收集 Palo Alto Networks 防火牆記錄
Palo Alto Networks 防火牆
總覽
本文說明如何設定系統記錄檔和 Google SecOps 轉送器,以收集 Palo Alto Networks 防火牆記錄。本文也說明 Palo Alto Networks 防火牆記錄欄位如何對應至 Google SecOps 整合式資料模型 (UDM) 欄位。如要瞭解 Google SecOps 資料擷取作業的概況,請參閱「將資料擷取至 Google SecOps」。擷取標籤會識別剖析器,該剖析器會將原始記錄資料正規化為具結構性的 UDM 格式。本文中的資訊適用於具有 PAN_FIREWALL 攝入標籤的剖析器。
事前準備
- 確認 Palo Alto Networks 防火牆產品已正確部署及設定。如需詳細設定操作說明,請參閱 PAN-OS 說明文件。
如要瞭解部署的元件,以便收集 Palo Alto Networks 防火牆記錄,請查看部署架構。每個客戶部署作業可能與此表示法不同,也可能更複雜。下圖顯示如何在 Palo Alto Networks 防火牆上設定系統記錄,以及在 Linux 伺服器上安裝 Google SecOps 轉送器,將記錄資料轉送至 Google SecOps。剖析器支援以半形逗號分隔值 (CSV)、通用事件格式 (CEF) 和記錄事件擴充格式 (LEEF) 等資料格式編寫的記錄。
確認 Google SecOps 剖析器支援的記錄格式和 PAN-OS 版本。下表列出 Google SecOps 剖析器支援的記錄格式和對應的 PAN-OS 版本:
記錄格式 PAN-OS 版本 CSV 10.1.3 CEF 10.0.0 LEEF 9.1.0 確認 Google SecOps 剖析器支援的 Palo Alto Networks 防火牆記錄檔類型。 Google SecOps 剖析器支援下列 Palo Alto Networks 防火牆記錄類型:
- 流量
- 威脅
- WildFire 提交內容
- 隧道檢查
- 設定
- 系統
- HIP 比對
- IP-Tag
- User-ID
- 解密
- 驗證
- 網址篩選
- 資料篩選
- GlobalProtect
- 關聯性
- GTP
- SCTP
- 稽核
如要進一步瞭解 Palo Alto Networks 防火牆記錄類型,請參閱 PAN-OS 記錄類型。
請確保部署架構中的所有系統都以世界標準時間設定。
使用 Palo Alto Networks 防火牆剖析器前,請先查看舊版剖析器與現行 Palo Alto Networks 防火牆剖析器之間的欄位對應關係變化。在遷移過程中,請確保依附於原始欄位的規則、搜尋、資訊主頁或其他程序,都使用更新後的欄位。
舉例來說,在先前的剖析器版本中,
category記錄檔欄位會對應至security_result.descriptionUDM 欄位。在目前的 Palo Alto Networks 防火牆剖析器中,category記錄欄位會對應至security_result.category_detailsUDM 欄位。如果您遷移至目前的 Palo Alto Networks 防火牆剖析器,並在規則中使用category欄位,則需要修改規則,才能使用目前剖析器的security_result.category_detailsUDM 欄位。
設定系統記錄和 Google Security Operations 轉送器
如要設定系統記錄和 Google SecOps 轉送器,請完成下列步驟:
- 如要監控 CSV 記錄檔,請設定系統記錄檔伺服器設定檔。詳情請參閱「設定系統記錄伺服器設定檔」。設定系統記錄伺服器設定檔時,請將「Default」指定為自訂記錄格式。
- 如要監控 CEF 記錄,請設定 Palo Alto Networks 防火牆轉送 CEF 記錄。詳情請下載 PAN-OS CEF 整合指南 PDF,並參閱「Configuration of Palo Alto Networks NGFW to output CEF events」(設定 Palo Alto Networks NGFW 以輸出 CEF 事件) 一節。
- 如要監控 LEEF 記錄,請設定系統記錄檔伺服器設定檔。詳情請參閱「以 LEEF 格式轉送自訂記錄」。
設定 Google SecOps 轉送器,將記錄傳送至 Google Security Operations。詳情請參閱「在 Linux 上安裝及設定轉送器」。以下是 Google SecOps 轉送站設定範例:
- syslog: common: enabled: true data_type: PAN_FIREWALL batch_n_seconds: 10 batch_n_bytes: 1048576 tcp_address: 0.0.0.0:10518 connection_timeout_sec: 60
在 PAN 防火牆上設定系統記錄轉送
建立系統記錄伺服器設定檔
- 登入 Palo Alto Networks 防火牆管理主控台。
- 依序前往「裝置」>「伺服器設定檔」>「系統記錄」。
- 按一下「新增」,建立新的伺服器設定檔。
- 提供下列設定詳細資料:
- 名稱:輸入描述性名稱 (例如
Google SecOps BindPlane)。 - 位置:選取這個設定檔可用的虛擬系統 (vsys) 或「共用」。
- 名稱:輸入描述性名稱 (例如
- 依序點選「Servers」(伺服器) >「Add」(新增),設定系統記錄伺服器。
- 提供下列伺服器設定詳細資料:
- 名稱:輸入伺服器的描述性名稱 (例如
BindPlane Agent)。 - Syslog 伺服器:輸入 BindPlane 代理程式 IP 位址。
- 傳輸:根據 BindPlane Agent 設定選取「UDP」或「TCP」 (預設為 UDP)。
- 「Port」(通訊埠):輸入 BindPlane 代理程式通訊埠編號 (例如
514)。 - 格式:視需求選取 BSD (預設) 或 IETF。
- 設施:選取「LOG_USER」(預設) 或其他設施 (如有需要)。
- 名稱:輸入伺服器的描述性名稱 (例如
- 按一下「確定」,儲存系統記錄伺服器設定檔。
選用:設定 CEF 或 LEEF 的自訂記錄格式
如需 CEF (通用事件格式) 或 LEEF (記錄事件擴充格式) 記錄,而非 CSV 檔案,請按照下列步驟操作:
- 在 Syslog 伺服器設定檔中,選取「Custom Log Format」(自訂記錄格式) 分頁。
- 為每種記錄類型 (設定、系統、威脅、流量、網址、資料、WildFire、通道、驗證、User-ID、HIP 比對) 設定自訂記錄格式。
- 如要設定 CEF 格式,請參閱 Palo Alto Networks CEF 設定指南。
- 按一下「確定」儲存設定。
建立記錄檔轉送設定檔
- 依序前往「物件」>「記錄轉送」。
- 按一下「新增」,建立新的記錄轉送設定檔。
- 提供下列設定詳細資料:
- 名稱:輸入設定檔名稱 (例如
Google SecOps Forwarding)。如要讓防火牆自動將這個設定檔指派給新的安全性規則和區域,請將設定檔命名為default。
- 名稱:輸入設定檔名稱 (例如
- 針對要轉送的每種記錄類型 (流量、威脅、WildFire 提交、網址篩選、資料篩選、通道、驗證),請設定下列項目:
- 在對應的記錄類型部分中,按一下「新增」。
- 「Syslog」Syslog:選取您建立的 Syslog 伺服器設定檔 (例如
Google SecOps BindPlane)。 - 記錄嚴重程度:選取要轉送的嚴重程度等級 (例如「全部」)。
- 按一下「確定」,儲存記錄轉送設定檔。
將記錄轉送設定檔套用至安全性政策
- 依序前往「政策」>「安全性」。
- 選取要啟用記錄轉送的安全規則。
- 按一下規則即可編輯。
- 前往「動作」分頁。
- 在「記錄檔轉送」選單中,選取您建立的記錄檔轉送設定檔 (例如
Google SecOps Forwarding)。 - 按一下「確定」,儲存安全性政策設定。
設定系統記錄的記錄設定
- 依序點選「裝置」>「記錄設定」。
- 針對每種記錄類型 (系統、設定、使用者 ID、HIP 比對、Global Protect、IP 標記、SCTP) 和嚴重程度,選取您建立的系統記錄伺服器設定檔。
- 按一下「確定」儲存記錄設定。
修訂變更
- 按一下防火牆網頁介面頂端的「Commit」。
- 等待提交作業順利完成。
- 檢查 Google SecOps 控制台是否有傳入的 Palo Alto Networks 防火牆記錄,確認記錄是否已傳送至 Bindplane 代理程式。
使用 Bindplane 代理程式將記錄轉送至 Google SecOps
- 安裝並設定 Linux 虛擬機器。
- 在 Linux 上安裝及設定 Bindplane 代理程式,將記錄轉寄至 Google SecOps。如要進一步瞭解如何安裝及設定 Bindplane 代理程式,請參閱 Bindplane 代理程式安裝及設定說明。
如果在建立動態饋給時遇到問題,請與 Google SecOps 支援團隊聯絡。
支援的記錄格式
Palo Alto Networks 防火牆剖析器支援 LEEF、CEF 和 CSV 格式的記錄。
支援的範例記錄
LEEF
<14>Jan 22 02:20:19 device_host LEEF:1.0|Palo Alto Networks|PAN-OS Syslog Integration|10.2.12-h4|Microsoft MSOFFICE(52033)|ReceiveTime=2025/01/22 02:20:18|SerialNumber=01250100xxxx|cat=THREAT|Subtype=wildfire|devTime=Jan 22 2025 08:20:18 GMT|src=198.50.100.1|dst=198.50.100.2|srcPostNAT=198.50.100.3|dstPostNAT=198.50.100.4|RuleName=AZURE-US-NEW-CNF_Inbound_To_Azure-ALLOW|usrName=|SourceUser=|DestinationUser=|Application=smtp-base|VirtualSystem=vsys1|SourceZone=McD-Global-Zone|DestinationZone=Azure-Zone|IngressInterface=ae1.111|EgressInterface=ae2.409|LogForwardingProfile=Default-Traffic-Logging|SessionID=35331795|RepeatCount=1|srcPort=21578|dstPort=25|srcPostNATPort=0|dstPostNATPort=0|Flags=0x2000|proto=tcp|action=allow|Miscellaneous=\"......3...................xls\"|ThreatID=Microsoft MSOFFICE(52033)|URLCategory=malicious|sev=4|Severity=high|Direction=client-to-server|sequence=7462614601465681755|ActionFlags=0x8000000000000000|SourceLocation=198.50.100.1-198.50.100.255|DestinationLocation=United States|ContentType=|PCAP_ID=0|FileDigest=0ea04c99bf188c2e4207f60f92ca7c6f5088c7943ee63f45c50032bbd2bf7ea9|Cloud=demo.com|URLIndex=1|RequestMethod=|FileType=ms-office|Sender=sender@ab.myownpersonaldomain.com|Subject=\"............:.................................................................................-.........(Name)-2025-01-22...............:Y107202501220005, ............:........................, ...............:.........\"|Recipient=abc@demo.myownpersonaldomain.com|ReportID=117022282776|DeviceGroupHierarchyL1=143|DeviceGroupHierarchyL2=144|DeviceGroupHierarchyL3=39|DeviceGroupHierarchyL4=0|vSrcName=|DeviceName=device_host|SrcUUID=|DstUUID=|TunnelID=0|MonitorTag=|ParentSessionID=0|ParentStartTime=|TunnelType=N/A|ThreatCategory=N/A|ContentVer=WildFire-0CEF
14>1 2024-04-04T16:21:56+02:00 FW-PERIMETRAL-AVG-01 - - - - CEF:0|Palo Alto Networks|PAN-OS|10.1.10-h2|end|TRAFFIC|1|src=198.51.100.1 dst=198.51.100.2 srcTranslatedAddress=198.51.100.3 dstTranslatedAddress=198.51.100.4 rule=FW_USER_NATS2_APP suser= duser= app=bittorrent vs=vsys1 sz=INSIDE dz=EXTERNAL InboundInterface=ae2.2266 OutboundInterface=ae1 lp=log_forwarding sid=2935823 cnt=1 spt=6881 dpt=51413 srcTranslatedPort=0 dstTranslatedPort=0 flags=0x7a proto=udp act=allow tbytes=475 in=150 out=325 pkt=2 pktReceived=1 pktSent=1 start=Apr 04 2024 14:21:56 GMT stime=1206 urlcat=any externalId=externalId reason=aged-out DGl1=11 DGl2=161 DGl3=0 DGl4=0 VsysName=STONESOFT dvchost=FW-PERIMETRAL-AVG-01 cat=from-policy ActionFlags=0x8000000000000000 srcUUID= dstUUID= TunnelID=0 MonitorTag= ParentSessionID=0 ParentStartTime= TunnelType=N/A SCTPAssocID=0 SCTPChunks=0 SCTPChunkSent=0 SCTPChunksRcv=0 RuleUUID=746c3eb6-3d51-4679-8438-bd0e00e170a8 HTTP2Con=0 LinkChange=0 PolicyID= LinkDetail= SDWANCluster= SDWANDevice= SDWANClustype= SDWANSite= DynamicUsrgrp= XFFIP= srcDevCat= srcDevProf= srcDevModel= srcDevVendor= srcDevOS= srcDevOSv= srcHostname= srcMac= dstDevCat= dstDevProf= dstDevModel= dstDevVendor= dstDevOS= dstDevOSv= dstHostname= dstMac= ContainerName= PODNamespace= PODName= srcEDL= dstEDL= GPHostID= EPSerial= srcDAG= dstDAG= HASessionOwner= TimeHighRes=2024-04-04T16:21:56.250+02:00 ASServiceType= ASServiceDiff="CSV
1,2021/10/24 15:30:07,,CONFIG,0,2561,2021/10/24 15:30:07,198.51.100.0,,set,admin,Web,Succeeded, network virtual-router VR1,,VR1 { ecmp { algorithm { ip-modulo ; } } protocol { bgp { routing-options { graceful-restart { enable yes; } } enable no; } rip { enable no; } ospf { enable no; } ospfv3 { enable no; } } routing-table { ip { static-route { vr1-log { path-monitor { enable no; failure-condition any; hold-time 2; } nexthop { ip-address 198.51.100.0; } bfd { profile None; } interface ethernet1/1; metric 10; destination 0.0.0.0/0; route-table { unicast ; } } } } } interface [ ethernet1/1 ethernet1/2 ]; } ,7022390503849066572,0x0,0,0,0,0,,PA-VM,0,
欄位對應參考資料:記錄欄位對應至 UDM 欄位
本節說明剖析器如何將 Palo Alto Networks 防火牆記錄欄位對應至各記錄類型的 Google SecOps UDM 事件欄位。Google SecOps 標籤鍵是指對應至 Labels.key UDM 欄位的鍵名稱。
舉例來說,如果是「虛擬系統」欄位,欄位名稱在 CEF 格式中為「cs3」,在 LEEF 格式中則為「VirtualSystem」。UDM 欄位「about.labels.key」包含值「vsys」,而 UDM 欄位「about.labels.value」包含該欄位的值。部分 CEF 或 LEEF 欄位名稱沒有對應的 CSV 欄位名稱。在這種情況下,如果您在系統記錄檔設定檔的自訂記錄格式中加入自己的變數名稱,剖析器不會將該名稱對應至 UDM 欄位。
如需各記錄類型的對應參考資料,請參閱下列章節:
系統
下表列出系統記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|
| 序號 (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| 類型 (型別) | type (Header) | cat | metadata.product_event_type 已設為「%{type} - %{subtype}」。 | |
| 威脅/內容類型 (子類型) | 子類型 (標題) | 子類型 | metadata.product_event_type 已設為「%{type} - %{subtype}」。 | |
| 產生時間 (time_generated 或 cef-formatted-time_generated) | metadata.event_timestamp | |||
| 虛擬系統 (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| 事件 ID (eventid) | cat | eventid | additional.fields.key 和 additional.fields.value.string_value | |
| 物件 (object) | fname | 檔案名稱 | object | target.resource.name |
| 模組 (module) | flexString2 | Module | 模組 | additional.fields.key 和 additional.fields.value.string_value |
| 嚴重性 (嚴重性) | $number-of-severity(header) | 嚴重性 | security_result.severity 和 security_result.severity_details | |
| 說明 (不透明) | msg | msg | metadata.description | |
| principal_user_userid (這個欄位是從 msg 欄位擷取) | principal.user.userid | |||
| principal_ip3 (這個欄位是從 msg 欄位擷取) | principal.ip | |||
| 原因 (這個欄位是從 msg 欄位擷取) | security_result.description | |||
| server_address (這個欄位是從 msg 欄位擷取而來) | target.ip | |||
| server_profile (這個欄位是從 msg 欄位擷取而來) | additional.fields.key 和 additional.fields.value.string_value | |||
| 序號 (seqno) | externalId | sequence | metadata.product_log_id | |
| 動作旗標 (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_1 至 dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value |
| 虛擬系統名稱 (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| 裝置名稱 (device_name) | dvchost | DeviceName | target.hostname | |
| 高解析度時間戳記 (high_res_timestamp) | anOSTimeGeneratedHighResolution | additional.fields.key 和 additional.fields.value.string_value |
設定
下表列出設定記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|
| 序號 (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| 類型 (型別) | type (Header) | cat | metadata.product_event_type | |
| 威脅/內容類型 (子類型) | 子類型 (標題) | metadata.product_event_type | ||
| 產生時間 (time_generated 或 cef-formatted-time_generated) | metadata.event_timestamp | |||
| 主機 (host) | shost | src | principal.ip/hostname | |
| 虛擬系統 (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| 指令 (cmd) | act | msg | cmd | principal.process.command_line |
| 管理員 (admin) | duser | usrName | principal.user.userid | |
| 用戶端 (client) | destinationServiceName | 用戶端 | principal.application | |
| 結果 (結果) | 簽章 ID (標頭)(原因) | 結果 | security_result.summary | |
| 設定路徑 (路徑) | msg | ConfigurationPath | principal.process.command_line | |
| 變更前詳細資料 (before_change_detail) | cs1 | BeforeChangeDetail | before_change_detail | target.resource.attribute.labels.key/value |
| 變更詳細資料 (after_change_detail) | cs2 | AfterChangeDetail | after_change_detail | target.resource.attribute.labels.key/value |
| 序號 (seqno) | externalId | sequence | metadata.product_log_id | |
| 動作旗標 (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_1 至 dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value |
| 虛擬系統名稱 (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| 裝置名稱 (device_name) | dvchost | DeviceName | target.hostname | |
| 裝置群組 (dg_id) | PanOSFWDeviceGroup | target.asset.attribute.labels.key/value | dg_id | principal.asset.attribute.labels.key/value |
| 稽核註解 (註解) | PanOSPolicyAuditComment | 註解 | additional.fields.key 和 additional.fields.value.string_value | |
| 高解析度時間戳記 (high_res_timestamp) | additional.fields.key 和 additional.fields.value.string_value | |||
| 嚴重性 (嚴重性) | number-of-severity(header) | security_result.severity 和 security_result.severity_details |
威脅/WildFire
下表列出 Threat/WildFire 記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|
| 序號 (序號) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| 類型 (型別) | type (Header) | cat | metadata.product_event_type | |
| 威脅/內容類型 (子類型) | cat/subtype (Header) | 子類型 | metadata.product_event_type | |
| 產生時間 (time_generated 或 cef-formatted-time_generated) | metadata.event_timestamp | |||
| 來源地址 (src) | src | src | principal.ip | |
| 目的地地址 (dst) | dst | dst | target.ip | |
| NAT 來源 IP (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| 網路位址轉譯 (NAT) 目的地 IP (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| 規則名稱 (規則) | cs1 | RuleName | security_result.rule_name | |
| 來源使用者 (srcuser) | suser | SourceUser / usrName | principal.user.userid | |
| 目的地使用者 (dstuser) | duser | DestinationUser | target.user.userid | |
| 應用程式 (app) | 應用程式 | 應用程式 | target.application | |
| 虛擬系統 (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| 來源區域 (從) | cs4 | SourceZone | 從 | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 目的地可用區 (至) | cs5 | DestinationZone | 到 | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 傳入介面 (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 傳出介面 (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 記錄動作 (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key 和 additional.fields.value.string_value |
| 工作階段 ID (sessionid) | cn1 | SessionID | network.session_id | |
| 重複次數 (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key 和 additional.fields.value.string_value |
| 來源通訊埠 (sport) | spt | srcPort | principal.port | |
| 目的地通訊埠 (dport) | dpt | dstPort | target.port | |
| NAT 來源通訊埠 (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| NAT 目的地通訊埠 (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| 旗標 (flags) | flexString1 | 旗標 | flags | additional.fields.key 和 additional.fields.value.string_value |
| IP 通訊協定 (proto) | proto | proto | network.ip_protocol | |
| 動作 (action) | act | action | security_result.action_details
security_result.action |
|
| 網址/檔案名稱 (其他) | 要求 | 其他 | target.file.names (如果子類型為「file」、「virus」、「wildfire-virus」或「wildfire」,則 `misc` 欄位會對應至 target.file.names) target.url (如果子類型為「url」,則 `misc` 欄位會對應至 target.url 和 target.hostname) |
|
| 威脅/內容名稱 (threatid) | cat | ThreatID | security_result.threat_name | |
| 類別 (類別) | cs2 | URLCategory | security_result.category_details | |
| 嚴重性 (嚴重性) | number-of-severity(header) | 嚴重性 | security_result.severity 和 security_result.severity_details | |
| 方向 (方向) | flexString2 | 方向 | network.direction | |
| 序號 (seqno) | externalId | sequence | metadata.product_log_id | |
| 動作旗標 (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value |
| 來源國家/地區 (srcloc) | SourceLocation | principal.location.country_or_region | ||
| 目的地國家/地區 (dstloc) | DestinationLocation | target.location.country_or_region | ||
| 內容類型 (contenttype) | ContentType | contenttype | additional.fields.key 和 additional.fields.value.string_value | |
| PCAP ID (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key 和 additional.fields.value.string_value |
| 檔案摘要 (filedigest) | fileHash | FileDigest | target.file.sha1/md5/sha256 | |
| 雲端 (cloud) | filePath | Cloud | 雲端 | additional.fields.key 和 additional.fields.value.string_value |
| 網址索引 (url_idx) | URLIndex | url_idx | additional.fields.key 和 additional.fields.value.string_value | |
| 使用者代理程式 (user_agent) | network.http.user_agent | |||
| 檔案類型 (filetype) | fileType | FileType | target.file.mime_type | |
| X-Forwarded-For (xff) | principal.ip | |||
| 參照網址 (referer) | network.http.referral_url | |||
| 寄件者 (寄件者) | suid | 寄件者 | network.email.from | |
| 主旨 (subject) | msg | 主旨 | network.email.subject | |
| 收件者 (recipient) | duid | 收件者 | network.email.to | |
| 報表 ID (reportid) | oldFileId | ReportID | reportid | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_1 至 dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value |
| 虛擬系統名稱 (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| 裝置名稱 (device_name) | dvchost | DeviceName | intermediary.hostname | |
| 來源 VM UUID (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id | |
| 目的地 VM UUID (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id | |
| HTTP 方法 (http_method) | RequestMethod | network.http.method | ||
| 通道 ID/IMSI (tunnel_id/imsi) | PanOSTunnelID | TunnelID | tunnel_id/imsi | additional.fields.key 和 additional.fields.value.string_value |
| 監控標籤/IMEI (monitortag/imei) | PanOSMonitorTag | MonitorTag | monitortag/imei | additional.fields.key 和 additional.fields.value.string_value |
| 父項工作階段 ID (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| 父項工作階段開始時間 (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key 和 additional.fields.value.string_value |
| 通道類型 (通道) | PanOSTunnelType | TunnelType | 通道 | additional.fields.key 和 additional.fields.value.string_value |
| 威脅類別 (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| 內容版本 (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key 和 additional.fields.value.string_value |
| SCTP 關聯 ID (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key 和 additional.fields.value.string_value | |
| 酬載通訊協定 ID (ppid) | PanOSPPID | ppid | additional.fields.key 和 additional.fields.value.string_value | |
