Recoger registros de cortafuegos de Palo Alto Networks
Firewall de Palo Alto Networks
Información general
En este documento se describe cómo puede configurar syslog y un reenviador de Google SecOps para recoger los registros del cortafuegos de Palo Alto Networks. En este documento también se explica cómo se asignan los campos de registro del cortafuegos de Palo Alto Networks a los campos del modelo de datos unificado (UDM) de Google SecOps. Para obtener una descripción general de la ingestión de datos en Google SecOps, consulta Ingestión de datos en Google SecOps. Una etiqueta de ingestión identifica el analizador que normaliza los datos de registro sin procesar en formato UDM estructurado. La información de este documento se aplica al analizador con la etiqueta de ingestión PAN_FIREWALL.
Antes de empezar
- Asegúrese de que el producto de cortafuegos de Palo Alto Networks se haya implementado y configurado correctamente. Para obtener instrucciones de configuración detalladas, consulta la documentación de PAN-OS.
Para comprender los componentes implementados para recoger los registros del cortafuegos de Palo Alto Networks, consulta la arquitectura de implementación. Cada implementación de cliente puede ser diferente de esta representación y puede ser más compleja. En el siguiente diagrama se muestra cómo puedes configurar syslog en un firewall de Palo Alto Networks e instalar un reenviador de Google SecOps en un servidor Linux para reenviar datos de registro a Google SecOps. El analizador admite registros escritos en los siguientes formatos de datos: valores separados por comas (CSV), formato de evento común (CEF) y formato de evento de registro extendido (LEEF).
Verifica los formatos de registro y las versiones de PAN-OS que admite el analizador de Google SecOps. En la siguiente tabla se indican los formatos de registro y las versiones de PAN-OS correspondientes que admite el analizador de Google SecOps:
Formato de registro Versión de PAN-OS CSV 10.1.3 CEF 10.0.0 LEEF 9.1.0 Verifica los tipos de registros de cortafuegos de Palo Alto Networks que admite el analizador de Google SecOps. El analizador de Google SecOps admite los siguientes tipos de registros de cortafuegos de Palo Alto Networks:
- Tráfico
- Amenaza
- Envíos de WildFire
- Inspección de túneles
- Configuración
- Sistema
- Coincidencia de HIP
- Etiqueta IP
- User-ID
- Desencriptado
- Autenticación
- Filtrado de URLs
- Filtrado de datos
- GlobalProtect
- Correlación
- GTP
- SCTP
- Auditoría
Para obtener más información sobre los tipos de registros de cortafuegos de Palo Alto Networks, consulta Tipos de registros de PAN-OS.
Asegúrate de que todos los sistemas de la arquitectura de implementación estén configurados en la zona horaria UTC.
Antes de usar el analizador de cortafuegos de Palo Alto Networks, consulta los cambios en las asignaciones de campos entre el analizador anterior y el actual. Como parte de la migración, asegúrate de que las reglas, las búsquedas, los paneles de control u otros procesos que dependan de los campos originales usen los campos actualizados.
Por ejemplo, en la versión anterior del analizador, el campo de registro
categoryse asigna al camposecurity_result.descriptionde UDM. En el analizador de cortafuegos de Palo Alto Networks actual, el campo de registrocategoryse asigna al camposecurity_result.category_detailsde UDM. Si migras al analizador de cortafuegos de Palo Alto Networks actual y usas el campocategoryen tus reglas, debes modificar las reglas para usar el camposecurity_result.category_detailsde UDM del analizador actual.
Configurar syslog y el reenviador de Google Security Operations
Para configurar syslog y el reenviador de SecOps de Google, sigue estos pasos:
- Para monitorizar los registros CSV, configura el perfil del servidor syslog. Para obtener más información, consulta Configurar el perfil del servidor syslog. Cuando configure el perfil del servidor syslog, especifique "Default" como formato de registro personalizado.
- Para monitorizar los registros de CEF, configure el cortafuegos de Palo Alto Networks para que reenvíe los registros de CEF. Para obtener más información, descarga la guía de integración de CEF de PAN-OS en PDF y consulta la sección "Configuration of Palo Alto Networks NGFW to output CEF events" (Configuración de Palo Alto Networks NGFW para generar eventos CEF).
- Para monitorizar los registros LEEF, configure el perfil del servidor syslog. Para obtener más información, consulta Reenvío de registros personalizados en formato LEEF.
Configura el reenviador de Google SecOps para enviar registros a Google Security Operations. Para obtener más información, consulta Instalar y configurar el reenviador en Linux. A continuación, se muestra un ejemplo de configuración de reenviador de Google SecOps:
- syslog: common: enabled: true data_type: PAN_FIREWALL batch_n_seconds: 10 batch_n_bytes: 1048576 tcp_address: 0.0.0.0:10518 connection_timeout_sec: 60
Configurar el reenvío de syslog en el cortafuegos de Palo Alto Networks
Crear un perfil de servidor syslog
- Inicia sesión en la consola de gestión de firewall de Palo Alto Networks.
- Ve a Dispositivo > Perfiles de servidor > Syslog.
- Haz clic en Añadir para crear un perfil de servidor.
- Proporcione los siguientes detalles de configuración:
- Nombre: introduce un nombre descriptivo (por ejemplo,
Google SecOps BindPlane). - Ubicación: selecciona el sistema virtual (vsys) o Compartido donde estará disponible este perfil.
- Nombre: introduce un nombre descriptivo (por ejemplo,
- Haz clic en Servidores > Añadir para configurar el servidor syslog.
- Proporcione los siguientes detalles de configuración del servidor:
- Nombre: introduce un nombre descriptivo para el servidor (por ejemplo,
BindPlane Agent). - Servidor Syslog: introduce la dirección IP del agente de BindPlane.
- Transporte: selecciona UDP o TCP, en función de la configuración de tu agente BindPlane (UDP es el valor predeterminado).
- Puerto: introduce el número de puerto del agente de BindPlane (por ejemplo,
514). - Formato: selecciona BSD (opción predeterminada) o IETF, según tus necesidades.
- Facility: selecciona LOG_USER (valor predeterminado) u otro valor si es necesario.
- Nombre: introduce un nombre descriptivo para el servidor (por ejemplo,
- Haga clic en Aceptar para guardar el perfil del servidor syslog.
Opcional: Configurar un formato de registro personalizado para CEF o LEEF
Si necesitas registros en formato de evento común (CEF) o en formato de evento de registro extendido (LEEF) en lugar de CSV, sigue estos pasos:
- En el perfil de servidor Syslog, selecciona la pestaña Formato de registro personalizado.
- Configura el formato de registro personalizado para cada tipo de registro (Config, System, Threat, Traffic, URL, Data, WildFire, Tunnel, Authentication, User-ID y HIP Match).
- Para obtener información sobre la configuración del formato CEF, consulta la guía de configuración de CEF de Palo Alto Networks.
- Haz clic en Aceptar para guardar la configuración.
Crear un perfil de reenvío de registros
- Vaya a Objetos > Reenvío de registros.
- Haga clic en Añadir para crear un perfil de reenvío de registros.
- Proporcione los siguientes detalles de configuración:
- Nombre: introduce un nombre de perfil (por ejemplo,
Google SecOps Forwarding). Si quieres que el cortafuegos asigne automáticamente este perfil a las nuevas reglas y zonas de seguridad, ponle el nombredefault.
- Nombre: introduce un nombre de perfil (por ejemplo,
- Para cada tipo de registro que quieras reenviar (Tráfico, Amenaza, Envío de WildFire, Filtrado de URLs, Filtrado de datos, Túnel y Autenticación), configura lo siguiente:
- Haz clic en Añadir en la sección del tipo de registro correspondiente.
- Syslog selecciona el perfil del servidor syslog que has creado (por ejemplo,
Google SecOps BindPlane). - Gravedad del registro: selecciona los niveles de gravedad que quieras reenviar (por ejemplo, Todos).
- Haga clic en Aceptar para guardar el perfil de reenvío de registros.
Aplicar un perfil de reenvío de registros a políticas de seguridad
- Ve a Políticas > Seguridad.
- Seleccione las reglas de seguridad para las que quiera habilitar el reenvío de registros.
- Haz clic en la regla para editarla.
- Ve a la pestaña Acciones.
- En el menú Reenvío de registros, selecciona el perfil de reenvío de registros que has creado (por ejemplo,
Google SecOps Forwarding). - Haz clic en Aceptar para guardar la configuración de la política de seguridad.
Configurar los ajustes de registro de los registros del sistema
- Ve a Dispositivo > Ajustes de registro.
- Para cada tipo de registro (System, Configuration, User-ID, HIP Match, Global Protect, IP-Tag y SCTP) y nivel de gravedad, seleccione el perfil de servidor syslog que haya creado.
- Haga clic en Aceptar para guardar la configuración del registro.
Confirmar los cambios
- En la parte superior de la interfaz web del cortafuegos, haga clic en Commit (Confirmar).
- Espera a que la confirmación se complete correctamente.
- Verifica que los registros se envían al agente de Bindplane comprobando si hay registros de firewall de Palo Alto Networks entrantes en la consola de Google SecOps.
Reenviar registros a Google SecOps mediante el agente Bindplane
- Instala y configura una máquina virtual Linux.
- Instala y configura el agente de Bindplane en Linux para reenviar registros a Google SecOps. Para obtener más información sobre cómo instalar y configurar el agente de Bindplane, consulta las instrucciones de instalación y configuración del agente de Bindplane.
Si tienes problemas al crear feeds, ponte en contacto con el equipo de Asistencia de SecOps de Google.
Formatos de registro admitidos
El analizador de cortafuegos de Palo Alto Networks admite registros en formato LEEF,CEF y CSV.
Registros de ejemplo admitidos
LEEF
<14>Jan 22 02:20:19 device_host LEEF:1.0|Palo Alto Networks|PAN-OS Syslog Integration|10.2.12-h4|Microsoft MSOFFICE(52033)|ReceiveTime=2025/01/22 02:20:18|SerialNumber=01250100xxxx|cat=THREAT|Subtype=wildfire|devTime=Jan 22 2025 08:20:18 GMT|src=198.50.100.1|dst=198.50.100.2|srcPostNAT=198.50.100.3|dstPostNAT=198.50.100.4|RuleName=AZURE-US-NEW-CNF_Inbound_To_Azure-ALLOW|usrName=|SourceUser=|DestinationUser=|Application=smtp-base|VirtualSystem=vsys1|SourceZone=McD-Global-Zone|DestinationZone=Azure-Zone|IngressInterface=ae1.111|EgressInterface=ae2.409|LogForwardingProfile=Default-Traffic-Logging|SessionID=35331795|RepeatCount=1|srcPort=21578|dstPort=25|srcPostNATPort=0|dstPostNATPort=0|Flags=0x2000|proto=tcp|action=allow|Miscellaneous=\"......3...................xls\"|ThreatID=Microsoft MSOFFICE(52033)|URLCategory=malicious|sev=4|Severity=high|Direction=client-to-server|sequence=7462614601465681755|ActionFlags=0x8000000000000000|SourceLocation=198.50.100.1-198.50.100.255|DestinationLocation=United States|ContentType=|PCAP_ID=0|FileDigest=0ea04c99bf188c2e4207f60f92ca7c6f5088c7943ee63f45c50032bbd2bf7ea9|Cloud=demo.com|URLIndex=1|RequestMethod=|FileType=ms-office|Sender=sender@ab.myownpersonaldomain.com|Subject=\"............:.................................................................................-.........(Name)-2025-01-22...............:Y107202501220005, ............:........................, ...............:.........\"|Recipient=abc@demo.myownpersonaldomain.com|ReportID=117022282776|DeviceGroupHierarchyL1=143|DeviceGroupHierarchyL2=144|DeviceGroupHierarchyL3=39|DeviceGroupHierarchyL4=0|vSrcName=|DeviceName=device_host|SrcUUID=|DstUUID=|TunnelID=0|MonitorTag=|ParentSessionID=0|ParentStartTime=|TunnelType=N/A|ThreatCategory=N/A|ContentVer=WildFire-0CEF
14>1 2024-04-04T16:21:56+02:00 FW-PERIMETRAL-AVG-01 - - - - CEF:0|Palo Alto Networks|PAN-OS|10.1.10-h2|end|TRAFFIC|1|src=198.51.100.1 dst=198.51.100.2 srcTranslatedAddress=198.51.100.3 dstTranslatedAddress=198.51.100.4 rule=FW_USER_NATS2_APP suser= duser= app=bittorrent vs=vsys1 sz=INSIDE dz=EXTERNAL InboundInterface=ae2.2266 OutboundInterface=ae1 lp=log_forwarding sid=2935823 cnt=1 spt=6881 dpt=51413 srcTranslatedPort=0 dstTranslatedPort=0 flags=0x7a proto=udp act=allow tbytes=475 in=150 out=325 pkt=2 pktReceived=1 pktSent=1 start=Apr 04 2024 14:21:56 GMT stime=1206 urlcat=any externalId=externalId reason=aged-out DGl1=11 DGl2=161 DGl3=0 DGl4=0 VsysName=STONESOFT dvchost=FW-PERIMETRAL-AVG-01 cat=from-policy ActionFlags=0x8000000000000000 srcUUID= dstUUID= TunnelID=0 MonitorTag= ParentSessionID=0 ParentStartTime= TunnelType=N/A SCTPAssocID=0 SCTPChunks=0 SCTPChunkSent=0 SCTPChunksRcv=0 RuleUUID=746c3eb6-3d51-4679-8438-bd0e00e170a8 HTTP2Con=0 LinkChange=0 PolicyID= LinkDetail= SDWANCluster= SDWANDevice= SDWANClustype= SDWANSite= DynamicUsrgrp= XFFIP= srcDevCat= srcDevProf= srcDevModel= srcDevVendor= srcDevOS= srcDevOSv= srcHostname= srcMac= dstDevCat= dstDevProf= dstDevModel= dstDevVendor= dstDevOS= dstDevOSv= dstHostname= dstMac= ContainerName= PODNamespace= PODName= srcEDL= dstEDL= GPHostID= EPSerial= srcDAG= dstDAG= HASessionOwner= TimeHighRes=2024-04-04T16:21:56.250+02:00 ASServiceType= ASServiceDiff="CSV
1,2021/10/24 15:30:07,,CONFIG,0,2561,2021/10/24 15:30:07,198.51.100.0,,set,admin,Web,Succeeded, network virtual-router VR1,,VR1 { ecmp { algorithm { ip-modulo ; } } protocol { bgp { routing-options { graceful-restart { enable yes; } } enable no; } rip { enable no; } ospf { enable no; } ospfv3 { enable no; } } routing-table { ip { static-route { vr1-log { path-monitor { enable no; failure-condition any; hold-time 2; } nexthop { ip-address 198.51.100.0; } bfd { profile None; } interface ethernet1/1; metric 10; destination 0.0.0.0/0; route-table { unicast ; } } } } } interface [ ethernet1/1 ethernet1/2 ]; } ,7022390503849066572,0x0,0,0,0,0,,PA-VM,0,
Referencia de la asignación de campos: campos de registro a campos de UDM
En esta sección se explica cómo asigna el analizador los campos de registro del firewall de Palo Alto Networks a los campos de evento de UDM de Google SecOps para cada tipo de registro. La clave de etiqueta de Google SecOps hace referencia al nombre de la clave asignada al campo UDM Labels.key.
Por ejemplo, en el caso del campo "Virtual System", el nombre del campo es "cs3" en formato CEF y "VirtualSystem" en formato LEEF. El campo de UDM "about.labels.key" contiene el valor "vsys" y el campo de UDM "about.labels.value" contiene el valor de ese campo. Algunos de los nombres de campo de CEF o LEEF no tienen un nombre correspondiente a los nombres de campo del archivo CSV. En estos casos, si añade su propio nombre de variable en el formato de registro personalizado del perfil de syslog, el analizador no lo asignará al campo UDM.
