收集 Palo Alto Networks 防火牆記錄

支援的國家/地區:

Palo Alto Networks 防火牆

總覽

本文說明如何設定系統記錄檔和 Google SecOps 轉送器,以收集 Palo Alto Networks 防火牆記錄。本文也說明 Palo Alto Networks 防火牆記錄欄位如何對應至 Google SecOps 整合式資料模型 (UDM) 欄位。如要瞭解 Google SecOps 資料擷取作業的概況,請參閱「將資料擷取至 Google SecOps」。擷取標籤會識別剖析器,該剖析器會將原始記錄資料正規化為具結構性的 UDM 格式。本文中的資訊適用於具有 PAN_FIREWALL 攝入標籤的剖析器。

事前準備

  • 確認 Palo Alto Networks 防火牆產品已正確部署及設定。如需詳細設定操作說明,請參閱 PAN-OS 說明文件
  • 如要瞭解部署的元件,以便收集 Palo Alto Networks 防火牆記錄,請查看部署架構。每個客戶部署作業可能與此表示法不同,也可能更複雜。下圖顯示如何在 Palo Alto Networks 防火牆上設定系統記錄,以及在 Linux 伺服器上安裝 Google SecOps 轉送器,將記錄資料轉送至 Google SecOps。剖析器支援以半形逗號分隔值 (CSV)、通用事件格式 (CEF) 和記錄事件擴充格式 (LEEF) 等資料格式編寫的記錄。

    部署架構

  • 確認 Google SecOps 剖析器支援的記錄格式和 PAN-OS 版本。下表列出 Google SecOps 剖析器支援的記錄格式和對應的 PAN-OS 版本:

    記錄格式 PAN-OS 版本
    CSV 10.1.3
    CEF 10.0.0
    LEEF 9.1.0
  • 確認 Google SecOps 剖析器支援的 Palo Alto Networks 防火牆記錄檔類型。 Google SecOps 剖析器支援下列 Palo Alto Networks 防火牆記錄類型:

    • 流量
    • 威脅
    • WildFire 提交內容
    • 隧道檢查
    • 設定
    • 系統
    • HIP 比對
    • IP-Tag
    • User-ID
    • 解密
    • 驗證
    • 網址篩選
    • 資料篩選
    • GlobalProtect
    • 關聯性
    • GTP
    • SCTP
    • 稽核

    如要進一步瞭解 Palo Alto Networks 防火牆記錄類型,請參閱 PAN-OS 記錄類型

  • 請確保部署架構中的所有系統都以世界標準時間設定。

  • 使用 Palo Alto Networks 防火牆剖析器前,請先查看舊版剖析器與現行 Palo Alto Networks 防火牆剖析器之間的欄位對應關係變化。在遷移過程中,請確保依附於原始欄位的規則、搜尋、資訊主頁或其他程序,都使用更新後的欄位。

    舉例來說,在先前的剖析器版本中,category 記錄檔欄位會對應至 security_result.description UDM 欄位。在目前的 Palo Alto Networks 防火牆剖析器中,category 記錄欄位會對應至 security_result.category_details UDM 欄位。如果您遷移至目前的 Palo Alto Networks 防火牆剖析器,並在規則中使用 category 欄位,則需要修改規則,才能使用目前剖析器的 security_result.category_details UDM 欄位。

設定系統記錄和 Google Security Operations 轉送器

如要設定系統記錄和 Google SecOps 轉送器,請完成下列步驟:

  1. 如要監控 CSV 記錄檔,請設定系統記錄檔伺服器設定檔。詳情請參閱「設定系統記錄伺服器設定檔」。設定系統記錄伺服器設定檔時,請將「Default」指定為自訂記錄格式。
  2. 如要監控 CEF 記錄,請設定 Palo Alto Networks 防火牆轉送 CEF 記錄。詳情請下載 PAN-OS CEF 整合指南 PDF,並參閱「Configuration of Palo Alto Networks NGFW to output CEF events」(設定 Palo Alto Networks NGFW 以輸出 CEF 事件) 一節。
  3. 如要監控 LEEF 記錄,請設定系統記錄檔伺服器設定檔。詳情請參閱「以 LEEF 格式轉送自訂記錄」。
  4. 設定 Google SecOps 轉送器,將記錄傳送至 Google Security Operations。詳情請參閱「在 Linux 上安裝及設定轉送器」。以下是 Google SecOps 轉送站設定範例:

      - syslog:
          common:
            enabled: true
            data_type: PAN_FIREWALL
            batch_n_seconds: 10
            batch_n_bytes: 1048576
          tcp_address: 0.0.0.0:10518
          connection_timeout_sec: 60
    

在 PAN 防火牆上設定系統記錄轉送

建立系統記錄伺服器設定檔

  1. 登入 Palo Alto Networks 防火牆管理主控台
  2. 依序前往「裝置」>「伺服器設定檔」>「系統記錄」
  3. 按一下「新增」,建立新的伺服器設定檔。
  4. 提供下列設定詳細資料:
    • 名稱:輸入描述性名稱 (例如 Google SecOps BindPlane)。
    • 位置:選取這個設定檔可用的虛擬系統 (vsys) 或「共用」
  5. 依序點選「Servers」(伺服器) >「Add」(新增),設定系統記錄伺服器。
  6. 提供下列伺服器設定詳細資料:
    • 名稱:輸入伺服器的描述性名稱 (例如 BindPlane Agent)。
    • Syslog 伺服器:輸入 BindPlane 代理程式 IP 位址。
    • 傳輸:根據 BindPlane Agent 設定選取「UDP」或「TCP」 (預設為 UDP)。
    • 「Port」(通訊埠):輸入 BindPlane 代理程式通訊埠編號 (例如 514)。
    • 格式:視需求選取 BSD (預設) 或 IETF
    • 設施:選取「LOG_USER」(預設) 或其他設施 (如有需要)。
  7. 按一下「確定」,儲存系統記錄伺服器設定檔。

選用:設定 CEF 或 LEEF 的自訂記錄格式

如需 CEF (通用事件格式) 或 LEEF (記錄事件擴充格式) 記錄,而非 CSV 檔案,請按照下列步驟操作:

  1. 在 Syslog 伺服器設定檔中,選取「Custom Log Format」(自訂記錄格式) 分頁。
  2. 為每種記錄類型 (設定、系統、威脅、流量、網址、資料、WildFire、通道、驗證、User-ID、HIP 比對) 設定自訂記錄格式。
  3. 如要設定 CEF 格式,請參閱 Palo Alto Networks CEF 設定指南
  4. 按一下「確定」儲存設定。

建立記錄檔轉送設定檔

  1. 依序前往「物件」>「記錄轉送」
  2. 按一下「新增」,建立新的記錄轉送設定檔。
  3. 提供下列設定詳細資料:
    • 名稱:輸入設定檔名稱 (例如 Google SecOps Forwarding)。如要讓防火牆自動將這個設定檔指派給新的安全性規則和區域,請將設定檔命名為 default
  4. 針對要轉送的每種記錄類型 (流量、威脅、WildFire 提交、網址篩選、資料篩選、通道、驗證),請設定下列項目:
    • 在對應的記錄類型部分中,按一下「新增」
    • 「Syslog」Syslog:選取您建立的 Syslog 伺服器設定檔 (例如 Google SecOps BindPlane)。
    • 記錄嚴重程度:選取要轉送的嚴重程度等級 (例如「全部」)。
  5. 按一下「確定」,儲存記錄轉送設定檔。

將記錄轉送設定檔套用至安全性政策

  1. 依序前往「政策」>「安全性」
  2. 選取要啟用記錄轉送的安全規則。
  3. 按一下規則即可編輯。
  4. 前往「動作」分頁。
  5. 在「記錄檔轉送」選單中,選取您建立的記錄檔轉送設定檔 (例如 Google SecOps Forwarding)。
  6. 按一下「確定」,儲存安全性政策設定。

設定系統記錄的記錄設定

  1. 依序點選「裝置」>「記錄設定」
  2. 針對每種記錄類型 (系統、設定、使用者 ID、HIP 比對、Global Protect、IP 標記、SCTP) 和嚴重程度,選取您建立的系統記錄伺服器設定檔。
  3. 按一下「確定」儲存記錄設定。

修訂變更

  1. 按一下防火牆網頁介面頂端的「Commit」
  2. 等待提交作業順利完成。
  3. 檢查 Google SecOps 控制台是否有傳入的 Palo Alto Networks 防火牆記錄,確認記錄是否已傳送至 Bindplane 代理程式。

使用 Bindplane 代理程式將記錄轉送至 Google SecOps

  1. 安裝並設定 Linux 虛擬機器
  2. 在 Linux 上安裝及設定 Bindplane 代理程式,將記錄轉寄至 Google SecOps。如要進一步瞭解如何安裝及設定 Bindplane 代理程式,請參閱 Bindplane 代理程式安裝及設定說明

如果在建立動態饋給時遇到問題,請與 Google SecOps 支援團隊聯絡。

支援的記錄格式

Palo Alto Networks 防火牆剖析器支援 LEEF、CEF 和 CSV 格式的記錄。

支援的範例記錄

  • LEEF

    <14>Jan 22 02:20:19 device_host LEEF:1.0|Palo Alto Networks|PAN-OS Syslog Integration|10.2.12-h4|Microsoft MSOFFICE(52033)|ReceiveTime=2025/01/22 02:20:18|SerialNumber=01250100xxxx|cat=THREAT|Subtype=wildfire|devTime=Jan 22 2025 08:20:18 GMT|src=198.50.100.1|dst=198.50.100.2|srcPostNAT=198.50.100.3|dstPostNAT=198.50.100.4|RuleName=AZURE-US-NEW-CNF_Inbound_To_Azure-ALLOW|usrName=|SourceUser=|DestinationUser=|Application=smtp-base|VirtualSystem=vsys1|SourceZone=McD-Global-Zone|DestinationZone=Azure-Zone|IngressInterface=ae1.111|EgressInterface=ae2.409|LogForwardingProfile=Default-Traffic-Logging|SessionID=35331795|RepeatCount=1|srcPort=21578|dstPort=25|srcPostNATPort=0|dstPostNATPort=0|Flags=0x2000|proto=tcp|action=allow|Miscellaneous=\"......3...................xls\"|ThreatID=Microsoft MSOFFICE(52033)|URLCategory=malicious|sev=4|Severity=high|Direction=client-to-server|sequence=7462614601465681755|ActionFlags=0x8000000000000000|SourceLocation=198.50.100.1-198.50.100.255|DestinationLocation=United States|ContentType=|PCAP_ID=0|FileDigest=0ea04c99bf188c2e4207f60f92ca7c6f5088c7943ee63f45c50032bbd2bf7ea9|Cloud=demo.com|URLIndex=1|RequestMethod=|FileType=ms-office|Sender=sender@ab.myownpersonaldomain.com|Subject=\"............:.................................................................................-.........(Name)-2025-01-22...............:Y107202501220005, ............:........................, ...............:.........\"|Recipient=abc@demo.myownpersonaldomain.com|ReportID=117022282776|DeviceGroupHierarchyL1=143|DeviceGroupHierarchyL2=144|DeviceGroupHierarchyL3=39|DeviceGroupHierarchyL4=0|vSrcName=|DeviceName=device_host|SrcUUID=|DstUUID=|TunnelID=0|MonitorTag=|ParentSessionID=0|ParentStartTime=|TunnelType=N/A|ThreatCategory=N/A|ContentVer=WildFire-0
    
  • CEF

    14>1 2024-04-04T16:21:56+02:00 FW-PERIMETRAL-AVG-01 - - - - CEF:0|Palo Alto Networks|PAN-OS|10.1.10-h2|end|TRAFFIC|1|src=198.51.100.1 dst=198.51.100.2 srcTranslatedAddress=198.51.100.3 dstTranslatedAddress=198.51.100.4 rule=FW_USER_NATS2_APP suser= duser= app=bittorrent vs=vsys1 sz=INSIDE dz=EXTERNAL InboundInterface=ae2.2266 OutboundInterface=ae1 lp=log_forwarding sid=2935823 cnt=1 spt=6881 dpt=51413 srcTranslatedPort=0 dstTranslatedPort=0 flags=0x7a proto=udp act=allow tbytes=475 in=150 out=325 pkt=2 pktReceived=1 pktSent=1 start=Apr 04 2024 14:21:56 GMT stime=1206 urlcat=any externalId=externalId reason=aged-out DGl1=11 DGl2=161 DGl3=0 DGl4=0 VsysName=STONESOFT dvchost=FW-PERIMETRAL-AVG-01 cat=from-policy ActionFlags=0x8000000000000000 srcUUID= dstUUID= TunnelID=0 MonitorTag= ParentSessionID=0 ParentStartTime= TunnelType=N/A SCTPAssocID=0 SCTPChunks=0 SCTPChunkSent=0 SCTPChunksRcv=0 RuleUUID=746c3eb6-3d51-4679-8438-bd0e00e170a8 HTTP2Con=0 LinkChange=0 PolicyID= LinkDetail= SDWANCluster= SDWANDevice= SDWANClustype= SDWANSite= DynamicUsrgrp= XFFIP= srcDevCat= srcDevProf= srcDevModel= srcDevVendor= srcDevOS= srcDevOSv= srcHostname= srcMac= dstDevCat= dstDevProf= dstDevModel= dstDevVendor= dstDevOS= dstDevOSv= dstHostname= dstMac= ContainerName= PODNamespace= PODName= srcEDL= dstEDL= GPHostID= EPSerial= srcDAG= dstDAG= HASessionOwner= TimeHighRes=2024-04-04T16:21:56.250+02:00 ASServiceType= ASServiceDiff="
    
  • CSV

    1,2021/10/24 15:30:07,,CONFIG,0,2561,2021/10/24 15:30:07,198.51.100.0,,set,admin,Web,Succeeded, network virtual-router  VR1,,VR1  { ecmp { algorithm { ip-modulo ; } } protocol { bgp { routing-options { graceful-restart { enable yes; } } enable no; } rip { enable no; } ospf { enable no; } ospfv3 { enable no; } } routing-table { ip { static-route { vr1-log  { path-monitor { enable no; failure-condition any; hold-time 2; } nexthop { ip-address 198.51.100.0; } bfd { profile None; } interface ethernet1/1; metric 10; destination 0.0.0.0/0; route-table { unicast ; } } } } } interface [ ethernet1/1 ethernet1/2 ]; } ,7022390503849066572,0x0,0,0,0,0,,PA-VM,0,
    

欄位對應參考資料:記錄欄位對應至 UDM 欄位

本節說明剖析器如何將 Palo Alto Networks 防火牆記錄欄位對應至各記錄類型的 Google SecOps UDM 事件欄位。Google SecOps 標籤鍵是指對應至 Labels.key UDM 欄位的鍵名稱。

舉例來說,如果是「虛擬系統」欄位,欄位名稱在 CEF 格式中為「cs3」,在 LEEF 格式中則為「VirtualSystem」。UDM 欄位「about.labels.key」包含值「vsys」,而 UDM 欄位「about.labels.value」包含該欄位的值。部分 CEF 或 LEEF 欄位名稱沒有對應的 CSV 欄位名稱。在這種情況下,如果您在系統記錄檔設定檔的自訂記錄格式中加入自己的變數名稱,剖析器不會將該名稱對應至 UDM 欄位。

如需各記錄類型的對應參考資料,請參閱下列章節:

系統

下表列出系統記錄類型的記錄欄位,以及對應的 UDM 欄位。

CSV 欄位 CEF 欄位 LEEF 欄位 Google Security Operations 標籤鍵 UDM 欄位
接收時間 (receive_time 或 cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (如果沒有「產生時間」)

