Coletar registros de firewall da Palo Alto Networks
Firewall da Palo Alto Networks
Visão geral
Neste documento, descrevemos como configurar o syslog e um encaminhador do Google SecOps para coletar registros de firewall da Palo Alto Networks. Este documento também explica como os campos de registro do firewall da Palo Alto Networks são mapeados para os campos do modelo de dados unificado (UDM) do Google SecOps. Para uma visão geral sobre a ingestão de dados do Google SecOps, consulte Ingestão de dados no Google SecOps. Um rótulo de ingestão identifica o analisador que normaliza dados de registro brutos para o formato UDM estruturado. As informações neste documento se aplicam ao analisador com o rótulo de ingestão PAN_FIREWALL.
Antes de começar
- Verifique se o produto de firewall da Palo Alto Networks está implantado e configurado corretamente. Para instruções detalhadas de configuração, consulte a documentação do PAN-OS.
Para entender os componentes implantados para coletar registros do firewall da Palo Alto Networks, revise a arquitetura de implantação. Cada implantação de cliente pode ser diferente dessa representação e ser mais complexa. O diagrama a seguir mostra como configurar o syslog em um firewall da Palo Alto Networks e instalar um encaminhador do Google SecOps em um servidor Linux para encaminhar dados de registro ao Google SecOps. O analisador aceita registros gravados nos seguintes formatos de dados: valores separados por vírgula (CSV), formato de evento comum (CEF) e formato estendido de evento de registro (LEEF).
Verifique os formatos de registro e as versões do PAN-OS compatíveis com o analisador do Google SecOps. A tabela a seguir lista os formatos de registro e as versões correspondentes do PAN-OS compatíveis com o analisador do Google SecOps:
Formato do registro Versão do PAN-OS CSV 10.1.3 CEF 10.0.0 LEEF 9.1.0 Verifique os tipos de registros de firewall da Palo Alto Networks compatíveis com o analisador do Google SecOps. O analisador do Google SecOps é compatível com os seguintes tipos de registros de firewall da Palo Alto Networks:
- Tráfego
- Ameaça
- Envios do WildFire
- Inspeção de túnel
- Configuração
- Sistema
- Correspondência de HIP
- IP-Tag
- User-ID
- Descriptografia
- Autenticação
- Filtragem de URL
- Filtragem de dados
- GlobalProtect
- Correlação
- GTP
- SCTP
- Auditoria
Para mais informações sobre os tipos de registros de firewall da Palo Alto Networks, consulte Tipos de registros do PAN-OS.
Verifique se todos os sistemas na arquitetura de implantação estão configurados no fuso horário UTC.
Antes de usar o analisador de firewall da Palo Alto Networks, revise as mudanças nos mapeamentos de campos entre o analisador anterior e o atual analisador de firewall da Palo Alto Networks. Como parte da migração, verifique se as regras, pesquisas, painéis ou outros processos que dependem dos campos originais estão usando os campos atualizados.
Por exemplo, na versão anterior do analisador, o campo de registro
categoryé mapeado para o camposecurity_result.descriptionda UDM. No analisador atual do firewall da Palo Alto Networks, o campo de registrocategoryé mapeado para o camposecurity_result.category_detailsdo UDM. Se você migrar para o analisador de firewall atual da Palo Alto Networks e usar o campocategorynas suas regras, será necessário modificar as regras para usar o camposecurity_result.category_detailsda UDM do analisador atual.
Configurar o syslog e o encaminhador do Google Security Operations
Para configurar o syslog e o encaminhador do Google SecOps, siga estas etapas:
- Para monitorar registros CSV, configure o perfil do servidor syslog. Para mais informações, consulte Configurar o perfil do servidor syslog. Ao configurar o perfil do servidor syslog, especifique "Padrão" como o formato de registro personalizado.
- Para monitorar registros CEF, configure o firewall da Palo Alto Networks para encaminhar esses registros. Para mais informações, faça o download do PDF do guia de integração do CEF do PAN-OS e consulte a seção "Configuração do NGFW da Palo Alto Networks para gerar eventos CEF".
- Para monitorar registros LEEF, configure o perfil do servidor syslog. Para mais informações, consulte Encaminhamento de registros personalizados no formato LEEF.
Configure o encaminhador do Google SecOps para enviar registros ao Google Security Operations. Para mais informações, consulte Instalar e configurar o encaminhador no Linux. Confira a seguir um exemplo de configuração de encaminhador do Google SecOps:
- syslog: common: enabled: true data_type: PAN_FIREWALL batch_n_seconds: 10 batch_n_bytes: 1048576 tcp_address: 0.0.0.0:10518 connection_timeout_sec: 60
Configurar o encaminhamento de syslog no firewall da PAN
Criar um perfil de servidor syslog
- Faça login no Console de gerenciamento de firewall da Palo Alto Networks.
- Acesse Dispositivo > Perfis de servidor > Syslog.
- Clique em Adicionar para criar um perfil de servidor.
- Informe os seguintes detalhes de configuração:
- Nome: insira um nome descritivo, por exemplo,
Google SecOps BindPlane. - Local: selecione o sistema virtual (vsys) ou Compartilhado em que esse perfil vai estar disponível.
- Nome: insira um nome descritivo, por exemplo,
- Clique em Servidores > Adicionar para configurar o servidor syslog.
- Forneça os seguintes detalhes de configuração do servidor:
- Nome: insira um nome descritivo para o servidor. Por exemplo,
BindPlane Agent. - Servidor Syslog: insira o endereço IP do agente do BindPlane.
- Transporte: selecione UDP ou TCP, dependendo da configuração do agente do BindPlane (UDP é o padrão).
- Porta: insira o número da porta do agente do BindPlane (por exemplo,
514). - Formato: selecione BSD (padrão) ou IETF, dependendo dos seus requisitos.
- Facilidade: selecione LOG_USER (padrão) ou outra facilidade, conforme necessário.
- Nome: insira um nome descritivo para o servidor. Por exemplo,
- Clique em OK para salvar o perfil do servidor syslog.
Opcional: configurar um formato de registro personalizado para CEF ou LEEF
Se você precisar de registros CEF (Common Event Format) ou LEEF (Log Event Extended Format) em vez de CSV:
- No perfil do servidor Syslog, selecione a guia Formato de registro personalizado.
- Configure o formato de registro personalizado para cada tipo de registro (Config, System, Threat, Traffic, URL, Data, WildFire, Tunnel, Authentication, User-ID, HIP Match).
- Para configurar o formato CEF, consulte o Guia de configuração do CEF da Palo Alto Networks (em inglês).
- Clique em OK para salvar a configuração.
Criar um perfil de encaminhamento de registros
- Acesse Objetos > Encaminhamento de registros.
- Clique em Adicionar para criar um perfil de encaminhamento de registros.
- Informe os seguintes detalhes de configuração:
- Nome: insira um nome de perfil (por exemplo,
Google SecOps Forwarding). Se você quiser que o firewall atribua automaticamente esse perfil a novas regras e zonas de segurança, nomeie-o comodefault.
- Nome: insira um nome de perfil (por exemplo,
- Para cada tipo de registro que você quer encaminhar (tráfego, ameaça, envio do WildFire, filtragem de URL, filtragem de dados, túnel, autenticação), configure o seguinte:
- Clique em Adicionar na seção do tipo de registro relevante.
- Syslog: selecione o perfil do servidor syslog que você criou (por exemplo,
Google SecOps BindPlane). - Gravidade do registro: selecione os níveis de gravidade a serem encaminhados (por exemplo, Todos).
- Clique em OK para salvar o perfil de encaminhamento de registros.
Aplicar perfil de encaminhamento de registros a políticas de segurança
- Acesse Políticas > Segurança.
- Selecione as regras de segurança para as quais você quer ativar o encaminhamento de registros.
- Clique na regra para editá-la.
- Acesse a guia Ações.
- No menu Encaminhamento de registros, selecione o perfil de encaminhamento de registros que você criou (por exemplo,
Google SecOps Forwarding). - Clique em OK para salvar a configuração da política de segurança.
Configurar as configurações de registro para registros do sistema
- Acesse Dispositivo > Configurações de registro.
- Para cada tipo de registro (System, Configuration, User-ID, HIP Match, Global Protect, IP-Tag, SCTP) e nível de gravidade, selecione o perfil do servidor syslog que você criou.
- Clique em OK para salvar as configurações de registro.
Confirmar as mudanças
- Clique em Commit na parte de cima da interface da Web do firewall.
- Aguarde a conclusão do commit.
- Verifique se os registros estão sendo enviados ao agente do Bindplane conferindo no console do Google SecOps os registros de firewall da Palo Alto Networks recebidos.
Encaminhar registros para o Google SecOps usando o agente do Bindplane
- Instale e configure uma máquina virtual Linux.
- Instale e configure o agente do Bindplane no Linux para encaminhar registros ao Google SecOps. Para mais informações sobre como instalar e configurar o agente do Bindplane, consulte as instruções de instalação e configuração do agente do Bindplane.
Se você tiver problemas ao criar feeds, entre em contato com o suporte do Google SecOps.
Formatos de registro aceitos
O analisador de firewall da Palo Alto Networks é compatível com registros nos formatos LEEF,CEF e CSV.
Registros de amostra compatíveis
LEEF
<14>Jan 22 02:20:19 device_host LEEF:1.0|Palo Alto Networks|PAN-OS Syslog Integration|10.2.12-h4|Microsoft MSOFFICE(52033)|ReceiveTime=2025/01/22 02:20:18|SerialNumber=01250100xxxx|cat=THREAT|Subtype=wildfire|devTime=Jan 22 2025 08:20:18 GMT|src=198.50.100.1|dst=198.50.100.2|srcPostNAT=198.50.100.3|dstPostNAT=198.50.100.4|RuleName=AZURE-US-NEW-CNF_Inbound_To_Azure-ALLOW|usrName=|SourceUser=|DestinationUser=|Application=smtp-base|VirtualSystem=vsys1|SourceZone=McD-Global-Zone|DestinationZone=Azure-Zone|IngressInterface=ae1.111|EgressInterface=ae2.409|LogForwardingProfile=Default-Traffic-Logging|SessionID=35331795|RepeatCount=1|srcPort=21578|dstPort=25|srcPostNATPort=0|dstPostNATPort=0|Flags=0x2000|proto=tcp|action=allow|Miscellaneous=\"......3...................xls\"|ThreatID=Microsoft MSOFFICE(52033)|URLCategory=malicious|sev=4|Severity=high|Direction=client-to-server|sequence=7462614601465681755|ActionFlags=0x8000000000000000|SourceLocation=198.50.100.1-198.50.100.255|DestinationLocation=United States|ContentType=|PCAP_ID=0|FileDigest=0ea04c99bf188c2e4207f60f92ca7c6f5088c7943ee63f45c50032bbd2bf7ea9|Cloud=demo.com|URLIndex=1|RequestMethod=|FileType=ms-office|Sender=sender@ab.myownpersonaldomain.com|Subject=\"............:.................................................................................-.........(Name)-2025-01-22...............:Y107202501220005, ............:........................, ...............:.........\"|Recipient=abc@demo.myownpersonaldomain.com|ReportID=117022282776|DeviceGroupHierarchyL1=143|DeviceGroupHierarchyL2=144|DeviceGroupHierarchyL3=39|DeviceGroupHierarchyL4=0|vSrcName=|DeviceName=device_host|SrcUUID=|DstUUID=|TunnelID=0|MonitorTag=|ParentSessionID=0|ParentStartTime=|TunnelType=N/A|ThreatCategory=N/A|ContentVer=WildFire-0CEF
14>1 2024-04-04T16:21:56+02:00 FW-PERIMETRAL-AVG-01 - - - - CEF:0|Palo Alto Networks|PAN-OS|10.1.10-h2|end|TRAFFIC|1|src=198.51.100.1 dst=198.51.100.2 srcTranslatedAddress=198.51.100.3 dstTranslatedAddress=198.51.100.4 rule=FW_USER_NATS2_APP suser= duser= app=bittorrent vs=vsys1 sz=INSIDE dz=EXTERNAL InboundInterface=ae2.2266 OutboundInterface=ae1 lp=log_forwarding sid=2935823 cnt=1 spt=6881 dpt=51413 srcTranslatedPort=0 dstTranslatedPort=0 flags=0x7a proto=udp act=allow tbytes=475 in=150 out=325 pkt=2 pktReceived=1 pktSent=1 start=Apr 04 2024 14:21:56 GMT stime=1206 urlcat=any externalId=externalId reason=aged-out DGl1=11 DGl2=161 DGl3=0 DGl4=0 VsysName=STONESOFT dvchost=FW-PERIMETRAL-AVG-01 cat=from-policy ActionFlags=0x8000000000000000 srcUUID= dstUUID= TunnelID=0 MonitorTag= ParentSessionID=0 ParentStartTime= TunnelType=N/A SCTPAssocID=0 SCTPChunks=0 SCTPChunkSent=0 SCTPChunksRcv=0 RuleUUID=746c3eb6-3d51-4679-8438-bd0e00e170a8 HTTP2Con=0 LinkChange=0 PolicyID= LinkDetail= SDWANCluster= SDWANDevice= SDWANClustype= SDWANSite= DynamicUsrgrp= XFFIP= srcDevCat= srcDevProf= srcDevModel= srcDevVendor= srcDevOS= srcDevOSv= srcHostname= srcMac= dstDevCat= dstDevProf= dstDevModel= dstDevVendor= dstDevOS= dstDevOSv= dstHostname= dstMac= ContainerName= PODNamespace= PODName= srcEDL= dstEDL= GPHostID= EPSerial= srcDAG= dstDAG= HASessionOwner= TimeHighRes=2024-04-04T16:21:56.250+02:00 ASServiceType= ASServiceDiff="CSV
1,2021/10/24 15:30:07,,CONFIG,0,2561,2021/10/24 15:30:07,198.51.100.0,,set,admin,Web,Succeeded, network virtual-router VR1,,VR1 { ecmp { algorithm { ip-modulo ; } } protocol { bgp { routing-options { graceful-restart { enable yes; } } enable no; } rip { enable no; } ospf { enable no; } ospfv3 { enable no; } } routing-table { ip { static-route { vr1-log { path-monitor { enable no; failure-condition any; hold-time 2; } nexthop { ip-address 198.51.100.0; } bfd { profile None; } interface ethernet1/1; metric 10; destination 0.0.0.0/0; route-table { unicast ; } } } } } interface [ ethernet1/1 ethernet1/2 ]; } ,7022390503849066572,0x0,0,0,0,0,,PA-VM,0,
Referência de mapeamento de campos: campos de registros para campos da UDM
Esta seção explica como o analisador mapeia os campos de registro do firewall da Palo Alto Networks para os campos de eventos do UDM do Google SecOps em cada tipo de registro. A chave de rótulo do Google SecOps se refere ao nome da chave mapeada para o campo UDM "Labels.key".
Por exemplo, no caso do campo "Sistema virtual", o nome do campo é "cs3" no formato CEF e "VirtualSystem" no formato LEEF. O campo da UDM "about.labels.key" contém o valor "vsys", e o campo "about.labels.value" contém o valor desse campo. Alguns nomes de campos CEF ou LEEF não têm um nome correspondente aos nomes de campos CSV. Nesses casos, se você adicionar seu próprio nome de variável no formato de registro personalizado no perfil do syslog, o analisador não vai mapeá-lo para o campo do UDM.
