Coletar registros de firewall da Palo Alto Networks

Compatível com:

Firewall da Palo Alto Networks

Visão geral

Neste documento, descrevemos como configurar o syslog e um encaminhador do Google SecOps para coletar registros de firewall da Palo Alto Networks. Este documento também explica como os campos de registro do firewall da Palo Alto Networks são mapeados para os campos do modelo de dados unificado (UDM) do Google SecOps. Para uma visão geral sobre a ingestão de dados do Google SecOps, consulte Ingestão de dados no Google SecOps. Um rótulo de ingestão identifica o analisador que normaliza dados de registro brutos para o formato UDM estruturado. As informações neste documento se aplicam ao analisador com o rótulo de ingestão PAN_FIREWALL.

Antes de começar

  • Verifique se o produto de firewall da Palo Alto Networks está implantado e configurado corretamente. Para instruções detalhadas de configuração, consulte a documentação do PAN-OS.
  • Para entender os componentes implantados para coletar registros do firewall da Palo Alto Networks, revise a arquitetura de implantação. Cada implantação de cliente pode ser diferente dessa representação e ser mais complexa. O diagrama a seguir mostra como configurar o syslog em um firewall da Palo Alto Networks e instalar um encaminhador do Google SecOps em um servidor Linux para encaminhar dados de registro ao Google SecOps. O analisador aceita registros gravados nos seguintes formatos de dados: valores separados por vírgula (CSV), formato de evento comum (CEF) e formato estendido de evento de registro (LEEF).

    Arquitetura de implantação

  • Verifique os formatos de registro e as versões do PAN-OS compatíveis com o analisador do Google SecOps. A tabela a seguir lista os formatos de registro e as versões correspondentes do PAN-OS compatíveis com o analisador do Google SecOps:

    Formato do registro Versão do PAN-OS
    CSV 10.1.3
    CEF 10.0.0
    LEEF 9.1.0
  • Verifique os tipos de registros de firewall da Palo Alto Networks compatíveis com o analisador do Google SecOps. O analisador do Google SecOps é compatível com os seguintes tipos de registros de firewall da Palo Alto Networks:

    • Tráfego
    • Ameaça
    • Envios do WildFire
    • Inspeção de túnel
    • Configuração
    • Sistema
    • Correspondência de HIP
    • IP-Tag
    • User-ID
    • Descriptografia
    • Autenticação
    • Filtragem de URL
    • Filtragem de dados
    • GlobalProtect
    • Correlação
    • GTP
    • SCTP
    • Auditoria

    Para mais informações sobre os tipos de registros de firewall da Palo Alto Networks, consulte Tipos de registros do PAN-OS.

  • Verifique se todos os sistemas na arquitetura de implantação estão configurados no fuso horário UTC.

  • Antes de usar o analisador de firewall da Palo Alto Networks, revise as mudanças nos mapeamentos de campos entre o analisador anterior e o atual analisador de firewall da Palo Alto Networks. Como parte da migração, verifique se as regras, pesquisas, painéis ou outros processos que dependem dos campos originais estão usando os campos atualizados.

    Por exemplo, na versão anterior do analisador, o campo de registro category é mapeado para o campo security_result.description da UDM. No analisador atual do firewall da Palo Alto Networks, o campo de registro category é mapeado para o campo security_result.category_details do UDM. Se você migrar para o analisador de firewall atual da Palo Alto Networks e usar o campo category nas suas regras, será necessário modificar as regras para usar o campo security_result.category_details da UDM do analisador atual.

Configurar o syslog e o encaminhador do Google Security Operations

Para configurar o syslog e o encaminhador do Google SecOps, siga estas etapas:

  1. Para monitorar registros CSV, configure o perfil do servidor syslog. Para mais informações, consulte Configurar o perfil do servidor syslog. Ao configurar o perfil do servidor syslog, especifique "Padrão" como o formato de registro personalizado.
  2. Para monitorar registros CEF, configure o firewall da Palo Alto Networks para encaminhar esses registros. Para mais informações, faça o download do PDF do guia de integração do CEF do PAN-OS e consulte a seção "Configuração do NGFW da Palo Alto Networks para gerar eventos CEF".
  3. Para monitorar registros LEEF, configure o perfil do servidor syslog. Para mais informações, consulte Encaminhamento de registros personalizados no formato LEEF.
  4. Configure o encaminhador do Google SecOps para enviar registros ao Google Security Operations. Para mais informações, consulte Instalar e configurar o encaminhador no Linux. Confira a seguir um exemplo de configuração de encaminhador do Google SecOps:

      - syslog:
          common:
            enabled: true
            data_type: PAN_FIREWALL
            batch_n_seconds: 10
            batch_n_bytes: 1048576
          tcp_address: 0.0.0.0:10518
          connection_timeout_sec: 60
    

Configurar o encaminhamento de syslog no firewall da PAN

Criar um perfil de servidor syslog

  1. Faça login no Console de gerenciamento de firewall da Palo Alto Networks.
  2. Acesse Dispositivo > Perfis de servidor > Syslog.
  3. Clique em Adicionar para criar um perfil de servidor.
  4. Informe os seguintes detalhes de configuração:
    • Nome: insira um nome descritivo, por exemplo, Google SecOps BindPlane.
    • Local: selecione o sistema virtual (vsys) ou Compartilhado em que esse perfil vai estar disponível.
  5. Clique em Servidores > Adicionar para configurar o servidor syslog.
  6. Forneça os seguintes detalhes de configuração do servidor:
    • Nome: insira um nome descritivo para o servidor. Por exemplo, BindPlane Agent.
    • Servidor Syslog: insira o endereço IP do agente do BindPlane.
    • Transporte: selecione UDP ou TCP, dependendo da configuração do agente do BindPlane (UDP é o padrão).
    • Porta: insira o número da porta do agente do BindPlane (por exemplo, 514).
    • Formato: selecione BSD (padrão) ou IETF, dependendo dos seus requisitos.
    • Facilidade: selecione LOG_USER (padrão) ou outra facilidade, conforme necessário.
  7. Clique em OK para salvar o perfil do servidor syslog.

Opcional: configurar um formato de registro personalizado para CEF ou LEEF

Se você precisar de registros CEF (Common Event Format) ou LEEF (Log Event Extended Format) em vez de CSV:

  1. No perfil do servidor Syslog, selecione a guia Formato de registro personalizado.
  2. Configure o formato de registro personalizado para cada tipo de registro (Config, System, Threat, Traffic, URL, Data, WildFire, Tunnel, Authentication, User-ID, HIP Match).
  3. Para configurar o formato CEF, consulte o Guia de configuração do CEF da Palo Alto Networks (em inglês).
  4. Clique em OK para salvar a configuração.

Criar um perfil de encaminhamento de registros

  1. Acesse Objetos > Encaminhamento de registros.
  2. Clique em Adicionar para criar um perfil de encaminhamento de registros.
  3. Informe os seguintes detalhes de configuração:
    • Nome: insira um nome de perfil (por exemplo, Google SecOps Forwarding). Se você quiser que o firewall atribua automaticamente esse perfil a novas regras e zonas de segurança, nomeie-o como default.
  4. Para cada tipo de registro que você quer encaminhar (tráfego, ameaça, envio do WildFire, filtragem de URL, filtragem de dados, túnel, autenticação), configure o seguinte:
    • Clique em Adicionar na seção do tipo de registro relevante.
    • Syslog: selecione o perfil do servidor syslog que você criou (por exemplo, Google SecOps BindPlane).
    • Gravidade do registro: selecione os níveis de gravidade a serem encaminhados (por exemplo, Todos).
  5. Clique em OK para salvar o perfil de encaminhamento de registros.

Aplicar perfil de encaminhamento de registros a políticas de segurança

  1. Acesse Políticas > Segurança.
  2. Selecione as regras de segurança para as quais você quer ativar o encaminhamento de registros.
  3. Clique na regra para editá-la.
  4. Acesse a guia Ações.
  5. No menu Encaminhamento de registros, selecione o perfil de encaminhamento de registros que você criou (por exemplo, Google SecOps Forwarding).
  6. Clique em OK para salvar a configuração da política de segurança.

Configurar as configurações de registro para registros do sistema

  1. Acesse Dispositivo > Configurações de registro.
  2. Para cada tipo de registro (System, Configuration, User-ID, HIP Match, Global Protect, IP-Tag, SCTP) e nível de gravidade, selecione o perfil do servidor syslog que você criou.
  3. Clique em OK para salvar as configurações de registro.

Confirmar as mudanças

  1. Clique em Commit na parte de cima da interface da Web do firewall.
  2. Aguarde a conclusão do commit.
  3. Verifique se os registros estão sendo enviados ao agente do Bindplane conferindo no console do Google SecOps os registros de firewall da Palo Alto Networks recebidos.

Encaminhar registros para o Google SecOps usando o agente do Bindplane

  1. Instale e configure uma máquina virtual Linux.
  2. Instale e configure o agente do Bindplane no Linux para encaminhar registros ao Google SecOps. Para mais informações sobre como instalar e configurar o agente do Bindplane, consulte as instruções de instalação e configuração do agente do Bindplane.

Se você tiver problemas ao criar feeds, entre em contato com o suporte do Google SecOps.

Formatos de registro aceitos

O analisador de firewall da Palo Alto Networks é compatível com registros nos formatos LEEF,CEF e CSV.

Registros de amostra compatíveis

  • LEEF

    <14>Jan 22 02:20:19 device_host LEEF:1.0|Palo Alto Networks|PAN-OS Syslog Integration|10.2.12-h4|Microsoft MSOFFICE(52033)|ReceiveTime=2025/01/22 02:20:18|SerialNumber=01250100xxxx|cat=THREAT|Subtype=wildfire|devTime=Jan 22 2025 08:20:18 GMT|src=198.50.100.1|dst=198.50.100.2|srcPostNAT=198.50.100.3|dstPostNAT=198.50.100.4|RuleName=AZURE-US-NEW-CNF_Inbound_To_Azure-ALLOW|usrName=|SourceUser=|DestinationUser=|Application=smtp-base|VirtualSystem=vsys1|SourceZone=McD-Global-Zone|DestinationZone=Azure-Zone|IngressInterface=ae1.111|EgressInterface=ae2.409|LogForwardingProfile=Default-Traffic-Logging|SessionID=35331795|RepeatCount=1|srcPort=21578|dstPort=25|srcPostNATPort=0|dstPostNATPort=0|Flags=0x2000|proto=tcp|action=allow|Miscellaneous=\"......3...................xls\"|ThreatID=Microsoft MSOFFICE(52033)|URLCategory=malicious|sev=4|Severity=high|Direction=client-to-server|sequence=7462614601465681755|ActionFlags=0x8000000000000000|SourceLocation=198.50.100.1-198.50.100.255|DestinationLocation=United States|ContentType=|PCAP_ID=0|FileDigest=0ea04c99bf188c2e4207f60f92ca7c6f5088c7943ee63f45c50032bbd2bf7ea9|Cloud=demo.com|URLIndex=1|RequestMethod=|FileType=ms-office|Sender=sender@ab.myownpersonaldomain.com|Subject=\"............:.................................................................................-.........(Name)-2025-01-22...............:Y107202501220005, ............:........................, ...............:.........\"|Recipient=abc@demo.myownpersonaldomain.com|ReportID=117022282776|DeviceGroupHierarchyL1=143|DeviceGroupHierarchyL2=144|DeviceGroupHierarchyL3=39|DeviceGroupHierarchyL4=0|vSrcName=|DeviceName=device_host|SrcUUID=|DstUUID=|TunnelID=0|MonitorTag=|ParentSessionID=0|ParentStartTime=|TunnelType=N/A|ThreatCategory=N/A|ContentVer=WildFire-0
    
  • CEF

    14>1 2024-04-04T16:21:56+02:00 FW-PERIMETRAL-AVG-01 - - - - CEF:0|Palo Alto Networks|PAN-OS|10.1.10-h2|end|TRAFFIC|1|src=198.51.100.1 dst=198.51.100.2 srcTranslatedAddress=198.51.100.3 dstTranslatedAddress=198.51.100.4 rule=FW_USER_NATS2_APP suser= duser= app=bittorrent vs=vsys1 sz=INSIDE dz=EXTERNAL InboundInterface=ae2.2266 OutboundInterface=ae1 lp=log_forwarding sid=2935823 cnt=1 spt=6881 dpt=51413 srcTranslatedPort=0 dstTranslatedPort=0 flags=0x7a proto=udp act=allow tbytes=475 in=150 out=325 pkt=2 pktReceived=1 pktSent=1 start=Apr 04 2024 14:21:56 GMT stime=1206 urlcat=any externalId=externalId reason=aged-out DGl1=11 DGl2=161 DGl3=0 DGl4=0 VsysName=STONESOFT dvchost=FW-PERIMETRAL-AVG-01 cat=from-policy ActionFlags=0x8000000000000000 srcUUID= dstUUID= TunnelID=0 MonitorTag= ParentSessionID=0 ParentStartTime= TunnelType=N/A SCTPAssocID=0 SCTPChunks=0 SCTPChunkSent=0 SCTPChunksRcv=0 RuleUUID=746c3eb6-3d51-4679-8438-bd0e00e170a8 HTTP2Con=0 LinkChange=0 PolicyID= LinkDetail= SDWANCluster= SDWANDevice= SDWANClustype= SDWANSite= DynamicUsrgrp= XFFIP= srcDevCat= srcDevProf= srcDevModel= srcDevVendor= srcDevOS= srcDevOSv= srcHostname= srcMac= dstDevCat= dstDevProf= dstDevModel= dstDevVendor= dstDevOS= dstDevOSv= dstHostname= dstMac= ContainerName= PODNamespace= PODName= srcEDL= dstEDL= GPHostID= EPSerial= srcDAG= dstDAG= HASessionOwner= TimeHighRes=2024-04-04T16:21:56.250+02:00 ASServiceType= ASServiceDiff="
    
  • CSV

    1,2021/10/24 15:30:07,,CONFIG,0,2561,2021/10/24 15:30:07,198.51.100.0,,set,admin,Web,Succeeded, network virtual-router  VR1,,VR1  { ecmp { algorithm { ip-modulo ; } } protocol { bgp { routing-options { graceful-restart { enable yes; } } enable no; } rip { enable no; } ospf { enable no; } ospfv3 { enable no; } } routing-table { ip { static-route { vr1-log  { path-monitor { enable no; failure-condition any; hold-time 2; } nexthop { ip-address 198.51.100.0; } bfd { profile None; } interface ethernet1/1; metric 10; destination 0.0.0.0/0; route-table { unicast ; } } } } } interface [ ethernet1/1 ethernet1/2 ]; } ,7022390503849066572,0x0,0,0,0,0,,PA-VM,0,
    

Referência de mapeamento de campos: campos de registros para campos da UDM

Esta seção explica como o analisador mapeia os campos de registro do firewall da Palo Alto Networks para os campos de eventos do UDM do Google SecOps em cada tipo de registro. A chave de rótulo do Google SecOps se refere ao nome da chave mapeada para o campo UDM "Labels.key".

Por exemplo, no caso do campo "Sistema virtual", o nome do campo é "cs3" no formato CEF e "VirtualSystem" no formato LEEF. O campo da UDM "about.labels.key" contém o valor "vsys", e o campo "about.labels.value" contém o valor desse campo. Alguns nomes de campos CEF ou LEEF não têm um nome correspondente aos nomes de campos CSV. Nesses casos, se você adicionar seu próprio nome de variável no formato de registro personalizado no perfil do syslog, o analisador não vai mapeá-lo para o campo do UDM.

Consulte as seções a seguir para ver a referência de mapeamento de cada tipo de registro:

Sistema

A tabela a seguir lista os campos de registro do tipo de registro do sistema e os campos correspondentes da UDM.

Campo CSV Campo CEF Campo LEEF Chave do rótulo do Google Security Operations Campo do UDM
Horário de recebimento (receive_time ou cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Número de série (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Type (tipo) type (Header) gato metadata.product_event_type está definido como "%{type} - %{subtype}".
Tipo de ameaça/conteúdo (subtipo) subtype (cabeçalho) Subtipo metadata.product_event_type está definido como "%{type} - %{subtype}".
Horário gerado (time_generated ou cef-formatted-time_generated) metadata.event_timestamp
Sistema virtual (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
ID do evento (eventid) gato eventid additional.fields.key e additional.fields.value.string_value
Objeto (objeto) fname Nome do arquivo objeto target.resource.name
Módulo (módulo) flexString2 Módulo module additional.fields.key e additional.fields.value.string_value
Gravidade (severity) $number-of-severity(header) Gravidade security_result.severity e security_result.severity_details
Descrição (opaca) msg msg metadata.description
principal_user_userid (extraído do campo "msg") principal.user.userid
principal_ip3 (extraído do campo "msg") principal.ip
Motivo (este campo é extraído do campo "msg") security_result.description
server_address (este campo é extraído do campo "msg"). target.ip
server_profile (esse campo é extraído do campo "msg") additional.fields.key e additional.fields.value.string_value
Número de sequência (seqno) externalId sequência metadata.product_log_id
Flags de ação (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Hierarquia de grupos de dispositivos (dg_hier_level_1 a dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Hierarquia de grupos de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Hierarquia de grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
Nome do dispositivo (device_name) dvchost DeviceName target.hostname
Carimbo de data/hora de alta resolução (high_res_timestamp) anOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value

Configuração

A tabela a seguir lista os campos de registro do tipo de registro de configuração e os campos da UDM correspondentes.