Consulta las siguientes secciones para obtener información sobre la asignación de cada tipo de registro:
- Sistema
- Configuración
- Amenaza o incendio forestal
- Tráfico
- ID de usuario
- Concordancia de HIP
- Etiqueta de IP
- Descifrado
- Túnel
- Autenticación
- URL
- Datos
- GlobalProtect
- Correlación
- GTP
- SCTP
- Auditoría
Sistema
En la siguiente tabla se enumeran los campos de registro del tipo de registro del sistema y sus campos de UDM correspondientes.
| Campo de CSV | Campo CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si no se incluye "Generate Time") |
|
| Número de serie (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | gato | metadata.product_event_type tiene el valor "%{type} - %{subtype}". | |
| Tipo de amenaza o contenido (subtipo) | Subtipo (encabezado) | Subtipo | metadata.product_event_type tiene el valor "%{type} - %{subtype}". | |
| Hora de generación (time_generated o cef-formatted-time_generated) | metadata.event_timestamp | |||
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| ID de evento (eventid) | gato | eventid | additional.fields.key y additional.fields.value.string_value | |
| Objeto (object) | fname | Nombre del archivo | objeto | target.resource.name |
| Módulo (module) | flexString2 | Módulo | module | additional.fields.key y additional.fields.value.string_value |
| Gravedad (severity) | $number-of-severity(header) | Gravedad | security_result.severity y security_result.severity_details | |
| Descripción (opaca) | msg | msg | metadata.description | |
| principal_user_userid (este campo se extrae del campo msg) | principal.user.userid | |||
| principal_ip3 (este campo se extrae del campo msg) | principal.ip | |||
| Motivo (este campo se extrae del campo msg) | security_result.description | |||
| server_address (este campo se extrae del campo msg). | target.ip | |||
| server_profile (este campo se extrae del campo msg) | additional.fields.key y additional.fields.value.string_value | |||
| Número de secuencia (seqno) | externalId | secuencia | metadata.product_log_id | |
| Marcas de acción (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_1 a dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value |
| Nombre del sistema virtual (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nombre del dispositivo (device_name) | dvchost | DeviceName | target.hostname | |
| Marca de tiempo de alta resolución (high_res_timestamp) | anOSTimeGeneratedHighResolution | additional.fields.key y additional.fields.value.string_value |
Configuración
En la siguiente tabla se enumeran los campos de registro del tipo de registro de configuración y sus campos de UDM correspondientes.
| Campo de CSV | Campo CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si no se incluye "Generate Time") |
|
| Número de serie (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | gato | metadata.product_event_type | |
| Tipo de amenaza o contenido (subtipo) | Subtipo (encabezado) | metadata.product_event_type | ||
| Hora de generación (time_generated o cef-formatted-time_generated) | metadata.event_timestamp | |||
| Host (host) | shost | src | principal.ip/hostname | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| Comando (cmd) | actuar | msg | cmd | principal.process.command_line |
| Administrador (admin) | duser | usrName | principal.user.userid | |
| Cliente (client) | destinationServiceName | client | principal.application | |
| Resultado (result) | ID de firma (encabezado)(motivo) | Resultado | security_result.summary | |
| Ruta de configuración (path) | msg | ConfigurationPath | principal.process.command_line | |
| Detalles del cambio anterior (before_change_detail) | cs1 | BeforeChangeDetail | before_change_detail | target.resource.attribute.labels.key/value |
| Detalle del cambio (after_change_detail) | cs2 | AfterChangeDetail | after_change_detail | target.resource.attribute.labels.key/value |
| Número de secuencia (seqno) | externalId | secuencia | metadata.product_log_id | |
| Marcas de acción (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_1 a dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value |
| Nombre del sistema virtual (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nombre del dispositivo (device_name) | dvchost | DeviceName | target.hostname | |
| Grupo de dispositivos (dg_id) | PanOSFWDeviceGroup | target.asset.attribute.labels.key/value | dg_id | principal.asset.attribute.labels.key/value |
| Comentario de auditoría (comment) | PanOSPolicyAuditComment | comentario | additional.fields.key y additional.fields.value.string_value | |
| Marca de tiempo de alta resolución (high_res_timestamp) | additional.fields.key y additional.fields.value.string_value | |||
| Gravedad (severity) | number-of-severity(header) | security_result.severity y security_result.severity_details |
Threat/WildFire
En la tabla siguiente se enumeran los campos de registro del tipo de registro Threat/WildFire y sus campos de UDM correspondientes.
| Campo de CSV | Campo CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si no se incluye "Generate Time") |
|
| Número de serie | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | gato | metadata.product_event_type | |
| Tipo de amenaza o contenido (subtipo) | cat/subtype (encabezado) | Subtipo | metadata.product_event_type | |
| Hora de generación (time_generated o cef-formatted-time_generated) | metadata.event_timestamp | |||
| Dirección de origen (src) | src | src | principal.ip | |
| Dirección de destino (dst) | dst | dst | target.ip | |
| IP de origen de NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP de destino de NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Nombre de la regla | cs1 | RuleName | security_result.rule_name | |
| Usuario de origen (srcuser) | suser | SourceUser/usrName | principal.user.userid | |
| Usuario de destino (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplicación | aplicación | Aplicación | target.application | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona de origen (desde) | cs4 | SourceZone | de | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Zona de destino | cs5 | DestinationZone | a | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
| Interfaz de entrada (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Interfaz de salida (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
| Registrar acción (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key y additional.fields.value.string_value |
| ID de sesión (sessionid) | cn1 | SessionID | network.session_id | |
| Número de repeticiones (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key y additional.fields.value.string_value |
| Puerto de origen (sport) | spt | srcPort | principal.port | |
| Puerto de destino (dport) | dpt | dstPort | target.port | |
| Puerto de origen de NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Puerto de destino de NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Marcas (flags) | flexString1 | Banderas | flags | additional.fields.key y additional.fields.value.string_value |
| Protocolo IP (proto) | proto | proto | network.ip_protocol | |
| Acción (action) | actuar | acción | security_result.action_details
security_result.action |
|
| URL/Nombre de archivo (varios) | solicitud | Varios | target.file.names (si subtype es "file", "virus", "wildfire-virus" o "wildfire", el campo `misc` se asigna a target.file.names) target.url (si el subtipo es "url", el campo `misc` se asigna a target.url y target.hostname) |
|
| Nombre de la amenaza o del contenido (threatid) | gato | ThreatID | security_result.threat_name | |
| Categoría (category) | cs2 | URLCategory | security_result.category_details | |
| Gravedad (severity) | number-of-severity(header) | Gravedad | security_result.severity y security_result.severity_details | |
| Dirección (direction) | flexString2 | Dirección | network.direction | |
| Número de secuencia (seqno) | externalId | secuencia | metadata.product_log_id | |
| Marcas de acción (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value |
| País de origen (srcloc) | SourceLocation | principal.location.country_or_region | ||
| País de destino (dstloc) | DestinationLocation | target.location.country_or_region | ||
| Tipo de contenido (contenttype) | ContentType | contenttype | additional.fields.key y additional.fields.value.string_value | |
| ID de PCAP (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key y additional.fields.value.string_value |
| Resumen de archivo (filedigest) | fileHash | FileDigest | target.file.sha1/md5/sha256 | |
| Cloud (cloud) | filePath | Nube | nube | additional.fields.key y additional.fields.value.string_value |
| Índice de URLs (url_idx) | URLIndex | url_idx | additional.fields.key y additional.fields.value.string_value | |
| User-agent (user_agent) | network.http.user_agent | |||
| Tipo de archivo (filetype) | fileType | FileType | target.file.mime_type | |
| X-Forwarded-For (xff) | principal.ip | |||
| Referente (referer) | network.http.referral_url | |||
| Remitente (sender) | suid | Remitente | network.email.from | |
| Asunto (subject) | msg | Asunto | network.email.subject | |
| Destinatario | duid | Destinatario | network.email.to | |
| ID de informe (reportid) | oldFileId | ReportID | reportid | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_1 a dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value |
| Nombre del sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nombre del dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| UUID de VM de origen (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id | |
| UUID de la VM de destino (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id | |
| Método HTTP (http_method) | RequestMethod | network.http.method | ||
| ID de túnel/IMSI (tunnel_id/imsi) | PanOSTunnelID | TunnelID | tunnel_id/imsi | additional.fields.key y additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag/imei) | PanOSMonitorTag | MonitorTag | monitortag/imei | additional.fields.key y additional.fields.value.string_value |
| ID de sesión principal (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Hora de inicio de la sesión principal (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key y additional.fields.value.string_value |
| Tipo de túnel (tunnel) | PanOSTunnelType | TunnelType | túnel | additional.fields.key y additional.fields.value.string_value |
| Categoría de amenaza (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| Versión del contenido (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key y additional.fields.value.string_value |
| ID de asociación SCTP (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key y additional.fields.value.string_value | |
| ID de protocolo de carga útil (ppid) | PanOSPPID | ppid | additional.fields.key y additional.fields.value.string_value | |
| Encabezados HTTP (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Lista de categorías de URLs (url_category_list) | PanOSURLCatList | url_category_list | additional.fields.key y additional.fields.value.string_value | |
| UUID de la regla (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| Conexión HTTP/2 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| Nombre del grupo de usuarios dinámico (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Dirección XFF (xff_ip) | PanXFFIP | principal.ip | ||
| Categoría del dispositivo de origen (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Perfil del dispositivo de origen (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Modelo del dispositivo de origen (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Proveedor del dispositivo de origen (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Familia del SO del dispositivo de origen (src_osfamily) | PanSrcDeviceOS | src_osfamily | principal.platform | |
| Versión del SO del dispositivo de origen (src_osversion) | PanSrcDeviceOSv | principal.platform_version | ||
| Nombre de host de origen (src_host) | PanSrcHostname | principal.hostname | ||
| Dirección MAC de origen (src_mac) | PanSrcMac | principal.mac | ||
| Categoría del dispositivo de destino (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Perfil de dispositivo de destino (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Modelo del dispositivo de destino (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Proveedor del dispositivo de destino (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Familia del SO del dispositivo de destino (dst_osfamily) | PanDstDeviceOS | dst_osfamily | target.platform | |
| Versión del SO del dispositivo de destino (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Nombre de host de destino (dst_host) | PanDstHostname | target.hostname | ||
| Dirección MAC de destino (dst_mac) | PanDstMac | target.mac | ||
| ID de contenedor (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| Espacio de nombres de POD (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| Nombre del POD (pod_name) | PanPODName | pod_name | target.resource.name | |
| Lista dinámica externa de origen (src_edl) | PanSrcEDL | src_edl | additional.fields.key y additional.fields.value.string_value | |
| Lista dinámica externa de destino (dst_edl) | PanDstEDL | dst_edl | additional.fields.key y additional.fields.value.string_value | |
| ID de host (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Número de serie del dispositivo del usuario (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| EDL de dominio (domain_edl) | PanDomainEDL | domain_edl | additional.fields.key y additional.fields.value.string_value | |
| Grupo de direcciones dinámicas de origen (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Grupo de direcciones dinámicas de destino (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| Hash parcial (partial_hash) | PanPartialHash | partial_hash | additional.fields.key y additional.fields.value.string_value | |
| Marca de tiempo de alta resolución (high_res timestamp) | PanTimeHighRes | Marca de tiempo de alta resolución | additional.fields.key y additional.fields.value.string_value | |
| Motivo (reason) | PanReasonFilteringAction | reason | security_result.summary | |
| Justificación (justification) | PanJustification | justificación | additional.fields.key y additional.fields.value.string_value | |
| Un tipo de servicio de segmento (nssai_sst) | PanASServiceType | nssai_sst | additional.fields.key y additional.fields.value.string_value | |
| Subcategoría de la aplicación (subcategory_of_app) | subcategory_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Categoría de la aplicación (category_of_app) | category_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Tecnología de la aplicación (technology_of_app) | technology_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Riesgo de la aplicación (risk_of_app) | risk_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Característica de la aplicación (characteristic_of_app) | characteristic_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Contenedor de aplicaciones (container_of_app) | container_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Aplicación SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Aplicación tunelizada (tunneled_app) | additional.fields.key y additional.fields.value.string_value | |||
| Tipo de flujo (flow_type) | additional.fields.key y additional.fields.value.string_value | |||
| Nombre del clúster (cluster_name) | intermediary.resource.name | |||
| Estado de sanción de la aplicación (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key y additional.fields.value.string_value |
Tráfico
En la siguiente tabla se enumeran los campos de registro del tipo de registro de tráfico y sus campos de UDM correspondientes.
| Campo de CSV | Campo CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si no se incluye "Generate Time") |
|
| Número de serie (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | cat/Type | metadata.product_event_type | |
| Tipo de amenaza o contenido (subtipo) | Subtipo (encabezado) | Subtipo | metadata.product_event_type | |
| Hora de generación (time_generated o cef-formatted-time_generated) | start | metadata.event_timestamp | ||
| Dirección de origen (src) | src | src | principal.ip | |
| Dirección de destino (dst) | dst | dst | target.ip | |
| IP de origen de NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP de destino de NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Nombre de la regla | cs1 | RuleName | security_result.rule_name | |
| Usuario de origen (srcuser) | suser | SourceUser | principal.user.userid | |
| Usuario de destino (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplicación | aplicación | Aplicación | target.application | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona de origen (desde) | cs4 | SourceZone | de | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Zona de destino | cs5 | DestinationZone | a | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
| Interfaz de entrada (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Interfaz de salida (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
| Registrar acción (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key y additional.fields.value.string_value |
| ID de sesión (sessionid) | cn1 | SessionID | network.session_id | |
| Número de repeticiones (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key y additional.fields.value.string_value |
| Puerto de origen (sport) | spt | srcPort | principal.port | |
| Puerto de destino (dport) | dpt | dstPort | target.port | |
| Puerto de origen de NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Puerto de destino de NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Marcas (flags) | flexString1 | Banderas | flags | additional.fields.key y additional.fields.value.string_value |
| Protocolo IP (proto) | proto | proto | network.ip_protocol | |
| Acción (action) | actuar | acción | security_result.action_details
security_result.action |
|
| Bytes (bytes) | flexNumber1 | totalBytes | bytes | additional.fields.key y additional.fields.value.string_value |
| Bytes enviados (bytes_sent) | está en | srcBytes | network.sent_bytes | |
| Bytes recibidos (bytes_received) | out | dstBytes | network.received_bytes | |
| Paquetes | cn2 | totalPackets | paquetes | additional.fields.key y additional.fields.value.string_value |
| Hora de inicio (start) | StartTime | start | additional.fields.key y additional.fields.value.string_value | |
| Tiempo transcurrido (elapsed) | cn3 | ElapsedTime | transcurrido | network.session_duration.seconds |
| Categoría (category) | cs2 | URLCategory | security_result.category/security_result.category_details | |
| Número de secuencia (seqno) | externalId | secuencia | metadata.product_log_id | |
| Marcas de acción (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value |
| País de origen (srcloc) | SourceLocation | principal.location.country_or_region | ||
| País de destino (dstloc) | DestinationLocation | target.location.country_or_region | ||
| Paquetes enviados (pkts_sent) | PanOSPacketsSent | srcPackets | pkts_sent | network.sent_packets |
| Paquetes recibidos (pkts_received) | PanOSPacketsReceived | dstPackets | pkts_received | network.received_packets |
| Motivo de finalización de la sesión (session_end_reason) | reason | SessionEndReason | security_result.summary | |
| Jerarquía de grupos de dispositivos 1 (dg_hier_level_1 a dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos 2 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos 3 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value |
| Nombre del sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nombre del dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| Fuente de la acción (action_source) | gato | ActionSource | action_source | additional.fields.key y additional.fields.value.string_value |
| UUID de VM de origen (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id | |
| UUID de la VM de destino (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id | |
| ID de túnel/IMSI (tunnelid/imsi) | PanOSTunnelID | TunnelID | tunnelid/imsi | additional.fields.key y additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag/imei) | PanOSMonitorTag | MonitorTag | monitortag/imei | additional.fields.key y additional.fields.value.string_value |
| ID de sesión principal (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Hora de inicio de la actividad principal (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key y additional.fields.value.string_value |
| Tipo de túnel (tunnel) | PanOSTunnelType | TunnelType | túnel | additional.fields.key y additional.fields.value.string_value |
| ID de asociación SCTP (assoc_id) | PanOSSCTPAssocID | assoc_id | additional.fields.key y additional.fields.value.string_value | |
| Bloques SCTP (chunks) | PanOSSCTPChunks | fragmentos | additional.fields.key y additional.fields.value.string_value | |
| Fragmentos SCTP enviados (chunks_sent) | PanOSSCTPChunkSent | chunks_sent | additional.fields.key y additional.fields.value.string_value | |
| Bloques SCTP recibidos (chunks_received) | PanOSSCTPChunksRcv | chunks_received | additional.fields.key y additional.fields.value.string_value | |
| UUID de la regla (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| Conexión HTTP/2 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| Número de veces que se ha mostrado la aplicación (link_change_count) | PanLinkChange | link_change_count | additional.fields.key y additional.fields.value.string_value | |
| ID de política (policy_id) | PanPolicyID | policy_id | additional.fields.key y additional.fields.value.string_value | |
| Interruptores de enlace (link_switches) | PanLinkDetail | link_switches | additional.fields.key y additional.fields.value.string_value | |
| Clúster de SD-WAN (sdwan_cluster) | PanSDWANCluster | sdwan_cluster | additional.fields.key y additional.fields.value.string_value | |
| Tipo de dispositivo SD-WAN (sdwan_device_type) | PanSDWANDevice | sdwan_device_type | additional.fields.key y additional.fields.value.string_value | |
| Tipo de clúster de SD-WAN (sdwan_cluster_type) | PanSDWANClustype | sdwan_cluster_type | additional.fields.key y additional.fields.value.string_value | |
| Sitio de SD-WAN (sdwan_site) | PanSDWANSite | sdwan_site | additional.fields.key y additional.fields.value.string_value | |
| Nombre del grupo de usuarios dinámico (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | additional.fields.key y additional.fields.value.string_value | |
| Dirección XFF (xff_ip) | PanXFFIP | principal.ip | ||
| Categoría del dispositivo de origen (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Perfil del dispositivo de origen (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Modelo del dispositivo de origen (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Proveedor del dispositivo de origen (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Familia del SO del dispositivo de origen (src_osfamily) | PanSrcDeviceOS | principal.platform | ||
| Versión del SO del dispositivo de origen (src_osversion) | PanSrcDeviceOSv | principal.asset.software.version | ||
| Nombre de host de origen (src_host) | PanSrcHostname | principal.hostname | ||
| Dirección MAC de origen (src_mac) | PanSrcMac | principal.mac | ||
| Categoría del dispositivo de destino (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Perfil de dispositivo de destino (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Modelo del dispositivo de destino (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Proveedor del dispositivo de destino (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Familia del SO del dispositivo de destino (dst_osfamily) | PanDstDeviceOS | dst_osfamily | target.platform | |
| Versión del SO del dispositivo de destino (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Nombre de host de destino (dst_host) | PanDstHostname | target.hostname | ||
| Dirección MAC de destino (dst_mac) | PanDstMac | target.mac | ||
| ID de contenedor (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| Espacio de nombres de POD (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| Nombre del POD (pod_name) | PanPODName | pod_name | target.resource.name | |
| Lista dinámica externa de origen (src_edl) | PanSrcEDL | src_edl | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Lista dinámica externa de destino (dst_edl) | PanDstEDL | dst_edl | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
|
| ID de host (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Número de serie del dispositivo del usuario (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| Grupo de direcciones dinámicas de origen (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Grupo de direcciones dinámicas de destino (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| Propietario de la sesión (session_owner) | PanHASessionOwner | session_owner | additional.fields.key y additional.fields.value.string_value | |
| Marca de tiempo de alta resolución (high_res_timestamp) | PanTimeHighRes | additional.fields.key y additional.fields.value.string_value | ||
| Un tipo de servicio de segmento (nsdsai_sst) | PanASServiceType | nsdsai_sst | additional.fields.key y additional.fields.value.string_value | |
| Un diferenciador de segmento (nsdsai_sd) | PanASServiceDiff | nsdsai_sd | additional.fields.key y additional.fields.value.string_value | |
| Subcategoría de la aplicación (subcategory_of_app) | subcategory_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Categoría de la aplicación (category_of_app) | category_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Tecnología de la aplicación (technology_of_app) | technology_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Riesgo de la aplicación (risk_of_app) | security_result.severity | |||
| Característica de la aplicación (characteristic_of_app) | characteristic_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Contenedor de aplicaciones (container_of_app) | container_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Aplicación SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Estado de sanción de la aplicación (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Subcategoría de la aplicación (subcategory_of_app) | subcategory_of_app1 | additional.fields.key y additional.fields.value.string_value | ||
| Gravedad (severity) | number-of-severity(header) | security_result.severity y security_result.severity_details |
User-ID
En la siguiente tabla se enumeran los campos de registro del tipo de registro user-id y sus campos de UDM correspondientes.