Consulte as seções a seguir para ver a referência de mapeamento de cada tipo de registro:
- Sistema
- Config
- Ameaça/incêndio florestal
- Tráfego
- ID do usuário
- Correspondência de HIP
- Tag de IP
- Descriptografia
- Tunnel
- Authentication
- URL
- Dados
- GlobalProtect
- Correlação
- GTP
- SCTP
- Auditoria
Sistema
A tabela a seguir lista os campos de registro do tipo de registro do sistema e os campos correspondentes da UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave do rótulo do Google Security Operations | Campo do UDM |
|---|---|---|---|---|
| Horário de recebimento (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|
| Número de série (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Type (tipo) | type (Header) | gato | metadata.product_event_type está definido como "%{type} - %{subtype}". | |
| Tipo de ameaça/conteúdo (subtipo) | subtype (cabeçalho) | Subtipo | metadata.product_event_type está definido como "%{type} - %{subtype}". | |
| Horário gerado (time_generated ou cef-formatted-time_generated) | metadata.event_timestamp | |||
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| ID do evento (eventid) | gato | eventid | additional.fields.key e additional.fields.value.string_value | |
| Objeto (objeto) | fname | Nome do arquivo | objeto | target.resource.name |
| Módulo (módulo) | flexString2 | Módulo | module | additional.fields.key e additional.fields.value.string_value |
| Gravidade (severity) | $number-of-severity(header) | Gravidade | security_result.severity e security_result.severity_details | |
| Descrição (opaca) | msg | msg | metadata.description | |
| principal_user_userid (extraído do campo "msg") | principal.user.userid | |||
| principal_ip3 (extraído do campo "msg") | principal.ip | |||
| Motivo (este campo é extraído do campo "msg") | security_result.description | |||
| server_address (este campo é extraído do campo "msg"). | target.ip | |||
| server_profile (esse campo é extraído do campo "msg") | additional.fields.key e additional.fields.value.string_value | |||
| Número de sequência (seqno) | externalId | sequência | metadata.product_log_id | |
| Flags de ação (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupos de dispositivos (dg_hier_level_1 a dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupos de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome do sistema virtual (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nome do dispositivo (device_name) | dvchost | DeviceName | target.hostname | |
| Carimbo de data/hora de alta resolução (high_res_timestamp) | anOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value |
Configuração
A tabela a seguir lista os campos de registro do tipo de registro de configuração e os campos da UDM correspondentes.
| Campo CSV | Campo CEF | Campo LEEF | Chave do rótulo do Google Security Operations | Campo do UDM |
|---|---|---|---|---|
| Horário de recebimento (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|
| Número de série (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Type (tipo) | type (Header) | gato | metadata.product_event_type | |
| Tipo de ameaça/conteúdo (subtipo) | subtype (cabeçalho) | metadata.product_event_type | ||
| Horário gerado (time_generated ou cef-formatted-time_generated) | metadata.event_timestamp | |||
| Host (host) | shost | src | principal.ip/hostname | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| Comando (cmd) | age | msg | cmd | principal.process.command_line |
| Administrador (admin) | duser | usrName | principal.user.userid | |
| Cliente (cliente) | destinationServiceName | cliente | principal.application | |
| Resultado (result) | ID da assinatura (cabeçalho)(motivo) | Resultado | security_result.summary | |
| Caminho de configuração (caminho) | msg | ConfigurationPath | principal.process.command_line | |
| Detalhe antes da mudança (before_change_detail) | cs1 | BeforeChangeDetail | before_change_detail | target.resource.attribute.labels.key/value |
| Detalhe após a mudança (after_change_detail) | cs2 | AfterChangeDetail | after_change_detail | target.resource.attribute.labels.key/value |
| Número de sequência (seqno) | externalId | sequência | metadata.product_log_id | |
| Flags de ação (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupos de dispositivos (dg_hier_level_1 a dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupos de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome do sistema virtual (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nome do dispositivo (device_name) | dvchost | DeviceName | target.hostname | |
| Grupo de dispositivos (dg_id) | PanOSFWDeviceGroup | target.asset.attribute.labels.key/value | dg_id | principal.asset.attribute.labels.key/value |
| Comentário de auditoria (comment) | PanOSPolicyAuditComment | comentário | additional.fields.key e additional.fields.value.string_value | |
| Carimbo de data/hora de alta resolução (high_res_timestamp) | additional.fields.key e additional.fields.value.string_value | |||
| Gravidade (severity) | number-of-severity(header) | security_result.severity e security_result.severity_details |
Ameaça/WildFire
A tabela a seguir lista os campos de registro do tipo de registro de ameaça/WildFire e os campos correspondentes da UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave do rótulo do Google Security Operations | Campo do UDM |
|---|---|---|---|---|
| Horário de recebimento (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|
| Número de série | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Type (tipo) | type (Header) | gato | metadata.product_event_type | |
| Tipo de ameaça/conteúdo (subtipo) | cat/subtype (cabeçalho) | Subtipo | metadata.product_event_type | |
| Geração de tempo (time_generated ou cef-formatted-time_generated) | metadata.event_timestamp | |||
| Endereço de origem (src) | src | src | principal.ip | |
| Endereço de destino (dst) | dst | dst | target.ip | |
| IP de origem NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP de destino NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Nome da regra (regra) | cs1 | RuleName | security_result.rule_name | |
| Usuário de origem (srcuser) | suser | SourceUser / usrName | principal.user.userid | |
| Usuário de destino (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplicativo | app | Aplicativo | target.application | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona de origem (de) | cs4 | SourceZone | de | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Zona de destino (para) | cs5 | DestinationZone | a | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Interface de entrada (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Interface de saída (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Ação de registro (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key e additional.fields.value.string_value |
| ID da sessão (sessionid) | cn1 | SessionID | network.session_id | |
| Contagem de repetições (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Porta de origem (sport) | spt | srcPort | principal.port | |
| Porta de destino (dport) | dpt | dstPort | target.port | |
| Porta de origem NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Porta de destino NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Flags (flags) | flexString1 | Flags | flags | additional.fields.key e additional.fields.value.string_value |
| Protocolo IP (proto) | proto | proto | network.ip_protocol | |
| Ação (action) | age | ação | security_result.action_details
security_result.action |
|
| URL/nome do arquivo (variados) | solicitação | Diversos | target.file.names (se o subtipo for "file", "virus", "wildfire-virus" ou "wildfire", o campo "misc" será mapeado para target.file.names) target.url (se o subtipo for "url", o campo "misc" será mapeado para target.url e target.hostname) |
|
| Nome da ameaça/do conteúdo (threatid) | gato | ThreatID | security_result.threat_name | |
| Categoria (category) | cs2 | URLCategory | security_result.category_details | |
| Gravidade (severity) | number-of-severity(header) | Gravidade | security_result.severity e security_result.severity_details | |
| Direção (direction) | flexString2 | Direção | network.direction | |
| Número de sequência (seqno) | externalId | sequência | metadata.product_log_id | |
| Flags de ação (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| País de origem (srcloc) | SourceLocation | principal.location.country_or_region | ||
| País de destino (dstloc) | DestinationLocation | target.location.country_or_region | ||
| Tipo de conteúdo (contenttype) | ContentType | contenttype | additional.fields.key e additional.fields.value.string_value | |
| ID do PCAP (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key e additional.fields.value.string_value |
| Resumo de arquivo (filedigest) | fileHash | FileDigest | target.file.sha1/md5/sha256 | |
| Nuvem (nuvem) | filePath | Cloud | nuvem | additional.fields.key e additional.fields.value.string_value |
| Índice de URL (url_idx) | URLIndex | url_idx | additional.fields.key e additional.fields.value.string_value | |
| User agent (user_agent) | network.http.user_agent | |||
| Tipo de arquivo (filetype) | fileType | FileType | target.file.mime_type | |
| X-Forwarded-For (xff) | principal.ip | |||
| Referenciador (referer) | network.http.referral_url | |||
| Remetente (sender) | suid | Remetente | network.email.from | |
| Assunto (subject) | msg | Assunto | network.email.subject | |
| Destinatário (destinatário) | duid | Destinatário | network.email.to | |
| ID do relatório (reportid) | oldFileId | ReportID | reportid | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupos de dispositivos (dg_hier_level_1 a dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupos de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome do sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nome do dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| UUID da VM de origem (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id | |
| UUID da VM de destino (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id | |
| Método HTTP (http_method) | RequestMethod | network.http.method | ||
| ID/IMSI do túnel (tunnel_id/imsi) | PanOSTunnelID | TunnelID | tunnel_id/imsi | additional.fields.key e additional.fields.value.string_value |
| Monitorar tag/IMEI (monitortag/imei) | PanOSMonitorTag | MonitorTag | monitortag/imei | additional.fields.key e additional.fields.value.string_value |
| ID da sessão principal (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Horário de início da sessão principal (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key e additional.fields.value.string_value |
| Tipo de túnel (túnel) | PanOSTunnelType | TunnelType | túnel | additional.fields.key e additional.fields.value.string_value |
| Categoria da ameaça (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| Versão do conteúdo (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key e additional.fields.value.string_value |
| ID da associação SCTP (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key e additional.fields.value.string_value | |
| ID do protocolo de payload (ppid) | PanOSPPID | ppid | additional.fields.key e additional.fields.value.string_value | |
| Cabeçalhos HTTP (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Lista de categorias de URL (url_category_list) | PanOSURLCatList | url_category_list | additional.fields.key e additional.fields.value.string_value | |
| UUID da regra (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| Conexão HTTP/2 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| Nome do grupo dinâmico de usuários (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Endereço XFF (xff_ip) | PanXFFIP | principal.ip | ||
| Categoria do dispositivo de origem (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Perfil do dispositivo de origem (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modelo do dispositivo de origem (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Fornecedor do dispositivo de origem (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Família do SO do dispositivo de origem (src_osfamily) | PanSrcDeviceOS | src_osfamily | principal.platform | |
| Versão do SO do dispositivo de origem (src_osversion) | PanSrcDeviceOSv | principal.platform_version | ||
| Nome do host de origem (src_host) | PanSrcHostname | principal.hostname | ||
| Endereço MAC de origem (src_mac) | PanSrcMac | principal.mac | ||
| Categoria do dispositivo de destino (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Perfil do dispositivo de destino (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modelo do dispositivo de destino (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Fornecedor do dispositivo de destino (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Família do SO do dispositivo de destino (dst_osfamily) | PanDstDeviceOS | dst_osfamily | target.platform | |
| Versão do SO do dispositivo de destino (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Nome do host de destino (dst_host) | PanDstHostname | target.hostname | ||
| Endereço MAC de destino (dst_mac) | PanDstMac | target.mac | ||
| ID do contêiner (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| Namespace do POD (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| Nome do POD (pod_name) | PanPODName | pod_name | target.resource.name | |
| Lista dinâmica externa de origem (src_edl) | PanSrcEDL | src_edl | additional.fields.key e additional.fields.value.string_value | |
| Lista dinâmica externa de destino (dst_edl) | PanDstEDL | dst_edl | additional.fields.key e additional.fields.value.string_value | |
| ID do host (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Número de série do dispositivo do usuário (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| EDL de domínio (domain_edl) | PanDomainEDL | domain_edl | additional.fields.key e additional.fields.value.string_value | |
| Grupo de endereços dinâmicos de origem (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Grupo de endereços dinâmicos de destino (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| Hash parcial (partial_hash) | PanPartialHash | partial_hash | additional.fields.key e additional.fields.value.string_value | |
| Carimbo de data/hora de alta resolução (high_res timestamp) | PanTimeHighRes | timestamp de alta resolução | additional.fields.key e additional.fields.value.string_value | |
| Motivo (reason) | PanReasonFilteringAction | reason | security_result.summary | |
| Justificativa (justification) | PanJustification | justificativa | additional.fields.key e additional.fields.value.string_value | |
| Um tipo de serviço de intervalo (nssai_sst) | PanASServiceType | nssai_sst | additional.fields.key e additional.fields.value.string_value | |
| Subcategoria do aplicativo (subcategory_of_app) | subcategory_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Categoria do aplicativo (category_of_app) | category_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia de aplicativos (technology_of_app) | technology_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Risco do aplicativo (risk_of_app) | risk_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Característica do aplicativo (characteristic_of_app) | characteristic_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Contêiner do aplicativo (container_of_app) | container_of_app | additional.fields.key e additional.fields.value.string_value | ||
| SaaS de aplicativo (is_saas_of_app) | is_saas_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Aplicativo em túnel (tunneled_app) | additional.fields.key e additional.fields.value.string_value | |||
| Tipo de fluxo (flow_type) | additional.fields.key e additional.fields.value.string_value | |||
| Nome do cluster (cluster_name) | intermediary.resource.name | |||
| Estado de sanção do aplicativo (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key e additional.fields.value.string_value |
Tráfego
A tabela a seguir lista os campos de registro do tipo de registro de tráfego e os campos correspondentes da UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave do rótulo do Google Security Operations | Campo do UDM |
|---|---|---|---|---|
| Horário de recebimento (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|
| Número de série (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Type (tipo) | type (Header) | cat/Type | metadata.product_event_type | |
| Tipo de ameaça/conteúdo (subtipo) | subtype (cabeçalho) | Subtipo | metadata.product_event_type | |
| Horário gerado (time_generated ou cef-formatted-time_generated) | start | metadata.event_timestamp | ||
| Endereço de origem (src) | src | src | principal.ip | |
| Endereço de destino (dst) | dst | dst | target.ip | |
| IP de origem NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP de destino NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Nome da regra (regra) | cs1 | RuleName | security_result.rule_name | |
| Usuário de origem (srcuser) | suser | SourceUser | principal.user.userid | |
| Usuário de destino (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplicativo | app | Aplicativo | target.application | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona de origem (de) | cs4 | SourceZone | de | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Zona de destino (para) | cs5 | DestinationZone | a | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Interface de entrada (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Interface de saída (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Ação de registro (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key e additional.fields.value.string_value |
| ID da sessão (sessionid) | cn1 | SessionID | network.session_id | |
| Contagem de repetições (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Porta de origem (sport) | spt | srcPort | principal.port | |
| Porta de destino (dport) | dpt | dstPort | target.port | |
| Porta de origem NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Porta de destino NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Flags (flags) | flexString1 | Flags | flags | additional.fields.key e additional.fields.value.string_value |
| Protocolo IP (proto) | proto | proto | network.ip_protocol | |
| Ação (action) | age | ação | security_result.action_details
security_result.action |
|
| Bytes (bytes) | flexNumber1 | totalBytes | bytes | additional.fields.key e additional.fields.value.string_value |
| Bytes enviados (bytes_sent) | em | srcBytes | network.sent_bytes | |
| Bytes recebidos (bytes_received) | out | dstBytes | network.received_bytes | |
| Pacotes (pacotes) | cn2 | totalPackets | pacotes | additional.fields.key e additional.fields.value.string_value |
| Horário de início (start) | StartTime | start | additional.fields.key e additional.fields.value.string_value | |
| Tempo decorrido (decorrido) | cn3 | ElapsedTime | decorrido | network.session_duration.seconds |
| Categoria (category) | cs2 | URLCategory | security_result.category / security_result.category_details | |
| Número de sequência (seqno) | externalId | sequência | metadata.product_log_id | |
| Flags de ação (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| País de origem (srcloc) | SourceLocation | principal.location.country_or_region | ||
| País de destino (dstloc) | DestinationLocation | target.location.country_or_region | ||
| Pacotes enviados (pkts_sent) | PanOSPacketsSent | srcPackets | pkts_sent | network.sent_packets |
| Pacotes recebidos (pkts_received) | PanOSPacketsReceived | dstPackets | pkts_received | network.received_packets |
| Motivo do término da sessão (session_end_reason) | reason | SessionEndReason | security_result.summary | |
| Hierarquia do grupo de dispositivos 1 (dg_hier_level_1 a dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupo de dispositivos 2 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupo de dispositivos 3 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome do sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nome do dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| Origem da ação (action_source) | gato | ActionSource | action_source | additional.fields.key e additional.fields.value.string_value |
