Recopila registros del firewall de Palo Alto Networks

Se admite en los siguientes sistemas operativos:

Firewall de Palo Alto Networks

Descripción general

En este documento, se describe cómo puedes configurar syslog y un retransmisor de SecOps de Google para recopilar registros de firewall de Palo Alto Networks. En este documento, también se explica cómo los campos de registro del firewall de Palo Alto Networks se asignan a los campos del Modelo de datos unificado (UDM) de Google SecOps. Para obtener una descripción general de la transferencia de datos a Google SecOps, consulta Transferencia de datos a Google SecOps. Una etiqueta de transferencia identifica el analizador que normaliza los datos de registro sin procesar en formato UDM estructurado. La información de este documento se aplica al analizador con la etiqueta de transferencia PAN_FIREWALL.

Antes de comenzar

  • Asegúrate de que el producto de firewall de Palo Alto Networks esté implementado y configurado correctamente. Para obtener instrucciones de configuración detalladas, consulta la documentación de PAN-OS.
  • Para comprender los componentes implementados para recopilar los registros del firewall de Palo Alto Networks, revisa la arquitectura de implementación. Cada implementación para el cliente puede ser diferente de esta representación y más compleja. En el siguiente diagrama, se muestra cómo puedes configurar syslog en un firewall de Palo Alto Networks y, luego, instalar un agente de reenvío de SecOps de Google en un servidor Linux para reenviar los datos de registro a SecOps de Google. El analizador admite registros escritos en los siguientes formatos de datos: valores separados por comas (CSV), formato de evento común (CEF) y formato extendido de evento de registro (LEEF).

    Arquitectura de implementación

  • Verifica los formatos de registro y las versiones de PAN-OS que admite el analizador de Google SecOps. En la siguiente tabla, se enumeran los formatos de registro y las versiones de PAN-OS correspondientes que admite el analizador de Google SecOps:

    Formato de registro Versión de PAN-OS
    CSV 10.1.3
    CEF 10.0.0
    LEEF 9.1.0
  • Verifica los tipos de registros del firewall de Palo Alto Networks que admite el analizador de SecOps de Google. El analizador de SecOps de Google admite los siguientes tipos de registros de firewall de Palo Alto Networks:

    • Tráfico
    • Amenaza
    • Envíos a WildFire
    • Inspección de túneles
    • Configuración
    • Sistema
    • Coincidencia de HIP
    • IP-Tag
    • User-ID
    • Desencriptación
    • Autenticación
    • Filtros de URL
    • Filtrado de datos
    • GlobalProtect
    • Correlación
    • GTP
    • SCTP
    • Auditoría

    Para obtener más información sobre los tipos de registros del firewall de Palo Alto Networks, consulta Tipos de registros de PAN-OS.

  • Asegúrate de que todos los sistemas de la arquitectura de implementación estén configurados en la zona horaria UTC.

  • Antes de usar el analizador de firewall de Palo Alto Networks, revisa los cambios en las asignaciones de campos entre el analizador anterior y el analizador de firewall de Palo Alto Networks actual. Como parte de la migración, asegúrate de que las reglas, las búsquedas, los paneles o cualquier otro proceso que dependa de los campos originales usen los campos actualizados.

    Por ejemplo, en la versión anterior del analizador, el campo de registro category se asigna al campo security_result.description del UDM. En el analizador de firewall actual de Palo Alto Networks, el campo de registro category se asigna al campo security_result.category_details de UDM. Si migras al analizador de firewall actual de Palo Alto Networks y usas el campo category en tus reglas, debes modificarlas para que usen el campo security_result.category_details del UDM del analizador actual.

Configura syslog y el reenvío de Google Security Operations

Para configurar syslog y el retransmisor de Google SecOps, completa los siguientes pasos:

  1. Para supervisar los registros CSV, configura el perfil del servidor Syslog. Para obtener más información, consulta Cómo configurar el perfil del servidor syslog. Cuando configures el perfil del servidor syslog, especifica "Predeterminado" como el formato de registro personalizado.
  2. Para supervisar los registros de CEF, configura el firewall de Palo Alto Networks para que reenvíe los registros de CEF. Para obtener más información, descarga la guía de integración de CEF de PAN-OS en formato PDF y consulta la sección "Configuración del NGFW de Palo Alto Networks para generar eventos de CEF".
  3. Para supervisar los registros de LEEF, configura el perfil del servidor syslog. Para obtener más información, consulta Reenvío de registros personalizados en formato LEEF.
  4. Configura el reenvío de Google SecOps para enviar registros a Google Security Operations. Para obtener más información, consulta Cómo instalar y configurar el reenvío en Linux. A continuación, se muestra un ejemplo de configuración de un retransmisor de Google SecOps:

      - syslog:
          common:
            enabled: true
            data_type: PAN_FIREWALL
            batch_n_seconds: 10
            batch_n_bytes: 1048576
          tcp_address: 0.0.0.0:10518
          connection_timeout_sec: 60
    

Configura el reenvío de syslog en el firewall de PAN

Crea un perfil de servidor syslog

  1. Accede a la consola de administración del firewall de Palo Alto Networks.
  2. Ve a Device > Server Profiles > Syslog.
  3. Haz clic en Agregar para crear un perfil de servidor nuevo.
  4. Proporciona los siguientes detalles de configuración:
    • Nombre: Ingresa un nombre descriptivo (por ejemplo, Google SecOps BindPlane).
    • Ubicación: Selecciona el sistema virtual (vsys) o Compartido en el que estará disponible este perfil.
  5. Haz clic en Servidores > Agregar para configurar el servidor syslog.
  6. Proporciona los siguientes detalles de configuración del servidor:
    • Nombre: Ingresa un nombre descriptivo para el servidor (por ejemplo, BindPlane Agent).
    • Servidor Syslog: Ingresa la dirección IP del agente de BindPlane.
    • Transporte: Selecciona UDP o TCP, según la configuración de tu agente de BindPlane (UDP es el valor predeterminado).
    • Puerto: Ingresa el número de puerto del agente de BindPlane (por ejemplo, 514).
    • Formato: Selecciona BSD (predeterminado) o IETF, según tus requisitos.
    • Facility: Selecciona LOG_USER (predeterminado) o cualquier otra instalación según sea necesario.
  7. Haz clic en Aceptar para guardar el perfil del servidor syslog.

Opcional: Configura un formato de registro personalizado para CEF o LEEF

Si necesitas registros en formato de evento común (CEF) o en formato extendido de evento de registro (LEEF) en lugar de CSV, haz lo siguiente:

  1. En el perfil del servidor Syslog, selecciona la pestaña Formato de registro personalizado.
  2. Configura el formato de registro personalizado para cada tipo de registro (Config, System, Threat, Traffic, URL, Data, WildFire, Tunnel, Authentication, User-ID, HIP Match).
  3. Para obtener información sobre la configuración del formato CEF, consulta la Guía de configuración de CEF de Palo Alto Networks.
  4. Haz clic en Aceptar para guardar la configuración.

Crea un perfil de reenvío de registros

  1. Ve a Objetos > Reenvío de registros.
  2. Haz clic en Agregar para crear un perfil nuevo de reenvío de registros.
  3. Proporciona los siguientes detalles de configuración:
    • Nombre: Ingresa un nombre de perfil (por ejemplo, Google SecOps Forwarding). Si quieres que el firewall asigne automáticamente este perfil a las nuevas reglas y zonas de seguridad, asígnale el nombre default.
  4. Para cada tipo de registro que desees reenviar (Tráfico, Amenaza, Envío a WildFire, Filtrado de URL, Filtrado de datos, Túnel, Autenticación), configura lo siguiente:
    • Haz clic en Agregar en la sección del tipo de registro correspondiente.
    • Syslog: Selecciona el perfil del servidor syslog que creaste (por ejemplo, Google SecOps BindPlane).
    • Gravedad del registro: Selecciona los niveles de gravedad que se reenviarán (por ejemplo, Todos).
  5. Haz clic en Aceptar para guardar el perfil de reenvío de registros.

Aplica el perfil de reenvío de registros a las políticas de seguridad

  1. Ve a Políticas > Seguridad.
  2. Selecciona las reglas de seguridad para las que deseas habilitar el reenvío de registros.
  3. Haz clic en la regla para editarla.
  4. Ve a la pestaña Acciones.
  5. En el menú Log Forwarding, selecciona el perfil de reenvío de registros que creaste (por ejemplo, Google SecOps Forwarding).
  6. Haz clic en Aceptar para guardar la configuración de la política de seguridad.

Configura los parámetros de registro para los registros del sistema

  1. Ve a Device > Log Settings.
  2. Para cada tipo de registro (System, Configuration, User-ID, HIP Match, Global Protect, IP-Tag, SCTP) y nivel de gravedad, selecciona el perfil del servidor syslog que creaste.
  3. Haz clic en Aceptar para guardar la configuración del registro.

Confirma los cambios

  1. Haz clic en Commit en la parte superior de la interfaz web del firewall.
  2. Espera a que la confirmación se complete correctamente.
  3. Verifica que los registros se envíen al agente de Bindplane. Para ello, consulta la consola de Google SecOps en busca de registros entrantes del firewall de Palo Alto Networks.

Reenvía registros a Google SecOps con el agente de BindPlane

  1. Instala y configura una máquina virtual de Linux.
  2. Instala y configura el agente de BindPlane en Linux para reenviar registros a Google SecOps. Para obtener más información sobre cómo instalar y configurar el agente de Bindplane, consulta las instrucciones de instalación y configuración del agente de Bindplane.

Si tienes problemas para crear feeds, comunícate con el equipo de asistencia de Google SecOps.

Formatos de registro admitidos

El analizador de firewall de Palo Alto Networks admite registros en formato LEEF,CEF y CSV.

Registros de muestra admitidos

  • LEEF

    <14>Jan 22 02:20:19 device_host LEEF:1.0|Palo Alto Networks|PAN-OS Syslog Integration|10.2.12-h4|Microsoft MSOFFICE(52033)|ReceiveTime=2025/01/22 02:20:18|SerialNumber=01250100xxxx|cat=THREAT|Subtype=wildfire|devTime=Jan 22 2025 08:20:18 GMT|src=198.50.100.1|dst=198.50.100.2|srcPostNAT=198.50.100.3|dstPostNAT=198.50.100.4|RuleName=AZURE-US-NEW-CNF_Inbound_To_Azure-ALLOW|usrName=|SourceUser=|DestinationUser=|Application=smtp-base|VirtualSystem=vsys1|SourceZone=McD-Global-Zone|DestinationZone=Azure-Zone|IngressInterface=ae1.111|EgressInterface=ae2.409|LogForwardingProfile=Default-Traffic-Logging|SessionID=35331795|RepeatCount=1|srcPort=21578|dstPort=25|srcPostNATPort=0|dstPostNATPort=0|Flags=0x2000|proto=tcp|action=allow|Miscellaneous=\"......3...................xls\"|ThreatID=Microsoft MSOFFICE(52033)|URLCategory=malicious|sev=4|Severity=high|Direction=client-to-server|sequence=7462614601465681755|ActionFlags=0x8000000000000000|SourceLocation=198.50.100.1-198.50.100.255|DestinationLocation=United States|ContentType=|PCAP_ID=0|FileDigest=0ea04c99bf188c2e4207f60f92ca7c6f5088c7943ee63f45c50032bbd2bf7ea9|Cloud=demo.com|URLIndex=1|RequestMethod=|FileType=ms-office|Sender=sender@ab.myownpersonaldomain.com|Subject=\"............:.................................................................................-.........(Name)-2025-01-22...............:Y107202501220005, ............:........................, ...............:.........\"|Recipient=abc@demo.myownpersonaldomain.com|ReportID=117022282776|DeviceGroupHierarchyL1=143|DeviceGroupHierarchyL2=144|DeviceGroupHierarchyL3=39|DeviceGroupHierarchyL4=0|vSrcName=|DeviceName=device_host|SrcUUID=|DstUUID=|TunnelID=0|MonitorTag=|ParentSessionID=0|ParentStartTime=|TunnelType=N/A|ThreatCategory=N/A|ContentVer=WildFire-0
    
  • CEF

    14>1 2024-04-04T16:21:56+02:00 FW-PERIMETRAL-AVG-01 - - - - CEF:0|Palo Alto Networks|PAN-OS|10.1.10-h2|end|TRAFFIC|1|src=198.51.100.1 dst=198.51.100.2 srcTranslatedAddress=198.51.100.3 dstTranslatedAddress=198.51.100.4 rule=FW_USER_NATS2_APP suser= duser= app=bittorrent vs=vsys1 sz=INSIDE dz=EXTERNAL InboundInterface=ae2.2266 OutboundInterface=ae1 lp=log_forwarding sid=2935823 cnt=1 spt=6881 dpt=51413 srcTranslatedPort=0 dstTranslatedPort=0 flags=0x7a proto=udp act=allow tbytes=475 in=150 out=325 pkt=2 pktReceived=1 pktSent=1 start=Apr 04 2024 14:21:56 GMT stime=1206 urlcat=any externalId=externalId reason=aged-out DGl1=11 DGl2=161 DGl3=0 DGl4=0 VsysName=STONESOFT dvchost=FW-PERIMETRAL-AVG-01 cat=from-policy ActionFlags=0x8000000000000000 srcUUID= dstUUID= TunnelID=0 MonitorTag= ParentSessionID=0 ParentStartTime= TunnelType=N/A SCTPAssocID=0 SCTPChunks=0 SCTPChunkSent=0 SCTPChunksRcv=0 RuleUUID=746c3eb6-3d51-4679-8438-bd0e00e170a8 HTTP2Con=0 LinkChange=0 PolicyID= LinkDetail= SDWANCluster= SDWANDevice= SDWANClustype= SDWANSite= DynamicUsrgrp= XFFIP= srcDevCat= srcDevProf= srcDevModel= srcDevVendor= srcDevOS= srcDevOSv= srcHostname= srcMac= dstDevCat= dstDevProf= dstDevModel= dstDevVendor= dstDevOS= dstDevOSv= dstHostname= dstMac= ContainerName= PODNamespace= PODName= srcEDL= dstEDL= GPHostID= EPSerial= srcDAG= dstDAG= HASessionOwner= TimeHighRes=2024-04-04T16:21:56.250+02:00 ASServiceType= ASServiceDiff="
    
  • CSV

    1,2021/10/24 15:30:07,,CONFIG,0,2561,2021/10/24 15:30:07,198.51.100.0,,set,admin,Web,Succeeded, network virtual-router  VR1,,VR1  { ecmp { algorithm { ip-modulo ; } } protocol { bgp { routing-options { graceful-restart { enable yes; } } enable no; } rip { enable no; } ospf { enable no; } ospfv3 { enable no; } } routing-table { ip { static-route { vr1-log  { path-monitor { enable no; failure-condition any; hold-time 2; } nexthop { ip-address 198.51.100.0; } bfd { profile None; } interface ethernet1/1; metric 10; destination 0.0.0.0/0; route-table { unicast ; } } } } } interface [ ethernet1/1 ethernet1/2 ]; } ,7022390503849066572,0x0,0,0,0,0,,PA-VM,0,
    

Referencia de la asignación de campos: Campos de registros a campos del UDM

En esta sección, se explica cómo el analizador asigna los campos de registro del firewall de Palo Alto Networks a los campos de eventos del UDM de Google SecOps para cada tipo de registro. La clave de la etiqueta de Google SecOps hace referencia al nombre de la clave asignada al campo Labels.key del UDM.

Por ejemplo, en el caso del campo "Sistema virtual", el nombre del campo es "cs3" en formato CEF y "VirtualSystem" en formato LEEF. El campo del UDM "about.labels.key" contiene el valor "vsys", y el campo del UDM "about.labels.value" contiene el valor de ese campo. Algunos de los nombres de campos de CEF o LEEF no tienen un nombre correspondiente a los nombres de campos del CSV. En esos casos, si agregas tu propio nombre de variable en el formato de registro personalizado del perfil de syslog, el analizador no lo asignará al campo del UDM.

Consulta las siguientes secciones para obtener referencias de asignación de cada tipo de registro:

Sistema

En la siguiente tabla, se enumeran los campos de registro del tipo de registro del sistema y sus campos de UDM correspondientes.

Campo CSV Campo de CEF Campo LEEF Clave de etiqueta de Google Security Operations Campo de UDM
Hora de recepción (receive_time o cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (si no está presente "Generate Time")

Número de serie (serie) deviceExternalId SerialNumber target.asset.hardware.serial_number
Tipo (type) type (Header) cat metadata.product_event_type se establece en "%{type} - %{subtype}".
Tipo de amenaza o contenido (subtipo) subtype (encabezado) Subtipo metadata.product_event_type se establece en "%{type} - %{subtype}".
Hora de generación (time_generated o cef-formatted-time_generated) metadata.event_timestamp
Sistema virtual (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
ID del evento (eventid) cat eventid additional.fields.key y additional.fields.value.string_value
Objeto (objeto) fname Nombre del archivo objeto target.resource.name
Módulo (module) flexString2 Módulo module additional.fields.key y additional.fields.value.string_value
Gravedad (severity) $number-of-severity(header) Gravedad security_result.severity y security_result.severity_details
Descripción (opaca) msg msg metadata.description
principal_user_userid (este campo se extrae del campo msg) principal.user.userid
principal_ip3 (este campo se extrae del campo msg) principal.ip
Motivo (este campo se extrae del campo msg) security_result.description
server_address (este campo se extrae del campo msg) target.ip
server_profile (este campo se extrae del campo msg) additional.fields.key y additional.fields.value.string_value
Número de secuencia (seqno) externalId secuencia metadata.product_log_id
Marcas de acción (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_1 a dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key y additional.fields.value.string_value
Nombre del sistema virtual (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
Nombre del dispositivo (device_name) dvchost DeviceName target.hostname
Marca de tiempo de alta resolución (high_res_timestamp) anOSTimeGeneratedHighResolution additional.fields.key y additional.fields.value.string_value

Configuración

En la siguiente tabla, se enumeran los campos de registro del tipo de registro de configuración y sus campos de UDM correspondientes.

