Recopila registros del firewall de Palo Alto Networks
Firewall de Palo Alto Networks
Descripción general
En este documento, se describe cómo puedes configurar syslog y un retransmisor de SecOps de Google para recopilar registros de firewall de Palo Alto Networks. En este documento, también se explica cómo los campos de registro del firewall de Palo Alto Networks se asignan a los campos del Modelo de datos unificado (UDM) de Google SecOps. Para obtener una descripción general de la transferencia de datos a Google SecOps, consulta Transferencia de datos a Google SecOps. Una etiqueta de transferencia identifica el analizador que normaliza los datos de registro sin procesar en formato UDM estructurado. La información de este documento se aplica al analizador con la etiqueta de transferencia PAN_FIREWALL.
Antes de comenzar
- Asegúrate de que el producto de firewall de Palo Alto Networks esté implementado y configurado correctamente. Para obtener instrucciones de configuración detalladas, consulta la documentación de PAN-OS.
Para comprender los componentes implementados para recopilar los registros del firewall de Palo Alto Networks, revisa la arquitectura de implementación. Cada implementación para el cliente puede ser diferente de esta representación y más compleja. En el siguiente diagrama, se muestra cómo puedes configurar syslog en un firewall de Palo Alto Networks y, luego, instalar un agente de reenvío de SecOps de Google en un servidor Linux para reenviar los datos de registro a SecOps de Google. El analizador admite registros escritos en los siguientes formatos de datos: valores separados por comas (CSV), formato de evento común (CEF) y formato extendido de evento de registro (LEEF).
Verifica los formatos de registro y las versiones de PAN-OS que admite el analizador de Google SecOps. En la siguiente tabla, se enumeran los formatos de registro y las versiones de PAN-OS correspondientes que admite el analizador de Google SecOps:
Formato de registro Versión de PAN-OS CSV 10.1.3 CEF 10.0.0 LEEF 9.1.0 Verifica los tipos de registros del firewall de Palo Alto Networks que admite el analizador de SecOps de Google. El analizador de SecOps de Google admite los siguientes tipos de registros de firewall de Palo Alto Networks:
- Tráfico
- Amenaza
- Envíos a WildFire
- Inspección de túneles
- Configuración
- Sistema
- Coincidencia de HIP
- IP-Tag
- User-ID
- Desencriptación
- Autenticación
- Filtros de URL
- Filtrado de datos
- GlobalProtect
- Correlación
- GTP
- SCTP
- Auditoría
Para obtener más información sobre los tipos de registros del firewall de Palo Alto Networks, consulta Tipos de registros de PAN-OS.
Asegúrate de que todos los sistemas de la arquitectura de implementación estén configurados en la zona horaria UTC.
Antes de usar el analizador de firewall de Palo Alto Networks, revisa los cambios en las asignaciones de campos entre el analizador anterior y el analizador de firewall de Palo Alto Networks actual. Como parte de la migración, asegúrate de que las reglas, las búsquedas, los paneles o cualquier otro proceso que dependa de los campos originales usen los campos actualizados.
Por ejemplo, en la versión anterior del analizador, el campo de registro
categoryse asigna al camposecurity_result.descriptiondel UDM. En el analizador de firewall actual de Palo Alto Networks, el campo de registrocategoryse asigna al camposecurity_result.category_detailsde UDM. Si migras al analizador de firewall actual de Palo Alto Networks y usas el campocategoryen tus reglas, debes modificarlas para que usen el camposecurity_result.category_detailsdel UDM del analizador actual.
Configura syslog y el reenvío de Google Security Operations
Para configurar syslog y el retransmisor de Google SecOps, completa los siguientes pasos:
- Para supervisar los registros CSV, configura el perfil del servidor Syslog. Para obtener más información, consulta Cómo configurar el perfil del servidor syslog. Cuando configures el perfil del servidor syslog, especifica "Predeterminado" como el formato de registro personalizado.
- Para supervisar los registros de CEF, configura el firewall de Palo Alto Networks para que reenvíe los registros de CEF. Para obtener más información, descarga la guía de integración de CEF de PAN-OS en formato PDF y consulta la sección "Configuración del NGFW de Palo Alto Networks para generar eventos de CEF".
- Para supervisar los registros de LEEF, configura el perfil del servidor syslog. Para obtener más información, consulta Reenvío de registros personalizados en formato LEEF.