| UUID da VM de origem (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id | |
| UUID da VM de destino (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id | |
| ID do túnel/IMSI (tunnelid/imsi) | PanOSTunnelID | TunnelID | tunnelid/imsi | additional.fields.key e additional.fields.value.string_value |
| Monitorar tag/IMEI (monitortag/imei) | PanOSMonitorTag | MonitorTag | monitortag/imei | additional.fields.key e additional.fields.value.string_value |
| ID da sessão principal (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Horário de início da atividade principal (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key e additional.fields.value.string_value |
| Tipo de túnel (túnel) | PanOSTunnelType | TunnelType | túnel | additional.fields.key e additional.fields.value.string_value |
| ID da associação SCTP (assoc_id) | PanOSSCTPAssocID | assoc_id | additional.fields.key e additional.fields.value.string_value | |
| Fragmentos SCTP (fragmentos) | PanOSSCTPChunks | pedaços | additional.fields.key e additional.fields.value.string_value | |
| Fragmentos SCTP enviados (chunks_sent) | PanOSSCTPChunkSent | chunks_sent | additional.fields.key e additional.fields.value.string_value | |
| Blocos SCTP recebidos (chunks_received) | PanOSSCTPChunksRcv | chunks_received | additional.fields.key e additional.fields.value.string_value | |
| UUID da regra (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| Conexão HTTP/2 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| Contagem de flaps do app (link_change_count) | PanLinkChange | link_change_count | additional.fields.key e additional.fields.value.string_value | |
| ID da política (policy_id) | PanPolicyID | policy_id | additional.fields.key e additional.fields.value.string_value | |
| Chaves de link (link_switches) | PanLinkDetail | link_switches | additional.fields.key e additional.fields.value.string_value | |
| Cluster SD-WAN (sdwan_cluster) | PanSDWANCluster | sdwan_cluster | additional.fields.key e additional.fields.value.string_value | |
| Tipo de dispositivo SD-WAN (sdwan_device_type) | PanSDWANDevice | sdwan_device_type | additional.fields.key e additional.fields.value.string_value | |
| Tipo de cluster SD-WAN (sdwan_cluster_type) | PanSDWANClustype | sdwan_cluster_type | additional.fields.key e additional.fields.value.string_value | |
| Site SD-WAN (sdwan_site) | PanSDWANSite | sdwan_site | additional.fields.key e additional.fields.value.string_value | |
| Nome do grupo dinâmico de usuários (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | additional.fields.key e additional.fields.value.string_value | |
| Endereço XFF (xff_ip) | PanXFFIP | principal.ip | ||
| Categoria do dispositivo de origem (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Perfil do dispositivo de origem (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modelo do dispositivo de origem (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Fornecedor do dispositivo de origem (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Família do SO do dispositivo de origem (src_osfamily) | PanSrcDeviceOS | principal.platform | ||
| Versão do SO do dispositivo de origem (src_osversion) | PanSrcDeviceOSv | principal.asset.software.version | ||
| Nome do host de origem (src_host) | PanSrcHostname | principal.hostname | ||
| Endereço MAC de origem (src_mac) | PanSrcMac | principal.mac | ||
| Categoria do dispositivo de destino (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Perfil do dispositivo de destino (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modelo do dispositivo de destino (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Fornecedor do dispositivo de destino (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Família do SO do dispositivo de destino (dst_osfamily) | PanDstDeviceOS | dst_osfamily | target.platform | |
| Versão do SO do dispositivo de destino (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Nome do host de destino (dst_host) | PanDstHostname | target.hostname | ||
| Endereço MAC de destino (dst_mac) | PanDstMac | target.mac | ||
| ID do contêiner (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| Namespace do POD (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| Nome do POD (pod_name) | PanPODName | pod_name | target.resource.name | |
| Lista dinâmica externa de origem (src_edl) | PanSrcEDL | src_edl | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Lista dinâmica externa de destino (dst_edl) | PanDstEDL | dst_edl | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| ID do host (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Número de série do dispositivo do usuário (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| Grupo de endereços dinâmicos de origem (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Grupo de endereços dinâmicos de destino (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| Proprietário da sessão (session_owner) | PanHASessionOwner | session_owner | additional.fields.key e additional.fields.value.string_value | |
| Carimbo de data/hora de alta resolução (high_res_timestamp) | PanTimeHighRes | additional.fields.key e additional.fields.value.string_value | ||
| Um tipo de serviço de fração (nsdsai_sst) | PanASServiceType | nsdsai_sst | additional.fields.key e additional.fields.value.string_value | |
| Um diferenciador de fração (nsdsai_sd) | PanASServiceDiff | nsdsai_sd | additional.fields.key e additional.fields.value.string_value | |
| Subcategoria do aplicativo (subcategory_of_app) | subcategory_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Categoria do aplicativo (category_of_app) | category_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia de aplicativos (technology_of_app) | technology_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Risco do aplicativo (risk_of_app) | security_result.severity | |||
| Característica do aplicativo (characteristic_of_app) | characteristic_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Contêiner do aplicativo (container_of_app) | container_of_app | additional.fields.key e additional.fields.value.string_value | ||
| SaaS de aplicativo (is_saas_of_app) | is_saas_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Estado de sanção do aplicativo (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Subcategoria do aplicativo (subcategory_of_app) | subcategory_of_app1 | additional.fields.key e additional.fields.value.string_value | ||
| Gravidade (severity) | number-of-severity(header) | security_result.severity e security_result.severity_details |
User-ID
A tabela a seguir lista os campos de registro do tipo de registro user-id e os campos correspondentes da UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave do rótulo do Google Security Operations | Campo do UDM |
|---|---|---|---|---|
| Horário de recebimento (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|
| Número de série (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Type (tipo) | type (Header) | gato | metadata.product_event_type | |
| Tipo de ameaça/conteúdo (subtipo) | subtype (cabeçalho) | Subtipo | metadata.product_event_type | |
| Horário gerado (time_generated ou cef-formatted-time_generated) | metadata.event_timestamp | |||
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| IP de origem (ip) | src | src | principal.ip | |
| Usuário (user) | duser | usrName | target.user.userid
target.administrative_domain target.user.email_addresses |
|
| Nome da fonte de dados (datasourcename) | cs4 | DataSourceName | datasourcename | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| ID do evento (eventid) | EventID | eventid | additional.fields.key e additional.fields.value.string_value | |
| Contagem de repetições (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Limite de tempo limite | cn3 | TimeoutThreshold | timeout | additional.fields.key e additional.fields.value.string_value |
| Porta de origem (beginport) | spt | srcPort | principal.port | |
| Porta de destino (endport) | dpt | dstPort | target.port | |
| Fonte de dados | cs5 | DataSource | fonte de dados | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Tipo de fonte de dados (datasourcetype) | cs6 | DataSourceType | datasourcetype | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Número de sequência (seqno) | externalId | sequência | metadata.product_log_id | |
| Flags de ação (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupos de dispositivos (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupos de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome do sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nome do dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| ID do sistema virtual (vsys_id) | cn2 | VirtualSystemID | intermediary.resource.product_object_id | |
| Tipo de fator (factortype) | cs1 | FactorType | factortype | additional.fields.key e additional.fields.value.string_value |
| Tempo de conclusão do fator (factorcompletiontime) | end | FactorCompletionTime | factorcompletiontime | additional.fields.key e additional.fields.value.string_value |
| Número do fator (factorno) | cn1 | FactorNumber | factorno | additional.fields.key e additional.fields.value.string_value |
| Flags de grupo de usuários (ugflags) | PanOSUGFlags | ugflags | additional.fields.key e additional.fields.value.string_value | |
| Usuário por origem (userbysource) | PanOSUserBySource | target.user.userid
target.administrative_domain target.user.email_addresses |
||
| Carimbo de data/hora de alta resolução (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value | ||
| Fonte de dados de origem (origindatasource) | additional.fields.key e additional.fields.value.string_value | |||
| Nome do cluster (cluster_name) | principal.resource.name | |||
| Gravidade (severity) | number-of-severity(header) | security_result.severity e security_result.severity_details |
Correspondência de HIP
A tabela a seguir lista os campos de registro do tipo de registro de correspondência do HIP e os campos correspondentes da UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave do rótulo do Google Security Operations | Campo do UDM |
|---|---|---|---|---|
| Horário de recebimento (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|
| Número de série (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Type (tipo) | type (Header) | gato | metadata.product_event_type | |
| Tipo de ameaça/conteúdo (subtipo) | subtype (cabeçalho) | Subtipo | ||
| Horário gerado (time_generated ou cef-formatted-time_generated) | start | startTime | metadata.event_timestamp | |
| Usuário de origem (srcuser) | suser | usrName | principal.user.userid | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| Nome da máquina (machinename) | shost | identHostName | principal.hostname | |
| Sistema operacional (os) | cs2 | SO | principal.asset.platform_software.platform | |
| Endereço de origem (src) | src | identsrc | principal.ip | |
| HIP (matchname) | gato | HIP | matchname | target.resource.attribute.labels.key/value additional.fields.key e additional.fields.value.string_value |
| Contagem de repetições (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Tipo de HIP (matchtype) | ID da classe de evento do dispositivo (cabeçalho) | HIPType | matchtype | target.resource.attribute.labels.key/value additional.fields.key e additional.fields.value.string_value |
| Número de sequência (seqno) | externalId | sequência | metadata.product_log_id | |
| Flags de ação (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupos de dispositivos (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupos de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome do sistema virtual (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nome do dispositivo (device_name) | dvchost | DeviceName | target.hostname | |
| ID do sistema virtual (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id | |
| Endereço IPv6 do sistema (srcipv6) | c6a2 | srcipv6 | principal.asset.ip | |
| ID do host (hostid) | PanOSHostID | principal.asset.asset_id | ||
| Número de série do dispositivo do usuário (serialnumber) | PanOSEndpointSerialNumber | principal.asset.hardware.serial_number | ||
| Endereço MAC do dispositivo (mac) | PanOSEndpointMac | principal.asset.mac | ||
| Carimbo de data/hora de alta resolução (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value | ||
| Nome do cluster (cluster_name) | principal.resource.name | |||
| Gravidade (severity) | number-of-severity(header) | security_result.severity e security_result.severity_details |
Tag de IP
A tabela a seguir lista os campos de registro do tipo de registro de tag de IP e os campos correspondentes da UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave do rótulo do Google Security Operations | Campo do UDM |
|---|---|---|---|---|
| Horário de recebimento (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|
| Número de série (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Type (tipo) | type (Header) | gato | metadata.product_event_type | |
| Tipo de ameaça/conteúdo (subtipo) | subtype (cabeçalho) | Subtipo | metadata.product_event_type | |
| Horário gerado (time_generated ou cef-formatted-time_generated) | GenerateTime | metadata.event_timestamp | ||
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| IP de origem (ip) | src | src | principal.ip | |
| Nome da tag (tag_name) | PanOSTagName | TagName | tag_name | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| ID do evento (event_id) | PanOSEventID | EventID | event_id | additional.fields.key e additional.fields.value.string_value |
| Contagem de repetições (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Tempo limite (timeout) | PanOSTimeout | TimeoutThreshold | timeout | additional.fields.key e additional.fields.value.string_value |
| Nome da fonte de dados (datasourcename) | PanOSDataSourceName | DataSourceName | datasourcename | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Tipo de fonte de dados (datasource_type) | PanOSDataSourceType | DataSource | datasource_type | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Subtipo da fonte de dados (datasource_subtype) | PanOSDataSourceSubType | DataSourceType | datasource_subtype | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Número de sequência (seqno) | externalId | sequência | metadata.product_log_id | |
| Flags de ação (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupos de dispositivos (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupos de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome do sistema virtual (vsys_name) | PanOsVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nome do dispositivo (device_name) | dvchost | DeviceName | target.hostname | |
| ID do sistema virtual (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id | |
| Carimbo de data/hora de alta resolução (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value | ||
| Gravidade (severity) | number-of-severity(header) | security_result.severity e security_result.severity_details | ||
| Nome do cluster (cluster_name) | principal.resource.name |
Descriptografia
A tabela a seguir lista os campos de registro do tipo de registro de descriptografia e os campos correspondentes da UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave do rótulo do Google Security Operations | Campo do UDM |
|---|---|---|---|---|
| Horário de recebimento (receive_time ou cef-formatted-receive_time) | rt | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
||
| Número de série (serial) | PanOSDeviceSN | intermediary.asset.hardware.serial_number | ||
| Type (tipo) | type (Header) | metadata.product_event_type | ||
| Tipo de ameaça/conteúdo (subtipo) | subtype (cabeçalho) | metadata.product_event_type | ||
| Versão da configuração (config_ver) | PanOSConfigVersion | config_ver | additional.fields.key e additional.fields.value.string_value | |
| Horário de geração (time_generated) | PanOSLogTimeStamp | metadata.event_timestamp | ||
| Endereço de origem (src) | src | principal.ip | ||
| Endereço de destino (dst) | dst | target.ip | ||
| IP de origem NAT (natsrc) | sourceTranslatedAddress | principa.nat_ip | ||
| IP de destino NAT (natdst) | destinationTranslatedAddress | target.nat_ip | ||
| Rule (regra) | cs1 | security_result.rule_name | ||
| Usuário de origem (srcuser) | suser | principal.user.userid | ||
| Usuário de destino (dstuser) | duser | target.user.userid | ||
| Aplicativo | app | network.application_protocol | ||
| Sistema virtual (vsys) | cs3 | vsys | intermediary.asset.attribute.labels.key/value | |
| Zona de origem (de) | cs4 | de | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Zona de destino (para) | cs5 | a | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Interface de entrada (inbound_if) | deviceInboundInterface | inbound_if | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Interface de saída (outbound_if) | deviceOutboundInterface | outbound_if | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Ação de registro (logset) | cs6 | logset | additional.fields.key e additional.fields.value.string_value | |
| Horário registrado (time_received) | PanOSTimeReceivedManagementPlane | - | ||
| ID da sessão (sessionid) | cn1 | network.session_id | ||
| Contagem de repetições (repeatcnt) | PanOSCountOfRepeats/RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value | |
| Porta de origem (sport) | spt | principal.port | ||
| Porta de destino (dport) | dpt | target.port | ||
| Porta de origem NAT (natsport) | sourceTranslatedPort | principal.nat_port | ||
| Porta de destino NAT (natdport) | destinationTranslatedPort | target.nat_port | ||
| Flags (flags) | flexString1 | flags | additional.fields.key e additional.fields.value.string_value | |
| Protocolo IP (proto) | proto | network.ip_protocol | ||
| Ação (action) | age | security_result.action_details
security_result.action |
||
| Túnel (tunnel) | PanOSTunnel | túnel | additional.fields.key e additional.fields.value.string_value | |
| UUID da VM de origem (src_uuid) | PanOSSourceUUID | principal.asset.product_object_id | ||
| UUID da VM de destino (dst_uuid) | PanOSDestinationUUID | target.asset.product_object_id | ||
| UUID da regra (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| Estágio de cliente para firewall (hs_stage_c2f) | PanOSClientToFirewall | hs_stage_c2f | additional.fields.key e additional.fields.value.string_value | |
| Estágio para firewall para servidor (hs_stage_f2s) | PanOSFirewallToServer | hs_stage_f2s | additional.fields.key e additional.fields.value.string_value | |
| Versão do TLS (tls_version) | PanOSTLSVersion | network.tls.version | ||
| Algoritmo de troca de chaves (tls_keyxchg) | PanOSTLSKeyExchange | tls_keyxchg | additional.fields.key e additional.fields.value.string_value | |
| Algoritmo de criptografia (tls_enc) | PanOSTLSEncryptionAlgorithm | tls_enc | additional.fields.key e additional.fields.value.string_value | |
| Algoritmo de hash (tls_auth) | PanOSTLSAuth | tls_auth | additional.fields.key e additional.fields.value.string_value | |
| Nome da política (policy_name) | PanOSPolicyName | policy_name | additional.fields.key e additional.fields.value.string_value | |
| Curva elíptica (ec_curve) | PanOSEllipticCurve | network.tls.curve | ||
| Índice de erro (err_index) | PanOSErrorIndex | err_index | additional.fields.key e additional.fields.value.string_value | |
| Status da raiz (root_status) | PanOSRootStatus | root_status | additional.fields.key e additional.fields.value.string_value | |
| Status da cadeia (chain_status) | PanOSChainStatus | chain_status | additional.fields.key e additional.fields.value.string_value | |
| Tipo de proxy (proxy_type) | PanOSProxyType | proxy_type | additional.fields.key e additional.fields.value.string_value | |
| Número de série do certificado (cert_serial) | PanOSCertificateSerial | network.tls.server.certificate.serial | ||
| Impressão digital do certificado (impressão digital) | PanOSFingerprint | network.tls.server.certificate.md5/sha1/sha256 | ||
| Data de início do certificado (notbefore) | PanOSTimeNotBefore | network.tls.server.certificate.not_before | ||
| Data de término do certificado (notafter) | PanOSTimeNotAfter | network.tls.server.certificate.not_after | ||
| Versão do certificado (cert_ver) | PanOSCertificateVersion | network.tls.server.certificate.version | ||