Campo CSV Campo de CEF Campo LEEF Clave de etiqueta de Google Security Operations Campo de UDM
Hora de recepción (receive_time o cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (si no está presente "Generate Time")

Número de serie (serie) deviceExternalId SerialNumber target.asset.hardware.serial_number
Tipo (type) type (Header) cat metadata.product_event_type
Tipo de amenaza o contenido (subtipo) subtype (encabezado) metadata.product_event_type
Hora de generación (time_generated o cef-formatted-time_generated) metadata.event_timestamp
Host (host) shost src principal.ip/hostname
Sistema virtual (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
Comando (cmd) actúa msg cmd principal.process.command_line
Administrador (admin) duser usrName principal.user.userid
Cliente (client) destinationServiceName cliente principal.application
Resultado (result) ID de firma (encabezado)(motivo) Resultado security_result.summary
Ruta de configuración (ruta) msg ConfigurationPath principal.process.command_line
Antes del cambio, detalle (before_change_detail) cs1 BeforeChangeDetail before_change_detail target.resource.attribute.labels.key/value
Detalle posterior al cambio (after_change_detail) cs2 AfterChangeDetail after_change_detail target.resource.attribute.labels.key/value
Número de secuencia (seqno) externalId secuencia metadata.product_log_id
Marcas de acción (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_1 a dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key y additional.fields.value.string_value
Nombre del sistema virtual (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
Nombre del dispositivo (device_name) dvchost DeviceName target.hostname
Grupo de dispositivos (dg_id) PanOSFWDeviceGroup target.asset.attribute.labels.key/value dg_id principal.asset.attribute.labels.key/value
Comentario de auditoría (comment) PanOSPolicyAuditComment comentario additional.fields.key y additional.fields.value.string_value
Marca de tiempo de alta resolución (high_res_timestamp) additional.fields.key y additional.fields.value.string_value
Gravedad (severity) number-of-severity(header) security_result.severity y security_result.severity_details

Amenaza/WildFire

En la siguiente tabla, se enumeran los campos de registro del tipo de registro Threat/WildFire y sus campos de UDM correspondientes.

Campo CSV Campo de CEF Campo LEEF Clave de etiqueta de Google Security Operations Campo de UDM
Hora de recepción (receive_time o cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (si no está presente "Generate Time")

Número de serie deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Tipo (type) type (Header) cat metadata.product_event_type
Tipo de amenaza o contenido (subtipo) cat/subtype (encabezado) Subtipo metadata.product_event_type
Fecha y hora de generación (time_generated o cef-formatted-time_generated) metadata.event_timestamp
Dirección de origen (src) src src principal.ip
Dirección de destino (dst) DST DST target.ip
IP de origen de NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP de destino de NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Nombre de la regla (rule) cs1 RuleName security_result.rule_name
Usuario de origen (srcuser) suser SourceUser / usrName principal.user.userid
Usuario de destino (dstuser) duser DestinationUser target.user.userid
Aplicación (app) app Aplicación target.application
Sistema virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona de origen (desde) cs4 SourceZone de

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Zona de destino (a) cs5 DestinationZone a

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

Interfaz entrante (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Interfaz de salida (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

Acción de registro (conjunto de registros) cs6 LogForwardingProfile logset additional.fields.key y additional.fields.value.string_value
ID de sesión (sessionid) cn1 SessionID network.session_id
Recuento de repeticiones (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key y additional.fields.value.string_value
Puerto de origen (sport) spt srcPort principal.port
Puerto de destino (dport) dpt dstPort target.port
Puerto de origen de NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Puerto de destino de NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Marcas (flags) flexString1 Marcas flags additional.fields.key y additional.fields.value.string_value
Protocolo de IP (proto) protocolo protocolo network.ip_protocol
Acción (action) actúa acción security_result.action_details

security_result.action

URL o nombre de archivo (varios) solicitud Varios

target.file.names (si el subtipo es "file", "virus", "wildfire-virus" o "wildfire", el campo "misc" se asigna a target.file.names)

target.url (si el subtipo es "url", el campo "misc" se asigna a target.url y target.hostname)

Nombre de la amenaza o el contenido (threatid) cat ThreatID security_result.threat_name
Categoría (category) cs2 URLCategory security_result.category_details
Gravedad (severity) number-of-severity(header) Gravedad security_result.severity y security_result.severity_details
Dirección (direction) flexString2 Dirección network.direction
Número de secuencia (seqno) externalId secuencia metadata.product_log_id
Marcas de acción (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key y additional.fields.value.string_value
País de origen (srcloc) SourceLocation principal.location.country_or_region
País de destino (dstloc) DestinationLocation target.location.country_or_region
Tipo de contenido (contenttype) ContentType contenttype additional.fields.key y additional.fields.value.string_value
ID de PCAP (pcap_id) ID del archivo PCAP_ID pcap_id additional.fields.key y additional.fields.value.string_value
Resumen del archivo (filedigest) fileHash FileDigest target.file.sha1/md5/sha256
Nube (cloud) filePath Nube nube additional.fields.key y additional.fields.value.string_value
Índice de URL (url_idx) URLIndex url_idx additional.fields.key y additional.fields.value.string_value
Usuario-agente (user_agent) network.http.user_agent
Tipo de archivo (filetype) fileType FileType target.file.mime_type
X-Forwarded-For (xff) principal.ip
Referer (referer) network.http.referral_url
Remitente (sender) suid Remitente network.email.from
Asunto (subject) msg Asunto network.email.subject
Destinatario (recipient) duid Destinatario network.email.to
ID del informe (reportid) oldFileId ReportID reportid additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_1 a dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key y additional.fields.value.string_value
Nombre del sistema virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nombre del dispositivo (device_name) dvchost DeviceName intermediary.hostname
UUID de la VM de origen (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
UUID de la VM de destino (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
Método HTTP (http_method) RequestMethod network.http.method
ID/IMSI del túnel (tunnel_id/imsi) PanOSTunnelID TunnelID tunnel_id/imsi additional.fields.key y additional.fields.value.string_value
Monitor Tag/IMEI (monitortag/imei) PanOSMonitorTag MonitorTag monitortag/imei additional.fields.key y additional.fields.value.string_value
ID de sesión principal (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Hora de inicio de la sesión principal (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key y additional.fields.value.string_value
Tipo de túnel (tunnel) PanOSTunnelType TunnelType túnel additional.fields.key y additional.fields.value.string_value
Categoría de amenaza (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
Versión del contenido (contentver) PanOSContentVer ContentVer contentver additional.fields.key y additional.fields.value.string_value
ID de asociación de SCTP (assoc_id) PanOSAssocID assoc_id additional.fields.key y additional.fields.value.string_value
ID de protocolo de carga útil (ppid) PanOSPPID ppid additional.fields.key y additional.fields.value.string_value
Encabezados HTTP (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
Lista de categorías de URL (url_category_list) PanOSURLCatList url_category_list additional.fields.key y additional.fields.value.string_value
UUID de la regla (rule_uuid) PanOSRuleUUID security_result.rule_id
Conexión HTTP/2 (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
Nombre del grupo de usuarios dinámico (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Dirección XFF (xff_ip) PanXFFIP principal.ip
Categoría del dispositivo fuente (src_category) PanSrcDeviceCat src_category principal.asset.category
Perfil del dispositivo fuente (src_profile) PanSrcDeviceProf src_profile

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Modelo del dispositivo fuente (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
Proveedor del dispositivo fuente (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
Familia del SO del dispositivo fuente (src_osfamily) PanSrcDeviceOS src_osfamily principal.platform
Versión del SO del dispositivo de origen (src_osversion) PanSrcDeviceOSv principal.platform_version
Nombre de host de origen (src_host) PanSrcHostname principal.hostname
Dirección MAC de origen (src_mac) PanSrcMac principal.mac
Categoría del dispositivo de destino (dst_category) PanDstDeviceCat dst_category target.asset.category
Perfil del dispositivo de destino (dst_profile) PanDstDeviceProf dst_profile

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

Modelo de dispositivo de destino (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
Proveedor del dispositivo de destino (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
Familia del SO del dispositivo de destino (dst_osfamily) PanDstDeviceOS dst_osfamily target.platform
Versión del SO del dispositivo de destino (dst_osversion) PanDstDeviceOSv target.platform_version
Nombre de host de destino (dst_host) PanDstHostname target.hostname
Dirección MAC de destino (dst_mac) PanDstMac target.mac
ID del contenedor (container_id) PanContainerName container_id intermediary.resource.product_object_id
Espacio de nombres del POD (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
Nombre del POD (pod_name) PanPODName pod_name target.resource.name
Lista dinámica externa de origen (src_edl) PanSrcEDL src_edl additional.fields.key y additional.fields.value.string_value
Lista dinámica externa de destino (dst_edl) PanDstEDL dst_edl additional.fields.key y additional.fields.value.string_value
ID del host (hostid) PanGPHostID hostid principal.asset.asset_id
Número de serie del dispositivo del usuario (serialnumber) PanEPSerial principal.asset.hardware.serial_number
EDL de dominio (domain_edl) PanDomainEDL domain_edl additional.fields.key y additional.fields.value.string_value
Grupo de direcciones dinámicas de origen (src_dag) PanSrcDAG principal.group.group_display_name
Grupo de direcciones dinámicas de destino (dst_dag) PanDstDAG target.group.group_display_name
Hash parcial (partial_hash) PanPartialHash partial_hash additional.fields.key y additional.fields.value.string_value
Marca de tiempo de alta resolución (high_res timestamp) PanTimeHighRes Marca de tiempo de alta resolución additional.fields.key y additional.fields.value.string_value
Motivo (reason) PanReasonFilteringAction Reason security_result.summary
Justificación (justification) PanJustification justificación additional.fields.key y additional.fields.value.string_value
Un tipo de servicio de segmentación (nssai_sst) PanASServiceType nssai_sst additional.fields.key y additional.fields.value.string_value
Subcategoría de la aplicación (subcategory_of_app) subcategory_of_app additional.fields.key y additional.fields.value.string_value
Categoría de la aplicación (category_of_app) category_of_app additional.fields.key y additional.fields.value.string_value
Tecnología de la aplicación (technology_of_app) technology_of_app additional.fields.key y additional.fields.value.string_value
Riesgo de la aplicación (risk_of_app) risk_of_app additional.fields.key y additional.fields.value.string_value
Característica de la aplicación (characteristic_of_app) characteristic_of_app additional.fields.key y additional.fields.value.string_value
Contenedor de la aplicación (container_of_app) container_of_app additional.fields.key y additional.fields.value.string_value
Aplicación SaaS (is_saas_of_app) is_saas_of_app additional.fields.key y additional.fields.value.string_value
Aplicación con túnel (tunneled_app) additional.fields.key y additional.fields.value.string_value
Tipo de flujo (flow_type) additional.fields.key y additional.fields.value.string_value
Nombre del clúster (cluster_name) intermediary.resource.name
Estado de aprobación de la aplicación (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key y additional.fields.value.string_value

Tráfico

En la siguiente tabla, se enumeran los campos de registro del tipo de registro de tráfico y sus campos de UDM correspondientes.

Campo CSV Campo de CEF Campo LEEF Clave de etiqueta de Google Security Operations Campo de UDM
Hora de recepción (receive_time o cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (si no está presente "Generate Time")

Número de serie (serie) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Tipo (type) type (Header) cat/Type metadata.product_event_type
Tipo de amenaza o contenido (subtipo) subtype (encabezado) Subtipo metadata.product_event_type
Hora de generación (time_generated o cef-formatted-time_generated) start metadata.event_timestamp
Dirección de origen (src) src src principal.ip
Dirección de destino (dst) DST DST target.ip
IP de origen de NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP de destino de NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Nombre de la regla (rule) cs1 RuleName security_result.rule_name
Usuario de origen (srcuser) suser SourceUser principal.user.userid
Usuario de destino (dstuser) duser DestinationUser target.user.userid
Aplicación (app) app Aplicación target.application
Sistema virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona de origen (desde) cs4 SourceZone de

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Zona de destino (a) cs5 DestinationZone a

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

Interfaz entrante (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Interfaz de salida (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

Acción de registro (conjunto de registros) cs6 LogForwardingProfile logset additional.fields.key y additional.fields.value.string_value
ID de sesión (sessionid) cn1 SessionID network.session_id
Recuento de repeticiones (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key y additional.fields.value.string_value
Puerto de origen (sport) spt srcPort principal.port
Puerto de destino (dport) dpt dstPort target.port
Puerto de origen de NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Puerto de destino de NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Marcas (flags) flexString1 Marcas flags additional.fields.key y additional.fields.value.string_value
Protocolo de IP (proto) protocolo protocolo network.ip_protocol
Acción (action) actúa acción security_result.action_details

security_result.action

Bytes (bytes) flexNumber1 totalBytes bytes additional.fields.key y additional.fields.value.string_value
Bytes enviados (bytes_sent) en srcBytes network.sent_bytes
Bytes recibidos (bytes_received) descifrar? dstBytes network.received_bytes
Paquetes (packets) cn2 totalPackets paquetes additional.fields.key y additional.fields.value.string_value
Hora de inicio (start) StartTime start additional.fields.key y additional.fields.value.string_value
Tiempo transcurrido (elapsed) cn3 ElapsedTime Transcurrido network.session_duration.seconds
Categoría (category) cs2 URLCategory security_result.category / security_result.category_details
Número de secuencia (seqno) externalId secuencia metadata.product_log_id
Marcas de acción (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key y additional.fields.value.string_value
País de origen (srcloc) SourceLocation principal.location.country_or_region
País de destino (dstloc) DestinationLocation target.location.country_or_region
Paquetes enviados (pkts_sent) PanOSPacketsSent srcPackets pkts_sent network.sent_packets
Paquetes recibidos (pkts_received) PanOSPacketsReceived dstPackets pkts_received network.received_packets
Motivo de finalización de la sesión (session_end_reason) Reason SessionEndReason security_result.summary
Jerarquía del grupo de dispositivos 1 (dg_hier_level_1 a dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos2 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos 3 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key y additional.fields.value.string_value
Nombre del sistema virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nombre del dispositivo (device_name) dvchost DeviceName intermediary.hostname
Fuente de la acción (action_source) cat ActionSource action_source additional.fields.key y additional.fields.value.string_value
UUID de la VM de origen (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
UUID de la VM de destino (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
ID de túnel/IMSI (tunnelid/imsi) PanOSTunnelID TunnelID tunnelid/imsi additional.fields.key y additional.fields.value.string_value
Monitor Tag/IMEI (monitortag/imei) PanOSMonitorTag MonitorTag monitortag/imei additional.fields.key y additional.fields.value.string_value
ID de sesión principal (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Hora de inicio principal (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key y additional.fields.value.string_value
Tipo de túnel (tunnel) PanOSTunnelType TunnelType túnel additional.fields.key y additional.fields.value.string_value
ID de asociación de SCTP (assoc_id) PanOSSCTPAssocID assoc_id additional.fields.key y additional.fields.value.string_value
Fragmentos de SCTP (chunks) PanOSSCTPChunks fragmentos additional.fields.key y additional.fields.value.string_value
Fragmentos SCTP enviados (chunks_sent) PanOSSCTPChunkSent chunks_sent additional.fields.key y additional.fields.value.string_value
Fragmentos SCTP recibidos (chunks_received) PanOSSCTPChunksRcv chunks_received additional.fields.key y additional.fields.value.string_value
UUID de la regla (rule_uuid) PanOSRuleUUID security_result.rule_id
Conexión HTTP/2 (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
Recuento de cambios de vínculo (link_change_count) PanLinkChange link_change_count additional.fields.key y additional.fields.value.string_value
ID de la política (policy_id) PanPolicyID policy_id additional.fields.key y additional.fields.value.string_value
Interruptores de vínculos (link_switches) PanLinkDetail link_switches additional.fields.key y additional.fields.value.string_value
Clúster de SD-WAN (sdwan_cluster) PanSDWANCluster sdwan_cluster additional.fields.key y additional.fields.value.string_value
Tipo de dispositivo SD-WAN (sdwan_device_type) PanSDWANDevice sdwan_device_type additional.fields.key y additional.fields.value.string_value
Tipo de clúster de SD-WAN (sdwan_cluster_type) PanSDWANClustype sdwan_cluster_type additional.fields.key y additional.fields.value.string_value
Sitio de SD-WAN (sdwan_site) PanSDWANSite sdwan_site additional.fields.key y additional.fields.value.string_value
Nombre del grupo de usuarios dinámico (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name additional.fields.key y additional.fields.value.string_value
Dirección XFF (xff_ip) PanXFFIP principal.ip
Categoría del dispositivo fuente (src_category) PanSrcDeviceCat src_category principal.asset.category
Perfil del dispositivo fuente (src_profile) PanSrcDeviceProf src_profile