序號 (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
類型 (型別) type (Header) cat metadata.product_event_type 已設為「%{type} - %{subtype}」。
威脅/內容類型 (子類型) 子類型 (標題) 子類型 metadata.product_event_type 已設為「%{type} - %{subtype}」。
產生時間 (time_generated 或 cef-formatted-time_generated) metadata.event_timestamp
虛擬系統 (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
事件 ID (eventid) cat eventid additional.fields.key 和 additional.fields.value.string_value
物件 (object) fname 檔案名稱 object target.resource.name
模組 (module) flexString2 Module 模組 additional.fields.key 和 additional.fields.value.string_value
嚴重性 (嚴重性) $number-of-severity(header) 嚴重性 security_result.severity 和 security_result.severity_details
說明 (不透明) msg msg metadata.description
principal_user_userid (這個欄位是從 msg 欄位擷取) principal.user.userid
principal_ip3 (這個欄位是從 msg 欄位擷取) principal.ip
原因 (這個欄位是從 msg 欄位擷取) security_result.description
server_address (這個欄位是從 msg 欄位擷取而來) target.ip
server_profile (這個欄位是從 msg 欄位擷取而來) additional.fields.key 和 additional.fields.value.string_value
序號 (seqno) externalId sequence metadata.product_log_id
動作旗標 (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_1 至 dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虛擬系統名稱 (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
裝置名稱 (device_name) dvchost DeviceName target.hostname
高解析度時間戳記 (high_res_timestamp) anOSTimeGeneratedHighResolution additional.fields.key 和 additional.fields.value.string_value

設定

下表列出設定記錄類型的記錄欄位,以及對應的 UDM 欄位。

CSV 欄位 CEF 欄位 LEEF 欄位 Google Security Operations 標籤鍵 UDM 欄位
接收時間 (receive_time 或 cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (如果沒有「產生時間」)

序號 (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
類型 (型別) type (Header) cat metadata.product_event_type
威脅/內容類型 (子類型) 子類型 (標題) metadata.product_event_type
產生時間 (time_generated 或 cef-formatted-time_generated) metadata.event_timestamp
主機 (host) shost src principal.ip/hostname
虛擬系統 (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
指令 (cmd) act msg cmd principal.process.command_line
管理員 (admin) duser usrName principal.user.userid
用戶端 (client) destinationServiceName 用戶端 principal.application
結果 (結果) 簽章 ID (標頭)(原因) 結果 security_result.summary
設定路徑 (路徑) msg ConfigurationPath principal.process.command_line
變更前詳細資料 (before_change_detail) cs1 BeforeChangeDetail before_change_detail target.resource.attribute.labels.key/value
變更詳細資料 (after_change_detail) cs2 AfterChangeDetail after_change_detail target.resource.attribute.labels.key/value
序號 (seqno) externalId sequence metadata.product_log_id
動作旗標 (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_1 至 dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虛擬系統名稱 (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
裝置名稱 (device_name) dvchost DeviceName target.hostname
裝置群組 (dg_id) PanOSFWDeviceGroup target.asset.attribute.labels.key/value dg_id principal.asset.attribute.labels.key/value
稽核註解 (註解) PanOSPolicyAuditComment 註解 additional.fields.key 和 additional.fields.value.string_value
高解析度時間戳記 (high_res_timestamp) additional.fields.key 和 additional.fields.value.string_value
嚴重性 (嚴重性) number-of-severity(header) security_result.severity 和 security_result.severity_details

威脅/WildFire

下表列出 Threat/WildFire 記錄類型的記錄欄位,以及對應的 UDM 欄位。

CSV 欄位 CEF 欄位 LEEF 欄位 Google Security Operations 標籤鍵 UDM 欄位
接收時間 (receive_time 或 cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (如果沒有「產生時間」)

序號 (序號) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
類型 (型別) type (Header) cat metadata.product_event_type
威脅/內容類型 (子類型) cat/subtype (Header) 子類型 metadata.product_event_type
產生時間 (time_generated 或 cef-formatted-time_generated) metadata.event_timestamp
來源地址 (src) src src principal.ip
目的地地址 (dst) dst dst target.ip
NAT 來源 IP (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
網路位址轉譯 (NAT) 目的地 IP (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
規則名稱 (規則) cs1 RuleName security_result.rule_name
來源使用者 (srcuser) suser SourceUser / usrName principal.user.userid
目的地使用者 (dstuser) duser DestinationUser target.user.userid
應用程式 (app) 應用程式 應用程式 target.application
虛擬系統 (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
來源區域 (從) cs4 SourceZone

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目的地可用區 (至) cs5 DestinationZone

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

傳入介面 (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

傳出介面 (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

記錄動作 (logset) cs6 LogForwardingProfile logset additional.fields.key 和 additional.fields.value.string_value
工作階段 ID (sessionid) cn1 SessionID network.session_id
重複次數 (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key 和 additional.fields.value.string_value
來源通訊埠 (sport) spt srcPort principal.port
目的地通訊埠 (dport) dpt dstPort target.port
NAT 來源通訊埠 (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
NAT 目的地通訊埠 (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
旗標 (flags) flexString1 旗標 flags additional.fields.key 和 additional.fields.value.string_value
IP 通訊協定 (proto) proto proto network.ip_protocol
動作 (action) act action security_result.action_details

security_result.action

網址/檔案名稱 (其他) 要求 其他

target.file.names (如果子類型為「file」、「virus」、「wildfire-virus」或「wildfire」,則 `misc` 欄位會對應至 target.file.names)

target.url (如果子類型為「url」,則 `misc` 欄位會對應至 target.url 和 target.hostname)

威脅/內容名稱 (threatid) cat ThreatID security_result.threat_name
類別 (類別) cs2 URLCategory security_result.category_details
嚴重性 (嚴重性) number-of-severity(header) 嚴重性 security_result.severity 和 security_result.severity_details
方向 (方向) flexString2 方向 network.direction
序號 (seqno) externalId sequence metadata.product_log_id
動作旗標 (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
來源國家/地區 (srcloc) SourceLocation principal.location.country_or_region
目的地國家/地區 (dstloc) DestinationLocation target.location.country_or_region
內容類型 (contenttype) ContentType contenttype additional.fields.key 和 additional.fields.value.string_value
PCAP ID (pcap_id) fileId PCAP_ID pcap_id additional.fields.key 和 additional.fields.value.string_value
檔案摘要 (filedigest) fileHash FileDigest target.file.sha1/md5/sha256
雲端 (cloud) filePath Cloud 雲端 additional.fields.key 和 additional.fields.value.string_value
網址索引 (url_idx) URLIndex url_idx additional.fields.key 和 additional.fields.value.string_value
使用者代理程式 (user_agent) network.http.user_agent
檔案類型 (filetype) fileType FileType target.file.mime_type
X-Forwarded-For (xff) principal.ip
參照網址 (referer) network.http.referral_url
寄件者 (寄件者) suid 寄件者 network.email.from
主旨 (subject) msg 主旨 network.email.subject
收件者 (recipient) duid 收件者 network.email.to
報表 ID (reportid) oldFileId ReportID reportid additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_1 至 dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虛擬系統名稱 (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
裝置名稱 (device_name) dvchost DeviceName intermediary.hostname
來源 VM UUID (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
目的地 VM UUID (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
HTTP 方法 (http_method) RequestMethod network.http.method
通道 ID/IMSI (tunnel_id/imsi) PanOSTunnelID TunnelID tunnel_id/imsi additional.fields.key 和 additional.fields.value.string_value
監控標籤/IMEI (monitortag/imei) PanOSMonitorTag MonitorTag monitortag/imei additional.fields.key 和 additional.fields.value.string_value
父項工作階段 ID (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
父項工作階段開始時間 (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key 和 additional.fields.value.string_value
通道類型 (通道) PanOSTunnelType TunnelType 通道 additional.fields.key 和 additional.fields.value.string_value
威脅類別 (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
內容版本 (contentver) PanOSContentVer ContentVer contentver additional.fields.key 和 additional.fields.value.string_value
SCTP 關聯 ID (assoc_id) PanOSAssocID assoc_id additional.fields.key 和 additional.fields.value.string_value
酬載通訊協定 ID (ppid) PanOSPPID ppid additional.fields.key 和 additional.fields.value.string_value
HTTP 標頭 (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
網址類別清單 (url_category_list) PanOSURLCatList url_category_list additional.fields.key 和 additional.fields.value.string_value
規則 UUID (rule_uuid) PanOSRuleUUID security_result.rule_id
HTTP/2 連線 (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
動態使用者群組名稱 (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

XFF 位址 (xff_ip) PanXFFIP principal.ip
來源裝置類別 (src_category) PanSrcDeviceCat src_category principal.asset.category
來源裝置設定檔 (src_profile) PanSrcDeviceProf src_profile

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

來源裝置型號 (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
來源裝置供應商 (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
來源裝置 OS 系列 (src_osfamily) PanSrcDeviceOS src_osfamily principal.platform
來源裝置 OS 版本 (src_osversion) PanSrcDeviceOSv principal.platform_version
來源主機名稱 (src_host) PanSrcHostname principal.hostname
來源 MAC 位址 (src_mac) PanSrcMac principal.mac
目的地裝置類別 (dst_category) PanDstDeviceCat dst_category target.asset.category
目的地裝置設定檔 (dst_profile) PanDstDeviceProf dst_profile

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

目的地裝置型號 (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
目的地裝置供應商 (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
目的地裝置 OS 系列 (dst_osfamily) PanDstDeviceOS dst_osfamily target.platform
目的地裝置 OS 版本 (dst_osversion) PanDstDeviceOSv target.platform_version
目的地主機名稱 (dst_host) PanDstHostname target.hostname
目的地 MAC 位址 (dst_mac) PanDstMac target.mac
容器 ID (container_id) PanContainerName container_id intermediary.resource.product_object_id
POD 命名空間 (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
POD 名稱 (pod_name) PanPODName pod_name target.resource.name
來源外部動態清單 (src_edl) PanSrcEDL src_edl additional.fields.key 和 additional.fields.value.string_value
目標外部動態清單 (dst_edl) PanDstEDL dst_edl additional.fields.key 和 additional.fields.value.string_value
主機 ID (hostid) PanGPHostID hostid principal.asset.asset_id
使用者裝置序號 (serialnumber) PanEPSerial principal.asset.hardware.serial_number
網域 EDL (domain_edl) PanDomainEDL domain_edl additional.fields.key 和 additional.fields.value.string_value
來源動態位址群組 (src_dag) PanSrcDAG principal.group.group_display_name
目的地動態地址群組 (dst_dag) PanDstDAG target.group.group_display_name
部分雜湊 (partial_hash) PanPartialHash partial_hash additional.fields.key 和 additional.fields.value.string_value
高解析度時間戳記 (high_res timestamp) PanTimeHighRes 高解析度時間戳記 additional.fields.key 和 additional.fields.value.string_value
原因 (原因) PanReasonFilteringAction 原因 security_result.summary
理由 (理由) PanJustification 理由 additional.fields.key 和 additional.fields.value.string_value
區塊服務類型 (nssai_sst) PanASServiceType nssai_sst additional.fields.key 和 additional.fields.value.string_value
應用程式子類別 (subcategory_of_app) subcategory_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式類別 (category_of_app) category_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式技術 (technology_of_app) technology_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式風險 (risk_of_app) risk_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式特徵 (characteristic_of_app) characteristic_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式容器 (container_of_app) container_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式 SaaS (is_saas_of_app) is_saas_of_app additional.fields.key 和 additional.fields.value.string_value
通道應用程式 (tunneled_app) additional.fields.key 和 additional.fields.value.string_value
流程類型 (flow_type) additional.fields.key 和 additional.fields.value.string_value
叢集名稱 (cluster_name) intermediary.resource.name
應用程式受制裁狀態 (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key 和 additional.fields.value.string_value

流量

下表列出流量記錄類型的記錄欄位,以及對應的 UDM 欄位。

CSV 欄位 CEF 欄位 LEEF 欄位 Google Security Operations 標籤鍵 UDM 欄位
接收時間 (receive_time 或 cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (如果沒有「產生時間」)

序號 (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
類型 (型別) type (Header) cat/Type metadata.product_event_type
威脅/內容類型 (子類型) 子類型 (標題) 子類型 metadata.product_event_type
產生時間 (time_generated 或 cef-formatted-time_generated) start metadata.event_timestamp
來源地址 (src) src src principal.ip
目的地地址 (dst) dst dst target.ip
NAT 來源 IP (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
網路位址轉譯 (NAT) 目的地 IP (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
規則名稱 (規則) cs1 RuleName security_result.rule_name
來源使用者 (srcuser) suser SourceUser principal.user.userid
目的地使用者 (dstuser) duser DestinationUser target.user.userid
應用程式 (app) 應用程式 應用程式 target.application
虛擬系統 (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
來源區域 (從) cs4 SourceZone

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目的地可用區 (至) cs5 DestinationZone

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

傳入介面 (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

傳出介面 (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

記錄動作 (logset) cs6 LogForwardingProfile logset additional.fields.key 和 additional.fields.value.string_value
工作階段 ID (sessionid) cn1 SessionID network.session_id
重複次數 (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key 和 additional.fields.value.string_value
來源通訊埠 (sport) spt srcPort principal.port
目的地通訊埠 (dport) dpt dstPort target.port
NAT 來源通訊埠 (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
NAT 目的地通訊埠 (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
旗標 (flags) flexString1 旗標 flags additional.fields.key 和 additional.fields.value.string_value
IP 通訊協定 (proto) proto proto network.ip_protocol
動作 (action) act action security_result.action_details

security_result.action

位元組 (位元組) flexNumber1 totalBytes 位元組 additional.fields.key 和 additional.fields.value.string_value
傳送的位元組 (bytes_sent) in srcBytes network.sent_bytes
收到的位元組 (bytes_received) out dstBytes network.received_bytes
封包 (封包) cn2 totalPackets 封包 additional.fields.key 和 additional.fields.value.string_value
開始時間 (開始) StartTime start additional.fields.key 和 additional.fields.value.string_value
經過時間 (elapsed) cn3 ElapsedTime 經過時間 network.session_duration.seconds
類別 (類別) cs2 URLCategory security_result.category / security_result.category_details
序號 (seqno) externalId sequence metadata.product_log_id
動作旗標 (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
來源國家/地區 (srcloc) SourceLocation principal.location.country_or_region
目的地國家/地區 (dstloc) DestinationLocation target.location.country_or_region
傳送的封包數 (pkts_sent) PanOSPacketsSent srcPackets pkts_sent network.sent_packets
接收的封包數 (pkts_received) PanOSPacketsReceived dstPackets pkts_received network.received_packets
工作階段結束原因 (session_end_reason) 原因 SessionEndReason security_result.summary
裝置群組階層 1 (dg_hier_level_1 至 dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 2 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 3 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虛擬系統名稱 (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
裝置名稱 (device_name) dvchost DeviceName intermediary.hostname
動作來源 (action_source) cat ActionSource action_source additional.fields.key 和 additional.fields.value.string_value
來源 VM UUID (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
目的地 VM UUID (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
通道 ID/IMSI (tunnelid/imsi) PanOSTunnelID TunnelID tunnelid/imsi additional.fields.key 和 additional.fields.value.string_value
監控標籤/IMEI (monitortag/imei) PanOSMonitorTag MonitorTag monitortag/imei additional.fields.key 和 additional.fields.value.string_value
父項工作階段 ID (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
父項開始時間 (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key 和 additional.fields.value.string_value
通道類型 (通道) PanOSTunnelType TunnelType 通道 additional.fields.key 和 additional.fields.value.string_value
SCTP 關聯 ID (assoc_id) PanOSSCTPAssocID assoc_id additional.fields.key 和 additional.fields.value.string_value
SCTP 區塊 (區塊) PanOSSCTPChunks chunks additional.fields.key 和 additional.fields.value.string_value
傳送的 SCTP 區塊 (chunks_sent) PanOSSCTPChunkSent chunks_sent additional.fields.key 和 additional.fields.value.string_value
收到的 SCTP 區塊 (chunks_received) PanOSSCTPChunksRcv chunks_received additional.fields.key 和 additional.fields.value.string_value
規則 UUID (rule_uuid) PanOSRuleUUID security_result.rule_id
HTTP/2 連線 (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
應用程式拍動次數 (link_change_count) PanLinkChange link_change_count additional.fields.key 和 additional.fields.value.string_value
政策 ID (policy_id) PanPolicyID policy_id additional.fields.key 和 additional.fields.value.string_value
連結開關 (link_switches) PanLinkDetail link_switches additional.fields.key 和 additional.fields.value.string_value
SD-WAN 叢集 (sdwan_cluster) PanSDWANCluster sdwan_cluster additional.fields.key 和 additional.fields.value.string_value
SD-WAN 裝置類型 (sdwan_device_type) PanSDWANDevice sdwan_device_type additional.fields.key 和 additional.fields.value.string_value
SD-WAN 叢集類型 (sdwan_cluster_type) PanSDWANClustype sdwan_cluster_type additional.fields.key 和 additional.fields.value.string_value
SD-WAN 網站 (sdwan_site) PanSDWANSite sdwan_site additional.fields.key 和 additional.fields.value.string_value
動態使用者群組名稱 (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name additional.fields.key 和 additional.fields.value.string_value
XFF 位址 (xff_ip) PanXFFIP principal.ip
來源裝置類別 (src_category) PanSrcDeviceCat src_category principal.asset.category
來源裝置設定檔 (src_profile) PanSrcDeviceProf src_profile