| Campo de CSV | Campo CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si no se incluye "Generate Time") |
|
| Número de serie (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | gato | metadata.product_event_type | |
| Tipo de amenaza o contenido (subtipo) | Subtipo (encabezado) | Subtipo | metadata.product_event_type | |
| Hora de generación (time_generated o cef-formatted-time_generated) | metadata.event_timestamp | |||
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| IP de origen (ip) | src | src | principal.ip | |
| Usuario (user) | duser | usrName | target.user.userid
target.administrative_domain target.user.email_addresses |
|
| Nombre de la fuente de datos (datasourcename) | cs4 | DataSourceName | datasourcename | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| ID de evento (eventid) | EventID | eventid | additional.fields.key y additional.fields.value.string_value | |
| Número de repeticiones (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key y additional.fields.value.string_value |
| Umbral de tiempo de espera (timeout) | cn3 | TimeoutThreshold | Tiempo de espera | additional.fields.key y additional.fields.value.string_value |
| Puerto de origen (beginport) | spt | srcPort | principal.port | |
| Puerto de destino (endport) | dpt | dstPort | target.port | |
| Fuente de datos (datasource) | cs5 | DataSource | fuente de datos | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Tipo de fuente de datos (datasourcetype) | cs6 | DataSourceType | datasourcetype | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Número de secuencia (seqno) | externalId | secuencia | metadata.product_log_id | |
| Marcas de acción (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value |
| Nombre del sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nombre del dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| ID de sistema virtual (vsys_id) | cn2 | VirtualSystemID | intermediary.resource.product_object_id | |
| Tipo de factor (factortype) | cs1 | FactorType | factortype | additional.fields.key y additional.fields.value.string_value |
| Tiempo de finalización del factor (factorcompletiontime) | fin | FactorCompletionTime | factorcompletiontime | additional.fields.key y additional.fields.value.string_value |
| Número de factor (factorno) | cn1 | FactorNumber | factorno | additional.fields.key y additional.fields.value.string_value |
| Marcas de grupos de usuarios (ugflags) | PanOSUGFlags | ugflags | additional.fields.key y additional.fields.value.string_value | |
| Usuario por fuente (userbysource) | PanOSUserBySource | target.user.userid
target.administrative_domain target.user.email_addresses |
||
| Marca de tiempo de alta resolución (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key y additional.fields.value.string_value | ||
| Fuente de datos de origen (origindatasource) | additional.fields.key y additional.fields.value.string_value | |||
| Nombre del clúster (cluster_name) | principal.resource.name | |||
| Gravedad (severity) | number-of-severity(header) | security_result.severity y security_result.severity_details |
Coincidencia de HIP
En la siguiente tabla se enumeran los campos de registro del tipo de registro de coincidencias de historial de IPs y sus campos de UDM correspondientes.
| Campo de CSV | Campo CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si no se incluye "Generate Time") |
|
| Número de serie (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | gato | metadata.product_event_type | |
| Tipo de amenaza o contenido (subtipo) | Subtipo (encabezado) | Subtipo | ||
| Hora de generación (time_generated o cef-formatted-time_generated) | start | startTime | metadata.event_timestamp | |
| Usuario de origen (srcuser) | suser | usrName | principal.user.userid | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| Nombre del equipo (machinename) | shost | identHostName | principal.hostname | |
| Sistema operativo | cs2 | SO | principal.asset.platform_software.platform | |
| Dirección de origen (src) | src | identsrc | principal.ip | |
| HIP (matchname) | gato | HIP | matchname | target.resource.attribute.labels.key/value additional.fields.key y additional.fields.value.string_value |
| Número de repeticiones (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key y additional.fields.value.string_value |
| Tipo de HIP (matchtype) | ID de clase de evento del dispositivo (encabezado) | HIPType | matchtype | target.resource.attribute.labels.key/value additional.fields.key y additional.fields.value.string_value |
| Número de secuencia (seqno) | externalId | secuencia | metadata.product_log_id | |
| Marcas de acción (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value |
| Nombre del sistema virtual (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nombre del dispositivo (device_name) | dvchost | DeviceName | target.hostname | |
| ID de sistema virtual (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id | |
| Dirección del sistema IPv6 (srcipv6) | c6a2 | srcipv6 | principal.asset.ip | |
| ID de host (hostid) | PanOSHostID | principal.asset.asset_id | ||
| Número de serie del dispositivo del usuario (serialnumber) | PanOSEndpointSerialNumber | principal.asset.hardware.serial_number | ||
| Dirección MAC del dispositivo (mac) | PanOSEndpointMac | principal.asset.mac | ||
| Marca de tiempo de alta resolución (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key y additional.fields.value.string_value | ||
| Nombre del clúster (cluster_name) | principal.resource.name | |||
| Gravedad (severity) | number-of-severity(header) | security_result.severity y security_result.severity_details |
Etiqueta de IP
En la siguiente tabla se enumeran los campos de registro del tipo de registro de etiquetas de IP y sus campos de UDM correspondientes.
| Campo de CSV | Campo CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si no se incluye "Generate Time") |
|
| Número de serie (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | gato | metadata.product_event_type | |
| Tipo de amenaza o contenido (subtipo) | Subtipo (encabezado) | Subtipo | metadata.product_event_type | |
| Hora de generación (time_generated o cef-formatted-time_generated) | GenerateTime | metadata.event_timestamp | ||
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| IP de origen (ip) | src | src | principal.ip | |
| Nombre de la etiqueta (tag_name) | PanOSTagName | TagName | tag_name | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| ID de evento (event_id) | PanOSEventID | EventID | event_id | additional.fields.key y additional.fields.value.string_value |
| Número de repeticiones (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key y additional.fields.value.string_value |
| Tiempo de espera (timeout) | PanOSTimeout | TimeoutThreshold | Tiempo de espera | additional.fields.key y additional.fields.value.string_value |
| Nombre de la fuente de datos (datasourcename) | PanOSDataSourceName | DataSourceName | datasourcename | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Tipo de fuente de datos (datasource_type) | PanOSDataSourceType | DataSource | datasource_type | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Subtipo de fuente de datos (datasource_subtype) | PanOSDataSourceSubType | DataSourceType | datasource_subtype | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Número de secuencia (seqno) | externalId | secuencia | metadata.product_log_id | |
| Marcas de acción (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value |
| Nombre del sistema virtual (vsys_name) | PanOsVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nombre del dispositivo (device_name) | dvchost | DeviceName | target.hostname | |
| ID de sistema virtual (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id | |
| Marca de tiempo de alta resolución (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key y additional.fields.value.string_value | ||
| Gravedad (severity) | number-of-severity(header) | security_result.severity y security_result.severity_details | ||
| Nombre del clúster (cluster_name) | principal.resource.name |
Desencriptado
En la siguiente tabla se enumeran los campos de registro del tipo de registro de descifrado y sus campos de UDM correspondientes.
| Campo de CSV | Campo CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | rt | metadata.collected_timestamp,
metadata.event_timestamp (si no se incluye "Generate Time") |
||
| Número de serie (serial) | PanOSDeviceSN | intermediary.asset.hardware.serial_number | ||
| Tipo (type) | type (Header) | metadata.product_event_type | ||
| Tipo de amenaza o contenido (subtipo) | Subtipo (encabezado) | metadata.product_event_type | ||
| Versión de configuración (config_ver) | PanOSConfigVersion | config_ver | additional.fields.key y additional.fields.value.string_value | |
| Hora de generación (time_generated) | PanOSLogTimeStamp | metadata.event_timestamp | ||
| Dirección de origen (src) | src | principal.ip | ||
| Dirección de destino (dst) | dst | target.ip | ||
| IP de origen de NAT (natsrc) | sourceTranslatedAddress | principa.nat_ip | ||
| IP de destino de NAT (natdst) | destinationTranslatedAddress | target.nat_ip | ||
| Rule (regla) | cs1 | security_result.rule_name | ||
| Usuario de origen (srcuser) | suser | principal.user.userid | ||
| Usuario de destino (dstuser) | duser | target.user.userid | ||
| Aplicación | aplicación | network.application_protocol | ||
| Sistema virtual (vsys) | cs3 | vsys | intermediary.asset.attribute.labels.key/value | |
| Zona de origen (desde) | cs4 | de | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Zona de destino | cs5 | a | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Interfaz de entrada (inbound_if) | deviceInboundInterface | inbound_if | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Interfaz de salida (outbound_if) | deviceOutboundInterface | outbound_if | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Registrar acción (logset) | cs6 | logset | additional.fields.key y additional.fields.value.string_value | |
| Hora registrada (time_received) | PanOSTimeReceivedManagementPlane | - | ||
| ID de sesión (sessionid) | cn1 | network.session_id | ||
| Número de repeticiones (repeatcnt) | PanOSCountOfRepeats/RepeatCount | repeatcnt | additional.fields.key y additional.fields.value.string_value | |
| Puerto de origen (sport) | spt | principal.port | ||
| Puerto de destino (dport) | dpt | target.port | ||
| Puerto de origen de NAT (natsport) | sourceTranslatedPort | principal.nat_port | ||
| Puerto de destino de NAT (natdport) | destinationTranslatedPort | target.nat_port | ||
| Marcas (flags) | flexString1 | flags | additional.fields.key y additional.fields.value.string_value | |
| Protocolo IP (proto) | proto | network.ip_protocol | ||
| Acción (action) | actuar | security_result.action_details
security_result.action |
||
| Túnel | PanOSTunnel | túnel | additional.fields.key y additional.fields.value.string_value | |
| UUID de VM de origen (src_uuid) | PanOSSourceUUID | principal.asset.product_object_id | ||
| UUID de la VM de destino (dst_uuid) | PanOSDestinationUUID | target.asset.product_object_id | ||
| UUID de la regla (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| Fase de cliente a firewall (hs_stage_c2f) | PanOSClientToFirewall | hs_stage_c2f | additional.fields.key y additional.fields.value.string_value | |
| Fase de cortafuegos a servidor (hs_stage_f2s) | PanOSFirewallToServer | hs_stage_f2s | additional.fields.key y additional.fields.value.string_value | |
| Versión de TLS (tls_version) | PanOSTLSVersion | network.tls.version | ||
| Algoritmo de intercambio de claves (tls_keyxchg) | PanOSTLSKeyExchange | tls_keyxchg | additional.fields.key y additional.fields.value.string_value | |
| Algoritmo de cifrado (tls_enc) | PanOSTLSEncryptionAlgorithm | tls_enc | additional.fields.key y additional.fields.value.string_value | |
| Algoritmo hash (tls_auth) | PanOSTLSAuth | tls_auth | additional.fields.key y additional.fields.value.string_value | |
| Nombre de la política (policy_name) | PanOSPolicyName | policy_name | additional.fields.key y additional.fields.value.string_value | |
| Curva elíptica (ec_curve) | PanOSEllipticCurve | network.tls.curve | ||
| Índice de errores (err_index) | PanOSErrorIndex | err_index | additional.fields.key y additional.fields.value.string_value | |
| Estado de la raíz (root_status) | PanOSRootStatus | root_status | additional.fields.key y additional.fields.value.string_value | |
| Estado de la cadena (chain_status) | PanOSChainStatus | chain_status | additional.fields.key y additional.fields.value.string_value | |
| Tipo de proxy (proxy_type) | PanOSProxyType | proxy_type | additional.fields.key y additional.fields.value.string_value | |
| Número de serie del certificado (cert_serial) | PanOSCertificateSerial | network.tls.server.certificate.serial | ||
| Huella digital del certificado (huella digital) | PanOSFingerprint | network.tls.server.certificate.md5/sha1/sha256 | ||
| Fecha de inicio del certificado (notbefore) | PanOSTimeNotBefore | network.tls.server.certificate.not_before | ||
| Fecha de finalización del certificado (notafter) | PanOSTimeNotAfter | network.tls.server.certificate.not_after | ||
| Versión del certificado (cert_ver) | PanOSCertificateVersion | network.tls.server.certificate.version | ||
| Tamaño del certificado (cert_size) | PanOSCertificateSize | cert_size | additional.fields.key y additional.fields.value.string_value | |
| Longitud del nombre común (cn_len) | PanOSCommonNameLength | cn_len | additional.fields.key y additional.fields.value.string_value | |
| Longitud del nombre común del emisor (issuer_len) | PanOSIssuerNameLength | issuer_len | additional.fields.key y additional.fields.value.string_value | |
| Longitud del nombre común raíz (rootcn_len) | PanOSRootCNLength | rootcn_len | additional.fields.key y additional.fields.value.string_value | |
| Longitud de SNI (sni_len) | PanOSSNILength | sni_len | additional.fields.key y additional.fields.value.string_value | |
| Marcas de certificado (cert_flags) | PanOSCertificateFlags | cert_flags | additional.fields.key y additional.fields.value.string_value | |
| Nombre común del sujeto (cn) | PanOSCommonName | cn | additional.fields.key y additional.fields.value.string_value | |
| Nombre común de la entidad emisora (issuer_cn) | PanOSIssuerCommonName | network.tls.server.certificate.issuer | ||
| Nombre común de la raíz (root_cn) | PanOSRootCommonName | root_cn | additional.fields.key y additional.fields.value.string_value | |
| Indicador del nombre del servidor
(sni) |
network.tls.client.server_name | |||
| Error (error) | PanOSErrorMessage | error | additional.fields.key y additional.fields.value.string_value | |
| ID de contenedor (container_id) | PanOSContainerID | container_id | intermediary.resource.product_object_id | |
| Espacio de nombres de POD (pod_namespace) | PanOSContainerNameSpace | pod_namespace | target.resource.attribute.labels.key/value additional.fields.key y additional.fields.value.string_value |
|
| Nombre del POD (pod_name) | PanOSContainerName | pod_name | target.resource.name | |
| Lista dinámica externa de origen (src_edl) | PanOSSourceEDL | src_edl | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Lista dinámica externa de destino (dst_edl) | PanOSDestinationEDL | dst_edl | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Grupo de direcciones dinámicas de origen (src_dag) | PanOSSourceDynamicAddressGroup | principal.group.group_display_name | ||
| Grupo de direcciones dinámicas de destino (dst_dag) | PanOSDestinationDynamicAddressGroup | target.group.group_display_name | ||
| Marca de tiempo de alta resolución (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key y additional.fields.value.string_value | ||
| Categoría del dispositivo de origen (src_category) | PanOSSourceDeviceCategory | src_category | principal.asset.category | |
| Perfil del dispositivo de origen (src_profile) | PanOSSourceDeviceProfile | src_profile | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Modelo del dispositivo de origen (src_model) | PanOSSourceDeviceModel | src_model | principal.asset.hardware.model | |
| Proveedor del dispositivo de origen (src_vendor) | PanOSSourceDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Familia del SO del dispositivo de origen (src_osfamily) | PanOSSourceDeviceOSFamily | principal.platform | ||
| Versión del SO del dispositivo de origen (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | ||
| Nombre de host de origen (src_host) | PanOSSourceDeviceHost | principal.hostname | ||
| Dirección MAC de origen (src_mac) | PanOSSourceDeviceMac | principal.mac | ||
| Categoría del dispositivo de destino (dst_category) | PanOSDestinationDeviceCategory | dst_category | target.asset.category | |
| Perfil de dispositivo de destino (dst_profile) | PanOSDestinationDeviceProfile | dst_profile | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Modelo del dispositivo de destino (dst_model) | PanOSDestinationDeviceModel | dst_model | target.asset.hardware.model | |
| Proveedor del dispositivo de destino (dst_vendor) | PanOSDestinationDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Familia del SO del dispositivo de destino (dst_osfamily) | PanOSDestinationDeviceOSFamily | dst_osfamily | target.platform | |
| Versión del SO del dispositivo de destino (dst_osversion) | PanOSDestinationDeviceOSVersion | target.platform_version | ||
| Nombre de host de destino (dst_host) | PanOSDestinationDeviceHost | target.hostname | ||
| Dirección MAC de destino (dst_mac) | PanOSDestinationDeviceMac | target.mac | ||
| Número de secuencia (seqno) | PanOSLogTypeSeqNo | metadata.product_log_id | ||
| Marcas de acción (actionflags) | PanOSActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value | |
| Jerarquía de grupos de dispositivos (dg_hier_level_1) | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value | |
| Jerarquía de grupos de dispositivos (dg_hier_level_2) | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value | |
| Jerarquía de grupos de dispositivos (dg_hier_level_3) | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value | |
| Jerarquía de grupos de dispositivos (dg_hier_level_4) | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value | |
| Nombre del sistema virtual (vsys_name) | intermediary.asset.attribute.labels.key/value | |||
| Nombre del dispositivo (device_name) | intermediary.hostname | |||
| ID de sistema virtual (vsys_id) | intermediary.resource.product_object_id | |||
| Subcategoría de la aplicación (subcategory_of_app) | subcategory_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Categoría de la aplicación (category_of_app) | category_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Tecnología de la aplicación (technology_of_app) | technology_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Riesgo de la aplicación (risk_of_app) | security_result.severity | |||
| Característica de la aplicación (characteristic_of_app) | characteristic_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Contenedor de aplicaciones (container_of_app) | container_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Aplicación SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Estado de sanción de la aplicación (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Gravedad (severity) | number-of-severity(header) | security_result.severity y security_result.severity_details |
Túnel
En la siguiente tabla se enumeran los campos de registro del tipo de registro de túnel y sus campos de UDM correspondientes.