| Tamanho do certificado (cert_size) | PanOSCertificateSize | cert_size | additional.fields.key e additional.fields.value.string_value | |
| Comprimento do nome comum (cn_len) | PanOSCommonNameLength | cn_len | additional.fields.key e additional.fields.value.string_value | |
| Comprimento do nome comum do emissor (issuer_len) | PanOSIssuerNameLength | issuer_len | additional.fields.key e additional.fields.value.string_value | |
| Comprimento do nome comum da raiz (rootcn_len) | PanOSRootCNLength | rootcn_len | additional.fields.key e additional.fields.value.string_value | |
| Comprimento do SNI (sni_len) | PanOSSNILength | sni_len | additional.fields.key e additional.fields.value.string_value | |
| Flags de certificado (cert_flags) | PanOSCertificateFlags | cert_flags | additional.fields.key e additional.fields.value.string_value | |
| Nome comum do assunto (cn) | PanOSCommonName | cn | additional.fields.key e additional.fields.value.string_value | |
| Nome comum do emissor (issuer_cn) | PanOSIssuerCommonName | network.tls.server.certificate.issuer | ||
| Nome comum da raiz (root_cn) | PanOSRootCommonName | root_cn | additional.fields.key e additional.fields.value.string_value | |
| Indicação de nome do servidor
(sni) |
network.tls.client.server_name | |||
| Erro (erro) | PanOSErrorMessage | erro | additional.fields.key e additional.fields.value.string_value | |
| ID do contêiner (container_id) | PanOSContainerID | container_id | intermediary.resource.product_object_id | |
| Namespace do POD (pod_namespace) | PanOSContainerNameSpace | pod_namespace | target.resource.attribute.labels.key/value additional.fields.key e additional.fields.value.string_value |
|
| Nome do POD (pod_name) | PanOSContainerName | pod_name | target.resource.name | |
| Lista dinâmica externa de origem (src_edl) | PanOSSourceEDL | src_edl | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Lista dinâmica externa de destino (dst_edl) | PanOSDestinationEDL | dst_edl | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Grupo de endereços dinâmicos de origem (src_dag) | PanOSSourceDynamicAddressGroup | principal.group.group_display_name | ||
| Grupo de endereços dinâmicos de destino (dst_dag) | PanOSDestinationDynamicAddressGroup | target.group.group_display_name | ||
| Carimbo de data/hora de alta resolução (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value | ||
| Categoria do dispositivo de origem (src_category) | PanOSSourceDeviceCategory | src_category | principal.asset.category | |
| Perfil do dispositivo de origem (src_profile) | PanOSSourceDeviceProfile | src_profile | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modelo do dispositivo de origem (src_model) | PanOSSourceDeviceModel | src_model | principal.asset.hardware.model | |
| Fornecedor do dispositivo de origem (src_vendor) | PanOSSourceDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Família do SO do dispositivo de origem (src_osfamily) | PanOSSourceDeviceOSFamily | principal.platform | ||
| Versão do SO do dispositivo de origem (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | ||
| Nome do host de origem (src_host) | PanOSSourceDeviceHost | principal.hostname | ||
| Endereço MAC de origem (src_mac) | PanOSSourceDeviceMac | principal.mac | ||
| Categoria do dispositivo de destino (dst_category) | PanOSDestinationDeviceCategory | dst_category | target.asset.category | |
| Perfil do dispositivo de destino (dst_profile) | PanOSDestinationDeviceProfile | dst_profile | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modelo do dispositivo de destino (dst_model) | PanOSDestinationDeviceModel | dst_model | target.asset.hardware.model | |
| Fornecedor do dispositivo de destino (dst_vendor) | PanOSDestinationDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Família do SO do dispositivo de destino (dst_osfamily) | PanOSDestinationDeviceOSFamily | dst_osfamily | target.platform | |
| Versão do SO do dispositivo de destino (dst_osversion) | PanOSDestinationDeviceOSVersion | target.platform_version | ||
| Nome do host de destino (dst_host) | PanOSDestinationDeviceHost | target.hostname | ||
| Endereço MAC de destino (dst_mac) | PanOSDestinationDeviceMac | target.mac | ||
| Número de sequência (seqno) | PanOSLogTypeSeqNo | metadata.product_log_id | ||
| Flags de ação (actionflags) | PanOSActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value | |
| Hierarquia de grupos de dispositivos (dg_hier_level_1) | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value | |
| Hierarquia do grupo de dispositivos (dg_hier_level_2) | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value | |
| Hierarquia de grupos de dispositivos (dg_hier_level_3) | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value | |
| Hierarquia de grupo de dispositivos (dg_hier_level_4) | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value | |
| Nome do sistema virtual (vsys_name) | intermediary.asset.attribute.labels.key/value | |||
| Nome do dispositivo (device_name) | intermediary.hostname | |||
| ID do sistema virtual (vsys_id) | intermediary.resource.product_object_id | |||
| Subcategoria do aplicativo (subcategory_of_app) | subcategory_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Categoria do aplicativo (category_of_app) | category_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia de aplicativos (technology_of_app) | technology_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Risco do aplicativo (risk_of_app) | security_result.severity | |||
| Característica do aplicativo (characteristic_of_app) | characteristic_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Contêiner do aplicativo (container_of_app) | container_of_app | additional.fields.key e additional.fields.value.string_value | ||
| SaaS de aplicativo (is_saas_of_app) | is_saas_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Estado de sanção do aplicativo (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Gravidade (severity) | number-of-severity(header) | security_result.severity e security_result.severity_details |
Túnel
A tabela a seguir lista os campos de registro do tipo de registro de túnel e os campos correspondentes da UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave do rótulo do Google Security Operations | Campo do UDM |
|---|---|---|---|---|
| Horário de recebimento (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|
| Número de série (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Type (tipo) | type (Header) | gato | metadata.product_event_type | |
| Tipo de ameaça/conteúdo (subtipo) | subtype (cabeçalho) | Subtipo | metadata.product_event_type | |
| Horário gerado (time_generated ou cef-formatted-time_generated) | metadata.event_timestamp | |||
| Endereço de origem (src) | src | src | principal.ip | |
| Endereço de destino (dst) | dst | dst | target.ip | |
| IP de origem NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP de destino NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Nome da regra (regra) | cs1 | RuleName | security_result.rule_name | |
| Usuário de origem (srcuser) | suser | SourceUser / usrName | principal.user.userid | |
| Usuário de destino (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplicativo | app | Aplicativo | network.application_protocol | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona de origem (de) | cs4 | SourceZone | de | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Zona de destino (para) | cs5 | DestinationZone | a | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Interface de entrada (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Interface de saída (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Ação de registro (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key e additional.fields.value.string_value |
| ID da sessão (sessionid) | cn1 | SessionID | network.session_id | |
| Contagem de repetições (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Porta de origem (sport) | spt | srcPort | principal.port | |
| Porta de destino (dport) | dpt | dstPort | target.port | |
| Porta de origem NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Porta de destino NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Flags (flags) | flexString1 | Flags | flags | additional.fields.key e additional.fields.value.string_value |
| Protocolo IP (proto) | proto | proto | network.ip_protocol | |
| Ação (action) | age | ação | security_result.action_details
security_result.action |
|
| Gravidade (severity) | number-of-severity(header) | security_result.severity e security_result.severity_details | ||
| Número de sequência (seqno) | externalId | sequência | metadata.product_log_id | |
| Flags de ação (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Local de origem (srcloc) | principal.location.country_or_region | |||
| Local de destino (dstloc) | target.location.country_or_region | |||
| Hierarquia de grupos de dispositivos (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupos de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome do sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nome do dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| ID do túnel (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key e additional.fields.value.string_value |
| Tag de monitoramento (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key e additional.fields.value.string_value |
| ID da sessão principal (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Horário de início da atividade principal (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key e additional.fields.value.string_value |
| Tipo de túnel (túnel) | cs2 | TunnelType | túnel | additional.fields.key e additional.fields.value.string_value |
| Bytes (bytes) | flexNumber1 | totalBytes | bytes | additional.fields.key e additional.fields.value.string_value |
| Bytes enviados (bytes_sent) | em | srcBytes | network.sent_bytes | |
| Bytes recebidos (bytes_received) | out | dstBytes | network.received_bytes | |
| Pacotes (pacotes) | cn2 | totalPackets | pacotes | additional.fields.key e additional.fields.value.string_value |
| Pacotes enviados (pkts_sent) | PanOSPacketsSent | srcPackets | pkts_sent | network.sent_packets |
| Pacotes recebidos (pkts_received) | PanOSPacketsReceived | dstPackets | pkts_received | network.received_packets |
| Encapsulamento máximo (max_encap) | flexNumber2 | MaximumEncapsulation | max_encap | additional.fields.key e additional.fields.value.string_value |
| Protocolo desconhecido (unknown_proto) | cfp1 | UnknownProtocol | unknown_proto | additional.fields.key e additional.fields.value.string_value |
| Verificação estrita (strict_check) | cfp2 | StrictChecking | strict_check | additional.fields.key e additional.fields.value.string_value |
| Fragmento de túnel (tunnel_fragment) | PanOSTunnelFragment | TunnelFragment | tunnel_fragment | additional.fields.key e additional.fields.value.string_value |
| Sessões criadas (sessions_created) | cfp3 | SessionsCreated | sessions_created | additional.fields.key e additional.fields.value.string_value |
| Sessões encerradas (sessions_closed) | cfp4 | SessionsClosed | sessions_closed | additional.fields.key e additional.fields.value.string_value |
| Motivo do término da sessão (session_end_reason) | reason | SessionEndReason | security_result.summary | |
| Origem da ação (action_source) | gato | ActionSource | action_source | additional.fields.key e additional.fields.value.string_value |
| Horário de início (start) | startTime | start | additional.fields.key e additional.fields.value.string_value | |
| Tempo decorrido (decorrido) | cn3 | ElapsedTime | decorrido | network.session_duration.seconds |
| Regra de inspeção de túnel (tunnel_insp_rule) | PanOSTunneInspectionRule | security_result.rule_name = "Tunnel Inspection Rule: %{PanOSTunnelInspectionRule}" | ||
| IP do usuário remoto (remote_user_ip) | PanOSRmtUserIP | principal.ip | ||
| ID do usuário remoto (remote_user_id) | PanOSRmtUserID | remote_user_id | principal.user.userid | |
| UUID da regra de segurança (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| ID do PCAP (pcap_id) | PanOSPcapID | pcap_id | additional.fields.key e additional.fields.value.string_value | |
| Nome do grupo dinâmico de usuários (dynusergroup_name) | PanDynamicUsrgrp | principal.group.group_display_name | ||
| Lista dinâmica externa de origem (src_edl) | PanOSSourceEDL | src_edl | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Lista dinâmica externa de destino (dst_edl) | PanOSDestinationEDL | dst_edl | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Carimbo de data/hora de alta resolução (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value | ||
| Um diferenciador de fração (nssai_sd) | nssai_sd | additional.fields.key e additional.fields.value.string_value | ||
| Um tipo de serviço de fatia (nssai_sd) | nssai_sd1 | additional.fields.key e additional.fields.value.string_value | ||
| ID da sessão do PDU (pdu_session_id) | pdu_session_id | additional.fields.key e additional.fields.value.string_value | ||
| Subcategoria do aplicativo (subcategory_of_app) | subcategory_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Categoria do aplicativo (category_of_app) | category_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia de aplicativos (technology_of_app) | technology_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Risco do aplicativo (risk_of_app) | risk_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Característica do aplicativo (characteristic_of_app) | characteristic_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Contêiner do aplicativo (container_of_app) | container_of_app | additional.fields.key e additional.fields.value.string_value | ||
| SaaS de aplicativo (is_saas_of_app) | is_saas_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Aplicativo em túnel (tunneled_app) | additional.fields.key e additional.fields.value.string_value | |||
| Descarregada (offloaded) | additional.fields.key e additional.fields.value.string_value | |||
| Tipo de fluxo (flow_type) | additional.fields.key e additional.fields.value.string_value | |||
| Nome do cluster (cluster_name) |
principal.resource.name |
|||
| Estado de sanção do aplicativo (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key e additional.fields.value.string_value |
Autenticação
A tabela a seguir lista os campos de registro do tipo de registro de autenticação e os campos correspondentes da UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave do rótulo do Google Security Operations | Campo do UDM |
|---|---|---|---|---|
| Horário de recebimento (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|
| Número de série (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Type (tipo) | type (Header) | gato | metadata.product_event_type | |
| Tipo de ameaça/conteúdo (subtipo) | subtype (cabeçalho) | Subtipo | metadata.product_event_type | |
| Horário gerado (time_generated ou cef-formatted-time_generated) | metadata.event_timestamp | |||
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| IP de origem (ip) | src | src | principal.ip | |
| Usuário (user) | duser | usrName | target.user.userid | |
| Normalizar usuário (normalize_user) | cs2 | NormalizeUser | target.user.user_display_name | |
| Objeto (objeto) | fname | ObjectName | objeto | target.resource.name |
| Política de autenticação (authpolicy) | cs4 | AuthPolicy | authpolicy | additional.fields.key e additional.fields.value.string_value |
| Contagem de repetições (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| ID de autenticação (authid) | cn2 | AuthenticationID | authid | additional.fields.key e additional.fields.value.string_value |
| Fornecedor (vendor) | flexString2 | Fornecedor | fornecedor | additional.fields.key e additional.fields.value.string_value |
| Ação de registro (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key e additional.fields.value.string_value |
| Perfil do servidor (serverprofile) | cs1 | ServerProfile | serverprofile | additional.fields.key e additional.fields.value.string_value |
| Descrição (decresc.) | PanOSDesc | AdditionalAuthInfo | security_result.description | |
| Tipo de cliente (clienttype) | cs5 | ClientType | clienttype | additional.fields.key e additional.fields.value.string_value |
| Tipo de evento (event) | msg | msg | extensions.auth.auth_details | |
| Número do fator (factorno) | cn1 | FactorNumber | factorno | additional.fields.key e additional.fields.value.string_value |
| Número de sequência (seqno) | externalId | sequência | metadata.product_log_id | |
| Flags de ação (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupos de dispositivos (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupos de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia de grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome do sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nome do dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| ID do sistema virtual (vsys_id) | intermediary.resource.product_object_id | |||
| Protocolo de autenticação (authproto) | authproto | additional.fields.key e additional.fields.value.string_value | ||
| UUID da regra (rule_uuid) | PanOSRuleUUID/RuleUUID | security_result.rule_id | ||
| Carimbo de data/hora de alta resolução (high_res _timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value | ||
| Categoria do dispositivo de origem (src_category) | PanOSSourceDeviceCategory | src_category | principal.asset.category | |
| Perfil do dispositivo de origem (src_profile) | PanOSSourceDeviceProfile | src_profile | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modelo do dispositivo de origem (src_model) | PanOSSourceDeviceModel | src_model | principal.asset.hardware.model | |
| Fornecedor do dispositivo de origem (src_vendor) | PanOSSourceDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Família do SO do dispositivo de origem (src_osfamily) | PanOSSourceDeviceOSFamily | principal.asset.platform_software.platform principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Versão do SO do dispositivo de origem (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | ||
| Nome do host de origem (src_host) | PanOSSourceHostname | principal.hostname | ||
| Endereço MAC de origem (src_mac) | PanOSSourceMac | principal.asset.mac | ||
| Região (região) | PanOSTrafficOriginRegion | principal.location.country_or_region | ||
| User agent (user_agent) | PanOSHTTPUserAgent | network.http.user_agent | ||
| ID da sessão(sessionid) | PanOSTrafficSessionID | network.session_id | ||
| Gravidade (severity) | number-of-severity(header) | security_result.severity e security_result.severity_details | ||
| Nome do cluster (cluster_name) | principal.resource.name |
URL
A tabela a seguir lista os campos de registro do tipo de registro de URL e os campos correspondentes da UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave do rótulo do Google Security Operations | Campo do UDM |
|---|---|---|---|---|
| Horário de recebimento (cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|
| Nº de série (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Type (tipo) | type (Header) | gato | metadata.product_event_type | |
| Tipo de ameaça/conteúdo (subtipo) | subtype (cabeçalho) | Subtipo | metadata.product_event_type | |
| Horário de geração | metadata.event_timestamp | |||
| Endereço de origem (src) | src | src | principal.ip | |
| Endereço de destino (dst) | dst | dst | target.ip | |
| IP de origem NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP de destino NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Rule (regra) | cs1 | RuleName | security_result.rule_name | |
| Usuário de origem (srcuser) | suser | SourceUser | principal.user.userid | |
| Usuário de destino (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplicativo | app | Aplicativo | network.application_protocol | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona de origem (de) | cs4 | SourceZone | de | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Zona de destino (para) | cs5 | DestinationZone | a | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Interface de entrada (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Interface de saída (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Ação de registro (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key e additional.fields.value.string_value |