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

來源裝置型號 (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
來源裝置供應商 (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
來源裝置 OS 系列 (src_osfamily) PanSrcDeviceOS principal.platform
來源裝置 OS 版本 (src_osversion) PanSrcDeviceOSv principal.asset.software.version
來源主機名稱 (src_host) PanSrcHostname principal.hostname
來源 MAC 位址 (src_mac) PanSrcMac principal.mac
目的地裝置類別 (dst_category) PanDstDeviceCat dst_category target.asset.category
目的地裝置設定檔 (dst_profile) PanDstDeviceProf dst_profile

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

目的地裝置型號 (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
目的地裝置供應商 (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
目的地裝置 OS 系列 (dst_osfamily) PanDstDeviceOS dst_osfamily target.platform
目的地裝置 OS 版本 (dst_osversion) PanDstDeviceOSv target.platform_version
目的地主機名稱 (dst_host) PanDstHostname target.hostname
目的地 MAC 位址 (dst_mac) PanDstMac target.mac
容器 ID (container_id) PanContainerName container_id intermediary.resource.product_object_id
POD 命名空間 (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
POD 名稱 (pod_name) PanPODName pod_name target.resource.name
來源外部動態清單 (src_edl) PanSrcEDL src_edl

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目標外部動態清單 (dst_edl) PanDstEDL dst_edl

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

主機 ID (hostid) PanGPHostID hostid principal.asset.asset_id
使用者裝置序號 (serialnumber) PanEPSerial principal.asset.hardware.serial_number
來源動態位址群組 (src_dag) PanSrcDAG principal.group.group_display_name
目的地動態地址群組 (dst_dag) PanDstDAG target.group.group_display_name
工作階段擁有者 (session_owner) PanHASessionOwner session_owner additional.fields.key 和 additional.fields.value.string_value
高解析度時間戳記 (high_res_timestamp) PanTimeHighRes additional.fields.key 和 additional.fields.value.string_value
切片服務類型 (nsdsai_sst) PanASServiceType nsdsai_sst additional.fields.key 和 additional.fields.value.string_value
Slice 差異化指標 (nsdsai_sd) PanASServiceDiff nsdsai_sd additional.fields.key 和 additional.fields.value.string_value
應用程式子類別 (subcategory_of_app) subcategory_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式類別 (category_of_app) category_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式技術 (technology_of_app) technology_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式風險 (risk_of_app) security_result.severity
應用程式特徵 (characteristic_of_app) characteristic_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式容器 (container_of_app) container_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式 SaaS (is_saas_of_app) is_saas_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式受制裁狀態 (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式子類別 (subcategory_of_app) subcategory_of_app1 additional.fields.key 和 additional.fields.value.string_value
嚴重性 (嚴重性) number-of-severity(header) security_result.severity 和 security_result.severity_details

User-ID

下表列出使用者 ID 記錄類型的記錄欄位,以及對應的 UDM 欄位。

CSV 欄位 CEF 欄位 LEEF 欄位 Google Security Operations 標籤鍵 UDM 欄位
接收時間 (receive_time 或 cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (如果沒有「產生時間」)

序號 (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
類型 (型別) type (Header) cat metadata.product_event_type
威脅/內容類型 (子類型) 子類型 (標題) 子類型 metadata.product_event_type
產生時間 (time_generated 或 cef-formatted-time_generated) metadata.event_timestamp
虛擬系統 (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
來源 IP (ip) src src principal.ip
使用者 (使用者) duser usrName target.user.userid

target.administrative_domain

target.user.email_addresses

資料來源名稱 (datasourcename) cs4 DataSourceName datasourcename

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

事件 ID (eventid) EventID eventid additional.fields.key 和 additional.fields.value.string_value
重複次數 (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key 和 additional.fields.value.string_value
逾時門檻 (逾時) cn3 TimeoutThreshold 逾時 additional.fields.key 和 additional.fields.value.string_value
來源通訊埠 (beginport) spt srcPort principal.port
目的地通訊埠 (endport) dpt dstPort target.port
資料來源 (datasource) cs5 DataSource 資料來源

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

資料來源類型 (datasourcetype) cs6 DataSourceType datasourcetype

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

序號 (seqno) externalId sequence metadata.product_log_id
動作旗標 (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虛擬系統名稱 (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
裝置名稱 (device_name) dvchost DeviceName intermediary.hostname
虛擬系統 ID (vsys_id) cn2 VirtualSystemID intermediary.resource.product_object_id
因素類型 (factortype) cs1 FactorType factortype additional.fields.key 和 additional.fields.value.string_value
因子完成時間 (factorcompletiontime) end FactorCompletionTime factorcompletiontime additional.fields.key 和 additional.fields.value.string_value
因素編號 (factorno) cn1 FactorNumber factorno additional.fields.key 和 additional.fields.value.string_value
使用者群組標記 (ugflags) PanOSUGFlags ugflags additional.fields.key 和 additional.fields.value.string_value
使用者 (按來源區隔) (userbysource) PanOSUserBySource target.user.userid

target.administrative_domain

target.user.email_addresses

高解析度時間戳記 (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key 和 additional.fields.value.string_value
原始資料來源 (origindatasource) additional.fields.key 和 additional.fields.value.string_value
叢集名稱 (cluster_name) principal.resource.name
嚴重性 (嚴重性) number-of-severity(header) security_result.severity 和 security_result.severity_details

HIP 比對

下表列出 HIP 比對記錄類型的記錄欄位,以及對應的 UDM 欄位。

CSV 欄位 CEF 欄位 LEEF 欄位 Google Security Operations 標籤鍵 UDM 欄位
接收時間 (receive_time 或 cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (如果沒有「產生時間」)

序號 (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
類型 (型別) type (Header) cat metadata.product_event_type
威脅/內容類型 (子類型) 子類型 (標題) 子類型
產生時間 (time_generated 或 cef-formatted-time_generated) start startTime metadata.event_timestamp
來源使用者 (srcuser) suser usrName principal.user.userid
虛擬系統 (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
電腦名稱 (machinename) shost identHostName principal.hostname
作業系統 (os) cs2 作業系統 principal.asset.platform_software.platform
來源地址 (src) src identsrc principal.ip
HIP (matchname) cat HIP matchname

target.resource.attribute.labels.key/value

additional.fields.key 和 additional.fields.value.string_value

重複次數 (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key 和 additional.fields.value.string_value
HIP 類型 (比對類型) 裝置事件類別 ID (標頭) HIPType matchtype

target.resource.attribute.labels.key/value

additional.fields.key 和 additional.fields.value.string_value

序號 (seqno) externalId sequence metadata.product_log_id
動作旗標 (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虛擬系統名稱 (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
裝置名稱 (device_name) dvchost DeviceName target.hostname
虛擬系統 ID (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
IPv6 系統位址 (srcipv6) c6a2 srcipv6 principal.asset.ip
主機 ID (hostid) PanOSHostID principal.asset.asset_id
使用者裝置序號 (serialnumber) PanOSEndpointSerialNumber principal.asset.hardware.serial_number
裝置 MAC 位址 (mac) PanOSEndpointMac principal.asset.mac
高解析度時間戳記 (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key 和 additional.fields.value.string_value
叢集名稱 (cluster_name) principal.resource.name
嚴重性 (嚴重性) number-of-severity(header) security_result.severity 和 security_result.severity_details

IP 標記

下表列出 IP 標記記錄類型的記錄欄位,以及對應的 UDM 欄位。

CSV 欄位 CEF 欄位 LEEF 欄位 Google Security Operations 標籤鍵 UDM 欄位
接收時間 (receive_time 或 cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (如果沒有「產生時間」)

序號 (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
類型 (型別) type (Header) cat metadata.product_event_type
威脅/內容類型 (子類型) 子類型 (標題) 子類型 metadata.product_event_type
產生時間 (time_generated 或 cef-formatted-time_generated) GenerateTime metadata.event_timestamp
虛擬系統 (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
來源 IP (ip) src src principal.ip
代碼名稱 (tag_name) PanOSTagName TagName tag_name

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

活動 ID (event_id) PanOSEventID EventID event_id additional.fields.key 和 additional.fields.value.string_value
重複次數 (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key 和 additional.fields.value.string_value
逾時 (逾時) PanOSTimeout TimeoutThreshold 逾時 additional.fields.key 和 additional.fields.value.string_value
資料來源名稱 (datasourcename) PanOSDataSourceName DataSourceName datasourcename

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

資料來源類型 (datasource_type) PanOSDataSourceType DataSource datasource_type

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

資料來源子類型 (datasource_subtype) PanOSDataSourceSubType DataSourceType datasource_subtype

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

序號 (seqno) externalId sequence metadata.product_log_id
動作旗標 (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虛擬系統名稱 (vsys_name) PanOsVsysName vSrcName target.asset.attribute.labels.key/value
裝置名稱 (device_name) dvchost DeviceName target.hostname
虛擬系統 ID (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
高解析度時間戳記 (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key 和 additional.fields.value.string_value
嚴重性 (嚴重性) number-of-severity(header) security_result.severity 和 security_result.severity_details
叢集名稱 (cluster_name) principal.resource.name

解密

下表列出解密記錄類型的記錄欄位,以及對應的 UDM 欄位。

CSV 欄位 CEF 欄位 LEEF 欄位 Google Security Operations 標籤鍵 UDM 欄位
接收時間 (receive_time 或 cef-formatted-receive_time) rt metadata.collected_timestamp,

metadata.event_timestamp (如果沒有「產生時間」)

序號 (serial) PanOSDeviceSN intermediary.asset.hardware.serial_number
類型 (型別) type (Header) metadata.product_event_type
威脅/內容類型 (子類型) 子類型 (標題) metadata.product_event_type
設定版本 (config_ver) PanOSConfigVersion config_ver additional.fields.key 和 additional.fields.value.string_value
生成時間 (time_generated) PanOSLogTimeStamp metadata.event_timestamp
來源地址 (src) src principal.ip
目的地地址 (dst) dst target.ip
NAT 來源 IP (natsrc) sourceTranslatedAddress principa.nat_ip
網路位址轉譯 (NAT) 目的地 IP (natdst) destinationTranslatedAddress target.nat_ip
規則 (規則) cs1 security_result.rule_name
來源使用者 (srcuser) suser principal.user.userid
目的地使用者 (dstuser) duser target.user.userid
應用程式 (app) 應用程式 network.application_protocol
虛擬系統 (vsys) cs3 vsys intermediary.asset.attribute.labels.key/value
來源區域 (從) cs4

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目的地可用區 (至) cs5

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

傳入介面 (inbound_if) deviceInboundInterface inbound_if

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

傳出介面 (outbound_if) deviceOutboundInterface outbound_if

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

記錄動作 (logset) cs6 logset additional.fields.key 和 additional.fields.value.string_value
記錄時間 (time_received) PanOSTimeReceivedManagementPlane -
工作階段 ID (sessionid) cn1 network.session_id
重複次數 (repeatcnt) PanOSCountOfRepeats/RepeatCount repeatcnt additional.fields.key 和 additional.fields.value.string_value
來源通訊埠 (sport) spt principal.port
目的地通訊埠 (dport) dpt target.port
NAT 來源通訊埠 (natsport) sourceTranslatedPort principal.nat_port
NAT 目的地通訊埠 (natdport) destinationTranslatedPort target.nat_port
旗標 (flags) flexString1 flags additional.fields.key 和 additional.fields.value.string_value
IP 通訊協定 (proto) proto network.ip_protocol
動作 (action) act security_result.action_details

security_result.action

隧道 (tunnel) PanOSTunnel 通道 additional.fields.key 和 additional.fields.value.string_value
來源 VM UUID (src_uuid) PanOSSourceUUID principal.asset.product_object_id
目的地 VM UUID (dst_uuid) PanOSDestinationUUID target.asset.product_object_id
規則的 UUID (rule_uuid) PanOSRuleUUID security_result.rule_id
從用戶端到防火牆的階段 (hs_stage_c2f) PanOSClientToFirewall hs_stage_c2f additional.fields.key 和 additional.fields.value.string_value
防火牆到伺服器階段 (hs_stage_f2s) PanOSFirewallToServer hs_stage_f2s additional.fields.key 和 additional.fields.value.string_value
TLS 版本 (tls_version) PanOSTLSVersion network.tls.version
金鑰交換演算法 (tls_keyxchg) PanOSTLSKeyExchange tls_keyxchg additional.fields.key 和 additional.fields.value.string_value
加密演算法 (tls_enc) PanOSTLSEncryptionAlgorithm tls_enc additional.fields.key 和 additional.fields.value.string_value
雜湊演算法 (tls_auth) PanOSTLSAuth tls_auth additional.fields.key 和 additional.fields.value.string_value
政策名稱 (policy_name) PanOSPolicyName policy_name additional.fields.key 和 additional.fields.value.string_value
橢圓曲線 (ec_curve) PanOSEllipticCurve network.tls.curve
錯誤索引 (err_index) PanOSErrorIndex err_index additional.fields.key 和 additional.fields.value.string_value
根狀態 (root_status) PanOSRootStatus root_status additional.fields.key 和 additional.fields.value.string_value
鏈結狀態 (chain_status) PanOSChainStatus chain_status additional.fields.key 和 additional.fields.value.string_value
Proxy 類型 (proxy_type) PanOSProxyType proxy_type additional.fields.key 和 additional.fields.value.string_value
憑證序號 (cert_serial) PanOSCertificateSerial network.tls.server.certificate.serial
憑證指紋 (指紋) PanOSFingerprint network.tls.server.certificate.md5/sha1/sha256
憑證開始日期 (notbefore) PanOSTimeNotBefore network.tls.server.certificate.not_before
憑證結束日期 (notafter) PanOSTimeNotAfter network.tls.server.certificate.not_after
憑證版本 (cert_ver) PanOSCertificateVersion network.tls.server.certificate.version
憑證大小 (cert_size) PanOSCertificateSize cert_size additional.fields.key 和 additional.fields.value.string_value
一般名稱長度 (cn_len) PanOSCommonNameLength cn_len additional.fields.key 和 additional.fields.value.string_value
核發者通用名稱長度 (issuer_len) PanOSIssuerNameLength issuer_len additional.fields.key 和 additional.fields.value.string_value
根一般名稱長度 (rootcn_len) PanOSRootCNLength rootcn_len additional.fields.key 和 additional.fields.value.string_value
SNI 長度 (sni_len) PanOSSNILength sni_len additional.fields.key 和 additional.fields.value.string_value
憑證標記 (cert_flags) PanOSCertificateFlags cert_flags additional.fields.key 和 additional.fields.value.string_value
主體通用名稱 (cn) PanOSCommonName cn additional.fields.key 和 additional.fields.value.string_value
核發者通用名稱 (issuer_cn) PanOSIssuerCommonName network.tls.server.certificate.issuer
根層級通用名稱 (root_cn) PanOSRootCommonName root_cn additional.fields.key 和 additional.fields.value.string_value
伺服器名稱指示

(sni)

network.tls.client.server_name
錯誤 (錯誤) PanOSErrorMessage error additional.fields.key 和 additional.fields.value.string_value
容器 ID (container_id) PanOSContainerID container_id intermediary.resource.product_object_id
POD 命名空間 (pod_namespace) PanOSContainerNameSpace pod_namespace

target.resource.attribute.labels.key/value

additional.fields.key 和 additional.fields.value.string_value

POD 名稱 (pod_name) PanOSContainerName pod_name target.resource.name
來源外部動態清單 (src_edl) PanOSSourceEDL src_edl

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目標外部動態清單 (dst_edl) PanOSDestinationEDL dst_edl

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

來源動態位址群組 (src_dag) PanOSSourceDynamicAddressGroup principal.group.group_display_name
目的地動態地址群組 (dst_dag) PanOSDestinationDynamicAddressGroup target.group.group_display_name
高解析度時間戳記 (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key 和 additional.fields.value.string_value
來源裝置類別 (src_category) PanOSSourceDeviceCategory src_category principal.asset.category
來源裝置設定檔 (src_profile) PanOSSourceDeviceProfile src_profile