Campo CSV Campo CEF Campo LEEF Chave do rótulo do Google Security Operations Campo do UDM
Horário de recebimento (receive_time ou cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Número de série (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Type (tipo) type (Header) gato metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) subtype (cabeçalho) metadata.product_event_type
Horário gerado (time_generated ou cef-formatted-time_generated) metadata.event_timestamp
Host (host) shost src principal.ip/hostname
Sistema virtual (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
Comando (cmd) age msg cmd principal.process.command_line
Administrador (admin) duser usrName principal.user.userid
Cliente (cliente) destinationServiceName cliente principal.application
Resultado (result) ID da assinatura (cabeçalho)(motivo) Resultado security_result.summary
Caminho de configuração (caminho) msg ConfigurationPath principal.process.command_line
Detalhe antes da mudança (before_change_detail) cs1 BeforeChangeDetail before_change_detail target.resource.attribute.labels.key/value
Detalhe após a mudança (after_change_detail) cs2 AfterChangeDetail after_change_detail target.resource.attribute.labels.key/value
Número de sequência (seqno) externalId sequência metadata.product_log_id
Flags de ação (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Hierarquia de grupos de dispositivos (dg_hier_level_1 a dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Hierarquia de grupos de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Hierarquia de grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
Nome do dispositivo (device_name) dvchost DeviceName target.hostname
Grupo de dispositivos (dg_id) PanOSFWDeviceGroup target.asset.attribute.labels.key/value dg_id principal.asset.attribute.labels.key/value
Comentário de auditoria (comment) PanOSPolicyAuditComment comentário additional.fields.key e additional.fields.value.string_value
Carimbo de data/hora de alta resolução (high_res_timestamp) additional.fields.key e additional.fields.value.string_value
Gravidade (severity) number-of-severity(header) security_result.severity e security_result.severity_details

Ameaça/WildFire

A tabela a seguir lista os campos de registro do tipo de registro de ameaça/WildFire e os campos correspondentes da UDM.

Campo CSV Campo CEF Campo LEEF Chave do rótulo do Google Security Operations Campo do UDM
Horário de recebimento (receive_time ou cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Número de série deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Type (tipo) type (Header) gato metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) cat/subtype (cabeçalho) Subtipo metadata.product_event_type
Geração de tempo (time_generated ou cef-formatted-time_generated) metadata.event_timestamp
Endereço de origem (src) src src principal.ip
Endereço de destino (dst) dst dst target.ip
IP de origem NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP de destino NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Nome da regra (regra) cs1 RuleName security_result.rule_name
Usuário de origem (srcuser) suser SourceUser / usrName principal.user.userid
Usuário de destino (dstuser) duser DestinationUser target.user.userid
Aplicativo app Aplicativo target.application
Sistema virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona de origem (de) cs4 SourceZone de

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Zona de destino (para) cs5 DestinationZone a

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de entrada (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de saída (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Ação de registro (logset) cs6 LogForwardingProfile logset additional.fields.key e additional.fields.value.string_value
ID da sessão (sessionid) cn1 SessionID network.session_id
Contagem de repetições (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Porta de origem (sport) spt srcPort principal.port
Porta de destino (dport) dpt dstPort target.port
Porta de origem NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Porta de destino NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Flags (flags) flexString1 Flags flags additional.fields.key e additional.fields.value.string_value
Protocolo IP (proto) proto proto network.ip_protocol
Ação (action) age ação security_result.action_details

security_result.action

URL/nome do arquivo (variados) solicitação Diversos

target.file.names (se o subtipo for "file", "virus", "wildfire-virus" ou "wildfire", o campo "misc" será mapeado para target.file.names)

target.url (se o subtipo for "url", o campo "misc" será mapeado para target.url e target.hostname)

Nome da ameaça/do conteúdo (threatid) gato ThreatID security_result.threat_name
Categoria (category) cs2 URLCategory security_result.category_details
Gravidade (severity) number-of-severity(header) Gravidade security_result.severity e security_result.severity_details
Direção (direction) flexString2 Direção network.direction
Número de sequência (seqno) externalId sequência metadata.product_log_id
Flags de ação (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
País de origem (srcloc) SourceLocation principal.location.country_or_region
País de destino (dstloc) DestinationLocation target.location.country_or_region
Tipo de conteúdo (contenttype) ContentType contenttype additional.fields.key e additional.fields.value.string_value
ID do PCAP (pcap_id) fileId PCAP_ID pcap_id additional.fields.key e additional.fields.value.string_value
Resumo de arquivo (filedigest) fileHash FileDigest target.file.sha1/md5/sha256
Nuvem (nuvem) filePath Cloud nuvem additional.fields.key e additional.fields.value.string_value
Índice de URL (url_idx) URLIndex url_idx additional.fields.key e additional.fields.value.string_value
User agent (user_agent) network.http.user_agent
Tipo de arquivo (filetype) fileType FileType target.file.mime_type
X-Forwarded-For (xff) principal.ip
Referenciador (referer) network.http.referral_url
Remetente (sender) suid Remetente network.email.from
Assunto (subject) msg Assunto network.email.subject
Destinatário (destinatário) duid Destinatário network.email.to
ID do relatório (reportid) oldFileId ReportID reportid additional.fields.key e additional.fields.value.string_value
Hierarquia de grupos de dispositivos (dg_hier_level_1 a dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Hierarquia de grupos de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Hierarquia de grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nome do dispositivo (device_name) dvchost DeviceName intermediary.hostname
UUID da VM de origem (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
UUID da VM de destino (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
Método HTTP (http_method) RequestMethod network.http.method
ID/IMSI do túnel (tunnel_id/imsi) PanOSTunnelID TunnelID tunnel_id/imsi additional.fields.key e additional.fields.value.string_value
Monitorar tag/IMEI (monitortag/imei) PanOSMonitorTag MonitorTag monitortag/imei additional.fields.key e additional.fields.value.string_value
ID da sessão principal (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Horário de início da sessão principal (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key e additional.fields.value.string_value
Tipo de túnel (túnel) PanOSTunnelType TunnelType túnel additional.fields.key e additional.fields.value.string_value
Categoria da ameaça (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
Versão do conteúdo (contentver) PanOSContentVer ContentVer contentver additional.fields.key e additional.fields.value.string_value
ID da associação SCTP (assoc_id) PanOSAssocID assoc_id additional.fields.key e additional.fields.value.string_value
ID do protocolo de payload (ppid) PanOSPPID ppid additional.fields.key e additional.fields.value.string_value
Cabeçalhos HTTP (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
Lista de categorias de URL (url_category_list) PanOSURLCatList url_category_list additional.fields.key e additional.fields.value.string_value
UUID da regra (rule_uuid) PanOSRuleUUID security_result.rule_id
Conexão HTTP/2 (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
Nome do grupo dinâmico de usuários (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Endereço XFF (xff_ip) PanXFFIP principal.ip
Categoria do dispositivo de origem (src_category) PanSrcDeviceCat src_category principal.asset.category
Perfil do dispositivo de origem (src_profile) PanSrcDeviceProf src_profile

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Modelo do dispositivo de origem (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
Fornecedor do dispositivo de origem (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
Família do SO do dispositivo de origem (src_osfamily) PanSrcDeviceOS src_osfamily principal.platform
Versão do SO do dispositivo de origem (src_osversion) PanSrcDeviceOSv principal.platform_version
Nome do host de origem (src_host) PanSrcHostname principal.hostname
Endereço MAC de origem (src_mac) PanSrcMac principal.mac
Categoria do dispositivo de destino (dst_category) PanDstDeviceCat dst_category target.asset.category
Perfil do dispositivo de destino (dst_profile) PanDstDeviceProf dst_profile

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Modelo do dispositivo de destino (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
Fornecedor do dispositivo de destino (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
Família do SO do dispositivo de destino (dst_osfamily) PanDstDeviceOS dst_osfamily target.platform
Versão do SO do dispositivo de destino (dst_osversion) PanDstDeviceOSv target.platform_version
Nome do host de destino (dst_host) PanDstHostname target.hostname
Endereço MAC de destino (dst_mac) PanDstMac target.mac
ID do contêiner (container_id) PanContainerName container_id intermediary.resource.product_object_id
Namespace do POD (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
Nome do POD (pod_name) PanPODName pod_name target.resource.name
Lista dinâmica externa de origem (src_edl) PanSrcEDL src_edl additional.fields.key e additional.fields.value.string_value
Lista dinâmica externa de destino (dst_edl) PanDstEDL dst_edl additional.fields.key e additional.fields.value.string_value
ID do host (hostid) PanGPHostID hostid principal.asset.asset_id
Número de série do dispositivo do usuário (serialnumber) PanEPSerial principal.asset.hardware.serial_number
EDL de domínio (domain_edl) PanDomainEDL domain_edl additional.fields.key e additional.fields.value.string_value
Grupo de endereços dinâmicos de origem (src_dag) PanSrcDAG principal.group.group_display_name
Grupo de endereços dinâmicos de destino (dst_dag) PanDstDAG target.group.group_display_name
Hash parcial (partial_hash) PanPartialHash partial_hash additional.fields.key e additional.fields.value.string_value
Carimbo de data/hora de alta resolução (high_res timestamp) PanTimeHighRes timestamp de alta resolução additional.fields.key e additional.fields.value.string_value
Motivo (reason) PanReasonFilteringAction reason security_result.summary
Justificativa (justification) PanJustification justificativa additional.fields.key e additional.fields.value.string_value
Um tipo de serviço de intervalo (nssai_sst) PanASServiceType nssai_sst additional.fields.key e additional.fields.value.string_value
Subcategoria do aplicativo (subcategory_of_app) subcategory_of_app additional.fields.key e additional.fields.value.string_value
Categoria do aplicativo (category_of_app) category_of_app additional.fields.key e additional.fields.value.string_value
Tecnologia de aplicativos (technology_of_app) technology_of_app additional.fields.key e additional.fields.value.string_value
Risco do aplicativo (risk_of_app) risk_of_app additional.fields.key e additional.fields.value.string_value
Característica do aplicativo (characteristic_of_app) characteristic_of_app additional.fields.key e additional.fields.value.string_value
Contêiner do aplicativo (container_of_app) container_of_app additional.fields.key e additional.fields.value.string_value
SaaS de aplicativo (is_saas_of_app) is_saas_of_app additional.fields.key e additional.fields.value.string_value
Aplicativo em túnel (tunneled_app) additional.fields.key e additional.fields.value.string_value
Tipo de fluxo (flow_type) additional.fields.key e additional.fields.value.string_value
Nome do cluster (cluster_name) intermediary.resource.name
Estado de sanção do aplicativo (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key e additional.fields.value.string_value

Tráfego

A tabela a seguir lista os campos de registro do tipo de registro de tráfego e os campos correspondentes da UDM.

Campo CSV Campo CEF Campo LEEF Chave do rótulo do Google Security Operations Campo do UDM
Horário de recebimento (receive_time ou cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Número de série (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Type (tipo) type (Header) cat/Type metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) subtype (cabeçalho) Subtipo metadata.product_event_type
Horário gerado (time_generated ou cef-formatted-time_generated) start metadata.event_timestamp
Endereço de origem (src) src src principal.ip
Endereço de destino (dst) dst dst target.ip
IP de origem NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP de destino NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Nome da regra (regra) cs1 RuleName security_result.rule_name
Usuário de origem (srcuser) suser SourceUser principal.user.userid
Usuário de destino (dstuser) duser DestinationUser target.user.userid
Aplicativo app Aplicativo target.application
Sistema virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona de origem (de) cs4 SourceZone de

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Zona de destino (para) cs5 DestinationZone a

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de entrada (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de saída (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Ação de registro (logset) cs6 LogForwardingProfile logset additional.fields.key e additional.fields.value.string_value
ID da sessão (sessionid) cn1 SessionID network.session_id
Contagem de repetições (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Porta de origem (sport) spt srcPort principal.port
Porta de destino (dport) dpt dstPort target.port
Porta de origem NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Porta de destino NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Flags (flags) flexString1 Flags flags additional.fields.key e additional.fields.value.string_value
Protocolo IP (proto) proto proto network.ip_protocol
Ação (action) age ação security_result.action_details

security_result.action

Bytes (bytes) flexNumber1 totalBytes bytes additional.fields.key e additional.fields.value.string_value
Bytes enviados (bytes_sent) em srcBytes network.sent_bytes
Bytes recebidos (bytes_received) out dstBytes network.received_bytes
Pacotes (pacotes) cn2 totalPackets pacotes additional.fields.key e additional.fields.value.string_value
Horário de início (start) StartTime start additional.fields.key e additional.fields.value.string_value
Tempo decorrido (decorrido) cn3 ElapsedTime decorrido network.session_duration.seconds
Categoria (category) cs2 URLCategory security_result.category / security_result.category_details
Número de sequência (seqno) externalId sequência metadata.product_log_id
Flags de ação (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
País de origem (srcloc) SourceLocation principal.location.country_or_region
País de destino (dstloc) DestinationLocation target.location.country_or_region
Pacotes enviados (pkts_sent) PanOSPacketsSent srcPackets pkts_sent network.sent_packets
Pacotes recebidos (pkts_received) PanOSPacketsReceived dstPackets pkts_received network.received_packets
Motivo do término da sessão (session_end_reason) reason SessionEndReason security_result.summary
Hierarquia do grupo de dispositivos 1 (dg_hier_level_1 a dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Hierarquia de grupo de dispositivos 2 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Hierarquia de grupo de dispositivos 3 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Hierarquia de grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nome do dispositivo (device_name) dvchost DeviceName intermediary.hostname
Origem da ação (action_source) gato ActionSource action_source additional.fields.key e additional.fields.value.string_value
UUID da VM de origem (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
UUID da VM de destino (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
ID do túnel/IMSI (tunnelid/imsi) PanOSTunnelID TunnelID tunnelid/imsi additional.fields.key e additional.fields.value.string_value
Monitorar tag/IMEI (monitortag/imei) PanOSMonitorTag MonitorTag monitortag/imei additional.fields.key e additional.fields.value.string_value
ID da sessão principal (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Horário de início da atividade principal (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key e additional.fields.value.string_value
Tipo de túnel (túnel) PanOSTunnelType TunnelType túnel additional.fields.key e additional.fields.value.string_value
ID da associação SCTP (assoc_id) PanOSSCTPAssocID assoc_id additional.fields.key e additional.fields.value.string_value
Fragmentos SCTP (fragmentos) PanOSSCTPChunks pedaços additional.fields.key e additional.fields.value.string_value
Fragmentos SCTP enviados (chunks_sent) PanOSSCTPChunkSent chunks_sent additional.fields.key e additional.fields.value.string_value
Blocos SCTP recebidos (chunks_received) PanOSSCTPChunksRcv chunks_received additional.fields.key e additional.fields.value.string_value
UUID da regra (rule_uuid) PanOSRuleUUID security_result.rule_id
Conexão HTTP/2 (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
Contagem de flaps do app (link_change_count) PanLinkChange link_change_count additional.fields.key e additional.fields.value.string_value
ID da política (policy_id) PanPolicyID policy_id additional.fields.key e additional.fields.value.string_value
Chaves de link (link_switches) PanLinkDetail link_switches additional.fields.key e additional.fields.value.string_value
Cluster SD-WAN (sdwan_cluster) PanSDWANCluster sdwan_cluster additional.fields.key e additional.fields.value.string_value
Tipo de dispositivo SD-WAN (sdwan_device_type) PanSDWANDevice sdwan_device_type additional.fields.key e additional.fields.value.string_value
Tipo de cluster SD-WAN (sdwan_cluster_type) PanSDWANClustype sdwan_cluster_type additional.fields.key e additional.fields.value.string_value
Site SD-WAN (sdwan_site) PanSDWANSite sdwan_site additional.fields.key e additional.fields.value.string_value
Nome do grupo dinâmico de usuários (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name additional.fields.key e additional.fields.value.string_value
Endereço XFF (xff_ip) PanXFFIP principal.ip
Categoria do dispositivo de origem (src_category) PanSrcDeviceCat src_category principal.asset.category
Perfil do dispositivo de origem (src_profile) PanSrcDeviceProf src_profile