| Campo de CSV | Campo CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si no se incluye "Generate Time") |
|
| Número de serie (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | gato | metadata.product_event_type | |
| Tipo de amenaza o contenido (subtipo) | Subtipo (encabezado) | Subtipo | metadata.product_event_type | |
| Hora de generación (time_generated o cef-formatted-time_generated) | metadata.event_timestamp | |||
| Dirección de origen (src) | src | src | principal.ip | |
| Dirección de destino (dst) | dst | dst | target.ip | |
| IP de origen de NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP de destino de NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Nombre de la regla | cs1 | RuleName | security_result.rule_name | |
| Usuario de origen (srcuser) | suser | SourceUser/usrName | principal.user.userid | |
| Usuario de destino (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplicación | aplicación | Aplicación | network.application_protocol | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona de origen (desde) | cs4 | SourceZone | de | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Zona de destino | cs5 | DestinationZone | a | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
| Interfaz de entrada (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Interfaz de salida (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
| Registrar acción (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key y additional.fields.value.string_value |
| ID de sesión (sessionid) | cn1 | SessionID | network.session_id | |
| Número de repeticiones (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key y additional.fields.value.string_value |
| Puerto de origen (sport) | spt | srcPort | principal.port | |
| Puerto de destino (dport) | dpt | dstPort | target.port | |
| Puerto de origen de NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Puerto de destino de NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Marcas (flags) | flexString1 | Banderas | flags | additional.fields.key y additional.fields.value.string_value |
| Protocolo IP (proto) | proto | proto | network.ip_protocol | |
| Acción (action) | actuar | acción | security_result.action_details
security_result.action |
|
| Gravedad (severity) | number-of-severity(header) | security_result.severity y security_result.severity_details | ||
| Número de secuencia (seqno) | externalId | secuencia | metadata.product_log_id | |
| Marcas de acción (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value |
| Ubicación de origen (srcloc) | principal.location.country_or_region | |||
| Ubicación de destino (dstloc) | target.location.country_or_region | |||
| Jerarquía de grupos de dispositivos (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value |
| Nombre del sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nombre del dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| ID de túnel (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key y additional.fields.value.string_value |
| Etiqueta de monitor (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key y additional.fields.value.string_value |
| ID de sesión principal (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Hora de inicio de la actividad principal (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key y additional.fields.value.string_value |
| Tipo de túnel (tunnel) | cs2 | TunnelType | túnel | additional.fields.key y additional.fields.value.string_value |
| Bytes (bytes) | flexNumber1 | totalBytes | bytes | additional.fields.key y additional.fields.value.string_value |
| Bytes enviados (bytes_sent) | está en | srcBytes | network.sent_bytes | |
| Bytes recibidos (bytes_received) | out | dstBytes | network.received_bytes | |
| Paquetes | cn2 | totalPackets | paquetes | additional.fields.key y additional.fields.value.string_value |
| Paquetes enviados (pkts_sent) | PanOSPacketsSent | srcPackets | pkts_sent | network.sent_packets |
| Paquetes recibidos (pkts_received) | PanOSPacketsReceived | dstPackets | pkts_received | network.received_packets |
| Encapsulación máxima (max_encap) | flexNumber2 | MaximumEncapsulation | max_encap | additional.fields.key y additional.fields.value.string_value |
| Protocolo desconocido (unknown_proto) | cfp1 | UnknownProtocol | unknown_proto | additional.fields.key y additional.fields.value.string_value |
| Comprobación estricta (strict_check) | cfp2 | StrictChecking | strict_check | additional.fields.key y additional.fields.value.string_value |
| Fragmento de túnel (tunnel_fragment) | PanOSTunnelFragment | TunnelFragment | tunnel_fragment | additional.fields.key y additional.fields.value.string_value |
| Sesiones creadas (sessions_created) | cfp3 | SessionsCreated | sessions_created | additional.fields.key y additional.fields.value.string_value |
| Sesiones cerradas (sessions_closed) | cfp4 | SessionsClosed | sessions_closed | additional.fields.key y additional.fields.value.string_value |
| Motivo de finalización de la sesión (session_end_reason) | reason | SessionEndReason | security_result.summary | |
| Fuente de la acción (action_source) | gato | ActionSource | action_source | additional.fields.key y additional.fields.value.string_value |
| Hora de inicio (inicio) | startTime | start | additional.fields.key y additional.fields.value.string_value | |
| Tiempo transcurrido (elapsed) | cn3 | ElapsedTime | transcurrido | network.session_duration.seconds |
| Regla de inspección de túneles (tunnel_insp_rule) | PanOSTunneInspectionRule | security_result.rule_name = "Tunnel Inspection Rule: %{PanOSTunnelInspectionRule}" | ||
| IP de usuario remoto (remote_user_ip) | PanOSRmtUserIP | principal.ip | ||
| ID de usuario remoto (remote_user_id) | PanOSRmtUserID | remote_user_id | principal.user.userid | |
| UUID de la regla de seguridad (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| ID de PCAP (pcap_id) | PanOSPcapID | pcap_id | additional.fields.key y additional.fields.value.string_value | |
| Nombre del grupo de usuarios dinámico (dynusergroup_name) | PanDynamicUsrgrp | principal.group.group_display_name | ||
| Lista dinámica externa de origen (src_edl) | PanOSSourceEDL | src_edl | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Lista dinámica externa de destino (dst_edl) | PanOSDestinationEDL | dst_edl | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Marca de tiempo de alta resolución (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key y additional.fields.value.string_value | ||
| Un diferenciador de slice (nssai_sd) | nssai_sd | additional.fields.key y additional.fields.value.string_value | ||
| Un tipo de servicio de segmento (nssai_sd) | nssai_sd1 | additional.fields.key y additional.fields.value.string_value | ||
| ID de sesión PDU (pdu_session_id) | pdu_session_id | additional.fields.key y additional.fields.value.string_value | ||
| Subcategoría de la aplicación (subcategory_of_app) | subcategory_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Categoría de la aplicación (category_of_app) | category_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Tecnología de la aplicación (technology_of_app) | technology_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Riesgo de la aplicación (risk_of_app) | risk_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Característica de la aplicación (characteristic_of_app) | characteristic_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Contenedor de aplicaciones (container_of_app) | container_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Aplicación SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Aplicación tunelizada (tunneled_app) | additional.fields.key y additional.fields.value.string_value | |||
| Descargado (descargado) | additional.fields.key y additional.fields.value.string_value | |||
| Tipo de flujo (flow_type) | additional.fields.key y additional.fields.value.string_value | |||
| Nombre del clúster (cluster_name) |
principal.resource.name |
|||
| Estado de sanción de la aplicación (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key y additional.fields.value.string_value |
Autenticación
En la siguiente tabla se enumeran los campos de registro del tipo de registro de autenticación y sus campos de UDM correspondientes.
| Campo de CSV | Campo CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si no se incluye "Generate Time") |
|
| Número de serie (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | gato | metadata.product_event_type | |
| Tipo de amenaza o contenido (subtipo) | Subtipo (encabezado) | Subtipo | metadata.product_event_type | |
| Hora de generación (time_generated o cef-formatted-time_generated) | metadata.event_timestamp | |||
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| IP de origen (ip) | src | src | principal.ip | |
| Usuario (user) | duser | usrName | target.user.userid | |
| Normalizar usuario (normalize_user) | cs2 | NormalizeUser | target.user.user_display_name | |
| Objeto (object) | fname | ObjectName | objeto | target.resource.name |
| Política de autenticación (authpolicy) | cs4 | AuthPolicy | authpolicy | additional.fields.key y additional.fields.value.string_value |
| Número de repeticiones (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key y additional.fields.value.string_value |
| ID de autenticación (authid) | cn2 | AuthenticationID | authid | additional.fields.key y additional.fields.value.string_value |
| Proveedor (vendor) | flexString2 | Proveedor | vendor | additional.fields.key y additional.fields.value.string_value |
| Registrar acción (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key y additional.fields.value.string_value |
| Perfil de servidor (serverprofile) | cs1 | ServerProfile | serverprofile | additional.fields.key y additional.fields.value.string_value |
| Descripción (descendente) | PanOSDesc | AdditionalAuthInfo | security_result.description | |
| Tipo de cliente (clienttype) | cs5 | ClientType | clienttype | additional.fields.key y additional.fields.value.string_value |
| Tipo de evento (event) | msg | msg | extensions.auth.auth_details | |
| Número de factor (factorno) | cn1 | FactorNumber | factorno | additional.fields.key y additional.fields.value.string_value |
| Número de secuencia (seqno) | externalId | secuencia | metadata.product_log_id | |
| Marcas de acción (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía de grupos de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value |
| Nombre del sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nombre del dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| ID de sistema virtual (vsys_id) | intermediary.resource.product_object_id | |||
| Protocolo de autenticación (authproto) | authproto | additional.fields.key y additional.fields.value.string_value | ||
| UUID de la regla (rule_uuid) | PanOSRuleUUID/RuleUUID | security_result.rule_id | ||
| Marca de tiempo de alta resolución (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key y additional.fields.value.string_value | ||
| Categoría del dispositivo de origen (src_category) | PanOSSourceDeviceCategory | src_category | principal.asset.category | |
| Perfil del dispositivo de origen (src_profile) | PanOSSourceDeviceProfile | src_profile | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Modelo del dispositivo de origen (src_model) | PanOSSourceDeviceModel | src_model | principal.asset.hardware.model | |
| Proveedor del dispositivo de origen (src_vendor) | PanOSSourceDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Familia del SO del dispositivo de origen (src_osfamily) | PanOSSourceDeviceOSFamily | principal.asset.platform_software.platform principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
||
| Versión del SO del dispositivo de origen (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | ||
| Nombre de host de origen (src_host) | PanOSSourceHostname | principal.hostname | ||
| Dirección MAC de origen (src_mac) | PanOSSourceMac | principal.asset.mac | ||
| Región | PanOSTrafficOriginRegion | principal.location.country_or_region | ||
| User-agent (user_agent) | PanOSHTTPUserAgent | network.http.user_agent | ||
| ID de sesión(sessionid) | PanOSTrafficSessionID | network.session_id | ||
| Gravedad (severity) | number-of-severity(header) | security_result.severity y security_result.severity_details | ||
| Nombre del clúster (cluster_name) | principal.resource.name |
URL
En la siguiente tabla se indican los campos de registro del tipo de registro de URL y sus campos de UDM correspondientes.
| Campo de CSV | Campo CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si no se incluye "Generate Time") |
|
| Serie # (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | gato | metadata.product_event_type | |
| Tipo de amenaza o contenido (subtipo) | Subtipo (encabezado) | Subtipo | metadata.product_event_type | |
| Generar hora | metadata.event_timestamp | |||
| Dirección de origen (src) | src | src | principal.ip | |
| Dirección de destino (dst) | dst | dst | target.ip | |
| IP de origen de NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP de destino de NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Rule (regla) | cs1 | RuleName | security_result.rule_name | |
| Usuario de origen (srcuser) | suser | SourceUser | principal.user.userid | |
| Usuario de destino (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplicación | aplicación | Aplicación | network.application_protocol | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona de origen (desde) | cs4 | SourceZone | de | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Zona de destino | cs5 | DestinationZone | a | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
| Interfaz de entrada (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Interfaz de salida (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
| Registrar acción (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key y additional.fields.value.string_value |
| Tiempo registrado | time_logged | additional.fields.key y additional.fields.value.string_value | ||
| ID de sesión (sessionid) | cn1 | SessionID | network.session_id | |
| Número de repeticiones (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key y additional.fields.value.string_value |
| Puerto de origen (sport) | spt | srcPort | principal.port | |
| Puerto de destino (dport) | dpt | dstPort | target.port | |
| Puerto de origen de NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Puerto de destino de NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Marcas (flags) | flexString1 | Banderas | flags | additional.fields.key y additional.fields.value.string_value |
| Protocolo IP (proto) | proto | proto | network.ip_protocol | |
| Acción (action) | actuar | acción | security_result.action_details
security_result.action |
|
| URL o nombre de archivo (varios) | Varios | target.file.names
target.url |
||
| Nombre de la amenaza o del contenido (threatid) | gato | ThreatID | security_result.threat_id | |
| Categoría (category) | cs2 | URLCategory | category | security_result.category_details |
| Gravedad (severity) | number-of-severity (encabezado) | Gravedad | security_result.severity
security_result.severity_details |
|
| Dirección (direction) | flexString2 | Dirección | network.direction | |
| Número de secuencia (seqno) | externalId | secuencia | metadata.product_log_id | |
| Marcas de acción (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value |
| País de origen (srcloc) | SourceLocation | principal.location.country_or_region | ||
| País de destino (dstloc) | DestinationLocation | target.location.country_or_region | ||
| contenttype (contenttype) | requestContext | ContentType | contenttype | additional.fields.key y additional.fields.value.string_value |
| pcap_id (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key y additional.fields.value.string_value |
| filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | ||
| nube (cloud) | Nube | nube | additional.fields.key y additional.fields.value.string_value | |
| url_idx (url_idx) | URLIndex | url_idx | additional.fields.key y additional.fields.value.string_value | |
| user_agent (user_agent) | requestClientApplication | UserAgent | network.http.user_agent | |
| filetype (filetype) | target.file.mime_type | |||
| xff (xff) | PanOSXForwarderfor | identSrc | xff | principal.ip |
| Referente (referer) | PanOSReferer | Referencia | network.http.referral_url | |
| sender (remitente) | network.email.from | |||
| Asunto (subject) | Asunto | network.email.subject | ||
| destinatario (recipient) | network.email.to | |||
| reportid (reportid) | reportid | additional.fields.key y additional.fields.value.string_value | ||
| Nivel 1 de jerarquía de Gen. demanda (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value |
| Nivel de jerarquía 2 de Gen. demanda (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value |
| Nivel 3 de jerarquía de Gen. demanda (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value |
| Nivel de jerarquía 4 de Gen. demanda (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value |
| Nombre del sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nombre del dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| file_url (file_url) | target.url | |||
| UUID de VM de origen (src_uuid) | SrcUUID | principal.asset.product_object_id | ||
| UUID de la VM de destino (dst_uuid) | DstUUID | target.asset.product_object_id | ||
| http_method (http_method) | requestMethod | RequestMethod | network.http.method | |
| ID de túnel o IMSI (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key y additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key y additional.fields.value.string_value |
| ID de sesión principal (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Hora de inicio de la sesión principal (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key y additional.fields.value.string_value |
| Túnel | PanOSTunnelType | TunnelType | túnel | additional.fields.key y additional.fields.value.string_value |
| thr_category (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| contentver (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key y additional.fields.value.string_value |
| sig_flags (sig_flags) | sig_flags | additional.fields.key y additional.fields.value.string_value | ||
| ID de asociación SCTP (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key y additional.fields.value.string_value | |
| ID de protocolo de carga útil (ppid) | PanOSPPID | ppid | additional.fields.key y additional.fields.value.string_value | |
| http_headers (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Lista de categorías de URLs (url_category_list) | PanOSURLCatList | url_category_list | additional.fields.key y additional.fields.value.string_value | |
| UUID de la regla (rule_uuid) | PanOSRuleUUID | rule_uuid | security_result.rule_id | |
| Conexión HTTP/2 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| dynusergroup_name (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | additional.fields.key y additional.fields.value.string_value | |
| Dirección XFF (xff_ip) | PanXFFIP | principal.ip | ||
| Categoría del dispositivo de origen (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Perfil del dispositivo de origen (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Modelo del dispositivo de origen (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Proveedor del dispositivo de origen (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Familia del SO del dispositivo de origen (src_osfamily) | PanSrcDeviceOS | principal.platform | ||
| Versión del SO del dispositivo de origen (src_osversion) | PanSrcDeviceOSv | principal.platform_version | ||
| Nombre de host de origen (src_host) | PanSrcHostname | src_host | principal.hostname | |
| Dirección MAC de origen (src_mac) | PanSrcMac | principal.mac | ||
| Categoría del dispositivo de destino (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Perfil de dispositivo de destino (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Modelo del dispositivo de destino (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Proveedor del dispositivo de destino (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Familia del SO del dispositivo de destino (dst_osfamily) | PanDstDeviceOS | target.platform | ||
| Versión del SO del dispositivo de destino (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Nombre de host de destino (dst_host) | PanPODNamespace | target.hostname | ||
| Dirección MAC de destino (dst_mac) | PanDstMac | target.mac | ||
| ID de contenedor (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| Espacio de nombres de POD (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| Nombre del POD (pod_name) | PanPODName | pod_name | target.resource.name | |
| Lista dinámica externa de origen (src_edl) | PanSrcEDL | src_edl | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Lista dinámica externa de destino (dst_edl) | PanDstEDL | dst_edl | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
|
| ID de host (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Número de serie (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| domain_edl (domain_edl) | PanDomainEDL | domain_edl | additional.fields.key y additional.fields.value.string_value | |
| Grupo de direcciones dinámicas de origen (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Grupo de direcciones dinámicas de destino (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| partial_hash (partial_hash) | PanPartialHash | partial_hash | additional.fields.key y additional.fields.value.string_value | |
| Marca de tiempo de alta resolución (high_res_timestamp) | PanTimeHighRes | additional.fields.key y additional.fields.value.string_value | ||
| Motivo (reason) | PanReasonFilteringAction | reason | security_result.summary | |
| Justificación (justification) | PanJustification | justificación | additional.fields.key y additional.fields.value.string_value | |
| nssai_sst (nssai_sst) | PanASServiceType | nssai_sst | additional.fields.key y additional.fields.value.string_value | |
| Subcategoría de la aplicación (subcategory_of_app) | subcategory_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Categoría de la aplicación (category_of_app) | category_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Tecnología de la aplicación (technology_of_app) | technology_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Riesgo de la aplicación (risk_of_app) | risk_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Característica de la aplicación (characteristic_of_app) | characteristic_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Contenedor de la aplicación (container_of_app) | container_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Aplicación tunelizada (tunneled_app) | tunneled_app | additional.fields.key y additional.fields.value.string_value | ||
| SaaS de la aplicación (is_saas_of_app) | is_saas_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Estado sancionado de la aplicación (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key y additional.fields.value.string_value | ||
| ID de informe de Cloud (cloud_reportid) | additional.fields.key y additional.fields.value.string_value | |||
| Nombre del clúster (cluster_name) |
principal.resource.name |
|||
| Tipo de flujo (flow_type) | additional.fields.key y additional.fields.value.string_value |
Datos
En la siguiente tabla se enumeran los campos de registro del tipo de registro de datos y sus campos de UDM correspondientes.