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

來源裝置型號 (src_model) PanOSSourceDeviceModel src_model principal.asset.hardware.model
來源裝置供應商 (src_vendor) PanOSSourceDeviceVendor src_vendor principal.asset.hardware.manufacturer
來源裝置 OS 系列 (src_osfamily) PanOSSourceDeviceOSFamily principal.platform
來源裝置 OS 版本 (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
來源主機名稱 (src_host) PanOSSourceDeviceHost principal.hostname
來源 MAC 位址 (src_mac) PanOSSourceDeviceMac principal.mac
目的地裝置類別 (dst_category) PanOSDestinationDeviceCategory dst_category target.asset.category
目的地裝置設定檔 (dst_profile) PanOSDestinationDeviceProfile dst_profile

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

目的地裝置型號 (dst_model) PanOSDestinationDeviceModel dst_model target.asset.hardware.model
目的地裝置供應商 (dst_vendor) PanOSDestinationDeviceVendor dst_vendor target.asset.hardware.manufacturer
目的地裝置 OS 系列 (dst_osfamily) PanOSDestinationDeviceOSFamily dst_osfamily target.platform
目的地裝置 OS 版本 (dst_osversion) PanOSDestinationDeviceOSVersion target.platform_version
目的地主機名稱 (dst_host) PanOSDestinationDeviceHost target.hostname
目的地 MAC 位址 (dst_mac) PanOSDestinationDeviceMac target.mac
序號 (seqno) PanOSLogTypeSeqNo metadata.product_log_id
動作旗標 (actionflags) PanOSActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_1) DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_2) DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_3) DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_4) DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虛擬系統名稱 (vsys_name) intermediary.asset.attribute.labels.key/value
裝置名稱 (device_name) intermediary.hostname
虛擬系統 ID (vsys_id) intermediary.resource.product_object_id
應用程式子類別 (subcategory_of_app) subcategory_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式類別 (category_of_app) category_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式技術 (technology_of_app) technology_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式風險 (risk_of_app) security_result.severity
應用程式特徵 (characteristic_of_app) characteristic_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式容器 (container_of_app) container_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式 SaaS (is_saas_of_app) is_saas_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式受制裁狀態 (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key 和 additional.fields.value.string_value
嚴重性 (嚴重性) number-of-severity(header) security_result.severity 和 security_result.severity_details

隧道

下表列出通道記錄類型的記錄欄位,以及對應的 UDM 欄位。

CSV 欄位 CEF 欄位 LEEF 欄位 Google Security Operations 標籤鍵 UDM 欄位
接收時間 (receive_time 或 cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (如果沒有「產生時間」)

序號 (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
類型 (型別) type (Header) cat metadata.product_event_type
威脅/內容類型 (子類型) 子類型 (標題) 子類型 metadata.product_event_type
產生時間 (time_generated 或 cef-formatted-time_generated) metadata.event_timestamp
來源地址 (src) src src principal.ip
目的地地址 (dst) dst dst target.ip
NAT 來源 IP (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
網路位址轉譯 (NAT) 目的地 IP (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
規則名稱 (規則) cs1 RuleName security_result.rule_name
來源使用者 (srcuser) suser SourceUser / usrName principal.user.userid
目的地使用者 (dstuser) duser DestinationUser target.user.userid
應用程式 (app) 應用程式 應用程式 network.application_protocol
虛擬系統 (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
來源區域 (從) cs4 SourceZone

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目的地可用區 (至) cs5 DestinationZone

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

傳入介面 (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

傳出介面 (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

記錄動作 (logset) cs6 LogForwardingProfile logset additional.fields.key 和 additional.fields.value.string_value
工作階段 ID (sessionid) cn1 SessionID network.session_id
重複次數 (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key 和 additional.fields.value.string_value
來源通訊埠 (sport) spt srcPort principal.port
目的地通訊埠 (dport) dpt dstPort target.port
NAT 來源通訊埠 (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
NAT 目的地通訊埠 (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
旗標 (flags) flexString1 旗標 flags additional.fields.key 和 additional.fields.value.string_value
IP 通訊協定 (proto) proto proto network.ip_protocol
動作 (action) act action security_result.action_details

security_result.action

嚴重性 (嚴重性) number-of-severity(header) security_result.severity 和 security_result.severity_details
序號 (seqno) externalId sequence metadata.product_log_id
動作旗標 (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
來源位置 (srcloc) principal.location.country_or_region
目的地位置 (dstloc) target.location.country_or_region
裝置群組階層 (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虛擬系統名稱 (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
裝置名稱 (device_name) dvchost DeviceName intermediary.hostname
通道 ID (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key 和 additional.fields.value.string_value
監控標記 (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key 和 additional.fields.value.string_value
父項工作階段 ID (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
父項開始時間 (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key 和 additional.fields.value.string_value
通道類型 (通道) cs2 TunnelType 通道 additional.fields.key 和 additional.fields.value.string_value
位元組 (位元組) flexNumber1 totalBytes 位元組 additional.fields.key 和 additional.fields.value.string_value
傳送的位元組 (bytes_sent) in srcBytes network.sent_bytes
收到的位元組 (bytes_received) out dstBytes network.received_bytes
封包 (封包) cn2 totalPackets 封包 additional.fields.key 和 additional.fields.value.string_value
傳送的封包數 (pkts_sent) PanOSPacketsSent srcPackets pkts_sent network.sent_packets
接收的封包數 (pkts_received) PanOSPacketsReceived dstPackets pkts_received network.received_packets
最大封裝 (max_encap) flexNumber2 MaximumEncapsulation max_encap additional.fields.key 和 additional.fields.value.string_value
不明通訊協定 (unknown_proto) cfp1 UnknownProtocol unknown_proto additional.fields.key 和 additional.fields.value.string_value
嚴格檢查 (strict_check) cfp2 StrictChecking strict_check additional.fields.key 和 additional.fields.value.string_value
隧道片段 (tunnel_fragment) PanOSTunnelFragment TunnelFragment tunnel_fragment additional.fields.key 和 additional.fields.value.string_value
建立的工作階段 (sessions_created) cfp3 SessionsCreated sessions_created additional.fields.key 和 additional.fields.value.string_value
已關閉的工作階段 (sessions_closed) cfp4 SessionsClosed sessions_closed additional.fields.key 和 additional.fields.value.string_value
工作階段結束原因 (session_end_reason) 原因 SessionEndReason security_result.summary
動作來源 (action_source) cat ActionSource action_source additional.fields.key 和 additional.fields.value.string_value
開始時間 (開始) startTime start additional.fields.key 和 additional.fields.value.string_value
經過時間 (elapsed) cn3 ElapsedTime 經過時間 network.session_duration.seconds
通道檢查規則 (tunnel_insp_rule) PanOSTunneInspectionRule security_result.rule_name = "Tunnel Inspection Rule: %{PanOSTunnelInspectionRule}"
遠端使用者 IP (remote_user_ip) PanOSRmtUserIP principal.ip
遠端使用者 ID (remote_user_id) PanOSRmtUserID remote_user_id principal.user.userid
安全性規則 UUID (rule_uuid) PanOSRuleUUID security_result.rule_id
PCAP ID (pcap_id) PanOSPcapID pcap_id additional.fields.key 和 additional.fields.value.string_value
動態使用者群組名稱 (dynusergroup_name) PanDynamicUsrgrp principal.group.group_display_name
來源外部動態清單 (src_edl) PanOSSourceEDL src_edl

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目標外部動態清單 (dst_edl) PanOSDestinationEDL dst_edl

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

高解析度時間戳記 (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key 和 additional.fields.value.string_value
配量鑑別器 (nssai_sd) nssai_sd additional.fields.key 和 additional.fields.value.string_value
切片服務類型 (nssai_sd) nssai_sd1 additional.fields.key 和 additional.fields.value.string_value
PDU 工作階段 ID (pdu_session_id) pdu_session_id additional.fields.key 和 additional.fields.value.string_value
應用程式子類別 (subcategory_of_app) subcategory_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式類別 (category_of_app) category_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式技術 (technology_of_app) technology_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式風險 (risk_of_app) risk_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式特徵 (characteristic_of_app) characteristic_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式容器 (container_of_app) container_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式 SaaS (is_saas_of_app) is_saas_of_app additional.fields.key 和 additional.fields.value.string_value
通道應用程式 (tunneled_app) additional.fields.key 和 additional.fields.value.string_value
已卸載 (已卸載) additional.fields.key 和 additional.fields.value.string_value
流程類型 (flow_type) additional.fields.key 和 additional.fields.value.string_value
叢集名稱 (cluster_name)

principal.resource.name

應用程式受制裁狀態 (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key 和 additional.fields.value.string_value

驗證

下表列出驗證記錄類型的記錄欄位,以及對應的 UDM 欄位。

CSV 欄位 CEF 欄位 LEEF 欄位 Google Security Operations 標籤鍵 UDM 欄位
接收時間 (receive_time 或 cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (如果沒有「產生時間」)

序號 (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
類型 (型別) type (Header) cat metadata.product_event_type
威脅/內容類型 (子類型) 子類型 (標題) 子類型 metadata.product_event_type
產生時間 (time_generated 或 cef-formatted-time_generated) metadata.event_timestamp
虛擬系統 (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
來源 IP (ip) src src principal.ip
使用者 (使用者) duser usrName target.user.userid
Normalize User (normalize_user) cs2 NormalizeUser target.user.user_display_name
物件 (object) fname ObjectName object target.resource.name
驗證政策 (authpolicy) cs4 AuthPolicy authpolicy additional.fields.key 和 additional.fields.value.string_value
重複次數 (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key 和 additional.fields.value.string_value
驗證 ID (authid) cn2 AuthenticationID authid additional.fields.key 和 additional.fields.value.string_value
供應商 (供應商) flexString2 供應商 供應商 additional.fields.key 和 additional.fields.value.string_value
記錄動作 (logset) cs6 LogForwardingProfile logset additional.fields.key 和 additional.fields.value.string_value
伺服器設定檔 (serverprofile) cs1 ServerProfile serverprofile additional.fields.key 和 additional.fields.value.string_value
說明 (desc) PanOSDesc AdditionalAuthInfo security_result.description
用戶端類型 (clienttype) cs5 ClientType clienttype additional.fields.key 和 additional.fields.value.string_value
事件類型 (事件) msg msg extensions.auth.auth_details
因素編號 (factorno) cn1 FactorNumber factorno additional.fields.key 和 additional.fields.value.string_value
序號 (seqno) externalId sequence metadata.product_log_id
動作旗標 (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虛擬系統名稱 (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
裝置名稱 (device_name) dvchost DeviceName intermediary.hostname
虛擬系統 ID (vsys_id) intermediary.resource.product_object_id
驗證通訊協定 (authproto) authproto additional.fields.key 和 additional.fields.value.string_value
規則的 UUID (rule_uuid) PanOSRuleUUID/RuleUUID security_result.rule_id
高解析度時間戳記 (high_res _timestamp) PanOSTimeGeneratedHighResolution additional.fields.key 和 additional.fields.value.string_value
來源裝置類別 (src_category) PanOSSourceDeviceCategory src_category principal.asset.category
來源裝置設定檔 (src_profile) PanOSSourceDeviceProfile src_profile

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

來源裝置型號 (src_model) PanOSSourceDeviceModel src_model principal.asset.hardware.model
來源裝置供應商 (src_vendor) PanOSSourceDeviceVendor src_vendor principal.asset.hardware.manufacturer
來源裝置 OS 系列 (src_osfamily) PanOSSourceDeviceOSFamily

principal.asset.platform_software.platform

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

來源裝置 OS 版本 (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
來源主機名稱 (src_host) PanOSSourceHostname principal.hostname
來源 MAC 位址 (src_mac) PanOSSourceMac principal.asset.mac
區域 (區域) PanOSTrafficOriginRegion principal.location.country_or_region
使用者代理程式 (user_agent) PanOSHTTPUserAgent network.http.user_agent
工作階段 ID(sessionid) PanOSTrafficSessionID network.session_id
嚴重性 (嚴重性) number-of-severity(header) security_result.severity 和 security_result.severity_details
叢集名稱 (cluster_name) principal.resource.name

網址

下表列出網址記錄類型的記錄欄位,以及對應的 UDM 欄位。

CSV 欄位 CEF 欄位 LEEF 欄位 Google Security Operations 標籤鍵 UDM 欄位
接收時間 (cef 格式的 receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (如果沒有「產生時間」)

序號 (序號) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
類型 (型別) type (Header) cat metadata.product_event_type
威脅/內容類型 (子類型) 子類型 (標題) 子類型 metadata.product_event_type
生成時間 metadata.event_timestamp
來源地址 (src) src src principal.ip
目的地地址 (dst) dst dst target.ip
NAT 來源 IP (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
網路位址轉譯 (NAT) 目的地 IP (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
規則 (規則) cs1 RuleName security_result.rule_name
來源使用者 (srcuser) suser SourceUser principal.user.userid
目的地使用者 (dstuser) duser DestinationUser target.user.userid
應用程式 (app) 應用程式 應用程式 network.application_protocol
虛擬系統 (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
來源區域 (從) cs4 SourceZone

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目的地可用區 (至) cs5 DestinationZone

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

傳入介面 (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

傳出介面 (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

記錄動作 (logset) cs6 LogForwardingProfile logset additional.fields.key 和 additional.fields.value.string_value
記錄時間 time_logged additional.fields.key 和 additional.fields.value.string_value
工作階段 ID (sessionid) cn1 SessionID network.session_id
重複次數 (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key 和 additional.fields.value.string_value
來源通訊埠 (sport) spt srcPort principal.port
目的地通訊埠 (dport) dpt dstPort target.port
NAT 來源通訊埠 (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
NAT 目的地通訊埠 (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
旗標 (flags) flexString1 旗標 flags additional.fields.key 和 additional.fields.value.string_value
IP 通訊協定 (proto) proto proto network.ip_protocol
動作 (action) act action security_result.action_details

security_result.action

網址/檔案名稱 (其他) 其他 target.file.names

target.url

威脅/內容名稱 (threatid) cat ThreatID security_result.threat_id
類別 (類別) cs2 URLCategory 類別 security_result.category_details
嚴重性 (嚴重性) number-of-severity (標頭) 嚴重性 security_result.severity

security_result.severity_details

方向 (方向) flexString2 方向 network.direction
序號 (seqno) externalId sequence metadata.product_log_id
動作旗標 (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
來源國家/地區 (srcloc) SourceLocation principal.location.country_or_region
目的地國家/地區 (dstloc) DestinationLocation target.location.country_or_region
contenttype (contenttype) requestContext ContentType contenttype additional.fields.key 和 additional.fields.value.string_value
pcap_id (pcap_id) fileId PCAP_ID pcap_id additional.fields.key 和 additional.fields.value.string_value
filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
cloud (cloud) Cloud 雲端 additional.fields.key 和 additional.fields.value.string_value
url_idx (url_idx) URLIndex url_idx additional.fields.key 和 additional.fields.value.string_value
user_agent (user_agent) requestClientApplication UserAgent network.http.user_agent
檔案類型 (filetype) target.file.mime_type
xff (xff) PanOSXForwarderfor identSrc xff principal.ip
參照網址 (referer) PanOSReferer 參照網址 network.http.referral_url
sender (sender) network.email.from
主旨 (主旨) 主旨 network.email.subject
收件者 (recipient) network.email.to
reportid (reportid) reportid additional.fields.key 和 additional.fields.value.string_value
DG Hierarchy Level 1 (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
需求開發廣告活動階層第 2 層 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
需求開發廣告活動階層第 3 層級 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
需求開發廣告活動階層第 4 層 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虛擬系統名稱 (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
裝置名稱 (device_name) dvchost DeviceName intermediary.hostname
file_url (file_url) target.url
來源 VM UUID (src_uuid) SrcUUID principal.asset.product_object_id
目的地 VM UUID (dst_uuid) DstUUID target.asset.product_object_id
http_method (http_method) requestMethod RequestMethod network.http.method
通道 ID/IMSI (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key 和 additional.fields.value.string_value
監控器標籤/IMEI (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key 和 additional.fields.value.string_value
父項工作階段 ID (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
父項工作階段開始時間 (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key 和 additional.fields.value.string_value
隧道 (tunnel) PanOSTunnelType TunnelType 通道 additional.fields.key 和 additional.fields.value.string_value
thr_category (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
contentver (contentver) PanOSContentVer ContentVer contentver additional.fields.key 和 additional.fields.value.string_value
sig_flags (sig_flags) sig_flags additional.fields.key 和 additional.fields.value.string_value
SCTP 關聯 ID (assoc_id) PanOSAssocID assoc_id additional.fields.key 和 additional.fields.value.string_value
酬載通訊協定 ID (ppid) PanOSPPID ppid additional.fields.key 和 additional.fields.value.string_value
http_headers (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
網址類別清單 (url_category_list) PanOSURLCatList url_category_list additional.fields.key 和 additional.fields.value.string_value
規則的 UUID (rule_uuid) PanOSRuleUUID rule_uuid security_result.rule_id
HTTP/2 連線 (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
dynusergroup_name (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name additional.fields.key 和 additional.fields.value.string_value
XFF 位址 (xff_ip) PanXFFIP principal.ip
來源裝置類別 (src_category) PanSrcDeviceCat src_category principal.asset.category
來源裝置設定檔 (src_profile) PanSrcDeviceProf src_profile