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Modelo do dispositivo de origem (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
Fornecedor do dispositivo de origem (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
Família do SO do dispositivo de origem (src_osfamily) PanSrcDeviceOS principal.platform
Versão do SO do dispositivo de origem (src_osversion) PanSrcDeviceOSv principal.asset.software.version
Nome do host de origem (src_host) PanSrcHostname principal.hostname
Endereço MAC de origem (src_mac) PanSrcMac principal.mac
Categoria do dispositivo de destino (dst_category) PanDstDeviceCat dst_category target.asset.category
Perfil do dispositivo de destino (dst_profile) PanDstDeviceProf dst_profile

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Modelo do dispositivo de destino (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
Fornecedor do dispositivo de destino (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
Família do SO do dispositivo de destino (dst_osfamily) PanDstDeviceOS dst_osfamily target.platform
Versão do SO do dispositivo de destino (dst_osversion) PanDstDeviceOSv target.platform_version
Nome do host de destino (dst_host) PanDstHostname target.hostname
Endereço MAC de destino (dst_mac) PanDstMac target.mac
ID do contêiner (container_id) PanContainerName container_id intermediary.resource.product_object_id
Namespace do POD (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
Nome do POD (pod_name) PanPODName pod_name target.resource.name
Lista dinâmica externa de origem (src_edl) PanSrcEDL src_edl

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Lista dinâmica externa de destino (dst_edl) PanDstEDL dst_edl

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

ID do host (hostid) PanGPHostID hostid principal.asset.asset_id
Número de série do dispositivo do usuário (serialnumber) PanEPSerial principal.asset.hardware.serial_number
Grupo de endereços dinâmicos de origem (src_dag) PanSrcDAG principal.group.group_display_name
Grupo de endereços dinâmicos de destino (dst_dag) PanDstDAG target.group.group_display_name
Proprietário da sessão (session_owner) PanHASessionOwner session_owner additional.fields.key e additional.fields.value.string_value
Carimbo de data/hora de alta resolução (high_res_timestamp) PanTimeHighRes additional.fields.key e additional.fields.value.string_value
Um tipo de serviço de fração (nsdsai_sst) PanASServiceType nsdsai_sst additional.fields.key e additional.fields.value.string_value
Um diferenciador de fração (nsdsai_sd) PanASServiceDiff nsdsai_sd additional.fields.key e additional.fields.value.string_value
Subcategoria do aplicativo (subcategory_of_app) subcategory_of_app additional.fields.key e additional.fields.value.string_value
Categoria do aplicativo (category_of_app) category_of_app additional.fields.key e additional.fields.value.string_value
Tecnologia de aplicativos (technology_of_app) technology_of_app additional.fields.key e additional.fields.value.string_value
Risco do aplicativo (risk_of_app) security_result.severity
Característica do aplicativo (characteristic_of_app) characteristic_of_app additional.fields.key e additional.fields.value.string_value
Contêiner do aplicativo (container_of_app) container_of_app additional.fields.key e additional.fields.value.string_value
SaaS de aplicativo (is_saas_of_app) is_saas_of_app additional.fields.key e additional.fields.value.string_value
Estado de sanção do aplicativo (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key e additional.fields.value.string_value
Subcategoria do aplicativo (subcategory_of_app) subcategory_of_app1 additional.fields.key e additional.fields.value.string_value
Gravidade (severity) number-of-severity(header) security_result.severity e security_result.severity_details

User-ID

A tabela a seguir lista os campos de registro do tipo de registro user-id e os campos correspondentes da UDM.

Campo CSV Campo CEF Campo LEEF Chave do rótulo do Google Security Operations Campo do UDM
Horário de recebimento (receive_time ou cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Número de série (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Type (tipo) type (Header) gato metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) subtype (cabeçalho) Subtipo metadata.product_event_type
Horário gerado (time_generated ou cef-formatted-time_generated) metadata.event_timestamp
Sistema virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
IP de origem (ip) src src principal.ip
Usuário (user) duser usrName target.user.userid

target.administrative_domain

target.user.email_addresses

Nome da fonte de dados (datasourcename) cs4 DataSourceName datasourcename

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

ID do evento (eventid) EventID eventid additional.fields.key e additional.fields.value.string_value
Contagem de repetições (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Limite de tempo limite cn3 TimeoutThreshold timeout additional.fields.key e additional.fields.value.string_value
Porta de origem (beginport) spt srcPort principal.port
Porta de destino (endport) dpt dstPort target.port
Fonte de dados cs5 DataSource fonte de dados

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Tipo de fonte de dados (datasourcetype) cs6 DataSourceType datasourcetype

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Número de sequência (seqno) externalId sequência metadata.product_log_id
Flags de ação (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Hierarquia de grupos de dispositivos (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Hierarquia de grupos de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Hierarquia de grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nome do dispositivo (device_name) dvchost DeviceName intermediary.hostname
ID do sistema virtual (vsys_id) cn2 VirtualSystemID intermediary.resource.product_object_id
Tipo de fator (factortype) cs1 FactorType factortype additional.fields.key e additional.fields.value.string_value
Tempo de conclusão do fator (factorcompletiontime) end FactorCompletionTime factorcompletiontime additional.fields.key e additional.fields.value.string_value
Número do fator (factorno) cn1 FactorNumber factorno additional.fields.key e additional.fields.value.string_value
Flags de grupo de usuários (ugflags) PanOSUGFlags ugflags additional.fields.key e additional.fields.value.string_value
Usuário por origem (userbysource) PanOSUserBySource target.user.userid

target.administrative_domain

target.user.email_addresses

Carimbo de data/hora de alta resolução (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value
Fonte de dados de origem (origindatasource) additional.fields.key e additional.fields.value.string_value
Nome do cluster (cluster_name) principal.resource.name
Gravidade (severity) number-of-severity(header) security_result.severity e security_result.severity_details

Correspondência de HIP

A tabela a seguir lista os campos de registro do tipo de registro de correspondência do HIP e os campos correspondentes da UDM.

Campo CSV Campo CEF Campo LEEF Chave do rótulo do Google Security Operations Campo do UDM
Horário de recebimento (receive_time ou cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Número de série (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Type (tipo) type (Header) gato metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) subtype (cabeçalho) Subtipo
Horário gerado (time_generated ou cef-formatted-time_generated) start startTime metadata.event_timestamp
Usuário de origem (srcuser) suser usrName principal.user.userid
Sistema virtual (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
Nome da máquina (machinename) shost identHostName principal.hostname
Sistema operacional (os) cs2 SO principal.asset.platform_software.platform
Endereço de origem (src) src identsrc principal.ip
HIP (matchname) gato HIP matchname

target.resource.attribute.labels.key/value

additional.fields.key e additional.fields.value.string_value

Contagem de repetições (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Tipo de HIP (matchtype) ID da classe de evento do dispositivo (cabeçalho) HIPType matchtype

target.resource.attribute.labels.key/value

additional.fields.key e additional.fields.value.string_value

Número de sequência (seqno) externalId sequência metadata.product_log_id
Flags de ação (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Hierarquia de grupos de dispositivos (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Hierarquia de grupos de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Hierarquia de grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
Nome do dispositivo (device_name) dvchost DeviceName target.hostname
ID do sistema virtual (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
Endereço IPv6 do sistema (srcipv6) c6a2 srcipv6 principal.asset.ip
ID do host (hostid) PanOSHostID principal.asset.asset_id
Número de série do dispositivo do usuário (serialnumber) PanOSEndpointSerialNumber principal.asset.hardware.serial_number
Endereço MAC do dispositivo (mac) PanOSEndpointMac principal.asset.mac
Carimbo de data/hora de alta resolução (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value
Nome do cluster (cluster_name) principal.resource.name
Gravidade (severity) number-of-severity(header) security_result.severity e security_result.severity_details

Tag de IP

A tabela a seguir lista os campos de registro do tipo de registro de tag de IP e os campos correspondentes da UDM.

Campo CSV Campo CEF Campo LEEF Chave do rótulo do Google Security Operations Campo do UDM
Horário de recebimento (receive_time ou cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Número de série (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Type (tipo) type (Header) gato metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) subtype (cabeçalho) Subtipo metadata.product_event_type
Horário gerado (time_generated ou cef-formatted-time_generated) GenerateTime metadata.event_timestamp
Sistema virtual (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
IP de origem (ip) src src principal.ip
Nome da tag (tag_name) PanOSTagName TagName tag_name

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

ID do evento (event_id) PanOSEventID EventID event_id additional.fields.key e additional.fields.value.string_value
Contagem de repetições (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Tempo limite (timeout) PanOSTimeout TimeoutThreshold timeout additional.fields.key e additional.fields.value.string_value
Nome da fonte de dados (datasourcename) PanOSDataSourceName DataSourceName datasourcename

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Tipo de fonte de dados (datasource_type) PanOSDataSourceType DataSource datasource_type

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Subtipo da fonte de dados (datasource_subtype) PanOSDataSourceSubType DataSourceType datasource_subtype

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Número de sequência (seqno) externalId sequência metadata.product_log_id
Flags de ação (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Hierarquia de grupos de dispositivos (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Hierarquia de grupos de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Hierarquia de grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) PanOsVsysName vSrcName target.asset.attribute.labels.key/value
Nome do dispositivo (device_name) dvchost DeviceName target.hostname
ID do sistema virtual (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
Carimbo de data/hora de alta resolução (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value
Gravidade (severity) number-of-severity(header) security_result.severity e security_result.severity_details
Nome do cluster (cluster_name) principal.resource.name

Descriptografia

A tabela a seguir lista os campos de registro do tipo de registro de descriptografia e os campos correspondentes da UDM.

Campo CSV Campo CEF Campo LEEF Chave do rótulo do Google Security Operations Campo do UDM
Horário de recebimento (receive_time ou cef-formatted-receive_time) rt metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Número de série (serial) PanOSDeviceSN intermediary.asset.hardware.serial_number
Type (tipo) type (Header) metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) subtype (cabeçalho) metadata.product_event_type
Versão da configuração (config_ver) PanOSConfigVersion config_ver additional.fields.key e additional.fields.value.string_value
Horário de geração (time_generated) PanOSLogTimeStamp metadata.event_timestamp
Endereço de origem (src) src principal.ip
Endereço de destino (dst) dst target.ip
IP de origem NAT (natsrc) sourceTranslatedAddress principa.nat_ip
IP de destino NAT (natdst) destinationTranslatedAddress target.nat_ip
Rule (regra) cs1 security_result.rule_name
Usuário de origem (srcuser) suser principal.user.userid
Usuário de destino (dstuser) duser target.user.userid
Aplicativo app network.application_protocol
Sistema virtual (vsys) cs3 vsys intermediary.asset.attribute.labels.key/value
Zona de origem (de) cs4 de

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Zona de destino (para) cs5 a

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de entrada (inbound_if) deviceInboundInterface inbound_if

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de saída (outbound_if) deviceOutboundInterface outbound_if

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Ação de registro (logset) cs6 logset additional.fields.key e additional.fields.value.string_value
Horário registrado (time_received) PanOSTimeReceivedManagementPlane -
ID da sessão (sessionid) cn1 network.session_id
Contagem de repetições (repeatcnt) PanOSCountOfRepeats/RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Porta de origem (sport) spt principal.port
Porta de destino (dport) dpt target.port
Porta de origem NAT (natsport) sourceTranslatedPort principal.nat_port
Porta de destino NAT (natdport) destinationTranslatedPort target.nat_port
Flags (flags) flexString1 flags additional.fields.key e additional.fields.value.string_value
Protocolo IP (proto) proto network.ip_protocol
Ação (action) age security_result.action_details

security_result.action

Túnel (tunnel) PanOSTunnel túnel additional.fields.key e additional.fields.value.string_value
UUID da VM de origem (src_uuid) PanOSSourceUUID principal.asset.product_object_id
UUID da VM de destino (dst_uuid) PanOSDestinationUUID target.asset.product_object_id
UUID da regra (rule_uuid) PanOSRuleUUID security_result.rule_id
Estágio de cliente para firewall (hs_stage_c2f) PanOSClientToFirewall hs_stage_c2f additional.fields.key e additional.fields.value.string_value
Estágio para firewall para servidor (hs_stage_f2s) PanOSFirewallToServer hs_stage_f2s additional.fields.key e additional.fields.value.string_value
Versão do TLS (tls_version) PanOSTLSVersion network.tls.version
Algoritmo de troca de chaves (tls_keyxchg) PanOSTLSKeyExchange tls_keyxchg additional.fields.key e additional.fields.value.string_value
Algoritmo de criptografia (tls_enc) PanOSTLSEncryptionAlgorithm tls_enc additional.fields.key e additional.fields.value.string_value
Algoritmo de hash (tls_auth) PanOSTLSAuth tls_auth additional.fields.key e additional.fields.value.string_value
Nome da política (policy_name) PanOSPolicyName policy_name additional.fields.key e additional.fields.value.string_value
Curva elíptica (ec_curve) PanOSEllipticCurve network.tls.curve
Índice de erro (err_index) PanOSErrorIndex err_index additional.fields.key e additional.fields.value.string_value
Status da raiz (root_status) PanOSRootStatus root_status additional.fields.key e additional.fields.value.string_value
Status da cadeia (chain_status) PanOSChainStatus chain_status additional.fields.key e additional.fields.value.string_value
Tipo de proxy (proxy_type) PanOSProxyType proxy_type additional.fields.key e additional.fields.value.string_value
Número de série do certificado (cert_serial) PanOSCertificateSerial network.tls.server.certificate.serial
Impressão digital do certificado (impressão digital) PanOSFingerprint network.tls.server.certificate.md5/sha1/sha256
Data de início do certificado (notbefore) PanOSTimeNotBefore network.tls.server.certificate.not_before
Data de término do certificado (notafter) PanOSTimeNotAfter network.tls.server.certificate.not_after
Versão do certificado (cert_ver) PanOSCertificateVersion network.tls.server.certificate.version
Tamanho do certificado (cert_size) PanOSCertificateSize cert_size additional.fields.key e additional.fields.value.string_value
Comprimento do nome comum (cn_len) PanOSCommonNameLength cn_len additional.fields.key e additional.fields.value.string_value
Comprimento do nome comum do emissor (issuer_len) PanOSIssuerNameLength issuer_len additional.fields.key e additional.fields.value.string_value
Comprimento do nome comum da raiz (rootcn_len) PanOSRootCNLength rootcn_len additional.fields.key e additional.fields.value.string_value
Comprimento do SNI (sni_len) PanOSSNILength sni_len additional.fields.key e additional.fields.value.string_value
Flags de certificado (cert_flags) PanOSCertificateFlags cert_flags additional.fields.key e additional.fields.value.string_value
Nome comum do assunto (cn) PanOSCommonName cn additional.fields.key e additional.fields.value.string_value
Nome comum do emissor (issuer_cn) PanOSIssuerCommonName network.tls.server.certificate.issuer
Nome comum da raiz (root_cn) PanOSRootCommonName root_cn additional.fields.key e additional.fields.value.string_value
Indicação de nome do servidor

(sni)

network.tls.client.server_name
Erro (erro) PanOSErrorMessage erro additional.fields.key e additional.fields.value.string_value
ID do contêiner (container_id) PanOSContainerID container_id intermediary.resource.product_object_id
Namespace do POD (pod_namespace) PanOSContainerNameSpace pod_namespace

target.resource.attribute.labels.key/value

additional.fields.key e additional.fields.value.string_value

Nome do POD (pod_name) PanOSContainerName pod_name target.resource.name
Lista dinâmica externa de origem (src_edl) PanOSSourceEDL src_edl

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Lista dinâmica externa de destino (dst_edl) PanOSDestinationEDL dst_edl

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Grupo de endereços dinâmicos de origem (src_dag) PanOSSourceDynamicAddressGroup principal.group.group_display_name
Grupo de endereços dinâmicos de destino (dst_dag) PanOSDestinationDynamicAddressGroup target.group.group_display_name
Carimbo de data/hora de alta resolução (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value
Categoria do dispositivo de origem (src_category) PanOSSourceDeviceCategory src_category principal.asset.category
Perfil do dispositivo de origem (src_profile) PanOSSourceDeviceProfile src_profile