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Modelo del dispositivo fuente (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
Proveedor del dispositivo fuente (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
Familia del SO del dispositivo fuente (src_osfamily) PanSrcDeviceOS principal.platform
Versión del SO del dispositivo de origen (src_osversion) PanSrcDeviceOSv principal.asset.software.version
Nombre de host de origen (src_host) PanSrcHostname principal.hostname
Dirección MAC de origen (src_mac) PanSrcMac principal.mac
Categoría del dispositivo de destino (dst_category) PanDstDeviceCat dst_category target.asset.category
Perfil del dispositivo de destino (dst_profile) PanDstDeviceProf dst_profile

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

Modelo de dispositivo de destino (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
Proveedor del dispositivo de destino (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
Familia del SO del dispositivo de destino (dst_osfamily) PanDstDeviceOS dst_osfamily target.platform
Versión del SO del dispositivo de destino (dst_osversion) PanDstDeviceOSv target.platform_version
Nombre de host de destino (dst_host) PanDstHostname target.hostname
Dirección MAC de destino (dst_mac) PanDstMac target.mac
ID del contenedor (container_id) PanContainerName container_id intermediary.resource.product_object_id
Espacio de nombres del POD (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
Nombre del POD (pod_name) PanPODName pod_name target.resource.name
Lista dinámica externa de origen (src_edl) PanSrcEDL src_edl

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Lista dinámica externa de destino (dst_edl) PanDstEDL dst_edl

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

ID del host (hostid) PanGPHostID hostid principal.asset.asset_id
Número de serie del dispositivo del usuario (serialnumber) PanEPSerial principal.asset.hardware.serial_number
Grupo de direcciones dinámicas de origen (src_dag) PanSrcDAG principal.group.group_display_name
Grupo de direcciones dinámicas de destino (dst_dag) PanDstDAG target.group.group_display_name
Propietario de la sesión (session_owner) PanHASessionOwner session_owner additional.fields.key y additional.fields.value.string_value
Marca de tiempo de alta resolución (high_res_timestamp) PanTimeHighRes additional.fields.key y additional.fields.value.string_value
Un tipo de servicio de Slice (nsdsai_sst) PanASServiceType nsdsai_sst additional.fields.key y additional.fields.value.string_value
Un diferenciador de Slice (nsdsai_sd) PanASServiceDiff nsdsai_sd additional.fields.key y additional.fields.value.string_value
Subcategoría de la aplicación (subcategory_of_app) subcategory_of_app additional.fields.key y additional.fields.value.string_value
Categoría de la aplicación (category_of_app) category_of_app additional.fields.key y additional.fields.value.string_value
Tecnología de la aplicación (technology_of_app) technology_of_app additional.fields.key y additional.fields.value.string_value
Riesgo de la aplicación (risk_of_app) security_result.severity
Característica de la aplicación (characteristic_of_app) characteristic_of_app additional.fields.key y additional.fields.value.string_value
Contenedor de la aplicación (container_of_app) container_of_app additional.fields.key y additional.fields.value.string_value
Aplicación SaaS (is_saas_of_app) is_saas_of_app additional.fields.key y additional.fields.value.string_value
Estado de aprobación de la aplicación (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key y additional.fields.value.string_value
Subcategoría de la aplicación (subcategory_of_app) subcategory_of_app1 additional.fields.key y additional.fields.value.string_value
Gravedad (severity) number-of-severity(header) security_result.severity y security_result.severity_details

User-ID

En la siguiente tabla, se enumeran los campos de registro del tipo de registro user-id y sus campos de UDM correspondientes.

Campo CSV Campo de CEF Campo LEEF Clave de etiqueta de Google Security Operations Campo de UDM
Hora de recepción (receive_time o cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (si no está presente "Generate Time")

Número de serie (serie) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Tipo (type) type (Header) cat metadata.product_event_type
Tipo de amenaza o contenido (subtipo) subtype (encabezado) Subtipo metadata.product_event_type
Hora de generación (time_generated o cef-formatted-time_generated) metadata.event_timestamp
Sistema virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
IP de origen (ip) src src principal.ip
Usuario (user) duser usrName target.user.userid

target.administrative_domain

target.user.email_addresses

Nombre de la fuente de datos (datasourcename) cs4 DataSourceName datasourcename

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

ID del evento (eventid) EventID eventid additional.fields.key y additional.fields.value.string_value
Recuento de repeticiones (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key y additional.fields.value.string_value
Umbral de tiempo de espera (timeout) cn3 TimeoutThreshold timeout additional.fields.key y additional.fields.value.string_value
Puerto de origen (beginport) spt srcPort principal.port
Puerto de destino (endport) dpt dstPort target.port
Fuente de datos cs5 DataSource fuente de datos

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Tipo de fuente de datos (datasourcetype) cs6 DataSourceType datasourcetype

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Número de secuencia (seqno) externalId secuencia metadata.product_log_id
Marcas de acción (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key y additional.fields.value.string_value
Nombre del sistema virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nombre del dispositivo (device_name) dvchost DeviceName intermediary.hostname
ID de sistema virtual (vsys_id) cn2 VirtualSystemID intermediary.resource.product_object_id
Tipo de factor (factortype) cs1 FactorType factortype additional.fields.key y additional.fields.value.string_value
Hora de finalización del factor (factorcompletiontime) end FactorCompletionTime factorcompletiontime additional.fields.key y additional.fields.value.string_value
Número de factor (factorno) cn1 FactorNumber factorno additional.fields.key y additional.fields.value.string_value
Marcas de grupos de usuarios (ugflags) PanOSUGFlags ugflags additional.fields.key y additional.fields.value.string_value
Usuario por fuente (userbysource) PanOSUserBySource target.user.userid

target.administrative_domain

target.user.email_addresses

Marca de tiempo de alta resolución (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key y additional.fields.value.string_value
Fuente de datos de origen (origindatasource) additional.fields.key y additional.fields.value.string_value
Nombre del clúster (cluster_name) principal.resource.name
Gravedad (severity) number-of-severity(header) security_result.severity y security_result.severity_details

Coincidencia de HIP

En la siguiente tabla, se enumeran los campos de registro del tipo de registro de coincidencia de HIP y sus campos de UDM correspondientes.

Campo CSV Campo de CEF Campo LEEF Clave de etiqueta de Google Security Operations Campo de UDM
Hora de recepción (receive_time o cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (si no está presente "Generate Time")

Número de serie (serie) deviceExternalId SerialNumber target.asset.hardware.serial_number
Tipo (type) type (Header) cat metadata.product_event_type
Tipo de amenaza o contenido (subtipo) subtype (encabezado) Subtipo
Hora de generación (time_generated o cef-formatted-time_generated) start startTime metadata.event_timestamp
Usuario de origen (srcuser) suser usrName principal.user.userid
Sistema virtual (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
Nombre de la máquina (machinename) shost identHostName principal.hostname
Sistema operativo (os) cs2 SO principal.asset.platform_software.platform
Dirección de origen (src) src identsrc principal.ip
HIP (matchname) cat HIP matchname

target.resource.attribute.labels.key/value

additional.fields.key y additional.fields.value.string_value

Recuento de repeticiones (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key y additional.fields.value.string_value
Tipo de HIP (matchtype) ID de clase de evento del dispositivo (encabezado) HIPType matchtype

target.resource.attribute.labels.key/value

additional.fields.key y additional.fields.value.string_value

Número de secuencia (seqno) externalId secuencia metadata.product_log_id
Marcas de acción (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key y additional.fields.value.string_value
Nombre del sistema virtual (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
Nombre del dispositivo (device_name) dvchost DeviceName target.hostname
ID de sistema virtual (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
Dirección del sistema IPv6 (srcipv6) c6a2 srcipv6 principal.asset.ip
ID del host (hostid) PanOSHostID principal.asset.asset_id
Número de serie del dispositivo del usuario (serialnumber) PanOSEndpointSerialNumber principal.asset.hardware.serial_number
Dirección MAC del dispositivo (mac) PanOSEndpointMac principal.asset.mac
Marca de tiempo de alta resolución (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key y additional.fields.value.string_value
Nombre del clúster (cluster_name) principal.resource.name
Gravedad (severity) number-of-severity(header) security_result.severity y security_result.severity_details

Etiqueta de IP

En la siguiente tabla, se enumeran los campos de registro del tipo de registro de etiquetas de IP y sus campos de UDM correspondientes.

Campo CSV Campo de CEF Campo LEEF Clave de etiqueta de Google Security Operations Campo de UDM
Hora de recepción (receive_time o cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (si no está presente "Generate Time")

Número de serie (serie) deviceExternalId SerialNumber target.asset.hardware.serial_number
Tipo (type) type (Header) cat metadata.product_event_type
Tipo de amenaza o contenido (subtipo) subtype (encabezado) Subtipo metadata.product_event_type
Hora de generación (time_generated o cef-formatted-time_generated) GenerateTime metadata.event_timestamp
Sistema virtual (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
IP de origen (ip) src src principal.ip
Nombre de la etiqueta (tag_name) PanOSTagName TagName tag_name

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

ID del evento (event_id) PanOSEventID EventID event_id additional.fields.key y additional.fields.value.string_value
Recuento de repeticiones (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key y additional.fields.value.string_value
Tiempo de espera (timeout) PanOSTimeout TimeoutThreshold timeout additional.fields.key y additional.fields.value.string_value
Nombre de la fuente de datos (datasourcename) PanOSDataSourceName DataSourceName datasourcename

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Tipo de fuente de datos (datasource_type) PanOSDataSourceType DataSource datasource_type

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Subtipo de fuente de datos (datasource_subtype) PanOSDataSourceSubType DataSourceType datasource_subtype

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Número de secuencia (seqno) externalId secuencia metadata.product_log_id
Marcas de acción (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key y additional.fields.value.string_value
Nombre del sistema virtual (vsys_name) PanOsVsysName vSrcName target.asset.attribute.labels.key/value
Nombre del dispositivo (device_name) dvchost DeviceName target.hostname
ID de sistema virtual (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
Marca de tiempo de alta resolución (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key y additional.fields.value.string_value
Gravedad (severity) number-of-severity(header) security_result.severity y security_result.severity_details
Nombre del clúster (cluster_name) principal.resource.name

Desencriptación

En la siguiente tabla, se enumeran los campos de registro del tipo de registro de desencriptación y sus campos de UDM correspondientes.

Campo CSV Campo de CEF Campo LEEF Clave de etiqueta de Google Security Operations Campo de UDM
Hora de recepción (receive_time o cef-formatted-receive_time) rt metadata.collected_timestamp,

metadata.event_timestamp (si no está presente "Generate Time")

Número de serie (serie) PanOSDeviceSN intermediary.asset.hardware.serial_number
Tipo (type) type (Header) metadata.product_event_type
Tipo de amenaza o contenido (subtipo) subtype (encabezado) metadata.product_event_type
Versión de configuración (config_ver) PanOSConfigVersion config_ver additional.fields.key y additional.fields.value.string_value
Fecha y hora de generación (time_generated) PanOSLogTimeStamp metadata.event_timestamp
Dirección de origen (src) src principal.ip
Dirección de destino (dst) DST target.ip
IP de origen de NAT (natsrc) sourceTranslatedAddress principa.nat_ip
IP de destino de NAT (natdst) destinationTranslatedAddress target.nat_ip
Regla (rule) cs1 security_result.rule_name
Usuario de origen (srcuser) suser principal.user.userid
Usuario de destino (dstuser) duser target.user.userid
Aplicación (app) app network.application_protocol
Sistema virtual (vsys) cs3 vsys intermediary.asset.attribute.labels.key/value
Zona de origen (desde) cs4 de

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Zona de destino (a) cs5 a

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

Interfaz entrante (inbound_if) deviceInboundInterface inbound_if

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Interfaz de salida (outbound_if) deviceOutboundInterface outbound_if

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

Acción de registro (conjunto de registros) cs6 logset additional.fields.key y additional.fields.value.string_value
Hora de registro (time_received) PanOSTimeReceivedManagementPlane -
ID de sesión (sessionid) cn1 network.session_id
Recuento de repeticiones (repeatcnt) PanOSCountOfRepeats/RepeatCount repeatcnt additional.fields.key y additional.fields.value.string_value
Puerto de origen (sport) spt principal.port
Puerto de destino (dport) dpt target.port
Puerto de origen de NAT (natsport) sourceTranslatedPort principal.nat_port
Puerto de destino de NAT (natdport) destinationTranslatedPort target.nat_port
Marcas (flags) flexString1 flags additional.fields.key y additional.fields.value.string_value
Protocolo de IP (proto) protocolo network.ip_protocol
Acción (action) actúa security_result.action_details

security_result.action

Túnel (tunnel) PanOSTunnel túnel additional.fields.key y additional.fields.value.string_value
UUID de la VM de origen (src_uuid) PanOSSourceUUID principal.asset.product_object_id
UUID de la VM de destino (dst_uuid) PanOSDestinationUUID target.asset.product_object_id
UUID de la regla (rule_uuid) PanOSRuleUUID security_result.rule_id
Etapa de cliente a firewall (hs_stage_c2f) PanOSClientToFirewall hs_stage_c2f additional.fields.key y additional.fields.value.string_value
Etapa de Firewall a servidor (hs_stage_f2s) PanOSFirewallToServer hs_stage_f2s additional.fields.key y additional.fields.value.string_value
Versión de TLS (tls_version) PanOSTLSVersion network.tls.version
Algoritmo de intercambio de claves (tls_keyxchg) PanOSTLSKeyExchange tls_keyxchg additional.fields.key y additional.fields.value.string_value
Algoritmo de encriptación (tls_enc) PanOSTLSEncryptionAlgorithm tls_enc additional.fields.key y additional.fields.value.string_value
Algoritmo de hash (tls_auth) PanOSTLSAuth tls_auth additional.fields.key y additional.fields.value.string_value
Nombre de la política (policy_name) PanOSPolicyName policy_name additional.fields.key y additional.fields.value.string_value
Curva elíptica (ec_curve) PanOSEllipticCurve network.tls.curve
Índice de error (err_index) PanOSErrorIndex err_index additional.fields.key y additional.fields.value.string_value
Estado de raíz (root_status) PanOSRootStatus root_status additional.fields.key y additional.fields.value.string_value
Estado de la cadena (chain_status) PanOSChainStatus chain_status additional.fields.key y additional.fields.value.string_value
Tipo de proxy (proxy_type) PanOSProxyType proxy_type additional.fields.key y additional.fields.value.string_value
Número de serie del certificado (cert_serial) PanOSCertificateSerial network.tls.server.certificate.serial
Huella digital del certificado (huella digital) PanOSFingerprint network.tls.server.certificate.md5/sha1/sha256
Fecha de inicio del certificado (notbefore) PanOSTimeNotBefore network.tls.server.certificate.not_before
Fecha de finalización del certificado (notafter) PanOSTimeNotAfter network.tls.server.certificate.not_after
Versión del certificado (cert_ver) PanOSCertificateVersion network.tls.server.certificate.version
Tamaño del certificado (cert_size) PanOSCertificateSize cert_size additional.fields.key y additional.fields.value.string_value
Longitud del nombre común (cn_len) PanOSCommonNameLength cn_len additional.fields.key y additional.fields.value.string_value
Longitud del nombre común de la entidad emisora (issuer_len) PanOSIssuerNameLength issuer_len additional.fields.key y additional.fields.value.string_value
Longitud del nombre común de la raíz (rootcn_len) PanOSRootCNLength rootcn_len additional.fields.key y additional.fields.value.string_value
Longitud del SNI (sni_len) PanOSSNILength sni_len additional.fields.key y additional.fields.value.string_value
Marcas de certificado (cert_flags) PanOSCertificateFlags cert_flags additional.fields.key y additional.fields.value.string_value
Nombre común del asunto (cn) PanOSCommonName cn additional.fields.key y additional.fields.value.string_value
Nombre común de la entidad emisora (issuer_cn) PanOSIssuerCommonName network.tls.server.certificate.issuer
Nombre común de la raíz (root_cn) PanOSRootCommonName root_cn additional.fields.key y additional.fields.value.string_value
Indicación del nombre del servidor

(sni)

network.tls.client.server_name
Error (error) PanOSErrorMessage error additional.fields.key y additional.fields.value.string_value
ID del contenedor (container_id) PanOSContainerID container_id intermediary.resource.product_object_id
Espacio de nombres del POD (pod_namespace) PanOSContainerNameSpace pod_namespace

target.resource.attribute.labels.key/value

additional.fields.key y additional.fields.value.string_value

Nombre del POD (pod_name) PanOSContainerName pod_name target.resource.name
Lista dinámica externa de origen (src_edl) PanOSSourceEDL src_edl

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Lista dinámica externa de destino (dst_edl) PanOSDestinationEDL dst_edl

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

Grupo de direcciones dinámicas de origen (src_dag) PanOSSourceDynamicAddressGroup principal.group.group_display_name
Grupo de direcciones dinámicas de destino (dst_dag) PanOSDestinationDynamicAddressGroup target.group.group_display_name
Marca de tiempo de alta resolución (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key y additional.fields.value.string_value
Categoría del dispositivo fuente (src_category) PanOSSourceDeviceCategory src_category principal.asset.category
Perfil del dispositivo fuente (src_profile) PanOSSourceDeviceProfile src_profile