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

來源裝置型號 (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
來源裝置供應商 (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
來源裝置 OS 系列 (src_osfamily) PanSrcDeviceOS principal.platform
來源裝置 OS 版本 (src_osversion) PanSrcDeviceOSv principal.platform_version
來源主機名稱 (src_host) PanSrcHostname src_host principal.hostname
來源 MAC 位址 (src_mac) PanSrcMac principal.mac
目的地裝置類別 (dst_category) PanDstDeviceCat dst_category target.asset.category
目的地裝置設定檔 (dst_profile) PanDstDeviceProf dst_profile

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

目的地裝置型號 (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
目的地裝置供應商 (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
目的地裝置 OS 系列 (dst_osfamily) PanDstDeviceOS target.platform
目的地裝置 OS 版本 (dst_osversion) PanDstDeviceOSv target.platform_version
目的地主機名稱 (dst_host) PanPODNamespace target.hostname
目的地 MAC 位址 (dst_mac) PanDstMac target.mac
容器 ID (container_id) PanContainerName container_id intermediary.resource.product_object_id
POD 命名空間 (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
POD 名稱 (pod_name) PanPODName pod_name target.resource.name
來源外部動態清單 (src_edl) PanSrcEDL src_edl

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目標外部動態清單 (dst_edl) PanDstEDL dst_edl

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

主機 ID (hostid) PanGPHostID hostid principal.asset.asset_id
序號 (serialnumber) PanEPSerial principal.asset.hardware.serial_number
domain_edl (domain_edl) PanDomainEDL domain_edl additional.fields.key 和 additional.fields.value.string_value
來源動態位址群組 (src_dag) PanSrcDAG principal.group.group_display_name
目的地動態地址群組 (dst_dag) PanDstDAG target.group.group_display_name
partial_hash (partial_hash) PanPartialHash partial_hash additional.fields.key 和 additional.fields.value.string_value
高解析度時間戳記 (high_res_timestamp) PanTimeHighRes additional.fields.key 和 additional.fields.value.string_value
原因 (原因) PanReasonFilteringAction 原因 security_result.summary
理由 (理由) PanJustification 理由 additional.fields.key 和 additional.fields.value.string_value
nssai_sst (nssai_sst) PanASServiceType nssai_sst additional.fields.key 和 additional.fields.value.string_value
應用程式子類別 (subcategory_of_app) subcategory_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式類別 (category_of_app) category_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式技術 (technology_of_app) technology_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式風險 (risk_of_app) risk_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式特徵 (characteristic_of_app) characteristic_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式容器 (container_of_app) container_of_app additional.fields.key 和 additional.fields.value.string_value
通道化應用程式 (tunneled_app) tunneled_app additional.fields.key 和 additional.fields.value.string_value
應用程式的軟體即服務 (is_saas_of_app) is_saas_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式的受制裁狀態 (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key 和 additional.fields.value.string_value
雲端報告 ID (cloud_reportid) additional.fields.key 和 additional.fields.value.string_value
叢集名稱 (cluster_name)

principal.resource.name

流程類型 (flow_type) additional.fields.key 和 additional.fields.value.string_value

資料

下表列出資料記錄類型的記錄欄位,以及對應的 UDM 欄位。

CSV 欄位 CEF 欄位 LEEF 欄位 Google Security Operations 標籤鍵 UDM 欄位
接收時間 (cef 格式的 receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (如果沒有「產生時間」)

序號 (序號) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
類型 (型別) type (Header) cat metadata.product_event_type
威脅/內容類型 (子類型) 子類型 (標題) 子類型 metadata.product_event_type
生成時間 metadata.event_timestamp
來源地址 (src) src src principal.ip
目的地地址 (dst) dst dst target.ip
NAT 來源 IP (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
網路位址轉譯 (NAT) 目的地 IP (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
規則 (規則) cs1 RuleName security_result.rule_name
來源使用者 (srcuser) suser SourceUser principal.user.userid
目的地使用者 (dstuser) duser DestinationUser target.user.userid
應用程式 (app) 應用程式 應用程式 network.application_protocol
虛擬系統 (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
來源區域 (從) cs4 SourceZone

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目的地可用區 (至) cs5 DestinationZone

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

傳入介面 (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

傳出介面 (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

記錄動作 (logset) cs6 LogForwardingProfile logset additional.fields.key 和 additional.fields.value.string_value
記錄時間 time_logged additional.fields.key 和 additional.fields.value.string_value
工作階段 ID (sessionid) cn1 SessionID network.session_id
重複次數 (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key 和 additional.fields.value.string_value
來源通訊埠 (sport) spt srcPort principal.port
目的地通訊埠 (dport) dpt dstPort target.port
NAT 來源通訊埠 (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
NAT 目的地通訊埠 (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
旗標 (flags) flexString1 旗標 flags additional.fields.key 和 additional.fields.value.string_value
IP 通訊協定 (proto) proto proto network.ip_protocol
動作 (action) act action security_result.action_details

security_result.action

網址/檔案名稱 (其他) 其他 target.file.names

target.url

威脅/內容名稱 (threatid) cat ThreatID security_result.threat_id
類別 (類別) cs2 URLCategory 類別 security_result.category_details
嚴重性 (嚴重性) number-of-severity (標頭) 嚴重性 security_result.severity

security_result.severity_details

方向 (方向) flexString2 方向 network.direction
序號 (seqno) externalId sequence metadata.product_log_id
動作旗標 (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
來源國家/地區 (srcloc) SourceLocation principal.location.country_or_region
目的地國家/地區 (dstloc) DestinationLocation target.location.country_or_region
contenttype (contenttype) ContentType contenttype additional.fields.key 和 additional.fields.value.string_value
pcap_id (pcap_id) fileId PCAP_ID pcap_id additional.fields.key 和 additional.fields.value.string_value
filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
cloud (cloud) Cloud 雲端 additional.fields.key 和 additional.fields.value.string_value
url_idx (url_idx) URLIndex url_idx additional.fields.key 和 additional.fields.value.string_value
user_agent (user_agent) network.http.user_agent
檔案類型 (filetype) target.file.mime_type
xff (xff) xff principal.ip
參照網址 (referer) network.http.referral_url
sender (sender) network.email.from
主旨 (主旨) 主旨 network.email.subject
收件者 (recipient) network.email.to
reportid (reportid) reportid additional.fields.key 和 additional.fields.value.string_value
DG Hierarchy Level 1 (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
需求開發廣告活動階層第 2 層 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
需求開發廣告活動階層第 3 層級 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
需求開發廣告活動階層第 4 層 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虛擬系統名稱 (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
裝置名稱 (device_name) dvchost DeviceName intermediary.hostname
file_url (file_url) target.url
來源 VM UUID (src_uuid) SrcUUID principal.asset.product_object_id
目的地 VM UUID (dst_uuid) DstUUID target.asset.product_object_id
http_method (http_method) RequestMethod network.http.method
通道 ID/IMSI (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key 和 additional.fields.value.string_value
監控器標籤/IMEI (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key 和 additional.fields.value.string_value
父項工作階段 ID (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
父項工作階段開始時間 (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key 和 additional.fields.value.string_value
隧道 (tunnel) PanOSTunnelType TunnelType 通道 additional.fields.key 和 additional.fields.value.string_value
thr_category (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
contentver (contentver) PanOSContentVer ContentVer contentver additional.fields.key 和 additional.fields.value.string_value
sig_flags (sig_flags) sig_flags additional.fields.key 和 additional.fields.value.string_value
SCTP 關聯 ID (assoc_id) PanOSAssocID assoc_id additional.fields.key 和 additional.fields.value.string_value
酬載通訊協定 ID (ppid) PanOSPPID ppid additional.fields.key 和 additional.fields.value.string_value
http_headers (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
網址類別清單 (url_category_list) url_category_list additional.fields.key 和 additional.fields.value.string_value
規則的 UUID (rule_uuid) PanOSRuleUUID rule_uuid security_result.rule_id
HTTP/2 連線 (http2_connection) http2_connection network.application_protocol_version
dynusergroup_name (dynusergroup_name) dynusergroup_name

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

XFF 位址 (xff_ip) principal.ip
來源裝置類別 (src_category) src_category principal.asset.category
來源裝置設定檔 (src_profile) src_profile

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

來源裝置型號 (src_model) src_model principal.asset.hardware.model
來源裝置供應商 (src_vendor) src_vendor principal.asset.hardware.manufacturer
來源裝置 OS 系列 (src_osfamily) principal.platform
來源裝置 OS 版本 (src_osversion) principal.platform_version
來源主機名稱 (src_host) src_host principal.hostname
來源 MAC 位址 (src_mac) principal.mac
目的地裝置類別 (dst_category) dst_category target.asset.category
目的地裝置設定檔 (dst_profile) dst_profile

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

目的地裝置型號 (dst_model) dst_model target.asset.hardware.model
目的地裝置供應商 (dst_vendor) dst_vendor target.asset.hardware.manufacturer
目的地裝置 OS 系列 (dst_osfamily) target.platform
目的地裝置 OS 版本 (dst_osversion) target.platform_version
目的地主機名稱 (dst_host) target.hostname
目的地 MAC 位址 (dst_mac) target.mac
容器 ID (container_id) container_id intermediary.resource.product_object_id
POD 命名空間 (pod_namespace) pod_namespace target.resource.attribute.labels.key/value
POD 名稱 (pod_name) pod_name target.resource.name
來源外部動態清單 (src_edl) src_edl

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目標外部動態清單 (dst_edl) dst_edl

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

主機 ID (hostid) hostid principal.asset.asset_id
序號 (serialnumber) principal.asset.hardware.serial_number
domain_edl (domain_edl) domain_edl additional.fields.key 和 additional.fields.value.string_value
來源動態位址群組 (src_dag) principal.group.group_display_name
目的地動態地址群組 (dst_dag) target.group.group_display_name
partial_hash (partial_hash) partial_hash additional.fields.key 和 additional.fields.value.string_value
高解析度時間戳記 (high_res_timestamp) additional.fields.key 和 additional.fields.value.string_value
原因 (原因) 原因 security_result.summary
理由 (理由) 理由 additional.fields.key 和 additional.fields.value.string_value
nssai_sst (nssai_sst) nssai_sst additional.fields.key 和 additional.fields.value.string_value
應用程式子類別 (subcategory_of_app) subcategory_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式類別 (category_of_app) category_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式技術 (technology_of_app) technology_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式風險 (risk_of_app) risk_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式特徵 (characteristic_of_app) characteristic_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式容器 (container_of_app) container_of_app additional.fields.key 和 additional.fields.value.string_value
通道化應用程式 (tunneled_app) tunneled_app additional.fields.key 和 additional.fields.value.string_value
應用程式的軟體即服務 (is_saas_of_app) is_saas_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式的受制裁狀態 (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key 和 additional.fields.value.string_value
雲端報告 ID (cloud_reportid) additional.fields.key 和 additional.fields.value.string_value
叢集名稱 (cluster_name) principal.resource.name
流程類型 (flow_type) additional.fields.key 和 additional.fields.value.string_value

GlobalProtect

下表列出 GlobalProtect 記錄類型的記錄欄位,以及對應的 UDM 欄位。

CSV 欄位 CEF 欄位 LEEF 欄位 Google Security Operations 標籤鍵 UDM 欄位
接收時間 (receive_time) rt received_time metadata.event_timestamp
序號 (序號) PanOSDeviceSN intermediary_asset_hardware_serial_number intermediary.asset.hardware.serial_number
類型 (型別) type (Header) metadata.product_event_type
威脅/內容類型 (子類型) 子類型 (標題) 子類型 metadata.product_event_type
生成時間 (time_generated) PanOSLogTimeStamp generated_timestamp metadata.event_timestamp
虛擬系統 (vsys) PanOSVirtualSystem vsys intermediary.asset.attribute.labels.key/value
事件 ID (eventid) PanOSEventID event_id additional.fields.key 和 additional.fields.value.string_value
階段 (階段) PanOSStage 階段 additional.fields.key 和 additional.fields.value.string_value
驗證方式 (auth_method) PanOSAuthMethod extension_auth_auth_details extensions.auth.auth_details
通道類型 (tunnel_type) PanOSTunnelType 通道 additional.fields.key 和 additional.fields.value.string_value
來源使用者 (srcuser) PanOSSourceUserName src_user principal.user.email_address

principal.user.userid

principal.administrative_domain

來源區域 (srcregion) PanOSSourceRegion src_region principal.location.country_or_region
電腦名稱 (machinename) PanOSEndpointDeviceName machine_name principal.hostname
公開 IP (public_ip) PanOSPublicIPv4 principal.nat_ip
公開 IPv6 (public_ipv6) PanOSPublicIPv6 principal.nat_ip
私人 IP (private_ip) PanOSPrivateIPv4 principal.ip
私人 IPv6 (private_ipv6) PanOSPrivateIPv6 principal.ip
主機 ID (hostid) PanOSHostID hostid principal.asset.asset_id
序號 (serialnumber) PanOSDeviceSN principal.asset.hardware.serial_number
用戶端版本 (client_ver) PanOSGlobalProtectClientVersion client_ver additional.fields.key 和 additional.fields.value.string_value
用戶端作業系統 (client_os) PanOSEndpointOSType principal.platform
用戶端作業系統版本 (client_os_ver) PanOSEndpointOSVersion principal.platform_version
重複次數 (repeatcnt) PanOSCountOfRepeats repeatcnt additional.fields.key 和 additional.fields.value.string_value
原因 (原因) PanOSQuarantineReason security_result.summary
錯誤 (錯誤) PanOSConnectionError error security_result.description
說明 (不透明) PanOSDescription security_result.description
狀態 (狀態) PanOSEventStatus 狀態 additional.fields.key 和 additional.fields.value.string_value
位置 (位置) PanOSGPGatewayLocation target.location.country_or_region
登入時間長度 (login_duration) PanOSLoginDuration network.session_duration
連線方法 (connect_method) PanOSConnectionMethod connect_method additional.fields.key 和 additional.fields.value.string_value
錯誤代碼 (error_code) PanOSConnectionErrorID error_code additional.fields.key 和 additional.fields.value.string_value
入口網站 (入口網站) PanOSPortal 入口網站 additional.fields.key 和 additional.fields.value.string_value
序號 (seqno) PanOSSequenceNo metadata.product_log_id
動作旗標 (actionflags) PanOSActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
高解析度時間戳記 (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key 和 additional.fields.value.string_value
閘道選取方法 (selection_type) PanOSGatewaySelectionType selection_type additional.fields.key 和 additional.fields.value.string_value
安全資料傳輸層 (SSL) 回應時間 (response_time) PanOSSSLResponseTime response_time additional.fields.key 和 additional.fields.value.string_value
閘道優先順序 (優先順序) PanOSGatewayPriority 優先順序 additional.fields.key 和 additional.fields.value.string_value
嘗試使用的閘道 (attempted_gateways) PanOSAttemptedGateways attempted_gateways additional.fields.key 和 additional.fields.value.string_value
閘道名稱 (閘道) PanOSAttemptedGateways 閘道 target.resource.name
裝置群組階層 (dg_hier_level_1) dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_2) dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_3) dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層 (dg_hier_level_4) dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虛擬系統名稱 (vsys_name) intermediary.asset.attribute.labels.key/value
裝置名稱 (device_name) intermediary.hostname
虛擬系統 ID (vsys_id) intermediary.resource.product_object_id
嚴重性 (嚴重性) number-of-severity(header) security_result.severity 和 security_result.severity_details
叢集名稱 (cluster_name) principal.resource.name