| HTTP 標頭 (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| 網址類別清單 (url_category_list) | PanOSURLCatList | url_category_list | additional.fields.key 和 additional.fields.value.string_value | |
| 規則 UUID (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| HTTP/2 連線 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| 動態使用者群組名稱 (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
|
| XFF 位址 (xff_ip) | PanXFFIP | principal.ip | ||
| 來源裝置類別 (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| 來源裝置設定檔 (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
|
| 來源裝置型號 (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| 來源裝置供應商 (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| 來源裝置 OS 系列 (src_osfamily) | PanSrcDeviceOS | src_osfamily | principal.platform | |
| 來源裝置 OS 版本 (src_osversion) | PanSrcDeviceOSv | principal.platform_version | ||
| 來源主機名稱 (src_host) | PanSrcHostname | principal.hostname | ||
| 來源 MAC 位址 (src_mac) | PanSrcMac | principal.mac | ||
| 目的地裝置類別 (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| 目的地裝置設定檔 (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
|
| 目的地裝置型號 (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| 目的地裝置供應商 (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| 目的地裝置 OS 系列 (dst_osfamily) | PanDstDeviceOS | dst_osfamily | target.platform | |
| 目的地裝置 OS 版本 (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| 目的地主機名稱 (dst_host) | PanDstHostname | target.hostname | ||
| 目的地 MAC 位址 (dst_mac) | PanDstMac | target.mac | ||
| 容器 ID (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| POD 命名空間 (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| POD 名稱 (pod_name) | PanPODName | pod_name | target.resource.name | |
| 來源外部動態清單 (src_edl) | PanSrcEDL | src_edl | additional.fields.key 和 additional.fields.value.string_value | |
| 目標外部動態清單 (dst_edl) | PanDstEDL | dst_edl | additional.fields.key 和 additional.fields.value.string_value | |
| 主機 ID (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| 使用者裝置序號 (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| 網域 EDL (domain_edl) | PanDomainEDL | domain_edl | additional.fields.key 和 additional.fields.value.string_value | |
| 來源動態位址群組 (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| 目的地動態地址群組 (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| 部分雜湊 (partial_hash) | PanPartialHash | partial_hash | additional.fields.key 和 additional.fields.value.string_value | |
| 高解析度時間戳記 (high_res timestamp) | PanTimeHighRes | 高解析度時間戳記 | additional.fields.key 和 additional.fields.value.string_value | |
| 原因 (原因) | PanReasonFilteringAction | 原因 | security_result.summary | |
| 理由 (理由) | PanJustification | 理由 | additional.fields.key 和 additional.fields.value.string_value | |
| 區塊服務類型 (nssai_sst) | PanASServiceType | nssai_sst | additional.fields.key 和 additional.fields.value.string_value | |
| 應用程式子類別 (subcategory_of_app) | subcategory_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式類別 (category_of_app) | category_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式技術 (technology_of_app) | technology_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式風險 (risk_of_app) | risk_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式特徵 (characteristic_of_app) | characteristic_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式容器 (container_of_app) | container_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式 SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 通道應用程式 (tunneled_app) | additional.fields.key 和 additional.fields.value.string_value | |||
| 流程類型 (flow_type) | additional.fields.key 和 additional.fields.value.string_value | |||
| 叢集名稱 (cluster_name) | intermediary.resource.name | |||
| 應用程式受制裁狀態 (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key 和 additional.fields.value.string_value |
流量
下表列出流量記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|
| 序號 (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| 類型 (型別) | type (Header) | cat/Type | metadata.product_event_type | |
| 威脅/內容類型 (子類型) | 子類型 (標題) | 子類型 | metadata.product_event_type | |
| 產生時間 (time_generated 或 cef-formatted-time_generated) | start | metadata.event_timestamp | ||
| 來源地址 (src) | src | src | principal.ip | |
| 目的地地址 (dst) | dst | dst | target.ip | |
| NAT 來源 IP (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| 網路位址轉譯 (NAT) 目的地 IP (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| 規則名稱 (規則) | cs1 | RuleName | security_result.rule_name | |
| 來源使用者 (srcuser) | suser | SourceUser | principal.user.userid | |
| 目的地使用者 (dstuser) | duser | DestinationUser | target.user.userid | |
| 應用程式 (app) | 應用程式 | 應用程式 | target.application | |
| 虛擬系統 (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| 來源區域 (從) | cs4 | SourceZone | 從 | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 目的地可用區 (至) | cs5 | DestinationZone | 到 | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 傳入介面 (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 傳出介面 (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 記錄動作 (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key 和 additional.fields.value.string_value |
| 工作階段 ID (sessionid) | cn1 | SessionID | network.session_id | |
| 重複次數 (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key 和 additional.fields.value.string_value |
| 來源通訊埠 (sport) | spt | srcPort | principal.port | |
| 目的地通訊埠 (dport) | dpt | dstPort | target.port | |
| NAT 來源通訊埠 (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| NAT 目的地通訊埠 (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| 旗標 (flags) | flexString1 | 旗標 | flags | additional.fields.key 和 additional.fields.value.string_value |
| IP 通訊協定 (proto) | proto | proto | network.ip_protocol | |
| 動作 (action) | act | action | security_result.action_details
security_result.action |
|
| 位元組 (位元組) | flexNumber1 | totalBytes | 位元組 | additional.fields.key 和 additional.fields.value.string_value |
| 傳送的位元組 (bytes_sent) | in | srcBytes | network.sent_bytes | |
| 收到的位元組 (bytes_received) | out | dstBytes | network.received_bytes | |
| 封包 (封包) | cn2 | totalPackets | 封包 | additional.fields.key 和 additional.fields.value.string_value |
| 開始時間 (開始) | StartTime | start | additional.fields.key 和 additional.fields.value.string_value | |
| 經過時間 (elapsed) | cn3 | ElapsedTime | 經過時間 | network.session_duration.seconds |
| 類別 (類別) | cs2 | URLCategory | security_result.category / security_result.category_details | |
| 序號 (seqno) | externalId | sequence | metadata.product_log_id | |
| 動作旗標 (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value |
| 來源國家/地區 (srcloc) | SourceLocation | principal.location.country_or_region | ||
| 目的地國家/地區 (dstloc) | DestinationLocation | target.location.country_or_region | ||
| 傳送的封包數 (pkts_sent) | PanOSPacketsSent | srcPackets | pkts_sent | network.sent_packets |
| 接收的封包數 (pkts_received) | PanOSPacketsReceived | dstPackets | pkts_received | network.received_packets |
| 工作階段結束原因 (session_end_reason) | 原因 | SessionEndReason | security_result.summary | |
| 裝置群組階層 1 (dg_hier_level_1 至 dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 2 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 3 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value |
| 虛擬系統名稱 (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| 裝置名稱 (device_name) | dvchost | DeviceName | intermediary.hostname | |
| 動作來源 (action_source) | cat | ActionSource | action_source | additional.fields.key 和 additional.fields.value.string_value |
| 來源 VM UUID (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id | |
| 目的地 VM UUID (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id | |
| 通道 ID/IMSI (tunnelid/imsi) | PanOSTunnelID | TunnelID | tunnelid/imsi | additional.fields.key 和 additional.fields.value.string_value |
| 監控標籤/IMEI (monitortag/imei) | PanOSMonitorTag | MonitorTag | monitortag/imei | additional.fields.key 和 additional.fields.value.string_value |
| 父項工作階段 ID (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| 父項開始時間 (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key 和 additional.fields.value.string_value |
| 通道類型 (通道) | PanOSTunnelType | TunnelType | 通道 | additional.fields.key 和 additional.fields.value.string_value |
| SCTP 關聯 ID (assoc_id) | PanOSSCTPAssocID | assoc_id | additional.fields.key 和 additional.fields.value.string_value | |
| SCTP 區塊 (區塊) | PanOSSCTPChunks | chunks | additional.fields.key 和 additional.fields.value.string_value | |
| 傳送的 SCTP 區塊 (chunks_sent) | PanOSSCTPChunkSent | chunks_sent | additional.fields.key 和 additional.fields.value.string_value | |
| 收到的 SCTP 區塊 (chunks_received) | PanOSSCTPChunksRcv | chunks_received | additional.fields.key 和 additional.fields.value.string_value | |
| 規則 UUID (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| HTTP/2 連線 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| 應用程式拍動次數 (link_change_count) | PanLinkChange | link_change_count | additional.fields.key 和 additional.fields.value.string_value | |
| 政策 ID (policy_id) | PanPolicyID | policy_id | additional.fields.key 和 additional.fields.value.string_value | |
| 連結開關 (link_switches) | PanLinkDetail | link_switches | additional.fields.key 和 additional.fields.value.string_value | |
| SD-WAN 叢集 (sdwan_cluster) | PanSDWANCluster | sdwan_cluster | additional.fields.key 和 additional.fields.value.string_value | |
| SD-WAN 裝置類型 (sdwan_device_type) | PanSDWANDevice | sdwan_device_type | additional.fields.key 和 additional.fields.value.string_value | |
| SD-WAN 叢集類型 (sdwan_cluster_type) | PanSDWANClustype | sdwan_cluster_type | additional.fields.key 和 additional.fields.value.string_value | |
| SD-WAN 網站 (sdwan_site) | PanSDWANSite | sdwan_site | additional.fields.key 和 additional.fields.value.string_value | |
| 動態使用者群組名稱 (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | additional.fields.key 和 additional.fields.value.string_value | |
| XFF 位址 (xff_ip) | PanXFFIP | principal.ip | ||
| 來源裝置類別 (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| 來源裝置設定檔 (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
|
| 來源裝置型號 (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| 來源裝置供應商 (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| 來源裝置 OS 系列 (src_osfamily) | PanSrcDeviceOS | principal.platform | ||
| 來源裝置 OS 版本 (src_osversion) | PanSrcDeviceOSv | principal.asset.software.version | ||
| 來源主機名稱 (src_host) | PanSrcHostname | principal.hostname | ||
| 來源 MAC 位址 (src_mac) | PanSrcMac | principal.mac | ||
| 目的地裝置類別 (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| 目的地裝置設定檔 (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
|
| 目的地裝置型號 (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| 目的地裝置供應商 (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| 目的地裝置 OS 系列 (dst_osfamily) | PanDstDeviceOS | dst_osfamily | target.platform | |
| 目的地裝置 OS 版本 (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| 目的地主機名稱 (dst_host) | PanDstHostname | target.hostname | ||
| 目的地 MAC 位址 (dst_mac) | PanDstMac | target.mac | ||
| 容器 ID (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| POD 命名空間 (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| POD 名稱 (pod_name) | PanPODName | pod_name | target.resource.name | |
| 來源外部動態清單 (src_edl) | PanSrcEDL | src_edl | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
|
| 目標外部動態清單 (dst_edl) | PanDstEDL | dst_edl | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
|
| 主機 ID (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| 使用者裝置序號 (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| 來源動態位址群組 (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| 目的地動態地址群組 (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| 工作階段擁有者 (session_owner) | PanHASessionOwner | session_owner | additional.fields.key 和 additional.fields.value.string_value | |
| 高解析度時間戳記 (high_res_timestamp) | PanTimeHighRes | additional.fields.key 和 additional.fields.value.string_value | ||
| 切片服務類型 (nsdsai_sst) | PanASServiceType | nsdsai_sst | additional.fields.key 和 additional.fields.value.string_value | |
| Slice 差異化指標 (nsdsai_sd) | PanASServiceDiff | nsdsai_sd | additional.fields.key 和 additional.fields.value.string_value | |
| 應用程式子類別 (subcategory_of_app) | subcategory_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式類別 (category_of_app) | category_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式技術 (technology_of_app) | technology_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式風險 (risk_of_app) | security_result.severity | |||
| 應用程式特徵 (characteristic_of_app) | characteristic_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式容器 (container_of_app) | container_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式 SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式受制裁狀態 (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式子類別 (subcategory_of_app) | subcategory_of_app1 | additional.fields.key 和 additional.fields.value.string_value | ||
| 嚴重性 (嚴重性) | number-of-severity(header) | security_result.severity 和 security_result.severity_details |
User-ID
下表列出使用者 ID 記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|
| 序號 (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| 類型 (型別) | type (Header) | cat | metadata.product_event_type | |
| 威脅/內容類型 (子類型) | 子類型 (標題) | 子類型 | metadata.product_event_type | |
| 產生時間 (time_generated 或 cef-formatted-time_generated) | metadata.event_timestamp | |||
| 虛擬系統 (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| 來源 IP (ip) | src | src | principal.ip | |
| 使用者 (使用者) | duser | usrName | target.user.userid
target.administrative_domain target.user.email_addresses |
|
| 資料來源名稱 (datasourcename) | cs4 | DataSourceName | datasourcename | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 事件 ID (eventid) | EventID | eventid | additional.fields.key 和 additional.fields.value.string_value | |
| 重複次數 (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key 和 additional.fields.value.string_value |
| 逾時門檻 (逾時) | cn3 | TimeoutThreshold | 逾時 | additional.fields.key 和 additional.fields.value.string_value |
| 來源通訊埠 (beginport) | spt | srcPort | principal.port | |
| 目的地通訊埠 (endport) | dpt | dstPort | target.port | |
| 資料來源 (datasource) | cs5 | DataSource | 資料來源 | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 資料來源類型 (datasourcetype) | cs6 | DataSourceType | datasourcetype | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 序號 (seqno) | externalId | sequence | metadata.product_log_id | |
| 動作旗標 (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value |
| 虛擬系統名稱 (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| 裝置名稱 (device_name) | dvchost | DeviceName | intermediary.hostname | |
| 虛擬系統 ID (vsys_id) | cn2 | VirtualSystemID | intermediary.resource.product_object_id | |
| 因素類型 (factortype) | cs1 | FactorType | factortype | additional.fields.key 和 additional.fields.value.string_value |
| 因子完成時間 (factorcompletiontime) | end | FactorCompletionTime | factorcompletiontime | additional.fields.key 和 additional.fields.value.string_value |
| 因素編號 (factorno) | cn1 | FactorNumber | factorno | additional.fields.key 和 additional.fields.value.string_value |
| 使用者群組標記 (ugflags) | PanOSUGFlags | ugflags | additional.fields.key 和 additional.fields.value.string_value | |
| 使用者 (按來源區隔) (userbysource) | PanOSUserBySource | target.user.userid
target.administrative_domain target.user.email_addresses |
||
| 高解析度時間戳記 (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key 和 additional.fields.value.string_value | ||
| 原始資料來源 (origindatasource) | additional.fields.key 和 additional.fields.value.string_value | |||
| 叢集名稱 (cluster_name) | principal.resource.name | |||
| 嚴重性 (嚴重性) | number-of-severity(header) | security_result.severity 和 security_result.severity_details |
HIP 比對
下表列出 HIP 比對記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|
| 序號 (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| 類型 (型別) | type (Header) | cat | metadata.product_event_type | |
| 威脅/內容類型 (子類型) | 子類型 (標題) | 子類型 | ||
| 產生時間 (time_generated 或 cef-formatted-time_generated) | start | startTime | metadata.event_timestamp | |
| 來源使用者 (srcuser) | suser | usrName | principal.user.userid | |
| 虛擬系統 (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| 電腦名稱 (machinename) | shost | identHostName | principal.hostname | |
| 作業系統 (os) | cs2 | 作業系統 | principal.asset.platform_software.platform | |
| 來源地址 (src) | src | identsrc | principal.ip | |
| HIP (matchname) | cat | HIP | matchname | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 重複次數 (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key 和 additional.fields.value.string_value |
| HIP 類型 (比對類型) | 裝置事件類別 ID (標頭) | HIPType | matchtype | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
| 序號 (seqno) | externalId | sequence | metadata.product_log_id | |
| 動作旗標 (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value |
| 虛擬系統名稱 (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| 裝置名稱 (device_name) | dvchost | DeviceName | target.hostname | |
| 虛擬系統 ID (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id | |
| IPv6 系統位址 (srcipv6) | c6a2 | srcipv6 | principal.asset.ip | |
| 主機 ID (hostid) | PanOSHostID | principal.asset.asset_id | ||
| 使用者裝置序號 (serialnumber) | PanOSEndpointSerialNumber | principal.asset.hardware.serial_number | ||