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Modelo del dispositivo fuente (src_model) PanOSSourceDeviceModel src_model principal.asset.hardware.model
Proveedor del dispositivo fuente (src_vendor) PanOSSourceDeviceVendor src_vendor principal.asset.hardware.manufacturer
Familia del SO del dispositivo fuente (src_osfamily) PanOSSourceDeviceOSFamily principal.platform
Versión del SO del dispositivo de origen (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
Nombre de host de origen (src_host) PanOSSourceDeviceHost principal.hostname
Dirección MAC de origen (src_mac) PanOSSourceDeviceMac principal.mac
Categoría del dispositivo de destino (dst_category) PanOSDestinationDeviceCategory dst_category target.asset.category
Perfil del dispositivo de destino (dst_profile) PanOSDestinationDeviceProfile dst_profile

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

Modelo de dispositivo de destino (dst_model) PanOSDestinationDeviceModel dst_model target.asset.hardware.model
Proveedor del dispositivo de destino (dst_vendor) PanOSDestinationDeviceVendor dst_vendor target.asset.hardware.manufacturer
Familia del SO del dispositivo de destino (dst_osfamily) PanOSDestinationDeviceOSFamily dst_osfamily target.platform
Versión del SO del dispositivo de destino (dst_osversion) PanOSDestinationDeviceOSVersion target.platform_version
Nombre de host de destino (dst_host) PanOSDestinationDeviceHost target.hostname
Dirección MAC de destino (dst_mac) PanOSDestinationDeviceMac target.mac
Número de secuencia (seqno) PanOSLogTypeSeqNo metadata.product_log_id
Marcas de acción (actionflags) PanOSActionFlags actionflags additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_1) DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_2) DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_3) DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_4) DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key y additional.fields.value.string_value
Nombre del sistema virtual (vsys_name) intermediary.asset.attribute.labels.key/value
Nombre del dispositivo (device_name) intermediary.hostname
ID de sistema virtual (vsys_id) intermediary.resource.product_object_id
Subcategoría de la aplicación (subcategory_of_app) subcategory_of_app additional.fields.key y additional.fields.value.string_value
Categoría de la aplicación (category_of_app) category_of_app additional.fields.key y additional.fields.value.string_value
Tecnología de la aplicación (technology_of_app) technology_of_app additional.fields.key y additional.fields.value.string_value
Riesgo de la aplicación (risk_of_app) security_result.severity
Característica de la aplicación (characteristic_of_app) characteristic_of_app additional.fields.key y additional.fields.value.string_value
Contenedor de la aplicación (container_of_app) container_of_app additional.fields.key y additional.fields.value.string_value
Aplicación SaaS (is_saas_of_app) is_saas_of_app additional.fields.key y additional.fields.value.string_value
Estado de aprobación de la aplicación (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key y additional.fields.value.string_value
Gravedad (severity) number-of-severity(header) security_result.severity y security_result.severity_details

Túnel

En la siguiente tabla, se enumeran los campos de registro del tipo de registro de túnel y sus campos de UDM correspondientes.

Campo CSV Campo de CEF Campo LEEF Clave de etiqueta de Google Security Operations Campo de UDM
Hora de recepción (receive_time o cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (si no está presente "Generate Time")

Número de serie (serie) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Tipo (type) type (Header) cat metadata.product_event_type
Tipo de amenaza o contenido (subtipo) subtype (encabezado) Subtipo metadata.product_event_type
Hora de generación (time_generated o cef-formatted-time_generated) metadata.event_timestamp
Dirección de origen (src) src src principal.ip
Dirección de destino (dst) DST DST target.ip
IP de origen de NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP de destino de NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Nombre de la regla (rule) cs1 RuleName security_result.rule_name
Usuario de origen (srcuser) suser SourceUser / usrName principal.user.userid
Usuario de destino (dstuser) duser DestinationUser target.user.userid
Aplicación (app) app Aplicación network.application_protocol
Sistema virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona de origen (desde) cs4 SourceZone de

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Zona de destino (a) cs5 DestinationZone a

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

Interfaz entrante (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Interfaz de salida (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

Acción de registro (conjunto de registros) cs6 LogForwardingProfile logset additional.fields.key y additional.fields.value.string_value
ID de sesión (sessionid) cn1 SessionID network.session_id
Recuento de repeticiones (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key y additional.fields.value.string_value
Puerto de origen (sport) spt srcPort principal.port
Puerto de destino (dport) dpt dstPort target.port
Puerto de origen de NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Puerto de destino de NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Marcas (flags) flexString1 Marcas flags additional.fields.key y additional.fields.value.string_value
Protocolo de IP (proto) protocolo protocolo network.ip_protocol
Acción (action) actúa acción security_result.action_details

security_result.action

Gravedad (severity) number-of-severity(header) security_result.severity y security_result.severity_details
Número de secuencia (seqno) externalId secuencia metadata.product_log_id
Marcas de acción (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key y additional.fields.value.string_value
Ubicación de origen (srcloc) principal.location.country_or_region
Ubicación de destino (dstloc) target.location.country_or_region
Jerarquía del grupo de dispositivos (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key y additional.fields.value.string_value
Nombre del sistema virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nombre del dispositivo (device_name) dvchost DeviceName intermediary.hostname
ID del túnel (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key y additional.fields.value.string_value
Etiqueta de monitoreo (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key y additional.fields.value.string_value
ID de sesión principal (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Hora de inicio principal (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key y additional.fields.value.string_value
Tipo de túnel (tunnel) cs2 TunnelType túnel additional.fields.key y additional.fields.value.string_value
Bytes (bytes) flexNumber1 totalBytes bytes additional.fields.key y additional.fields.value.string_value
Bytes enviados (bytes_sent) en srcBytes network.sent_bytes
Bytes recibidos (bytes_received) descifrar? dstBytes network.received_bytes
Paquetes (packets) cn2 totalPackets paquetes additional.fields.key y additional.fields.value.string_value
Paquetes enviados (pkts_sent) PanOSPacketsSent srcPackets pkts_sent network.sent_packets
Paquetes recibidos (pkts_received) PanOSPacketsReceived dstPackets pkts_received network.received_packets
Encapsulamiento máximo (max_encap) flexNumber2 MaximumEncapsulation max_encap additional.fields.key y additional.fields.value.string_value
Protocolo desconocido (unknown_proto) cfp1 UnknownProtocol unknown_proto additional.fields.key y additional.fields.value.string_value
Verificación estricta (strict_check) cfp2 StrictChecking strict_check additional.fields.key y additional.fields.value.string_value
Fragmento de túnel (tunnel_fragment) PanOSTunnelFragment TunnelFragment tunnel_fragment additional.fields.key y additional.fields.value.string_value
Sesiones creadas (sessions_created) cfp3 SessionsCreated sessions_created additional.fields.key y additional.fields.value.string_value
Sesiones cerradas (sessions_closed) cfp4 SessionsClosed sessions_closed additional.fields.key y additional.fields.value.string_value
Motivo de finalización de la sesión (session_end_reason) Reason SessionEndReason security_result.summary
Fuente de la acción (action_source) cat ActionSource action_source additional.fields.key y additional.fields.value.string_value
Hora de inicio (start) startTime start additional.fields.key y additional.fields.value.string_value
Tiempo transcurrido (elapsed) cn3 ElapsedTime Transcurrido network.session_duration.seconds
Regla de inspección de túnel (tunnel_insp_rule) PanOSTunneInspectionRule security_result.rule_name = "Tunnel Inspection Rule: %{PanOSTunnelInspectionRule}"
IP del usuario remoto (remote_user_ip) PanOSRmtUserIP principal.ip
ID de usuario remoto (remote_user_id) PanOSRmtUserID remote_user_id principal.user.userid
UUID de la regla de seguridad (rule_uuid) PanOSRuleUUID security_result.rule_id
ID de PCAP (pcap_id) PanOSPcapID pcap_id additional.fields.key y additional.fields.value.string_value
Nombre del grupo de usuarios dinámico (dynusergroup_name) PanDynamicUsrgrp principal.group.group_display_name
Lista dinámica externa de origen (src_edl) PanOSSourceEDL src_edl

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Lista dinámica externa de destino (dst_edl) PanOSDestinationEDL dst_edl

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

Marca de tiempo de alta resolución (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key y additional.fields.value.string_value
Un diferenciador de segmentos (nssai_sd) nssai_sd additional.fields.key y additional.fields.value.string_value
Un tipo de servicio de segmentación (nssai_sd) nssai_sd1 additional.fields.key y additional.fields.value.string_value
ID de sesión de PDU (pdu_session_id) pdu_session_id additional.fields.key y additional.fields.value.string_value
Subcategoría de la aplicación (subcategory_of_app) subcategory_of_app additional.fields.key y additional.fields.value.string_value
Categoría de la aplicación (category_of_app) category_of_app additional.fields.key y additional.fields.value.string_value
Tecnología de la aplicación (technology_of_app) technology_of_app additional.fields.key y additional.fields.value.string_value
Riesgo de la aplicación (risk_of_app) risk_of_app additional.fields.key y additional.fields.value.string_value
Característica de la aplicación (characteristic_of_app) characteristic_of_app additional.fields.key y additional.fields.value.string_value
Contenedor de la aplicación (container_of_app) container_of_app additional.fields.key y additional.fields.value.string_value
Aplicación SaaS (is_saas_of_app) is_saas_of_app additional.fields.key y additional.fields.value.string_value
Aplicación con túnel (tunneled_app) additional.fields.key y additional.fields.value.string_value
Descargado (offloaded) additional.fields.key y additional.fields.value.string_value
Tipo de flujo (flow_type) additional.fields.key y additional.fields.value.string_value
Nombre del clúster (cluster_name)

principal.resource.name

Estado de aprobación de la aplicación (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key y additional.fields.value.string_value

Autenticación

En la siguiente tabla, se enumeran los campos de registro del tipo de registro de autenticación y sus campos de UDM correspondientes.

Campo CSV Campo de CEF Campo LEEF Clave de etiqueta de Google Security Operations Campo de UDM
Hora de recepción (receive_time o cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (si no está presente "Generate Time")

Número de serie (serie) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Tipo (type) type (Header) cat metadata.product_event_type
Tipo de amenaza o contenido (subtipo) subtype (encabezado) Subtipo metadata.product_event_type
Hora de generación (time_generated o cef-formatted-time_generated) metadata.event_timestamp
Sistema virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
IP de origen (ip) src src principal.ip
Usuario (user) duser usrName target.user.userid
Normalizar usuario (normalize_user) cs2 NormalizeUser target.user.user_display_name
Objeto (objeto) fname ObjectName objeto target.resource.name
Política de autenticación (authpolicy) cs4 AuthPolicy authpolicy additional.fields.key y additional.fields.value.string_value
Recuento de repeticiones (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key y additional.fields.value.string_value
ID de autenticación (authid) cn2 AuthenticationID authid additional.fields.key y additional.fields.value.string_value
Proveedor (vendor) flexString2 Proveedor vendor additional.fields.key y additional.fields.value.string_value
Acción de registro (conjunto de registros) cs6 LogForwardingProfile logset additional.fields.key y additional.fields.value.string_value
Perfil del servidor (serverprofile) cs1 ServerProfile serverprofile additional.fields.key y additional.fields.value.string_value
Descripción (desc) PanOSDesc AdditionalAuthInfo security_result.description
Tipo de cliente (clienttype) cs5 ClientType clienttype additional.fields.key y additional.fields.value.string_value
Tipo de evento (event) msg msg extensions.auth.auth_details
Número de factor (factorno) cn1 FactorNumber factorno additional.fields.key y additional.fields.value.string_value
Número de secuencia (seqno) externalId secuencia metadata.product_log_id
Marcas de acción (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key y additional.fields.value.string_value
Nombre del sistema virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nombre del dispositivo (device_name) dvchost DeviceName intermediary.hostname
ID de sistema virtual (vsys_id) intermediary.resource.product_object_id
Protocolo de autenticación (authproto) authproto additional.fields.key y additional.fields.value.string_value
UUID de la regla (rule_uuid) PanOSRuleUUID/RuleUUID security_result.rule_id
Marca de tiempo de alta resolución (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key y additional.fields.value.string_value
Categoría del dispositivo fuente (src_category) PanOSSourceDeviceCategory src_category principal.asset.category
Perfil del dispositivo fuente (src_profile) PanOSSourceDeviceProfile src_profile

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Modelo del dispositivo fuente (src_model) PanOSSourceDeviceModel src_model principal.asset.hardware.model
Proveedor del dispositivo fuente (src_vendor) PanOSSourceDeviceVendor src_vendor principal.asset.hardware.manufacturer
Familia del SO del dispositivo fuente (src_osfamily) PanOSSourceDeviceOSFamily

principal.asset.platform_software.platform

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Versión del SO del dispositivo de origen (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
Nombre de host de origen (src_host) PanOSSourceHostname principal.hostname
Dirección MAC de origen (src_mac) PanOSSourceMac principal.asset.mac
Región (región) PanOSTrafficOriginRegion principal.location.country_or_region
Usuario-agente (user_agent) PanOSHTTPUserAgent network.http.user_agent
ID de sesión(sessionid) PanOSTrafficSessionID network.session_id
Gravedad (severity) number-of-severity(header) security_result.severity y security_result.severity_details
Nombre del clúster (cluster_name) principal.resource.name

URL

En la siguiente tabla, se enumeran los campos de registro del tipo de registro de URL y sus campos de UDM correspondientes.

Campo CSV Campo de CEF Campo LEEF Clave de etiqueta de Google Security Operations Campo de UDM
Hora de recepción (cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (si no está presente "Generate Time")

Núm. de serie (serie) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Tipo (type) type (Header) cat metadata.product_event_type
Tipo de amenaza o contenido (subtipo) subtype (encabezado) Subtipo metadata.product_event_type
Fecha de generación metadata.event_timestamp
Dirección de origen (src) src src principal.ip
Dirección de destino (dst) DST DST target.ip
IP de origen de NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP de destino de NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Regla (rule) cs1 RuleName security_result.rule_name
Usuario de origen (srcuser) suser SourceUser principal.user.userid
Usuario de destino (dstuser) duser DestinationUser target.user.userid
Aplicación (app) app Aplicación network.application_protocol
Sistema virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona de origen (desde) cs4 SourceZone de

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Zona de destino (a) cs5 DestinationZone a

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

Interfaz entrante (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Interfaz de salida (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

Acción de registro (conjunto de registros) cs6 LogForwardingProfile logset additional.fields.key y additional.fields.value.string_value
Tiempo registrado time_logged additional.fields.key y additional.fields.value.string_value
ID de sesión (sessionid) cn1 SessionID network.session_id
Recuento de repeticiones (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key y additional.fields.value.string_value
Puerto de origen (sport) spt srcPort principal.port
Puerto de destino (dport) dpt dstPort target.port
Puerto de origen de NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Puerto de destino de NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Marcas (flags) flexString1 Marcas flags additional.fields.key y additional.fields.value.string_value
Protocolo de IP (proto) protocolo protocolo network.ip_protocol
Acción (action) actúa acción security_result.action_details

security_result.action

URL o nombre de archivo (varios) Varios target.file.names

target.url

Nombre de la amenaza o el contenido (threatid) cat ThreatID security_result.threat_id
Categoría (category) cs2 URLCategory category security_result.category_details
Gravedad (severity) number-of-severity (encabezado) Gravedad security_result.severity

security_result.severity_details

Dirección (direction) flexString2 Dirección network.direction
Número de secuencia (seqno) externalId secuencia metadata.product_log_id
Marcas de acción (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key y additional.fields.value.string_value
País de origen (srcloc) SourceLocation principal.location.country_or_region
País de destino (dstloc) DestinationLocation target.location.country_or_region
contenttype (contenttype) requestContext ContentType contenttype additional.fields.key y additional.fields.value.string_value
pcap_id (pcap_id) ID del archivo PCAP_ID pcap_id additional.fields.key y additional.fields.value.string_value
filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
nube (cloud) Nube nube additional.fields.key y additional.fields.value.string_value
url_idx (url_idx) URLIndex url_idx additional.fields.key y additional.fields.value.string_value
user_agent (user_agent) requestClientApplication UserAgent network.http.user_agent
filetype (filetype) target.file.mime_type
xff (xff) PanOSXForwarderfor identSrc xff principal.ip
Referencia (referer) PanOSReferer Referencia network.http.referral_url
remitente (sender) network.email.from
Asunto (subject) Asunto network.email.subject
destinatario (recipient) network.email.to
reportid (reportid) reportid additional.fields.key y additional.fields.value.string_value
DG Hierarchy Level 1 (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key y additional.fields.value.string_value
Nivel 2 de la jerarquía del DG (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key y additional.fields.value.string_value
Nivel 3 de la jerarquía de DG (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key y additional.fields.value.string_value
Nivel 4 de la jerarquía de DG (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key y additional.fields.value.string_value
Nombre del sistema virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nombre del dispositivo (device_name) dvchost DeviceName intermediary.hostname
file_url (file_url) target.url
UUID de la VM de origen (src_uuid) SrcUUID principal.asset.product_object_id
UUID de la VM de destino (dst_uuid) DstUUID target.asset.product_object_id
http_method (http_method) requestMethod RequestMethod network.http.method
ID de túnel/IMSI (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key y additional.fields.value.string_value
Monitor Tag/IMEI (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key y additional.fields.value.string_value
ID de sesión principal (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Hora de inicio de la sesión principal (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key y additional.fields.value.string_value
Túnel (tunnel) PanOSTunnelType TunnelType túnel additional.fields.key y additional.fields.value.string_value
thr_category (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
contentver (contentver) PanOSContentVer ContentVer contentver additional.fields.key y additional.fields.value.string_value
sig_flags (sig_flags) sig_flags additional.fields.key y additional.fields.value.string_value
ID de asociación de SCTP (assoc_id) PanOSAssocID assoc_id additional.fields.key y additional.fields.value.string_value
ID de protocolo de carga útil (ppid) PanOSPPID ppid additional.fields.key y additional.fields.value.string_value
http_headers (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
Lista de categorías de URL (url_category_list) PanOSURLCatList url_category_list additional.fields.key y additional.fields.value.string_value
UUID de la regla (rule_uuid) PanOSRuleUUID rule_uuid security_result.rule_id
Conexión HTTP/2 (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
dynusergroup_name (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name additional.fields.key y additional.fields.value.string_value
Dirección XFF (xff_ip) PanXFFIP principal.ip
Categoría del dispositivo fuente (src_category) PanSrcDeviceCat src_category principal.asset.category
Perfil del dispositivo fuente (src_profile) PanSrcDeviceProf src_profile