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Modelo do dispositivo de origem (src_model) PanOSSourceDeviceModel src_model principal.asset.hardware.model
Fornecedor do dispositivo de origem (src_vendor) PanOSSourceDeviceVendor src_vendor principal.asset.hardware.manufacturer
Família do SO do dispositivo de origem (src_osfamily) PanOSSourceDeviceOSFamily principal.platform
Versão do SO do dispositivo de origem (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
Nome do host de origem (src_host) PanOSSourceDeviceHost principal.hostname
Endereço MAC de origem (src_mac) PanOSSourceDeviceMac principal.mac
Categoria do dispositivo de destino (dst_category) PanOSDestinationDeviceCategory dst_category target.asset.category
Perfil do dispositivo de destino (dst_profile) PanOSDestinationDeviceProfile dst_profile

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Modelo do dispositivo de destino (dst_model) PanOSDestinationDeviceModel dst_model target.asset.hardware.model
Fornecedor do dispositivo de destino (dst_vendor) PanOSDestinationDeviceVendor dst_vendor target.asset.hardware.manufacturer
Família do SO do dispositivo de destino (dst_osfamily) PanOSDestinationDeviceOSFamily dst_osfamily target.platform
Versão do SO do dispositivo de destino (dst_osversion) PanOSDestinationDeviceOSVersion target.platform_version
Nome do host de destino (dst_host) PanOSDestinationDeviceHost target.hostname
Endereço MAC de destino (dst_mac) PanOSDestinationDeviceMac target.mac
Número de sequência (seqno) PanOSLogTypeSeqNo metadata.product_log_id
Flags de ação (actionflags) PanOSActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Hierarquia de grupos de dispositivos (dg_hier_level_1) DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_2) DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Hierarquia de grupos de dispositivos (dg_hier_level_3) DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Hierarquia de grupo de dispositivos (dg_hier_level_4) DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) intermediary.asset.attribute.labels.key/value
Nome do dispositivo (device_name) intermediary.hostname
ID do sistema virtual (vsys_id) intermediary.resource.product_object_id
Subcategoria do aplicativo (subcategory_of_app) subcategory_of_app additional.fields.key e additional.fields.value.string_value
Categoria do aplicativo (category_of_app) category_of_app additional.fields.key e additional.fields.value.string_value
Tecnologia de aplicativos (technology_of_app) technology_of_app additional.fields.key e additional.fields.value.string_value
Risco do aplicativo (risk_of_app) security_result.severity
Característica do aplicativo (characteristic_of_app) characteristic_of_app additional.fields.key e additional.fields.value.string_value
Contêiner do aplicativo (container_of_app) container_of_app additional.fields.key e additional.fields.value.string_value
SaaS de aplicativo (is_saas_of_app) is_saas_of_app additional.fields.key e additional.fields.value.string_value
Estado de sanção do aplicativo (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key e additional.fields.value.string_value
Gravidade (severity) number-of-severity(header) security_result.severity e security_result.severity_details

Túnel

A tabela a seguir lista os campos de registro do tipo de registro de túnel e os campos correspondentes da UDM.

Campo CSV Campo CEF Campo LEEF Chave do rótulo do Google Security Operations Campo do UDM
Horário de recebimento (receive_time ou cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Número de série (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Type (tipo) type (Header) gato metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) subtype (cabeçalho) Subtipo metadata.product_event_type
Horário gerado (time_generated ou cef-formatted-time_generated) metadata.event_timestamp
Endereço de origem (src) src src principal.ip
Endereço de destino (dst) dst dst target.ip
IP de origem NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP de destino NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Nome da regra (regra) cs1 RuleName security_result.rule_name
Usuário de origem (srcuser) suser SourceUser / usrName principal.user.userid
Usuário de destino (dstuser) duser DestinationUser target.user.userid
Aplicativo app Aplicativo network.application_protocol
Sistema virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona de origem (de) cs4 SourceZone de

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Zona de destino (para) cs5 DestinationZone a

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de entrada (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de saída (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Ação de registro (logset) cs6 LogForwardingProfile logset additional.fields.key e additional.fields.value.string_value
ID da sessão (sessionid) cn1 SessionID network.session_id
Contagem de repetições (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Porta de origem (sport) spt srcPort principal.port
Porta de destino (dport) dpt dstPort target.port
Porta de origem NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Porta de destino NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Flags (flags) flexString1 Flags flags additional.fields.key e additional.fields.value.string_value
Protocolo IP (proto) proto proto network.ip_protocol
Ação (action) age ação security_result.action_details

security_result.action

Gravidade (severity) number-of-severity(header) security_result.severity e security_result.severity_details
Número de sequência (seqno) externalId sequência metadata.product_log_id
Flags de ação (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Local de origem (srcloc) principal.location.country_or_region
Local de destino (dstloc) target.location.country_or_region
Hierarquia de grupos de dispositivos (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Hierarquia de grupos de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Hierarquia de grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nome do dispositivo (device_name) dvchost DeviceName intermediary.hostname
ID do túnel (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key e additional.fields.value.string_value
Tag de monitoramento (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key e additional.fields.value.string_value
ID da sessão principal (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Horário de início da atividade principal (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key e additional.fields.value.string_value
Tipo de túnel (túnel) cs2 TunnelType túnel additional.fields.key e additional.fields.value.string_value
Bytes (bytes) flexNumber1 totalBytes bytes additional.fields.key e additional.fields.value.string_value
Bytes enviados (bytes_sent) em srcBytes network.sent_bytes
Bytes recebidos (bytes_received) out dstBytes network.received_bytes
Pacotes (pacotes) cn2 totalPackets pacotes additional.fields.key e additional.fields.value.string_value
Pacotes enviados (pkts_sent) PanOSPacketsSent srcPackets pkts_sent network.sent_packets
Pacotes recebidos (pkts_received) PanOSPacketsReceived dstPackets pkts_received network.received_packets
Encapsulamento máximo (max_encap) flexNumber2 MaximumEncapsulation max_encap additional.fields.key e additional.fields.value.string_value
Protocolo desconhecido (unknown_proto) cfp1 UnknownProtocol unknown_proto additional.fields.key e additional.fields.value.string_value
Verificação estrita (strict_check) cfp2 StrictChecking strict_check additional.fields.key e additional.fields.value.string_value
Fragmento de túnel (tunnel_fragment) PanOSTunnelFragment TunnelFragment tunnel_fragment additional.fields.key e additional.fields.value.string_value
Sessões criadas (sessions_created) cfp3 SessionsCreated sessions_created additional.fields.key e additional.fields.value.string_value
Sessões encerradas (sessions_closed) cfp4 SessionsClosed sessions_closed additional.fields.key e additional.fields.value.string_value
Motivo do término da sessão (session_end_reason) reason SessionEndReason security_result.summary
Origem da ação (action_source) gato ActionSource action_source additional.fields.key e additional.fields.value.string_value
Horário de início (start) startTime start additional.fields.key e additional.fields.value.string_value
Tempo decorrido (decorrido) cn3 ElapsedTime decorrido network.session_duration.seconds
Regra de inspeção de túnel (tunnel_insp_rule) PanOSTunneInspectionRule security_result.rule_name = "Tunnel Inspection Rule: %{PanOSTunnelInspectionRule}"
IP do usuário remoto (remote_user_ip) PanOSRmtUserIP principal.ip
ID do usuário remoto (remote_user_id) PanOSRmtUserID remote_user_id principal.user.userid
UUID da regra de segurança (rule_uuid) PanOSRuleUUID security_result.rule_id
ID do PCAP (pcap_id) PanOSPcapID pcap_id additional.fields.key e additional.fields.value.string_value
Nome do grupo dinâmico de usuários (dynusergroup_name) PanDynamicUsrgrp principal.group.group_display_name
Lista dinâmica externa de origem (src_edl) PanOSSourceEDL src_edl

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Lista dinâmica externa de destino (dst_edl) PanOSDestinationEDL dst_edl

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Carimbo de data/hora de alta resolução (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value
Um diferenciador de fração (nssai_sd) nssai_sd additional.fields.key e additional.fields.value.string_value
Um tipo de serviço de fatia (nssai_sd) nssai_sd1 additional.fields.key e additional.fields.value.string_value
ID da sessão do PDU (pdu_session_id) pdu_session_id additional.fields.key e additional.fields.value.string_value
Subcategoria do aplicativo (subcategory_of_app) subcategory_of_app additional.fields.key e additional.fields.value.string_value
Categoria do aplicativo (category_of_app) category_of_app additional.fields.key e additional.fields.value.string_value
Tecnologia de aplicativos (technology_of_app) technology_of_app additional.fields.key e additional.fields.value.string_value
Risco do aplicativo (risk_of_app) risk_of_app additional.fields.key e additional.fields.value.string_value
Característica do aplicativo (characteristic_of_app) characteristic_of_app additional.fields.key e additional.fields.value.string_value
Contêiner do aplicativo (container_of_app) container_of_app additional.fields.key e additional.fields.value.string_value
SaaS de aplicativo (is_saas_of_app) is_saas_of_app additional.fields.key e additional.fields.value.string_value
Aplicativo em túnel (tunneled_app) additional.fields.key e additional.fields.value.string_value
Descarregada (offloaded) additional.fields.key e additional.fields.value.string_value
Tipo de fluxo (flow_type) additional.fields.key e additional.fields.value.string_value
Nome do cluster (cluster_name)

principal.resource.name

Estado de sanção do aplicativo (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key e additional.fields.value.string_value

Autenticação

A tabela a seguir lista os campos de registro do tipo de registro de autenticação e os campos correspondentes da UDM.

Campo CSV Campo CEF Campo LEEF Chave do rótulo do Google Security Operations Campo do UDM
Horário de recebimento (receive_time ou cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Número de série (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Type (tipo) type (Header) gato metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) subtype (cabeçalho) Subtipo metadata.product_event_type
Horário gerado (time_generated ou cef-formatted-time_generated) metadata.event_timestamp
Sistema virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
IP de origem (ip) src src principal.ip
Usuário (user) duser usrName target.user.userid
Normalizar usuário (normalize_user) cs2 NormalizeUser target.user.user_display_name
Objeto (objeto) fname ObjectName objeto target.resource.name
Política de autenticação (authpolicy) cs4 AuthPolicy authpolicy additional.fields.key e additional.fields.value.string_value
Contagem de repetições (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
ID de autenticação (authid) cn2 AuthenticationID authid additional.fields.key e additional.fields.value.string_value
Fornecedor (vendor) flexString2 Fornecedor fornecedor additional.fields.key e additional.fields.value.string_value
Ação de registro (logset) cs6 LogForwardingProfile logset additional.fields.key e additional.fields.value.string_value
Perfil do servidor (serverprofile) cs1 ServerProfile serverprofile additional.fields.key e additional.fields.value.string_value
Descrição (decresc.) PanOSDesc AdditionalAuthInfo security_result.description
Tipo de cliente (clienttype) cs5 ClientType clienttype additional.fields.key e additional.fields.value.string_value
Tipo de evento (event) msg msg extensions.auth.auth_details
Número do fator (factorno) cn1 FactorNumber factorno additional.fields.key e additional.fields.value.string_value
Número de sequência (seqno) externalId sequência metadata.product_log_id
Flags de ação (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Hierarquia de grupos de dispositivos (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Hierarquia de grupos de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Hierarquia de grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nome do dispositivo (device_name) dvchost DeviceName intermediary.hostname
ID do sistema virtual (vsys_id) intermediary.resource.product_object_id
Protocolo de autenticação (authproto) authproto additional.fields.key e additional.fields.value.string_value
UUID da regra (rule_uuid) PanOSRuleUUID/RuleUUID security_result.rule_id
Carimbo de data/hora de alta resolução (high_res _timestamp) PanOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value
Categoria do dispositivo de origem (src_category) PanOSSourceDeviceCategory src_category principal.asset.category
Perfil do dispositivo de origem (src_profile) PanOSSourceDeviceProfile src_profile

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Modelo do dispositivo de origem (src_model) PanOSSourceDeviceModel src_model principal.asset.hardware.model
Fornecedor do dispositivo de origem (src_vendor) PanOSSourceDeviceVendor src_vendor principal.asset.hardware.manufacturer
Família do SO do dispositivo de origem (src_osfamily) PanOSSourceDeviceOSFamily

principal.asset.platform_software.platform

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Versão do SO do dispositivo de origem (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
Nome do host de origem (src_host) PanOSSourceHostname principal.hostname
Endereço MAC de origem (src_mac) PanOSSourceMac principal.asset.mac
Região (região) PanOSTrafficOriginRegion principal.location.country_or_region
User agent (user_agent) PanOSHTTPUserAgent network.http.user_agent
ID da sessão(sessionid) PanOSTrafficSessionID network.session_id
Gravidade (severity) number-of-severity(header) security_result.severity e security_result.severity_details
Nome do cluster (cluster_name) principal.resource.name

URL

A tabela a seguir lista os campos de registro do tipo de registro de URL e os campos correspondentes da UDM.

Campo CSV Campo CEF Campo LEEF Chave do rótulo do Google Security Operations Campo do UDM
Horário de recebimento (cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Nº de série (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Type (tipo) type (Header) gato metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) subtype (cabeçalho) Subtipo metadata.product_event_type
Horário de geração metadata.event_timestamp
Endereço de origem (src) src src principal.ip
Endereço de destino (dst) dst dst target.ip
IP de origem NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP de destino NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Rule (regra) cs1 RuleName security_result.rule_name
Usuário de origem (srcuser) suser SourceUser principal.user.userid
Usuário de destino (dstuser) duser DestinationUser target.user.userid
Aplicativo app Aplicativo network.application_protocol
Sistema virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona de origem (de) cs4 SourceZone de

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Zona de destino (para) cs5 DestinationZone a

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de entrada (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de saída (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Ação de registro (logset) cs6 LogForwardingProfile logset additional.fields.key e additional.fields.value.string_value
Horário registrado time_logged additional.fields.key e additional.fields.value.string_value
ID da sessão (sessionid) cn1 SessionID network.session_id
Contagem de repetições (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Porta de origem (sport) spt srcPort principal.port
Porta de destino (dport) dpt dstPort target.port
Porta de origem NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Porta de destino NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Flags (flags) flexString1 Flags flags additional.fields.key e additional.fields.value.string_value
Protocolo IP (proto) proto proto network.ip_protocol
Ação (action) age ação security_result.action_details

security_result.action

URL/nome do arquivo (variados) Diversos target.file.names

target.url

Nome da ameaça/do conteúdo (threatid) gato ThreatID security_result.threat_id
Categoria (category) cs2 URLCategory categoria security_result.category_details
Gravidade (severity) number-of-severity (cabeçalho) Gravidade security_result.severity

security_result.severity_details

Direção (direction) flexString2 Direção network.direction
Número de sequência (seqno) externalId sequência metadata.product_log_id
Flags de ação (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
País de origem (srcloc) SourceLocation principal.location.country_or_region
País de destino (dstloc) DestinationLocation target.location.country_or_region
contenttype (contenttype) requestContext ContentType contenttype additional.fields.key e additional.fields.value.string_value
pcap_id (pcap_id) fileId PCAP_ID pcap_id additional.fields.key e additional.fields.value.string_value
filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
nuvem (cloud) Cloud nuvem additional.fields.key e additional.fields.value.string_value
url_idx (url_idx) URLIndex url_idx additional.fields.key e additional.fields.value.string_value
user_agent (user_agent) requestClientApplication UserAgent network.http.user_agent
filetype (filetype) target.file.mime_type
xff (xff) PanOSXForwarderfor identSrc xff principal.ip
Referenciador (referer) PanOSReferer Referenciador network.http.referral_url
sender (sender) network.email.from
assunto (assunto) Assunto network.email.subject
destinatário (recipient) network.email.to
reportid (reportid) reportid additional.fields.key e additional.fields.value.string_value
Nível 1 da hierarquia de DG (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Nível 2 da hierarquia de DG (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Nível 3 da hierarquia de DG (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Nível 4 da hierarquia de DG (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nome do dispositivo (device_name) dvchost DeviceName intermediary.hostname
file_url (file_url) target.url
UUID da VM de origem (src_uuid) SrcUUID principal.asset.product_object_id
UUID da VM de destino (dst_uuid) DstUUID target.asset.product_object_id
http_method (http_method) requestMethod RequestMethod network.http.method
ID do túnel/IMSI (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key e additional.fields.value.string_value
Monitorar tag/IMEI (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key e additional.fields.value.string_value
ID da sessão principal (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Horário de início da sessão principal (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key e additional.fields.value.string_value
Túnel (tunnel) PanOSTunnelType TunnelType túnel additional.fields.key e additional.fields.value.string_value
thr_category (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
contentver (contentver) PanOSContentVer ContentVer contentver additional.fields.key e additional.fields.value.string_value
sig_flags (sig_flags) sig_flags additional.fields.key e additional.fields.value.string_value
ID da associação SCTP (assoc_id) PanOSAssocID assoc_id additional.fields.key e additional.fields.value.string_value
ID do protocolo de payload (ppid) PanOSPPID ppid additional.fields.key e additional.fields.value.string_value
http_headers (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
Lista de categorias de URL (url_category_list) PanOSURLCatList url_category_list additional.fields.key e additional.fields.value.string_value
UUID da regra (rule_uuid) PanOSRuleUUID rule_uuid security_result.rule_id
Conexão HTTP/2 (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
dynusergroup_name (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name additional.fields.key e additional.fields.value.string_value
Endereço XFF (xff_ip) PanXFFIP principal.ip
Categoria do dispositivo de origem (src_category) PanSrcDeviceCat src_category principal.asset.category
Perfil do dispositivo de origem (src_profile) PanSrcDeviceProf src_profile