| Horário registrado | time_logged | additional.fields.key e additional.fields.value.string_value | ||
| ID da sessão (sessionid) | cn1 | SessionID | network.session_id | |
| Contagem de repetições (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Porta de origem (sport) | spt | srcPort | principal.port | |
| Porta de destino (dport) | dpt | dstPort | target.port | |
| Porta de origem NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Porta de destino NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Flags (flags) | flexString1 | Flags | flags | additional.fields.key e additional.fields.value.string_value |
| Protocolo IP (proto) | proto | proto | network.ip_protocol | |
| Ação (action) | age | ação | security_result.action_details
security_result.action |
|
| URL/nome do arquivo (variados) | Diversos | target.file.names
target.url |
||
| Nome da ameaça/do conteúdo (threatid) | gato | ThreatID | security_result.threat_id | |
| Categoria (category) | cs2 | URLCategory | categoria | security_result.category_details |
| Gravidade (severity) | number-of-severity (cabeçalho) | Gravidade | security_result.severity
security_result.severity_details |
|
| Direção (direction) | flexString2 | Direção | network.direction | |
| Número de sequência (seqno) | externalId | sequência | metadata.product_log_id | |
| Flags de ação (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| País de origem (srcloc) | SourceLocation | principal.location.country_or_region | ||
| País de destino (dstloc) | DestinationLocation | target.location.country_or_region | ||
| contenttype (contenttype) | requestContext | ContentType | contenttype | additional.fields.key e additional.fields.value.string_value |
| pcap_id (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key e additional.fields.value.string_value |
| filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | ||
| nuvem (cloud) | Cloud | nuvem | additional.fields.key e additional.fields.value.string_value | |
| url_idx (url_idx) | URLIndex | url_idx | additional.fields.key e additional.fields.value.string_value | |
| user_agent (user_agent) | requestClientApplication | UserAgent | network.http.user_agent | |
| filetype (filetype) | target.file.mime_type | |||
| xff (xff) | PanOSXForwarderfor | identSrc | xff | principal.ip |
| Referenciador (referer) | PanOSReferer | Referenciador | network.http.referral_url | |
| sender (sender) | network.email.from | |||
| assunto (assunto) | Assunto | network.email.subject | ||
| destinatário (recipient) | network.email.to | |||
| reportid (reportid) | reportid | additional.fields.key e additional.fields.value.string_value | ||
| Nível 1 da hierarquia de DG (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Nível 2 da hierarquia de DG (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Nível 3 da hierarquia de DG (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Nível 4 da hierarquia de DG (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome do sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nome do dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| file_url (file_url) | target.url | |||
| UUID da VM de origem (src_uuid) | SrcUUID | principal.asset.product_object_id | ||
| UUID da VM de destino (dst_uuid) | DstUUID | target.asset.product_object_id | ||
| http_method (http_method) | requestMethod | RequestMethod | network.http.method | |
| ID do túnel/IMSI (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key e additional.fields.value.string_value |
| Monitorar tag/IMEI (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key e additional.fields.value.string_value |
| ID da sessão principal (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Horário de início da sessão principal (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key e additional.fields.value.string_value |
| Túnel (tunnel) | PanOSTunnelType | TunnelType | túnel | additional.fields.key e additional.fields.value.string_value |
| thr_category (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| contentver (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key e additional.fields.value.string_value |
| sig_flags (sig_flags) | sig_flags | additional.fields.key e additional.fields.value.string_value | ||
| ID da associação SCTP (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key e additional.fields.value.string_value | |
| ID do protocolo de payload (ppid) | PanOSPPID | ppid | additional.fields.key e additional.fields.value.string_value | |
| http_headers (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Lista de categorias de URL (url_category_list) | PanOSURLCatList | url_category_list | additional.fields.key e additional.fields.value.string_value | |
| UUID da regra (rule_uuid) | PanOSRuleUUID | rule_uuid | security_result.rule_id | |
| Conexão HTTP/2 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| dynusergroup_name (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | additional.fields.key e additional.fields.value.string_value | |
| Endereço XFF (xff_ip) | PanXFFIP | principal.ip | ||
| Categoria do dispositivo de origem (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Perfil do dispositivo de origem (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modelo do dispositivo de origem (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Fornecedor do dispositivo de origem (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Família do SO do dispositivo de origem (src_osfamily) | PanSrcDeviceOS | principal.platform | ||
| Versão do SO do dispositivo de origem (src_osversion) | PanSrcDeviceOSv | principal.platform_version | ||
| Nome do host de origem (src_host) | PanSrcHostname | src_host | principal.hostname | |
| Endereço MAC de origem (src_mac) | PanSrcMac | principal.mac | ||
| Categoria do dispositivo de destino (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Perfil do dispositivo de destino (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modelo do dispositivo de destino (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Fornecedor do dispositivo de destino (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Família do SO do dispositivo de destino (dst_osfamily) | PanDstDeviceOS | target.platform | ||
| Versão do SO do dispositivo de destino (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Nome do host de destino (dst_host) | PanPODNamespace | target.hostname | ||
| Endereço MAC de destino (dst_mac) | PanDstMac | target.mac | ||
| ID do contêiner (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| Namespace do POD (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| Nome do POD (pod_name) | PanPODName | pod_name | target.resource.name | |
| Lista dinâmica externa de origem (src_edl) | PanSrcEDL | src_edl | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Lista dinâmica externa de destino (dst_edl) | PanDstEDL | dst_edl | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| ID do host (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Número de série (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| domain_edl (domain_edl) | PanDomainEDL | domain_edl | additional.fields.key e additional.fields.value.string_value | |
| Grupo de endereços dinâmicos de origem (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Grupo de endereços dinâmicos de destino (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| partial_hash (partial_hash) | PanPartialHash | partial_hash | additional.fields.key e additional.fields.value.string_value | |
| Carimbo de data/hora de alta resolução (high_res_timestamp) | PanTimeHighRes | additional.fields.key e additional.fields.value.string_value | ||
| Motivo (reason) | PanReasonFilteringAction | reason | security_result.summary | |
| justificação (justification) | PanJustification | justificativa | additional.fields.key e additional.fields.value.string_value | |
| nssai_sst (nssai_sst) | PanASServiceType | nssai_sst | additional.fields.key e additional.fields.value.string_value | |
| Subcategoria do app (subcategory_of_app) | subcategory_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Categoria do app (category_of_app) | category_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia do app (technology_of_app) | technology_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Risco do app (risk_of_app) | risk_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Característica do app (characteristic_of_app) | characteristic_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Contêiner do app (container_of_app) | container_of_app | additional.fields.key e additional.fields.value.string_value | ||
| App em túnel (tunneled_app) | tunneled_app | additional.fields.key e additional.fields.value.string_value | ||
| SaaS do app (is_saas_of_app) | is_saas_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Estado autorizado do app (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key e additional.fields.value.string_value | ||
| ID do relatório da nuvem (cloud_reportid) | additional.fields.key e additional.fields.value.string_value | |||
| Nome do cluster (cluster_name) |
principal.resource.name |
|||
| Tipo de fluxo (flow_type) | additional.fields.key e additional.fields.value.string_value |
Dados
A tabela a seguir lista os campos de registro do tipo de registro de dados e os campos correspondentes da UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave do rótulo do Google Security Operations | Campo do UDM |
|---|---|---|---|---|
| Horário de recebimento (cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|
| Nº de série (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Type (tipo) | type (Header) | gato | metadata.product_event_type | |
| Tipo de ameaça/conteúdo (subtipo) | subtype (cabeçalho) | Subtipo | metadata.product_event_type | |
| Horário de geração | metadata.event_timestamp | |||
| Endereço de origem (src) | src | src | principal.ip | |
| Endereço de destino (dst) | dst | dst | target.ip | |
| IP de origem NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP de destino NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Rule (regra) | cs1 | RuleName | security_result.rule_name | |
| Usuário de origem (srcuser) | suser | SourceUser | principal.user.userid | |
| Usuário de destino (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplicativo | app | Aplicativo | network.application_protocol | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona de origem (de) | cs4 | SourceZone | de | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Zona de destino (para) | cs5 | DestinationZone | a | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Interface de entrada (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Interface de saída (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Ação de registro (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key e additional.fields.value.string_value |
| Horário registrado | time_logged | additional.fields.key e additional.fields.value.string_value | ||
| ID da sessão (sessionid) | cn1 | SessionID | network.session_id | |
| Contagem de repetições (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Porta de origem (sport) | spt | srcPort | principal.port | |
| Porta de destino (dport) | dpt | dstPort | target.port | |
| Porta de origem NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Porta de destino NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Flags (flags) | flexString1 | Flags | flags | additional.fields.key e additional.fields.value.string_value |
| Protocolo IP (proto) | proto | proto | network.ip_protocol | |
| Ação (action) | age | ação | security_result.action_details
security_result.action |
|
| URL/nome do arquivo (variados) | Diversos | target.file.names
target.url |
||
| Nome da ameaça/do conteúdo (threatid) | gato | ThreatID | security_result.threat_id | |
| Categoria (category) | cs2 | URLCategory | categoria | security_result.category_details |
| Gravidade (severity) | number-of-severity (cabeçalho) | Gravidade | security_result.severity
security_result.severity_details |
|
| Direção (direction) | flexString2 | Direção | network.direction | |
| Número de sequência (seqno) | externalId | sequência | metadata.product_log_id | |
| Flags de ação (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| País de origem (srcloc) | SourceLocation | principal.location.country_or_region | ||
| País de destino (dstloc) | DestinationLocation | target.location.country_or_region | ||
| contenttype (contenttype) | ContentType | contenttype | additional.fields.key e additional.fields.value.string_value | |
| pcap_id (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key e additional.fields.value.string_value |
| filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | ||
| nuvem (cloud) | Cloud | nuvem | additional.fields.key e additional.fields.value.string_value | |
| url_idx (url_idx) | URLIndex | url_idx | additional.fields.key e additional.fields.value.string_value | |
| user_agent (user_agent) | network.http.user_agent | |||
| filetype (filetype) | target.file.mime_type | |||
| xff (xff) | xff | principal.ip | ||
| Referenciador (referer) | network.http.referral_url | |||
| sender (sender) | network.email.from | |||
| assunto (assunto) | Assunto | network.email.subject | ||
| destinatário (recipient) | network.email.to | |||
| reportid (reportid) | reportid | additional.fields.key e additional.fields.value.string_value | ||
| Nível 1 da hierarquia de DG (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Nível 2 da hierarquia de DG (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Nível 3 da hierarquia de DG (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Nível 4 da hierarquia de DG (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome do sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nome do dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| file_url (file_url) | target.url | |||
| UUID da VM de origem (src_uuid) | SrcUUID | principal.asset.product_object_id | ||
| UUID da VM de destino (dst_uuid) | DstUUID | target.asset.product_object_id | ||
| http_method (http_method) | RequestMethod | network.http.method | ||
| ID do túnel/IMSI (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key e additional.fields.value.string_value |
| Monitorar tag/IMEI (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key e additional.fields.value.string_value |
| ID da sessão principal (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Horário de início da sessão principal (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key e additional.fields.value.string_value |
| Túnel (tunnel) | PanOSTunnelType | TunnelType | túnel | additional.fields.key e additional.fields.value.string_value |
| thr_category (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| contentver (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key e additional.fields.value.string_value |
| sig_flags (sig_flags) | sig_flags | additional.fields.key e additional.fields.value.string_value | ||
| ID da associação SCTP (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key e additional.fields.value.string_value | |
| ID do protocolo de payload (ppid) | PanOSPPID | ppid | additional.fields.key e additional.fields.value.string_value | |
| http_headers (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Lista de categorias de URL (url_category_list) | url_category_list | additional.fields.key e additional.fields.value.string_value | ||
| UUID da regra (rule_uuid) | PanOSRuleUUID | rule_uuid | security_result.rule_id | |
| Conexão HTTP/2 (http2_connection) | http2_connection | network.application_protocol_version | ||
| dynusergroup_name (dynusergroup_name) | dynusergroup_name | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Endereço XFF (xff_ip) | principal.ip | |||
| Categoria do dispositivo de origem (src_category) | src_category | principal.asset.category | ||
| Perfil do dispositivo de origem (src_profile) | src_profile | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Modelo do dispositivo de origem (src_model) | src_model | principal.asset.hardware.model | ||
| Fornecedor do dispositivo de origem (src_vendor) | src_vendor | principal.asset.hardware.manufacturer | ||
| Família do SO do dispositivo de origem (src_osfamily) | principal.platform | |||
| Versão do SO do dispositivo de origem (src_osversion) | principal.platform_version | |||
| Nome do host de origem (src_host) | src_host | principal.hostname | ||
| Endereço MAC de origem (src_mac) | principal.mac | |||
| Categoria do dispositivo de destino (dst_category) | dst_category | target.asset.category | ||
| Perfil do dispositivo de destino (dst_profile) | dst_profile | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Modelo do dispositivo de destino (dst_model) | dst_model | target.asset.hardware.model | ||
| Fornecedor do dispositivo de destino (dst_vendor) | dst_vendor | target.asset.hardware.manufacturer | ||
| Família do SO do dispositivo de destino (dst_osfamily) | target.platform | |||
| Versão do SO do dispositivo de destino (dst_osversion) | target.platform_version | |||
| Nome do host de destino (dst_host) | target.hostname | |||
| Endereço MAC de destino (dst_mac) | target.mac | |||
| ID do contêiner (container_id) | container_id | intermediary.resource.product_object_id | ||
| Namespace do POD (pod_namespace) | pod_namespace | target.resource.attribute.labels.key/value | ||
| Nome do POD (pod_name) | pod_name | target.resource.name | ||
| Lista dinâmica externa de origem (src_edl) | src_edl | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Lista dinâmica externa de destino (dst_edl) | dst_edl | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
||
| ID do host (hostid) | hostid | principal.asset.asset_id | ||
| Número de série (serialnumber) | principal.asset.hardware.serial_number | |||
| domain_edl (domain_edl) | domain_edl | additional.fields.key e additional.fields.value.string_value | ||
| Grupo de endereços dinâmicos de origem (src_dag) | principal.group.group_display_name | |||
| Grupo de endereços dinâmicos de destino (dst_dag) | target.group.group_display_name | |||
| partial_hash (partial_hash) | partial_hash | additional.fields.key e additional.fields.value.string_value | ||
| Carimbo de data/hora de alta resolução (high_res_timestamp) | additional.fields.key e additional.fields.value.string_value | |||
| Motivo (reason) | reason | security_result.summary | ||
| justificação (justification) | justificativa | additional.fields.key e additional.fields.value.string_value | ||
| nssai_sst (nssai_sst) | nssai_sst | additional.fields.key e additional.fields.value.string_value | ||
| Subcategoria do app (subcategory_of_app) | subcategory_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Categoria do app (category_of_app) | category_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia do app (technology_of_app) | technology_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Risco do app (risk_of_app) | risk_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Característica do app (characteristic_of_app) | characteristic_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Contêiner do app (container_of_app) | container_of_app | additional.fields.key e additional.fields.value.string_value | ||
| App em túnel (tunneled_app) | tunneled_app | additional.fields.key e additional.fields.value.string_value | ||
| SaaS do app (is_saas_of_app) | is_saas_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Estado autorizado do app (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key e additional.fields.value.string_value | ||
| ID do relatório da nuvem (cloud_reportid) | additional.fields.key e additional.fields.value.string_value | |||
| Nome do cluster (cluster_name) | principal.resource.name | |||
| Tipo de fluxo (flow_type) | additional.fields.key e additional.fields.value.string_value |
GlobalProtect
A tabela a seguir lista os campos de registro do tipo GlobalProtect e os campos correspondentes da UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave do rótulo do Google Security Operations | Campo do UDM |