| Campo de CSV | Campo CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si no se incluye "Generate Time") |
|
| Serie # (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | gato | metadata.product_event_type | |
| Tipo de amenaza o contenido (subtipo) | Subtipo (encabezado) | Subtipo | metadata.product_event_type | |
| Generar hora | metadata.event_timestamp | |||
| Dirección de origen (src) | src | src | principal.ip | |
| Dirección de destino (dst) | dst | dst | target.ip | |
| IP de origen de NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP de destino de NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Rule (regla) | cs1 | RuleName | security_result.rule_name | |
| Usuario de origen (srcuser) | suser | SourceUser | principal.user.userid | |
| Usuario de destino (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplicación | aplicación | Aplicación | network.application_protocol | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona de origen (desde) | cs4 | SourceZone | de | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Zona de destino | cs5 | DestinationZone | a | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
| Interfaz de entrada (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Interfaz de salida (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
| Registrar acción (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key y additional.fields.value.string_value |
| Tiempo registrado | time_logged | additional.fields.key y additional.fields.value.string_value | ||
| ID de sesión (sessionid) | cn1 | SessionID | network.session_id | |
| Número de repeticiones (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key y additional.fields.value.string_value |
| Puerto de origen (sport) | spt | srcPort | principal.port | |
| Puerto de destino (dport) | dpt | dstPort | target.port | |
| Puerto de origen de NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Puerto de destino de NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Marcas (flags) | flexString1 | Banderas | flags | additional.fields.key y additional.fields.value.string_value |
| Protocolo IP (proto) | proto | proto | network.ip_protocol | |
| Acción (action) | actuar | acción | security_result.action_details
security_result.action |
|
| URL o nombre de archivo (varios) | Varios | target.file.names
target.url |
||
| Nombre de la amenaza o del contenido (threatid) | gato | ThreatID | security_result.threat_id | |
| Categoría (category) | cs2 | URLCategory | category | security_result.category_details |
| Gravedad (severity) | number-of-severity (encabezado) | Gravedad | security_result.severity
security_result.severity_details |
|
| Dirección (direction) | flexString2 | Dirección | network.direction | |
| Número de secuencia (seqno) | externalId | secuencia | metadata.product_log_id | |
| Marcas de acción (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value |
| País de origen (srcloc) | SourceLocation | principal.location.country_or_region | ||
| País de destino (dstloc) | DestinationLocation | target.location.country_or_region | ||
| contenttype (contenttype) | ContentType | contenttype | additional.fields.key y additional.fields.value.string_value | |
| pcap_id (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key y additional.fields.value.string_value |
| filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | ||
| nube (cloud) | Nube | nube | additional.fields.key y additional.fields.value.string_value | |
| url_idx (url_idx) | URLIndex | url_idx | additional.fields.key y additional.fields.value.string_value | |
| user_agent (user_agent) | network.http.user_agent | |||
| filetype (filetype) | target.file.mime_type | |||
| xff (xff) | xff | principal.ip | ||
| Referente (referer) | network.http.referral_url | |||
| sender (remitente) | network.email.from | |||
| Asunto (subject) | Asunto | network.email.subject | ||
| destinatario (recipient) | network.email.to | |||
| reportid (reportid) | reportid | additional.fields.key y additional.fields.value.string_value | ||
| Nivel 1 de jerarquía de Gen. demanda (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value |
| Nivel de jerarquía 2 de Gen. demanda (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value |
| Nivel 3 de jerarquía de Gen. demanda (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value |
| Nivel de jerarquía 4 de Gen. demanda (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value |
| Nombre del sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nombre del dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| file_url (file_url) | target.url | |||
| UUID de VM de origen (src_uuid) | SrcUUID | principal.asset.product_object_id | ||
| UUID de la VM de destino (dst_uuid) | DstUUID | target.asset.product_object_id | ||
| http_method (http_method) | RequestMethod | network.http.method | ||
| ID de túnel o IMSI (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key y additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key y additional.fields.value.string_value |
| ID de sesión principal (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Hora de inicio de la sesión principal (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key y additional.fields.value.string_value |
| Túnel | PanOSTunnelType | TunnelType | túnel | additional.fields.key y additional.fields.value.string_value |
| thr_category (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| contentver (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key y additional.fields.value.string_value |
| sig_flags (sig_flags) | sig_flags | additional.fields.key y additional.fields.value.string_value | ||
| ID de asociación SCTP (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key y additional.fields.value.string_value | |
| ID de protocolo de carga útil (ppid) | PanOSPPID | ppid | additional.fields.key y additional.fields.value.string_value | |
| http_headers (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Lista de categorías de URLs (url_category_list) | url_category_list | additional.fields.key y additional.fields.value.string_value | ||
| UUID de la regla (rule_uuid) | PanOSRuleUUID | rule_uuid | security_result.rule_id | |
| Conexión HTTP/2 (http2_connection) | http2_connection | network.application_protocol_version | ||
| dynusergroup_name (dynusergroup_name) | dynusergroup_name | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
||
| Dirección XFF (xff_ip) | principal.ip | |||
| Categoría del dispositivo de origen (src_category) | src_category | principal.asset.category | ||
| Perfil del dispositivo de origen (src_profile) | src_profile | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
||
| Modelo del dispositivo de origen (src_model) | src_model | principal.asset.hardware.model | ||
| Proveedor del dispositivo de origen (src_vendor) | src_vendor | principal.asset.hardware.manufacturer | ||
| Familia del SO del dispositivo de origen (src_osfamily) | principal.platform | |||
| Versión del SO del dispositivo de origen (src_osversion) | principal.platform_version | |||
| Nombre de host de origen (src_host) | src_host | principal.hostname | ||
| Dirección MAC de origen (src_mac) | principal.mac | |||
| Categoría del dispositivo de destino (dst_category) | dst_category | target.asset.category | ||
| Perfil del dispositivo de destino (dst_profile) | dst_profile | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
||
| Modelo del dispositivo de destino (dst_model) | dst_model | target.asset.hardware.model | ||
| Proveedor del dispositivo de destino (dst_vendor) | dst_vendor | target.asset.hardware.manufacturer | ||
| Familia del SO del dispositivo de destino (dst_osfamily) | target.platform | |||
| Versión del SO del dispositivo de destino (dst_osversion) | target.platform_version | |||
| Nombre de host de destino (dst_host) | target.hostname | |||
| Dirección MAC de destino (dst_mac) | target.mac | |||
| ID de contenedor (container_id) | container_id | intermediary.resource.product_object_id | ||
| Espacio de nombres de POD (pod_namespace) | pod_namespace | target.resource.attribute.labels.key/value | ||
| Nombre del POD (pod_name) | pod_name | target.resource.name | ||
| Lista dinámica externa de origen (src_edl) | src_edl | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
||
| Lista dinámica externa de destino (dst_edl) | dst_edl | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
||
| ID de host (hostid) | hostid | principal.asset.asset_id | ||
| Número de serie (serialnumber) | principal.asset.hardware.serial_number | |||
| domain_edl (domain_edl) | domain_edl | additional.fields.key y additional.fields.value.string_value | ||
| Grupo de direcciones dinámicas de origen (src_dag) | principal.group.group_display_name | |||
| Grupo de direcciones dinámicas de destino (dst_dag) | target.group.group_display_name | |||
| partial_hash (partial_hash) | partial_hash | additional.fields.key y additional.fields.value.string_value | ||
| Marca de tiempo de alta resolución (high_res_timestamp) | additional.fields.key y additional.fields.value.string_value | |||
| Motivo (reason) | reason | security_result.summary | ||
| Justificación (justification) | justificación | additional.fields.key y additional.fields.value.string_value | ||
| nssai_sst (nssai_sst) | nssai_sst | additional.fields.key y additional.fields.value.string_value | ||
| Subcategoría de la aplicación (subcategory_of_app) | subcategory_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Categoría de la aplicación (category_of_app) | category_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Tecnología de la aplicación (technology_of_app) | technology_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Riesgo de la aplicación (risk_of_app) | risk_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Característica de la aplicación (characteristic_of_app) | characteristic_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Contenedor de la aplicación (container_of_app) | container_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Aplicación tunelizada (tunneled_app) | tunneled_app | additional.fields.key y additional.fields.value.string_value | ||
| SaaS de la aplicación (is_saas_of_app) | is_saas_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Estado sancionado de la aplicación (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key y additional.fields.value.string_value | ||
| ID de informe de Cloud (cloud_reportid) | additional.fields.key y additional.fields.value.string_value | |||
| Nombre del clúster (cluster_name) | principal.resource.name | |||
| Tipo de flujo (flow_type) | additional.fields.key y additional.fields.value.string_value |
GlobalProtect
En la siguiente tabla se enumeran los campos de registro del tipo de registro GlobalProtect y sus campos de UDM correspondientes.
| Campo de CSV | Campo CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time) | rt | received_time | metadata.event_timestamp | |
| Número de serie (serial) | PanOSDeviceSN | intermediary_asset_hardware_serial_number | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | metadata.product_event_type | ||
| Tipo de amenaza o contenido (subtipo) | Subtipo (encabezado) | Subtipo | metadata.product_event_type | |
| Hora de generación (time_generated) | PanOSLogTimeStamp | generated_timestamp | metadata.event_timestamp | |
| Sistema virtual (vsys) | PanOSVirtualSystem | vsys | intermediary.asset.attribute.labels.key/value | |
| ID de evento (eventid) | PanOSEventID | event_id | additional.fields.key y additional.fields.value.string_value | |
| Fase (stage) | PanOSStage | fase | additional.fields.key y additional.fields.value.string_value | |
| Método de autenticación (auth_method) | PanOSAuthMethod | extension_auth_auth_details | extensions.auth.auth_details | |
| Tipo de túnel (tunnel_type) | PanOSTunnelType | túnel | additional.fields.key y additional.fields.value.string_value | |
| Usuario de origen (srcuser) | PanOSSourceUserName | src_user | principal.user.email_address
principal.user.userid principal.administrative_domain |
|
| Región de origen (srcregion) | PanOSSourceRegion | src_region | principal.location.country_or_region | |
| Nombre del equipo (machinename) | PanOSEndpointDeviceName | machine_name | principal.hostname | |
| IP pública (public_ip) | PanOSPublicIPv4 | principal.nat_ip | ||
| IPv6 pública (public_ipv6) | PanOSPublicIPv6 | principal.nat_ip | ||
| IP privada (private_ip) | PanOSPrivateIPv4 | principal.ip | ||
| IPv6 privada (private_ipv6) | PanOSPrivateIPv6 | principal.ip | ||
| ID de host (hostid) | PanOSHostID | hostid | principal.asset.asset_id | |
| Número de serie (serialnumber) | PanOSDeviceSN | principal.asset.hardware.serial_number | ||
| Versión de cliente (client_ver) | PanOSGlobalProtectClientVersion | client_ver | additional.fields.key y additional.fields.value.string_value | |
| Sistema operativo del cliente (client_os) | PanOSEndpointOSType | principal.platform | ||
| Versión del SO del cliente (client_os_ver) | PanOSEndpointOSVersion | principal.platform_version | ||
| Número de repeticiones (repeatcnt) | PanOSCountOfRepeats | repeatcnt | additional.fields.key y additional.fields.value.string_value | |
| Motivo (reason) | PanOSQuarantineReason | security_result.summary | ||
| Error (error) | PanOSConnectionError | error | security_result.description | |
| Descripción (opaca) | PanOSDescription | security_result.description | ||
| Estado (status) | PanOSEventStatus | status | additional.fields.key y additional.fields.value.string_value | |
| Ubicación (ubicación) | PanOSGPGatewayLocation | target.location.country_or_region | ||
| Duración de inicio de sesión (login_duration) | PanOSLoginDuration | network.session_duration | ||
| Método de conexión (connect_method) | PanOSConnectionMethod | connect_method | additional.fields.key y additional.fields.value.string_value | |
| Código de error (error_code) | PanOSConnectionErrorID | error_code | additional.fields.key y additional.fields.value.string_value | |
| Portal (portal) | PanOSPortal | portal | additional.fields.key y additional.fields.value.string_value | |
| Número de secuencia (seqno) | PanOSSequenceNo | metadata.product_log_id | ||
| Marcas de acción (actionflags) | PanOSActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value | |
| Marca de tiempo de alta resolución (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key y additional.fields.value.string_value | ||
| Método de selección de pasarela (selection_type) | PanOSGatewaySelectionType | selection_type | additional.fields.key y additional.fields.value.string_value | |
| Tiempo de respuesta de SSL (response_time) | PanOSSSLResponseTime | response_time | additional.fields.key y additional.fields.value.string_value | |
| Prioridad de la pasarela (priority) | PanOSGatewayPriority | prioridad | additional.fields.key y additional.fields.value.string_value | |
| Pasarelas intentadas (attempted_gateways) | PanOSAttemptedGateways | attempted_gateways | additional.fields.key y additional.fields.value.string_value | |
| Nombre de la pasarela (gateway) | PanOSAttemptedGateways | pasarela | target.resource.name | |
| Jerarquía de grupos de dispositivos (dg_hier_level_1) | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value | ||
| Jerarquía de grupos de dispositivos (dg_hier_level_2) | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value | ||
| Jerarquía de grupos de dispositivos (dg_hier_level_3) | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value | ||
| Jerarquía de grupos de dispositivos (dg_hier_level_4) | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value | ||
| Nombre del sistema virtual (vsys_name) | intermediary.asset.attribute.labels.key/value | |||
| Nombre del dispositivo (device_name) | intermediary.hostname | |||
| ID de sistema virtual (vsys_id) | intermediary.resource.product_object_id | |||
| Gravedad (severity) | number-of-severity(header) | security_result.severity y security_result.severity_details | ||
| Nombre del clúster (cluster_name) | principal.resource.name |
Correlación
En la siguiente tabla se enumeran los campos de registro del tipo de registro de correlación y sus campos de UDM correspondientes.