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Modelo del dispositivo fuente (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
Proveedor del dispositivo fuente (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
Familia del SO del dispositivo fuente (src_osfamily) PanSrcDeviceOS principal.platform
Versión del SO del dispositivo de origen (src_osversion) PanSrcDeviceOSv principal.platform_version
Nombre de host de origen (src_host) PanSrcHostname src_host principal.hostname
Dirección MAC de origen (src_mac) PanSrcMac principal.mac
Categoría del dispositivo de destino (dst_category) PanDstDeviceCat dst_category target.asset.category
Perfil del dispositivo de destino (dst_profile) PanDstDeviceProf dst_profile

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

Modelo de dispositivo de destino (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
Proveedor del dispositivo de destino (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
Familia del SO del dispositivo de destino (dst_osfamily) PanDstDeviceOS target.platform
Versión del SO del dispositivo de destino (dst_osversion) PanDstDeviceOSv target.platform_version
Nombre de host de destino (dst_host) PanPODNamespace target.hostname
Dirección MAC de destino (dst_mac) PanDstMac target.mac
ID del contenedor (container_id) PanContainerName container_id intermediary.resource.product_object_id
Espacio de nombres del POD (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
Nombre del POD (pod_name) PanPODName pod_name target.resource.name
Lista dinámica externa de origen (src_edl) PanSrcEDL src_edl

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Lista dinámica externa de destino (dst_edl) PanDstEDL dst_edl

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

ID del host (hostid) PanGPHostID hostid principal.asset.asset_id
Número de serie (serialnumber) PanEPSerial principal.asset.hardware.serial_number
domain_edl (domain_edl) PanDomainEDL domain_edl additional.fields.key y additional.fields.value.string_value
Grupo de direcciones dinámicas de origen (src_dag) PanSrcDAG principal.group.group_display_name
Grupo de direcciones dinámicas de destino (dst_dag) PanDstDAG target.group.group_display_name
partial_hash (partial_hash) PanPartialHash partial_hash additional.fields.key y additional.fields.value.string_value
Marca de tiempo en alta resolución (high_res_timestamp) PanTimeHighRes additional.fields.key y additional.fields.value.string_value
Motivo (reason) PanReasonFilteringAction Reason security_result.summary
justificación (justification) PanJustification justificación additional.fields.key y additional.fields.value.string_value
nssai_sst (nssai_sst) PanASServiceType nssai_sst additional.fields.key y additional.fields.value.string_value
Subcategoría de la app (subcategory_of_app) subcategory_of_app additional.fields.key y additional.fields.value.string_value
Categoría de la app (category_of_app) category_of_app additional.fields.key y additional.fields.value.string_value
Tecnología de la app (technology_of_app) technology_of_app additional.fields.key y additional.fields.value.string_value
Riesgo de la app (risk_of_app) risk_of_app additional.fields.key y additional.fields.value.string_value
Característica de la app (characteristic_of_app) characteristic_of_app additional.fields.key y additional.fields.value.string_value
Contenedor de la app (container_of_app) container_of_app additional.fields.key y additional.fields.value.string_value
App con túnel (tunneled_app) tunneled_app additional.fields.key y additional.fields.value.string_value
SaaS de la app (is_saas_of_app) is_saas_of_app additional.fields.key y additional.fields.value.string_value
Estado de la app con respecto a las sanciones (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key y additional.fields.value.string_value
ID del informe de Cloud (cloud_reportid) additional.fields.key y additional.fields.value.string_value
Nombre del clúster (cluster_name)

principal.resource.name

Tipo de flujo (flow_type) additional.fields.key y additional.fields.value.string_value

Datos

En la siguiente tabla, se enumeran los campos de registro del tipo de registro de datos y sus campos de UDM correspondientes.

Campo CSV Campo de CEF Campo LEEF Clave de etiqueta de Google Security Operations Campo de UDM
Hora de recepción (cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (si no está presente "Generate Time")

Núm. de serie (serie) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Tipo (type) type (Header) cat metadata.product_event_type
Tipo de amenaza o contenido (subtipo) subtype (encabezado) Subtipo metadata.product_event_type
Fecha de generación metadata.event_timestamp
Dirección de origen (src) src src principal.ip
Dirección de destino (dst) DST DST target.ip
IP de origen de NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP de destino de NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Regla (rule) cs1 RuleName security_result.rule_name
Usuario de origen (srcuser) suser SourceUser principal.user.userid
Usuario de destino (dstuser) duser DestinationUser target.user.userid
Aplicación (app) app Aplicación network.application_protocol
Sistema virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona de origen (desde) cs4 SourceZone de

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Zona de destino (a) cs5 DestinationZone a

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

Interfaz entrante (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Interfaz de salida (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

Acción de registro (conjunto de registros) cs6 LogForwardingProfile logset additional.fields.key y additional.fields.value.string_value
Tiempo registrado time_logged additional.fields.key y additional.fields.value.string_value
ID de sesión (sessionid) cn1 SessionID network.session_id
Recuento de repeticiones (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key y additional.fields.value.string_value
Puerto de origen (sport) spt srcPort principal.port
Puerto de destino (dport) dpt dstPort target.port
Puerto de origen de NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Puerto de destino de NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Marcas (flags) flexString1 Marcas flags additional.fields.key y additional.fields.value.string_value
Protocolo de IP (proto) protocolo protocolo network.ip_protocol
Acción (action) actúa acción security_result.action_details

security_result.action

URL o nombre de archivo (varios) Varios target.file.names

target.url

Nombre de la amenaza o el contenido (threatid) cat ThreatID security_result.threat_id
Categoría (category) cs2 URLCategory category security_result.category_details
Gravedad (severity) number-of-severity (encabezado) Gravedad security_result.severity

security_result.severity_details

Dirección (direction) flexString2 Dirección network.direction
Número de secuencia (seqno) externalId secuencia metadata.product_log_id
Marcas de acción (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key y additional.fields.value.string_value
País de origen (srcloc) SourceLocation principal.location.country_or_region
País de destino (dstloc) DestinationLocation target.location.country_or_region
contenttype (contenttype) ContentType contenttype additional.fields.key y additional.fields.value.string_value
pcap_id (pcap_id) ID del archivo PCAP_ID pcap_id additional.fields.key y additional.fields.value.string_value
filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
nube (cloud) Nube nube additional.fields.key y additional.fields.value.string_value
url_idx (url_idx) URLIndex url_idx additional.fields.key y additional.fields.value.string_value
user_agent (user_agent) network.http.user_agent
filetype (filetype) target.file.mime_type
xff (xff) xff principal.ip
Referencia (referer) network.http.referral_url
remitente (sender) network.email.from
Asunto (subject) Asunto network.email.subject
destinatario (recipient) network.email.to
reportid (reportid) reportid additional.fields.key y additional.fields.value.string_value
DG Hierarchy Level 1 (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key y additional.fields.value.string_value
Nivel 2 de la jerarquía del DG (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key y additional.fields.value.string_value
Nivel 3 de la jerarquía de DG (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key y additional.fields.value.string_value
Nivel 4 de la jerarquía de DG (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key y additional.fields.value.string_value
Nombre del sistema virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nombre del dispositivo (device_name) dvchost DeviceName intermediary.hostname
file_url (file_url) target.url
UUID de la VM de origen (src_uuid) SrcUUID principal.asset.product_object_id
UUID de la VM de destino (dst_uuid) DstUUID target.asset.product_object_id
http_method (http_method) RequestMethod network.http.method
ID de túnel/IMSI (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key y additional.fields.value.string_value
Monitor Tag/IMEI (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key y additional.fields.value.string_value
ID de sesión principal (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Hora de inicio de la sesión principal (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key y additional.fields.value.string_value
Túnel (tunnel) PanOSTunnelType TunnelType túnel additional.fields.key y additional.fields.value.string_value
thr_category (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
contentver (contentver) PanOSContentVer ContentVer contentver additional.fields.key y additional.fields.value.string_value
sig_flags (sig_flags) sig_flags additional.fields.key y additional.fields.value.string_value
ID de asociación de SCTP (assoc_id) PanOSAssocID assoc_id additional.fields.key y additional.fields.value.string_value
ID de protocolo de carga útil (ppid) PanOSPPID ppid additional.fields.key y additional.fields.value.string_value
http_headers (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
Lista de categorías de URL (url_category_list) url_category_list additional.fields.key y additional.fields.value.string_value
UUID de la regla (rule_uuid) PanOSRuleUUID rule_uuid security_result.rule_id
Conexión HTTP/2 (http2_connection) http2_connection network.application_protocol_version
dynusergroup_name (dynusergroup_name) dynusergroup_name

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Dirección XFF (xff_ip) principal.ip
Categoría del dispositivo fuente (src_category) src_category principal.asset.category
Perfil del dispositivo fuente (src_profile) src_profile

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Modelo del dispositivo fuente (src_model) src_model principal.asset.hardware.model
Proveedor del dispositivo fuente (src_vendor) src_vendor principal.asset.hardware.manufacturer
Familia del SO del dispositivo fuente (src_osfamily) principal.platform
Versión del SO del dispositivo de origen (src_osversion) principal.platform_version
Nombre de host de origen (src_host) src_host principal.hostname
Dirección MAC de origen (src_mac) principal.mac
Categoría del dispositivo de destino (dst_category) dst_category target.asset.category
Perfil del dispositivo de destino (dst_profile) dst_profile

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

Modelo de dispositivo de destino (dst_model) dst_model target.asset.hardware.model
Proveedor del dispositivo de destino (dst_vendor) dst_vendor target.asset.hardware.manufacturer
Familia del SO del dispositivo de destino (dst_osfamily) target.platform
Versión del SO del dispositivo de destino (dst_osversion) target.platform_version
Nombre de host de destino (dst_host) target.hostname
Dirección MAC de destino (dst_mac) target.mac
ID del contenedor (container_id) container_id intermediary.resource.product_object_id
Espacio de nombres del POD (pod_namespace) pod_namespace target.resource.attribute.labels.key/value
Nombre del POD (pod_name) pod_name target.resource.name
Lista dinámica externa de origen (src_edl) src_edl

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Lista dinámica externa de destino (dst_edl) dst_edl

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

ID del host (hostid) hostid principal.asset.asset_id
Número de serie (serialnumber) principal.asset.hardware.serial_number
domain_edl (domain_edl) domain_edl additional.fields.key y additional.fields.value.string_value
Grupo de direcciones dinámicas de origen (src_dag) principal.group.group_display_name
Grupo de direcciones dinámicas de destino (dst_dag) target.group.group_display_name
partial_hash (partial_hash) partial_hash additional.fields.key y additional.fields.value.string_value
Marca de tiempo en alta resolución (high_res_timestamp) additional.fields.key y additional.fields.value.string_value
Motivo (reason) Reason security_result.summary
justificación (justification) justificación additional.fields.key y additional.fields.value.string_value
nssai_sst (nssai_sst) nssai_sst additional.fields.key y additional.fields.value.string_value
Subcategoría de la app (subcategory_of_app) subcategory_of_app additional.fields.key y additional.fields.value.string_value
Categoría de la app (category_of_app) category_of_app additional.fields.key y additional.fields.value.string_value
Tecnología de la app (technology_of_app) technology_of_app additional.fields.key y additional.fields.value.string_value
Riesgo de la app (risk_of_app) risk_of_app additional.fields.key y additional.fields.value.string_value
Característica de la app (characteristic_of_app) characteristic_of_app additional.fields.key y additional.fields.value.string_value
Contenedor de la app (container_of_app) container_of_app additional.fields.key y additional.fields.value.string_value
App con túnel (tunneled_app) tunneled_app additional.fields.key y additional.fields.value.string_value
SaaS de la app (is_saas_of_app) is_saas_of_app additional.fields.key y additional.fields.value.string_value
Estado de la app con respecto a las sanciones (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key y additional.fields.value.string_value
ID del informe de Cloud (cloud_reportid) additional.fields.key y additional.fields.value.string_value
Nombre del clúster (cluster_name) principal.resource.name
Tipo de flujo (flow_type) additional.fields.key y additional.fields.value.string_value

GlobalProtect

En la siguiente tabla, se enumeran los campos de registro del tipo de registro de GlobalProtect y sus campos de UDM correspondientes.

Campo CSV Campo de CEF Campo LEEF Clave de etiqueta de Google Security Operations Campo de UDM
Hora de recepción (receive_time) rt received_time metadata.event_timestamp
Núm. de serie (serie) PanOSDeviceSN intermediary_asset_hardware_serial_number intermediary.asset.hardware.serial_number
Tipo (type) type (Header) metadata.product_event_type
Tipo de amenaza o contenido (subtipo) subtype (encabezado) Subtipo metadata.product_event_type
Fecha y hora de generación (time_generated) PanOSLogTimeStamp generated_timestamp metadata.event_timestamp
Sistema virtual (vsys) PanOSVirtualSystem vsys intermediary.asset.attribute.labels.key/value
ID del evento (eventid) PanOSEventID event_id additional.fields.key y additional.fields.value.string_value
Etapa (stage) PanOSStage de este proceso, additional.fields.key y additional.fields.value.string_value
Método de autenticación (auth_method) PanOSAuthMethod extension_auth_auth_details extensions.auth.auth_details
Tipo de túnel (tunnel_type) PanOSTunnelType túnel additional.fields.key y additional.fields.value.string_value
Usuario de origen (srcuser) PanOSSourceUserName src_user principal.user.email_address

principal.user.userid

principal.administrative_domain

Región de origen (srcregion) PanOSSourceRegion src_region principal.location.country_or_region
Nombre de la máquina (machinename) PanOSEndpointDeviceName machine_name principal.hostname
IP pública (public_ip) PanOSPublicIPv4 principal.nat_ip
IPv6 pública (public_ipv6) PanOSPublicIPv6 principal.nat_ip
IP privada (private_ip) PanOSPrivateIPv4 principal.ip
IPv6 privada (private_ipv6) PanOSPrivateIPv6 principal.ip
ID del host (hostid) PanOSHostID hostid principal.asset.asset_id
Número de serie (serialnumber) PanOSDeviceSN principal.asset.hardware.serial_number
Versión del cliente (client_ver) PanOSGlobalProtectClientVersion client_ver additional.fields.key y additional.fields.value.string_value
SO del cliente (client_os) PanOSEndpointOSType principal.platform
Versión del SO del cliente (client_os_ver) PanOSEndpointOSVersion principal.platform_version
Recuento de repeticiones (repeatcnt) PanOSCountOfRepeats repeatcnt additional.fields.key y additional.fields.value.string_value
Motivo (reason) PanOSQuarantineReason security_result.summary
Error (error) PanOSConnectionError error security_result.description
Descripción (opaca) PanOSDescription security_result.description
Estado (status) PanOSEventStatus estado additional.fields.key y additional.fields.value.string_value
Ubicación (ubicación) PanOSGPGatewayLocation target.location.country_or_region
Duración del acceso (login_duration) PanOSLoginDuration network.session_duration
Método de conexión (connect_method) PanOSConnectionMethod connect_method additional.fields.key y additional.fields.value.string_value
Código de error (error_code) PanOSConnectionErrorID error_code additional.fields.key y additional.fields.value.string_value
Portal (portal) PanOSPortal portal additional.fields.key y additional.fields.value.string_value
Número de secuencia (seqno) PanOSSequenceNo metadata.product_log_id
Marcas de acción (actionflags) PanOSActionFlags actionflags additional.fields.key y additional.fields.value.string_value
Marca de tiempo de alta resolución (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key y additional.fields.value.string_value
Método de selección de puerta de enlace (selection_type) PanOSGatewaySelectionType selection_type additional.fields.key y additional.fields.value.string_value
Tiempo de respuesta de SSL (response_time) PanOSSSLResponseTime response_time additional.fields.key y additional.fields.value.string_value
Prioridad de la puerta de enlace (prioridad) PanOSGatewayPriority priority additional.fields.key y additional.fields.value.string_value
Puertas de enlace intentadas (attempted_gateways) PanOSAttemptedGateways attempted_gateways additional.fields.key y additional.fields.value.string_value
Nombre de la puerta de enlace (gateway) PanOSAttemptedGateways puerta de enlace target.resource.name
Jerarquía del grupo de dispositivos (dg_hier_level_1) dg_hier_level_1 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_2) dg_hier_level_2 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_3) dg_hier_level_3 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos (dg_hier_level_4) dg_hier_level_4 additional.fields.key y additional.fields.value.string_value
Nombre del sistema virtual (vsys_name) intermediary.asset.attribute.labels.key/value
Nombre del dispositivo (device_name) intermediary.hostname
ID de sistema virtual (vsys_id) intermediary.resource.product_object_id
Gravedad (severity) number-of-severity(header) security_result.severity y security_result.severity_details
Nombre del clúster (cluster_name) principal.resource.name

Correlación

En la siguiente tabla, se enumeran los campos de registro del tipo de registro Correlation y sus campos de UDM correspondientes.