關聯性

下表列出關聯記錄類型的記錄欄位,以及對應的 UDM 欄位。

CSV 欄位 CEF 欄位 LEEF 欄位 Google Security Operations 標籤鍵 UDM 欄位
產生時間 (time_generated 或 cef-formatted-time_generated) startTime generated_timestamp metadata.event_timestamp
來源地址 (src) src principal.ip
來源使用者 (srcuser) SourceUser / usrName principal.user.userid
虛擬系統 (vsys) VirtualSystem vsys intermediary.asset.attribute.labels.key/value
類別 (類別) security_result.category_details
嚴重性 (嚴重性) 嚴重性 security_result.severity 和 security_result.severity_details
裝置群組階層層級 1 DeviceGroupHierarchyL1 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層層級 2 DeviceGroupHierarchyL2 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層層級 3 DeviceGroupHierarchyL3 additional.fields.key 和 additional.fields.value.string_value
裝置群組階層層級 4 DeviceGroupHierarchyL4 additional.fields.key 和 additional.fields.value.string_value
虛擬系統名稱 (vsys_name) vSrcName intermediary.asset.attribute.labels.key/value
裝置名稱 (device_name) DeviceName intermediary.hostname
虛擬系統 ID (vsys_id) VirtualSystemID intermediary.resource.product_object_id
物件名稱 (objectname) ObjectName target.resource.name
物件 ID (object_id) ObjectID target.resource.product_object_id
證據 (證據) msg security_result.summary

GTP

下表列出 gtp 記錄類型的記錄欄位,以及對應的 UDM 欄位。

CSV 欄位 CEF 欄位 LEEF 欄位 Google Security Operations 標籤鍵 UDM 欄位
接收時間 (receive_time 或 cef-formatted-receive_time) metadata.collected_timestamp,

metadata.event_timestamp (如果沒有「產生時間」)

序號 (serial) intermediary.asset.hardware.serial_number
類型 (型別) metadata.product_event_type
威脅/內容類型 (子類型) metadata.product_event_type
產生時間 (time_generated 或 cef-formatted-time_generated) metadata.event_timestamp
來源地址 (src) principal.ip
目的地地址 (dst) target.ip
規則名稱 (規則) security_result.rule_name
應用程式 (應用程式) network.application_protocol
虛擬系統 (vsys) vsys intermediary.asset.attribute.labels.key/value
來源可用區 (從)

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目的地可用區 (至)

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

傳入介面 (inbound_if) inbound_if

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

傳出介面 (outbound_if) outbound_if

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

記錄動作 (logset) logset additional.fields.key 和 additional.fields.value.string_value
工作階段 ID (sessionid) network.session_id
來源通訊埠 (sport) principal.port
目的地通訊埠 (dport) target.port
IP 通訊協定 (proto) network.ip_protocol
動作 (動作) security_result.action_details

security_result.action

GTP 事件類型 (event_type) gtp_event_type additional.fields.key 和 additional.fields.value.string_value
MSISDN (msisdn) msisdn additional.fields.key 和 additional.fields.value.string_value
存取點名稱 (apn) apn additional.fields.key 和 additional.fields.value.string_value
無線電存取技術 (RAT) rat additional.fields.key 和 additional.fields.value.string_value
GTP 訊息類型 (msg_type) gtp_msg_type additional.fields.key 和 additional.fields.value.string_value
結束 IP 位址 (end_ip_adr) principal.ip
通道端點 ID 1 (teid1) teid1 additional.fields.key 和 additional.fields.value.string_value
通道端點 ID 2 (teid2) teid2 additional.fields.key 和 additional.fields.value.string_value
GTP 介面 (gtp_interface) gtp_interface additional.fields.key 和 additional.fields.value.string_value
GTP Cause (cause_code) gtp_cause_code additional.fields.key 和 additional.fields.value.string_value
嚴重性 (嚴重性) security_result.severity 和 security_result.severity_details
放送聯播網 MCC (mcc) mcc additional.fields.key 和 additional.fields.value.string_value
供應網路 MNC (mnc) mnc additional.fields.key 和 additional.fields.value.string_value
區碼 (area_code) area_code additional.fields.key 和 additional.fields.value.string_value
儲存格 ID (cell_id) cell_id additional.fields.key 和 additional.fields.value.string_value
GTP 事件代碼 (event_code) event_code additional.fields.key 和 additional.fields.value.string_value
來源位置 (srcloc) principal.location.country_or_region
目的地位置 (dstloc) target.location.country_or_region
通道 ID/IMSI (imsi) tunnelid additional.fields.key 和 additional.fields.value.string_value
監視器標籤/IMEI (imei) monitortag additional.fields.key 和 additional.fields.value.string_value
開始時間 (開始) start additional.fields.key 和 additional.fields.value.string_value
經過時間 (elapsed) network.session_duration.seconds
隧道檢查規則 (tunnel_insp_rule) tunnel_insp_rule security_result.detection_fields.key/value
遠端使用者 IP (remote_user_ip) principal.ip
遠端使用者 ID (remote_user_id) remote_user_id principal.user.userid
規則的 UUID (rule_uuid) security_result.rule_id
PCAP ID (pcap_id) pcap_id additional.fields.key 和 additional.fields.value.string_value
高解析度時間戳記 (high_res_timestamp) additional.fields.key 和 additional.fields.value.string_value
切片服務類型 (nsdsai_sst) nsdsai_sst additional.fields.key 和 additional.fields.value.string_value
配量差異化指標 (nsdsai_sd) nsdsai_sd additional.fields.key 和 additional.fields.value.string_value
應用程式子類別 (subcategory_of_app) subcategory_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式類別 (category_of_app) category_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式技術 (technology_of_app) technology_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式風險 (risk_of_app) risk_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式特徵 (characteristic_of_app) characteristic_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式容器 (container_of_app) container_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式 SaaS (is_saas_of_app) is_saas_of_app additional.fields.key 和 additional.fields.value.string_value
應用程式受制裁狀態 (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key 和 additional.fields.value.string_value

SCTP

CSV 欄位 CEF 欄位 LEEF 欄位 Google Security Operations 標籤鍵 UDM 欄位
接收時間 (receive_time 或 cef-formatted-receive_time) receive_time 或 cef-formatted-receive_time metadata.collected_timestamp
序號 (serial) serial intermediary.asset.hardware.serial_number
類型 (type) 類型 metadata.product_event_type
產生時間 (time_generated 或 cef-formatted-time_generated) time_generated 或 cef-formatted-time_generated metadata.event_timestamp
來源地址 (src) src principal.ip
目的地地址 (dst) dst target.ip
規則名稱 (規則) 規則 security_result.rule_name
來源可用區 (從) 來自 additional.fields.key 和 additional.fields.value.string_value
目的地 (到) additional.fields.key 和 additional.fields.value.string_value
傳入介面 (inbound_if) inbound_if additional.fields.key 和 additional.fields.value.string_value
輸出介面 (outbound_if) outbound_if additional.fields.key 和 additional.fields.value.string_value
記錄動作 (記錄集) logset additional.fields.key 和 additional.fields.value.string_value
工作階段 ID (sessionid) sessionid network.session_id
重複次數 (repeatcnt) repeatcnt additional.fields.key 和 additional.fields.value.string_value
來源通訊埠 (sport) 運動 principal.port
目的地通訊埠 (dport) dport target.port
IP 通訊協定 (proto) proto network.ip_protocol (enum)
動作 (action) 動作 security_result.action_details
security_result.action
裝置群組階層 (dg_hier_level_1 至 dg_hier_level_4) dg_hier_level_1 至 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
裝置名稱 (device_name) device_name intermediary.hostname
序號 (seqno) seqno metadata.product_log_id
SCTP 關聯 ID (assoc_id) assoc_id additional.fields.key 和 additional.fields.value.string_value
酬載通訊協定 ID (ppid) ppid additional.fields.key 和 additional.fields.value.string_value
嚴重性 (severity) 嚴重性 security_result.severity 和 security_result.severity_details
SCTP 區塊類型 (sctp_chunk_type) sctp_chunk_type additional.fields.key 和 additional.fields.value.string_value
SCTP 事件類型 (sctp_event_type) sctp_event_type additional.fields.key 和 additional.fields.value.string_value
SCTP 驗證代碼 1 (verif_tag_1) verif_tag_1 additional.fields.key 和 additional.fields.value.string_value
SCTP 驗證廣告代碼 2 (verif_tag_2) verif_tag_2 additional.fields.key 和 additional.fields.value.string_value
SCTP 原因代碼 (sctp_cause_code) sctp_cause_code additional.fields.key 和 additional.fields.value.string_value
Diameter 應用程式 ID (diam_app_id) diam_app_id additional.fields.key 和 additional.fields.value.string_value
Diameter 指令代碼 (diam_cmd_code) diam_cmd_code additional.fields.key 和 additional.fields.value.string_value
Diameter AVP 代碼 (diam_avp_code) diam_avp_code additional.fields.key 和 additional.fields.value.string_value
SCTP 串流 ID (stream_id) stream_id additional.fields.key 和 additional.fields.value.string_value
SCTP 關聯結束原因 (assoc_end_reason) assoc_end_reason additional.fields.key 和 additional.fields.value.string_value
運算碼 (op_code) op_code additional.fields.key 和 additional.fields.value.string_value
SCCP Calling Party SSN (sccp_calling_ssn) sccp_calling_ssn additional.fields.key 和 additional.fields.value.string_value
SCCP Calling Party Global Title (sccp_calling_gt) sccp_calling_gt additional.fields.key 和 additional.fields.value.string_value
SCTP 篩選器 (sctp_filter) sctp_filter additional.fields.key 和 additional.fields.value.string_value
SCTP 區塊 (區塊) chunks additional.fields.key 和 additional.fields.value.string_value
傳送的 SCTP 區塊 (chunks_sent) chunks_sent additional.fields.key 和 additional.fields.value.string_value
收到的 SCTP 區塊 (chunks_received) chunks_received additional.fields.key 和 additional.fields.value.string_value
封包 (封包) 封包 additional.fields.key 和 additional.fields.value.string_value
規則的 UUID (rule_uuid) rule_uuid security_result.rule_id
虛擬系統 (vsys) vsys intermediary.asset.attribute.labels.key/value
虛擬系統名稱 (vsys_name) vsys_name intermediary.asset.attribute.labels.key/value
傳送的封包數 (pkts_sent) pkts_sent network.sent_packets
接收的封包數 (pkts_received) pkts_received network.received_packets

稽核

CSV 欄位 CEF 欄位 LEEF 欄位 Google Security Operations 標籤鍵 UDM 欄位
生成時間 metadata.event_timestamp
威脅/內容類型 (子類型) metadata.product_event_type
事件 ID principal.application
物件 principal.user.userid
CLI 指令 principal.process.command_line
嚴重性 security_result.severity
序號 intermediary.asset.hardware.serial_number

欄位對應參考資料:記錄類型至 UDM 事件類型

下表列出 Palo Alto Networks 防火牆記錄類型,以及對應的 UDM 事件類型。

記錄類型 UDM 事件類型
流量 NETWORK_CONNECTION
威脅 NETWORK_CONNECTION
網址篩選 NETWORK_CONNECTION
WildFire NETWORK_CONNECTION

WildFire 提交記錄是威脅記錄類型的子類型,使用相同的系統記錄格式。

資料篩選 NETWORK_CONNECTION
通道 NETWORK_CONNECTION
GTP NETWORK_CONNECTION
設定 SETTING_MODIFICATION/SETTING_CREATION/SETTING_DELETION/SETTING_UNCATEGORIZED

「Command (cmd)」欄位的值會決定 UDM 事件類型對應。 如果 cmd 欄位值為 add 或 clone,系統會設定 SETTING_CREATION。

如果 cmd 欄位值為 delete,系統會設定 SETTING_DELETION。

如果 cmd 欄位值為 edit、move、rename、set 或 commit,系統會設定 SETTING_MODIFICATION。

如果 cmd 欄位值不含任何值,系統會設定 SETTING_UNCATEGORIZED。

系統

如果子類型值為「dhcp」,系統會設定 NETWORK_DHCP。

如果子類型值為「auth」,系統就會設定 USER_LOGIN。

如果說明值為「logged in」,系統就會設定 USER_LOGIN。

如果說明值為「logged out」,系統會設定 USER_LOGOUT。

如果子類型為其他值,系統會設定 GENERIC_EVENT。

HIP Match NETWORK_CONNECTION
IP 代碼 GENERIC_EVENT
User-ID USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED

如果子類型值為「login」,系統就會設定 USER_LOGIN。

如果子類型值為「logout」,系統會設定 USER_LOGOUT。

如果子類型不含任何值,系統會設定 USER_UNCATEGORIZED。

解密 NETWORK_CONNECTION
驗證 GENERIC_EVENT
SCTP NETWORK_CONNECTION
稽核 GENERIC_EVENT

UDM 對應差異

UDM 對應差異參考資料:Palo Alto Networks 防火牆

下表列出 Palo Alto Networks Firewall 的舊版 UDM 對應與新版 UDM 對應之間的差異。Palo Alto Networks Firewall

UDM Event Type Delta

Log type Old UDM Event Type New UDM Event Type
WildFire NETWORK_CONNECTION SCAN_UNCATEGORIZED
Data Filtering NETWORK_CONNECTION NETWORK_UNCATEGORIZED
Authentication STATUS_UPDATE STATUS_UNCATEGORIZED