| 裝置 MAC 位址 (mac) | PanOSEndpointMac | principal.asset.mac | ||
| 高解析度時間戳記 (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key 和 additional.fields.value.string_value | ||
| 叢集名稱 (cluster_name) | principal.resource.name | |||
| 嚴重性 (嚴重性) | number-of-severity(header) | security_result.severity 和 security_result.severity_details |
IP 標記
下表列出 IP 標記記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|
| 序號 (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| 類型 (型別) | type (Header) | cat | metadata.product_event_type | |
| 威脅/內容類型 (子類型) | 子類型 (標題) | 子類型 | metadata.product_event_type | |
| 產生時間 (time_generated 或 cef-formatted-time_generated) | GenerateTime | metadata.event_timestamp | ||
| 虛擬系統 (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| 來源 IP (ip) | src | src | principal.ip | |
| 代碼名稱 (tag_name) | PanOSTagName | TagName | tag_name | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 活動 ID (event_id) | PanOSEventID | EventID | event_id | additional.fields.key 和 additional.fields.value.string_value |
| 重複次數 (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key 和 additional.fields.value.string_value |
| 逾時 (逾時) | PanOSTimeout | TimeoutThreshold | 逾時 | additional.fields.key 和 additional.fields.value.string_value |
| 資料來源名稱 (datasourcename) | PanOSDataSourceName | DataSourceName | datasourcename | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 資料來源類型 (datasource_type) | PanOSDataSourceType | DataSource | datasource_type | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 資料來源子類型 (datasource_subtype) | PanOSDataSourceSubType | DataSourceType | datasource_subtype | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 序號 (seqno) | externalId | sequence | metadata.product_log_id | |
| 動作旗標 (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value |
| 虛擬系統名稱 (vsys_name) | PanOsVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| 裝置名稱 (device_name) | dvchost | DeviceName | target.hostname | |
| 虛擬系統 ID (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id | |
| 高解析度時間戳記 (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key 和 additional.fields.value.string_value | ||
| 嚴重性 (嚴重性) | number-of-severity(header) | security_result.severity 和 security_result.severity_details | ||
| 叢集名稱 (cluster_name) | principal.resource.name |
解密
下表列出解密記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | rt | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
||
| 序號 (serial) | PanOSDeviceSN | intermediary.asset.hardware.serial_number | ||
| 類型 (型別) | type (Header) | metadata.product_event_type | ||
| 威脅/內容類型 (子類型) | 子類型 (標題) | metadata.product_event_type | ||
| 設定版本 (config_ver) | PanOSConfigVersion | config_ver | additional.fields.key 和 additional.fields.value.string_value | |
| 生成時間 (time_generated) | PanOSLogTimeStamp | metadata.event_timestamp | ||
| 來源地址 (src) | src | principal.ip | ||
| 目的地地址 (dst) | dst | target.ip | ||
| NAT 來源 IP (natsrc) | sourceTranslatedAddress | principa.nat_ip | ||
| 網路位址轉譯 (NAT) 目的地 IP (natdst) | destinationTranslatedAddress | target.nat_ip | ||
| 規則 (規則) | cs1 | security_result.rule_name | ||
| 來源使用者 (srcuser) | suser | principal.user.userid | ||
| 目的地使用者 (dstuser) | duser | target.user.userid | ||
| 應用程式 (app) | 應用程式 | network.application_protocol | ||
| 虛擬系統 (vsys) | cs3 | vsys | intermediary.asset.attribute.labels.key/value | |
| 來源區域 (從) | cs4 | 從 | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
|
| 目的地可用區 (至) | cs5 | 到 | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
|
| 傳入介面 (inbound_if) | deviceInboundInterface | inbound_if | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
|
| 傳出介面 (outbound_if) | deviceOutboundInterface | outbound_if | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
|
| 記錄動作 (logset) | cs6 | logset | additional.fields.key 和 additional.fields.value.string_value | |
| 記錄時間 (time_received) | PanOSTimeReceivedManagementPlane | - | ||
| 工作階段 ID (sessionid) | cn1 | network.session_id | ||
| 重複次數 (repeatcnt) | PanOSCountOfRepeats/RepeatCount | repeatcnt | additional.fields.key 和 additional.fields.value.string_value | |
| 來源通訊埠 (sport) | spt | principal.port | ||
| 目的地通訊埠 (dport) | dpt | target.port | ||
| NAT 來源通訊埠 (natsport) | sourceTranslatedPort | principal.nat_port | ||
| NAT 目的地通訊埠 (natdport) | destinationTranslatedPort | target.nat_port | ||
| 旗標 (flags) | flexString1 | flags | additional.fields.key 和 additional.fields.value.string_value | |
| IP 通訊協定 (proto) | proto | network.ip_protocol | ||
| 動作 (action) | act | security_result.action_details
security_result.action |
||
| 隧道 (tunnel) | PanOSTunnel | 通道 | additional.fields.key 和 additional.fields.value.string_value | |
| 來源 VM UUID (src_uuid) | PanOSSourceUUID | principal.asset.product_object_id | ||
| 目的地 VM UUID (dst_uuid) | PanOSDestinationUUID | target.asset.product_object_id | ||
| 規則的 UUID (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| 從用戶端到防火牆的階段 (hs_stage_c2f) | PanOSClientToFirewall | hs_stage_c2f | additional.fields.key 和 additional.fields.value.string_value | |
| 防火牆到伺服器階段 (hs_stage_f2s) | PanOSFirewallToServer | hs_stage_f2s | additional.fields.key 和 additional.fields.value.string_value | |
| TLS 版本 (tls_version) | PanOSTLSVersion | network.tls.version | ||
| 金鑰交換演算法 (tls_keyxchg) | PanOSTLSKeyExchange | tls_keyxchg | additional.fields.key 和 additional.fields.value.string_value | |
| 加密演算法 (tls_enc) | PanOSTLSEncryptionAlgorithm | tls_enc | additional.fields.key 和 additional.fields.value.string_value | |
| 雜湊演算法 (tls_auth) | PanOSTLSAuth | tls_auth | additional.fields.key 和 additional.fields.value.string_value | |
| 政策名稱 (policy_name) | PanOSPolicyName | policy_name | additional.fields.key 和 additional.fields.value.string_value | |
| 橢圓曲線 (ec_curve) | PanOSEllipticCurve | network.tls.curve | ||
| 錯誤索引 (err_index) | PanOSErrorIndex | err_index | additional.fields.key 和 additional.fields.value.string_value | |
| 根狀態 (root_status) | PanOSRootStatus | root_status | additional.fields.key 和 additional.fields.value.string_value | |
| 鏈結狀態 (chain_status) | PanOSChainStatus | chain_status | additional.fields.key 和 additional.fields.value.string_value | |
| Proxy 類型 (proxy_type) | PanOSProxyType | proxy_type | additional.fields.key 和 additional.fields.value.string_value | |
| 憑證序號 (cert_serial) | PanOSCertificateSerial | network.tls.server.certificate.serial | ||
| 憑證指紋 (指紋) | PanOSFingerprint | network.tls.server.certificate.md5/sha1/sha256 | ||
| 憑證開始日期 (notbefore) | PanOSTimeNotBefore | network.tls.server.certificate.not_before | ||
| 憑證結束日期 (notafter) | PanOSTimeNotAfter | network.tls.server.certificate.not_after | ||
| 憑證版本 (cert_ver) | PanOSCertificateVersion | network.tls.server.certificate.version | ||
| 憑證大小 (cert_size) | PanOSCertificateSize | cert_size | additional.fields.key 和 additional.fields.value.string_value | |
| 一般名稱長度 (cn_len) | PanOSCommonNameLength | cn_len | additional.fields.key 和 additional.fields.value.string_value | |
| 核發者通用名稱長度 (issuer_len) | PanOSIssuerNameLength | issuer_len | additional.fields.key 和 additional.fields.value.string_value | |
| 根一般名稱長度 (rootcn_len) | PanOSRootCNLength | rootcn_len | additional.fields.key 和 additional.fields.value.string_value | |
| SNI 長度 (sni_len) | PanOSSNILength | sni_len | additional.fields.key 和 additional.fields.value.string_value | |
| 憑證標記 (cert_flags) | PanOSCertificateFlags | cert_flags | additional.fields.key 和 additional.fields.value.string_value | |
| 主體通用名稱 (cn) | PanOSCommonName | cn | additional.fields.key 和 additional.fields.value.string_value | |
| 核發者通用名稱 (issuer_cn) | PanOSIssuerCommonName | network.tls.server.certificate.issuer | ||
| 根層級通用名稱 (root_cn) | PanOSRootCommonName | root_cn | additional.fields.key 和 additional.fields.value.string_value | |
| 伺服器名稱指示 (sni) |
network.tls.client.server_name | |||
| 錯誤 (錯誤) | PanOSErrorMessage | error | additional.fields.key 和 additional.fields.value.string_value | |
| 容器 ID (container_id) | PanOSContainerID | container_id | intermediary.resource.product_object_id | |
| POD 命名空間 (pod_namespace) | PanOSContainerNameSpace | pod_namespace | target.resource.attribute.labels.key/value additional.fields.key 和 additional.fields.value.string_value |
|
| POD 名稱 (pod_name) | PanOSContainerName | pod_name | target.resource.name | |
| 來源外部動態清單 (src_edl) | PanOSSourceEDL | src_edl | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
|
| 目標外部動態清單 (dst_edl) | PanOSDestinationEDL | dst_edl | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
|
| 來源動態位址群組 (src_dag) | PanOSSourceDynamicAddressGroup | principal.group.group_display_name | ||
| 目的地動態地址群組 (dst_dag) | PanOSDestinationDynamicAddressGroup | target.group.group_display_name | ||
| 高解析度時間戳記 (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key 和 additional.fields.value.string_value | ||
| 來源裝置類別 (src_category) | PanOSSourceDeviceCategory | src_category | principal.asset.category | |
| 來源裝置設定檔 (src_profile) | PanOSSourceDeviceProfile | src_profile | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
|
| 來源裝置型號 (src_model) | PanOSSourceDeviceModel | src_model | principal.asset.hardware.model | |
| 來源裝置供應商 (src_vendor) | PanOSSourceDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| 來源裝置 OS 系列 (src_osfamily) | PanOSSourceDeviceOSFamily | principal.platform | ||
| 來源裝置 OS 版本 (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | ||
| 來源主機名稱 (src_host) | PanOSSourceDeviceHost | principal.hostname | ||
| 來源 MAC 位址 (src_mac) | PanOSSourceDeviceMac | principal.mac | ||
| 目的地裝置類別 (dst_category) | PanOSDestinationDeviceCategory | dst_category | target.asset.category | |
| 目的地裝置設定檔 (dst_profile) | PanOSDestinationDeviceProfile | dst_profile | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
|
| 目的地裝置型號 (dst_model) | PanOSDestinationDeviceModel | dst_model | target.asset.hardware.model | |
| 目的地裝置供應商 (dst_vendor) | PanOSDestinationDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| 目的地裝置 OS 系列 (dst_osfamily) | PanOSDestinationDeviceOSFamily | dst_osfamily | target.platform | |
| 目的地裝置 OS 版本 (dst_osversion) | PanOSDestinationDeviceOSVersion | target.platform_version | ||
| 目的地主機名稱 (dst_host) | PanOSDestinationDeviceHost | target.hostname | ||
| 目的地 MAC 位址 (dst_mac) | PanOSDestinationDeviceMac | target.mac | ||
| 序號 (seqno) | PanOSLogTypeSeqNo | metadata.product_log_id | ||
| 動作旗標 (actionflags) | PanOSActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value | |
| 裝置群組階層 (dg_hier_level_1) | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value | |
| 裝置群組階層 (dg_hier_level_2) | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value | |
| 裝置群組階層 (dg_hier_level_3) | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value | |
| 裝置群組階層 (dg_hier_level_4) | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value | |
| 虛擬系統名稱 (vsys_name) | intermediary.asset.attribute.labels.key/value | |||
| 裝置名稱 (device_name) | intermediary.hostname | |||
| 虛擬系統 ID (vsys_id) | intermediary.resource.product_object_id | |||
| 應用程式子類別 (subcategory_of_app) | subcategory_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式類別 (category_of_app) | category_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式技術 (technology_of_app) | technology_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式風險 (risk_of_app) | security_result.severity | |||
| 應用程式特徵 (characteristic_of_app) | characteristic_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式容器 (container_of_app) | container_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式 SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式受制裁狀態 (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 嚴重性 (嚴重性) | number-of-severity(header) | security_result.severity 和 security_result.severity_details |
隧道
下表列出通道記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|
| 序號 (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| 類型 (型別) | type (Header) | cat | metadata.product_event_type | |
| 威脅/內容類型 (子類型) | 子類型 (標題) | 子類型 | metadata.product_event_type | |
| 產生時間 (time_generated 或 cef-formatted-time_generated) | metadata.event_timestamp | |||
| 來源地址 (src) | src | src | principal.ip | |
| 目的地地址 (dst) | dst | dst | target.ip | |
| NAT 來源 IP (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| 網路位址轉譯 (NAT) 目的地 IP (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| 規則名稱 (規則) | cs1 | RuleName | security_result.rule_name | |
| 來源使用者 (srcuser) | suser | SourceUser / usrName | principal.user.userid | |
| 目的地使用者 (dstuser) | duser | DestinationUser | target.user.userid | |
| 應用程式 (app) | 應用程式 | 應用程式 | network.application_protocol | |
| 虛擬系統 (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| 來源區域 (從) | cs4 | SourceZone | 從 | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 目的地可用區 (至) | cs5 | DestinationZone | 到 | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 傳入介面 (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 傳出介面 (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 記錄動作 (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key 和 additional.fields.value.string_value |
| 工作階段 ID (sessionid) | cn1 | SessionID | network.session_id | |
| 重複次數 (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key 和 additional.fields.value.string_value |
| 來源通訊埠 (sport) | spt | srcPort | principal.port | |
| 目的地通訊埠 (dport) | dpt | dstPort | target.port | |
| NAT 來源通訊埠 (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| NAT 目的地通訊埠 (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| 旗標 (flags) | flexString1 | 旗標 | flags | additional.fields.key 和 additional.fields.value.string_value |
| IP 通訊協定 (proto) | proto | proto | network.ip_protocol | |
| 動作 (action) | act | action | security_result.action_details
security_result.action |
|
| 嚴重性 (嚴重性) | number-of-severity(header) | security_result.severity 和 security_result.severity_details | ||
| 序號 (seqno) | externalId | sequence | metadata.product_log_id | |
| 動作旗標 (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value |
| 來源位置 (srcloc) | principal.location.country_or_region | |||
| 目的地位置 (dstloc) | target.location.country_or_region | |||
| 裝置群組階層 (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value |
| 虛擬系統名稱 (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| 裝置名稱 (device_name) | dvchost | DeviceName | intermediary.hostname | |
| 通道 ID (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key 和 additional.fields.value.string_value |
| 監控標記 (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key 和 additional.fields.value.string_value |
| 父項工作階段 ID (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| 父項開始時間 (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key 和 additional.fields.value.string_value |
| 通道類型 (通道) | cs2 | TunnelType | 通道 | additional.fields.key 和 additional.fields.value.string_value |
| 位元組 (位元組) | flexNumber1 | totalBytes | 位元組 | additional.fields.key 和 additional.fields.value.string_value |
| 傳送的位元組 (bytes_sent) | in | srcBytes | network.sent_bytes | |
| 收到的位元組 (bytes_received) | out | dstBytes | network.received_bytes | |
| 封包 (封包) | cn2 | totalPackets | 封包 | additional.fields.key 和 additional.fields.value.string_value |
| 傳送的封包數 (pkts_sent) | PanOSPacketsSent | srcPackets | pkts_sent | network.sent_packets |
| 接收的封包數 (pkts_received) | PanOSPacketsReceived | dstPackets | pkts_received | network.received_packets |
| 最大封裝 (max_encap) | flexNumber2 | MaximumEncapsulation | max_encap | additional.fields.key 和 additional.fields.value.string_value |
| 不明通訊協定 (unknown_proto) | cfp1 | UnknownProtocol | unknown_proto | additional.fields.key 和 additional.fields.value.string_value |
| 嚴格檢查 (strict_check) | cfp2 | StrictChecking | strict_check | additional.fields.key 和 additional.fields.value.string_value |
| 隧道片段 (tunnel_fragment) | PanOSTunnelFragment | TunnelFragment | tunnel_fragment | additional.fields.key 和 additional.fields.value.string_value |
| 建立的工作階段 (sessions_created) | cfp3 | SessionsCreated | sessions_created | additional.fields.key 和 additional.fields.value.string_value |
| 已關閉的工作階段 (sessions_closed) | cfp4 | SessionsClosed | sessions_closed | additional.fields.key 和 additional.fields.value.string_value |
| 工作階段結束原因 (session_end_reason) | 原因 | SessionEndReason | security_result.summary | |
| 動作來源 (action_source) | cat | ActionSource | action_source | additional.fields.key 和 additional.fields.value.string_value |
| 開始時間 (開始) | startTime | start | additional.fields.key 和 additional.fields.value.string_value | |
| 經過時間 (elapsed) | cn3 | ElapsedTime | 經過時間 | network.session_duration.seconds |
| 通道檢查規則 (tunnel_insp_rule) | PanOSTunneInspectionRule | security_result.rule_name = "Tunnel Inspection Rule: %{PanOSTunnelInspectionRule}" | ||
| 遠端使用者 IP (remote_user_ip) | PanOSRmtUserIP | principal.ip | ||
| 遠端使用者 ID (remote_user_id) | PanOSRmtUserID | remote_user_id | principal.user.userid | |
| 安全性規則 UUID (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| PCAP ID (pcap_id) | PanOSPcapID | pcap_id | additional.fields.key 和 additional.fields.value.string_value | |
| 動態使用者群組名稱 (dynusergroup_name) | PanDynamicUsrgrp | principal.group.group_display_name | ||