| Campo de CSV | Campo CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de generación (time_generated o cef-formatted-time_generated) | startTime | generated_timestamp | metadata.event_timestamp | |
| Dirección de origen (src) | src | principal.ip | ||
| Usuario de origen (srcuser) | SourceUser/usrName | principal.user.userid | ||
| Sistema virtual (vsys) | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value | |
| Categoría (category) | security_result.category_details | |||
| Gravedad (severity) | Gravedad | security_result.severity y security_result.severity_details | ||
| Nivel 1 de la jerarquía de grupos de dispositivos | DeviceGroupHierarchyL1 | additional.fields.key y additional.fields.value.string_value | ||
| Nivel 2 de la jerarquía de grupos de dispositivos | DeviceGroupHierarchyL2 | additional.fields.key y additional.fields.value.string_value | ||
| Nivel 3 de la jerarquía de grupos de dispositivos | DeviceGroupHierarchyL3 | additional.fields.key y additional.fields.value.string_value | ||
| Nivel 4 de la jerarquía de grupos de dispositivos | DeviceGroupHierarchyL4 | additional.fields.key y additional.fields.value.string_value | ||
| Nombre del sistema virtual (vsys_name) | vSrcName | intermediary.asset.attribute.labels.key/value | ||
| Nombre del dispositivo (device_name) | DeviceName | intermediary.hostname | ||
| ID de sistema virtual (vsys_id) | VirtualSystemID | intermediary.resource.product_object_id | ||
| Nombre del objeto (objectname) | ObjectName | target.resource.name | ||
| ID de objeto (object_id) | ObjectID | target.resource.product_object_id | ||
| Pruebas | msg | security_result.summary |
GTP
En la tabla siguiente se enumeran los campos de registro del tipo de registro gtp y sus campos de UDM correspondientes.
| Campo de CSV | Campo CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | metadata.collected_timestamp,
metadata.event_timestamp (si no se incluye "Generate Time") |
|||
| Número de serie (serial) | intermediary.asset.hardware.serial_number | |||
| Tipo (type) | metadata.product_event_type | |||
| Tipo de amenaza o contenido (subtipo) | metadata.product_event_type | |||
| Hora de generación (time_generated o cef-formatted-time_generated) | metadata.event_timestamp | |||
| Dirección de origen (src) | principal.ip | |||
| Dirección de destino (dst) | target.ip | |||
| Nombre de la regla | security_result.rule_name | |||
| Aplicación | network.application_protocol | |||
| Sistema virtual (vsys) | vsys | intermediary.asset.attribute.labels.key/value | ||
| Zona de origen (desde) | de | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
||
| Zona de destino | a | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
||
| Interfaz de entrada (inbound_if) | inbound_if | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
||
| Interfaz de salida (outbound_if) | outbound_if | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
||
| Registrar acción (logset) | logset | additional.fields.key y additional.fields.value.string_value | ||
| ID de sesión (sessionid) | network.session_id | |||
| Puerto de origen (sport) | principal.port | |||
| Puerto de destino (dport) | target.port | |||
| Protocolo IP (proto) | network.ip_protocol | |||
| Acción (action) | security_result.action_details
security_result.action |
|||
| Tipo de evento de GTP (event_type) | gtp_event_type | additional.fields.key y additional.fields.value.string_value | ||
| MSISDN (msisdn) | msisdn | additional.fields.key y additional.fields.value.string_value | ||
| Nombre de punto de acceso (APN) | apn | additional.fields.key y additional.fields.value.string_value | ||
| Tecnología de acceso radioeléctrico (RAT) | rata | additional.fields.key y additional.fields.value.string_value | ||
| Tipo de mensaje de GTP (msg_type) | gtp_msg_type | additional.fields.key y additional.fields.value.string_value | ||
| Dirección IP final (end_ip_adr) | principal.ip | |||
| Identificador de endpoint de túnel 1 (teid1) | teid1 | additional.fields.key y additional.fields.value.string_value | ||
| Identificador de endpoint de túnel 2 (teid2) | teid2 | additional.fields.key y additional.fields.value.string_value | ||
| Interfaz GTP (gtp_interface) | gtp_interface | additional.fields.key y additional.fields.value.string_value | ||
| Causa de GTP (cause_code) | gtp_cause_code | additional.fields.key y additional.fields.value.string_value | ||
| Gravedad (severity) | security_result.severity y security_result.severity_details | |||
| Serving Network MCC (mcc) | mcc | additional.fields.key y additional.fields.value.string_value | ||
| Serving Network MNC (mnc) | mnc | additional.fields.key y additional.fields.value.string_value | ||
| Prefijo (area_code) | area_code | additional.fields.key y additional.fields.value.string_value | ||
| ID de celda (cell_id) | cell_id | additional.fields.key y additional.fields.value.string_value | ||
| Código de evento de GTP (event_code) | event_code | additional.fields.key y additional.fields.value.string_value | ||
| Ubicación de origen (srcloc) | principal.location.country_or_region | |||
| Ubicación de destino (dstloc) | target.location.country_or_region | |||
| ID de túnel o IMSI (imsi) | tunnelid | additional.fields.key y additional.fields.value.string_value | ||
| Monitor Tag/IMEI (imei) | monitortag | additional.fields.key y additional.fields.value.string_value | ||
| Hora de inicio (start) | start | additional.fields.key y additional.fields.value.string_value | ||
| Tiempo transcurrido (elapsed) | network.session_duration.seconds | |||
| Regla de inspección de túneles (tunnel_insp_rule) | tunnel_insp_rule | security_result.detection_fields.key/value | ||
| IP de usuario remoto (remote_user_ip) | principal.ip | |||
| ID de usuario remoto (remote_user_id) | remote_user_id | principal.user.userid | ||
| UUID de la regla (rule_uuid) | security_result.rule_id | |||
| ID de PCAP (pcap_id) | pcap_id | additional.fields.key y additional.fields.value.string_value | ||
| Marca de tiempo de alta resolución (high_res_timestamp) | additional.fields.key y additional.fields.value.string_value | |||
| Un tipo de servicio de segmento (nsdsai_sst) | nsdsai_sst | additional.fields.key y additional.fields.value.string_value | ||
| Un diferenciador de segmento (nsdsai_sd) | nsdsai_sd | additional.fields.key y additional.fields.value.string_value | ||
| Subcategoría de la aplicación (subcategory_of_app) | subcategory_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Categoría de la aplicación (category_of_app) | category_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Tecnología de aplicaciones (technology_of_app) | technology_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Riesgo de la aplicación (risk_of_app) | risk_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Característica de la aplicación (characteristic_of_app) | characteristic_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Contenedor de aplicaciones (container_of_app) | container_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Aplicación SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Estado de sanción de la aplicación (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key y additional.fields.value.string_value |
SCTP
| Campo de CSV | Campo CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | receive_time o cef-formatted-receive_time | metadata.collected_timestamp | ||
| Número de serie (serial) | serial | intermediary.asset.hardware.serial_number | ||
| Tipo (type) | tipo | metadata.product_event_type | ||
| Hora de generación (time_generated o cef-formatted-time_generated) | time_generated o cef-formatted-time_generated | metadata.event_timestamp | ||
| Dirección de origen (src) | src | principal.ip | ||
| Dirección de destino (dst) | dst | target.ip | ||
| Nombre de la regla | regla | security_result.rule_name | ||
| Zona de origen (desde) | de | additional.fields.key y additional.fields.value.string_value | ||
| Zona de destino | a | additional.fields.key y additional.fields.value.string_value | ||
| Interfaz de entrada (inbound_if) | inbound_if | additional.fields.key y additional.fields.value.string_value | ||
| Interfaz de salida (outbound_if) | outbound_if | additional.fields.key y additional.fields.value.string_value | ||
| Registrar acción (logset) | logset | additional.fields.key y additional.fields.value.string_value | ||
| ID de sesión (sessionid) | sessionid | network.session_id | ||
| Número de repeticiones (repeatcnt) | repeatcnt | additional.fields.key y additional.fields.value.string_value | ||
| Puerto de origen (sport) | deporte | principal.port | ||
| Puerto de destino (dport) | dport | target.port | ||
| Protocolo IP (proto) | proto | network.ip_protocol (enum) | ||
| Acción (action) | acción | security_result.action_details security_result.action |
||
| Jerarquía de grupos de dispositivos (dg_hier_level_1 a dg_hier_level_4) | dg_hier_level_1 a dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value | ||
| Nombre del dispositivo (device_name) | device_name | intermediary.hostname | ||
| Número de secuencia (seqno) | seqno | metadata.product_log_id | ||
| ID de asociación SCTP (assoc_id) | assoc_id | additional.fields.key y additional.fields.value.string_value | ||
| ID de protocolo de carga útil (ppid) | ppid | additional.fields.key y additional.fields.value.string_value | ||
| Gravedad (severity) | gravedad | security_result.severity y security_result.severity_details | ||
| Tipo de fragmento SCTP (sctp_chunk_type) | sctp_chunk_type | additional.fields.key y additional.fields.value.string_value | ||
| Tipo de evento SCTP (sctp_event_type) | sctp_event_type | additional.fields.key y additional.fields.value.string_value | ||
| Etiqueta de verificación SCTP 1 (verif_tag_1) | verif_tag_1 | additional.fields.key y additional.fields.value.string_value | ||
| Etiqueta de verificación SCTP 2 (verif_tag_2) | verif_tag_2 | additional.fields.key y additional.fields.value.string_value | ||
| Código de motivo de SCTP (sctp_cause_code) | sctp_cause_code | additional.fields.key y additional.fields.value.string_value | ||
| ID de aplicación de Diameter (diam_app_id) | diam_app_id | additional.fields.key y additional.fields.value.string_value | ||
| Código de comando de diámetro (diam_cmd_code) | diam_cmd_code | additional.fields.key y additional.fields.value.string_value | ||
| Código de AVP de diámetro (diam_avp_code) | diam_avp_code | additional.fields.key y additional.fields.value.string_value | ||
| ID de flujo SCTP (stream_id) | stream_id | additional.fields.key y additional.fields.value.string_value | ||
| Motivo de finalización de la asociación SCTP (assoc_end_reason) | assoc_end_reason | additional.fields.key y additional.fields.value.string_value | ||
| Código de operación (op_code) | op_code | additional.fields.key y additional.fields.value.string_value | ||
| SSN de la parte que llama de SCCP (sccp_calling_ssn) | sccp_calling_ssn | additional.fields.key y additional.fields.value.string_value | ||
| Título global de la parte que llama de SCCP (sccp_calling_gt) | sccp_calling_gt | additional.fields.key y additional.fields.value.string_value | ||
| Filtro SCTP (sctp_filter) | sctp_filter | additional.fields.key y additional.fields.value.string_value | ||
| Bloques de SCTP | trozos | additional.fields.key y additional.fields.value.string_value | ||
| Fragmentos SCTP enviados (chunks_sent) | chunks_sent | additional.fields.key y additional.fields.value.string_value | ||
| Bloques SCTP recibidos (chunks_received) | chunks_received | additional.fields.key y additional.fields.value.string_value | ||
| Paquetes | paquetes | additional.fields.key y additional.fields.value.string_value | ||
| UUID de la regla (rule_uuid) | rule_uuid | security_result.rule_id | ||
| Sistema virtual (vsys) | vsys | intermediary.asset.attribute.labels.key/value | ||
| Nombre del sistema virtual (vsys_name) | vsys_name | intermediary.asset.attribute.labels.key/value | ||
| Paquetes enviados (pkts_sent) | pkts_sent | network.sent_packets | ||
| Paquetes recibidos (pkts_received) | pkts_received | network.received_packets |
Auditoría
| Campo de CSV | Campo CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Generar hora | metadata.event_timestamp | |||
| Tipo de amenaza o contenido (subtipo) | metadata.product_event_type | |||
| ID de evento | principal.application | |||
| Objeto | principal.user.userid | |||
| Comando de la CLI | principal.process.command_line | |||
| Gravedad | security_result.severity | |||
| Número de serie | intermediary.asset.hardware.serial_number |
Referencia de asignación de campos: tipos de registro a tipos de evento de UDM
En la siguiente tabla se enumeran los tipos de registros de cortafuegos de Palo Alto Networks y sus tipos de eventos de UDM correspondientes.
| Tipo de registro | Tipo de evento de UDM |
| Tráfico | NETWORK_CONNECTION |
| Amenaza | NETWORK_CONNECTION |
| Filtrado de URLs | NETWORK_CONNECTION |
| WildFire | NETWORK_CONNECTION
Los registros de envíos de WildFire son un subtipo de registro de amenazas y usan el mismo formato syslog. |
| Filtrado de datos | NETWORK_CONNECTION |
| Túnel | NETWORK_CONNECTION |
| GTP | NETWORK_CONNECTION |
| Configuración | SETTING_MODIFICATION/SETTING_CREATION/SETTING_DELETION/SETTING_UNCATEGORIZED
El valor del campo "Command (cmd)" determina la asignación del tipo de evento de UDM. Si el valor del campo cmd es add o clone, se define SETTING_CREATION. Si el valor del campo cmd es delete, se asigna SETTING_DELETION. Si el valor del campo cmd es edit, move, rename, set o commit, se define SETTING_MODIFICATION. Si el valor del campo cmd no contiene ningún valor, se asigna SETTING_UNCATEGORIZED. |
| Sistema |
Si el valor de subtype es "dhcp", se define NETWORK_DHCP. Si el valor de subtype es "auth", se define USER_LOGIN. Si el valor de la descripción es "logged in", se define USER_LOGIN. Si el valor de la descripción es "logged out", se define USER_LOGOUT. En el caso de otros valores del subtipo, se asigna GENERIC_EVENT. |
| Coincidencia de HIP | NETWORK_CONNECTION |
| Etiqueta de IP | GENERIC_EVENT |
| User-ID | USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED
Si el valor de subtype es "login", se define USER_LOGIN. Si el valor de subtype es "logout", se define USER_LOGOUT. Si el subtipo no contiene ningún valor, se asigna USER_UNCATEGORIZED. |
| Desencriptado | NETWORK_CONNECTION |
| Autenticación | GENERIC_EVENT |
| SCTP | NETWORK_CONNECTION |
| Auditoría | GENERIC_EVENT |
Delta de asignación de UDM
Referencia de delta de asignación de UDM: cortafuegos de Palo Alto Networks
En la siguiente tabla se muestra la diferencia entre la antigua asignación de UDM de Palo Alto Networks Firewall y la nueva asignación de UDM de Palo Alto Networks Firewall.