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Modelo do dispositivo de origem (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
Fornecedor do dispositivo de origem (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
Família do SO do dispositivo de origem (src_osfamily) PanSrcDeviceOS principal.platform
Versão do SO do dispositivo de origem (src_osversion) PanSrcDeviceOSv principal.platform_version
Nome do host de origem (src_host) PanSrcHostname src_host principal.hostname
Endereço MAC de origem (src_mac) PanSrcMac principal.mac
Categoria do dispositivo de destino (dst_category) PanDstDeviceCat dst_category target.asset.category
Perfil do dispositivo de destino (dst_profile) PanDstDeviceProf dst_profile

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Modelo do dispositivo de destino (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
Fornecedor do dispositivo de destino (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
Família do SO do dispositivo de destino (dst_osfamily) PanDstDeviceOS target.platform
Versão do SO do dispositivo de destino (dst_osversion) PanDstDeviceOSv target.platform_version
Nome do host de destino (dst_host) PanPODNamespace target.hostname
Endereço MAC de destino (dst_mac) PanDstMac target.mac
ID do contêiner (container_id) PanContainerName container_id intermediary.resource.product_object_id
Namespace do POD (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
Nome do POD (pod_name) PanPODName pod_name target.resource.name
Lista dinâmica externa de origem (src_edl) PanSrcEDL src_edl

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Lista dinâmica externa de destino (dst_edl) PanDstEDL dst_edl

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

ID do host (hostid) PanGPHostID hostid principal.asset.asset_id
Número de série (serialnumber) PanEPSerial principal.asset.hardware.serial_number
domain_edl (domain_edl) PanDomainEDL domain_edl additional.fields.key e additional.fields.value.string_value
Grupo de endereços dinâmicos de origem (src_dag) PanSrcDAG principal.group.group_display_name
Grupo de endereços dinâmicos de destino (dst_dag) PanDstDAG target.group.group_display_name
partial_hash (partial_hash) PanPartialHash partial_hash additional.fields.key e additional.fields.value.string_value
Carimbo de data/hora de alta resolução (high_res_timestamp) PanTimeHighRes additional.fields.key e additional.fields.value.string_value
Motivo (reason) PanReasonFilteringAction reason security_result.summary
justificação (justification) PanJustification justificativa additional.fields.key e additional.fields.value.string_value
nssai_sst (nssai_sst) PanASServiceType nssai_sst additional.fields.key e additional.fields.value.string_value
Subcategoria do app (subcategory_of_app) subcategory_of_app additional.fields.key e additional.fields.value.string_value
Categoria do app (category_of_app) category_of_app additional.fields.key e additional.fields.value.string_value
Tecnologia do app (technology_of_app) technology_of_app additional.fields.key e additional.fields.value.string_value
Risco do app (risk_of_app) risk_of_app additional.fields.key e additional.fields.value.string_value
Característica do app (characteristic_of_app) characteristic_of_app additional.fields.key e additional.fields.value.string_value
Contêiner do app (container_of_app) container_of_app additional.fields.key e additional.fields.value.string_value
App em túnel (tunneled_app) tunneled_app additional.fields.key e additional.fields.value.string_value
SaaS do app (is_saas_of_app) is_saas_of_app additional.fields.key e additional.fields.value.string_value
Estado autorizado do app (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key e additional.fields.value.string_value
ID do relatório da nuvem (cloud_reportid) additional.fields.key e additional.fields.value.string_value
Nome do cluster (cluster_name)

principal.resource.name

Tipo de fluxo (flow_type) additional.fields.key e additional.fields.value.string_value

Dados

A tabela a seguir lista os campos de registro do tipo de registro de dados e os campos correspondentes da UDM.

Campo CSV Campo CEF Campo LEEF Chave do rótulo do Google Security Operations Campo do UDM
Horário de recebimento (cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Nº de série (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Type (tipo) type (Header) gato metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) subtype (cabeçalho) Subtipo metadata.product_event_type
Horário de geração metadata.event_timestamp
Endereço de origem (src) src src principal.ip
Endereço de destino (dst) dst dst target.ip
IP de origem NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP de destino NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Rule (regra) cs1 RuleName security_result.rule_name
Usuário de origem (srcuser) suser SourceUser principal.user.userid
Usuário de destino (dstuser) duser DestinationUser target.user.userid
Aplicativo app Aplicativo network.application_protocol
Sistema virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona de origem (de) cs4 SourceZone de

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Zona de destino (para) cs5 DestinationZone a

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de entrada (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de saída (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Ação de registro (logset) cs6 LogForwardingProfile logset additional.fields.key e additional.fields.value.string_value
Horário registrado time_logged additional.fields.key e additional.fields.value.string_value
ID da sessão (sessionid) cn1 SessionID network.session_id
Contagem de repetições (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Porta de origem (sport) spt srcPort principal.port
Porta de destino (dport) dpt dstPort target.port
Porta de origem NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Porta de destino NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Flags (flags) flexString1 Flags flags additional.fields.key e additional.fields.value.string_value
Protocolo IP (proto) proto proto network.ip_protocol
Ação (action) age ação security_result.action_details

security_result.action

URL/nome do arquivo (variados) Diversos target.file.names

target.url

Nome da ameaça/do conteúdo (threatid) gato ThreatID security_result.threat_id
Categoria (category) cs2 URLCategory categoria security_result.category_details
Gravidade (severity) number-of-severity (cabeçalho) Gravidade security_result.severity

security_result.severity_details

Direção (direction) flexString2 Direção network.direction
Número de sequência (seqno) externalId sequência metadata.product_log_id
Flags de ação (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
País de origem (srcloc) SourceLocation principal.location.country_or_region
País de destino (dstloc) DestinationLocation target.location.country_or_region
contenttype (contenttype) ContentType contenttype additional.fields.key e additional.fields.value.string_value
pcap_id (pcap_id) fileId PCAP_ID pcap_id additional.fields.key e additional.fields.value.string_value
filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
nuvem (cloud) Cloud nuvem additional.fields.key e additional.fields.value.string_value
url_idx (url_idx) URLIndex url_idx additional.fields.key e additional.fields.value.string_value
user_agent (user_agent) network.http.user_agent
filetype (filetype) target.file.mime_type
xff (xff) xff principal.ip
Referenciador (referer) network.http.referral_url
sender (sender) network.email.from
assunto (assunto) Assunto network.email.subject
destinatário (recipient) network.email.to
reportid (reportid) reportid additional.fields.key e additional.fields.value.string_value
Nível 1 da hierarquia de DG (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Nível 2 da hierarquia de DG (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Nível 3 da hierarquia de DG (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Nível 4 da hierarquia de DG (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nome do dispositivo (device_name) dvchost DeviceName intermediary.hostname
file_url (file_url) target.url
UUID da VM de origem (src_uuid) SrcUUID principal.asset.product_object_id
UUID da VM de destino (dst_uuid) DstUUID target.asset.product_object_id
http_method (http_method) RequestMethod network.http.method
ID do túnel/IMSI (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key e additional.fields.value.string_value
Monitorar tag/IMEI (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key e additional.fields.value.string_value
ID da sessão principal (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Horário de início da sessão principal (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key e additional.fields.value.string_value
Túnel (tunnel) PanOSTunnelType TunnelType túnel additional.fields.key e additional.fields.value.string_value
thr_category (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
contentver (contentver) PanOSContentVer ContentVer contentver additional.fields.key e additional.fields.value.string_value
sig_flags (sig_flags) sig_flags additional.fields.key e additional.fields.value.string_value
ID da associação SCTP (assoc_id) PanOSAssocID assoc_id additional.fields.key e additional.fields.value.string_value
ID do protocolo de payload (ppid) PanOSPPID ppid additional.fields.key e additional.fields.value.string_value
http_headers (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
Lista de categorias de URL (url_category_list) url_category_list additional.fields.key e additional.fields.value.string_value
UUID da regra (rule_uuid) PanOSRuleUUID rule_uuid security_result.rule_id
Conexão HTTP/2 (http2_connection) http2_connection network.application_protocol_version
dynusergroup_name (dynusergroup_name) dynusergroup_name

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Endereço XFF (xff_ip) principal.ip
Categoria do dispositivo de origem (src_category) src_category principal.asset.category
Perfil do dispositivo de origem (src_profile) src_profile

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Modelo do dispositivo de origem (src_model) src_model principal.asset.hardware.model
Fornecedor do dispositivo de origem (src_vendor) src_vendor principal.asset.hardware.manufacturer
Família do SO do dispositivo de origem (src_osfamily) principal.platform
Versão do SO do dispositivo de origem (src_osversion) principal.platform_version
Nome do host de origem (src_host) src_host principal.hostname
Endereço MAC de origem (src_mac) principal.mac
Categoria do dispositivo de destino (dst_category) dst_category target.asset.category
Perfil do dispositivo de destino (dst_profile) dst_profile

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Modelo do dispositivo de destino (dst_model) dst_model target.asset.hardware.model
Fornecedor do dispositivo de destino (dst_vendor) dst_vendor target.asset.hardware.manufacturer
Família do SO do dispositivo de destino (dst_osfamily) target.platform
Versão do SO do dispositivo de destino (dst_osversion) target.platform_version
Nome do host de destino (dst_host) target.hostname
Endereço MAC de destino (dst_mac) target.mac
ID do contêiner (container_id) container_id intermediary.resource.product_object_id
Namespace do POD (pod_namespace) pod_namespace target.resource.attribute.labels.key/value
Nome do POD (pod_name) pod_name target.resource.name
Lista dinâmica externa de origem (src_edl) src_edl

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Lista dinâmica externa de destino (dst_edl) dst_edl

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

ID do host (hostid) hostid principal.asset.asset_id
Número de série (serialnumber) principal.asset.hardware.serial_number
domain_edl (domain_edl) domain_edl additional.fields.key e additional.fields.value.string_value
Grupo de endereços dinâmicos de origem (src_dag) principal.group.group_display_name
Grupo de endereços dinâmicos de destino (dst_dag) target.group.group_display_name
partial_hash (partial_hash) partial_hash additional.fields.key e additional.fields.value.string_value
Carimbo de data/hora de alta resolução (high_res_timestamp) additional.fields.key e additional.fields.value.string_value
Motivo (reason) reason security_result.summary
justificação (justification) justificativa additional.fields.key e additional.fields.value.string_value
nssai_sst (nssai_sst) nssai_sst additional.fields.key e additional.fields.value.string_value
Subcategoria do app (subcategory_of_app) subcategory_of_app additional.fields.key e additional.fields.value.string_value
Categoria do app (category_of_app) category_of_app additional.fields.key e additional.fields.value.string_value
Tecnologia do app (technology_of_app) technology_of_app additional.fields.key e additional.fields.value.string_value
Risco do app (risk_of_app) risk_of_app additional.fields.key e additional.fields.value.string_value
Característica do app (characteristic_of_app) characteristic_of_app additional.fields.key e additional.fields.value.string_value
Contêiner do app (container_of_app) container_of_app additional.fields.key e additional.fields.value.string_value
App em túnel (tunneled_app) tunneled_app additional.fields.key e additional.fields.value.string_value
SaaS do app (is_saas_of_app) is_saas_of_app additional.fields.key e additional.fields.value.string_value
Estado autorizado do app (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key e additional.fields.value.string_value
ID do relatório da nuvem (cloud_reportid) additional.fields.key e additional.fields.value.string_value
Nome do cluster (cluster_name) principal.resource.name
Tipo de fluxo (flow_type) additional.fields.key e additional.fields.value.string_value

GlobalProtect

A tabela a seguir lista os campos de registro do tipo GlobalProtect e os campos correspondentes da UDM.

Campo CSV Campo CEF Campo LEEF Chave do rótulo do Google Security Operations Campo do UDM
Horário de recebimento (receive_time) rt received_time metadata.event_timestamp
Nº de série (serial) PanOSDeviceSN intermediary_asset_hardware_serial_number intermediary.asset.hardware.serial_number
Type (tipo) type (Header) metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) subtype (cabeçalho) Subtipo metadata.product_event_type
Horário de geração (time_generated) PanOSLogTimeStamp generated_timestamp metadata.event_timestamp
Sistema virtual (vsys) PanOSVirtualSystem vsys intermediary.asset.attribute.labels.key/value
ID do evento (eventid) PanOSEventID event_id additional.fields.key e additional.fields.value.string_value
Etapa (stage) PanOSStage etapa additional.fields.key e additional.fields.value.string_value
Método de autenticação (auth_method) PanOSAuthMethod extension_auth_auth_details extensions.auth.auth_details
Tipo de túnel (tunnel_type) PanOSTunnelType túnel additional.fields.key e additional.fields.value.string_value
Usuário de origem (srcuser) PanOSSourceUserName src_user principal.user.email_address

principal.user.userid

principal.administrative_domain

Região de origem (srcregion) PanOSSourceRegion src_region principal.location.country_or_region
Nome da máquina (machinename) PanOSEndpointDeviceName machine_name principal.hostname
IP público (public_ip) PanOSPublicIPv4 principal.nat_ip
IPv6 público (public_ipv6) PanOSPublicIPv6 principal.nat_ip
IP particular (private_ip) PanOSPrivateIPv4 principal.ip
IPv6 particular (private_ipv6) PanOSPrivateIPv6 principal.ip
ID do host (hostid) PanOSHostID hostid principal.asset.asset_id
Número de série (serialnumber) PanOSDeviceSN principal.asset.hardware.serial_number
Versão do cliente (client_ver) PanOSGlobalProtectClientVersion client_ver additional.fields.key e additional.fields.value.string_value
SO do cliente (client_os) PanOSEndpointOSType principal.platform
Versão do SO do cliente (client_os_ver) PanOSEndpointOSVersion principal.platform_version
Contagem de repetições (repeatcnt) PanOSCountOfRepeats repeatcnt additional.fields.key e additional.fields.value.string_value
Motivo (reason) PanOSQuarantineReason security_result.summary
Erro (erro) PanOSConnectionError erro security_result.description
Descrição (opaca) PanOSDescription security_result.description
Status (status) PanOSEventStatus status additional.fields.key e additional.fields.value.string_value
Local (local) PanOSGPGatewayLocation target.location.country_or_region
Duração do login (login_duration) PanOSLoginDuration network.session_duration
Método de conexão (connect_method) PanOSConnectionMethod connect_method additional.fields.key e additional.fields.value.string_value
Código do erro (error_code) PanOSConnectionErrorID error_code additional.fields.key e additional.fields.value.string_value
Portal (portal) PanOSPortal portal additional.fields.key e additional.fields.value.string_value
Número de sequência (seqno) PanOSSequenceNo metadata.product_log_id
Flags de ação (actionflags) PanOSActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Carimbo de data/hora de alta resolução (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value
Método de seleção de gateway (selection_type) PanOSGatewaySelectionType selection_type additional.fields.key e additional.fields.value.string_value
Tempo de resposta do SSL (response_time) PanOSSSLResponseTime response_time additional.fields.key e additional.fields.value.string_value
Prioridade do gateway (priority) PanOSGatewayPriority prioridade additional.fields.key e additional.fields.value.string_value
Tentativas de gateway (attempted_gateways) PanOSAttemptedGateways attempted_gateways additional.fields.key e additional.fields.value.string_value
Nome do gateway (gateway) PanOSAttemptedGateways gateway target.resource.name
Hierarquia de grupos de dispositivos (dg_hier_level_1) dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_2) dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Hierarquia de grupos de dispositivos (dg_hier_level_3) dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Hierarquia de grupo de dispositivos (dg_hier_level_4) dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) intermediary.asset.attribute.labels.key/value
Nome do dispositivo (device_name) intermediary.hostname
ID do sistema virtual (vsys_id) intermediary.resource.product_object_id
Gravidade (severity) number-of-severity(header) security_result.severity e security_result.severity_details
Nome do cluster (cluster_name) principal.resource.name

Correlação

A tabela a seguir lista os campos de registro do tipo "Correlação" e os campos correspondentes da UDM.