| 來源外部動態清單 (src_edl) | PanOSSourceEDL | src_edl | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
|
| 目標外部動態清單 (dst_edl) | PanOSDestinationEDL | dst_edl | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
|
| 高解析度時間戳記 (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key 和 additional.fields.value.string_value | ||
| 配量鑑別器 (nssai_sd) | nssai_sd | additional.fields.key 和 additional.fields.value.string_value | ||
| 切片服務類型 (nssai_sd) | nssai_sd1 | additional.fields.key 和 additional.fields.value.string_value | ||
| PDU 工作階段 ID (pdu_session_id) | pdu_session_id | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式子類別 (subcategory_of_app) | subcategory_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式類別 (category_of_app) | category_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式技術 (technology_of_app) | technology_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式風險 (risk_of_app) | risk_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式特徵 (characteristic_of_app) | characteristic_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式容器 (container_of_app) | container_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式 SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 通道應用程式 (tunneled_app) | additional.fields.key 和 additional.fields.value.string_value | |||
| 已卸載 (已卸載) | additional.fields.key 和 additional.fields.value.string_value | |||
| 流程類型 (flow_type) | additional.fields.key 和 additional.fields.value.string_value | |||
| 叢集名稱 (cluster_name) |
principal.resource.name |
|||
| 應用程式受制裁狀態 (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key 和 additional.fields.value.string_value |
驗證
下表列出驗證記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|
| 序號 (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| 類型 (型別) | type (Header) | cat | metadata.product_event_type | |
| 威脅/內容類型 (子類型) | 子類型 (標題) | 子類型 | metadata.product_event_type | |
| 產生時間 (time_generated 或 cef-formatted-time_generated) | metadata.event_timestamp | |||
| 虛擬系統 (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| 來源 IP (ip) | src | src | principal.ip | |
| 使用者 (使用者) | duser | usrName | target.user.userid | |
| Normalize User (normalize_user) | cs2 | NormalizeUser | target.user.user_display_name | |
| 物件 (object) | fname | ObjectName | object | target.resource.name |
| 驗證政策 (authpolicy) | cs4 | AuthPolicy | authpolicy | additional.fields.key 和 additional.fields.value.string_value |
| 重複次數 (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key 和 additional.fields.value.string_value |
| 驗證 ID (authid) | cn2 | AuthenticationID | authid | additional.fields.key 和 additional.fields.value.string_value |
| 供應商 (供應商) | flexString2 | 供應商 | 供應商 | additional.fields.key 和 additional.fields.value.string_value |
| 記錄動作 (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key 和 additional.fields.value.string_value |
| 伺服器設定檔 (serverprofile) | cs1 | ServerProfile | serverprofile | additional.fields.key 和 additional.fields.value.string_value |
| 說明 (desc) | PanOSDesc | AdditionalAuthInfo | security_result.description | |
| 用戶端類型 (clienttype) | cs5 | ClientType | clienttype | additional.fields.key 和 additional.fields.value.string_value |
| 事件類型 (事件) | msg | msg | extensions.auth.auth_details | |
| 因素編號 (factorno) | cn1 | FactorNumber | factorno | additional.fields.key 和 additional.fields.value.string_value |
| 序號 (seqno) | externalId | sequence | metadata.product_log_id | |
| 動作旗標 (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value |
| 裝置群組階層 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value |
| 虛擬系統名稱 (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| 裝置名稱 (device_name) | dvchost | DeviceName | intermediary.hostname | |
| 虛擬系統 ID (vsys_id) | intermediary.resource.product_object_id | |||
| 驗證通訊協定 (authproto) | authproto | additional.fields.key 和 additional.fields.value.string_value | ||
| 規則的 UUID (rule_uuid) | PanOSRuleUUID/RuleUUID | security_result.rule_id | ||
| 高解析度時間戳記 (high_res _timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key 和 additional.fields.value.string_value | ||
| 來源裝置類別 (src_category) | PanOSSourceDeviceCategory | src_category | principal.asset.category | |
| 來源裝置設定檔 (src_profile) | PanOSSourceDeviceProfile | src_profile | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
|
| 來源裝置型號 (src_model) | PanOSSourceDeviceModel | src_model | principal.asset.hardware.model | |
| 來源裝置供應商 (src_vendor) | PanOSSourceDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| 來源裝置 OS 系列 (src_osfamily) | PanOSSourceDeviceOSFamily | principal.asset.platform_software.platform principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
||
| 來源裝置 OS 版本 (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | ||
| 來源主機名稱 (src_host) | PanOSSourceHostname | principal.hostname | ||
| 來源 MAC 位址 (src_mac) | PanOSSourceMac | principal.asset.mac | ||
| 區域 (區域) | PanOSTrafficOriginRegion | principal.location.country_or_region | ||
| 使用者代理程式 (user_agent) | PanOSHTTPUserAgent | network.http.user_agent | ||
| 工作階段 ID(sessionid) | PanOSTrafficSessionID | network.session_id | ||
| 嚴重性 (嚴重性) | number-of-severity(header) | security_result.severity 和 security_result.severity_details | ||
| 叢集名稱 (cluster_name) | principal.resource.name |
網址
下表列出網址記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (cef 格式的 receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|
| 序號 (序號) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| 類型 (型別) | type (Header) | cat | metadata.product_event_type | |
| 威脅/內容類型 (子類型) | 子類型 (標題) | 子類型 | metadata.product_event_type | |
| 生成時間 | metadata.event_timestamp | |||
| 來源地址 (src) | src | src | principal.ip | |
| 目的地地址 (dst) | dst | dst | target.ip | |
| NAT 來源 IP (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| 網路位址轉譯 (NAT) 目的地 IP (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| 規則 (規則) | cs1 | RuleName | security_result.rule_name | |
| 來源使用者 (srcuser) | suser | SourceUser | principal.user.userid | |
| 目的地使用者 (dstuser) | duser | DestinationUser | target.user.userid | |
| 應用程式 (app) | 應用程式 | 應用程式 | network.application_protocol | |
| 虛擬系統 (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| 來源區域 (從) | cs4 | SourceZone | 從 | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 目的地可用區 (至) | cs5 | DestinationZone | 到 | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 傳入介面 (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 傳出介面 (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 記錄動作 (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key 和 additional.fields.value.string_value |
| 記錄時間 | time_logged | additional.fields.key 和 additional.fields.value.string_value | ||
| 工作階段 ID (sessionid) | cn1 | SessionID | network.session_id | |
| 重複次數 (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key 和 additional.fields.value.string_value |
| 來源通訊埠 (sport) | spt | srcPort | principal.port | |
| 目的地通訊埠 (dport) | dpt | dstPort | target.port | |
| NAT 來源通訊埠 (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| NAT 目的地通訊埠 (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| 旗標 (flags) | flexString1 | 旗標 | flags | additional.fields.key 和 additional.fields.value.string_value |
| IP 通訊協定 (proto) | proto | proto | network.ip_protocol | |
| 動作 (action) | act | action | security_result.action_details
security_result.action |
|
| 網址/檔案名稱 (其他) | 其他 | target.file.names
target.url |
||
| 威脅/內容名稱 (threatid) | cat | ThreatID | security_result.threat_id | |
| 類別 (類別) | cs2 | URLCategory | 類別 | security_result.category_details |
| 嚴重性 (嚴重性) | number-of-severity (標頭) | 嚴重性 | security_result.severity
security_result.severity_details |
|
| 方向 (方向) | flexString2 | 方向 | network.direction | |
| 序號 (seqno) | externalId | sequence | metadata.product_log_id | |
| 動作旗標 (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value |
| 來源國家/地區 (srcloc) | SourceLocation | principal.location.country_or_region | ||
| 目的地國家/地區 (dstloc) | DestinationLocation | target.location.country_or_region | ||
| contenttype (contenttype) | requestContext | ContentType | contenttype | additional.fields.key 和 additional.fields.value.string_value |
| pcap_id (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key 和 additional.fields.value.string_value |
| filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | ||
| cloud (cloud) | Cloud | 雲端 | additional.fields.key 和 additional.fields.value.string_value | |
| url_idx (url_idx) | URLIndex | url_idx | additional.fields.key 和 additional.fields.value.string_value | |
| user_agent (user_agent) | requestClientApplication | UserAgent | network.http.user_agent | |
| 檔案類型 (filetype) | target.file.mime_type | |||
| xff (xff) | PanOSXForwarderfor | identSrc | xff | principal.ip |
| 參照網址 (referer) | PanOSReferer | 參照網址 | network.http.referral_url | |
| sender (sender) | network.email.from | |||
| 主旨 (主旨) | 主旨 | network.email.subject | ||
| 收件者 (recipient) | network.email.to | |||
| reportid (reportid) | reportid | additional.fields.key 和 additional.fields.value.string_value | ||
| DG Hierarchy Level 1 (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value |
| 需求開發廣告活動階層第 2 層 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value |
| 需求開發廣告活動階層第 3 層級 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value |
| 需求開發廣告活動階層第 4 層 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value |
| 虛擬系統名稱 (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| 裝置名稱 (device_name) | dvchost | DeviceName | intermediary.hostname | |
| file_url (file_url) | target.url | |||
| 來源 VM UUID (src_uuid) | SrcUUID | principal.asset.product_object_id | ||
| 目的地 VM UUID (dst_uuid) | DstUUID | target.asset.product_object_id | ||
| http_method (http_method) | requestMethod | RequestMethod | network.http.method | |
| 通道 ID/IMSI (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key 和 additional.fields.value.string_value |
| 監控器標籤/IMEI (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key 和 additional.fields.value.string_value |
| 父項工作階段 ID (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| 父項工作階段開始時間 (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key 和 additional.fields.value.string_value |
| 隧道 (tunnel) | PanOSTunnelType | TunnelType | 通道 | additional.fields.key 和 additional.fields.value.string_value |
| thr_category (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| contentver (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key 和 additional.fields.value.string_value |
| sig_flags (sig_flags) | sig_flags | additional.fields.key 和 additional.fields.value.string_value | ||
| SCTP 關聯 ID (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key 和 additional.fields.value.string_value | |
| 酬載通訊協定 ID (ppid) | PanOSPPID | ppid | additional.fields.key 和 additional.fields.value.string_value | |
| http_headers (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| 網址類別清單 (url_category_list) | PanOSURLCatList | url_category_list | additional.fields.key 和 additional.fields.value.string_value | |
| 規則的 UUID (rule_uuid) | PanOSRuleUUID | rule_uuid | security_result.rule_id | |
| HTTP/2 連線 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| dynusergroup_name (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | additional.fields.key 和 additional.fields.value.string_value | |
| XFF 位址 (xff_ip) | PanXFFIP | principal.ip | ||
| 來源裝置類別 (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| 來源裝置設定檔 (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
|
| 來源裝置型號 (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| 來源裝置供應商 (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| 來源裝置 OS 系列 (src_osfamily) | PanSrcDeviceOS | principal.platform | ||
| 來源裝置 OS 版本 (src_osversion) | PanSrcDeviceOSv | principal.platform_version | ||
| 來源主機名稱 (src_host) | PanSrcHostname | src_host | principal.hostname | |
| 來源 MAC 位址 (src_mac) | PanSrcMac | principal.mac | ||
| 目的地裝置類別 (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| 目的地裝置設定檔 (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
|
| 目的地裝置型號 (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| 目的地裝置供應商 (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| 目的地裝置 OS 系列 (dst_osfamily) | PanDstDeviceOS | target.platform | ||
| 目的地裝置 OS 版本 (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| 目的地主機名稱 (dst_host) | PanPODNamespace | target.hostname | ||
| 目的地 MAC 位址 (dst_mac) | PanDstMac | target.mac | ||
| 容器 ID (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| POD 命名空間 (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| POD 名稱 (pod_name) | PanPODName | pod_name | target.resource.name | |
| 來源外部動態清單 (src_edl) | PanSrcEDL | src_edl | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
|
| 目標外部動態清單 (dst_edl) | PanDstEDL | dst_edl | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
|
| 主機 ID (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| 序號 (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| domain_edl (domain_edl) | PanDomainEDL | domain_edl | additional.fields.key 和 additional.fields.value.string_value | |
| 來源動態位址群組 (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| 目的地動態地址群組 (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| partial_hash (partial_hash) | PanPartialHash | partial_hash | additional.fields.key 和 additional.fields.value.string_value | |
| 高解析度時間戳記 (high_res_timestamp) | PanTimeHighRes | additional.fields.key 和 additional.fields.value.string_value | ||
| 原因 (原因) | PanReasonFilteringAction | 原因 | security_result.summary | |
| 理由 (理由) | PanJustification | 理由 | additional.fields.key 和 additional.fields.value.string_value | |
| nssai_sst (nssai_sst) | PanASServiceType | nssai_sst | additional.fields.key 和 additional.fields.value.string_value | |
| 應用程式子類別 (subcategory_of_app) | subcategory_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式類別 (category_of_app) | category_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式技術 (technology_of_app) | technology_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式風險 (risk_of_app) | risk_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式特徵 (characteristic_of_app) | characteristic_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式容器 (container_of_app) | container_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 通道化應用程式 (tunneled_app) | tunneled_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式的軟體即服務 (is_saas_of_app) | is_saas_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式的受制裁狀態 (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 雲端報告 ID (cloud_reportid) | additional.fields.key 和 additional.fields.value.string_value | |||
| 叢集名稱 (cluster_name) |
principal.resource.name |
|||
| 流程類型 (flow_type) | additional.fields.key 和 additional.fields.value.string_value |
資料
下表列出資料記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (cef 格式的 receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|
| 序號 (序號) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| 類型 (型別) | type (Header) | cat | metadata.product_event_type | |
| 威脅/內容類型 (子類型) | 子類型 (標題) | 子類型 | metadata.product_event_type | |
| 生成時間 | metadata.event_timestamp | |||
| 來源地址 (src) | src | src | principal.ip | |
| 目的地地址 (dst) | dst | dst | target.ip | |
| NAT 來源 IP (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| 網路位址轉譯 (NAT) 目的地 IP (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| 規則 (規則) | cs1 | RuleName | security_result.rule_name | |
| 來源使用者 (srcuser) | suser | SourceUser | principal.user.userid | |
| 目的地使用者 (dstuser) | duser | DestinationUser | target.user.userid | |
| 應用程式 (app) | 應用程式 | 應用程式 | network.application_protocol | |
| 虛擬系統 (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| 來源區域 (從) | cs4 | SourceZone | 從 | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 目的地可用區 (至) | cs5 | DestinationZone | 到 | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 傳入介面 (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 傳出介面 (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
| 記錄動作 (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key 和 additional.fields.value.string_value |
| 記錄時間 | time_logged | additional.fields.key 和 additional.fields.value.string_value | ||
| 工作階段 ID (sessionid) | cn1 | SessionID | network.session_id | |
| 重複次數 (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key 和 additional.fields.value.string_value |
| 來源通訊埠 (sport) | spt | srcPort | principal.port | |
| 目的地通訊埠 (dport) | dpt | dstPort | target.port | |
| NAT 來源通訊埠 (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| NAT 目的地通訊埠 (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| 旗標 (flags) | flexString1 | 旗標 | flags | additional.fields.key 和 additional.fields.value.string_value |
| IP 通訊協定 (proto) | proto | proto | network.ip_protocol | |
| 動作 (action) | act | action | security_result.action_details
security_result.action |
|
| 網址/檔案名稱 (其他) | 其他 | target.file.names
target.url |
||
| 威脅/內容名稱 (threatid) | cat | ThreatID | security_result.threat_id | |
| 類別 (類別) | cs2 | URLCategory | 類別 | security_result.category_details |
| 嚴重性 (嚴重性) | number-of-severity (標頭) | 嚴重性 | security_result.severity