|---|---|---|---|---|
| Horário de recebimento (receive_time) | rt | received_time | metadata.event_timestamp | |
| Nº de série (serial) | PanOSDeviceSN | intermediary_asset_hardware_serial_number | intermediary.asset.hardware.serial_number | |
| Type (tipo) | type (Header) | metadata.product_event_type | ||
| Tipo de ameaça/conteúdo (subtipo) | subtype (cabeçalho) | Subtipo | metadata.product_event_type | |
| Horário de geração (time_generated) | PanOSLogTimeStamp | generated_timestamp | metadata.event_timestamp | |
| Sistema virtual (vsys) | PanOSVirtualSystem | vsys | intermediary.asset.attribute.labels.key/value | |
| ID do evento (eventid) | PanOSEventID | event_id | additional.fields.key e additional.fields.value.string_value | |
| Etapa (stage) | PanOSStage | etapa | additional.fields.key e additional.fields.value.string_value | |
| Método de autenticação (auth_method) | PanOSAuthMethod | extension_auth_auth_details | extensions.auth.auth_details | |
| Tipo de túnel (tunnel_type) | PanOSTunnelType | túnel | additional.fields.key e additional.fields.value.string_value | |
| Usuário de origem (srcuser) | PanOSSourceUserName | src_user | principal.user.email_address
principal.user.userid principal.administrative_domain |
|
| Região de origem (srcregion) | PanOSSourceRegion | src_region | principal.location.country_or_region | |
| Nome da máquina (machinename) | PanOSEndpointDeviceName | machine_name | principal.hostname | |
| IP público (public_ip) | PanOSPublicIPv4 | principal.nat_ip | ||
| IPv6 público (public_ipv6) | PanOSPublicIPv6 | principal.nat_ip | ||
| IP particular (private_ip) | PanOSPrivateIPv4 | principal.ip | ||
| IPv6 particular (private_ipv6) | PanOSPrivateIPv6 | principal.ip | ||
| ID do host (hostid) | PanOSHostID | hostid | principal.asset.asset_id | |
| Número de série (serialnumber) | PanOSDeviceSN | principal.asset.hardware.serial_number | ||
| Versão do cliente (client_ver) | PanOSGlobalProtectClientVersion | client_ver | additional.fields.key e additional.fields.value.string_value | |
| SO do cliente (client_os) | PanOSEndpointOSType | principal.platform | ||
| Versão do SO do cliente (client_os_ver) | PanOSEndpointOSVersion | principal.platform_version | ||
| Contagem de repetições (repeatcnt) | PanOSCountOfRepeats | repeatcnt | additional.fields.key e additional.fields.value.string_value | |
| Motivo (reason) | PanOSQuarantineReason | security_result.summary | ||
| Erro (erro) | PanOSConnectionError | erro | security_result.description | |
| Descrição (opaca) | PanOSDescription | security_result.description | ||
| Status (status) | PanOSEventStatus | status | additional.fields.key e additional.fields.value.string_value | |
| Local (local) | PanOSGPGatewayLocation | target.location.country_or_region | ||
| Duração do login (login_duration) | PanOSLoginDuration | network.session_duration | ||
| Método de conexão (connect_method) | PanOSConnectionMethod | connect_method | additional.fields.key e additional.fields.value.string_value | |
| Código do erro (error_code) | PanOSConnectionErrorID | error_code | additional.fields.key e additional.fields.value.string_value | |
| Portal (portal) | PanOSPortal | portal | additional.fields.key e additional.fields.value.string_value | |
| Número de sequência (seqno) | PanOSSequenceNo | metadata.product_log_id | ||
| Flags de ação (actionflags) | PanOSActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value | |
| Carimbo de data/hora de alta resolução (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value | ||
| Método de seleção de gateway (selection_type) | PanOSGatewaySelectionType | selection_type | additional.fields.key e additional.fields.value.string_value | |
| Tempo de resposta do SSL (response_time) | PanOSSSLResponseTime | response_time | additional.fields.key e additional.fields.value.string_value | |
| Prioridade do gateway (priority) | PanOSGatewayPriority | prioridade | additional.fields.key e additional.fields.value.string_value | |
| Tentativas de gateway (attempted_gateways) | PanOSAttemptedGateways | attempted_gateways | additional.fields.key e additional.fields.value.string_value | |
| Nome do gateway (gateway) | PanOSAttemptedGateways | gateway | target.resource.name | |
| Hierarquia de grupos de dispositivos (dg_hier_level_1) | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value | ||
| Hierarquia do grupo de dispositivos (dg_hier_level_2) | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value | ||
| Hierarquia de grupos de dispositivos (dg_hier_level_3) | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value | ||
| Hierarquia de grupo de dispositivos (dg_hier_level_4) | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value | ||
| Nome do sistema virtual (vsys_name) | intermediary.asset.attribute.labels.key/value | |||
| Nome do dispositivo (device_name) | intermediary.hostname | |||
| ID do sistema virtual (vsys_id) | intermediary.resource.product_object_id | |||
| Gravidade (severity) | number-of-severity(header) | security_result.severity e security_result.severity_details | ||
| Nome do cluster (cluster_name) | principal.resource.name |
Correlação
A tabela a seguir lista os campos de registro do tipo "Correlação" e os campos correspondentes da UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave do rótulo do Google Security Operations | Campo do UDM |
|---|---|---|---|---|
| Horário gerado (time_generated ou cef-formatted-time_generated) | startTime | generated_timestamp | metadata.event_timestamp | |
| Endereço de origem (src) | src | principal.ip | ||
| Usuário de origem (srcuser) | SourceUser / usrName | principal.user.userid | ||
| Sistema virtual (vsys) | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value | |
| Categoria (category) | security_result.category_details | |||
| Gravidade (severity) | Gravidade | security_result.severity e security_result.severity_details | ||
| Nível 1 da hierarquia do grupo de dispositivos | DeviceGroupHierarchyL1 | additional.fields.key e additional.fields.value.string_value | ||
| Nível 2 da hierarquia do grupo de dispositivos | DeviceGroupHierarchyL2 | additional.fields.key e additional.fields.value.string_value | ||
| Nível 3 da hierarquia do grupo de dispositivos | DeviceGroupHierarchyL3 | additional.fields.key e additional.fields.value.string_value | ||
| Nível 4 da hierarquia do grupo de dispositivos | DeviceGroupHierarchyL4 | additional.fields.key e additional.fields.value.string_value | ||
| Nome do sistema virtual (vsys_name) | vSrcName | intermediary.asset.attribute.labels.key/value | ||
| Nome do dispositivo (device_name) | DeviceName | intermediary.hostname | ||
| ID do sistema virtual (vsys_id) | VirtualSystemID | intermediary.resource.product_object_id | ||
| Nome do objeto (objectname) | ObjectName | target.resource.name | ||
| ID do objeto (object_id) | ObjectID | target.resource.product_object_id | ||
| Evidência (evidence) | msg | security_result.summary |
GTP
A tabela a seguir lista os campos de registro do tipo gtp e os campos correspondentes da UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave do rótulo do Google Security Operations | Campo do UDM |
|---|---|---|---|---|
| Horário de recebimento (receive_time ou cef-formatted-receive_time) | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|||
| Número de série (serial) | intermediary.asset.hardware.serial_number | |||
| Type (tipo) | metadata.product_event_type | |||
| Tipo de ameaça/conteúdo (subtipo) | metadata.product_event_type | |||
| Horário gerado (time_generated ou cef-formatted-time_generated) | metadata.event_timestamp | |||
| Endereço de origem (src) | principal.ip | |||
| Endereço de destino (dst) | target.ip | |||
| Nome da regra (regra) | security_result.rule_name | |||
| Aplicativo | network.application_protocol | |||
| Sistema virtual (vsys) | vsys | intermediary.asset.attribute.labels.key/value | ||
| Zona de origem (de) | de | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Zona de destino (para) | a | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Interface de entrada (inbound_if) | inbound_if | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Interface de saída (outbound_if) | outbound_if | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Ação de registro (logset) | logset | additional.fields.key e additional.fields.value.string_value | ||
| ID da sessão (sessionid) | network.session_id | |||
| Porta de origem (sport) | principal.port | |||
| Porta de destino (dport) | target.port | |||
| Protocolo IP (proto) | network.ip_protocol | |||
| Ação (action) | security_result.action_details
security_result.action |
|||
| Tipo de evento do GTP (event_type) | gtp_event_type | additional.fields.key e additional.fields.value.string_value | ||
| MSISDN (msisdn) | msisdn | additional.fields.key e additional.fields.value.string_value | ||
| Nome do ponto de acesso (apn) | apn | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia de acesso por rádio (RAT) | rato | additional.fields.key e additional.fields.value.string_value | ||
| Tipo de mensagem do GTP (msg_type) | gtp_msg_type | additional.fields.key e additional.fields.value.string_value | ||
| Endereço IP final (end_ip_adr) | principal.ip | |||
| Identificador do endpoint do túnel 1 (teid1) | teid1 | additional.fields.key e additional.fields.value.string_value | ||
| Identificador do endpoint do túnel 2 (teid2) | teid2 | additional.fields.key e additional.fields.value.string_value | ||
| Interface do GTP (gtp_interface) | gtp_interface | additional.fields.key e additional.fields.value.string_value | ||
| Causa do GTP (cause_code) | gtp_cause_code | additional.fields.key e additional.fields.value.string_value | ||
| Gravidade (severity) | security_result.severity e security_result.severity_details | |||
| MCC da rede de veiculação (mcc) | mcc | additional.fields.key e additional.fields.value.string_value | ||
| MNC da rede de veiculação (mnc) | mnc | additional.fields.key e additional.fields.value.string_value | ||
| Código de área (area_code) | area_code | additional.fields.key e additional.fields.value.string_value | ||
| ID da célula (cell_id) | cell_id | additional.fields.key e additional.fields.value.string_value | ||
| Código do evento do GTP (event_code) | event_code | additional.fields.key e additional.fields.value.string_value | ||
| Local de origem (srcloc) | principal.location.country_or_region | |||
| Local de destino (dstloc) | target.location.country_or_region | |||
| ID do túnel/IMSI (imsi) | tunnelid | additional.fields.key e additional.fields.value.string_value | ||
| Monitorar tag/IMEI (imei) | monitortag | additional.fields.key e additional.fields.value.string_value | ||
| Horário de início (start) | start | additional.fields.key e additional.fields.value.string_value | ||
| Tempo decorrido (decorrido) | network.session_duration.seconds | |||
| Tunnel Inspection RuleTunnel (tunnel_insp_rule) | tunnel_insp_rule | security_result.detection_fields.key/value | ||
| IP do usuário remoto (remote_user_ip) | principal.ip | |||
| ID do usuário remoto (remote_user_id) | remote_user_id | principal.user.userid | ||
| UUID da regra (rule_uuid) | security_result.rule_id | |||
| ID do PCAP (pcap_id) | pcap_id | additional.fields.key e additional.fields.value.string_value | ||
| Carimbo de data/hora de alta resolução (high_res_timestamp) | additional.fields.key e additional.fields.value.string_value | |||
| Um tipo de serviço de fração (nsdsai_sst) | nsdsai_sst | additional.fields.key e additional.fields.value.string_value | ||
| Um diferenciador de fração (nsdsai_sd) | nsdsai_sd | additional.fields.key e additional.fields.value.string_value | ||
| Subcategoria do aplicativo (subcategory_of_app) | subcategory_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Categoria do aplicativo (category_of_app) | category_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia de aplicativos (technology_of_app) | technology_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Risco do aplicativo (risk_of_app) | risk_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Característica do aplicativo (characteristic_of_app) | characteristic_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Contêiner do aplicativo (container_of_app) | container_of_app | additional.fields.key e additional.fields.value.string_value | ||
| SaaS de aplicativo (is_saas_of_app) | is_saas_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Estado de sanção do aplicativo (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key e additional.fields.value.string_value |
SCTP
| Campo CSV | Campo CEF | Campo LEEF | Chave do rótulo do Google Security Operations | Campo do UDM |
|---|---|---|---|---|
| Horário de recebimento (receive_time ou cef-formatted-receive_time) | receive_time ou cef-formatted-receive_time | metadata.collected_timestamp | ||
| Número de série (serial) | serial | intermediary.asset.hardware.serial_number | ||
| Type (tipo) | tipo | metadata.product_event_type | ||
| Horário gerado (time_generated ou cef-formatted-time_generated) | time_generated ou cef-formatted-time_generated | metadata.event_timestamp | ||
| Endereço de origem (src) | src | principal.ip | ||
| Endereço de destino (dst) | dst | target.ip | ||
| Nome da regra (regra) | regra | security_result.rule_name | ||
| Zona de origem (de) | de | additional.fields.key e additional.fields.value.string_value | ||
| Zona de destino (para) | a | additional.fields.key e additional.fields.value.string_value | ||
| Interface de entrada (inbound_if) | inbound_if | additional.fields.key e additional.fields.value.string_value | ||
| Interface de saída (outbound_if) | outbound_if | additional.fields.key e additional.fields.value.string_value | ||
| Ação de registro (logset) | logset | additional.fields.key e additional.fields.value.string_value | ||
| ID da sessão (sessionid) | sessionid | network.session_id | ||
| Contagem de repetições (repeatcnt) | repeatcnt | additional.fields.key e additional.fields.value.string_value | ||
| Porta de origem (sport) | esporte | principal.port | ||
| Porta de destino (dport) | dport | target.port | ||
| Protocolo IP (proto) | proto | network.ip_protocol (enum) | ||
| Ação (action) | ação | security_result.action_details security_result.action |
||
| Hierarquia de grupos de dispositivos (dg_hier_level_1 a dg_hier_level_4) | dg_hier_level_1 a dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value | ||
| Nome do dispositivo (device_name) | device_name | intermediary.hostname | ||
| Número de sequência (seqno) | seqno | metadata.product_log_id | ||
| ID da associação SCTP (assoc_id) | assoc_id | additional.fields.key e additional.fields.value.string_value | ||
| ID do protocolo de payload (ppid) | ppid | additional.fields.key e additional.fields.value.string_value | ||
| Gravidade (severity) | gravidade, | security_result.severity e security_result.severity_details | ||
| Tipo de fragmento SCTP (sctp_chunk_type) | sctp_chunk_type | additional.fields.key e additional.fields.value.string_value | ||
| Tipo de evento SCTP (sctp_event_type) | sctp_event_type | additional.fields.key e additional.fields.value.string_value | ||
| Tag de verificação SCTP 1 (verif_tag_1) | verif_tag_1 | additional.fields.key e additional.fields.value.string_value | ||
| Tag de verificação SCTP 2 (verif_tag_2) | verif_tag_2 | additional.fields.key e additional.fields.value.string_value | ||
| Código de causa do SCTP (sctp_cause_code) | sctp_cause_code | additional.fields.key e additional.fields.value.string_value | ||
| ID do app Diameter (diam_app_id) | diam_app_id | additional.fields.key e additional.fields.value.string_value | ||
| Código de comando do Diameter (diam_cmd_code) | diam_cmd_code | additional.fields.key e additional.fields.value.string_value | ||
| Código AVP do diâmetro (diam_avp_code) | diam_avp_code | additional.fields.key e additional.fields.value.string_value | ||
| ID do fluxo SCTP (stream_id) | stream_id | additional.fields.key e additional.fields.value.string_value | ||
| Motivo do término da associação SCTP (assoc_end_reason) | assoc_end_reason | additional.fields.key e additional.fields.value.string_value | ||
| Código de operação (op_code) | op_code | additional.fields.key e additional.fields.value.string_value | ||
| Número de série do assinante (SSN) da parte que está ligando SCCP (sccp_calling_ssn) | sccp_calling_ssn | additional.fields.key e additional.fields.value.string_value | ||
| Título global da parte de chamada do SCCP (sccp_calling_gt) | sccp_calling_gt | additional.fields.key e additional.fields.value.string_value | ||
| Filtro SCTP (sctp_filter) | sctp_filter | additional.fields.key e additional.fields.value.string_value | ||
| Fragmentos SCTP (fragmentos) | pedaços | additional.fields.key e additional.fields.value.string_value | ||
| Fragmentos SCTP enviados (chunks_sent) | chunks_sent | additional.fields.key e additional.fields.value.string_value | ||
| Blocos SCTP recebidos (chunks_received) | chunks_received | additional.fields.key e additional.fields.value.string_value | ||
| Pacotes (pacotes) | pacotes | additional.fields.key e additional.fields.value.string_value | ||
| UUID da regra (rule_uuid) | rule_uuid | security_result.rule_id | ||
| Sistema virtual (vsys) | vsys | intermediary.asset.attribute.labels.key/value | ||
| Nome do sistema virtual (vsys_name) | vsys_name | intermediary.asset.attribute.labels.key/value | ||
| Pacotes enviados (pkts_sent) | pkts_sent | network.sent_packets | ||
| Pacotes recebidos (pkts_received) | pkts_received | network.received_packets |
Auditoria
| Campo CSV | Campo CEF | Campo LEEF | Chave do rótulo do Google Security Operations | Campo do UDM |
|---|---|---|---|---|
| Horário de geração | metadata.event_timestamp | |||
| Tipo de ameaça/conteúdo (subtipo) | metadata.product_event_type | |||
| ID do evento | principal.application | |||
| Objeto | principal.user.userid | |||
| Comando da CLI | principal.process.command_line | |||
| Gravidade | security_result.severity | |||
| Número de série | intermediary.asset.hardware.serial_number |
Referência de mapeamento de campos: tipos de registros para tipo de evento do UDM
A tabela a seguir lista os tipos de registros de firewall da Palo Alto Networks e os tipos de eventos correspondentes da UDM.
| Tipo de registro | Tipo de evento do UDM |
| Tráfego | NETWORK_CONNECTION |
| Ameaça | NETWORK_CONNECTION |
| Filtragem de URL | NETWORK_CONNECTION |
| WildFire | NETWORK_CONNECTION
Os registros de envios do WildFire são um subtipo do tipo de registro de ameaça e usam o mesmo formato syslog. |
| Filtragem de dados | NETWORK_CONNECTION |
| Túnel | NETWORK_CONNECTION |
| GTP | NETWORK_CONNECTION |
| Configuração | SETTING_MODIFICATION/SETTING_CREATION/SETTING_DELETION/SETTING_UNCATEGORIZED
O valor do campo "Comando (cmd)" determina o mapeamento do tipo de evento da UDM. Se o valor do campo "cmd" for "add" ou "clone", SETTING_CREATION será definido. Se o valor do campo "cmd" for "delete", SETTING_DELETION será definido. Se o valor do campo "cmd" for "edit", "move", "rename", "set" ou "commit", SETTING_MODIFICATION será definido. Se o valor do campo "cmd" não tiver nenhum valor, SETTING_UNCATEGORIZED será definido. |
| Sistema |
Se o valor do subtipo for "dhcp", NETWORK_DHCP será definido. Se o valor do subtipo for "auth", USER_LOGIN será definido. Se o valor da descrição for "logged in", USER_LOGIN será definido. Se o valor da descrição for "logged out", USER_LOGOUT será definido. Para outros valores do subtipo, GENERIC_EVENT é definido. |
| Correspondência de HIP | NETWORK_CONNECTION |
| Tag de IP | GENERIC_EVENT |
| User-ID | USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED
Se o valor do subtipo for "login", USER_LOGIN será definido. Se o valor do subtipo for "logout", USER_LOGOUT será definido. Se o subtipo não tiver nenhum valor, USER_UNCATEGORIZED será definido. |
| Descriptografia | NETWORK_CONNECTION |
| Autenticação | GENERIC_EVENT |
| SCTP | NETWORK_CONNECTION |
| Auditoria | GENERIC_EVENT |
Delta de mapeamento do UDM
Referência de delta de mapeamento do UDM: firewall da Palo Alto Networks
A tabela a seguir lista o delta entre o mapeamento da UDM antiga de Palo Alto Networks Firewall e o novo mapeamento da UDM de Palo Alto Networks Firewall.