Campo CSV Campo de CEF Campo LEEF Clave de etiqueta de Google Security Operations Campo de UDM
Hora de generación (time_generated o cef-formatted-time_generated) startTime generated_timestamp metadata.event_timestamp
Dirección de origen (src) src principal.ip
Usuario de origen (srcuser) SourceUser / usrName principal.user.userid
Sistema virtual (vsys) VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Categoría (category) security_result.category_details
Gravedad (severity) Gravedad security_result.severity y security_result.severity_details
Nivel 1 de la jerarquía del grupo de dispositivos DeviceGroupHierarchyL1 additional.fields.key y additional.fields.value.string_value
Nivel 2 de la jerarquía del grupo de dispositivos DeviceGroupHierarchyL2 additional.fields.key y additional.fields.value.string_value
Jerarquía del grupo de dispositivos, nivel 3 DeviceGroupHierarchyL3 additional.fields.key y additional.fields.value.string_value
Nivel 4 de la jerarquía del grupo de dispositivos DeviceGroupHierarchyL4 additional.fields.key y additional.fields.value.string_value
Nombre del sistema virtual (vsys_name) vSrcName intermediary.asset.attribute.labels.key/value
Nombre del dispositivo (device_name) DeviceName intermediary.hostname
ID de sistema virtual (vsys_id) VirtualSystemID intermediary.resource.product_object_id
Nombre del objeto (objectname) ObjectName target.resource.name
ID de objeto (object_id) ObjectID target.resource.product_object_id
Evidencia (evidence) msg security_result.summary

GTP

En la siguiente tabla, se enumeran los campos de registro del tipo de registro gtp y sus campos de UDM correspondientes.

Campo CSV Campo de CEF Campo LEEF Clave de etiqueta de Google Security Operations Campo de UDM
Hora de recepción (receive_time o cef-formatted-receive_time) metadata.collected_timestamp,

metadata.event_timestamp (si no está presente "Generate Time")

Número de serie (serie) intermediary.asset.hardware.serial_number
Tipo (type) metadata.product_event_type
Tipo de amenaza o contenido (subtipo) metadata.product_event_type
Hora de generación (time_generated o cef-formatted-time_generated) metadata.event_timestamp
Dirección de origen (src) principal.ip
Dirección de destino (dst) target.ip
Nombre de la regla (rule) security_result.rule_name
Aplicación (app) network.application_protocol
Sistema virtual (vsys) vsys intermediary.asset.attribute.labels.key/value
Zona de origen (desde) de

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Zona de destino (a) a

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

Interfaz entrante (inbound_if) inbound_if

principal.labels.key y principal.labels.value

additional.fields.key y additional.fields.value.string_value

Interfaz de salida (outbound_if) outbound_if

target.labels.key y target.labels.value

additional.fields.key y additional.fields.value.string_value

Acción de registro (conjunto de registros) logset additional.fields.key y additional.fields.value.string_value
ID de sesión (sessionid) network.session_id
Puerto de origen (sport) principal.port
Puerto de destino (dport) target.port
Protocolo de IP (proto) network.ip_protocol
Acción (action) security_result.action_details

security_result.action

Tipo de evento de GTP (event_type) gtp_event_type additional.fields.key y additional.fields.value.string_value
MSISDN (msisdn) msisdn additional.fields.key y additional.fields.value.string_value
Nombre de punto de acceso (apn) apn additional.fields.key y additional.fields.value.string_value
Tecnología de acceso por radio (RAT) rata additional.fields.key y additional.fields.value.string_value
Tipo de mensaje de GTP (msg_type) gtp_msg_type additional.fields.key y additional.fields.value.string_value
Dirección IP final (end_ip_adr) principal.ip
Identificador de extremo de túnel 1 (teid1) teid1 additional.fields.key y additional.fields.value.string_value
Identificador de extremo de túnel 2 (teid2) teid2 additional.fields.key y additional.fields.value.string_value
Interfaz de GTP (gtp_interface) gtp_interface additional.fields.key y additional.fields.value.string_value
Causa del GTP (cause_code) gtp_cause_code additional.fields.key y additional.fields.value.string_value
Gravedad (severity) security_result.severity y security_result.severity_details
MCC de la red de publicación (mcc) mcc additional.fields.key y additional.fields.value.string_value
MNC de la red de publicación (mnc) mnc additional.fields.key y additional.fields.value.string_value
Código de área (area_code) area_code additional.fields.key y additional.fields.value.string_value
ID de celda (cell_id) cell_id additional.fields.key y additional.fields.value.string_value
Código de evento de GTP (event_code) event_code additional.fields.key y additional.fields.value.string_value
Ubicación de origen (srcloc) principal.location.country_or_region
Ubicación de destino (dstloc) target.location.country_or_region
ID de túnel/IMSI (imsi) tunnelid additional.fields.key y additional.fields.value.string_value
Etiqueta de supervisión/IMEI (imei) monitortag additional.fields.key y additional.fields.value.string_value
Hora de inicio (start) start additional.fields.key y additional.fields.value.string_value
Tiempo transcurrido (elapsed) network.session_duration.seconds
Regla de inspección del túnel (tunnel_insp_rule) tunnel_insp_rule security_result.detection_fields.key/value
IP del usuario remoto (remote_user_ip) principal.ip
ID de usuario remoto (remote_user_id) remote_user_id principal.user.userid
UUID de la regla (rule_uuid) security_result.rule_id
ID de PCAP (pcap_id) pcap_id additional.fields.key y additional.fields.value.string_value
Marca de tiempo de alta resolución (high_res_timestamp) additional.fields.key y additional.fields.value.string_value
Un tipo de servicio de Slice (nsdsai_sst) nsdsai_sst additional.fields.key y additional.fields.value.string_value
Un diferenciador de Slice (nsdsai_sd) nsdsai_sd additional.fields.key y additional.fields.value.string_value
Subcategoría de la aplicación (subcategory_of_app) subcategory_of_app additional.fields.key y additional.fields.value.string_value
Categoría de la aplicación (category_of_app) category_of_app additional.fields.key y additional.fields.value.string_value
Tecnología de la aplicación (technology_of_app) technology_of_app additional.fields.key y additional.fields.value.string_value
Riesgo de la aplicación (risk_of_app) risk_of_app additional.fields.key y additional.fields.value.string_value
Característica de la aplicación (characteristic_of_app) characteristic_of_app additional.fields.key y additional.fields.value.string_value
Contenedor de la aplicación (container_of_app) container_of_app additional.fields.key y additional.fields.value.string_value
Aplicación SaaS (is_saas_of_app) is_saas_of_app additional.fields.key y additional.fields.value.string_value
Estado de aprobación de la aplicación (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key y additional.fields.value.string_value

SCTP

Campo CSV Campo de CEF Campo LEEF Clave de etiqueta de Google Security Operations Campo de UDM
Hora de recepción (receive_time o cef-formatted-receive_time) receive_time o cef-formatted-receive_time metadata.collected_timestamp
Número de serie (serie) serial intermediary.asset.hardware.serial_number
Tipo (type) tipo metadata.product_event_type
Hora de generación (time_generated o cef-formatted-time_generated) time_generated o cef-formatted-time_generated metadata.event_timestamp
Dirección de origen (src) src principal.ip
Dirección de destino (dst) DST target.ip
Nombre de la regla (rule) regla security_result.rule_name
Zona de origen (desde) de additional.fields.key y additional.fields.value.string_value
Zona de destino (a) a additional.fields.key y additional.fields.value.string_value
Interfaz entrante (inbound_if) inbound_if additional.fields.key y additional.fields.value.string_value
Interfaz de salida (outbound_if) outbound_if additional.fields.key y additional.fields.value.string_value
Acción de registro (conjunto de registros) logset additional.fields.key y additional.fields.value.string_value
ID de sesión (sessionid) sessionid network.session_id
Recuento de repeticiones (repeatcnt) repeatcnt additional.fields.key y additional.fields.value.string_value
Puerto de origen (sport) deporte principal.port
Puerto de destino (dport) dport target.port
Protocolo de IP (proto) protocolo network.ip_protocol (enum)
Acción (action) acción security_result.action_details
security_result.action
Jerarquía del grupo de dispositivos (dg_hier_level_1 a dg_hier_level_4) dg_hier_level_1 a dg_hier_level_4 additional.fields.key y additional.fields.value.string_value
Nombre del dispositivo (device_name) device_name intermediary.hostname
Número de secuencia (seqno) seqno metadata.product_log_id
ID de asociación de SCTP (assoc_id) assoc_id additional.fields.key y additional.fields.value.string_value
ID de protocolo de carga útil (ppid) ppid additional.fields.key y additional.fields.value.string_value
Gravedad (severity) gravedad, security_result.severity y security_result.severity_details
Tipo de fragmento SCTP (sctp_chunk_type) sctp_chunk_type additional.fields.key y additional.fields.value.string_value
Tipo de evento de SCTP (sctp_event_type) sctp_event_type additional.fields.key y additional.fields.value.string_value
Etiqueta de verificación 1 de SCTP (verif_tag_1) verif_tag_1 additional.fields.key y additional.fields.value.string_value
Etiqueta de verificación de SCTP 2 (verif_tag_2) verif_tag_2 additional.fields.key y additional.fields.value.string_value
Código de causa de SCTP (sctp_cause_code) sctp_cause_code additional.fields.key y additional.fields.value.string_value
ID de la app de Diameter (diam_app_id) diam_app_id additional.fields.key y additional.fields.value.string_value
Código de comando de diámetro (diam_cmd_code) diam_cmd_code additional.fields.key y additional.fields.value.string_value
Código de AVP de diámetro (diam_avp_code) diam_avp_code additional.fields.key y additional.fields.value.string_value
ID de transmisión de SCTP (stream_id) stream_id additional.fields.key y additional.fields.value.string_value
Motivo de finalización de la asociación de SCTP (assoc_end_reason) assoc_end_reason additional.fields.key y additional.fields.value.string_value
Código de operación (op_code) op_code additional.fields.key y additional.fields.value.string_value
SSN de la parte llamante de SCCP (sccp_calling_ssn) sccp_calling_ssn additional.fields.key y additional.fields.value.string_value
Título global de la parte llamadora de SCCP (sccp_calling_gt) sccp_calling_gt additional.fields.key y additional.fields.value.string_value
Filtro SCTP (sctp_filter) sctp_filter additional.fields.key y additional.fields.value.string_value
Fragmentos de SCTP (chunks) fragmentos additional.fields.key y additional.fields.value.string_value
Fragmentos SCTP enviados (chunks_sent) chunks_sent additional.fields.key y additional.fields.value.string_value
Fragmentos SCTP recibidos (chunks_received) chunks_received additional.fields.key y additional.fields.value.string_value
Paquetes (packets) paquetes additional.fields.key y additional.fields.value.string_value
UUID de la regla (rule_uuid) rule_uuid security_result.rule_id
Sistema virtual (vsys) vsys intermediary.asset.attribute.labels.key/value
Nombre del sistema virtual (vsys_name) vsys_name intermediary.asset.attribute.labels.key/value
Paquetes enviados (pkts_sent) pkts_sent network.sent_packets
Paquetes recibidos (pkts_received) pkts_received network.received_packets

Auditoría

Campo CSV Campo de CEF Campo LEEF Clave de etiqueta de Google Security Operations Campo de UDM
Fecha de generación metadata.event_timestamp
Tipo de amenaza o contenido (subtipo) metadata.product_event_type
ID del evento principal.application
Objeto principal.user.userid
Comando de la CLI principal.process.command_line
Gravedad security_result.severity
Número de serie intermediary.asset.hardware.serial_number

Referencia de asignación de campos: Tipos de registros a tipo de evento de UDM

En la siguiente tabla, se enumeran los tipos de registros de firewall de Palo Alto Networks y sus tipos de eventos de UDM correspondientes.

Tipo de registro Tipo de evento de UDM
Tráfico NETWORK_CONNECTION
Amenaza NETWORK_CONNECTION
Filtrado de URLs NETWORK_CONNECTION
WildFire NETWORK_CONNECTION

Los registros de envíos de WildFire son un subtipo del tipo de registro de amenazas y usan el mismo formato de syslog.

Filtrado de datos NETWORK_CONNECTION
Túnel NETWORK_CONNECTION
GTP NETWORK_CONNECTION
Configuración SETTING_MODIFICATION/SETTING_CREATION/SETTING_DELETION/SETTING_UNCATEGORIZED

El valor del campo "Comando (cmd)" determina la asignación del tipo de evento del UDM. Si el valor del campo cmd es add o clone, se establece SETTING_CREATION.

Si el valor del campo cmd es delete, se establece SETTING_DELETION.

Si el valor del campo cmd es edit, move, rename, set o commit, se establece SETTING_MODIFICATION.

Si el valor del campo cmd no contiene ningún valor, se establece SETTING_UNCATEGORIZED.

Sistema

Si el valor del subtipo es "dhcp", se establece NETWORK_DHCP.

Si el valor del subtipo es "auth", se establece USER_LOGIN.

Si el valor de la descripción es "logged in", se establece USER_LOGIN.

Si el valor de la descripción es "logged out", se establece USER_LOGOUT.

Para otros valores del subtipo, se establece GENERIC_EVENT.

HIP Match NETWORK_CONNECTION
Etiqueta de IP GENERIC_EVENT
User-ID USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED

Si el valor del subtipo es "login", se establece USER_LOGIN.

Si el valor del subtipo es "logout", se establece USER_LOGOUT.

Si el subtipo no contiene ningún valor, se establece USER_UNCATEGORIZED.

Desencriptación NETWORK_CONNECTION
Autenticación GENERIC_EVENT
SCTP NETWORK_CONNECTION
Auditoría GENERIC_EVENT

Delta de asignación de UDM

Referencia del delta de la asignación del UDM: Firewall de Palo Alto Networks

En la siguiente tabla, se muestra la diferencia entre la asignación de UDM anterior de Palo Alto Networks Firewall y la asignación de UDM nueva de Palo Alto Networks Firewall.