security_result.severity_details |
|
| 方向 (方向) | flexString2 | 方向 | network.direction | |
| 序號 (seqno) | externalId | sequence | metadata.product_log_id | |
| 動作旗標 (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value |
| 來源國家/地區 (srcloc) | SourceLocation | principal.location.country_or_region | ||
| 目的地國家/地區 (dstloc) | DestinationLocation | target.location.country_or_region | ||
| contenttype (contenttype) | ContentType | contenttype | additional.fields.key 和 additional.fields.value.string_value | |
| pcap_id (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key 和 additional.fields.value.string_value |
| filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | ||
| cloud (cloud) | Cloud | 雲端 | additional.fields.key 和 additional.fields.value.string_value | |
| url_idx (url_idx) | URLIndex | url_idx | additional.fields.key 和 additional.fields.value.string_value | |
| user_agent (user_agent) | network.http.user_agent | |||
| 檔案類型 (filetype) | target.file.mime_type | |||
| xff (xff) | xff | principal.ip | ||
| 參照網址 (referer) | network.http.referral_url | |||
| sender (sender) | network.email.from | |||
| 主旨 (主旨) | 主旨 | network.email.subject | ||
| 收件者 (recipient) | network.email.to | |||
| reportid (reportid) | reportid | additional.fields.key 和 additional.fields.value.string_value | ||
| DG Hierarchy Level 1 (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value |
| 需求開發廣告活動階層第 2 層 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value |
| 需求開發廣告活動階層第 3 層級 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value |
| 需求開發廣告活動階層第 4 層 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value |
| 虛擬系統名稱 (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| 裝置名稱 (device_name) | dvchost | DeviceName | intermediary.hostname | |
| file_url (file_url) | target.url | |||
| 來源 VM UUID (src_uuid) | SrcUUID | principal.asset.product_object_id | ||
| 目的地 VM UUID (dst_uuid) | DstUUID | target.asset.product_object_id | ||
| http_method (http_method) | RequestMethod | network.http.method | ||
| 通道 ID/IMSI (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key 和 additional.fields.value.string_value |
| 監控器標籤/IMEI (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key 和 additional.fields.value.string_value |
| 父項工作階段 ID (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| 父項工作階段開始時間 (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key 和 additional.fields.value.string_value |
| 隧道 (tunnel) | PanOSTunnelType | TunnelType | 通道 | additional.fields.key 和 additional.fields.value.string_value |
| thr_category (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| contentver (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key 和 additional.fields.value.string_value |
| sig_flags (sig_flags) | sig_flags | additional.fields.key 和 additional.fields.value.string_value | ||
| SCTP 關聯 ID (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key 和 additional.fields.value.string_value | |
| 酬載通訊協定 ID (ppid) | PanOSPPID | ppid | additional.fields.key 和 additional.fields.value.string_value | |
| http_headers (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| 網址類別清單 (url_category_list) | url_category_list | additional.fields.key 和 additional.fields.value.string_value | ||
| 規則的 UUID (rule_uuid) | PanOSRuleUUID | rule_uuid | security_result.rule_id | |
| HTTP/2 連線 (http2_connection) | http2_connection | network.application_protocol_version | ||
| dynusergroup_name (dynusergroup_name) | dynusergroup_name | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
||
| XFF 位址 (xff_ip) | principal.ip | |||
| 來源裝置類別 (src_category) | src_category | principal.asset.category | ||
| 來源裝置設定檔 (src_profile) | src_profile | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
||
| 來源裝置型號 (src_model) | src_model | principal.asset.hardware.model | ||
| 來源裝置供應商 (src_vendor) | src_vendor | principal.asset.hardware.manufacturer | ||
| 來源裝置 OS 系列 (src_osfamily) | principal.platform | |||
| 來源裝置 OS 版本 (src_osversion) | principal.platform_version | |||
| 來源主機名稱 (src_host) | src_host | principal.hostname | ||
| 來源 MAC 位址 (src_mac) | principal.mac | |||
| 目的地裝置類別 (dst_category) | dst_category | target.asset.category | ||
| 目的地裝置設定檔 (dst_profile) | dst_profile | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
||
| 目的地裝置型號 (dst_model) | dst_model | target.asset.hardware.model | ||
| 目的地裝置供應商 (dst_vendor) | dst_vendor | target.asset.hardware.manufacturer | ||
| 目的地裝置 OS 系列 (dst_osfamily) | target.platform | |||
| 目的地裝置 OS 版本 (dst_osversion) | target.platform_version | |||
| 目的地主機名稱 (dst_host) | target.hostname | |||
| 目的地 MAC 位址 (dst_mac) | target.mac | |||
| 容器 ID (container_id) | container_id | intermediary.resource.product_object_id | ||
| POD 命名空間 (pod_namespace) | pod_namespace | target.resource.attribute.labels.key/value | ||
| POD 名稱 (pod_name) | pod_name | target.resource.name | ||
| 來源外部動態清單 (src_edl) | src_edl | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
||
| 目標外部動態清單 (dst_edl) | dst_edl | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
||
| 主機 ID (hostid) | hostid | principal.asset.asset_id | ||
| 序號 (serialnumber) | principal.asset.hardware.serial_number | |||
| domain_edl (domain_edl) | domain_edl | additional.fields.key 和 additional.fields.value.string_value | ||
| 來源動態位址群組 (src_dag) | principal.group.group_display_name | |||
| 目的地動態地址群組 (dst_dag) | target.group.group_display_name | |||
| partial_hash (partial_hash) | partial_hash | additional.fields.key 和 additional.fields.value.string_value | ||
| 高解析度時間戳記 (high_res_timestamp) | additional.fields.key 和 additional.fields.value.string_value | |||
| 原因 (原因) | 原因 | security_result.summary | ||
| 理由 (理由) | 理由 | additional.fields.key 和 additional.fields.value.string_value | ||
| nssai_sst (nssai_sst) | nssai_sst | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式子類別 (subcategory_of_app) | subcategory_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式類別 (category_of_app) | category_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式技術 (technology_of_app) | technology_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式風險 (risk_of_app) | risk_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式特徵 (characteristic_of_app) | characteristic_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式容器 (container_of_app) | container_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 通道化應用程式 (tunneled_app) | tunneled_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式的軟體即服務 (is_saas_of_app) | is_saas_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式的受制裁狀態 (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 雲端報告 ID (cloud_reportid) | additional.fields.key 和 additional.fields.value.string_value | |||
| 叢集名稱 (cluster_name) | principal.resource.name | |||
| 流程類型 (flow_type) | additional.fields.key 和 additional.fields.value.string_value |
GlobalProtect
下表列出 GlobalProtect 記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time) | rt | received_time | metadata.event_timestamp | |
| 序號 (序號) | PanOSDeviceSN | intermediary_asset_hardware_serial_number | intermediary.asset.hardware.serial_number | |
| 類型 (型別) | type (Header) | metadata.product_event_type | ||
| 威脅/內容類型 (子類型) | 子類型 (標題) | 子類型 | metadata.product_event_type | |
| 生成時間 (time_generated) | PanOSLogTimeStamp | generated_timestamp | metadata.event_timestamp | |
| 虛擬系統 (vsys) | PanOSVirtualSystem | vsys | intermediary.asset.attribute.labels.key/value | |
| 事件 ID (eventid) | PanOSEventID | event_id | additional.fields.key 和 additional.fields.value.string_value | |
| 階段 (階段) | PanOSStage | 階段 | additional.fields.key 和 additional.fields.value.string_value | |
| 驗證方式 (auth_method) | PanOSAuthMethod | extension_auth_auth_details | extensions.auth.auth_details | |
| 通道類型 (tunnel_type) | PanOSTunnelType | 通道 | additional.fields.key 和 additional.fields.value.string_value | |
| 來源使用者 (srcuser) | PanOSSourceUserName | src_user | principal.user.email_address
principal.user.userid principal.administrative_domain |
|
| 來源區域 (srcregion) | PanOSSourceRegion | src_region | principal.location.country_or_region | |
| 電腦名稱 (machinename) | PanOSEndpointDeviceName | machine_name | principal.hostname | |
| 公開 IP (public_ip) | PanOSPublicIPv4 | principal.nat_ip | ||
| 公開 IPv6 (public_ipv6) | PanOSPublicIPv6 | principal.nat_ip | ||
| 私人 IP (private_ip) | PanOSPrivateIPv4 | principal.ip | ||
| 私人 IPv6 (private_ipv6) | PanOSPrivateIPv6 | principal.ip | ||
| 主機 ID (hostid) | PanOSHostID | hostid | principal.asset.asset_id | |
| 序號 (serialnumber) | PanOSDeviceSN | principal.asset.hardware.serial_number | ||
| 用戶端版本 (client_ver) | PanOSGlobalProtectClientVersion | client_ver | additional.fields.key 和 additional.fields.value.string_value | |
| 用戶端作業系統 (client_os) | PanOSEndpointOSType | principal.platform | ||
| 用戶端作業系統版本 (client_os_ver) | PanOSEndpointOSVersion | principal.platform_version | ||
| 重複次數 (repeatcnt) | PanOSCountOfRepeats | repeatcnt | additional.fields.key 和 additional.fields.value.string_value | |
| 原因 (原因) | PanOSQuarantineReason | security_result.summary | ||
| 錯誤 (錯誤) | PanOSConnectionError | error | security_result.description | |
| 說明 (不透明) | PanOSDescription | security_result.description | ||
| 狀態 (狀態) | PanOSEventStatus | 狀態 | additional.fields.key 和 additional.fields.value.string_value | |
| 位置 (位置) | PanOSGPGatewayLocation | target.location.country_or_region | ||
| 登入時間長度 (login_duration) | PanOSLoginDuration | network.session_duration | ||
| 連線方法 (connect_method) | PanOSConnectionMethod | connect_method | additional.fields.key 和 additional.fields.value.string_value | |
| 錯誤代碼 (error_code) | PanOSConnectionErrorID | error_code | additional.fields.key 和 additional.fields.value.string_value | |
| 入口網站 (入口網站) | PanOSPortal | 入口網站 | additional.fields.key 和 additional.fields.value.string_value | |
| 序號 (seqno) | PanOSSequenceNo | metadata.product_log_id | ||
| 動作旗標 (actionflags) | PanOSActionFlags | actionflags | additional.fields.key 和 additional.fields.value.string_value | |
| 高解析度時間戳記 (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key 和 additional.fields.value.string_value | ||
| 閘道選取方法 (selection_type) | PanOSGatewaySelectionType | selection_type | additional.fields.key 和 additional.fields.value.string_value | |
| 安全資料傳輸層 (SSL) 回應時間 (response_time) | PanOSSSLResponseTime | response_time | additional.fields.key 和 additional.fields.value.string_value | |
| 閘道優先順序 (優先順序) | PanOSGatewayPriority | 優先順序 | additional.fields.key 和 additional.fields.value.string_value | |
| 嘗試使用的閘道 (attempted_gateways) | PanOSAttemptedGateways | attempted_gateways | additional.fields.key 和 additional.fields.value.string_value | |
| 閘道名稱 (閘道) | PanOSAttemptedGateways | 閘道 | target.resource.name | |
| 裝置群組階層 (dg_hier_level_1) | dg_hier_level_1 | additional.fields.key 和 additional.fields.value.string_value | ||
| 裝置群組階層 (dg_hier_level_2) | dg_hier_level_2 | additional.fields.key 和 additional.fields.value.string_value | ||
| 裝置群組階層 (dg_hier_level_3) | dg_hier_level_3 | additional.fields.key 和 additional.fields.value.string_value | ||
| 裝置群組階層 (dg_hier_level_4) | dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value | ||
| 虛擬系統名稱 (vsys_name) | intermediary.asset.attribute.labels.key/value | |||
| 裝置名稱 (device_name) | intermediary.hostname | |||
| 虛擬系統 ID (vsys_id) | intermediary.resource.product_object_id | |||
| 嚴重性 (嚴重性) | number-of-severity(header) | security_result.severity 和 security_result.severity_details | ||
| 叢集名稱 (cluster_name) | principal.resource.name |
關聯性
下表列出關聯記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 產生時間 (time_generated 或 cef-formatted-time_generated) | startTime | generated_timestamp | metadata.event_timestamp | |
| 來源地址 (src) | src | principal.ip | ||
| 來源使用者 (srcuser) | SourceUser / usrName | principal.user.userid | ||
| 虛擬系統 (vsys) | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value | |
| 類別 (類別) | security_result.category_details | |||
| 嚴重性 (嚴重性) | 嚴重性 | security_result.severity 和 security_result.severity_details | ||
| 裝置群組階層層級 1 | DeviceGroupHierarchyL1 | additional.fields.key 和 additional.fields.value.string_value | ||
| 裝置群組階層層級 2 | DeviceGroupHierarchyL2 | additional.fields.key 和 additional.fields.value.string_value | ||
| 裝置群組階層層級 3 | DeviceGroupHierarchyL3 | additional.fields.key 和 additional.fields.value.string_value | ||
| 裝置群組階層層級 4 | DeviceGroupHierarchyL4 | additional.fields.key 和 additional.fields.value.string_value | ||
| 虛擬系統名稱 (vsys_name) | vSrcName | intermediary.asset.attribute.labels.key/value | ||
| 裝置名稱 (device_name) | DeviceName | intermediary.hostname | ||
| 虛擬系統 ID (vsys_id) | VirtualSystemID | intermediary.resource.product_object_id | ||
| 物件名稱 (objectname) | ObjectName | target.resource.name | ||
| 物件 ID (object_id) | ObjectID | target.resource.product_object_id | ||
| 證據 (證據) | msg | security_result.summary |
GTP
下表列出 gtp 記錄類型的記錄欄位,以及對應的 UDM 欄位。
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | metadata.collected_timestamp,
metadata.event_timestamp (如果沒有「產生時間」) |
|||
| 序號 (serial) | intermediary.asset.hardware.serial_number | |||
| 類型 (型別) | metadata.product_event_type | |||
| 威脅/內容類型 (子類型) | metadata.product_event_type | |||
| 產生時間 (time_generated 或 cef-formatted-time_generated) | metadata.event_timestamp | |||
| 來源地址 (src) | principal.ip | |||
| 目的地地址 (dst) | target.ip | |||
| 規則名稱 (規則) | security_result.rule_name | |||
| 應用程式 (應用程式) | network.application_protocol | |||
| 虛擬系統 (vsys) | vsys | intermediary.asset.attribute.labels.key/value | ||
| 來源可用區 (從) | 從 | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
||
| 目的地可用區 (至) | 到 | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
||
| 傳入介面 (inbound_if) | inbound_if | principal.labels.key 和 principal.labels.value additional.fields.key 和 additional.fields.value.string_value |
||
| 傳出介面 (outbound_if) | outbound_if | target.labels.key 和 target.labels.value additional.fields.key 和 additional.fields.value.string_value |
||
| 記錄動作 (logset) | logset | additional.fields.key 和 additional.fields.value.string_value | ||
| 工作階段 ID (sessionid) | network.session_id | |||
| 來源通訊埠 (sport) | principal.port | |||
| 目的地通訊埠 (dport) | target.port | |||
| IP 通訊協定 (proto) | network.ip_protocol | |||
| 動作 (動作) | security_result.action_details
security_result.action |
|||
| GTP 事件類型 (event_type) | gtp_event_type | additional.fields.key 和 additional.fields.value.string_value | ||
| MSISDN (msisdn) | msisdn | additional.fields.key 和 additional.fields.value.string_value | ||
| 存取點名稱 (apn) | apn | additional.fields.key 和 additional.fields.value.string_value | ||
| 無線電存取技術 (RAT) | rat | additional.fields.key 和 additional.fields.value.string_value | ||
| GTP 訊息類型 (msg_type) | gtp_msg_type | additional.fields.key 和 additional.fields.value.string_value | ||
| 結束 IP 位址 (end_ip_adr) | principal.ip | |||
| 通道端點 ID 1 (teid1) | teid1 | additional.fields.key 和 additional.fields.value.string_value | ||
| 通道端點 ID 2 (teid2) | teid2 | additional.fields.key 和 additional.fields.value.string_value | ||
| GTP 介面 (gtp_interface) | gtp_interface | additional.fields.key 和 additional.fields.value.string_value | ||
| GTP Cause (cause_code) | gtp_cause_code | additional.fields.key 和 additional.fields.value.string_value | ||
| 嚴重性 (嚴重性) | security_result.severity 和 security_result.severity_details | |||
| 放送聯播網 MCC (mcc) | mcc | additional.fields.key 和 additional.fields.value.string_value | ||
| 供應網路 MNC (mnc) | mnc | additional.fields.key 和 additional.fields.value.string_value | ||
| 區碼 (area_code) | area_code | additional.fields.key 和 additional.fields.value.string_value | ||
| 儲存格 ID (cell_id) | cell_id | additional.fields.key 和 additional.fields.value.string_value | ||
| GTP 事件代碼 (event_code) | event_code | additional.fields.key 和 additional.fields.value.string_value | ||
| 來源位置 (srcloc) | principal.location.country_or_region | |||
| 目的地位置 (dstloc) | target.location.country_or_region | |||
| 通道 ID/IMSI (imsi) | tunnelid | additional.fields.key 和 additional.fields.value.string_value | ||
| 監視器標籤/IMEI (imei) | monitortag | additional.fields.key 和 additional.fields.value.string_value | ||
| 開始時間 (開始) | start | additional.fields.key 和 additional.fields.value.string_value | ||
| 經過時間 (elapsed) | network.session_duration.seconds | |||
| 隧道檢查規則 (tunnel_insp_rule) | tunnel_insp_rule | security_result.detection_fields.key/value | ||
| 遠端使用者 IP (remote_user_ip) | principal.ip | |||
| 遠端使用者 ID (remote_user_id) | remote_user_id | principal.user.userid | ||
| 規則的 UUID (rule_uuid) | security_result.rule_id | |||
| PCAP ID (pcap_id) | pcap_id | additional.fields.key 和 additional.fields.value.string_value | ||
| 高解析度時間戳記 (high_res_timestamp) | additional.fields.key 和 additional.fields.value.string_value | |||
| 切片服務類型 (nsdsai_sst) | nsdsai_sst | additional.fields.key 和 additional.fields.value.string_value | ||