UDM Field Mapping Delta

Log Type Old UDM Mapping CSV Log Field CEF Log Field LEEF Log Field New UDM Mapping
System intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
System about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
System about.labels.key/value additional.fields.key/value.string_value Object (object) fname Filename target.resource.name
System Description (opaque) msg msg metadata.description
System principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
System intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
Config intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Config about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
Config principal.process.command_line Configuration Path (path) msg ConfigurationPath principal.process.command_line
Config principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
Config intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
Config principal.asset.attribute.labels.key/value Device Group (dg_id) PanOSFWDeviceGroup target.asset.attribute.labels
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Threat/Wildfire target.file.full_path target.url target.hostname URL/Filename (misc) request Miscellaneous target.file.names target.url
Threat/Wildfire about.file.sha1/md5/sha256 File Digest (filedigest) fileHash FileDigest target.file.sha1/md5/sha256
Threat/Wildfire about.file.mime_type File Type (filetype) fileType FileType target.file.mime_type
Threat/Wildfire principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Threat/Wildfire principal.user.product_object_id Source VM UUID (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
Threat/Wildfire target.user.product_object_id Destination VM UUID (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value HTTP Headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
Threat/Wildfire principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
Threat/Wildfire principal.asset.software.version Source Device OS Version (src_osversion) PanSrcDeviceOSv principal.platform_version
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
Threat/Wildfire target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
Threat/Wildfire metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Reason (reason) PanReasonFilteringAction security_result.summary
Traffic about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value Packets Sent (pkts_sent) PanOSPacketsSent srcPackets network.sent_packets
Traffic about.labels.key/value additional.fields.key/value.string_value Packets Received (pkts_received) PanOSPacketsReceived dstPackets network.received_packets
Traffic principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
Traffic principal.asset.platform_software.platform(enum) principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
Traffic target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
Traffic about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
Traffic about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
Traffic about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
Traffic metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
User-ID about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
User-ID principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
User-ID principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID intermediary.resource.product_object_id
User-ID principal.user.userid principal.administrative_domain principal.user.email_addresses User by Source (userbysource) PanOSUserBySource target.user.userid target.user.email_addresses
User-ID metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
HIP Match intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
HIP Match about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
HIP Match about.labels.key/value additional.fields.key/value.string_value HIP (matchname) cat HIP target.resource.attribute.labels
HIP Match about.labels.key/value additional.fields.key/value.string_value HIP Type (matchtype) Device Event Class ID (Header) HIPType target.resource.attribute.labels
HIP Match principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
HIP Match intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
HIP Match principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
HIP Match principal.asset.product_object_id Host ID (hostid) PanOSHostID principal.asset.asset_id
HIP Match metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
IP-Tag intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
IP-Tag about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
IP-Tag principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOsVsysName vSrcName target.asset.attribute.labels
IP-Tag intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
IP-Tag principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
IP-Tag metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Decryption target.application Application (app) app network.application_protocol
Decryption about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 intermediary.asset.attribute.labels
Decryption principal.asset.asset_id Source VM UUID (src_uuid) PanOSSourceUUID principal.asset.product_object_id
Decryption target.asset.asset_id Destination VM UUID (dst_uuid) PanOSDestinationUUID target.asset.product_object_id
Decryption about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanOSContainerID intermediary.resource.product_object_id
Decryption about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanOSContainerNameSpace target.resource.attribute.labels additional.fields.key/value.string_value
Decryption about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanOSContainerName target.resource.name
Decryption metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanOSSourceDeviceCategory principal.asset.category
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanOSSourceDeviceModel principal.asset.hardware.model
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanOSSourceDeviceVendor principal.asset.hardware.manufacturer
Decryption principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanOSSourceDeviceOSFamily principal.platform
Decryption principal.asset.software.version Source Device OS Version (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanOSDestinationDeviceCategory target.asset.category
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanOSDestinationDeviceModel target.asset.hardware.model
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanOSDestinationDeviceVendor target.asset.hardware.manufacturer
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanOSDestinationDeviceOSFamily target.platform
Decryption target.asset.software.version Destination Device OS Version (dst_osversion) PanOSDestinationDeviceOSVersion target.platform_version
Decryption principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) intermediary.asset.attribute.labels
Decryption principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
Tunnel about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Tunnel principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Tunnel about.labels.key/value additional.fields.key/value.string_value Packets Sent (pkts_sent) PanOSPacketsSent srcPackets network.sent_packets
Tunnel about.labels.key/value additional.fields.key/value.string_value Packets Received (pkts_received) PanOSPacketsReceived dstPackets network.received_packets
Tunnel target.ip Remote User IP (remote_user_ip) PanOSRmtUserIP principal.ip
Tunnel target.labels.key/value additional.fields.key/value.string_value Remote User ID (remote_user_id) PanOSRmtUserID principal.user.userid
Tunnel metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Authentication about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Authentication target.user.user_display_name Normalize User (normalize_user) cs2 NormalizeUser target.user.user_display_name
Authentication about.labels.key/value additional.fields.key/value.string_value Object (object) fname ObjectName target.resource.name
Authentication about.labels.key/value additional.fields.key/value.string_value Authentication Policy (authpolicy) cs4 AuthPolicy additional.fields.key/value.string_value
Authentication principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Authentication principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
Authentication metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res _timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanOSSourceDeviceCategory principal.asset.category
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanOSSourceDeviceModel principal.asset.hardware.model
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanOSSourceDeviceVendor principal.asset.hardware.manufacturer
Authentication principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanOSSourceDeviceOSFamily principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value
Authentication principal.asset.software.version Source Device OS Version (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
URL about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
URL target.file.full_path target.url URL/Filename (misc) Miscellaneous target.file.names target.url
URL about.labels.key/value additional.fields.key/value.string_value Category (category) cs2 URLCategory security_result.category_details
URL about.file.sha1/md5/sha256 filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
URL about.file.mime_type filetype (filetype) target.file.mime_type
URL about.labels.key/value additional.fields.key/value.string_value xff (xff) PanOSXForwarderfor identSrc principal.ip
URL principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
URL about.url file_url (file_url) target.url
URL principal.asset.asset_id Source VM UUID (src_uuid) SrcUUID principal.asset.product_object_id
URL target.asset.asset_id Destination VM UUID (dst_uuid) DstUUID target.asset.product_object_id
URL about.labels.key/value additional.fields.key/value.string_value http_headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
URL about.labels.key/value additional.fields.key/value.string_value UUID for rule (rule_uuid) PanOSRuleUUID security_result.rule_id
URL about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
URL principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
URL principal.asset.software.version Source Device OS Version (src_osversion) PanSrcDeviceOSv principal.platform_version
URL principal.labels.key/value additional.fields.key/value.string_value Source Hostname (src_host) PanSrcHostname principal.hostname
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
URL target.asset.platform_software.platform target.labels.key/value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
URL target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
URL about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
URL about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
URL about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
URL about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
URL metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Res Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
URL about.labels.key/value additional.fields.key/value.string_value Reason (reason) PanReasonFilteringAction security_result.summary
Data about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Data target.file.full_path target.url URL/Filename (misc) Miscellaneous target.file.names target.url
Data about.labels.key/value additional.fields.key/value.string_value Category (category) cs2 URLCategory security_result.category_details
Data about.file.sha1/md5/sha256 filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
Data about.file.mime_type filetype (filetype) target.file.mime_type
Data about.labels.key/value additional.fields.key/value.string_value xff (xff) principal.ip
Data principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Data about.url file_url (file_url) target.url
Data principal.asset.asset_id Source VM UUID (src_uuid) SrcUUID principal.asset.product_object_id
Data target.asset.asset_id Destination VM UUID (dst_uuid) DstUUID target.asset.product_object_id
Data about.labels.key/value additional.fields.key/value.string_value http_headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
Data about.labels.key/value additional.fields.key/value.string_value UUID for rule (rule_uuid) PanOSRuleUUID security_result.rule_id
Data about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) network.application_protocol_version
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) principal.asset.category
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) principal.asset.hardware.model
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) principal.asset.hardware.manufacturer
Data principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) principal.platform
Data principal.asset.software.version Source Device OS Version (src_osversion) principal.platform_version
Data principal.labels.key/value additional.fields.key/value.string_value Source Hostname (src_host) principal.hostname
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) target.asset.category
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) target.asset.hardware.model
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) target.asset.hardware.manufacturer
Data target.asset.platform_software.platform target.labels.key/value Destination Device OS Family (dst_osfamily) target.platform
Data target.asset.software.version Destination Device OS Version (dst_osversion) target.platform_version
Data about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) intermediary.resource.product_object_id
Data about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) target.resource.attribute.labels
Data about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) target.resource.name
Data about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) principal.asset.asset_id
Data metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Res Timestamp (high_res_timestamp) additional.fields.key/value.string_value
Data about.labels.key/value additional.fields.key/value.string_value Reason (reason) security_result.summary
GlobalProtect about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) PanOSVirtualSystem intermediary.asset.attribute.labels
GlobalProtect principal.user.email_address principal.user.userid principal.administrative_domain Source User (srcuser) PanOSSourceUserName target.user.email_address target.user.userid
GlobalProtect principal.asset.platform_software.platform(enum) Client OS (client_os) PanOSEndpointOSType principal.platform
GlobalProtect principal.asset.platform_software.platform_version Client OS Version (client_os_ver) PanOSEndpointOSVersion principal.platform_version
GlobalProtect metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
GlobalProtect about.labels.key/value additional.fields.key/value.string_value Gateway Name (gateway) PanOSAttemptedGateways target.resource.name
GlobalProtect principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) intermediary.asset.attribute.labels
GlobalProtect target.hostname Device Name (device_name) intermediary.hostname
GlobalProtect principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
CORRELATION about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) VirtualSystem intermediary.asset.attribute.labels
CORRELATION principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) vSrcName intermediary.asset.attribute.labels
CORRELATION principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) VirtualSystemID intermediary.resource.product_object_id
GTP additional.fields.key/value.string_value Virtual System (vsys) intermediary.asset.attribute.labels
GTP target.ip Remote User IP (remote_user_ip) principal.ip
GTP additional.fields.key/value.string_value Remote User ID (remote_user_id) principal.user.userid
GTP metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) additional.fields.key/value.string_value

Palo Alto Networks 防火牆 Strata 記錄服務

總覽

Palo Alto Networks® Strata Logging Service 提供雲端式集中記錄儲存和彙整服務,適用於地端、虛擬 (私有雲和公有雲) 防火牆、Prisma Access,以及 Cortex XDR 等雲端服務。Strata Logging Service 安全無虞、具備復原能力且容錯,可確保記錄資料保持最新狀態,並在您需要時隨時可用。這項服務提供可擴充的記錄基礎架構,讓您不必規劃及部署記錄收集器,即可滿足記錄保留需求。如果您已有內部部署的記錄收集器,新的 Strata Logging Service 可做為現有設定的輔助工具。您可以透過雲端 Strata Logging Service 擴充現有的記錄檔收集基礎架構,隨著業務成長擴大作業容量,或滿足新地點的容量需求。有了這項服務,Palo Alto Networks 會負責記錄檔基礎架構的持續維護和監控作業,讓您專注於業務。

  • 確認 Strata Logging Service 剖析器支援的記錄格式和 PAN-OS 版本。下表列出 Strata Logging Service 剖析器支援的記錄格式和對應的 PAN-OS 版本:

    記錄格式 PAN-OS 版本
    JSON 12.1
  • 確認 Google SecOps 剖析器支援的 Palo Alto Networks 防火牆記錄檔類型。 Google SecOps 剖析器支援下列 Palo Alto Networks 防火牆記錄類型:

    • 流量
    • 威脅
    • 隧道檢查
    • 系統
    • HIP 比對
    • IP-Tag
    • User-ID
    • 解密
    • 驗證
    • 網址篩選
    • GlobalProtect

部署 Strata Logging 服務

開始將記錄檔傳送至 Strata Logging 服務:

如要開始將記錄檔傳送至 Strata Logging Service,請按照下列步驟操作:

  1. 安裝支援的 PAN-OS® 版本
  2. 啟用 Strata Logging Service:啟用 Strata Logging Service 時,系統會佈建防火牆安全連線至 Strata Logging Service 時所需的憑證。
  3. 將防火牆加入 Strata Logging Service,可選擇是否使用 Panorama

如需詳細的啟用步驟,請參閱說明文件

轉送 Strata Logging Service 的記錄

為滿足長期儲存、報表和監控,或法律和法規遵循需求,您可以將 Strata Logging Service 設定為將記錄轉送至 HTTPS 伺服器,或下列 SIEM:

  1. Exabeam
  2. Google Chronicle
  3. Microsoft Sentinel
  4. Splunk HTTP 事件收集器 (HEC)

使用 HTTPS 轉送方法,透過 Strata Logging Service 轉送記錄檔。如需詳細資訊,請參閱這份文件

支援的記錄格式

Palo Alto Networks Strata Logging Service 防火牆剖析器支援 JSON 格式的記錄。

支援的範例記錄

  • JSON

    {"source": "Palo Alto Networks FLS LF", "host": "dummy-loghost", "time": "1730265996460", "event": {"TimeReceived": "2024-10-30T05:25:50.000000Z", "DeviceSN": "no-serial", "LogType": "TRAFFIC", "Subtype": "end", "ConfigVersion": "10.2", "TimeGenerated": "2024-10-30T05:25:40.000000Z", "SourceAddress": "198.51.100.6", "DestinationAddress": "198.51.100.6", "NATSource": "", "NATDestination": "", "Rule": "egress-dns-ping-traceroute", "SourceUser": null, "DestinationUser": null, "Application": "dns-base", "VirtualLocation": "vsys1", "FromZone": "VA8280-RN", "ToZone": "inter-fw", "InboundInterface": "tunnel.101", "OutboundInterface": "tunnel.4005", "LogSetting": "Cortex Data Lake", "SessionID": 754194, "RepeatCount": 1, "SourcePort": 53578, "DestinationPort": 53, "NATSourcePort": 0, "NATDestinationPort": 0, "Protocol": "udp", "Action": "allow", "Bytes": 214, "BytesSent": 72, "BytesReceived": 142, "PacketsTotal": 2, "SessionStartTime": "2024-10-30T05:25:10.000000Z", "SessionDuration": 0, "URLCategory": "any", "SequenceNo": 7382192512716388639, "SourceLocation": "198.51.100.6-198.51.255.255", "DestinationLocation": "198.51.100.6-198.51.255.255", "PacketsSent": 1, "PacketsReceived": 1, "SessionEndReason": "aged-out", "DGHierarchyLevel1": 65537, "DGHierarchyLevel2": 65538, "DGHierarchyLevel3": 65541, "DGHierarchyLevel4": 0, "VirtualSystemName": "", "DeviceName": "VA8280-RN", "ActionSource": "from-policy", "SourceUUID": null, "DestinationUUID": null, "IMSI": 0, "IMEI": null, "ParentSessionID": 0, "ParentStarttime": "1970-01-01T00:00:00.000000Z", "Tunnel": "N/A", "EndpointAssociationID": 72057594037927936, "ChunksTotal": 0, "ChunksSent": 0, "ChunksReceived": 0, "RuleUUID": "95cfc3cc-cb00-4758-af1d-de9ab5f07f97", "HTTP2Connection": 0, "LinkChangeCount": 0, "SDWANPolicyName": null, "LinkSwitches": null, "SDWANCluster": null, "SDWANDeviceType": null, "SDWANClusterType": null, "SDWANSite": null, "DynamicUserGroupName": null, "X-Forwarded-ForIP": null, "SourceDeviceCategory": null, "SourceDeviceProfile": null, "SourceDeviceModel": null, "SourceDeviceVendor": null, "SourceDeviceOSFamily": null, "SourceDeviceOSVersion": null, "SourceDeviceHost": null, "SourceDeviceMac": null, "DestinationDeviceCategory": null, "DestinationDeviceProfile": null, "DestinationDeviceModel": null, "DestinationDeviceVendor": null, "DestinationDeviceOSFamily": null, "DestinationDeviceOSVersion": null, "DestinationDeviceHost": null, "DestinationDeviceMac": null, "ContainerID": null, "ContainerNameSpace": null, "ContainerName": null, "SourceEDL": null, "DestinationEDL": null, "GPHostID": null, "EndpointSerialNumber": null, "SourceDynamicAddressGroup": null, "DestinationDynamicAddressGroup": null, "HASessionOwner": null, "TimeGeneratedHighResolution": "2024-10-30T05:25:41.009000Z", "NSSAINetworkSliceType": null, "NSSAINetworkSliceDifferentiator": null}}"
    

欄位對應參考資料:記錄欄位對應至 UDM 欄位

本節說明剖析器如何將 Palo Alto Networks Strata Logging Service 防火牆記錄欄位,對應至各記錄類型的 Google UDM 事件欄位。

如需各記錄類型的對應參考資料,請參閱下列章節:

系統

下表列出「系統」記錄類型中的記錄欄位,以及對應的 UDM 欄位。

Log field UDM mapping
AgentContentVersion additional.fields.key/value.string_value
AgentDataCollectionStatus target.resource.attribute.labels
AgentID target.resource.attribute.labels
AgentIsolationStatus target.resource.attribute.labels
AgentStatus target.resource.attribute.labels
AgentVersion target.asset.software.version
ConfigVersion additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DeviceGroup target.group.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EndpointCPUArchitecture target.asset.hardware.cpu_platform
EndpointDeviceDomain target.asset.administrative_domain
EndpointDeviceName target.asset.hostname
EndpointIPaddress target.asset.ip
VDIEndpoint target.asset.attribute.labels
EndpointOSType additional.fields.key/value.string_value
EndpointOSVersion target.platform_version
AgentTimeZoneOffset additional.fields.key/value.string_value
EndpointUserDomain additional.fields.key/value.string_value
EndpointUserName target.user.user_display_name
EndpointUserUUID target.user.userid
EventComponent additional.fields.key/value.string_value
EventDescription metadata.description
EventName additional.fields.key/value.string_value
EventTime metadata.event_timestamp
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogCategory security_result.category_details
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
LogSourceID target.resource.attribute.labels
LogSourceName observer.asset.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
LogTime metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Severity security_result.severity
Subtype metadata.product_event_type
Template target.resource.attribute.labels
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

威脅

下表列出「威脅」記錄類型的記錄欄位,以及對應的 UDM 欄位。

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
ApplianceOrCloud additional.fields.key/value.string_value
CloudHostname additional.fields.key/value.string_value
CloudReportID security_result.detection_fields.key/value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DirectionOfAttack security_result.detection_fields.key/value
DomainEDL additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
FileName target.file.names
FileHash target.file.sha1
FileType additional.fields.key/value.string_value
FileURL target.url
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HostID principal.asset.asset_id
HTTP2Connection network.application_protocol_version
HTTPMethod network.http.method
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
LocalDeepLearningAnalyzed additional.fields.key/value.string_value
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
PartialHash additional.fields.key/value.string_value
PayloadProtocolID additional.fields.key/value.string_value
Packet additional.fields.key/value.string_value
PacketID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
RecipientEmail target.user.email_addresses
ReportID security_result.detection_fields.key/value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SenderEmail principal.user.email_addresses
SequenceNo metadata.product_log_id
SessionID network.session_id
Severity security_result.severity
SigFlags additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
EmailSubject network.email.subject
ApplicationTechnology additional.fields.key/value.string_value
ThreatCategory security_result.detection_fields.key/value.key/value
ThreatID security_result.threat_id
ThreatName security_result.threat_name
ThreatNameFirewall additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLDomain target.domain.name
URLCounter additional.fields.key/value.string_value
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
Verdict additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-ForIP principal.ip