UDM Event Type Delta
| Log type | Old UDM Event Type | New UDM Event Type |
| WildFire | NETWORK_CONNECTION | SCAN_UNCATEGORIZED |
| Data Filtering | NETWORK_CONNECTION | NETWORK_UNCATEGORIZED |
| Authentication | STATUS_UPDATE | STATUS_UNCATEGORIZED |
UDM Field Mapping Delta
| Log Type | Old UDM Mapping | CSV Log Field | CEF Log Field | LEEF Log Field | New UDM Mapping |
|---|---|---|---|---|---|
| System | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| System | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| System | about.labels.key/value additional.fields.key/value.string_value | Object (object) | fname | Filename | target.resource.name |
| System | Description (opaque) | msg | msg | metadata.description | |
| System | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| System | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| Config | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| Config | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| Config | principal.process.command_line | Configuration Path (path) | msg | ConfigurationPath | principal.process.command_line |
| Config | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| Config | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| Config | principal.asset.attribute.labels.key/value | Device Group (dg_id) | PanOSFWDeviceGroup | target.asset.attribute.labels | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Threat/Wildfire | target.file.full_path target.url target.hostname | URL/Filename (misc) | request | Miscellaneous | target.file.names target.url |
| Threat/Wildfire | about.file.sha1/md5/sha256 | File Digest (filedigest) | fileHash | FileDigest | target.file.sha1/md5/sha256 |
| Threat/Wildfire | about.file.mime_type | File Type (filetype) | fileType | FileType | target.file.mime_type |
| Threat/Wildfire | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Threat/Wildfire | principal.user.product_object_id | Source VM UUID (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id |
| Threat/Wildfire | target.user.product_object_id | Destination VM UUID (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | HTTP Headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| Threat/Wildfire | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| Threat/Wildfire | principal.asset.software.version | Source Device OS Version (src_osversion) | PanSrcDeviceOSv | principal.platform_version | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| Threat/Wildfire | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| Threat/Wildfire | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | PanReasonFilteringAction | security_result.summary | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Packets Sent (pkts_sent) | PanOSPacketsSent | srcPackets | network.sent_packets |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Packets Received (pkts_received) | PanOSPacketsReceived | dstPackets | network.received_packets |
| Traffic | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| Traffic | principal.asset.platform_software.platform(enum) principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| Traffic | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| Traffic | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| User-ID | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| User-ID | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| User-ID | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | intermediary.resource.product_object_id |
| User-ID | principal.user.userid principal.administrative_domain principal.user.email_addresses | User by Source (userbysource) | PanOSUserBySource | target.user.userid target.user.email_addresses | |
| User-ID | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| HIP Match | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | HIP (matchname) | cat | HIP | target.resource.attribute.labels |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | HIP Type (matchtype) | Device Event Class ID (Header) | HIPType | target.resource.attribute.labels |
| HIP Match | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| HIP Match | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| HIP Match | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id |
| HIP Match | principal.asset.product_object_id | Host ID (hostid) | PanOSHostID | principal.asset.asset_id | |
| HIP Match | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| IP-Tag | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| IP-Tag | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| IP-Tag | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOsVsysName | vSrcName | target.asset.attribute.labels |
| IP-Tag | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| IP-Tag | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id |
| IP-Tag | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Decryption | target.application | Application (app) | app | network.application_protocol | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | intermediary.asset.attribute.labels | |
| Decryption | principal.asset.asset_id | Source VM UUID (src_uuid) | PanOSSourceUUID | principal.asset.product_object_id | |
| Decryption | target.asset.asset_id | Destination VM UUID (dst_uuid) | PanOSDestinationUUID | target.asset.product_object_id | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanOSContainerID | intermediary.resource.product_object_id | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanOSContainerNameSpace | target.resource.attribute.labels additional.fields.key/value.string_value | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanOSContainerName | target.resource.name | |
| Decryption | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanOSSourceDeviceCategory | principal.asset.category | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanOSSourceDeviceModel | principal.asset.hardware.model | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanOSSourceDeviceVendor | principal.asset.hardware.manufacturer | |
| Decryption | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanOSSourceDeviceOSFamily | principal.platform | |
| Decryption | principal.asset.software.version | Source Device OS Version (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanOSDestinationDeviceCategory | target.asset.category | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanOSDestinationDeviceModel | target.asset.hardware.model | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanOSDestinationDeviceVendor | target.asset.hardware.manufacturer | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanOSDestinationDeviceOSFamily | target.platform | |
| Decryption | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanOSDestinationDeviceOSVersion | target.platform_version | |
| Decryption | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | intermediary.asset.attribute.labels | ||
| Decryption | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Tunnel | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Packets Sent (pkts_sent) | PanOSPacketsSent | srcPackets | network.sent_packets |
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Packets Received (pkts_received) | PanOSPacketsReceived | dstPackets | network.received_packets |
| Tunnel | target.ip | Remote User IP (remote_user_ip) | PanOSRmtUserIP | principal.ip | |
| Tunnel | target.labels.key/value additional.fields.key/value.string_value | Remote User ID (remote_user_id) | PanOSRmtUserID | principal.user.userid | |
| Tunnel | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Authentication | target.user.user_display_name | Normalize User (normalize_user) | cs2 | NormalizeUser | target.user.user_display_name |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Object (object) | fname | ObjectName | target.resource.name |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Authentication Policy (authpolicy) | cs4 | AuthPolicy | additional.fields.key/value.string_value |
| Authentication | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Authentication | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| Authentication | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res _timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanOSSourceDeviceCategory | principal.asset.category | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanOSSourceDeviceModel | principal.asset.hardware.model | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanOSSourceDeviceVendor | principal.asset.hardware.manufacturer | |
| Authentication | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanOSSourceDeviceOSFamily | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | |
| Authentication | principal.asset.software.version | Source Device OS Version (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| URL | target.file.full_path target.url | URL/Filename (misc) | Miscellaneous | target.file.names target.url | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Category (category) | cs2 | URLCategory | security_result.category_details |
| URL | about.file.sha1/md5/sha256 | filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | |
| URL | about.file.mime_type | filetype (filetype) | target.file.mime_type | ||
| URL | about.labels.key/value additional.fields.key/value.string_value | xff (xff) | PanOSXForwarderfor | identSrc | principal.ip |
| URL | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| URL | about.url | file_url (file_url) | target.url | ||
| URL | principal.asset.asset_id | Source VM UUID (src_uuid) | SrcUUID | principal.asset.product_object_id | |
| URL | target.asset.asset_id | Destination VM UUID (dst_uuid) | DstUUID | target.asset.product_object_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | http_headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| URL | about.labels.key/value additional.fields.key/value.string_value | UUID for rule (rule_uuid) | PanOSRuleUUID | security_result.rule_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| URL | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| URL | principal.asset.software.version | Source Device OS Version (src_osversion) | PanSrcDeviceOSv | principal.platform_version | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Hostname (src_host) | PanSrcHostname | principal.hostname | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| URL | target.asset.platform_software.platform target.labels.key/value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| URL | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| URL | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| URL | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Res Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | PanReasonFilteringAction | security_result.summary | |
| Data | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Data | target.file.full_path target.url | URL/Filename (misc) | Miscellaneous | target.file.names target.url | |
| Data | about.labels.key/value additional.fields.key/value.string_value | Category (category) | cs2 | URLCategory | security_result.category_details |
| Data | about.file.sha1/md5/sha256 | filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | |
| Data | about.file.mime_type | filetype (filetype) | target.file.mime_type | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | xff (xff) | principal.ip | ||
| Data | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Data | about.url | file_url (file_url) | target.url | ||
| Data | principal.asset.asset_id | Source VM UUID (src_uuid) | SrcUUID | principal.asset.product_object_id | |
| Data | target.asset.asset_id | Destination VM UUID (dst_uuid) | DstUUID | target.asset.product_object_id | |
| Data | about.labels.key/value additional.fields.key/value.string_value | http_headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| Data | about.labels.key/value additional.fields.key/value.string_value | UUID for rule (rule_uuid) | PanOSRuleUUID | security_result.rule_id | |
| Data | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | network.application_protocol_version | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | principal.asset.category | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | principal.asset.hardware.model | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | principal.asset.hardware.manufacturer | ||
| Data | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | principal.platform | ||
| Data | principal.asset.software.version | Source Device OS Version (src_osversion) | principal.platform_version | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Hostname (src_host) | principal.hostname | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | target.asset.category | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | target.asset.hardware.model | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | target.asset.hardware.manufacturer | ||
| Data | target.asset.platform_software.platform target.labels.key/value | Destination Device OS Family (dst_osfamily) | target.platform | ||
| Data | target.asset.software.version | Destination Device OS Version (dst_osversion) | target.platform_version | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | intermediary.resource.product_object_id | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | target.resource.attribute.labels | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | target.resource.name | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | principal.asset.asset_id | ||
| Data | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Res Timestamp (high_res_timestamp) | additional.fields.key/value.string_value | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | security_result.summary | ||
| GlobalProtect | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | PanOSVirtualSystem | intermediary.asset.attribute.labels | |
| GlobalProtect | principal.user.email_address principal.user.userid principal.administrative_domain | Source User (srcuser) | PanOSSourceUserName | target.user.email_address target.user.userid | |
| GlobalProtect | principal.asset.platform_software.platform(enum) | Client OS (client_os) | PanOSEndpointOSType | principal.platform | |
| GlobalProtect | principal.asset.platform_software.platform_version | Client OS Version (client_os_ver) | PanOSEndpointOSVersion | principal.platform_version | |
| GlobalProtect | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| GlobalProtect | about.labels.key/value additional.fields.key/value.string_value | Gateway Name (gateway) | PanOSAttemptedGateways | target.resource.name | |
| GlobalProtect | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | intermediary.asset.attribute.labels | ||
| GlobalProtect | target.hostname | Device Name (device_name) | intermediary.hostname | ||
| GlobalProtect | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| CORRELATION | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | VirtualSystem | intermediary.asset.attribute.labels | |
| CORRELATION | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | vSrcName | intermediary.asset.attribute.labels | |
| CORRELATION | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | VirtualSystemID | intermediary.resource.product_object_id | |
| GTP | additional.fields.key/value.string_value | Virtual System (vsys) | intermediary.asset.attribute.labels | ||
| GTP | target.ip | Remote User IP (remote_user_ip) | principal.ip | ||
| GTP | additional.fields.key/value.string_value | Remote User ID (remote_user_id) | principal.user.userid | ||
| GTP | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | additional.fields.key/value.string_value |
Servicio de registro de Strata Firewall de Palo Alto Networks
Información general
El servicio de registro de Strata de Palo Alto Networks® proporciona almacenamiento y agregación de registros centralizados basados en la nube para tus firewalls on-premise y virtuales (nube privada y nube pública), para Prisma Access y para servicios ofrecidos en la nube, como Cortex XDR.El servicio de registro de Strata es seguro, resistente y tolerante a fallos, y asegura que tus datos de registro estén actualizados y disponibles cuando los necesites. Proporciona una infraestructura de registro escalable que te permite no tener que planificar ni implementar colectores de registros para satisfacer tus necesidades de conservación de registros. Si ya tienes Log Collectors locales, el nuevo servicio de registro de Strata puede complementar tu configuración actual. Puede aumentar su infraestructura de recogida de registros con el servicio de registro de Strata basado en la nube para ampliar la capacidad operativa a medida que crece su empresa o para satisfacer las necesidades de capacidad de nuevas ubicaciones.Con este servicio, Palo Alto Networks se encarga del mantenimiento y la monitorización continuos de la infraestructura de registro para que usted pueda centrarse en su empresa.
Verifica los formatos de registro y las versiones de PAN-OS que admite el analizador del servicio de registro de Strata. En la siguiente tabla se indican los formatos de registro y las versiones de PAN-OS que admite el analizador del servicio de registro de Strata:
Formato de registro Versión de PAN-OS JSON 12.1 Verifica los tipos de registros de cortafuegos de Palo Alto Networks que admite el analizador de Google SecOps. El analizador de Google SecOps admite los siguientes tipos de registros de cortafuegos de Palo Alto Networks:
- Tráfico
- Amenaza
- Inspección de túneles
- Sistema
- Coincidencia de HIP
- Etiqueta IP
- User-ID
- Desencriptado
- Autenticación
- Filtrado de URLs
- GlobalProtect
Despliegue del servicio de registro de Strata
- Asegúrese de que el producto de cortafuegos de Palo Alto Networks se haya implementado y configurado correctamente. Para obtener instrucciones de configuración detalladas, consulta la documentación de PAN-OS y, a continuación, sigue este documento de implementación antes de enviar los registros al servicio de registro de Strata Requisitos previos de la implementación del servicio de registro de Strata.
Empieza a enviar registros al servicio de registro de Strata:
Para empezar a enviar registros al servicio de registro de Strata, sigue estos pasos:
- Instalar una versión compatible de PAN-OS®
- Activar el servicio de registro de Strata: para activar el servicio de registro de Strata, se debe aprovisionar el certificado que necesitan los cortafuegos para conectarse de forma segura al servicio de registro de Strata.
- Incorporar cortafuegos al servicio de registro de Strata con o sin Panorama
Para ver los pasos detallados de la configuración inicial, consulta la documentación.
Reenviar registros del servicio de registro de Strata
Para satisfacer tus necesidades de almacenamiento, informes y monitorización a largo plazo, o bien tus requisitos legales y de cumplimiento, puedes configurar Strata Logging Service para que reenvíe los registros a un servidor HTTPS o a los siguientes SIEMs:
- Exabeam
- Google Chronicle
- Microsoft Sentinel
- Recopilador de eventos HTTP (HEC) de Splunk
Usa el método de reenvío HTTPS para reenviar los registros mediante el servicio de registro de Strata. Para obtener información detallada, consulta esta documentación.
Formatos de registro admitidos
El analizador de firewall del servicio de registro de Strata de Palo Alto Networks admite registros en formato JSON.
Registros de ejemplo admitidos
JSON
{"source": "Palo Alto Networks FLS LF", "host": "dummy-loghost", "time": "1730265996460", "event": {"TimeReceived": "2024-10-30T05:25:50.000000Z", "DeviceSN": "no-serial", "LogType": "TRAFFIC", "Subtype": "end", "ConfigVersion": "10.2", "TimeGenerated": "2024-10-30T05:25:40.000000Z", "SourceAddress": "198.51.100.6", "DestinationAddress": "198.51.100.6", "NATSource": "", "NATDestination": "", "Rule": "egress-dns-ping-traceroute", "SourceUser": null, "DestinationUser": null, "Application": "dns-base", "VirtualLocation": "vsys1", "FromZone": "VA8280-RN", "ToZone": "inter-fw", "InboundInterface": "tunnel.101", "OutboundInterface": "tunnel.4005", "LogSetting": "Cortex Data Lake", "SessionID": 754194, "RepeatCount": 1, "SourcePort": 53578, "DestinationPort": 53, "NATSourcePort": 0, "NATDestinationPort": 0, "Protocol": "udp", "Action": "allow", "Bytes": 214, "BytesSent": 72, "BytesReceived": 142, "PacketsTotal": 2, "SessionStartTime": "2024-10-30T05:25:10.000000Z", "SessionDuration": 0, "URLCategory": "any", "SequenceNo": 7382192512716388639, "SourceLocation": "198.51.100.6-198.51.255.255", "DestinationLocation": "198.51.100.6-198.51.255.255", "PacketsSent": 1, "PacketsReceived": 1, "SessionEndReason": "aged-out", "DGHierarchyLevel1": 65537, "DGHierarchyLevel2": 65538, "DGHierarchyLevel3": 65541, "DGHierarchyLevel4": 0, "VirtualSystemName": "", "DeviceName": "VA8280-RN", "ActionSource": "from-policy", "SourceUUID": null, "DestinationUUID": null, "IMSI": 0, "IMEI": null, "ParentSessionID": 0, "ParentStarttime": "1970-01-01T00:00:00.000000Z", "Tunnel": "N/A", "EndpointAssociationID": 72057594037927936, "ChunksTotal": 0, "ChunksSent": 0, "ChunksReceived": 0, "RuleUUID": "95cfc3cc-cb00-4758-af1d-de9ab5f07f97", "HTTP2Connection": 0, "LinkChangeCount": 0, "SDWANPolicyName": null, "LinkSwitches": null, "SDWANCluster": null, "SDWANDeviceType": null, "SDWANClusterType": null, "SDWANSite": null, "DynamicUserGroupName": null, "X-Forwarded-ForIP": null, "SourceDeviceCategory": null, "SourceDeviceProfile": null, "SourceDeviceModel": null, "SourceDeviceVendor": null, "SourceDeviceOSFamily": null, "SourceDeviceOSVersion": null, "SourceDeviceHost": null, "SourceDeviceMac": null, "DestinationDeviceCategory": null, "DestinationDeviceProfile": null, "DestinationDeviceModel": null, "DestinationDeviceVendor": null, "DestinationDeviceOSFamily": null, "DestinationDeviceOSVersion": null, "DestinationDeviceHost": null, "DestinationDeviceMac": null, "ContainerID": null, "ContainerNameSpace": null, "ContainerName": null, "SourceEDL": null, "DestinationEDL": null, "GPHostID": null, "EndpointSerialNumber": null, "SourceDynamicAddressGroup": null, "DestinationDynamicAddressGroup": null, "HASessionOwner": null, "TimeGeneratedHighResolution": "2024-10-30T05:25:41.009000Z", "NSSAINetworkSliceType": null, "NSSAINetworkSliceDifferentiator": null}}"
Referencia de la asignación de campos: campos de registro a campos de UDM
En esta sección se explica cómo asigna el analizador los campos de registro del firewall de Palo Alto Networks Strata Logging Service a los campos de evento de UDM de Google para cada tipo de registro.