| 配量差異化指標 (nsdsai_sd) | nsdsai_sd | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式子類別 (subcategory_of_app) | subcategory_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式類別 (category_of_app) | category_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式技術 (technology_of_app) | technology_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式風險 (risk_of_app) | risk_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式特徵 (characteristic_of_app) | characteristic_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式容器 (container_of_app) | container_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式 SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key 和 additional.fields.value.string_value | ||
| 應用程式受制裁狀態 (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key 和 additional.fields.value.string_value |
SCTP
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 接收時間 (receive_time 或 cef-formatted-receive_time) | receive_time 或 cef-formatted-receive_time | metadata.collected_timestamp | ||
| 序號 (serial) | serial | intermediary.asset.hardware.serial_number | ||
| 類型 (type) | 類型 | metadata.product_event_type | ||
| 產生時間 (time_generated 或 cef-formatted-time_generated) | time_generated 或 cef-formatted-time_generated | metadata.event_timestamp | ||
| 來源地址 (src) | src | principal.ip | ||
| 目的地地址 (dst) | dst | target.ip | ||
| 規則名稱 (規則) | 規則 | security_result.rule_name | ||
| 來源可用區 (從) | 來自 | additional.fields.key 和 additional.fields.value.string_value | ||
| 目的地 (到) | 至 | additional.fields.key 和 additional.fields.value.string_value | ||
| 傳入介面 (inbound_if) | inbound_if | additional.fields.key 和 additional.fields.value.string_value | ||
| 輸出介面 (outbound_if) | outbound_if | additional.fields.key 和 additional.fields.value.string_value | ||
| 記錄動作 (記錄集) | logset | additional.fields.key 和 additional.fields.value.string_value | ||
| 工作階段 ID (sessionid) | sessionid | network.session_id | ||
| 重複次數 (repeatcnt) | repeatcnt | additional.fields.key 和 additional.fields.value.string_value | ||
| 來源通訊埠 (sport) | 運動 | principal.port | ||
| 目的地通訊埠 (dport) | dport | target.port | ||
| IP 通訊協定 (proto) | proto | network.ip_protocol (enum) | ||
| 動作 (action) | 動作 | security_result.action_details security_result.action |
||
| 裝置群組階層 (dg_hier_level_1 至 dg_hier_level_4) | dg_hier_level_1 至 dg_hier_level_4 | additional.fields.key 和 additional.fields.value.string_value | ||
| 裝置名稱 (device_name) | device_name | intermediary.hostname | ||
| 序號 (seqno) | seqno | metadata.product_log_id | ||
| SCTP 關聯 ID (assoc_id) | assoc_id | additional.fields.key 和 additional.fields.value.string_value | ||
| 酬載通訊協定 ID (ppid) | ppid | additional.fields.key 和 additional.fields.value.string_value | ||
| 嚴重性 (severity) | 嚴重性 | security_result.severity 和 security_result.severity_details | ||
| SCTP 區塊類型 (sctp_chunk_type) | sctp_chunk_type | additional.fields.key 和 additional.fields.value.string_value | ||
| SCTP 事件類型 (sctp_event_type) | sctp_event_type | additional.fields.key 和 additional.fields.value.string_value | ||
| SCTP 驗證代碼 1 (verif_tag_1) | verif_tag_1 | additional.fields.key 和 additional.fields.value.string_value | ||
| SCTP 驗證廣告代碼 2 (verif_tag_2) | verif_tag_2 | additional.fields.key 和 additional.fields.value.string_value | ||
| SCTP 原因代碼 (sctp_cause_code) | sctp_cause_code | additional.fields.key 和 additional.fields.value.string_value | ||
| Diameter 應用程式 ID (diam_app_id) | diam_app_id | additional.fields.key 和 additional.fields.value.string_value | ||
| Diameter 指令代碼 (diam_cmd_code) | diam_cmd_code | additional.fields.key 和 additional.fields.value.string_value | ||
| Diameter AVP 代碼 (diam_avp_code) | diam_avp_code | additional.fields.key 和 additional.fields.value.string_value | ||
| SCTP 串流 ID (stream_id) | stream_id | additional.fields.key 和 additional.fields.value.string_value | ||
| SCTP 關聯結束原因 (assoc_end_reason) | assoc_end_reason | additional.fields.key 和 additional.fields.value.string_value | ||
| 運算碼 (op_code) | op_code | additional.fields.key 和 additional.fields.value.string_value | ||
| SCCP Calling Party SSN (sccp_calling_ssn) | sccp_calling_ssn | additional.fields.key 和 additional.fields.value.string_value | ||
| SCCP Calling Party Global Title (sccp_calling_gt) | sccp_calling_gt | additional.fields.key 和 additional.fields.value.string_value | ||
| SCTP 篩選器 (sctp_filter) | sctp_filter | additional.fields.key 和 additional.fields.value.string_value | ||
| SCTP 區塊 (區塊) | chunks | additional.fields.key 和 additional.fields.value.string_value | ||
| 傳送的 SCTP 區塊 (chunks_sent) | chunks_sent | additional.fields.key 和 additional.fields.value.string_value | ||
| 收到的 SCTP 區塊 (chunks_received) | chunks_received | additional.fields.key 和 additional.fields.value.string_value | ||
| 封包 (封包) | 封包 | additional.fields.key 和 additional.fields.value.string_value | ||
| 規則的 UUID (rule_uuid) | rule_uuid | security_result.rule_id | ||
| 虛擬系統 (vsys) | vsys | intermediary.asset.attribute.labels.key/value | ||
| 虛擬系統名稱 (vsys_name) | vsys_name | intermediary.asset.attribute.labels.key/value | ||
| 傳送的封包數 (pkts_sent) | pkts_sent | network.sent_packets | ||
| 接收的封包數 (pkts_received) | pkts_received | network.received_packets |
稽核
| CSV 欄位 | CEF 欄位 | LEEF 欄位 | Google Security Operations 標籤鍵 | UDM 欄位 |
|---|---|---|---|---|
| 生成時間 | metadata.event_timestamp | |||
| 威脅/內容類型 (子類型) | metadata.product_event_type | |||
| 事件 ID | principal.application | |||
| 物件 | principal.user.userid | |||
| CLI 指令 | principal.process.command_line | |||
| 嚴重性 | security_result.severity | |||
| 序號 | intermediary.asset.hardware.serial_number |
欄位對應參考資料:記錄類型至 UDM 事件類型
下表列出 Palo Alto Networks 防火牆記錄類型,以及對應的 UDM 事件類型。
| 記錄類型 | UDM 事件類型 |
| 流量 | NETWORK_CONNECTION |
| 威脅 | NETWORK_CONNECTION |
| 網址篩選 | NETWORK_CONNECTION |
| WildFire | NETWORK_CONNECTION
WildFire 提交記錄是威脅記錄類型的子類型,使用相同的系統記錄格式。 |
| 資料篩選 | NETWORK_CONNECTION |
| 通道 | NETWORK_CONNECTION |
| GTP | NETWORK_CONNECTION |
| 設定 | SETTING_MODIFICATION/SETTING_CREATION/SETTING_DELETION/SETTING_UNCATEGORIZED
「Command (cmd)」欄位的值會決定 UDM 事件類型對應。 如果 cmd 欄位值為 add 或 clone,系統會設定 SETTING_CREATION。 如果 cmd 欄位值為 delete,系統會設定 SETTING_DELETION。 如果 cmd 欄位值為 edit、move、rename、set 或 commit,系統會設定 SETTING_MODIFICATION。 如果 cmd 欄位值不含任何值,系統會設定 SETTING_UNCATEGORIZED。 |
| 系統 |
如果子類型值為「dhcp」,系統會設定 NETWORK_DHCP。 如果子類型值為「auth」,系統就會設定 USER_LOGIN。 如果說明值為「logged in」,系統就會設定 USER_LOGIN。 如果說明值為「logged out」,系統會設定 USER_LOGOUT。 如果子類型為其他值,系統會設定 GENERIC_EVENT。 |
| HIP Match | NETWORK_CONNECTION |
| IP 代碼 | GENERIC_EVENT |
| User-ID | USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED
如果子類型值為「login」,系統就會設定 USER_LOGIN。 如果子類型值為「logout」,系統會設定 USER_LOGOUT。 如果子類型不含任何值,系統會設定 USER_UNCATEGORIZED。 |
| 解密 | NETWORK_CONNECTION |
| 驗證 | GENERIC_EVENT |
| SCTP | NETWORK_CONNECTION |
| 稽核 | GENERIC_EVENT |
UDM 對應差異
UDM 對應差異參考資料:Palo Alto Networks 防火牆
下表列出 Palo Alto Networks Firewall 的舊版 UDM 對應與新版 UDM 對應之間的差異。Palo Alto Networks Firewall
UDM Event Type Delta
| Log type | Old UDM Event Type | New UDM Event Type |
| WildFire | NETWORK_CONNECTION | SCAN_UNCATEGORIZED |
| Data Filtering | NETWORK_CONNECTION | NETWORK_UNCATEGORIZED |
| Authentication | STATUS_UPDATE | STATUS_UNCATEGORIZED |
UDM Field Mapping Delta
| Log Type | Old UDM Mapping | CSV Log Field | CEF Log Field | LEEF Log Field | New UDM Mapping |
|---|---|---|---|---|---|
| System | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| System | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| System | about.labels.key/value additional.fields.key/value.string_value | Object (object) | fname | Filename | target.resource.name |
| System | Description (opaque) | msg | msg | metadata.description | |
| System | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| System | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| Config | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| Config | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| Config | principal.process.command_line | Configuration Path (path) | msg | ConfigurationPath | principal.process.command_line |
| Config | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| Config | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| Config | principal.asset.attribute.labels.key/value | Device Group (dg_id) | PanOSFWDeviceGroup | target.asset.attribute.labels | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Threat/Wildfire | target.file.full_path target.url target.hostname | URL/Filename (misc) | request | Miscellaneous | target.file.names target.url |
| Threat/Wildfire | about.file.sha1/md5/sha256 | File Digest (filedigest) | fileHash | FileDigest | target.file.sha1/md5/sha256 |
| Threat/Wildfire | about.file.mime_type | File Type (filetype) | fileType | FileType | target.file.mime_type |
| Threat/Wildfire | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Threat/Wildfire | principal.user.product_object_id | Source VM UUID (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id |
| Threat/Wildfire | target.user.product_object_id | Destination VM UUID (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | HTTP Headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| Threat/Wildfire | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| Threat/Wildfire | principal.asset.software.version | Source Device OS Version (src_osversion) | PanSrcDeviceOSv | principal.platform_version | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| Threat/Wildfire | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| Threat/Wildfire | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | PanReasonFilteringAction | security_result.summary | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Packets Sent (pkts_sent) | PanOSPacketsSent | srcPackets | network.sent_packets |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Packets Received (pkts_received) | PanOSPacketsReceived | dstPackets | network.received_packets |
| Traffic | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| Traffic | principal.asset.platform_software.platform(enum) principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| Traffic | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| Traffic | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| User-ID | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| User-ID | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| User-ID | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | intermediary.resource.product_object_id |
| User-ID | principal.user.userid principal.administrative_domain principal.user.email_addresses | User by Source (userbysource) | PanOSUserBySource | target.user.userid target.user.email_addresses | |
| User-ID | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| HIP Match | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | HIP (matchname) | cat | HIP | target.resource.attribute.labels |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | HIP Type (matchtype) | Device Event Class ID (Header) | HIPType | target.resource.attribute.labels |
| HIP Match | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| HIP Match | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| HIP Match | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id |
| HIP Match | principal.asset.product_object_id | Host ID (hostid) | PanOSHostID | principal.asset.asset_id | |
| HIP Match | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| IP-Tag | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| IP-Tag | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| IP-Tag | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOsVsysName | vSrcName | target.asset.attribute.labels |
| IP-Tag | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| IP-Tag | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id |
| IP-Tag | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Decryption | target.application | Application (app) | app | network.application_protocol | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | intermediary.asset.attribute.labels | |
| Decryption | principal.asset.asset_id | Source VM UUID (src_uuid) | PanOSSourceUUID | principal.asset.product_object_id | |
| Decryption | target.asset.asset_id | Destination VM UUID (dst_uuid) | PanOSDestinationUUID | target.asset.product_object_id | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanOSContainerID | intermediary.resource.product_object_id | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanOSContainerNameSpace | target.resource.attribute.labels additional.fields.key/value.string_value | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanOSContainerName | target.resource.name | |
| Decryption | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanOSSourceDeviceCategory | principal.asset.category | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanOSSourceDeviceModel | principal.asset.hardware.model | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanOSSourceDeviceVendor | principal.asset.hardware.manufacturer | |
| Decryption | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanOSSourceDeviceOSFamily | principal.platform | |
| Decryption | principal.asset.software.version | Source Device OS Version (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanOSDestinationDeviceCategory | target.asset.category | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanOSDestinationDeviceModel | target.asset.hardware.model | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanOSDestinationDeviceVendor | target.asset.hardware.manufacturer | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanOSDestinationDeviceOSFamily | target.platform | |
| Decryption | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanOSDestinationDeviceOSVersion | target.platform_version | |
| Decryption | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | intermediary.asset.attribute.labels | ||
| Decryption | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Tunnel | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Packets Sent (pkts_sent) | PanOSPacketsSent | srcPackets | network.sent_packets |
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Packets Received (pkts_received) | PanOSPacketsReceived | dstPackets | network.received_packets |
| Tunnel | target.ip | Remote User IP (remote_user_ip) | PanOSRmtUserIP | principal.ip | |
| Tunnel | target.labels.key/value additional.fields.key/value.string_value | Remote User ID (remote_user_id) | PanOSRmtUserID | principal.user.userid | |
| Tunnel | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Authentication | target.user.user_display_name | Normalize User (normalize_user) | cs2 | NormalizeUser | target.user.user_display_name |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Object (object) | fname | ObjectName | target.resource.name |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Authentication Policy (authpolicy) | cs4 | AuthPolicy | additional.fields.key/value.string_value |
| Authentication | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Authentication | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| Authentication | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res _timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanOSSourceDeviceCategory | principal.asset.category | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanOSSourceDeviceModel | principal.asset.hardware.model | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanOSSourceDeviceVendor | principal.asset.hardware.manufacturer | |
| Authentication | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanOSSourceDeviceOSFamily | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | |
| Authentication | principal.asset.software.version | Source Device OS Version (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| URL | target.file.full_path target.url | URL/Filename (misc) | Miscellaneous | target.file.names target.url | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Category (category) | cs2 | URLCategory | security_result.category_details |
| URL | about.file.sha1/md5/sha256 | filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | |
| URL | about.file.mime_type | filetype (filetype) | target.file.mime_type | ||
| URL | about.labels.key/value additional.fields.key/value.string_value | xff (xff) | PanOSXForwarderfor | identSrc | principal.ip |
| URL | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| URL | about.url | file_url (file_url) | target.url | ||
| URL | principal.asset.asset_id | Source VM UUID (src_uuid) | SrcUUID | principal.asset.product_object_id | |
| URL | target.asset.asset_id | Destination VM UUID (dst_uuid) | DstUUID | target.asset.product_object_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | http_headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| URL | about.labels.key/value additional.fields.key/value.string_value | UUID for rule (rule_uuid) | PanOSRuleUUID | security_result.rule_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| URL | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| URL | principal.asset.software.version | Source Device OS Version (src_osversion) | PanSrcDeviceOSv | principal.platform_version | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Hostname (src_host) | PanSrcHostname | principal.hostname | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| URL | target.asset.platform_software.platform target.labels.key/value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| URL | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| URL | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| URL | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Res Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | PanReasonFilteringAction | security_result.summary | |