Campo CSV Campo CEF Campo LEEF Chave do rótulo do Google Security Operations Campo do UDM
Horário gerado (time_generated ou cef-formatted-time_generated) startTime generated_timestamp metadata.event_timestamp
Endereço de origem (src) src principal.ip
Usuário de origem (srcuser) SourceUser / usrName principal.user.userid
Sistema virtual (vsys) VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Categoria (category) security_result.category_details
Gravidade (severity) Gravidade security_result.severity e security_result.severity_details
Nível 1 da hierarquia do grupo de dispositivos DeviceGroupHierarchyL1 additional.fields.key e additional.fields.value.string_value
Nível 2 da hierarquia do grupo de dispositivos DeviceGroupHierarchyL2 additional.fields.key e additional.fields.value.string_value
Nível 3 da hierarquia do grupo de dispositivos DeviceGroupHierarchyL3 additional.fields.key e additional.fields.value.string_value
Nível 4 da hierarquia do grupo de dispositivos DeviceGroupHierarchyL4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) vSrcName intermediary.asset.attribute.labels.key/value
Nome do dispositivo (device_name) DeviceName intermediary.hostname
ID do sistema virtual (vsys_id) VirtualSystemID intermediary.resource.product_object_id
Nome do objeto (objectname) ObjectName target.resource.name
ID do objeto (object_id) ObjectID target.resource.product_object_id
Evidência (evidence) msg security_result.summary

GTP

A tabela a seguir lista os campos de registro do tipo gtp e os campos correspondentes da UDM.

Campo CSV Campo CEF Campo LEEF Chave do rótulo do Google Security Operations Campo do UDM
Horário de recebimento (receive_time ou cef-formatted-receive_time) metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Número de série (serial) intermediary.asset.hardware.serial_number
Type (tipo) metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) metadata.product_event_type
Horário gerado (time_generated ou cef-formatted-time_generated) metadata.event_timestamp
Endereço de origem (src) principal.ip
Endereço de destino (dst) target.ip
Nome da regra (regra) security_result.rule_name
Aplicativo network.application_protocol
Sistema virtual (vsys) vsys intermediary.asset.attribute.labels.key/value
Zona de origem (de) de

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Zona de destino (para) a

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de entrada (inbound_if) inbound_if

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de saída (outbound_if) outbound_if

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Ação de registro (logset) logset additional.fields.key e additional.fields.value.string_value
ID da sessão (sessionid) network.session_id
Porta de origem (sport) principal.port
Porta de destino (dport) target.port
Protocolo IP (proto) network.ip_protocol
Ação (action) security_result.action_details

security_result.action

Tipo de evento do GTP (event_type) gtp_event_type additional.fields.key e additional.fields.value.string_value
MSISDN (msisdn) msisdn additional.fields.key e additional.fields.value.string_value
Nome do ponto de acesso (apn) apn additional.fields.key e additional.fields.value.string_value
Tecnologia de acesso por rádio (RAT) rato additional.fields.key e additional.fields.value.string_value
Tipo de mensagem do GTP (msg_type) gtp_msg_type additional.fields.key e additional.fields.value.string_value
Endereço IP final (end_ip_adr) principal.ip
Identificador do endpoint do túnel 1 (teid1) teid1 additional.fields.key e additional.fields.value.string_value
Identificador do endpoint do túnel 2 (teid2) teid2 additional.fields.key e additional.fields.value.string_value
Interface do GTP (gtp_interface) gtp_interface additional.fields.key e additional.fields.value.string_value
Causa do GTP (cause_code) gtp_cause_code additional.fields.key e additional.fields.value.string_value
Gravidade (severity) security_result.severity e security_result.severity_details
MCC da rede de veiculação (mcc) mcc additional.fields.key e additional.fields.value.string_value
MNC da rede de veiculação (mnc) mnc additional.fields.key e additional.fields.value.string_value
Código de área (area_code) area_code additional.fields.key e additional.fields.value.string_value
ID da célula (cell_id) cell_id additional.fields.key e additional.fields.value.string_value
Código do evento do GTP (event_code) event_code additional.fields.key e additional.fields.value.string_value
Local de origem (srcloc) principal.location.country_or_region
Local de destino (dstloc) target.location.country_or_region
ID do túnel/IMSI (imsi) tunnelid additional.fields.key e additional.fields.value.string_value
Monitorar tag/IMEI (imei) monitortag additional.fields.key e additional.fields.value.string_value
Horário de início (start) start additional.fields.key e additional.fields.value.string_value
Tempo decorrido (decorrido) network.session_duration.seconds
Tunnel Inspection RuleTunnel (tunnel_insp_rule) tunnel_insp_rule security_result.detection_fields.key/value
IP do usuário remoto (remote_user_ip) principal.ip
ID do usuário remoto (remote_user_id) remote_user_id principal.user.userid
UUID da regra (rule_uuid) security_result.rule_id
ID do PCAP (pcap_id) pcap_id additional.fields.key e additional.fields.value.string_value
Carimbo de data/hora de alta resolução (high_res_timestamp) additional.fields.key e additional.fields.value.string_value
Um tipo de serviço de fração (nsdsai_sst) nsdsai_sst additional.fields.key e additional.fields.value.string_value
Um diferenciador de fração (nsdsai_sd) nsdsai_sd additional.fields.key e additional.fields.value.string_value
Subcategoria do aplicativo (subcategory_of_app) subcategory_of_app additional.fields.key e additional.fields.value.string_value
Categoria do aplicativo (category_of_app) category_of_app additional.fields.key e additional.fields.value.string_value
Tecnologia de aplicativos (technology_of_app) technology_of_app additional.fields.key e additional.fields.value.string_value
Risco do aplicativo (risk_of_app) risk_of_app additional.fields.key e additional.fields.value.string_value
Característica do aplicativo (characteristic_of_app) characteristic_of_app additional.fields.key e additional.fields.value.string_value
Contêiner do aplicativo (container_of_app) container_of_app additional.fields.key e additional.fields.value.string_value
SaaS de aplicativo (is_saas_of_app) is_saas_of_app additional.fields.key e additional.fields.value.string_value
Estado de sanção do aplicativo (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key e additional.fields.value.string_value

SCTP

Campo CSV Campo CEF Campo LEEF Chave do rótulo do Google Security Operations Campo do UDM
Horário de recebimento (receive_time ou cef-formatted-receive_time) receive_time ou cef-formatted-receive_time metadata.collected_timestamp
Número de série (serial) serial intermediary.asset.hardware.serial_number
Type (tipo) tipo metadata.product_event_type
Horário gerado (time_generated ou cef-formatted-time_generated) time_generated ou cef-formatted-time_generated metadata.event_timestamp
Endereço de origem (src) src principal.ip
Endereço de destino (dst) dst target.ip
Nome da regra (regra) regra security_result.rule_name
Zona de origem (de) de additional.fields.key e additional.fields.value.string_value
Zona de destino (para) a additional.fields.key e additional.fields.value.string_value
Interface de entrada (inbound_if) inbound_if additional.fields.key e additional.fields.value.string_value
Interface de saída (outbound_if) outbound_if additional.fields.key e additional.fields.value.string_value
Ação de registro (logset) logset additional.fields.key e additional.fields.value.string_value
ID da sessão (sessionid) sessionid network.session_id
Contagem de repetições (repeatcnt) repeatcnt additional.fields.key e additional.fields.value.string_value
Porta de origem (sport) esporte principal.port
Porta de destino (dport) dport target.port
Protocolo IP (proto) proto network.ip_protocol (enum)
Ação (action) ação security_result.action_details
security_result.action
Hierarquia de grupos de dispositivos (dg_hier_level_1 a dg_hier_level_4) dg_hier_level_1 a dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do dispositivo (device_name) device_name intermediary.hostname
Número de sequência (seqno) seqno metadata.product_log_id
ID da associação SCTP (assoc_id) assoc_id additional.fields.key e additional.fields.value.string_value
ID do protocolo de payload (ppid) ppid additional.fields.key e additional.fields.value.string_value
Gravidade (severity) gravidade, security_result.severity e security_result.severity_details
Tipo de fragmento SCTP (sctp_chunk_type) sctp_chunk_type additional.fields.key e additional.fields.value.string_value
Tipo de evento SCTP (sctp_event_type) sctp_event_type additional.fields.key e additional.fields.value.string_value
Tag de verificação SCTP 1 (verif_tag_1) verif_tag_1 additional.fields.key e additional.fields.value.string_value
Tag de verificação SCTP 2 (verif_tag_2) verif_tag_2 additional.fields.key e additional.fields.value.string_value
Código de causa do SCTP (sctp_cause_code) sctp_cause_code additional.fields.key e additional.fields.value.string_value
ID do app Diameter (diam_app_id) diam_app_id additional.fields.key e additional.fields.value.string_value
Código de comando do Diameter (diam_cmd_code) diam_cmd_code additional.fields.key e additional.fields.value.string_value
Código AVP do diâmetro (diam_avp_code) diam_avp_code additional.fields.key e additional.fields.value.string_value
ID do fluxo SCTP (stream_id) stream_id additional.fields.key e additional.fields.value.string_value
Motivo do término da associação SCTP (assoc_end_reason) assoc_end_reason additional.fields.key e additional.fields.value.string_value
Código de operação (op_code) op_code additional.fields.key e additional.fields.value.string_value
Número de série do assinante (SSN) da parte que está ligando SCCP (sccp_calling_ssn) sccp_calling_ssn additional.fields.key e additional.fields.value.string_value
Título global da parte de chamada do SCCP (sccp_calling_gt) sccp_calling_gt additional.fields.key e additional.fields.value.string_value
Filtro SCTP (sctp_filter) sctp_filter additional.fields.key e additional.fields.value.string_value
Fragmentos SCTP (fragmentos) pedaços additional.fields.key e additional.fields.value.string_value
Fragmentos SCTP enviados (chunks_sent) chunks_sent additional.fields.key e additional.fields.value.string_value
Blocos SCTP recebidos (chunks_received) chunks_received additional.fields.key e additional.fields.value.string_value
Pacotes (pacotes) pacotes additional.fields.key e additional.fields.value.string_value
UUID da regra (rule_uuid) rule_uuid security_result.rule_id
Sistema virtual (vsys) vsys intermediary.asset.attribute.labels.key/value
Nome do sistema virtual (vsys_name) vsys_name intermediary.asset.attribute.labels.key/value
Pacotes enviados (pkts_sent) pkts_sent network.sent_packets
Pacotes recebidos (pkts_received) pkts_received network.received_packets

Auditoria

Campo CSV Campo CEF Campo LEEF Chave do rótulo do Google Security Operations Campo do UDM
Horário de geração metadata.event_timestamp
Tipo de ameaça/conteúdo (subtipo) metadata.product_event_type
ID do evento principal.application
Objeto principal.user.userid
Comando da CLI principal.process.command_line
Gravidade security_result.severity
Número de série intermediary.asset.hardware.serial_number

Referência de mapeamento de campos: tipos de registros para tipo de evento do UDM

A tabela a seguir lista os tipos de registros de firewall da Palo Alto Networks e os tipos de eventos correspondentes da UDM.

Tipo de registro Tipo de evento do UDM
Tráfego NETWORK_CONNECTION
Ameaça NETWORK_CONNECTION
Filtragem de URL NETWORK_CONNECTION
WildFire NETWORK_CONNECTION

Os registros de envios do WildFire são um subtipo do tipo de registro de ameaça e usam o mesmo formato syslog.

Filtragem de dados NETWORK_CONNECTION
Túnel NETWORK_CONNECTION
GTP NETWORK_CONNECTION
Configuração SETTING_MODIFICATION/SETTING_CREATION/SETTING_DELETION/SETTING_UNCATEGORIZED

O valor do campo "Comando (cmd)" determina o mapeamento do tipo de evento da UDM. Se o valor do campo "cmd" for "add" ou "clone", SETTING_CREATION será definido.

Se o valor do campo "cmd" for "delete", SETTING_DELETION será definido.

Se o valor do campo "cmd" for "edit", "move", "rename", "set" ou "commit", SETTING_MODIFICATION será definido.

Se o valor do campo "cmd" não tiver nenhum valor, SETTING_UNCATEGORIZED será definido.

Sistema

Se o valor do subtipo for "dhcp", NETWORK_DHCP será definido.

Se o valor do subtipo for "auth", USER_LOGIN será definido.

Se o valor da descrição for "logged in", USER_LOGIN será definido.

Se o valor da descrição for "logged out", USER_LOGOUT será definido.

Para outros valores do subtipo, GENERIC_EVENT é definido.

Correspondência de HIP NETWORK_CONNECTION
Tag de IP GENERIC_EVENT
User-ID USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED

Se o valor do subtipo for "login", USER_LOGIN será definido.

Se o valor do subtipo for "logout", USER_LOGOUT será definido.

Se o subtipo não tiver nenhum valor, USER_UNCATEGORIZED será definido.

Descriptografia NETWORK_CONNECTION
Autenticação GENERIC_EVENT
SCTP NETWORK_CONNECTION
Auditoria GENERIC_EVENT

Delta de mapeamento do UDM

Referência de delta de mapeamento do UDM: firewall da Palo Alto Networks

A tabela a seguir lista o delta entre o mapeamento da UDM antiga de Palo Alto Networks Firewall e o novo mapeamento da UDM de Palo Alto Networks Firewall.

UDM Event Type Delta

Log type Old UDM Event Type New UDM Event Type
WildFire NETWORK_CONNECTION SCAN_UNCATEGORIZED
Data Filtering NETWORK_CONNECTION NETWORK_UNCATEGORIZED
Authentication STATUS_UPDATE STATUS_UNCATEGORIZED