UDM Event Type Delta
| Log type | Old UDM Event Type | New UDM Event Type |
| WildFire | NETWORK_CONNECTION | SCAN_UNCATEGORIZED |
| Data Filtering | NETWORK_CONNECTION | NETWORK_UNCATEGORIZED |
| Authentication | STATUS_UPDATE | STATUS_UNCATEGORIZED |
UDM Field Mapping Delta
| Log Type | Old UDM Mapping | CSV Log Field | CEF Log Field | LEEF Log Field | New UDM Mapping |
|---|---|---|---|---|---|
| System | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| System | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| System | about.labels.key/value additional.fields.key/value.string_value | Object (object) | fname | Filename | target.resource.name |
| System | Description (opaque) | msg | msg | metadata.description | |
| System | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| System | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| Config | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| Config | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| Config | principal.process.command_line | Configuration Path (path) | msg | ConfigurationPath | principal.process.command_line |
| Config | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| Config | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| Config | principal.asset.attribute.labels.key/value | Device Group (dg_id) | PanOSFWDeviceGroup | target.asset.attribute.labels | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Threat/Wildfire | target.file.full_path target.url target.hostname | URL/Filename (misc) | request | Miscellaneous | target.file.names target.url |
| Threat/Wildfire | about.file.sha1/md5/sha256 | File Digest (filedigest) | fileHash | FileDigest | target.file.sha1/md5/sha256 |
| Threat/Wildfire | about.file.mime_type | File Type (filetype) | fileType | FileType | target.file.mime_type |
| Threat/Wildfire | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Threat/Wildfire | principal.user.product_object_id | Source VM UUID (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id |
| Threat/Wildfire | target.user.product_object_id | Destination VM UUID (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | HTTP Headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| Threat/Wildfire | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| Threat/Wildfire | principal.asset.software.version | Source Device OS Version (src_osversion) | PanSrcDeviceOSv | principal.platform_version | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| Threat/Wildfire | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| Threat/Wildfire | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | PanReasonFilteringAction | security_result.summary | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Packets Sent (pkts_sent) | PanOSPacketsSent | srcPackets | network.sent_packets |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Packets Received (pkts_received) | PanOSPacketsReceived | dstPackets | network.received_packets |
| Traffic | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| Traffic | principal.asset.platform_software.platform(enum) principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| Traffic | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| Traffic | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| User-ID | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| User-ID | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| User-ID | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | intermediary.resource.product_object_id |
| User-ID | principal.user.userid principal.administrative_domain principal.user.email_addresses | User by Source (userbysource) | PanOSUserBySource | target.user.userid target.user.email_addresses | |
| User-ID | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| HIP Match | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | HIP (matchname) | cat | HIP | target.resource.attribute.labels |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | HIP Type (matchtype) | Device Event Class ID (Header) | HIPType | target.resource.attribute.labels |
| HIP Match | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| HIP Match | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| HIP Match | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id |
| HIP Match | principal.asset.product_object_id | Host ID (hostid) | PanOSHostID | principal.asset.asset_id | |
| HIP Match | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| IP-Tag | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| IP-Tag | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| IP-Tag | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOsVsysName | vSrcName | target.asset.attribute.labels |
| IP-Tag | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| IP-Tag | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id |
| IP-Tag | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Decryption | target.application | Application (app) | app | network.application_protocol | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | intermediary.asset.attribute.labels | |
| Decryption | principal.asset.asset_id | Source VM UUID (src_uuid) | PanOSSourceUUID | principal.asset.product_object_id | |
| Decryption | target.asset.asset_id | Destination VM UUID (dst_uuid) | PanOSDestinationUUID | target.asset.product_object_id | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanOSContainerID | intermediary.resource.product_object_id | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanOSContainerNameSpace | target.resource.attribute.labels additional.fields.key/value.string_value | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanOSContainerName | target.resource.name | |
| Decryption | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanOSSourceDeviceCategory | principal.asset.category | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanOSSourceDeviceModel | principal.asset.hardware.model | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanOSSourceDeviceVendor | principal.asset.hardware.manufacturer | |
| Decryption | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanOSSourceDeviceOSFamily | principal.platform | |
| Decryption | principal.asset.software.version | Source Device OS Version (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanOSDestinationDeviceCategory | target.asset.category | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanOSDestinationDeviceModel | target.asset.hardware.model | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanOSDestinationDeviceVendor | target.asset.hardware.manufacturer | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanOSDestinationDeviceOSFamily | target.platform | |
| Decryption | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanOSDestinationDeviceOSVersion | target.platform_version | |
| Decryption | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | intermediary.asset.attribute.labels | ||
| Decryption | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Tunnel | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Packets Sent (pkts_sent) | PanOSPacketsSent | srcPackets | network.sent_packets |
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Packets Received (pkts_received) | PanOSPacketsReceived | dstPackets | network.received_packets |
| Tunnel | target.ip | Remote User IP (remote_user_ip) | PanOSRmtUserIP | principal.ip | |
| Tunnel | target.labels.key/value additional.fields.key/value.string_value | Remote User ID (remote_user_id) | PanOSRmtUserID | principal.user.userid | |
| Tunnel | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Authentication | target.user.user_display_name | Normalize User (normalize_user) | cs2 | NormalizeUser | target.user.user_display_name |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Object (object) | fname | ObjectName | target.resource.name |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Authentication Policy (authpolicy) | cs4 | AuthPolicy | additional.fields.key/value.string_value |
| Authentication | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Authentication | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| Authentication | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res _timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanOSSourceDeviceCategory | principal.asset.category | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanOSSourceDeviceModel | principal.asset.hardware.model | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanOSSourceDeviceVendor | principal.asset.hardware.manufacturer | |
| Authentication | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanOSSourceDeviceOSFamily | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | |
| Authentication | principal.asset.software.version | Source Device OS Version (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| URL | target.file.full_path target.url | URL/Filename (misc) | Miscellaneous | target.file.names target.url | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Category (category) | cs2 | URLCategory | security_result.category_details |
| URL | about.file.sha1/md5/sha256 | filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | |
| URL | about.file.mime_type | filetype (filetype) | target.file.mime_type | ||
| URL | about.labels.key/value additional.fields.key/value.string_value | xff (xff) | PanOSXForwarderfor | identSrc | principal.ip |
| URL | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| URL | about.url | file_url (file_url) | target.url | ||
| URL | principal.asset.asset_id | Source VM UUID (src_uuid) | SrcUUID | principal.asset.product_object_id | |
| URL | target.asset.asset_id | Destination VM UUID (dst_uuid) | DstUUID | target.asset.product_object_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | http_headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| URL | about.labels.key/value additional.fields.key/value.string_value | UUID for rule (rule_uuid) | PanOSRuleUUID | security_result.rule_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| URL | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| URL | principal.asset.software.version | Source Device OS Version (src_osversion) | PanSrcDeviceOSv | principal.platform_version | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Hostname (src_host) | PanSrcHostname | principal.hostname | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| URL | target.asset.platform_software.platform target.labels.key/value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| URL | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| URL | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| URL | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Res Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | PanReasonFilteringAction | security_result.summary | |
| Data | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Data | target.file.full_path target.url | URL/Filename (misc) | Miscellaneous | target.file.names target.url | |
| Data | about.labels.key/value additional.fields.key/value.string_value | Category (category) | cs2 | URLCategory | security_result.category_details |
| Data | about.file.sha1/md5/sha256 | filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | |
| Data | about.file.mime_type | filetype (filetype) | target.file.mime_type | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | xff (xff) | principal.ip | ||
| Data | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Data | about.url | file_url (file_url) | target.url | ||
| Data | principal.asset.asset_id | Source VM UUID (src_uuid) | SrcUUID | principal.asset.product_object_id | |
| Data | target.asset.asset_id | Destination VM UUID (dst_uuid) | DstUUID | target.asset.product_object_id | |
| Data | about.labels.key/value additional.fields.key/value.string_value | http_headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| Data | about.labels.key/value additional.fields.key/value.string_value | UUID for rule (rule_uuid) | PanOSRuleUUID | security_result.rule_id | |
| Data | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | network.application_protocol_version | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | principal.asset.category | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | principal.asset.hardware.model | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | principal.asset.hardware.manufacturer | ||
| Data | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | principal.platform | ||
| Data | principal.asset.software.version | Source Device OS Version (src_osversion) | principal.platform_version | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Hostname (src_host) | principal.hostname | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | target.asset.category | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | target.asset.hardware.model | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | target.asset.hardware.manufacturer | ||
| Data | target.asset.platform_software.platform target.labels.key/value | Destination Device OS Family (dst_osfamily) | target.platform | ||
| Data | target.asset.software.version | Destination Device OS Version (dst_osversion) | target.platform_version | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | intermediary.resource.product_object_id | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | target.resource.attribute.labels | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | target.resource.name | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | principal.asset.asset_id | ||
| Data | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Res Timestamp (high_res_timestamp) | additional.fields.key/value.string_value | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | security_result.summary | ||
| GlobalProtect | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | PanOSVirtualSystem | intermediary.asset.attribute.labels | |
| GlobalProtect | principal.user.email_address principal.user.userid principal.administrative_domain | Source User (srcuser) | PanOSSourceUserName | target.user.email_address target.user.userid | |
| GlobalProtect | principal.asset.platform_software.platform(enum) | Client OS (client_os) | PanOSEndpointOSType | principal.platform | |
| GlobalProtect | principal.asset.platform_software.platform_version | Client OS Version (client_os_ver) | PanOSEndpointOSVersion | principal.platform_version | |
| GlobalProtect | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| GlobalProtect | about.labels.key/value additional.fields.key/value.string_value | Gateway Name (gateway) | PanOSAttemptedGateways | target.resource.name | |
| GlobalProtect | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | intermediary.asset.attribute.labels | ||
| GlobalProtect | target.hostname | Device Name (device_name) | intermediary.hostname | ||
| GlobalProtect | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| CORRELATION | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | VirtualSystem | intermediary.asset.attribute.labels | |
| CORRELATION | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | vSrcName | intermediary.asset.attribute.labels | |
| CORRELATION | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | VirtualSystemID | intermediary.resource.product_object_id | |
| GTP | additional.fields.key/value.string_value | Virtual System (vsys) | intermediary.asset.attribute.labels | ||
| GTP | target.ip | Remote User IP (remote_user_ip) | principal.ip | ||
| GTP | additional.fields.key/value.string_value | Remote User ID (remote_user_id) | principal.user.userid | ||
| GTP | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | additional.fields.key/value.string_value |
Serviço de geração de registros do firewall Strata da Palo Alto Networks.
Visão geral
O serviço de geração de registros do Strata da Palo Alto Networks® oferece armazenamento e agregação de registros centralizados e baseados na nuvem para seus firewalls locais, virtuais (nuvem privada e pública), para o Prisma Access e para serviços fornecidos na nuvem, como o Cortex XDR.O serviço de geração de registros do Strata é seguro, resiliente e tolerante a falhas, além de garantir que seus dados de registro estejam atualizados e disponíveis quando você precisar deles. Ela oferece uma infraestrutura de geração de registros escalonável que elimina a necessidade de planejar e implantar coletores de registros para atender às suas necessidades de retenção. Se você já tiver coletores de registros locais, o novo serviço de registros do Strata poderá complementar sua configuração atual. É possível aumentar sua infraestrutura de coleta de registros atual com o serviço de geração de registros do Strata baseado na nuvem para expandir a capacidade operacional à medida que sua empresa cresce ou para atender às necessidades de capacidade de novas unidades.Com esse serviço, a Palo Alto Networks cuida da manutenção e do monitoramento contínuos da infraestrutura de geração de registros para que você possa se concentrar nos negócios.
Verifique os formatos de registro e as versões do PAN-OS compatíveis com o analisador do Strata Logging Service. A tabela a seguir lista os formatos de registro e as versões correspondentes do PAN-OS compatíveis com o analisador do serviço de geração de registros do Strata:
Formato do registro Versão do PAN-OS JSON 12.1 Verifique os tipos de registros de firewall da Palo Alto Networks compatíveis com o analisador do Google SecOps. O analisador do Google SecOps é compatível com os seguintes tipos de registros de firewall da Palo Alto Networks:
- Tráfego
- Ameaça
- Inspeção de túnel
- Sistema
- Correspondência de HIP
- IP-Tag
- User-ID
- Descriptografia
- Autenticação
- Filtragem de URL
- GlobalProtect
Implantação do serviço de geração de registros do Strata
- Verifique se o produto de firewall da Palo Alto Networks está implantado e configurado corretamente. Para instruções de configuração detalhadas, consulte a Documentação do PAN-OS e siga este documento de implantação antes de enviar registros ao serviço de registro em strata Pré-requisitos de implantação do serviço de registro em strata.
Comece a enviar registros ao serviço de registro do Strata:
Para começar a enviar registros ao serviço de registro do Strata, siga estas etapas:
- Instalar uma versão compatível do PAN-OS®
- Ative o serviço de geração de registros do Strata. Isso inclui o provisionamento do certificado necessário para que os firewalls se conectem com segurança ao serviço.
- Integrar firewalls ao serviço de geração de registros do Strata com ou sem o Panorama
Para conferir as etapas detalhadas de integração, consulte a documentação.
Encaminhar registros do serviço de registro do Strata
Para atender às suas necessidades de armazenamento, relatórios e monitoramento de longo prazo ou legais e de compliance, configure o serviço de geração de registros do Strata para encaminhar registros a um servidor HTTPS ou aos seguintes SIEMs:
- Exabeam
- Google Chronicle
- Microsoft Sentinel
- Coletor de eventos HTTP (HEC) do Splunk
Use o método de encaminhamento HTTPS para encaminhar os registros usando o serviço de geração de registros do Strata. Para informações detalhadas, consulte esta documentação.
Formatos de registro aceitos
O analisador de firewall do serviço de registro do Strata da Palo Alto Networks é compatível com registros no formato JSON.
Registros de amostra compatíveis
JSON
{"source": "Palo Alto Networks FLS LF", "host": "dummy-loghost", "time": "1730265996460", "event": {"TimeReceived": "2024-10-30T05:25:50.000000Z", "DeviceSN": "no-serial", "LogType": "TRAFFIC", "Subtype": "end", "ConfigVersion": "10.2", "TimeGenerated": "2024-10-30T05:25:40.000000Z", "SourceAddress": "198.51.100.6", "DestinationAddress": "198.51.100.6", "NATSource": "", "NATDestination": "", "Rule": "egress-dns-ping-traceroute", "SourceUser": null, "DestinationUser": null, "Application": "dns-base", "VirtualLocation": "vsys1", "FromZone": "VA8280-RN", "ToZone": "inter-fw", "InboundInterface": "tunnel.101", "OutboundInterface": "tunnel.4005", "LogSetting": "Cortex Data Lake", "SessionID": 754194, "RepeatCount": 1, "SourcePort": 53578, "DestinationPort": 53, "NATSourcePort": 0, "NATDestinationPort": 0, "Protocol": "udp", "Action": "allow", "Bytes": 214, "BytesSent": 72, "BytesReceived": 142, "PacketsTotal": 2, "SessionStartTime": "2024-10-30T05:25:10.000000Z", "SessionDuration": 0, "URLCategory": "any", "SequenceNo": 7382192512716388639, "SourceLocation": "198.51.100.6-198.51.255.255", "DestinationLocation": "198.51.100.6-198.51.255.255", "PacketsSent": 1, "PacketsReceived": 1, "SessionEndReason": "aged-out", "DGHierarchyLevel1": 65537, "DGHierarchyLevel2": 65538, "DGHierarchyLevel3": 65541, "DGHierarchyLevel4": 0, "VirtualSystemName": "", "DeviceName": "VA8280-RN", "ActionSource": "from-policy", "SourceUUID": null, "DestinationUUID": null, "IMSI": 0, "IMEI": null, "ParentSessionID": 0, "ParentStarttime": "1970-01-01T00:00:00.000000Z", "Tunnel": "N/A", "EndpointAssociationID": 72057594037927936, "ChunksTotal": 0, "ChunksSent": 0, "ChunksReceived": 0, "RuleUUID": "95cfc3cc-cb00-4758-af1d-de9ab5f07f97", "HTTP2Connection": 0, "LinkChangeCount": 0, "SDWANPolicyName": null, "LinkSwitches": null, "SDWANCluster": null, "SDWANDeviceType": null, "SDWANClusterType": null, "SDWANSite": null, "DynamicUserGroupName": null, "X-Forwarded-ForIP": null, "SourceDeviceCategory": null, "SourceDeviceProfile": null, "SourceDeviceModel": null, "SourceDeviceVendor": null, "SourceDeviceOSFamily": null, "SourceDeviceOSVersion": null, "SourceDeviceHost": null, "SourceDeviceMac": null, "DestinationDeviceCategory": null, "DestinationDeviceProfile": null, "DestinationDeviceModel": null, "DestinationDeviceVendor": null, "DestinationDeviceOSFamily": null, "DestinationDeviceOSVersion": null, "DestinationDeviceHost": null, "DestinationDeviceMac": null, "ContainerID": null, "ContainerNameSpace": null, "ContainerName": null, "SourceEDL": null, "DestinationEDL": null, "GPHostID": null, "EndpointSerialNumber": null, "SourceDynamicAddressGroup": null, "DestinationDynamicAddressGroup": null, "HASessionOwner": null, "TimeGeneratedHighResolution": "2024-10-30T05:25:41.009000Z", "NSSAINetworkSliceType": null, "NSSAINetworkSliceDifferentiator": null}}"
Referência de mapeamento de campos: campos de registros para campos da UDM
Nesta seção, explicamos como o analisador mapeia os campos de registro do firewall do serviço de registro em log do Palo Alto Networks Strata para os campos de evento do UDM do Google em cada tipo de registro.
Consulte as seções a seguir para ver a referência de mapeamento de cada tipo de registro:
- Sistema
- Ameaça
- Tráfego
- ID do usuário
- Correspondência de HIP
- Tag de IP
- Descriptografia
- Tunnel
- Authentication
- URL
- GlobalProtect
- SCTP
- Auditoria
Sistema
A tabela a seguir lista os campos de registro do tipo "Registro do sistema" e os campos correspondentes da UDM.
| Log field | UDM mapping |
|---|---|
| AgentContentVersion | additional.fields.key/value.string_value |
| AgentDataCollectionStatus | target.resource.attribute.labels |
| AgentID | target.resource.attribute.labels |
| AgentIsolationStatus | target.resource.attribute.labels |
| AgentStatus | target.resource.attribute.labels |
| AgentVersion | target.asset.software.version |
| ConfigVersion | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DeviceGroup | target.group.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EndpointCPUArchitecture | target.asset.hardware.cpu_platform |
| EndpointDeviceDomain | target.asset.administrative_domain |
| EndpointDeviceName | target.asset.hostname |
| EndpointIPaddress | target.asset.ip |
| VDIEndpoint | target.asset.attribute.labels |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointOSVersion | target.platform_version |
| AgentTimeZoneOffset | additional.fields.key/value.string_value |
| EndpointUserDomain | additional.fields.key/value.string_value |
| EndpointUserName | target.user.user_display_name |
| EndpointUserUUID | target.user.userid |
| EventComponent | additional.fields.key/value.string_value |
| EventDescription | metadata.description |
| EventName | additional.fields.key/value.string_value |
| EventTime | metadata.event_timestamp |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogCategory | security_result.category_details |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| LogSourceID | target.resource.attribute.labels |
| LogSourceName | observer.asset.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| LogTime | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Severity | security_result.severity |
| Subtype | metadata.product_event_type |
| Template | target.resource.attribute.labels |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
Ameaça
A tabela a seguir lista os campos de registro do tipo "Registro de ameaças" e os campos correspondentes da UDM.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| ApplianceOrCloud | additional.fields.key/value.string_value |
| CloudHostname | additional.fields.key/value.string_value |
| CloudReportID | security_result.detection_fields.key/value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DirectionOfAttack | security_result.detection_fields.key/value |
| DomainEDL | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| FileName | target.file.names |
| FileHash | target.file.sha1 |
| FileType | additional.fields.key/value.string_value |
| FileURL | target.url |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HostID | principal.asset.asset_id |
| HTTP2Connection | network.application_protocol_version |
| HTTPMethod | network.http.method |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| LocalDeepLearningAnalyzed | additional.fields.key/value.string_value |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| PartialHash | additional.fields.key/value.string_value |
| PayloadProtocolID | additional.fields.key/value.string_value |
| Packet | additional.fields.key/value.string_value |
| PacketID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| RecipientEmail | target.user.email_addresses |
| ReportID | security_result.detection_fields.key/value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SenderEmail | principal.user.email_addresses |
| SequenceNo | metadata.product_log_id |
| SessionID | network.session_id |
| Severity | security_result.severity |
| SigFlags | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| EmailSubject | network.email.subject |
| ApplicationTechnology | additional.fields.key/value.string_value |
| ThreatCategory | security_result.detection_fields.key/value.key/value |
| ThreatID | security_result.threat_id |
| ThreatName | security_result.threat_name |
| ThreatNameFirewall | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLDomain | target.domain.name |
| URLCounter | additional.fields.key/value.string_value |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| Verdict | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-ForIP | principal.ip |
Tráfego
A tabela a seguir lista os campos de registro do tipo "Tráfego" e os campos correspondentes da UDM.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| ActionSource | additional.fields.key/value.string_value |
| AIFwdError | additional.fields.key/value.string_value |
| AITraffic | additional.fields.key/value.string_value |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| BytesReceived | network.received_bytes |
| BytesSent | network.sent_bytes |
| Bytes | additional.fields.key/value.string_value |
| ChunksReceived | additional.fields.key/value.string_value |
| ChunksSent | additional.fields.key/value.string_value |
| ChunksTotal | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| EndpointAssociationID | additional.fields.key/value.string_value |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HASessionOwner | additional.fields.key/value.string_value |
| GPHostID | additional.fields.key/value.string_value |
| HTTP2Connection | network.application_protocol_version |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsOffloaded | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| LinkChangeCount | additional.fields.key/value.string_value |
| LinkSwitches | additional.fields.key/value.string_value |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| SDWANPolicyName | additional.fields.key/value.string_value |
| Protocol | network.ip_protocol |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SDWANFECRatio | additional.fields.key/value.string_value |
| SDWANCluster | additional.fields.key/value.string_value |
| SDWANClusterType | additional.fields.key/value.string_value |
| SDWANDeviceType | additional.fields.key/value.string_value |
| SDWANSite | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionStartTime | additional.fields.key/value.string_value |
| SessionTracker | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| SessionDuration | network.session_duration |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLCategory | target.url_metadata.categories |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-ForIP | principal.ip |
User-ID
A tabela a seguir lista os campos de registro do tipo de registro User-ID e os campos correspondentes da UDM.