| Data | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Data | target.file.full_path target.url | URL/Filename (misc) | Miscellaneous | target.file.names target.url | |
| Data | about.labels.key/value additional.fields.key/value.string_value | Category (category) | cs2 | URLCategory | security_result.category_details |
| Data | about.file.sha1/md5/sha256 | filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | |
| Data | about.file.mime_type | filetype (filetype) | target.file.mime_type | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | xff (xff) | principal.ip | ||
| Data | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Data | about.url | file_url (file_url) | target.url | ||
| Data | principal.asset.asset_id | Source VM UUID (src_uuid) | SrcUUID | principal.asset.product_object_id | |
| Data | target.asset.asset_id | Destination VM UUID (dst_uuid) | DstUUID | target.asset.product_object_id | |
| Data | about.labels.key/value additional.fields.key/value.string_value | http_headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| Data | about.labels.key/value additional.fields.key/value.string_value | UUID for rule (rule_uuid) | PanOSRuleUUID | security_result.rule_id | |
| Data | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | network.application_protocol_version | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | principal.asset.category | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | principal.asset.hardware.model | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | principal.asset.hardware.manufacturer | ||
| Data | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | principal.platform | ||
| Data | principal.asset.software.version | Source Device OS Version (src_osversion) | principal.platform_version | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Hostname (src_host) | principal.hostname | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | target.asset.category | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | target.asset.hardware.model | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | target.asset.hardware.manufacturer | ||
| Data | target.asset.platform_software.platform target.labels.key/value | Destination Device OS Family (dst_osfamily) | target.platform | ||
| Data | target.asset.software.version | Destination Device OS Version (dst_osversion) | target.platform_version | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | intermediary.resource.product_object_id | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | target.resource.attribute.labels | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | target.resource.name | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | principal.asset.asset_id | ||
| Data | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Res Timestamp (high_res_timestamp) | additional.fields.key/value.string_value | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | security_result.summary | ||
| GlobalProtect | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | PanOSVirtualSystem | intermediary.asset.attribute.labels | |
| GlobalProtect | principal.user.email_address principal.user.userid principal.administrative_domain | Source User (srcuser) | PanOSSourceUserName | target.user.email_address target.user.userid | |
| GlobalProtect | principal.asset.platform_software.platform(enum) | Client OS (client_os) | PanOSEndpointOSType | principal.platform | |
| GlobalProtect | principal.asset.platform_software.platform_version | Client OS Version (client_os_ver) | PanOSEndpointOSVersion | principal.platform_version | |
| GlobalProtect | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| GlobalProtect | about.labels.key/value additional.fields.key/value.string_value | Gateway Name (gateway) | PanOSAttemptedGateways | target.resource.name | |
| GlobalProtect | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | intermediary.asset.attribute.labels | ||
| GlobalProtect | target.hostname | Device Name (device_name) | intermediary.hostname | ||
| GlobalProtect | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| CORRELATION | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | VirtualSystem | intermediary.asset.attribute.labels | |
| CORRELATION | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | vSrcName | intermediary.asset.attribute.labels | |
| CORRELATION | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | VirtualSystemID | intermediary.resource.product_object_id | |
| GTP | additional.fields.key/value.string_value | Virtual System (vsys) | intermediary.asset.attribute.labels | ||
| GTP | target.ip | Remote User IP (remote_user_ip) | principal.ip | ||
| GTP | additional.fields.key/value.string_value | Remote User ID (remote_user_id) | principal.user.userid | ||
| GTP | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | additional.fields.key/value.string_value |
Palo Alto Networks 防火牆 Strata 記錄服務
總覽
Palo Alto Networks® Strata Logging Service 提供雲端式集中記錄儲存和彙整服務,適用於地端、虛擬 (私有雲和公有雲) 防火牆、Prisma Access,以及 Cortex XDR 等雲端服務。Strata Logging Service 安全無虞、具備復原能力且容錯,可確保記錄資料保持最新狀態,並在您需要時隨時可用。這項服務提供可擴充的記錄基礎架構,讓您不必規劃及部署記錄收集器,即可滿足記錄保留需求。如果您已有內部部署的記錄收集器,新的 Strata Logging Service 可做為現有設定的輔助工具。您可以透過雲端 Strata Logging Service 擴充現有的記錄檔收集基礎架構,隨著業務成長擴大作業容量,或滿足新地點的容量需求。有了這項服務,Palo Alto Networks 會負責記錄檔基礎架構的持續維護和監控作業,讓您專注於業務。
確認 Strata Logging Service 剖析器支援的記錄格式和 PAN-OS 版本。下表列出 Strata Logging Service 剖析器支援的記錄格式和對應的 PAN-OS 版本:
記錄格式 PAN-OS 版本 JSON 12.1 確認 Google SecOps 剖析器支援的 Palo Alto Networks 防火牆記錄檔類型。 Google SecOps 剖析器支援下列 Palo Alto Networks 防火牆記錄類型:
- 流量
- 威脅
- 隧道檢查
- 系統
- HIP 比對
- IP-Tag
- User-ID
- 解密
- 驗證
- 網址篩選
- GlobalProtect
部署 Strata Logging 服務
- 確認 Palo Alto Networks 防火牆產品已正確部署及設定。如需詳細設定說明,請參閱 PAN-OS 說明文件,然後按照這份部署文件操作,再將記錄傳送至 Strata Logging Service Strata Logging Service 部署作業必要條件
開始將記錄檔傳送至 Strata Logging 服務:
如要開始將記錄檔傳送至 Strata Logging Service,請按照下列步驟操作:
- 安裝支援的 PAN-OS® 版本
- 啟用 Strata Logging Service:啟用 Strata Logging Service 時,系統會佈建防火牆安全連線至 Strata Logging Service 時所需的憑證。
- 將防火牆加入 Strata Logging Service,可選擇是否使用 Panorama
如需詳細的啟用步驟,請參閱說明文件。
轉送 Strata Logging Service 的記錄
為滿足長期儲存、報表和監控,或法律和法規遵循需求,您可以將 Strata Logging Service 設定為將記錄轉送至 HTTPS 伺服器,或下列 SIEM:
- Exabeam
- Google Chronicle
- Microsoft Sentinel
- Splunk HTTP 事件收集器 (HEC)
使用 HTTPS 轉送方法,透過 Strata Logging Service 轉送記錄檔。如需詳細資訊,請參閱這份文件。
支援的記錄格式
Palo Alto Networks Strata Logging Service 防火牆剖析器支援 JSON 格式的記錄。
支援的範例記錄
JSON
{"source": "Palo Alto Networks FLS LF", "host": "dummy-loghost", "time": "1730265996460", "event": {"TimeReceived": "2024-10-30T05:25:50.000000Z", "DeviceSN": "no-serial", "LogType": "TRAFFIC", "Subtype": "end", "ConfigVersion": "10.2", "TimeGenerated": "2024-10-30T05:25:40.000000Z", "SourceAddress": "198.51.100.6", "DestinationAddress": "198.51.100.6", "NATSource": "", "NATDestination": "", "Rule": "egress-dns-ping-traceroute", "SourceUser": null, "DestinationUser": null, "Application": "dns-base", "VirtualLocation": "vsys1", "FromZone": "VA8280-RN", "ToZone": "inter-fw", "InboundInterface": "tunnel.101", "OutboundInterface": "tunnel.4005", "LogSetting": "Cortex Data Lake", "SessionID": 754194, "RepeatCount": 1, "SourcePort": 53578, "DestinationPort": 53, "NATSourcePort": 0, "NATDestinationPort": 0, "Protocol": "udp", "Action": "allow", "Bytes": 214, "BytesSent": 72, "BytesReceived": 142, "PacketsTotal": 2, "SessionStartTime": "2024-10-30T05:25:10.000000Z", "SessionDuration": 0, "URLCategory": "any", "SequenceNo": 7382192512716388639, "SourceLocation": "198.51.100.6-198.51.255.255", "DestinationLocation": "198.51.100.6-198.51.255.255", "PacketsSent": 1, "PacketsReceived": 1, "SessionEndReason": "aged-out", "DGHierarchyLevel1": 65537, "DGHierarchyLevel2": 65538, "DGHierarchyLevel3": 65541, "DGHierarchyLevel4": 0, "VirtualSystemName": "", "DeviceName": "VA8280-RN", "ActionSource": "from-policy", "SourceUUID": null, "DestinationUUID": null, "IMSI": 0, "IMEI": null, "ParentSessionID": 0, "ParentStarttime": "1970-01-01T00:00:00.000000Z", "Tunnel": "N/A", "EndpointAssociationID": 72057594037927936, "ChunksTotal": 0, "ChunksSent": 0, "ChunksReceived": 0, "RuleUUID": "95cfc3cc-cb00-4758-af1d-de9ab5f07f97", "HTTP2Connection": 0, "LinkChangeCount": 0, "SDWANPolicyName": null, "LinkSwitches": null, "SDWANCluster": null, "SDWANDeviceType": null, "SDWANClusterType": null, "SDWANSite": null, "DynamicUserGroupName": null, "X-Forwarded-ForIP": null, "SourceDeviceCategory": null, "SourceDeviceProfile": null, "SourceDeviceModel": null, "SourceDeviceVendor": null, "SourceDeviceOSFamily": null, "SourceDeviceOSVersion": null, "SourceDeviceHost": null, "SourceDeviceMac": null, "DestinationDeviceCategory": null, "DestinationDeviceProfile": null, "DestinationDeviceModel": null, "DestinationDeviceVendor": null, "DestinationDeviceOSFamily": null, "DestinationDeviceOSVersion": null, "DestinationDeviceHost": null, "DestinationDeviceMac": null, "ContainerID": null, "ContainerNameSpace": null, "ContainerName": null, "SourceEDL": null, "DestinationEDL": null, "GPHostID": null, "EndpointSerialNumber": null, "SourceDynamicAddressGroup": null, "DestinationDynamicAddressGroup": null, "HASessionOwner": null, "TimeGeneratedHighResolution": "2024-10-30T05:25:41.009000Z", "NSSAINetworkSliceType": null, "NSSAINetworkSliceDifferentiator": null}}"
欄位對應參考資料:記錄欄位對應至 UDM 欄位
本節說明剖析器如何將 Palo Alto Networks Strata Logging Service 防火牆記錄欄位,對應至各記錄類型的 Google UDM 事件欄位。
如需各記錄類型的對應參考資料,請參閱下列章節:
系統
下表列出「系統」記錄類型中的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| AgentContentVersion | additional.fields.key/value.string_value |
| AgentDataCollectionStatus | target.resource.attribute.labels |
| AgentID | target.resource.attribute.labels |
| AgentIsolationStatus | target.resource.attribute.labels |
| AgentStatus | target.resource.attribute.labels |
| AgentVersion | target.asset.software.version |
| ConfigVersion | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DeviceGroup | target.group.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EndpointCPUArchitecture | target.asset.hardware.cpu_platform |
| EndpointDeviceDomain | target.asset.administrative_domain |
| EndpointDeviceName | target.asset.hostname |
| EndpointIPaddress | target.asset.ip |
| VDIEndpoint | target.asset.attribute.labels |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointOSVersion | target.platform_version |
| AgentTimeZoneOffset | additional.fields.key/value.string_value |
| EndpointUserDomain | additional.fields.key/value.string_value |
| EndpointUserName | target.user.user_display_name |
| EndpointUserUUID | target.user.userid |
| EventComponent | additional.fields.key/value.string_value |
| EventDescription | metadata.description |
| EventName | additional.fields.key/value.string_value |
| EventTime | metadata.event_timestamp |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogCategory | security_result.category_details |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| LogSourceID | target.resource.attribute.labels |
| LogSourceName | observer.asset.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| LogTime | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Severity | security_result.severity |
| Subtype | metadata.product_event_type |
| Template | target.resource.attribute.labels |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
威脅
下表列出「威脅」記錄類型的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| ApplianceOrCloud | additional.fields.key/value.string_value |
| CloudHostname | additional.fields.key/value.string_value |
| CloudReportID | security_result.detection_fields.key/value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DirectionOfAttack | security_result.detection_fields.key/value |
| DomainEDL | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| FileName | target.file.names |
| FileHash | target.file.sha1 |
| FileType | additional.fields.key/value.string_value |
| FileURL | target.url |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HostID | principal.asset.asset_id |
| HTTP2Connection | network.application_protocol_version |
| HTTPMethod | network.http.method |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| LocalDeepLearningAnalyzed | additional.fields.key/value.string_value |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| PartialHash | additional.fields.key/value.string_value |
| PayloadProtocolID | additional.fields.key/value.string_value |
| Packet | additional.fields.key/value.string_value |
| PacketID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| RecipientEmail | target.user.email_addresses |
| ReportID | security_result.detection_fields.key/value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SenderEmail | principal.user.email_addresses |
| SequenceNo | metadata.product_log_id |
| SessionID | network.session_id |
| Severity | security_result.severity |
| SigFlags | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| EmailSubject | network.email.subject |
| ApplicationTechnology | additional.fields.key/value.string_value |
| ThreatCategory | security_result.detection_fields.key/value.key/value |
| ThreatID | security_result.threat_id |
| ThreatName | security_result.threat_name |
| ThreatNameFirewall | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLDomain | target.domain.name |
| URLCounter | additional.fields.key/value.string_value |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| Verdict | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-ForIP | principal.ip |
流量
下表列出「流量」記錄類型的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| ActionSource | additional.fields.key/value.string_value |
| AIFwdError | additional.fields.key/value.string_value |
| AITraffic | additional.fields.key/value.string_value |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| BytesReceived | network.received_bytes |
| BytesSent | network.sent_bytes |
| Bytes | additional.fields.key/value.string_value |
| ChunksReceived | additional.fields.key/value.string_value |
| ChunksSent | additional.fields.key/value.string_value |
| ChunksTotal | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| EndpointAssociationID | additional.fields.key/value.string_value |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HASessionOwner | additional.fields.key/value.string_value |
| GPHostID | additional.fields.key/value.string_value |
| HTTP2Connection | network.application_protocol_version |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsOffloaded | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| LinkChangeCount | additional.fields.key/value.string_value |
| LinkSwitches | additional.fields.key/value.string_value |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| SDWANPolicyName | additional.fields.key/value.string_value |
| Protocol | network.ip_protocol |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SDWANFECRatio | additional.fields.key/value.string_value |
| SDWANCluster | additional.fields.key/value.string_value |
| SDWANClusterType | additional.fields.key/value.string_value |
| SDWANDeviceType | additional.fields.key/value.string_value |
| SDWANSite | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionStartTime | additional.fields.key/value.string_value |
| SessionTracker | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| SessionDuration | network.session_duration |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLCategory | target.url_metadata.categories |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-ForIP | principal.ip |
User-ID
下表列出 User-ID 記錄類型的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| AuthFactorNo | security_result.detection_fields.key/value |
| AuthenticatedUserDomain | target.user.administrative_domain |
| AuthenticatedUserName | target.user.userid |
| AuthenticatedUserUUID | target.user.product_object_id |
| ConfigVersion | additional.fields.key/value.string_value |
| CountofRepeats | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationPort | target.port |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EventID | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsDuplicateUser | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MappingDataSource | additional.fields.key/value.string_value |
| MappingDataSourceName | additional.fields.key/value.string_value |
| MappingDataSourceType | additional.fields.key/value.string_value |
| MappingTimeout | additional.fields.key/value.string_value |
| MFAFactorType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SourceIP | principal.ip |
| SourcePort | principal.port |
| Subtype | metadata.product_event_type |
| Tag | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| UGFlags | additional.fields.key/value.string_value |
| User | target.user.userid |