UDM Event Type Delta

Log type Old UDM Event Type New UDM Event Type
WildFire NETWORK_CONNECTION SCAN_UNCATEGORIZED
Data Filtering NETWORK_CONNECTION NETWORK_UNCATEGORIZED
Authentication STATUS_UPDATE STATUS_UNCATEGORIZED

UDM Field Mapping Delta

Log Type Old UDM Mapping CSV Log Field CEF Log Field LEEF Log Field New UDM Mapping
System intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
System about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
System about.labels.key/value additional.fields.key/value.string_value Object (object) fname Filename target.resource.name
System Description (opaque) msg msg metadata.description
System principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
System intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
Config intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Config about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
Config principal.process.command_line Configuration Path (path) msg ConfigurationPath principal.process.command_line
Config principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
Config intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
Config principal.asset.attribute.labels.key/value Device Group (dg_id) PanOSFWDeviceGroup target.asset.attribute.labels
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Threat/Wildfire target.file.full_path target.url target.hostname URL/Filename (misc) request Miscellaneous target.file.names target.url
Threat/Wildfire about.file.sha1/md5/sha256 File Digest (filedigest) fileHash FileDigest target.file.sha1/md5/sha256
Threat/Wildfire about.file.mime_type File Type (filetype) fileType FileType target.file.mime_type
Threat/Wildfire principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Threat/Wildfire principal.user.product_object_id Source VM UUID (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
Threat/Wildfire target.user.product_object_id Destination VM UUID (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value HTTP Headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
Threat/Wildfire principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
Threat/Wildfire principal.asset.software.version Source Device OS Version (src_osversion) PanSrcDeviceOSv principal.platform_version
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
Threat/Wildfire target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
Threat/Wildfire metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Reason (reason) PanReasonFilteringAction security_result.summary
Traffic about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value Packets Sent (pkts_sent) PanOSPacketsSent srcPackets network.sent_packets
Traffic about.labels.key/value additional.fields.key/value.string_value Packets Received (pkts_received) PanOSPacketsReceived dstPackets network.received_packets
Traffic principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
Traffic principal.asset.platform_software.platform(enum) principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
Traffic target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
Traffic about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
Traffic about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
Traffic about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
Traffic metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
User-ID about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
User-ID principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
User-ID principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID intermediary.resource.product_object_id
User-ID principal.user.userid principal.administrative_domain principal.user.email_addresses User by Source (userbysource) PanOSUserBySource target.user.userid target.user.email_addresses
User-ID metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
HIP Match intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
HIP Match about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
HIP Match about.labels.key/value additional.fields.key/value.string_value HIP (matchname) cat HIP target.resource.attribute.labels
HIP Match about.labels.key/value additional.fields.key/value.string_value HIP Type (matchtype) Device Event Class ID (Header) HIPType target.resource.attribute.labels
HIP Match principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
HIP Match intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
HIP Match principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
HIP Match principal.asset.product_object_id Host ID (hostid) PanOSHostID principal.asset.asset_id
HIP Match metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
IP-Tag intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
IP-Tag about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
IP-Tag principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOsVsysName vSrcName target.asset.attribute.labels
IP-Tag intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
IP-Tag principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
IP-Tag metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Decryption target.application Application (app) app network.application_protocol
Decryption about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 intermediary.asset.attribute.labels
Decryption principal.asset.asset_id Source VM UUID (src_uuid) PanOSSourceUUID principal.asset.product_object_id
Decryption target.asset.asset_id Destination VM UUID (dst_uuid) PanOSDestinationUUID target.asset.product_object_id
Decryption about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanOSContainerID intermediary.resource.product_object_id
Decryption about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanOSContainerNameSpace target.resource.attribute.labels additional.fields.key/value.string_value
Decryption about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanOSContainerName target.resource.name
Decryption metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanOSSourceDeviceCategory principal.asset.category
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanOSSourceDeviceModel principal.asset.hardware.model
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanOSSourceDeviceVendor principal.asset.hardware.manufacturer
Decryption principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanOSSourceDeviceOSFamily principal.platform
Decryption principal.asset.software.version Source Device OS Version (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanOSDestinationDeviceCategory target.asset.category
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanOSDestinationDeviceModel target.asset.hardware.model
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanOSDestinationDeviceVendor target.asset.hardware.manufacturer
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanOSDestinationDeviceOSFamily target.platform
Decryption target.asset.software.version Destination Device OS Version (dst_osversion) PanOSDestinationDeviceOSVersion target.platform_version
Decryption principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) intermediary.asset.attribute.labels
Decryption principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
Tunnel about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Tunnel principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Tunnel about.labels.key/value additional.fields.key/value.string_value Packets Sent (pkts_sent) PanOSPacketsSent srcPackets network.sent_packets
Tunnel about.labels.key/value additional.fields.key/value.string_value Packets Received (pkts_received) PanOSPacketsReceived dstPackets network.received_packets
Tunnel target.ip Remote User IP (remote_user_ip) PanOSRmtUserIP principal.ip
Tunnel target.labels.key/value additional.fields.key/value.string_value Remote User ID (remote_user_id) PanOSRmtUserID principal.user.userid
Tunnel metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Authentication about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Authentication target.user.user_display_name Normalize User (normalize_user) cs2 NormalizeUser target.user.user_display_name
Authentication about.labels.key/value additional.fields.key/value.string_value Object (object) fname ObjectName target.resource.name
Authentication about.labels.key/value additional.fields.key/value.string_value Authentication Policy (authpolicy) cs4 AuthPolicy additional.fields.key/value.string_value
Authentication principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Authentication principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
Authentication metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res _timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanOSSourceDeviceCategory principal.asset.category
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanOSSourceDeviceModel principal.asset.hardware.model
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanOSSourceDeviceVendor principal.asset.hardware.manufacturer
Authentication principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanOSSourceDeviceOSFamily principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value
Authentication principal.asset.software.version Source Device OS Version (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
URL about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
URL target.file.full_path target.url URL/Filename (misc) Miscellaneous target.file.names target.url
URL about.labels.key/value additional.fields.key/value.string_value Category (category) cs2 URLCategory security_result.category_details
URL about.file.sha1/md5/sha256 filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
URL about.file.mime_type filetype (filetype) target.file.mime_type
URL about.labels.key/value additional.fields.key/value.string_value xff (xff) PanOSXForwarderfor identSrc principal.ip
URL principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
URL about.url file_url (file_url) target.url
URL principal.asset.asset_id Source VM UUID (src_uuid) SrcUUID principal.asset.product_object_id
URL target.asset.asset_id Destination VM UUID (dst_uuid) DstUUID target.asset.product_object_id
URL about.labels.key/value additional.fields.key/value.string_value http_headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
URL about.labels.key/value additional.fields.key/value.string_value UUID for rule (rule_uuid) PanOSRuleUUID security_result.rule_id
URL about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
URL principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
URL principal.asset.software.version Source Device OS Version (src_osversion) PanSrcDeviceOSv principal.platform_version
URL principal.labels.key/value additional.fields.key/value.string_value Source Hostname (src_host) PanSrcHostname principal.hostname
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
URL target.asset.platform_software.platform target.labels.key/value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
URL target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
URL about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
URL about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
URL about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
URL about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
URL metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Res Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
URL about.labels.key/value additional.fields.key/value.string_value Reason (reason) PanReasonFilteringAction security_result.summary
Data about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Data target.file.full_path target.url URL/Filename (misc) Miscellaneous target.file.names target.url
Data about.labels.key/value additional.fields.key/value.string_value Category (category) cs2 URLCategory security_result.category_details
Data about.file.sha1/md5/sha256 filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
Data about.file.mime_type filetype (filetype) target.file.mime_type
Data about.labels.key/value additional.fields.key/value.string_value xff (xff) principal.ip
Data principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Data about.url file_url (file_url) target.url
Data principal.asset.asset_id Source VM UUID (src_uuid) SrcUUID principal.asset.product_object_id
Data target.asset.asset_id Destination VM UUID (dst_uuid) DstUUID target.asset.product_object_id
Data about.labels.key/value additional.fields.key/value.string_value http_headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
Data about.labels.key/value additional.fields.key/value.string_value UUID for rule (rule_uuid) PanOSRuleUUID security_result.rule_id
Data about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) network.application_protocol_version
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) principal.asset.category
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) principal.asset.hardware.model
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) principal.asset.hardware.manufacturer
Data principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) principal.platform
Data principal.asset.software.version Source Device OS Version (src_osversion) principal.platform_version
Data principal.labels.key/value additional.fields.key/value.string_value Source Hostname (src_host) principal.hostname
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) target.asset.category
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) target.asset.hardware.model
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) target.asset.hardware.manufacturer
Data target.asset.platform_software.platform target.labels.key/value Destination Device OS Family (dst_osfamily) target.platform
Data target.asset.software.version Destination Device OS Version (dst_osversion) target.platform_version
Data about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) intermediary.resource.product_object_id
Data about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) target.resource.attribute.labels
Data about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) target.resource.name
Data about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) principal.asset.asset_id
Data metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Res Timestamp (high_res_timestamp) additional.fields.key/value.string_value
Data about.labels.key/value additional.fields.key/value.string_value Reason (reason) security_result.summary
GlobalProtect about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) PanOSVirtualSystem intermediary.asset.attribute.labels
GlobalProtect principal.user.email_address principal.user.userid principal.administrative_domain Source User (srcuser) PanOSSourceUserName target.user.email_address target.user.userid
GlobalProtect principal.asset.platform_software.platform(enum) Client OS (client_os) PanOSEndpointOSType principal.platform
GlobalProtect principal.asset.platform_software.platform_version Client OS Version (client_os_ver) PanOSEndpointOSVersion principal.platform_version
GlobalProtect metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
GlobalProtect about.labels.key/value additional.fields.key/value.string_value Gateway Name (gateway) PanOSAttemptedGateways target.resource.name
GlobalProtect principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) intermediary.asset.attribute.labels
GlobalProtect target.hostname Device Name (device_name) intermediary.hostname
GlobalProtect principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
CORRELATION about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) VirtualSystem intermediary.asset.attribute.labels
CORRELATION principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) vSrcName intermediary.asset.attribute.labels
CORRELATION principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) VirtualSystemID intermediary.resource.product_object_id
GTP additional.fields.key/value.string_value Virtual System (vsys) intermediary.asset.attribute.labels
GTP target.ip Remote User IP (remote_user_ip) principal.ip
GTP additional.fields.key/value.string_value Remote User ID (remote_user_id) principal.user.userid
GTP metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) additional.fields.key/value.string_value

Servicio de registro de Strata Firewall de Palo Alto Networks

Descripción general

El servicio de registro de Strata de Palo Alto Networks® proporciona almacenamiento y agregación de registros centralizados basados en la nube para tus firewalls locales y virtuales (nube privada y nube pública), para Prisma Access y para servicios entregados en la nube, como Cortex XDR.El servicio de registro de Strata es seguro, resiliente y tolerante a fallas, y garantiza que tus datos de registro estén actualizados y disponibles cuando los necesites. Proporciona una infraestructura de registro escalable que alivia la necesidad de planificar e implementar colectores de registros para satisfacer tus necesidades de retención de registros. Si ya tienes recopiladores de registros locales, el nuevo servicio de registro de Strata puede complementar tu configuración existente. Puedes aumentar tu infraestructura existente de recopilación de registros con el servicio de registro de Strata basado en la nube para expandir la capacidad operativa a medida que crece tu empresa o para satisfacer las necesidades de capacidad de las ubicaciones nuevas.Con este servicio, Palo Alto Networks se encarga del mantenimiento y la supervisión continuos de la infraestructura de registro para que puedas concentrarte en tu empresa.

  • Verifica los formatos de registro y las versiones de PAN-OS que admite el analizador del servicio de registro de Strata. En la siguiente tabla, se enumeran los formatos de registro y las versiones correspondientes de PAN-OS que admite el analizador del servicio de registro de Strata:

    Formato de registro Versión de PAN-OS
    JSON 12.1
  • Verifica los tipos de registros del firewall de Palo Alto Networks que admite el analizador de SecOps de Google. El analizador de SecOps de Google admite los siguientes tipos de registros de firewall de Palo Alto Networks:

    • Tráfico
    • Amenaza
    • Inspección de túneles
    • Sistema
    • Coincidencia de HIP
    • IP-Tag
    • User-ID
    • Desencriptación
    • Autenticación
    • Filtros de URL
    • GlobalProtect

Implementación del servicio de registro de Strata

Comienza a enviar registros al servicio de Strata Logging:

Para comenzar a enviar registros al servicio de Strata Logging, sigue estos pasos:

  1. Instala una versión compatible de PAN-OS®
  2. Activa el servicio de registro de Strata: La activación del servicio de registro de Strata incluye el aprovisionamiento del certificado que los firewalls necesitan para conectarse de forma segura al servicio de registro de Strata.
  3. Incorpora firewalls al servicio de registro de Strata con o sin Panorama

Para conocer los pasos detallados de incorporación, consulta la Documentación.

Reenvía registros del servicio de registro de Strata

Para satisfacer tus necesidades de almacenamiento, informes y supervisión a largo plazo, o bien de cumplimiento y legales, puedes configurar el Servicio de registro de Strata para que reenvíe los registros a un servidor HTTPS o a los siguientes SIEM:

  1. Exabeam
  2. Google Chronicle
  3. Microsoft Sentinel
  4. Recopilador de eventos HTTP (HEC) de Splunk

Usa el método de reenvío HTTPS para reenviar los registros con el Servicio de registro de Strata. Para obtener información detallada, consulta esta documentación.

Formatos de registro admitidos

El analizador de firewall de Strata Logging Service de Palo Alto Networks admite registros en formato JSON.

Registros de muestra admitidos

  • JSON

    {"source": "Palo Alto Networks FLS LF", "host": "dummy-loghost", "time": "1730265996460", "event": {"TimeReceived": "2024-10-30T05:25:50.000000Z", "DeviceSN": "no-serial", "LogType": "TRAFFIC", "Subtype": "end", "ConfigVersion": "10.2", "TimeGenerated": "2024-10-30T05:25:40.000000Z", "SourceAddress": "198.51.100.6", "DestinationAddress": "198.51.100.6", "NATSource": "", "NATDestination": "", "Rule": "egress-dns-ping-traceroute", "SourceUser": null, "DestinationUser": null, "Application": "dns-base", "VirtualLocation": "vsys1", "FromZone": "VA8280-RN", "ToZone": "inter-fw", "InboundInterface": "tunnel.101", "OutboundInterface": "tunnel.4005", "LogSetting": "Cortex Data Lake", "SessionID": 754194, "RepeatCount": 1, "SourcePort": 53578, "DestinationPort": 53, "NATSourcePort": 0, "NATDestinationPort": 0, "Protocol": "udp", "Action": "allow", "Bytes": 214, "BytesSent": 72, "BytesReceived": 142, "PacketsTotal": 2, "SessionStartTime": "2024-10-30T05:25:10.000000Z", "SessionDuration": 0, "URLCategory": "any", "SequenceNo": 7382192512716388639, "SourceLocation": "198.51.100.6-198.51.255.255", "DestinationLocation": "198.51.100.6-198.51.255.255", "PacketsSent": 1, "PacketsReceived": 1, "SessionEndReason": "aged-out", "DGHierarchyLevel1": 65537, "DGHierarchyLevel2": 65538, "DGHierarchyLevel3": 65541, "DGHierarchyLevel4": 0, "VirtualSystemName": "", "DeviceName": "VA8280-RN", "ActionSource": "from-policy", "SourceUUID": null, "DestinationUUID": null, "IMSI": 0, "IMEI": null, "ParentSessionID": 0, "ParentStarttime": "1970-01-01T00:00:00.000000Z", "Tunnel": "N/A", "EndpointAssociationID": 72057594037927936, "ChunksTotal": 0, "ChunksSent": 0, "ChunksReceived": 0, "RuleUUID": "95cfc3cc-cb00-4758-af1d-de9ab5f07f97", "HTTP2Connection": 0, "LinkChangeCount": 0, "SDWANPolicyName": null, "LinkSwitches": null, "SDWANCluster": null, "SDWANDeviceType": null, "SDWANClusterType": null, "SDWANSite": null, "DynamicUserGroupName": null, "X-Forwarded-ForIP": null, "SourceDeviceCategory": null, "SourceDeviceProfile": null, "SourceDeviceModel": null, "SourceDeviceVendor": null, "SourceDeviceOSFamily": null, "SourceDeviceOSVersion": null, "SourceDeviceHost": null, "SourceDeviceMac": null, "DestinationDeviceCategory": null, "DestinationDeviceProfile": null, "DestinationDeviceModel": null, "DestinationDeviceVendor": null, "DestinationDeviceOSFamily": null, "DestinationDeviceOSVersion": null, "DestinationDeviceHost": null, "DestinationDeviceMac": null, "ContainerID": null, "ContainerNameSpace": null, "ContainerName": null, "SourceEDL": null, "DestinationEDL": null, "GPHostID": null, "EndpointSerialNumber": null, "SourceDynamicAddressGroup": null, "DestinationDynamicAddressGroup": null, "HASessionOwner": null, "TimeGeneratedHighResolution": "2024-10-30T05:25:41.009000Z", "NSSAINetworkSliceType": null, "NSSAINetworkSliceDifferentiator": null}}"
    

Referencia de la asignación de campos: Campos de registros a campos del UDM

En esta sección, se explica cómo el analizador asigna los campos de registro del firewall del servicio de registro de Strata de Palo Alto Networks a los campos de eventos del UDM de Google para cada tipo de registro.

Consulta las siguientes secciones para obtener referencias de asignación de cada tipo de registro:

Sistema

En la siguiente tabla, se enumeran los campos de registro del tipo de registro del sistema y sus campos de UDM correspondientes.

Log field UDM mapping
AgentContentVersion additional.fields.key/value.string_value
AgentDataCollectionStatus target.resource.attribute.labels
AgentID target.resource.attribute.labels
AgentIsolationStatus target.resource.attribute.labels
AgentStatus target.resource.attribute.labels
AgentVersion target.asset.software.version
ConfigVersion additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DeviceGroup target.group.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EndpointCPUArchitecture target.asset.hardware.cpu_platform
EndpointDeviceDomain target.asset.administrative_domain
EndpointDeviceName target.asset.hostname
EndpointIPaddress target.asset.ip
VDIEndpoint target.asset.attribute.labels
EndpointOSType additional.fields.key/value.string_value
EndpointOSVersion target.platform_version
AgentTimeZoneOffset additional.fields.key/value.string_value
EndpointUserDomain additional.fields.key/value.string_value
EndpointUserName target.user.user_display_name
EndpointUserUUID target.user.userid
EventComponent additional.fields.key/value.string_value
EventDescription metadata.description
EventName additional.fields.key/value.string_value
EventTime metadata.event_timestamp
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogCategory security_result.category_details
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
LogSourceID target.resource.attribute.labels
LogSourceName observer.asset.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
LogTime metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Severity security_result.severity
Subtype metadata.product_event_type
Template target.resource.attribute.labels
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

Amenaza

En la siguiente tabla, se enumeran los campos de registro del tipo de registro de amenazas y sus campos de UDM correspondientes.