流量

下表列出「流量」記錄類型的記錄欄位,以及對應的 UDM 欄位。

Log field UDM mapping
Action security_result.action
ActionSource additional.fields.key/value.string_value
AIFwdError additional.fields.key/value.string_value
AITraffic additional.fields.key/value.string_value
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
BytesReceived network.received_bytes
BytesSent network.sent_bytes
Bytes additional.fields.key/value.string_value
ChunksReceived additional.fields.key/value.string_value
ChunksSent additional.fields.key/value.string_value
ChunksTotal additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
EndpointAssociationID additional.fields.key/value.string_value
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HASessionOwner additional.fields.key/value.string_value
GPHostID additional.fields.key/value.string_value
HTTP2Connection network.application_protocol_version
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsOffloaded additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
LinkChangeCount additional.fields.key/value.string_value
LinkSwitches additional.fields.key/value.string_value
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
SDWANPolicyName additional.fields.key/value.string_value
Protocol network.ip_protocol
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SDWANFECRatio additional.fields.key/value.string_value
SDWANCluster additional.fields.key/value.string_value
SDWANClusterType additional.fields.key/value.string_value
SDWANDeviceType additional.fields.key/value.string_value
SDWANSite additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionStartTime additional.fields.key/value.string_value
SessionTracker additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
SessionDuration network.session_duration
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLCategory target.url_metadata.categories
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-ForIP principal.ip

User-ID

下表列出 User-ID 記錄類型的記錄欄位,以及對應的 UDM 欄位。

Log field UDM mapping
AuthFactorNo security_result.detection_fields.key/value
AuthenticatedUserDomain target.user.administrative_domain
AuthenticatedUserName target.user.userid
AuthenticatedUserUUID target.user.product_object_id
ConfigVersion additional.fields.key/value.string_value
CountofRepeats additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationPort target.port
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EventID additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsDuplicateUser additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MappingDataSource additional.fields.key/value.string_value
MappingDataSourceName additional.fields.key/value.string_value
MappingDataSourceType additional.fields.key/value.string_value
MappingTimeout additional.fields.key/value.string_value
MFAFactorType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SourceIP principal.ip
SourcePort principal.port
Subtype metadata.product_event_type
Tag additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
UGFlags additional.fields.key/value.string_value
User target.user.userid
UserGroupFound additional.fields.key/value.string_value
UserIdentifiedBySource additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

HIP 比對

下表列出 HIP 比對記錄類型的記錄欄位,以及對應的 UDM 欄位。

Log field UDM mapping
ConfigVersion additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EndpointDeviceName principal.asset.hostname
EndpointOSType additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
HipMatchName target.resource.attribute.labels
HipMatchType target.resource.attribute.labels
HostID principal.asset.asset_id
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType metadata.product_event_type
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Source additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceIP principal.ip
SourceIPv6 principal.ip
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
TimestampDeviceIdentification principal.asset.first_seen_time
UUID additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

IP 標記

下表列出 IP 標記記錄類型的記錄欄位,以及對應的 UDM 欄位。

Log field UDM mapping
ConfigVersion additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EventID additional.fields.key/value.string_value
IPSubnetRange network.ip_subnet_range
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSetting target.resource.attribute.labels
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MappingDataSource additional.fields.key/value.string_value
MappingDataSourceSubType additional.fields.key/value.string_value
MappingDataSourceType additional.fields.key/value.string_value
MappingTimeout additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
RuleMatched security_result.rule_name
RuleMatchedUUID security_result.rule_id
SequenceNo metadata.product_log_id
SourceIP principal.ip
Subtype metadata.product_event_type
TagName additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

解密

下表列出「解密」記錄類型的記錄欄位,以及對應的 UDM 欄位。

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
CertificateFlags additional.fields.key/value.string_value
CertificateSerial network.tls.server.certificate.serial
CertificateSize additional.fields.key/value.string_value
CertificateVersion network.tls.server.certificate.version
ChainStatus additional.fields.key/value.string_value
ApplicationCharacteristics additional.fields.key/value.string_value
ClientToFirewall additional.fields.key/value.string_value
CommonName additional.fields.key/value.string_value
CommonNameLength additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
Cpadding additional.fields.key/value.string_value
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
Domain target.hostname
EllipticCurve network.tls.curve
ErrorIndex additional.fields.key/value.string_value
ErrorMessage additional.fields.key/value.string_value
Fingerprint network.tls.server.certificate.md5/sha1/sha256
FirewallToClient additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsCertECDSA additional.fields.key/value.string_value
IsCertRSA additional.fields.key/value.string_value
IsCertCNTruncated additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
IsForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsIssuerCNTruncated additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
IsNAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
PacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsResumeSession additional.fields.key/value.string_value
IsRootCNTruncated additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSNITruncated additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
IssuerCommonName network.tls.server.certificate.issuer
IssuerNameLength additional.fields.key/value.string_value
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
TimeNotAfter additional.fields.key/value.string_value
TimeNotBefore additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
Padding additional.fields.key/value.string_value
Padding3 additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
PolicyName additional.fields.key/value.string_value
Protocol network.ip_protocol
ProxyType additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
RootCommonName additional.fields.key/value.string_value
RootCNLength additional.fields.key/value.string_value
RootStatus additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SessionID network.session_id
ServerNameIndication network.tls.client.server_name
SNILength additional.fields.key/value.string_value
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceOS additional.fields.key/value.string_value
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
ApplicationTechnology additional.fields.key/value.string_value
TimeReceivedManagementPlane additional.fields.key/value.string_value
TLSAuth additional.fields.key/value.string_value
TLSEncryptionAlgorithm additional.fields.key/value.string_value
TLSKeyExchange additional.fields.key/value.string_value
TLSVersion network.tls.version
ToZone additional.fields.key/value.string_value
Tpadding additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
Vpadding additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SourceDeviceCategory principal.asset.category
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

隧道

下表列出 Tunnel 記錄類型的記錄欄位,以及對應的 UDM 欄位。

Log field UDM mapping
AccessPointName additional.fields.key/value.string_value
Action security_result.action
ActionSource additional.fields.key/value.string_value
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
BytesReceived network.received_bytes
BytesSent network.sent_bytes
Bytes additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
LoggingServiceID additional.fields.key/value.string_value
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MobileAreaCode additional.fields.key/value.string_value
MobileBaseStationCode additional.fields.key/value.string_value
MobileCountryCode additional.fields.key/value.string_value
MobileIP additional.fields.key/value.string_value
MobileNetworkCode additional.fields.key/value.string_value
MobileSubscriberISDN additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceDifferentiator additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsDroppedMax additional.fields.key/value.string_value
PacketsDroppedStrict additional.fields.key/value.string_value
PacketsDroppedTunnel additional.fields.key/value.string_value
PacketsDroppedProtocol additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
ProtocolDataUnitsessionID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
RadioAccessTechnology additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionStartTime additional.fields.key/value.string_value
SessionTracker additional.fields.key/value.string_value
Severity security_result.severity
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
StandardPortsOfApp additional.fields.key/value.string_value
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
SessionDuration network.session_duration
Tunnel additional.fields.key/value.string_value
TunnelCauseCode additional.fields.key/value.string_value
TunnelEndpointID1 additional.fields.key/value.string_value
TunnelEndpointID2 additional.fields.key/value.string_value
TunnelEventCode additional.fields.key/value.string_value
TunnelEventType additional.fields.key/value.string_value
TunnelInspectionRule additional.fields.key/value.string_value
TunnelInterface additional.fields.key/value.string_value
TunnelMessageType additional.fields.key/value.string_value
TunnelRemoteIMSIID additional.fields.key/value.string_value
TunnelRemoteUserIP principal.ip
TunnelSessionsClosed additional.fields.key/value.string_value
TunnelSessionsCreated additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLCategory target.url_metadata.categories
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

驗證

下表列出「驗證」記錄類型的記錄欄位,以及對應的 UDM 欄位。

Log field UDM mapping
AuthenticationDescription security_result.description
AuthEvent metadata.description
AuthFactorNo security_result.detection_fields.key/value
AuthenticationPolicy security_result.detection_fields.key/value
AuthenticationProtocol additional.fields.key/value.string_value
AuthServerProfile additional.fields.key/value.string_value
AuthenticatedUserDomain target.administrative_domain
AuthenticatedUserName target.user.userid
AuthenticatedUserUUID target.user.product_object_id
ClientType additional.fields.key/value.string_value
ClientTypeName additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
IsPrismaNetworks additional.fields.key/value.string_value
Location target.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogType additional.fields.key/value.string_value
MFAAuthenticationID additional.fields.key/value.string_value
MFAVendor additional.fields.key/value.string_value
NormalizeUser target.user.user_display_name
Object target.resource.name
RuleMatched security_result.rule_name
RuleMatchedUUID security_result.rule_id
AuthCacheServiceRegion additional.fields.key/value.string_value
SessionID network.session_id
SourceDeviceCategory principal.asset.category
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceIP principal.ip
TimeGenerated metadata.event_timestamp
User target.user.userid
UserAgentString network.http.user_agent
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Subtype metadata.product_event_type
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

網址

下表列出網址記錄類型的記錄欄位,以及對應的 UDM 欄位。

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
CloudHostname additional.fields.key/value.string_value
CloudReportID security_result.detection_fields.key/value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentType additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DirectionOfAttack security_result.detection_fields.key/value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
FileURL target.url
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HostID principal.asset.asset_id
HTTP2Connection network.application_protocol_version
HTTPHeaders additional.fields.key/value.string_value
HTTPMethod network.http.method
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
InlineMLVerdict additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
Packet additional.fields.key/value.string_value
PacketID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
Referer network.http.referral_url
HTTPRefererFQDN additional.fields.key/value.string_value
HTTPRefererPort additional.fields.key/value.string_value
HTTPRefererProtocol additional.fields.key/value.string_value
HTTPRefererURLPath additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionID network.session_id
Severity security_result.severity
SigFlags additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URL target.url_metadata.URL
URLCategory target.url_metadata.categories
URLCategoryList additional.fields.key/value.string_value
URLDomain target.domain.name
URLCounter additional.fields.key/value.string_value
UserAgent network.http.user_agent
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-For additional.fields.key/value.string_value
X-Forwarded-ForIP principal.ip

GlobalProtect

下表列出 GlobalProtect 記錄類型的記錄欄位,以及對應的 UDM 欄位。

Log field UDM mapping
AttemptedGateways additional.fields.key/value.string_value
AuthMethod extensions.auth.auth_details
ConnectionMethod additional.fields.key/value.string_value
ConnectionErrorID additional.fields.key/value.string_value
ConnectionError additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
EndpointDeviceName principal.asset.hostname
GlobalProtectClientVersion additional.fields.key/value.string_value
EndpointOSType additional.fields.key/value.string_value
EndpointSN principal.asset.hardware.serial_number
EventIDValue additional.fields.key/value.string_value
Gateway target.resource.name
GatewayPriority additional.fields.key/value.string_value
GatewaySelectionType additional.fields.key/value.string_value
GlobalProtectGatewayLocation target.location.country_or_region
HostID principal.asset.asset_id
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LoginDuration network.session_duration
Description security_result.description
Portal target.hostname
PrivateIPv4 principal.ip
PrivateIPv6 principal.ip
ProjectName additional.fields.key/value.string_value
PublicIPv4 principal.nat_ip
PublicIPv6 principal.nat_ip
QuarantineReason security_result.summary
SequenceNo metadata.product_log_id
SourceRegion principal.location.country_or_region
SourceUserName principal.user.user_display_name
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SSLResponseTime additional.fields.key/value.string_value
Stage additional.fields.key/value.string_value
EventStatus additional.fields.key/value.string_value
LogSubtype metadata.product_event_type
TunnelType additional.fields.key/value.string_value
VirtualSystem intermediary.asset.attribute.labels
VirtualSystemName intermediary.asset.attribute.labels
EndpointOSVersion principal.platform_version
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType metadata.product_event_type
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualSystemID intermediary.resource.product_object_id

SCTP

下表列出 SCTP 記錄類型的記錄欄位,以及對應的 UDM 欄位。

Log field UDM mapping
Action security_result.action
Application target.application
AssocationEndReason additional.fields.key/value.string_value
ChunksReceived additional.fields.key/value.string_value
ChunksSent additional.fields.key/value.string_value
ChunksTotal additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceClass target.asset.category
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationIP target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DiamAppID additional.fields.key/value.string_value
DiamAvpCode additional.fields.key/value.string_value
DiameterCommandCode additional.fields.key/value.string_value
DiameterRequestFlag additional.fields.key/value.string_value
DeviceName principal.asset.hostname
SCTPEventType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLFiltering additional.fields.key/value.string_value
IsWildfire additional.fields.key/value.string_value
LogAction additional.fields.key/value.string_value
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MapAppCode additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PayloadProtocolID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
Rule security_result.rule_name
RuleUUID security_result.rule_id
SccpCallingGt additional.fields.key/value.string_value
SccpCallingSSN additional.fields.key/value.string_value
SctpCauseCode additional.fields.key/value.string_value
SctpChunkType additional.fields.key/value.string_value
SctpFilter additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionTracker additional.fields.key/value.string_value
Severity security_result.severity
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceIP principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VerificationTag1 additional.fields.key/value.string_value
VerificationTag2 additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

稽核

下表列出稽核記錄類型和對應 UDM 欄位的記錄檔欄位。

Log field UDM mapping
EventCategory network.http.method
EventDescription metadata.description
EventDestinationURL target.url
EventDestinationUserUserID target.user.userid
DestinationVendor additional.fields.key/value.string_value
EventDetails additional.fields.key/value.string_value
EventID metadata.product_log_id
EventName additional.fields.key/value.string_value
EventResult security_result.summary
EventSourceUserUserID principal.user.userid
EventTime metadata.event_timestamp
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
Subtype metadata.product_event_type
TSGID additional.fields.key/value.string_value
Vendor additional.fields.key/value.string_value
VendorSeverity security_result.severity_details

欄位對應參考資料:記錄類型至 UDM 事件類型

下表列出 Palo Alto Networks Strata Logging Service 防火牆記錄類型,以及對應的 UDM 事件類型。

記錄類型 UDM 事件類型
流量 NETWORK_CONNECTION
威脅 NETWORK_CONNECTION
網址篩選 NETWORK_CONNECTION
通道 NETWORK_CONNECTION
系統

如果子類型值為「dhcp」,系統會設定 NETWORK_DHCP。

如果子類型值為「auth」,系統就會設定 USER_LOGIN。

如果說明值為「logged in」,系統就會設定 USER_LOGIN。

如果說明值為「logged out」,系統會設定 USER_LOGOUT。

如果子類型為其他值,系統會設定 GENERIC_EVENT。

HIP Match NETWORK_CONNECTION
IP 代碼 GENERIC_EVENT
User-ID USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED

如果子類型值為「login」,系統就會設定 USER_LOGIN。

如果子類型值為「logout」,系統會設定 USER_LOGOUT。

如果子類型不含任何值,系統會設定 USER_UNCATEGORIZED。

解密 NETWORK_CONNECTION
驗證 STATUS_UNCATEGORIZED
Globalprotect USER_LOGIN/USER_LOGOUT/USER_RESOURCE_ACCESS

如果子類型值為「auth」,系統會設定 USER_LOGIN。

如果子類型值為「logout」,系統會設定 USER_LOGOUT。

如果子類型不含任何值,系統會設定 USER_RESOURCE_ACCESS。

SCTP NETWORK_CONNECTION
稽核 NETWORK_CONNECTION

後續步驟

還有其他問題嗎?向社群成員和 Google SecOps 專業人員尋求答案。