UDM Field Mapping Delta

Log Type Old UDM Mapping CSV Log Field CEF Log Field LEEF Log Field New UDM Mapping
System intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
System about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
System about.labels.key/value additional.fields.key/value.string_value Object (object) fname Filename target.resource.name
System Description (opaque) msg msg metadata.description
System principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
System intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
Config intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Config about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
Config principal.process.command_line Configuration Path (path) msg ConfigurationPath principal.process.command_line
Config principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
Config intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
Config principal.asset.attribute.labels.key/value Device Group (dg_id) PanOSFWDeviceGroup target.asset.attribute.labels
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Threat/Wildfire target.file.full_path target.url target.hostname URL/Filename (misc) request Miscellaneous target.file.names target.url
Threat/Wildfire about.file.sha1/md5/sha256 File Digest (filedigest) fileHash FileDigest target.file.sha1/md5/sha256
Threat/Wildfire about.file.mime_type File Type (filetype) fileType FileType target.file.mime_type
Threat/Wildfire principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Threat/Wildfire principal.user.product_object_id Source VM UUID (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
Threat/Wildfire target.user.product_object_id Destination VM UUID (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value HTTP Headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
Threat/Wildfire principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
Threat/Wildfire principal.asset.software.version Source Device OS Version (src_osversion) PanSrcDeviceOSv principal.platform_version
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
Threat/Wildfire target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
Threat/Wildfire metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Reason (reason) PanReasonFilteringAction security_result.summary
Traffic about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value Packets Sent (pkts_sent) PanOSPacketsSent srcPackets network.sent_packets
Traffic about.labels.key/value additional.fields.key/value.string_value Packets Received (pkts_received) PanOSPacketsReceived dstPackets network.received_packets
Traffic principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
Traffic principal.asset.platform_software.platform(enum) principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
Traffic target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
Traffic about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
Traffic about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
Traffic about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
Traffic metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
User-ID about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
User-ID principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
User-ID principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID intermediary.resource.product_object_id
User-ID principal.user.userid principal.administrative_domain principal.user.email_addresses User by Source (userbysource) PanOSUserBySource target.user.userid target.user.email_addresses
User-ID metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
HIP Match intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
HIP Match about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
HIP Match about.labels.key/value additional.fields.key/value.string_value HIP (matchname) cat HIP target.resource.attribute.labels
HIP Match about.labels.key/value additional.fields.key/value.string_value HIP Type (matchtype) Device Event Class ID (Header) HIPType target.resource.attribute.labels
HIP Match principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
HIP Match intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
HIP Match principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
HIP Match principal.asset.product_object_id Host ID (hostid) PanOSHostID principal.asset.asset_id
HIP Match metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
IP-Tag intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
IP-Tag about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
IP-Tag principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOsVsysName vSrcName target.asset.attribute.labels
IP-Tag intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
IP-Tag principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
IP-Tag metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Decryption target.application Application (app) app network.application_protocol
Decryption about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 intermediary.asset.attribute.labels
Decryption principal.asset.asset_id Source VM UUID (src_uuid) PanOSSourceUUID principal.asset.product_object_id
Decryption target.asset.asset_id Destination VM UUID (dst_uuid) PanOSDestinationUUID target.asset.product_object_id
Decryption about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanOSContainerID intermediary.resource.product_object_id
Decryption about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanOSContainerNameSpace target.resource.attribute.labels additional.fields.key/value.string_value
Decryption about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanOSContainerName target.resource.name
Decryption metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanOSSourceDeviceCategory principal.asset.category
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanOSSourceDeviceModel principal.asset.hardware.model
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanOSSourceDeviceVendor principal.asset.hardware.manufacturer
Decryption principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanOSSourceDeviceOSFamily principal.platform
Decryption principal.asset.software.version Source Device OS Version (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanOSDestinationDeviceCategory target.asset.category
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanOSDestinationDeviceModel target.asset.hardware.model
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanOSDestinationDeviceVendor target.asset.hardware.manufacturer
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanOSDestinationDeviceOSFamily target.platform
Decryption target.asset.software.version Destination Device OS Version (dst_osversion) PanOSDestinationDeviceOSVersion target.platform_version
Decryption principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) intermediary.asset.attribute.labels
Decryption principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
Tunnel about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Tunnel principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Tunnel about.labels.key/value additional.fields.key/value.string_value Packets Sent (pkts_sent) PanOSPacketsSent srcPackets network.sent_packets
Tunnel about.labels.key/value additional.fields.key/value.string_value Packets Received (pkts_received) PanOSPacketsReceived dstPackets network.received_packets
Tunnel target.ip Remote User IP (remote_user_ip) PanOSRmtUserIP principal.ip
Tunnel target.labels.key/value additional.fields.key/value.string_value Remote User ID (remote_user_id) PanOSRmtUserID principal.user.userid
Tunnel metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Authentication about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Authentication target.user.user_display_name Normalize User (normalize_user) cs2 NormalizeUser target.user.user_display_name
Authentication about.labels.key/value additional.fields.key/value.string_value Object (object) fname ObjectName target.resource.name
Authentication about.labels.key/value additional.fields.key/value.string_value Authentication Policy (authpolicy) cs4 AuthPolicy additional.fields.key/value.string_value
Authentication principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Authentication principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
Authentication metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res _timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanOSSourceDeviceCategory principal.asset.category
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanOSSourceDeviceModel principal.asset.hardware.model
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanOSSourceDeviceVendor principal.asset.hardware.manufacturer
Authentication principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanOSSourceDeviceOSFamily principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value
Authentication principal.asset.software.version Source Device OS Version (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
URL about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
URL target.file.full_path target.url URL/Filename (misc) Miscellaneous target.file.names target.url
URL about.labels.key/value additional.fields.key/value.string_value Category (category) cs2 URLCategory security_result.category_details
URL about.file.sha1/md5/sha256 filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
URL about.file.mime_type filetype (filetype) target.file.mime_type
URL about.labels.key/value additional.fields.key/value.string_value xff (xff) PanOSXForwarderfor identSrc principal.ip
URL principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
URL about.url file_url (file_url) target.url
URL principal.asset.asset_id Source VM UUID (src_uuid) SrcUUID principal.asset.product_object_id
URL target.asset.asset_id Destination VM UUID (dst_uuid) DstUUID target.asset.product_object_id
URL about.labels.key/value additional.fields.key/value.string_value http_headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
URL about.labels.key/value additional.fields.key/value.string_value UUID for rule (rule_uuid) PanOSRuleUUID security_result.rule_id
URL about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
URL principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
URL principal.asset.software.version Source Device OS Version (src_osversion) PanSrcDeviceOSv principal.platform_version
URL principal.labels.key/value additional.fields.key/value.string_value Source Hostname (src_host) PanSrcHostname principal.hostname
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
URL target.asset.platform_software.platform target.labels.key/value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
URL target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
URL about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
URL about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
URL about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
URL about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
URL metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Res Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
URL about.labels.key/value additional.fields.key/value.string_value Reason (reason) PanReasonFilteringAction security_result.summary
Data about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Data target.file.full_path target.url URL/Filename (misc) Miscellaneous target.file.names target.url
Data about.labels.key/value additional.fields.key/value.string_value Category (category) cs2 URLCategory security_result.category_details
Data about.file.sha1/md5/sha256 filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
Data about.file.mime_type filetype (filetype) target.file.mime_type
Data about.labels.key/value additional.fields.key/value.string_value xff (xff) principal.ip
Data principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Data about.url file_url (file_url) target.url
Data principal.asset.asset_id Source VM UUID (src_uuid) SrcUUID principal.asset.product_object_id
Data target.asset.asset_id Destination VM UUID (dst_uuid) DstUUID target.asset.product_object_id
Data about.labels.key/value additional.fields.key/value.string_value http_headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
Data about.labels.key/value additional.fields.key/value.string_value UUID for rule (rule_uuid) PanOSRuleUUID security_result.rule_id
Data about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) network.application_protocol_version
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) principal.asset.category
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) principal.asset.hardware.model
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) principal.asset.hardware.manufacturer
Data principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) principal.platform
Data principal.asset.software.version Source Device OS Version (src_osversion) principal.platform_version
Data principal.labels.key/value additional.fields.key/value.string_value Source Hostname (src_host) principal.hostname
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) target.asset.category
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) target.asset.hardware.model
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) target.asset.hardware.manufacturer
Data target.asset.platform_software.platform target.labels.key/value Destination Device OS Family (dst_osfamily) target.platform
Data target.asset.software.version Destination Device OS Version (dst_osversion) target.platform_version
Data about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) intermediary.resource.product_object_id
Data about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) target.resource.attribute.labels
Data about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) target.resource.name
Data about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) principal.asset.asset_id
Data metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Res Timestamp (high_res_timestamp) additional.fields.key/value.string_value
Data about.labels.key/value additional.fields.key/value.string_value Reason (reason) security_result.summary
GlobalProtect about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) PanOSVirtualSystem intermediary.asset.attribute.labels
GlobalProtect principal.user.email_address principal.user.userid principal.administrative_domain Source User (srcuser) PanOSSourceUserName target.user.email_address target.user.userid
GlobalProtect principal.asset.platform_software.platform(enum) Client OS (client_os) PanOSEndpointOSType principal.platform
GlobalProtect principal.asset.platform_software.platform_version Client OS Version (client_os_ver) PanOSEndpointOSVersion principal.platform_version
GlobalProtect metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
GlobalProtect about.labels.key/value additional.fields.key/value.string_value Gateway Name (gateway) PanOSAttemptedGateways target.resource.name
GlobalProtect principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) intermediary.asset.attribute.labels
GlobalProtect target.hostname Device Name (device_name) intermediary.hostname
GlobalProtect principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
CORRELATION about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) VirtualSystem intermediary.asset.attribute.labels
CORRELATION principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) vSrcName intermediary.asset.attribute.labels
CORRELATION principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) VirtualSystemID intermediary.resource.product_object_id
GTP additional.fields.key/value.string_value Virtual System (vsys) intermediary.asset.attribute.labels
GTP target.ip Remote User IP (remote_user_ip) principal.ip
GTP additional.fields.key/value.string_value Remote User ID (remote_user_id) principal.user.userid
GTP metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) additional.fields.key/value.string_value

Serviço de geração de registros do firewall Strata da Palo Alto Networks.

Visão geral

O serviço de geração de registros do Strata da Palo Alto Networks® oferece armazenamento e agregação de registros centralizados e baseados na nuvem para seus firewalls locais, virtuais (nuvem privada e pública), para o Prisma Access e para serviços fornecidos na nuvem, como o Cortex XDR.O serviço de geração de registros do Strata é seguro, resiliente e tolerante a falhas, além de garantir que seus dados de registro estejam atualizados e disponíveis quando você precisar deles. Ela oferece uma infraestrutura de geração de registros escalonável que elimina a necessidade de planejar e implantar coletores de registros para atender às suas necessidades de retenção. Se você já tiver coletores de registros locais, o novo serviço de registros do Strata poderá complementar sua configuração atual. É possível aumentar sua infraestrutura de coleta de registros atual com o serviço de geração de registros do Strata baseado na nuvem para expandir a capacidade operacional à medida que sua empresa cresce ou para atender às necessidades de capacidade de novas unidades.Com esse serviço, a Palo Alto Networks cuida da manutenção e do monitoramento contínuos da infraestrutura de geração de registros para que você possa se concentrar nos negócios.

  • Verifique os formatos de registro e as versões do PAN-OS compatíveis com o analisador do Strata Logging Service. A tabela a seguir lista os formatos de registro e as versões correspondentes do PAN-OS compatíveis com o analisador do serviço de geração de registros do Strata:

    Formato do registro Versão do PAN-OS
    JSON 12.1
  • Verifique os tipos de registros de firewall da Palo Alto Networks compatíveis com o analisador do Google SecOps. O analisador do Google SecOps é compatível com os seguintes tipos de registros de firewall da Palo Alto Networks:

    • Tráfego
    • Ameaça
    • Inspeção de túnel
    • Sistema
    • Correspondência de HIP
    • IP-Tag
    • User-ID
    • Descriptografia
    • Autenticação
    • Filtragem de URL
    • GlobalProtect

Implantação do serviço de geração de registros do Strata

Comece a enviar registros ao serviço de registro do Strata:

Para começar a enviar registros ao serviço de registro do Strata, siga estas etapas:

  1. Instalar uma versão compatível do PAN-OS®
  2. Ative o serviço de geração de registros do Strata. Isso inclui o provisionamento do certificado necessário para que os firewalls se conectem com segurança ao serviço.
  3. Integrar firewalls ao serviço de geração de registros do Strata com ou sem o Panorama

Para conferir as etapas detalhadas de integração, consulte a documentação.

Encaminhar registros do serviço de registro do Strata

Para atender às suas necessidades de armazenamento, relatórios e monitoramento de longo prazo ou legais e de compliance, configure o serviço de geração de registros do Strata para encaminhar registros a um servidor HTTPS ou aos seguintes SIEMs:

  1. Exabeam
  2. Google Chronicle
  3. Microsoft Sentinel
  4. Coletor de eventos HTTP (HEC) do Splunk

Use o método de encaminhamento HTTPS para encaminhar os registros usando o serviço de geração de registros do Strata. Para informações detalhadas, consulte esta documentação.

Formatos de registro aceitos

O analisador de firewall do serviço de registro do Strata da Palo Alto Networks é compatível com registros no formato JSON.

Registros de amostra compatíveis

  • JSON

    {"source": "Palo Alto Networks FLS LF", "host": "dummy-loghost", "time": "1730265996460", "event": {"TimeReceived": "2024-10-30T05:25:50.000000Z", "DeviceSN": "no-serial", "LogType": "TRAFFIC", "Subtype": "end", "ConfigVersion": "10.2", "TimeGenerated": "2024-10-30T05:25:40.000000Z", "SourceAddress": "198.51.100.6", "DestinationAddress": "198.51.100.6", "NATSource": "", "NATDestination": "", "Rule": "egress-dns-ping-traceroute", "SourceUser": null, "DestinationUser": null, "Application": "dns-base", "VirtualLocation": "vsys1", "FromZone": "VA8280-RN", "ToZone": "inter-fw", "InboundInterface": "tunnel.101", "OutboundInterface": "tunnel.4005", "LogSetting": "Cortex Data Lake", "SessionID": 754194, "RepeatCount": 1, "SourcePort": 53578, "DestinationPort": 53, "NATSourcePort": 0, "NATDestinationPort": 0, "Protocol": "udp", "Action": "allow", "Bytes": 214, "BytesSent": 72, "BytesReceived": 142, "PacketsTotal": 2, "SessionStartTime": "2024-10-30T05:25:10.000000Z", "SessionDuration": 0, "URLCategory": "any", "SequenceNo": 7382192512716388639, "SourceLocation": "198.51.100.6-198.51.255.255", "DestinationLocation": "198.51.100.6-198.51.255.255", "PacketsSent": 1, "PacketsReceived": 1, "SessionEndReason": "aged-out", "DGHierarchyLevel1": 65537, "DGHierarchyLevel2": 65538, "DGHierarchyLevel3": 65541, "DGHierarchyLevel4": 0, "VirtualSystemName": "", "DeviceName": "VA8280-RN", "ActionSource": "from-policy", "SourceUUID": null, "DestinationUUID": null, "IMSI": 0, "IMEI": null, "ParentSessionID": 0, "ParentStarttime": "1970-01-01T00:00:00.000000Z", "Tunnel": "N/A", "EndpointAssociationID": 72057594037927936, "ChunksTotal": 0, "ChunksSent": 0, "ChunksReceived": 0, "RuleUUID": "95cfc3cc-cb00-4758-af1d-de9ab5f07f97", "HTTP2Connection": 0, "LinkChangeCount": 0, "SDWANPolicyName": null, "LinkSwitches": null, "SDWANCluster": null, "SDWANDeviceType": null, "SDWANClusterType": null, "SDWANSite": null, "DynamicUserGroupName": null, "X-Forwarded-ForIP": null, "SourceDeviceCategory": null, "SourceDeviceProfile": null, "SourceDeviceModel": null, "SourceDeviceVendor": null, "SourceDeviceOSFamily": null, "SourceDeviceOSVersion": null, "SourceDeviceHost": null, "SourceDeviceMac": null, "DestinationDeviceCategory": null, "DestinationDeviceProfile": null, "DestinationDeviceModel": null, "DestinationDeviceVendor": null, "DestinationDeviceOSFamily": null, "DestinationDeviceOSVersion": null, "DestinationDeviceHost": null, "DestinationDeviceMac": null, "ContainerID": null, "ContainerNameSpace": null, "ContainerName": null, "SourceEDL": null, "DestinationEDL": null, "GPHostID": null, "EndpointSerialNumber": null, "SourceDynamicAddressGroup": null, "DestinationDynamicAddressGroup": null, "HASessionOwner": null, "TimeGeneratedHighResolution": "2024-10-30T05:25:41.009000Z", "NSSAINetworkSliceType": null, "NSSAINetworkSliceDifferentiator": null}}"
    

Referência de mapeamento de campos: campos de registros para campos da UDM

Nesta seção, explicamos como o analisador mapeia os campos de registro do firewall do serviço de registro em log do Palo Alto Networks Strata para os campos de evento do UDM do Google em cada tipo de registro.

Consulte as seções a seguir para ver a referência de mapeamento de cada tipo de registro:

Sistema

A tabela a seguir lista os campos de registro do tipo "Registro do sistema" e os campos correspondentes da UDM.

Log field UDM mapping
AgentContentVersion additional.fields.key/value.string_value
AgentDataCollectionStatus target.resource.attribute.labels
AgentID target.resource.attribute.labels
AgentIsolationStatus target.resource.attribute.labels
AgentStatus target.resource.attribute.labels
AgentVersion target.asset.software.version
ConfigVersion additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DeviceGroup target.group.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EndpointCPUArchitecture target.asset.hardware.cpu_platform
EndpointDeviceDomain target.asset.administrative_domain
EndpointDeviceName target.asset.hostname
EndpointIPaddress target.asset.ip
VDIEndpoint target.asset.attribute.labels
EndpointOSType additional.fields.key/value.string_value
EndpointOSVersion target.platform_version
AgentTimeZoneOffset additional.fields.key/value.string_value
EndpointUserDomain additional.fields.key/value.string_value
EndpointUserName target.user.user_display_name
EndpointUserUUID target.user.userid
EventComponent additional.fields.key/value.string_value
EventDescription metadata.description
EventName additional.fields.key/value.string_value
EventTime metadata.event_timestamp
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogCategory security_result.category_details
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
LogSourceID target.resource.attribute.labels
LogSourceName observer.asset.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
LogTime metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Severity security_result.severity
Subtype metadata.product_event_type
Template target.resource.attribute.labels
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

Ameaça

A tabela a seguir lista os campos de registro do tipo "Registro de ameaças" e os campos correspondentes da UDM.