| Log field | UDM mapping |
|---|---|
| AuthFactorNo | security_result.detection_fields.key/value |
| AuthenticatedUserDomain | target.user.administrative_domain |
| AuthenticatedUserName | target.user.userid |
| AuthenticatedUserUUID | target.user.product_object_id |
| ConfigVersion | additional.fields.key/value.string_value |
| CountofRepeats | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationPort | target.port |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EventID | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsDuplicateUser | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MappingDataSource | additional.fields.key/value.string_value |
| MappingDataSourceName | additional.fields.key/value.string_value |
| MappingDataSourceType | additional.fields.key/value.string_value |
| MappingTimeout | additional.fields.key/value.string_value |
| MFAFactorType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SourceIP | principal.ip |
| SourcePort | principal.port |
| Subtype | metadata.product_event_type |
| Tag | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| UGFlags | additional.fields.key/value.string_value |
| User | target.user.userid |
| UserGroupFound | additional.fields.key/value.string_value |
| UserIdentifiedBySource | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Correspondência de HIP
A tabela a seguir lista os campos de registro do tipo de registro de correspondência do HIP e os campos correspondentes da UDM.
| Log field | UDM mapping |
|---|---|
| ConfigVersion | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EndpointDeviceName | principal.asset.hostname |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| HipMatchName | target.resource.attribute.labels |
| HipMatchType | target.resource.attribute.labels |
| HostID | principal.asset.asset_id |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | metadata.product_event_type |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Source | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceIP | principal.ip |
| SourceIPv6 | principal.ip |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| TimestampDeviceIdentification | principal.asset.first_seen_time |
| UUID | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
Tag de IP
A tabela a seguir lista os campos de registro do tipo de registro de tag de IP e os campos correspondentes da UDM.
| Log field | UDM mapping |
|---|---|
| ConfigVersion | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EventID | additional.fields.key/value.string_value |
| IPSubnetRange | network.ip_subnet_range |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSetting | target.resource.attribute.labels |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MappingDataSource | additional.fields.key/value.string_value |
| MappingDataSourceSubType | additional.fields.key/value.string_value |
| MappingDataSourceType | additional.fields.key/value.string_value |
| MappingTimeout | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| RuleMatched | security_result.rule_name |
| RuleMatchedUUID | security_result.rule_id |
| SequenceNo | metadata.product_log_id |
| SourceIP | principal.ip |
| Subtype | metadata.product_event_type |
| TagName | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
Descriptografia
A tabela a seguir lista os campos de registro do tipo "Decryption" e os campos correspondentes da UDM.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| CertificateFlags | additional.fields.key/value.string_value |
| CertificateSerial | network.tls.server.certificate.serial |
| CertificateSize | additional.fields.key/value.string_value |
| CertificateVersion | network.tls.server.certificate.version |
| ChainStatus | additional.fields.key/value.string_value |
| ApplicationCharacteristics | additional.fields.key/value.string_value |
| ClientToFirewall | additional.fields.key/value.string_value |
| CommonName | additional.fields.key/value.string_value |
| CommonNameLength | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| Cpadding | additional.fields.key/value.string_value |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| Domain | target.hostname |
| EllipticCurve | network.tls.curve |
| ErrorIndex | additional.fields.key/value.string_value |
| ErrorMessage | additional.fields.key/value.string_value |
| Fingerprint | network.tls.server.certificate.md5/sha1/sha256 |
| FirewallToClient | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsCertECDSA | additional.fields.key/value.string_value |
| IsCertRSA | additional.fields.key/value.string_value |
| IsCertCNTruncated | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| IsForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsIssuerCNTruncated | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| IsNAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| PacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsResumeSession | additional.fields.key/value.string_value |
| IsRootCNTruncated | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSNITruncated | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| IssuerCommonName | network.tls.server.certificate.issuer |
| IssuerNameLength | additional.fields.key/value.string_value |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| TimeNotAfter | additional.fields.key/value.string_value |
| TimeNotBefore | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| Padding | additional.fields.key/value.string_value |
| Padding3 | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| PolicyName | additional.fields.key/value.string_value |
| Protocol | network.ip_protocol |
| ProxyType | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| RootCommonName | additional.fields.key/value.string_value |
| RootCNLength | additional.fields.key/value.string_value |
| RootStatus | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SessionID | network.session_id |
| ServerNameIndication | network.tls.client.server_name |
| SNILength | additional.fields.key/value.string_value |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeReceivedManagementPlane | additional.fields.key/value.string_value |
| TLSAuth | additional.fields.key/value.string_value |
| TLSEncryptionAlgorithm | additional.fields.key/value.string_value |
| TLSKeyExchange | additional.fields.key/value.string_value |
| TLSVersion | network.tls.version |
| ToZone | additional.fields.key/value.string_value |
| Tpadding | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| Vpadding | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Túnel
A tabela a seguir lista os campos de registro do tipo "Tunnel" e os campos correspondentes da UDM.
| Log field | UDM mapping |
|---|---|
| AccessPointName | additional.fields.key/value.string_value |
| Action | security_result.action |
| ActionSource | additional.fields.key/value.string_value |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| BytesReceived | network.received_bytes |
| BytesSent | network.sent_bytes |
| Bytes | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| LoggingServiceID | additional.fields.key/value.string_value |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MobileAreaCode | additional.fields.key/value.string_value |
| MobileBaseStationCode | additional.fields.key/value.string_value |
| MobileCountryCode | additional.fields.key/value.string_value |
| MobileIP | additional.fields.key/value.string_value |
| MobileNetworkCode | additional.fields.key/value.string_value |
| MobileSubscriberISDN | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceDifferentiator | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsDroppedMax | additional.fields.key/value.string_value |
| PacketsDroppedStrict | additional.fields.key/value.string_value |
| PacketsDroppedTunnel | additional.fields.key/value.string_value |
| PacketsDroppedProtocol | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| ProtocolDataUnitsessionID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| RadioAccessTechnology | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionStartTime | additional.fields.key/value.string_value |
| SessionTracker | additional.fields.key/value.string_value |
| Severity | security_result.severity |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| StandardPortsOfApp | additional.fields.key/value.string_value |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| SessionDuration | network.session_duration |
| Tunnel | additional.fields.key/value.string_value |
| TunnelCauseCode | additional.fields.key/value.string_value |
| TunnelEndpointID1 | additional.fields.key/value.string_value |
| TunnelEndpointID2 | additional.fields.key/value.string_value |
| TunnelEventCode | additional.fields.key/value.string_value |
| TunnelEventType | additional.fields.key/value.string_value |
| TunnelInspectionRule | additional.fields.key/value.string_value |
| TunnelInterface | additional.fields.key/value.string_value |
| TunnelMessageType | additional.fields.key/value.string_value |
| TunnelRemoteIMSIID | additional.fields.key/value.string_value |
| TunnelRemoteUserIP | principal.ip |
| TunnelSessionsClosed | additional.fields.key/value.string_value |
| TunnelSessionsCreated | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLCategory | target.url_metadata.categories |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Autenticação
A tabela a seguir lista os campos de registro do tipo "Registro de autenticação" e os campos correspondentes da UDM.
| Log field | UDM mapping |
|---|---|
| AuthenticationDescription | security_result.description |
| AuthEvent | metadata.description |
| AuthFactorNo | security_result.detection_fields.key/value |
| AuthenticationPolicy | security_result.detection_fields.key/value |
| AuthenticationProtocol | additional.fields.key/value.string_value |
| AuthServerProfile | additional.fields.key/value.string_value |
| AuthenticatedUserDomain | target.administrative_domain |
| AuthenticatedUserName | target.user.userid |
| AuthenticatedUserUUID | target.user.product_object_id |
| ClientType | additional.fields.key/value.string_value |
| ClientTypeName | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| Location | target.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogType | additional.fields.key/value.string_value |
| MFAAuthenticationID | additional.fields.key/value.string_value |
| MFAVendor | additional.fields.key/value.string_value |
| NormalizeUser | target.user.user_display_name |
| Object | target.resource.name |
| RuleMatched | security_result.rule_name |
| RuleMatchedUUID | security_result.rule_id |
| AuthCacheServiceRegion | additional.fields.key/value.string_value |
| SessionID | network.session_id |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceIP | principal.ip |
| TimeGenerated | metadata.event_timestamp |
| User | target.user.userid |
| UserAgentString | network.http.user_agent |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Subtype | metadata.product_event_type |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
URL
A tabela a seguir lista os campos de registro do tipo de registro de URL e os campos correspondentes da UDM.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| CloudHostname | additional.fields.key/value.string_value |
| CloudReportID | security_result.detection_fields.key/value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentType | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DirectionOfAttack | security_result.detection_fields.key/value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| FileURL | target.url |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HostID | principal.asset.asset_id |
| HTTP2Connection | network.application_protocol_version |
| HTTPHeaders | additional.fields.key/value.string_value |
| HTTPMethod | network.http.method |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| InlineMLVerdict | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| Packet | additional.fields.key/value.string_value |
| PacketID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| Referer | network.http.referral_url |
| HTTPRefererFQDN | additional.fields.key/value.string_value |
| HTTPRefererPort | additional.fields.key/value.string_value |
| HTTPRefererProtocol | additional.fields.key/value.string_value |
| HTTPRefererURLPath | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionID | network.session_id |
| Severity | security_result.severity |
| SigFlags | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URL | target.url_metadata.URL |
| URLCategory | target.url_metadata.categories |
| URLCategoryList | additional.fields.key/value.string_value |
| URLDomain | target.domain.name |
| URLCounter | additional.fields.key/value.string_value |
| UserAgent | network.http.user_agent |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-For | additional.fields.key/value.string_value |
| X-Forwarded-ForIP | principal.ip |
GlobalProtect
A tabela a seguir lista os campos de registro do tipo GlobalProtect e os campos correspondentes da UDM.
| Log field | UDM mapping |
|---|---|
| AttemptedGateways | additional.fields.key/value.string_value |
| AuthMethod | extensions.auth.auth_details |
| ConnectionMethod | additional.fields.key/value.string_value |
| ConnectionErrorID | additional.fields.key/value.string_value |
| ConnectionError | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| EndpointDeviceName | principal.asset.hostname |
| GlobalProtectClientVersion | additional.fields.key/value.string_value |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointSN | principal.asset.hardware.serial_number |
| EventIDValue | additional.fields.key/value.string_value |
| Gateway | target.resource.name |
| GatewayPriority | additional.fields.key/value.string_value |
| GatewaySelectionType | additional.fields.key/value.string_value |
| GlobalProtectGatewayLocation | target.location.country_or_region |
| HostID | principal.asset.asset_id |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LoginDuration | network.session_duration |
| Description | security_result.description |
| Portal | target.hostname |
| PrivateIPv4 | principal.ip |
| PrivateIPv6 | principal.ip |
| ProjectName | additional.fields.key/value.string_value |
| PublicIPv4 | principal.nat_ip |
| PublicIPv6 | principal.nat_ip |
| QuarantineReason | security_result.summary |
| SequenceNo | metadata.product_log_id |
| SourceRegion | principal.location.country_or_region |
| SourceUserName | principal.user.user_display_name |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SSLResponseTime | additional.fields.key/value.string_value |
| Stage | additional.fields.key/value.string_value |
| EventStatus | additional.fields.key/value.string_value |
| LogSubtype | metadata.product_event_type |
| TunnelType | additional.fields.key/value.string_value |
| VirtualSystem | intermediary.asset.attribute.labels |
| VirtualSystemName | intermediary.asset.attribute.labels |
| EndpointOSVersion | principal.platform_version |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | metadata.product_event_type |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualSystemID | intermediary.resource.product_object_id |
SCTP
A tabela a seguir lista os campos de registro do tipo de registro SCTP e os campos correspondentes da UDM.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| AssocationEndReason | additional.fields.key/value.string_value |
| ChunksReceived | additional.fields.key/value.string_value |
| ChunksSent | additional.fields.key/value.string_value |
| ChunksTotal | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceClass | target.asset.category |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationIP | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DiamAppID | additional.fields.key/value.string_value |
| DiamAvpCode | additional.fields.key/value.string_value |
| DiameterCommandCode | additional.fields.key/value.string_value |
| DiameterRequestFlag | additional.fields.key/value.string_value |
| DeviceName | principal.asset.hostname |
| SCTPEventType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLFiltering | additional.fields.key/value.string_value |
| IsWildfire | additional.fields.key/value.string_value |
| LogAction | additional.fields.key/value.string_value |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MapAppCode | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PayloadProtocolID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SccpCallingGt | additional.fields.key/value.string_value |
| SccpCallingSSN | additional.fields.key/value.string_value |
| SctpCauseCode | additional.fields.key/value.string_value |
| SctpChunkType | additional.fields.key/value.string_value |
| SctpFilter | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionTracker | additional.fields.key/value.string_value |
| Severity | security_result.severity |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceIP | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VerificationTag1 | additional.fields.key/value.string_value |
| VerificationTag2 | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Auditoria
A tabela a seguir lista os campos de registro do tipo "Registro de auditoria" e os campos correspondentes da UDM.
| Log field | UDM mapping |
|---|---|
| EventCategory | network.http.method |
| EventDescription | metadata.description |
| EventDestinationURL | target.url |
| EventDestinationUserUserID | target.user.userid |
| DestinationVendor | additional.fields.key/value.string_value |
| EventDetails | additional.fields.key/value.string_value |
| EventID | metadata.product_log_id |
| EventName | additional.fields.key/value.string_value |
| EventResult | security_result.summary |
| EventSourceUserUserID | principal.user.userid |
| EventTime | metadata.event_timestamp |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| Subtype | metadata.product_event_type |
| TSGID | additional.fields.key/value.string_value |
| Vendor | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
Referência de mapeamento de campos: tipos de registros para tipo de evento do UDM
A tabela a seguir lista os tipos de registro de firewall do serviço de registro do Strata da Palo Alto Networks e os tipos de evento UDM correspondentes.
| Tipo de registro | Tipo de evento do UDM |
| Tráfego | NETWORK_CONNECTION |
| Ameaça | NETWORK_CONNECTION |
| Filtragem de URL | NETWORK_CONNECTION |
| Túnel | NETWORK_CONNECTION |
| Sistema |
Se o valor do subtipo for "dhcp", NETWORK_DHCP será definido. Se o valor do subtipo for "auth", USER_LOGIN será definido. Se o valor da descrição for "logged in", USER_LOGIN será definido. Se o valor da descrição for "logged out", USER_LOGOUT será definido. Para outros valores do subtipo, GENERIC_EVENT é definido. |
| Correspondência de HIP | NETWORK_CONNECTION |
| Tag de IP | GENERIC_EVENT |
| User-ID | USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED
Se o valor do subtipo for "login", USER_LOGIN será definido. Se o valor do subtipo for "logout", USER_LOGOUT será definido. Se o subtipo não tiver nenhum valor, USER_UNCATEGORIZED será definido. |
| Descriptografia | NETWORK_CONNECTION |
| Autenticação | STATUS_UNCATEGORIZED |
| Globalprotect | USER_LOGIN/USER_LOGOUT/USER_RESOURCE_ACCESS
Se o valor do subtipo for "auth", USER_LOGIN será definido. Se o valor do subtipo for "logout", USER_LOGOUT será definido. Se o subtipo não tiver um valor, USER_RESOURCE_ACCESS será definido. |
| SCTP | NETWORK_CONNECTION |
| Auditoria | NETWORK_CONNECTION |
A seguir
Precisa de mais ajuda? Receba respostas de membros da comunidade e profissionais do Google SecOps.