| UserGroupFound | additional.fields.key/value.string_value |
| UserIdentifiedBySource | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
HIP 比對
下表列出 HIP 比對記錄類型的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| ConfigVersion | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EndpointDeviceName | principal.asset.hostname |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| HipMatchName | target.resource.attribute.labels |
| HipMatchType | target.resource.attribute.labels |
| HostID | principal.asset.asset_id |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | metadata.product_event_type |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Source | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceIP | principal.ip |
| SourceIPv6 | principal.ip |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| TimestampDeviceIdentification | principal.asset.first_seen_time |
| UUID | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
IP 標記
下表列出 IP 標記記錄類型的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| ConfigVersion | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EventID | additional.fields.key/value.string_value |
| IPSubnetRange | network.ip_subnet_range |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSetting | target.resource.attribute.labels |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MappingDataSource | additional.fields.key/value.string_value |
| MappingDataSourceSubType | additional.fields.key/value.string_value |
| MappingDataSourceType | additional.fields.key/value.string_value |
| MappingTimeout | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| RuleMatched | security_result.rule_name |
| RuleMatchedUUID | security_result.rule_id |
| SequenceNo | metadata.product_log_id |
| SourceIP | principal.ip |
| Subtype | metadata.product_event_type |
| TagName | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
解密
下表列出「解密」記錄類型的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| CertificateFlags | additional.fields.key/value.string_value |
| CertificateSerial | network.tls.server.certificate.serial |
| CertificateSize | additional.fields.key/value.string_value |
| CertificateVersion | network.tls.server.certificate.version |
| ChainStatus | additional.fields.key/value.string_value |
| ApplicationCharacteristics | additional.fields.key/value.string_value |
| ClientToFirewall | additional.fields.key/value.string_value |
| CommonName | additional.fields.key/value.string_value |
| CommonNameLength | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| Cpadding | additional.fields.key/value.string_value |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| Domain | target.hostname |
| EllipticCurve | network.tls.curve |
| ErrorIndex | additional.fields.key/value.string_value |
| ErrorMessage | additional.fields.key/value.string_value |
| Fingerprint | network.tls.server.certificate.md5/sha1/sha256 |
| FirewallToClient | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsCertECDSA | additional.fields.key/value.string_value |
| IsCertRSA | additional.fields.key/value.string_value |
| IsCertCNTruncated | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| IsForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsIssuerCNTruncated | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| IsNAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| PacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsResumeSession | additional.fields.key/value.string_value |
| IsRootCNTruncated | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSNITruncated | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| IssuerCommonName | network.tls.server.certificate.issuer |
| IssuerNameLength | additional.fields.key/value.string_value |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| TimeNotAfter | additional.fields.key/value.string_value |
| TimeNotBefore | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| Padding | additional.fields.key/value.string_value |
| Padding3 | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| PolicyName | additional.fields.key/value.string_value |
| Protocol | network.ip_protocol |
| ProxyType | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| RootCommonName | additional.fields.key/value.string_value |
| RootCNLength | additional.fields.key/value.string_value |
| RootStatus | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SessionID | network.session_id |
| ServerNameIndication | network.tls.client.server_name |
| SNILength | additional.fields.key/value.string_value |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeReceivedManagementPlane | additional.fields.key/value.string_value |
| TLSAuth | additional.fields.key/value.string_value |
| TLSEncryptionAlgorithm | additional.fields.key/value.string_value |
| TLSKeyExchange | additional.fields.key/value.string_value |
| TLSVersion | network.tls.version |
| ToZone | additional.fields.key/value.string_value |
| Tpadding | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| Vpadding | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
隧道
下表列出 Tunnel 記錄類型的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| AccessPointName | additional.fields.key/value.string_value |
| Action | security_result.action |
| ActionSource | additional.fields.key/value.string_value |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| BytesReceived | network.received_bytes |
| BytesSent | network.sent_bytes |
| Bytes | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| LoggingServiceID | additional.fields.key/value.string_value |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MobileAreaCode | additional.fields.key/value.string_value |
| MobileBaseStationCode | additional.fields.key/value.string_value |
| MobileCountryCode | additional.fields.key/value.string_value |
| MobileIP | additional.fields.key/value.string_value |
| MobileNetworkCode | additional.fields.key/value.string_value |
| MobileSubscriberISDN | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceDifferentiator | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsDroppedMax | additional.fields.key/value.string_value |
| PacketsDroppedStrict | additional.fields.key/value.string_value |
| PacketsDroppedTunnel | additional.fields.key/value.string_value |
| PacketsDroppedProtocol | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| ProtocolDataUnitsessionID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| RadioAccessTechnology | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionStartTime | additional.fields.key/value.string_value |
| SessionTracker | additional.fields.key/value.string_value |
| Severity | security_result.severity |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| StandardPortsOfApp | additional.fields.key/value.string_value |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| SessionDuration | network.session_duration |
| Tunnel | additional.fields.key/value.string_value |
| TunnelCauseCode | additional.fields.key/value.string_value |
| TunnelEndpointID1 | additional.fields.key/value.string_value |
| TunnelEndpointID2 | additional.fields.key/value.string_value |
| TunnelEventCode | additional.fields.key/value.string_value |
| TunnelEventType | additional.fields.key/value.string_value |
| TunnelInspectionRule | additional.fields.key/value.string_value |
| TunnelInterface | additional.fields.key/value.string_value |
| TunnelMessageType | additional.fields.key/value.string_value |
| TunnelRemoteIMSIID | additional.fields.key/value.string_value |
| TunnelRemoteUserIP | principal.ip |
| TunnelSessionsClosed | additional.fields.key/value.string_value |
| TunnelSessionsCreated | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLCategory | target.url_metadata.categories |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
驗證
下表列出「驗證」記錄類型的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| AuthenticationDescription | security_result.description |
| AuthEvent | metadata.description |
| AuthFactorNo | security_result.detection_fields.key/value |
| AuthenticationPolicy | security_result.detection_fields.key/value |
| AuthenticationProtocol | additional.fields.key/value.string_value |
| AuthServerProfile | additional.fields.key/value.string_value |
| AuthenticatedUserDomain | target.administrative_domain |
| AuthenticatedUserName | target.user.userid |
| AuthenticatedUserUUID | target.user.product_object_id |
| ClientType | additional.fields.key/value.string_value |
| ClientTypeName | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| Location | target.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogType | additional.fields.key/value.string_value |
| MFAAuthenticationID | additional.fields.key/value.string_value |
| MFAVendor | additional.fields.key/value.string_value |
| NormalizeUser | target.user.user_display_name |
| Object | target.resource.name |
| RuleMatched | security_result.rule_name |
| RuleMatchedUUID | security_result.rule_id |
| AuthCacheServiceRegion | additional.fields.key/value.string_value |
| SessionID | network.session_id |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceIP | principal.ip |
| TimeGenerated | metadata.event_timestamp |
| User | target.user.userid |
| UserAgentString | network.http.user_agent |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Subtype | metadata.product_event_type |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
網址
下表列出網址記錄類型的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| CloudHostname | additional.fields.key/value.string_value |
| CloudReportID | security_result.detection_fields.key/value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentType | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DirectionOfAttack | security_result.detection_fields.key/value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| FileURL | target.url |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HostID | principal.asset.asset_id |
| HTTP2Connection | network.application_protocol_version |
| HTTPHeaders | additional.fields.key/value.string_value |
| HTTPMethod | network.http.method |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| InlineMLVerdict | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| Packet | additional.fields.key/value.string_value |
| PacketID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| Referer | network.http.referral_url |
| HTTPRefererFQDN | additional.fields.key/value.string_value |
| HTTPRefererPort | additional.fields.key/value.string_value |
| HTTPRefererProtocol | additional.fields.key/value.string_value |
| HTTPRefererURLPath | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionID | network.session_id |
| Severity | security_result.severity |
| SigFlags | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URL | target.url_metadata.URL |
| URLCategory | target.url_metadata.categories |
| URLCategoryList | additional.fields.key/value.string_value |
| URLDomain | target.domain.name |
| URLCounter | additional.fields.key/value.string_value |
| UserAgent | network.http.user_agent |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-For | additional.fields.key/value.string_value |
| X-Forwarded-ForIP | principal.ip |
GlobalProtect
下表列出 GlobalProtect 記錄類型的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| AttemptedGateways | additional.fields.key/value.string_value |
| AuthMethod | extensions.auth.auth_details |
| ConnectionMethod | additional.fields.key/value.string_value |
| ConnectionErrorID | additional.fields.key/value.string_value |
| ConnectionError | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| EndpointDeviceName | principal.asset.hostname |
| GlobalProtectClientVersion | additional.fields.key/value.string_value |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointSN | principal.asset.hardware.serial_number |
| EventIDValue | additional.fields.key/value.string_value |
| Gateway | target.resource.name |
| GatewayPriority | additional.fields.key/value.string_value |
| GatewaySelectionType | additional.fields.key/value.string_value |
| GlobalProtectGatewayLocation | target.location.country_or_region |
| HostID | principal.asset.asset_id |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LoginDuration | network.session_duration |
| Description | security_result.description |
| Portal | target.hostname |
| PrivateIPv4 | principal.ip |
| PrivateIPv6 | principal.ip |
| ProjectName | additional.fields.key/value.string_value |
| PublicIPv4 | principal.nat_ip |
| PublicIPv6 | principal.nat_ip |
| QuarantineReason | security_result.summary |
| SequenceNo | metadata.product_log_id |
| SourceRegion | principal.location.country_or_region |
| SourceUserName | principal.user.user_display_name |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SSLResponseTime | additional.fields.key/value.string_value |
| Stage | additional.fields.key/value.string_value |
| EventStatus | additional.fields.key/value.string_value |
| LogSubtype | metadata.product_event_type |
| TunnelType | additional.fields.key/value.string_value |
| VirtualSystem | intermediary.asset.attribute.labels |
| VirtualSystemName | intermediary.asset.attribute.labels |
| EndpointOSVersion | principal.platform_version |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | metadata.product_event_type |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualSystemID | intermediary.resource.product_object_id |
SCTP
下表列出 SCTP 記錄類型的記錄欄位,以及對應的 UDM 欄位。
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| AssocationEndReason | additional.fields.key/value.string_value |
| ChunksReceived | additional.fields.key/value.string_value |
| ChunksSent | additional.fields.key/value.string_value |
| ChunksTotal | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceClass | target.asset.category |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationIP | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DiamAppID | additional.fields.key/value.string_value |
| DiamAvpCode | additional.fields.key/value.string_value |
| DiameterCommandCode | additional.fields.key/value.string_value |
| DiameterRequestFlag | additional.fields.key/value.string_value |
| DeviceName | principal.asset.hostname |
| SCTPEventType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLFiltering | additional.fields.key/value.string_value |
| IsWildfire | additional.fields.key/value.string_value |
| LogAction | additional.fields.key/value.string_value |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MapAppCode | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PayloadProtocolID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SccpCallingGt | additional.fields.key/value.string_value |
| SccpCallingSSN | additional.fields.key/value.string_value |
| SctpCauseCode | additional.fields.key/value.string_value |
| SctpChunkType | additional.fields.key/value.string_value |
| SctpFilter | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionTracker | additional.fields.key/value.string_value |
| Severity | security_result.severity |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceIP | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VerificationTag1 | additional.fields.key/value.string_value |
| VerificationTag2 | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
稽核
下表列出稽核記錄類型和對應 UDM 欄位的記錄檔欄位。
| Log field | UDM mapping |
|---|---|
| EventCategory | network.http.method |
| EventDescription | metadata.description |
| EventDestinationURL | target.url |
| EventDestinationUserUserID | target.user.userid |
| DestinationVendor | additional.fields.key/value.string_value |
| EventDetails | additional.fields.key/value.string_value |
| EventID | metadata.product_log_id |
| EventName | additional.fields.key/value.string_value |
| EventResult | security_result.summary |
| EventSourceUserUserID | principal.user.userid |
| EventTime | metadata.event_timestamp |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| Subtype | metadata.product_event_type |
| TSGID | additional.fields.key/value.string_value |
| Vendor | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
欄位對應參考資料:記錄類型至 UDM 事件類型
下表列出 Palo Alto Networks Strata Logging Service 防火牆記錄類型,以及對應的 UDM 事件類型。
| 記錄類型 | UDM 事件類型 |
| 流量 | NETWORK_CONNECTION |
| 威脅 | NETWORK_CONNECTION |
| 網址篩選 | NETWORK_CONNECTION |
| 通道 | NETWORK_CONNECTION |
| 系統 |
如果子類型值為「dhcp」,系統會設定 NETWORK_DHCP。 如果子類型值為「auth」,系統就會設定 USER_LOGIN。 如果說明值為「logged in」,系統就會設定 USER_LOGIN。 如果說明值為「logged out」,系統會設定 USER_LOGOUT。 如果子類型為其他值,系統會設定 GENERIC_EVENT。 |
| HIP Match | NETWORK_CONNECTION |
| IP 代碼 | GENERIC_EVENT |
| User-ID | USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED
如果子類型值為「login」,系統就會設定 USER_LOGIN。 如果子類型值為「logout」,系統會設定 USER_LOGOUT。 如果子類型不含任何值,系統會設定 USER_UNCATEGORIZED。 |
| 解密 | NETWORK_CONNECTION |
| 驗證 | STATUS_UNCATEGORIZED |
| Globalprotect | USER_LOGIN/USER_LOGOUT/USER_RESOURCE_ACCESS
如果子類型值為「auth」,系統會設定 USER_LOGIN。 如果子類型值為「logout」,系統會設定 USER_LOGOUT。 如果子類型不含任何值,系統會設定 USER_RESOURCE_ACCESS。 |
| SCTP | NETWORK_CONNECTION |
| 稽核 | NETWORK_CONNECTION |
後續步驟
還有其他問題嗎?向社群成員和 Google SecOps 專業人員尋求答案。