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
ApplianceOrCloud additional.fields.key/value.string_value
CloudHostname additional.fields.key/value.string_value
CloudReportID security_result.detection_fields.key/value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DirectionOfAttack security_result.detection_fields.key/value
DomainEDL additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
FileName target.file.names
FileHash target.file.sha1
FileType additional.fields.key/value.string_value
FileURL target.url
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HostID principal.asset.asset_id
HTTP2Connection network.application_protocol_version
HTTPMethod network.http.method
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
LocalDeepLearningAnalyzed additional.fields.key/value.string_value
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
PartialHash additional.fields.key/value.string_value
PayloadProtocolID additional.fields.key/value.string_value
Packet additional.fields.key/value.string_value
PacketID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
RecipientEmail target.user.email_addresses
ReportID security_result.detection_fields.key/value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SenderEmail principal.user.email_addresses
SequenceNo metadata.product_log_id
SessionID network.session_id
Severity security_result.severity
SigFlags additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
EmailSubject network.email.subject
ApplicationTechnology additional.fields.key/value.string_value
ThreatCategory security_result.detection_fields.key/value.key/value
ThreatID security_result.threat_id
ThreatName security_result.threat_name
ThreatNameFirewall additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLDomain target.domain.name
URLCounter additional.fields.key/value.string_value
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
Verdict additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-ForIP principal.ip

Tráfego

A tabela a seguir lista os campos de registro do tipo "Tráfego" e os campos correspondentes da UDM.

Log field UDM mapping
Action security_result.action
ActionSource additional.fields.key/value.string_value
AIFwdError additional.fields.key/value.string_value
AITraffic additional.fields.key/value.string_value
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
BytesReceived network.received_bytes
BytesSent network.sent_bytes
Bytes additional.fields.key/value.string_value
ChunksReceived additional.fields.key/value.string_value
ChunksSent additional.fields.key/value.string_value
ChunksTotal additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
EndpointAssociationID additional.fields.key/value.string_value
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HASessionOwner additional.fields.key/value.string_value
GPHostID additional.fields.key/value.string_value
HTTP2Connection network.application_protocol_version
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsOffloaded additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
LinkChangeCount additional.fields.key/value.string_value
LinkSwitches additional.fields.key/value.string_value
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
SDWANPolicyName additional.fields.key/value.string_value
Protocol network.ip_protocol
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SDWANFECRatio additional.fields.key/value.string_value
SDWANCluster additional.fields.key/value.string_value
SDWANClusterType additional.fields.key/value.string_value
SDWANDeviceType additional.fields.key/value.string_value
SDWANSite additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionStartTime additional.fields.key/value.string_value
SessionTracker additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
SessionDuration network.session_duration
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLCategory target.url_metadata.categories
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-ForIP principal.ip

User-ID

A tabela a seguir lista os campos de registro do tipo de registro User-ID e os campos correspondentes da UDM.

Log field UDM mapping
AuthFactorNo security_result.detection_fields.key/value
AuthenticatedUserDomain target.user.administrative_domain
AuthenticatedUserName target.user.userid
AuthenticatedUserUUID target.user.product_object_id
ConfigVersion additional.fields.key/value.string_value
CountofRepeats additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationPort target.port
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EventID additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsDuplicateUser additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MappingDataSource additional.fields.key/value.string_value
MappingDataSourceName additional.fields.key/value.string_value
MappingDataSourceType additional.fields.key/value.string_value
MappingTimeout additional.fields.key/value.string_value
MFAFactorType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SourceIP principal.ip
SourcePort principal.port
Subtype metadata.product_event_type
Tag additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
UGFlags additional.fields.key/value.string_value
User target.user.userid
UserGroupFound additional.fields.key/value.string_value
UserIdentifiedBySource additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Correspondência de HIP

A tabela a seguir lista os campos de registro do tipo de registro de correspondência do HIP e os campos correspondentes da UDM.

Log field UDM mapping
ConfigVersion additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EndpointDeviceName principal.asset.hostname
EndpointOSType additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
HipMatchName target.resource.attribute.labels
HipMatchType target.resource.attribute.labels
HostID principal.asset.asset_id
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType metadata.product_event_type
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Source additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceIP principal.ip
SourceIPv6 principal.ip
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
TimestampDeviceIdentification principal.asset.first_seen_time
UUID additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

Tag de IP

A tabela a seguir lista os campos de registro do tipo de registro de tag de IP e os campos correspondentes da UDM.

Log field UDM mapping
ConfigVersion additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EventID additional.fields.key/value.string_value
IPSubnetRange network.ip_subnet_range
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSetting target.resource.attribute.labels
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MappingDataSource additional.fields.key/value.string_value
MappingDataSourceSubType additional.fields.key/value.string_value
MappingDataSourceType additional.fields.key/value.string_value
MappingTimeout additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
RuleMatched security_result.rule_name
RuleMatchedUUID security_result.rule_id
SequenceNo metadata.product_log_id
SourceIP principal.ip
Subtype metadata.product_event_type
TagName additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

Descriptografia

A tabela a seguir lista os campos de registro do tipo "Decryption" e os campos correspondentes da UDM.

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
CertificateFlags additional.fields.key/value.string_value
CertificateSerial network.tls.server.certificate.serial
CertificateSize additional.fields.key/value.string_value
CertificateVersion network.tls.server.certificate.version
ChainStatus additional.fields.key/value.string_value
ApplicationCharacteristics additional.fields.key/value.string_value
ClientToFirewall additional.fields.key/value.string_value
CommonName additional.fields.key/value.string_value
CommonNameLength additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
Cpadding additional.fields.key/value.string_value
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
Domain target.hostname
EllipticCurve network.tls.curve
ErrorIndex additional.fields.key/value.string_value
ErrorMessage additional.fields.key/value.string_value
Fingerprint network.tls.server.certificate.md5/sha1/sha256
FirewallToClient additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsCertECDSA additional.fields.key/value.string_value
IsCertRSA additional.fields.key/value.string_value
IsCertCNTruncated additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
IsForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsIssuerCNTruncated additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
IsNAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
PacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsResumeSession additional.fields.key/value.string_value
IsRootCNTruncated additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSNITruncated additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
IssuerCommonName network.tls.server.certificate.issuer
IssuerNameLength additional.fields.key/value.string_value
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
TimeNotAfter additional.fields.key/value.string_value
TimeNotBefore additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
Padding additional.fields.key/value.string_value
Padding3 additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
PolicyName additional.fields.key/value.string_value
Protocol network.ip_protocol
ProxyType additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
RootCommonName additional.fields.key/value.string_value
RootCNLength additional.fields.key/value.string_value
RootStatus additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SessionID network.session_id
ServerNameIndication network.tls.client.server_name
SNILength additional.fields.key/value.string_value
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceOS additional.fields.key/value.string_value
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
ApplicationTechnology additional.fields.key/value.string_value
TimeReceivedManagementPlane additional.fields.key/value.string_value
TLSAuth additional.fields.key/value.string_value
TLSEncryptionAlgorithm additional.fields.key/value.string_value
TLSKeyExchange additional.fields.key/value.string_value
TLSVersion network.tls.version
ToZone additional.fields.key/value.string_value
Tpadding additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
Vpadding additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SourceDeviceCategory principal.asset.category
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Túnel

A tabela a seguir lista os campos de registro do tipo "Tunnel" e os campos correspondentes da UDM.

Log field UDM mapping
AccessPointName additional.fields.key/value.string_value
Action security_result.action
ActionSource additional.fields.key/value.string_value
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
BytesReceived network.received_bytes
BytesSent network.sent_bytes
Bytes additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
LoggingServiceID additional.fields.key/value.string_value
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MobileAreaCode additional.fields.key/value.string_value
MobileBaseStationCode additional.fields.key/value.string_value
MobileCountryCode additional.fields.key/value.string_value
MobileIP additional.fields.key/value.string_value
MobileNetworkCode additional.fields.key/value.string_value
MobileSubscriberISDN additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceDifferentiator additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsDroppedMax additional.fields.key/value.string_value
PacketsDroppedStrict additional.fields.key/value.string_value
PacketsDroppedTunnel additional.fields.key/value.string_value
PacketsDroppedProtocol additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
ProtocolDataUnitsessionID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
RadioAccessTechnology additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionStartTime additional.fields.key/value.string_value
SessionTracker additional.fields.key/value.string_value
Severity security_result.severity
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
StandardPortsOfApp additional.fields.key/value.string_value
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
SessionDuration network.session_duration
Tunnel additional.fields.key/value.string_value
TunnelCauseCode additional.fields.key/value.string_value
TunnelEndpointID1 additional.fields.key/value.string_value
TunnelEndpointID2 additional.fields.key/value.string_value
TunnelEventCode additional.fields.key/value.string_value
TunnelEventType additional.fields.key/value.string_value
TunnelInspectionRule additional.fields.key/value.string_value
TunnelInterface additional.fields.key/value.string_value
TunnelMessageType additional.fields.key/value.string_value
TunnelRemoteIMSIID additional.fields.key/value.string_value
TunnelRemoteUserIP principal.ip
TunnelSessionsClosed additional.fields.key/value.string_value
TunnelSessionsCreated additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLCategory target.url_metadata.categories
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Autenticação

A tabela a seguir lista os campos de registro do tipo "Registro de autenticação" e os campos correspondentes da UDM.

Log field UDM mapping
AuthenticationDescription security_result.description
AuthEvent metadata.description
AuthFactorNo security_result.detection_fields.key/value
AuthenticationPolicy security_result.detection_fields.key/value
AuthenticationProtocol additional.fields.key/value.string_value
AuthServerProfile additional.fields.key/value.string_value
AuthenticatedUserDomain target.administrative_domain
AuthenticatedUserName target.user.userid
AuthenticatedUserUUID target.user.product_object_id
ClientType additional.fields.key/value.string_value
ClientTypeName additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
IsPrismaNetworks additional.fields.key/value.string_value
Location target.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogType additional.fields.key/value.string_value
MFAAuthenticationID additional.fields.key/value.string_value
MFAVendor additional.fields.key/value.string_value
NormalizeUser target.user.user_display_name
Object target.resource.name
RuleMatched security_result.rule_name
RuleMatchedUUID security_result.rule_id
AuthCacheServiceRegion additional.fields.key/value.string_value
SessionID network.session_id
SourceDeviceCategory principal.asset.category
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceIP principal.ip
TimeGenerated metadata.event_timestamp
User target.user.userid
UserAgentString network.http.user_agent
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Subtype metadata.product_event_type
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

URL

A tabela a seguir lista os campos de registro do tipo de registro de URL e os campos correspondentes da UDM.

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
CloudHostname additional.fields.key/value.string_value
CloudReportID security_result.detection_fields.key/value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentType additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DirectionOfAttack security_result.detection_fields.key/value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
FileURL target.url
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HostID principal.asset.asset_id
HTTP2Connection network.application_protocol_version
HTTPHeaders additional.fields.key/value.string_value
HTTPMethod network.http.method
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
InlineMLVerdict additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
Packet additional.fields.key/value.string_value
PacketID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
Referer network.http.referral_url
HTTPRefererFQDN additional.fields.key/value.string_value
HTTPRefererPort additional.fields.key/value.string_value
HTTPRefererProtocol additional.fields.key/value.string_value
HTTPRefererURLPath additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionID network.session_id
Severity security_result.severity
SigFlags additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URL target.url_metadata.URL
URLCategory target.url_metadata.categories
URLCategoryList additional.fields.key/value.string_value
URLDomain target.domain.name
URLCounter additional.fields.key/value.string_value
UserAgent network.http.user_agent
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-For additional.fields.key/value.string_value
X-Forwarded-ForIP principal.ip

GlobalProtect

A tabela a seguir lista os campos de registro do tipo GlobalProtect e os campos correspondentes da UDM.

Log field UDM mapping
AttemptedGateways additional.fields.key/value.string_value
AuthMethod extensions.auth.auth_details
ConnectionMethod additional.fields.key/value.string_value
ConnectionErrorID additional.fields.key/value.string_value
ConnectionError additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
EndpointDeviceName principal.asset.hostname
GlobalProtectClientVersion additional.fields.key/value.string_value
EndpointOSType additional.fields.key/value.string_value
EndpointSN principal.asset.hardware.serial_number
EventIDValue additional.fields.key/value.string_value
Gateway target.resource.name
GatewayPriority additional.fields.key/value.string_value
GatewaySelectionType additional.fields.key/value.string_value
GlobalProtectGatewayLocation target.location.country_or_region
HostID principal.asset.asset_id
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LoginDuration network.session_duration
Description security_result.description
Portal target.hostname
PrivateIPv4 principal.ip
PrivateIPv6 principal.ip
ProjectName additional.fields.key/value.string_value
PublicIPv4 principal.nat_ip
PublicIPv6 principal.nat_ip
QuarantineReason security_result.summary
SequenceNo metadata.product_log_id
SourceRegion principal.location.country_or_region
SourceUserName principal.user.user_display_name
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SSLResponseTime additional.fields.key/value.string_value
Stage additional.fields.key/value.string_value
EventStatus additional.fields.key/value.string_value
LogSubtype metadata.product_event_type
TunnelType additional.fields.key/value.string_value
VirtualSystem intermediary.asset.attribute.labels
VirtualSystemName intermediary.asset.attribute.labels
EndpointOSVersion principal.platform_version
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType metadata.product_event_type
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualSystemID intermediary.resource.product_object_id

SCTP

A tabela a seguir lista os campos de registro do tipo de registro SCTP e os campos correspondentes da UDM.

Log field UDM mapping
Action security_result.action
Application target.application
AssocationEndReason additional.fields.key/value.string_value
ChunksReceived additional.fields.key/value.string_value
ChunksSent additional.fields.key/value.string_value
ChunksTotal additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceClass target.asset.category
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationIP target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DiamAppID additional.fields.key/value.string_value
DiamAvpCode additional.fields.key/value.string_value
DiameterCommandCode additional.fields.key/value.string_value
DiameterRequestFlag additional.fields.key/value.string_value
DeviceName principal.asset.hostname
SCTPEventType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLFiltering additional.fields.key/value.string_value
IsWildfire additional.fields.key/value.string_value
LogAction additional.fields.key/value.string_value
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MapAppCode additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PayloadProtocolID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
Rule security_result.rule_name
RuleUUID security_result.rule_id
SccpCallingGt additional.fields.key/value.string_value
SccpCallingSSN additional.fields.key/value.string_value
SctpCauseCode additional.fields.key/value.string_value
SctpChunkType additional.fields.key/value.string_value
SctpFilter additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionTracker additional.fields.key/value.string_value
Severity security_result.severity
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceIP principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VerificationTag1 additional.fields.key/value.string_value
VerificationTag2 additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Auditoria

A tabela a seguir lista os campos de registro do tipo "Registro de auditoria" e os campos correspondentes da UDM.

Log field UDM mapping
EventCategory network.http.method
EventDescription metadata.description
EventDestinationURL target.url
EventDestinationUserUserID target.user.userid
DestinationVendor additional.fields.key/value.string_value
EventDetails additional.fields.key/value.string_value
EventID metadata.product_log_id
EventName additional.fields.key/value.string_value
EventResult security_result.summary
EventSourceUserUserID principal.user.userid
EventTime metadata.event_timestamp
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
Subtype metadata.product_event_type
TSGID additional.fields.key/value.string_value
Vendor additional.fields.key/value.string_value
VendorSeverity security_result.severity_details

Referência de mapeamento de campos: tipos de registros para tipo de evento do UDM

A tabela a seguir lista os tipos de registro de firewall do serviço de registro do Strata da Palo Alto Networks e os tipos de evento UDM correspondentes.

Tipo de registro Tipo de evento do UDM
Tráfego NETWORK_CONNECTION
Ameaça NETWORK_CONNECTION
Filtragem de URL NETWORK_CONNECTION
Túnel NETWORK_CONNECTION
Sistema

Se o valor do subtipo for "dhcp", NETWORK_DHCP será definido.

Se o valor do subtipo for "auth", USER_LOGIN será definido.

Se o valor da descrição for "logged in", USER_LOGIN será definido.

Se o valor da descrição for "logged out", USER_LOGOUT será definido.

Para outros valores do subtipo, GENERIC_EVENT é definido.

Correspondência de HIP NETWORK_CONNECTION
Tag de IP GENERIC_EVENT
User-ID USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED

Se o valor do subtipo for "login", USER_LOGIN será definido.

Se o valor do subtipo for "logout", USER_LOGOUT será definido.

Se o subtipo não tiver nenhum valor, USER_UNCATEGORIZED será definido.

Descriptografia NETWORK_CONNECTION
Autenticação STATUS_UNCATEGORIZED
Globalprotect USER_LOGIN/USER_LOGOUT/USER_RESOURCE_ACCESS

Se o valor do subtipo for "auth", USER_LOGIN será definido.

Se o valor do subtipo for "logout", USER_LOGOUT será definido.

Se o subtipo não tiver um valor, USER_RESOURCE_ACCESS será definido.

SCTP NETWORK_CONNECTION
Auditoria NETWORK_CONNECTION

A seguir

Precisa de mais ajuda? Receba respostas de membros da comunidade e profissionais do Google SecOps.