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
ApplianceOrCloud additional.fields.key/value.string_value
CloudHostname additional.fields.key/value.string_value
CloudReportID security_result.detection_fields.key/value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DirectionOfAttack security_result.detection_fields.key/value
DomainEDL additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
FileName target.file.names
FileHash target.file.sha1
FileType additional.fields.key/value.string_value
FileURL target.url
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HostID principal.asset.asset_id
HTTP2Connection network.application_protocol_version
HTTPMethod network.http.method
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
LocalDeepLearningAnalyzed additional.fields.key/value.string_value
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
PartialHash additional.fields.key/value.string_value
PayloadProtocolID additional.fields.key/value.string_value
Packet additional.fields.key/value.string_value
PacketID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
RecipientEmail target.user.email_addresses
ReportID security_result.detection_fields.key/value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SenderEmail principal.user.email_addresses
SequenceNo metadata.product_log_id
SessionID network.session_id
Severity security_result.severity
SigFlags additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
EmailSubject network.email.subject
ApplicationTechnology additional.fields.key/value.string_value
ThreatCategory security_result.detection_fields.key/value.key/value
ThreatID security_result.threat_id
ThreatName security_result.threat_name
ThreatNameFirewall additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLDomain target.domain.name
URLCounter additional.fields.key/value.string_value
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
Verdict additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-ForIP principal.ip

Tráfico

En la siguiente tabla, se enumeran los campos de registro del tipo de registro de tráfico y sus campos de UDM correspondientes.

Log field UDM mapping
Action security_result.action
ActionSource additional.fields.key/value.string_value
AIFwdError additional.fields.key/value.string_value
AITraffic additional.fields.key/value.string_value
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
BytesReceived network.received_bytes
BytesSent network.sent_bytes
Bytes additional.fields.key/value.string_value
ChunksReceived additional.fields.key/value.string_value
ChunksSent additional.fields.key/value.string_value
ChunksTotal additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
EndpointAssociationID additional.fields.key/value.string_value
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HASessionOwner additional.fields.key/value.string_value
GPHostID additional.fields.key/value.string_value
HTTP2Connection network.application_protocol_version
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsOffloaded additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
LinkChangeCount additional.fields.key/value.string_value
LinkSwitches additional.fields.key/value.string_value
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
SDWANPolicyName additional.fields.key/value.string_value
Protocol network.ip_protocol
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SDWANFECRatio additional.fields.key/value.string_value
SDWANCluster additional.fields.key/value.string_value
SDWANClusterType additional.fields.key/value.string_value
SDWANDeviceType additional.fields.key/value.string_value
SDWANSite additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionStartTime additional.fields.key/value.string_value
SessionTracker additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
SessionDuration network.session_duration
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLCategory target.url_metadata.categories
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-ForIP principal.ip

User-ID

En la siguiente tabla, se enumeran los campos de registro del tipo de registro User-ID y sus campos de UDM correspondientes.

Log field UDM mapping
AuthFactorNo security_result.detection_fields.key/value
AuthenticatedUserDomain target.user.administrative_domain
AuthenticatedUserName target.user.userid
AuthenticatedUserUUID target.user.product_object_id
ConfigVersion additional.fields.key/value.string_value
CountofRepeats additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationPort target.port
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EventID additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsDuplicateUser additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MappingDataSource additional.fields.key/value.string_value
MappingDataSourceName additional.fields.key/value.string_value
MappingDataSourceType additional.fields.key/value.string_value
MappingTimeout additional.fields.key/value.string_value
MFAFactorType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SourceIP principal.ip
SourcePort principal.port
Subtype metadata.product_event_type
Tag additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
UGFlags additional.fields.key/value.string_value
User target.user.userid
UserGroupFound additional.fields.key/value.string_value
UserIdentifiedBySource additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Coincidencia de HIP

En la siguiente tabla, se enumeran los campos de registro del tipo de registro de coincidencia de HIP y sus campos de UDM correspondientes.

Log field UDM mapping
ConfigVersion additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EndpointDeviceName principal.asset.hostname
EndpointOSType additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
HipMatchName target.resource.attribute.labels
HipMatchType target.resource.attribute.labels
HostID principal.asset.asset_id
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType metadata.product_event_type
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Source additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceIP principal.ip
SourceIPv6 principal.ip
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
TimestampDeviceIdentification principal.asset.first_seen_time
UUID additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

Etiqueta de IP

En la siguiente tabla, se enumeran los campos de registro del tipo de registro de etiquetas de IP y sus campos de UDM correspondientes.

Log field UDM mapping
ConfigVersion additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EventID additional.fields.key/value.string_value
IPSubnetRange network.ip_subnet_range
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSetting target.resource.attribute.labels
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MappingDataSource additional.fields.key/value.string_value
MappingDataSourceSubType additional.fields.key/value.string_value
MappingDataSourceType additional.fields.key/value.string_value
MappingTimeout additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
RuleMatched security_result.rule_name
RuleMatchedUUID security_result.rule_id
SequenceNo metadata.product_log_id
SourceIP principal.ip
Subtype metadata.product_event_type
TagName additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

Desencriptación

En la siguiente tabla, se enumeran los campos de registro del tipo de registro Decryption y sus campos de UDM correspondientes.

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
CertificateFlags additional.fields.key/value.string_value
CertificateSerial network.tls.server.certificate.serial
CertificateSize additional.fields.key/value.string_value
CertificateVersion network.tls.server.certificate.version
ChainStatus additional.fields.key/value.string_value
ApplicationCharacteristics additional.fields.key/value.string_value
ClientToFirewall additional.fields.key/value.string_value
CommonName additional.fields.key/value.string_value
CommonNameLength additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
Cpadding additional.fields.key/value.string_value
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
Domain target.hostname
EllipticCurve network.tls.curve
ErrorIndex additional.fields.key/value.string_value
ErrorMessage additional.fields.key/value.string_value
Fingerprint network.tls.server.certificate.md5/sha1/sha256
FirewallToClient additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsCertECDSA additional.fields.key/value.string_value
IsCertRSA additional.fields.key/value.string_value
IsCertCNTruncated additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
IsForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsIssuerCNTruncated additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
IsNAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
PacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsResumeSession additional.fields.key/value.string_value
IsRootCNTruncated additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSNITruncated additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
IssuerCommonName network.tls.server.certificate.issuer
IssuerNameLength additional.fields.key/value.string_value
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
TimeNotAfter additional.fields.key/value.string_value
TimeNotBefore additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
Padding additional.fields.key/value.string_value
Padding3 additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
PolicyName additional.fields.key/value.string_value
Protocol network.ip_protocol
ProxyType additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
RootCommonName additional.fields.key/value.string_value
RootCNLength additional.fields.key/value.string_value
RootStatus additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SessionID network.session_id
ServerNameIndication network.tls.client.server_name
SNILength additional.fields.key/value.string_value
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceOS additional.fields.key/value.string_value
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
ApplicationTechnology additional.fields.key/value.string_value
TimeReceivedManagementPlane additional.fields.key/value.string_value
TLSAuth additional.fields.key/value.string_value
TLSEncryptionAlgorithm additional.fields.key/value.string_value
TLSKeyExchange additional.fields.key/value.string_value
TLSVersion network.tls.version
ToZone additional.fields.key/value.string_value
Tpadding additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
Vpadding additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SourceDeviceCategory principal.asset.category
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Túnel

En la siguiente tabla, se enumeran los campos de registro del tipo de registro Túnel y sus campos de UDM correspondientes.

Log field UDM mapping
AccessPointName additional.fields.key/value.string_value
Action security_result.action
ActionSource additional.fields.key/value.string_value
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
BytesReceived network.received_bytes
BytesSent network.sent_bytes
Bytes additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
LoggingServiceID additional.fields.key/value.string_value
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MobileAreaCode additional.fields.key/value.string_value
MobileBaseStationCode additional.fields.key/value.string_value
MobileCountryCode additional.fields.key/value.string_value
MobileIP additional.fields.key/value.string_value
MobileNetworkCode additional.fields.key/value.string_value
MobileSubscriberISDN additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceDifferentiator additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsDroppedMax additional.fields.key/value.string_value
PacketsDroppedStrict additional.fields.key/value.string_value
PacketsDroppedTunnel additional.fields.key/value.string_value
PacketsDroppedProtocol additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
ProtocolDataUnitsessionID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
RadioAccessTechnology additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionStartTime additional.fields.key/value.string_value
SessionTracker additional.fields.key/value.string_value
Severity security_result.severity
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
StandardPortsOfApp additional.fields.key/value.string_value
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
SessionDuration network.session_duration
Tunnel additional.fields.key/value.string_value
TunnelCauseCode additional.fields.key/value.string_value
TunnelEndpointID1 additional.fields.key/value.string_value
TunnelEndpointID2 additional.fields.key/value.string_value
TunnelEventCode additional.fields.key/value.string_value
TunnelEventType additional.fields.key/value.string_value
TunnelInspectionRule additional.fields.key/value.string_value
TunnelInterface additional.fields.key/value.string_value
TunnelMessageType additional.fields.key/value.string_value
TunnelRemoteIMSIID additional.fields.key/value.string_value
TunnelRemoteUserIP principal.ip
TunnelSessionsClosed additional.fields.key/value.string_value
TunnelSessionsCreated additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLCategory target.url_metadata.categories
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Autenticación

En la siguiente tabla, se enumeran los campos de registro del tipo de registro Authentication y sus campos de UDM correspondientes.

Log field UDM mapping
AuthenticationDescription security_result.description
AuthEvent metadata.description
AuthFactorNo security_result.detection_fields.key/value
AuthenticationPolicy security_result.detection_fields.key/value
AuthenticationProtocol additional.fields.key/value.string_value
AuthServerProfile additional.fields.key/value.string_value
AuthenticatedUserDomain target.administrative_domain
AuthenticatedUserName target.user.userid
AuthenticatedUserUUID target.user.product_object_id
ClientType additional.fields.key/value.string_value
ClientTypeName additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
IsPrismaNetworks additional.fields.key/value.string_value
Location target.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogType additional.fields.key/value.string_value
MFAAuthenticationID additional.fields.key/value.string_value
MFAVendor additional.fields.key/value.string_value
NormalizeUser target.user.user_display_name
Object target.resource.name
RuleMatched security_result.rule_name
RuleMatchedUUID security_result.rule_id
AuthCacheServiceRegion additional.fields.key/value.string_value
SessionID network.session_id
SourceDeviceCategory principal.asset.category
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceIP principal.ip
TimeGenerated metadata.event_timestamp
User target.user.userid
UserAgentString network.http.user_agent
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Subtype metadata.product_event_type
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

URL

En la siguiente tabla, se enumeran los campos de registro del tipo de registro de URL y sus campos de UDM correspondientes.

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
CloudHostname additional.fields.key/value.string_value
CloudReportID security_result.detection_fields.key/value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentType additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DirectionOfAttack security_result.detection_fields.key/value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
FileURL target.url
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HostID principal.asset.asset_id
HTTP2Connection network.application_protocol_version
HTTPHeaders additional.fields.key/value.string_value
HTTPMethod network.http.method
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
InlineMLVerdict additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
Packet additional.fields.key/value.string_value
PacketID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
Referer network.http.referral_url
HTTPRefererFQDN additional.fields.key/value.string_value
HTTPRefererPort additional.fields.key/value.string_value
HTTPRefererProtocol additional.fields.key/value.string_value
HTTPRefererURLPath additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionID network.session_id
Severity security_result.severity
SigFlags additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URL target.url_metadata.URL
URLCategory target.url_metadata.categories
URLCategoryList additional.fields.key/value.string_value
URLDomain target.domain.name
URLCounter additional.fields.key/value.string_value
UserAgent network.http.user_agent
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-For additional.fields.key/value.string_value
X-Forwarded-ForIP principal.ip

GlobalProtect

En la siguiente tabla, se enumeran los campos de registro del tipo de registro de GlobalProtect y sus campos de UDM correspondientes.

Log field UDM mapping
AttemptedGateways additional.fields.key/value.string_value
AuthMethod extensions.auth.auth_details
ConnectionMethod additional.fields.key/value.string_value
ConnectionErrorID additional.fields.key/value.string_value
ConnectionError additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
EndpointDeviceName principal.asset.hostname
GlobalProtectClientVersion additional.fields.key/value.string_value
EndpointOSType additional.fields.key/value.string_value
EndpointSN principal.asset.hardware.serial_number
EventIDValue additional.fields.key/value.string_value
Gateway target.resource.name
GatewayPriority additional.fields.key/value.string_value
GatewaySelectionType additional.fields.key/value.string_value
GlobalProtectGatewayLocation target.location.country_or_region
HostID principal.asset.asset_id
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LoginDuration network.session_duration
Description security_result.description
Portal target.hostname
PrivateIPv4 principal.ip
PrivateIPv6 principal.ip
ProjectName additional.fields.key/value.string_value
PublicIPv4 principal.nat_ip
PublicIPv6 principal.nat_ip
QuarantineReason security_result.summary
SequenceNo metadata.product_log_id
SourceRegion principal.location.country_or_region
SourceUserName principal.user.user_display_name
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SSLResponseTime additional.fields.key/value.string_value
Stage additional.fields.key/value.string_value
EventStatus additional.fields.key/value.string_value
LogSubtype metadata.product_event_type
TunnelType additional.fields.key/value.string_value
VirtualSystem intermediary.asset.attribute.labels
VirtualSystemName intermediary.asset.attribute.labels
EndpointOSVersion principal.platform_version
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType metadata.product_event_type
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualSystemID intermediary.resource.product_object_id

SCTP

En la siguiente tabla, se enumeran los campos de registro del tipo de registro SCTP y sus campos de UDM correspondientes.

Log field UDM mapping
Action security_result.action
Application target.application
AssocationEndReason additional.fields.key/value.string_value
ChunksReceived additional.fields.key/value.string_value
ChunksSent additional.fields.key/value.string_value
ChunksTotal additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceClass target.asset.category
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationIP target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DiamAppID additional.fields.key/value.string_value
DiamAvpCode additional.fields.key/value.string_value
DiameterCommandCode additional.fields.key/value.string_value
DiameterRequestFlag additional.fields.key/value.string_value
DeviceName principal.asset.hostname
SCTPEventType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLFiltering additional.fields.key/value.string_value
IsWildfire additional.fields.key/value.string_value
LogAction additional.fields.key/value.string_value
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MapAppCode additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PayloadProtocolID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
Rule security_result.rule_name
RuleUUID security_result.rule_id
SccpCallingGt additional.fields.key/value.string_value
SccpCallingSSN additional.fields.key/value.string_value
SctpCauseCode additional.fields.key/value.string_value
SctpChunkType additional.fields.key/value.string_value
SctpFilter additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionTracker additional.fields.key/value.string_value
Severity security_result.severity
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceIP principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VerificationTag1 additional.fields.key/value.string_value
VerificationTag2 additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Auditoría

En la siguiente tabla, se enumeran los campos de registro del tipo Registro de auditoría y sus campos de UDM correspondientes.

Log field UDM mapping
EventCategory network.http.method
EventDescription metadata.description
EventDestinationURL target.url
EventDestinationUserUserID target.user.userid
DestinationVendor additional.fields.key/value.string_value
EventDetails additional.fields.key/value.string_value
EventID metadata.product_log_id
EventName additional.fields.key/value.string_value
EventResult security_result.summary
EventSourceUserUserID principal.user.userid
EventTime metadata.event_timestamp
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
Subtype metadata.product_event_type
TSGID additional.fields.key/value.string_value
Vendor additional.fields.key/value.string_value
VendorSeverity security_result.severity_details

Referencia de asignación de campos: Tipos de registros a tipo de evento de UDM

En la siguiente tabla, se enumeran los tipos de registros del firewall del servicio de registro de Strata de Palo Alto Networks y sus tipos de eventos de UDM correspondientes.

Tipo de registro Tipo de evento de UDM
Tráfico NETWORK_CONNECTION
Amenaza NETWORK_CONNECTION
Filtrado de URLs NETWORK_CONNECTION
Túnel NETWORK_CONNECTION
Sistema

Si el valor del subtipo es "dhcp", se establece NETWORK_DHCP.

Si el valor del subtipo es "auth", se establece USER_LOGIN.

Si el valor de la descripción es "logged in", se establece USER_LOGIN.

Si el valor de la descripción es "logged out", se establece USER_LOGOUT.

Para otros valores del subtipo, se establece GENERIC_EVENT.

HIP Match NETWORK_CONNECTION
Etiqueta de IP GENERIC_EVENT
User-ID USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED

Si el valor del subtipo es "login", se establece USER_LOGIN.

Si el valor del subtipo es "logout", se establece USER_LOGOUT.

Si el subtipo no contiene ningún valor, se establece USER_UNCATEGORIZED.

Desencriptación NETWORK_CONNECTION
Autenticación STATUS_UNCATEGORIZED
Globalprotect USER_LOGIN/USER_LOGOUT/USER_RESOURCE_ACCESS

Si el valor del subtipo es "auth", se establece USER_LOGIN.

Si el valor del subtipo es "logout", se establece USER_LOGOUT.

Si el subtipo no contiene ningún valor, se establece USER_RESOURCE_ACCESS.

SCTP NETWORK_CONNECTION
Auditoría NETWORK_CONNECTION

¿Qué sigue?

¿Necesitas más ayuda? Obtén respuestas de miembros de la comunidad y profesionales de Google SecOps.