Consulta las siguientes secciones para obtener información sobre la asignación de cada tipo de registro:
- Sistema
- Amenaza
- Tráfico
- ID de usuario
- Concordancia de HIP
- Etiqueta de IP
- Descifrado
- Túnel
- Autenticación
- URL
- GlobalProtect
- SCTP
- Auditoría
Sistema
En la siguiente tabla se enumeran los campos de registro del tipo de registro del sistema y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| AgentContentVersion | additional.fields.key/value.string_value |
| AgentDataCollectionStatus | target.resource.attribute.labels |
| AgentID | target.resource.attribute.labels |
| AgentIsolationStatus | target.resource.attribute.labels |
| AgentStatus | target.resource.attribute.labels |
| AgentVersion | target.asset.software.version |
| ConfigVersion | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DeviceGroup | target.group.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EndpointCPUArchitecture | target.asset.hardware.cpu_platform |
| EndpointDeviceDomain | target.asset.administrative_domain |
| EndpointDeviceName | target.asset.hostname |
| EndpointIPaddress | target.asset.ip |
| VDIEndpoint | target.asset.attribute.labels |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointOSVersion | target.platform_version |
| AgentTimeZoneOffset | additional.fields.key/value.string_value |
| EndpointUserDomain | additional.fields.key/value.string_value |
| EndpointUserName | target.user.user_display_name |
| EndpointUserUUID | target.user.userid |
| EventComponent | additional.fields.key/value.string_value |
| EventDescription | metadata.description |
| EventName | additional.fields.key/value.string_value |
| EventTime | metadata.event_timestamp |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogCategory | security_result.category_details |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| LogSourceID | target.resource.attribute.labels |
| LogSourceName | observer.asset.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| LogTime | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Severity | security_result.severity |
| Subtype | metadata.product_event_type |
| Template | target.resource.attribute.labels |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
Amenaza
En la siguiente tabla se enumeran los campos de registro del tipo de registro Amenaza y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| ApplianceOrCloud | additional.fields.key/value.string_value |
| CloudHostname | additional.fields.key/value.string_value |
| CloudReportID | security_result.detection_fields.key/value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DirectionOfAttack | security_result.detection_fields.key/value |
| DomainEDL | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| FileName | target.file.names |
| FileHash | target.file.sha1 |
| FileType | additional.fields.key/value.string_value |
| FileURL | target.url |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HostID | principal.asset.asset_id |
| HTTP2Connection | network.application_protocol_version |
| HTTPMethod | network.http.method |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| LocalDeepLearningAnalyzed | additional.fields.key/value.string_value |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| PartialHash | additional.fields.key/value.string_value |
| PayloadProtocolID | additional.fields.key/value.string_value |
| Packet | additional.fields.key/value.string_value |
| PacketID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| RecipientEmail | target.user.email_addresses |
| ReportID | security_result.detection_fields.key/value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SenderEmail | principal.user.email_addresses |
| SequenceNo | metadata.product_log_id |
| SessionID | network.session_id |
| Severity | security_result.severity |
| SigFlags | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| EmailSubject | network.email.subject |
| ApplicationTechnology | additional.fields.key/value.string_value |
| ThreatCategory | security_result.detection_fields.key/value.key/value |
| ThreatID | security_result.threat_id |
| ThreatName | security_result.threat_name |
| ThreatNameFirewall | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLDomain | target.domain.name |
| URLCounter | additional.fields.key/value.string_value |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| Verdict | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-ForIP | principal.ip |
Tráfico
En la siguiente tabla se enumeran los campos de registro del tipo de registro de tráfico y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| ActionSource | additional.fields.key/value.string_value |
| AIFwdError | additional.fields.key/value.string_value |
| AITraffic | additional.fields.key/value.string_value |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| BytesReceived | network.received_bytes |
| BytesSent | network.sent_bytes |
| Bytes | additional.fields.key/value.string_value |
| ChunksReceived | additional.fields.key/value.string_value |
| ChunksSent | additional.fields.key/value.string_value |
| ChunksTotal | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| EndpointAssociationID | additional.fields.key/value.string_value |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HASessionOwner | additional.fields.key/value.string_value |
| GPHostID | additional.fields.key/value.string_value |
| HTTP2Connection | network.application_protocol_version |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsOffloaded | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| LinkChangeCount | additional.fields.key/value.string_value |
| LinkSwitches | additional.fields.key/value.string_value |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| SDWANPolicyName | additional.fields.key/value.string_value |
| Protocol | network.ip_protocol |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SDWANFECRatio | additional.fields.key/value.string_value |
| SDWANCluster | additional.fields.key/value.string_value |
| SDWANClusterType | additional.fields.key/value.string_value |
| SDWANDeviceType | additional.fields.key/value.string_value |
| SDWANSite | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionStartTime | additional.fields.key/value.string_value |
| SessionTracker | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| SessionDuration | network.session_duration |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLCategory | target.url_metadata.categories |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-ForIP | principal.ip |
User-ID
En la siguiente tabla se enumeran los campos de registro del tipo de registro User-Id y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| AuthFactorNo | security_result.detection_fields.key/value |
| AuthenticatedUserDomain | target.user.administrative_domain |
| AuthenticatedUserName | target.user.userid |
| AuthenticatedUserUUID | target.user.product_object_id |
| ConfigVersion | additional.fields.key/value.string_value |
| CountofRepeats | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationPort | target.port |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EventID | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsDuplicateUser | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MappingDataSource | additional.fields.key/value.string_value |
| MappingDataSourceName | additional.fields.key/value.string_value |
| MappingDataSourceType | additional.fields.key/value.string_value |
| MappingTimeout | additional.fields.key/value.string_value |
| MFAFactorType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SourceIP | principal.ip |
| SourcePort | principal.port |
| Subtype | metadata.product_event_type |
| Tag | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| UGFlags | additional.fields.key/value.string_value |
| User | target.user.userid |
| UserGroupFound | additional.fields.key/value.string_value |
| UserIdentifiedBySource | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Coincidencia de HIP
En la siguiente tabla se enumeran los campos de registro del tipo de registro de coincidencias de historial de IPs y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| ConfigVersion | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EndpointDeviceName | principal.asset.hostname |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| HipMatchName | target.resource.attribute.labels |
| HipMatchType | target.resource.attribute.labels |
| HostID | principal.asset.asset_id |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | metadata.product_event_type |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Source | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceIP | principal.ip |
| SourceIPv6 | principal.ip |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| TimestampDeviceIdentification | principal.asset.first_seen_time |
| UUID | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
Etiqueta de IP
En la siguiente tabla se enumeran los campos de registro del tipo de registro de etiquetas de IP y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| ConfigVersion | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EventID | additional.fields.key/value.string_value |
| IPSubnetRange | network.ip_subnet_range |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSetting | target.resource.attribute.labels |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MappingDataSource | additional.fields.key/value.string_value |
| MappingDataSourceSubType | additional.fields.key/value.string_value |
| MappingDataSourceType | additional.fields.key/value.string_value |
| MappingTimeout | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| RuleMatched | security_result.rule_name |
| RuleMatchedUUID | security_result.rule_id |
| SequenceNo | metadata.product_log_id |
| SourceIP | principal.ip |
| Subtype | metadata.product_event_type |
| TagName | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
Desencriptado
En la siguiente tabla se enumeran los campos de registro del tipo de registro de descifrado y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| CertificateFlags | additional.fields.key/value.string_value |
| CertificateSerial | network.tls.server.certificate.serial |
| CertificateSize | additional.fields.key/value.string_value |
| CertificateVersion | network.tls.server.certificate.version |
| ChainStatus | additional.fields.key/value.string_value |
| ApplicationCharacteristics | additional.fields.key/value.string_value |
| ClientToFirewall | additional.fields.key/value.string_value |
| CommonName | additional.fields.key/value.string_value |
| CommonNameLength | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| Cpadding | additional.fields.key/value.string_value |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| Domain | target.hostname |
| EllipticCurve | network.tls.curve |
| ErrorIndex | additional.fields.key/value.string_value |
| ErrorMessage | additional.fields.key/value.string_value |
| Fingerprint | network.tls.server.certificate.md5/sha1/sha256 |
| FirewallToClient | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsCertECDSA | additional.fields.key/value.string_value |
| IsCertRSA | additional.fields.key/value.string_value |
| IsCertCNTruncated | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| IsForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsIssuerCNTruncated | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| IsNAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| PacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsResumeSession | additional.fields.key/value.string_value |
| IsRootCNTruncated | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSNITruncated | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| IssuerCommonName | network.tls.server.certificate.issuer |
| IssuerNameLength | additional.fields.key/value.string_value |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| TimeNotAfter | additional.fields.key/value.string_value |
| TimeNotBefore | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| Padding | additional.fields.key/value.string_value |
| Padding3 | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| PolicyName | additional.fields.key/value.string_value |
| Protocol | network.ip_protocol |
| ProxyType | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| RootCommonName | additional.fields.key/value.string_value |
| RootCNLength | additional.fields.key/value.string_value |
| RootStatus | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SessionID | network.session_id |
| ServerNameIndication | network.tls.client.server_name |
| SNILength | additional.fields.key/value.string_value |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeReceivedManagementPlane | additional.fields.key/value.string_value |
| TLSAuth | additional.fields.key/value.string_value |
| TLSEncryptionAlgorithm | additional.fields.key/value.string_value |
| TLSKeyExchange | additional.fields.key/value.string_value |
| TLSVersion | network.tls.version |
| ToZone | additional.fields.key/value.string_value |
| Tpadding | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| Vpadding | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Túnel
En la siguiente tabla se enumeran los campos de registro del tipo de registro Tunnel y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| AccessPointName | additional.fields.key/value.string_value |
| Action | security_result.action |
| ActionSource | additional.fields.key/value.string_value |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| BytesReceived | network.received_bytes |
| BytesSent | network.sent_bytes |
| Bytes | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| LoggingServiceID | additional.fields.key/value.string_value |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MobileAreaCode | additional.fields.key/value.string_value |
| MobileBaseStationCode | additional.fields.key/value.string_value |
| MobileCountryCode | additional.fields.key/value.string_value |
| MobileIP | additional.fields.key/value.string_value |
| MobileNetworkCode | additional.fields.key/value.string_value |
| MobileSubscriberISDN | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceDifferentiator | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsDroppedMax | additional.fields.key/value.string_value |
| PacketsDroppedStrict | additional.fields.key/value.string_value |
| PacketsDroppedTunnel | additional.fields.key/value.string_value |
| PacketsDroppedProtocol | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| ProtocolDataUnitsessionID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| RadioAccessTechnology | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionStartTime | additional.fields.key/value.string_value |
| SessionTracker | additional.fields.key/value.string_value |
| Severity | security_result.severity |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| StandardPortsOfApp | additional.fields.key/value.string_value |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| SessionDuration | network.session_duration |
| Tunnel | additional.fields.key/value.string_value |
| TunnelCauseCode | additional.fields.key/value.string_value |
| TunnelEndpointID1 | additional.fields.key/value.string_value |
| TunnelEndpointID2 | additional.fields.key/value.string_value |
| TunnelEventCode | additional.fields.key/value.string_value |
| TunnelEventType | additional.fields.key/value.string_value |
| TunnelInspectionRule | additional.fields.key/value.string_value |
| TunnelInterface | additional.fields.key/value.string_value |
| TunnelMessageType | additional.fields.key/value.string_value |
| TunnelRemoteIMSIID | additional.fields.key/value.string_value |
| TunnelRemoteUserIP | principal.ip |
| TunnelSessionsClosed | additional.fields.key/value.string_value |
| TunnelSessionsCreated | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLCategory | target.url_metadata.categories |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Autenticación
En la siguiente tabla se enumeran los campos de registro del tipo de registro de autenticación y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| AuthenticationDescription | security_result.description |
| AuthEvent | metadata.description |
| AuthFactorNo | security_result.detection_fields.key/value |
| AuthenticationPolicy | security_result.detection_fields.key/value |
| AuthenticationProtocol | additional.fields.key/value.string_value |
| AuthServerProfile | additional.fields.key/value.string_value |
| AuthenticatedUserDomain | target.administrative_domain |
| AuthenticatedUserName | target.user.userid |
| AuthenticatedUserUUID | target.user.product_object_id |
| ClientType | additional.fields.key/value.string_value |
| ClientTypeName | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| Location | target.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogType | additional.fields.key/value.string_value |
| MFAAuthenticationID | additional.fields.key/value.string_value |
| MFAVendor | additional.fields.key/value.string_value |
| NormalizeUser | target.user.user_display_name |
| Object | target.resource.name |
| RuleMatched | security_result.rule_name |
| RuleMatchedUUID | security_result.rule_id |
| AuthCacheServiceRegion | additional.fields.key/value.string_value |
| SessionID | network.session_id |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceIP | principal.ip |
| TimeGenerated | metadata.event_timestamp |
| User | target.user.userid |
| UserAgentString | network.http.user_agent |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Subtype | metadata.product_event_type |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
URL
En la siguiente tabla se indican los campos de registro del tipo de registro de URL y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| CloudHostname | additional.fields.key/value.string_value |
| CloudReportID | security_result.detection_fields.key/value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentType | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DirectionOfAttack | security_result.detection_fields.key/value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| FileURL | target.url |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HostID | principal.asset.asset_id |
| HTTP2Connection | network.application_protocol_version |
| HTTPHeaders | additional.fields.key/value.string_value |
| HTTPMethod | network.http.method |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| InlineMLVerdict | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| Packet | additional.fields.key/value.string_value |
| PacketID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| Referer | network.http.referral_url |
| HTTPRefererFQDN | additional.fields.key/value.string_value |
| HTTPRefererPort | additional.fields.key/value.string_value |
| HTTPRefererProtocol | additional.fields.key/value.string_value |
| HTTPRefererURLPath | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionID | network.session_id |
| Severity | security_result.severity |
| SigFlags | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URL | target.url_metadata.URL |
| URLCategory | target.url_metadata.categories |
| URLCategoryList | additional.fields.key/value.string_value |
| URLDomain | target.domain.name |
| URLCounter | additional.fields.key/value.string_value |
| UserAgent | network.http.user_agent |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-For | additional.fields.key/value.string_value |
| X-Forwarded-ForIP | principal.ip |
GlobalProtect
En la siguiente tabla se enumeran los campos de registro del tipo de registro GlobalProtect y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| AttemptedGateways | additional.fields.key/value.string_value |
| AuthMethod | extensions.auth.auth_details |
| ConnectionMethod | additional.fields.key/value.string_value |
| ConnectionErrorID | additional.fields.key/value.string_value |
| ConnectionError | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| EndpointDeviceName | principal.asset.hostname |
| GlobalProtectClientVersion | additional.fields.key/value.string_value |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointSN | principal.asset.hardware.serial_number |
| EventIDValue | additional.fields.key/value.string_value |
| Gateway | target.resource.name |
| GatewayPriority | additional.fields.key/value.string_value |
| GatewaySelectionType | additional.fields.key/value.string_value |
| GlobalProtectGatewayLocation | target.location.country_or_region |
| HostID | principal.asset.asset_id |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LoginDuration | network.session_duration |
| Description | security_result.description |
| Portal | target.hostname |
| PrivateIPv4 | principal.ip |
| PrivateIPv6 | principal.ip |
| ProjectName | additional.fields.key/value.string_value |
| PublicIPv4 | principal.nat_ip |
| PublicIPv6 | principal.nat_ip |
| QuarantineReason | security_result.summary |
| SequenceNo | metadata.product_log_id |
| SourceRegion | principal.location.country_or_region |
| SourceUserName | principal.user.user_display_name |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SSLResponseTime | additional.fields.key/value.string_value |
| Stage | additional.fields.key/value.string_value |
| EventStatus | additional.fields.key/value.string_value |
| LogSubtype | metadata.product_event_type |
| TunnelType | additional.fields.key/value.string_value |
| VirtualSystem | intermediary.asset.attribute.labels |
| VirtualSystemName | intermediary.asset.attribute.labels |
| EndpointOSVersion | principal.platform_version |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | metadata.product_event_type |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualSystemID | intermediary.resource.product_object_id |
SCTP
En la siguiente tabla se enumeran los campos de registro del tipo de registro SCTP y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| AssocationEndReason | additional.fields.key/value.string_value |
| ChunksReceived | additional.fields.key/value.string_value |
| ChunksSent | additional.fields.key/value.string_value |
| ChunksTotal | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceClass | target.asset.category |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationIP | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DiamAppID | additional.fields.key/value.string_value |
| DiamAvpCode | additional.fields.key/value.string_value |
| DiameterCommandCode | additional.fields.key/value.string_value |
| DiameterRequestFlag | additional.fields.key/value.string_value |
| DeviceName | principal.asset.hostname |
| SCTPEventType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLFiltering | additional.fields.key/value.string_value |
| IsWildfire | additional.fields.key/value.string_value |
| LogAction | additional.fields.key/value.string_value |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MapAppCode | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PayloadProtocolID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SccpCallingGt | additional.fields.key/value.string_value |
| SccpCallingSSN | additional.fields.key/value.string_value |
| SctpCauseCode | additional.fields.key/value.string_value |
| SctpChunkType | additional.fields.key/value.string_value |
| SctpFilter | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionTracker | additional.fields.key/value.string_value |
| Severity | security_result.severity |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceIP | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VerificationTag1 | additional.fields.key/value.string_value |
| VerificationTag2 | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Auditoría
En la siguiente tabla se enumeran los campos de registro del tipo de registro de auditoría y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| EventCategory | network.http.method |
| EventDescription | metadata.description |
| EventDestinationURL | target.url |
| EventDestinationUserUserID | target.user.userid |
| DestinationVendor | additional.fields.key/value.string_value |
| EventDetails | additional.fields.key/value.string_value |
| EventID | metadata.product_log_id |
| EventName | additional.fields.key/value.string_value |
| EventResult | security_result.summary |
| EventSourceUserUserID | principal.user.userid |
| EventTime | metadata.event_timestamp |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| Subtype | metadata.product_event_type |
| TSGID | additional.fields.key/value.string_value |
| Vendor | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
Referencia de asignación de campos: tipos de registro a tipos de evento de UDM
En la siguiente tabla se muestran los tipos de registros de cortafuegos del servicio de registro de Strata de Palo Alto Networks y sus tipos de eventos de UDM correspondientes.
| Tipo de registro | Tipo de evento de UDM |
| Tráfico | NETWORK_CONNECTION |
| Amenaza | NETWORK_CONNECTION |
| Filtrado de URLs | NETWORK_CONNECTION |
| Túnel | NETWORK_CONNECTION |
| Sistema |
Si el valor de subtype es "dhcp", se define NETWORK_DHCP. Si el valor de subtype es "auth", se define USER_LOGIN. Si el valor de la descripción es "logged in", se define USER_LOGIN. Si el valor de la descripción es "logged out", se define USER_LOGOUT. En el caso de otros valores del subtipo, se asigna GENERIC_EVENT. |
| Coincidencia de HIP | NETWORK_CONNECTION |
| Etiqueta de IP | GENERIC_EVENT |
| User-ID | USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED
Si el valor de subtype es "login", se define USER_LOGIN. Si el valor de subtype es "logout", se define USER_LOGOUT. Si el subtipo no contiene ningún valor, se asigna USER_UNCATEGORIZED. |
| Desencriptado | NETWORK_CONNECTION |
| Autenticación | STATUS_UNCATEGORIZED |
| Globalprotect | USER_LOGIN/USER_LOGOUT/USER_RESOURCE_ACCESS
Si el valor de subtype es "auth", se define USER_LOGIN. Si el valor de subtype es "logout", se define USER_LOGOUT. Si el subtipo no contiene ningún valor, se asigna USER_RESOURCE_ACCESS. |
| SCTP | NETWORK_CONNECTION |
| Auditoría | NETWORK_CONNECTION |
Siguientes pasos
¿Necesitas más ayuda? Recibe respuestas de los miembros de la comunidad y de los profesionales de Google SecOps.