "logged out", viene impostato USER_LOGOUT.

Per gli altri valori del sottotipo, viene impostato GENERIC_EVENT.

HIP Match NETWORK_CONNECTION
Tag IP GENERIC_EVENT
User-ID USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED

Se il valore del sottotipo è "login", viene impostato USER_LOGIN.

Se il valore del sottotipo è "logout", viene impostato USER_LOGOUT.

Se il sottotipo non contiene alcun valore, viene impostato USER_UNCATEGORIZED.

Decriptazione NETWORK_CONNECTION
Autenticazione STATUS_UNCATEGORIZED
Globalprotect USER_LOGIN/USER_LOGOUT/USER_RESOURCE_ACCESS

Se il valore del sottotipo è "auth", viene impostato USER_LOGIN.

Se il valore del sottotipo è "logout", viene impostato USER_LOGOUT.

Se il sottotipo non contiene alcun valore, viene impostato USER_RESOURCE_ACCESS.

SCTP NETWORK_CONNECTION
Controlla NETWORK_CONNECTION

Passaggi successivi

Hai bisogno di ulteriore assistenza? Ricevi risposte dai membri della community e dai professionisti di Google SecOps.