Configura el reenvío de Google SecOps para enviar registros a Google Security Operations. Para obtener más información, consulta Cómo instalar y configurar el reenvío en Linux. A continuación, se muestra un ejemplo de configuración de un retransmisor de Google SecOps:
- syslog: common: enabled: true data_type: PAN_FIREWALL batch_n_seconds: 10 batch_n_bytes: 1048576 tcp_address: 0.0.0.0:10518 connection_timeout_sec: 60
Configura el reenvío de syslog en el firewall de PAN
Crea un perfil de servidor syslog
- Accede a la consola de administración del firewall de Palo Alto Networks.
- Ve a Device > Server Profiles > Syslog.
- Haz clic en Agregar para crear un perfil de servidor nuevo.
- Proporciona los siguientes detalles de configuración:
- Nombre: Ingresa un nombre descriptivo (por ejemplo,
Google SecOps BindPlane). - Ubicación: Selecciona el sistema virtual (vsys) o Compartido en el que estará disponible este perfil.
- Nombre: Ingresa un nombre descriptivo (por ejemplo,
- Haz clic en Servidores > Agregar para configurar el servidor syslog.
- Proporciona los siguientes detalles de configuración del servidor:
- Nombre: Ingresa un nombre descriptivo para el servidor (por ejemplo,
BindPlane Agent). - Servidor Syslog: Ingresa la dirección IP del agente de BindPlane.
- Transporte: Selecciona UDP o TCP, según la configuración de tu agente de BindPlane (UDP es el valor predeterminado).
- Puerto: Ingresa el número de puerto del agente de BindPlane (por ejemplo,
514). - Formato: Selecciona BSD (predeterminado) o IETF, según tus requisitos.
- Facility: Selecciona LOG_USER (predeterminado) o cualquier otra instalación según sea necesario.
- Nombre: Ingresa un nombre descriptivo para el servidor (por ejemplo,
- Haz clic en Aceptar para guardar el perfil del servidor syslog.
Opcional: Configura un formato de registro personalizado para CEF o LEEF
Si necesitas registros en formato de evento común (CEF) o en formato extendido de evento de registro (LEEF) en lugar de CSV, haz lo siguiente:
- En el perfil del servidor Syslog, selecciona la pestaña Formato de registro personalizado.
- Configura el formato de registro personalizado para cada tipo de registro (Config, System, Threat, Traffic, URL, Data, WildFire, Tunnel, Authentication, User-ID, HIP Match).
- Para obtener información sobre la configuración del formato CEF, consulta la Guía de configuración de CEF de Palo Alto Networks.
- Haz clic en Aceptar para guardar la configuración.
Crea un perfil de reenvío de registros
- Ve a Objetos > Reenvío de registros.
- Haz clic en Agregar para crear un perfil nuevo de reenvío de registros.
- Proporciona los siguientes detalles de configuración:
- Nombre: Ingresa un nombre de perfil (por ejemplo,
Google SecOps Forwarding). Si quieres que el firewall asigne automáticamente este perfil a las nuevas reglas y zonas de seguridad, asígnale el nombredefault.
- Nombre: Ingresa un nombre de perfil (por ejemplo,
- Para cada tipo de registro que desees reenviar (Tráfico, Amenaza, Envío a WildFire, Filtrado de URL, Filtrado de datos, Túnel, Autenticación), configura lo siguiente:
- Haz clic en Agregar en la sección del tipo de registro correspondiente.
- Syslog: Selecciona el perfil del servidor syslog que creaste (por ejemplo,
Google SecOps BindPlane). - Gravedad del registro: Selecciona los niveles de gravedad que se reenviarán (por ejemplo, Todos).
- Haz clic en Aceptar para guardar el perfil de reenvío de registros.
Aplica el perfil de reenvío de registros a las políticas de seguridad
- Ve a Políticas > Seguridad.
- Selecciona las reglas de seguridad para las que deseas habilitar el reenvío de registros.
- Haz clic en la regla para editarla.
- Ve a la pestaña Acciones.
- En el menú Log Forwarding, selecciona el perfil de reenvío de registros que creaste (por ejemplo,
Google SecOps Forwarding). - Haz clic en Aceptar para guardar la configuración de la política de seguridad.
Configura los parámetros de registro para los registros del sistema
- Ve a Device > Log Settings.
- Para cada tipo de registro (System, Configuration, User-ID, HIP Match, Global Protect, IP-Tag, SCTP) y nivel de gravedad, selecciona el perfil del servidor syslog que creaste.
- Haz clic en Aceptar para guardar la configuración del registro.
Confirma los cambios
- Haz clic en Commit en la parte superior de la interfaz web del firewall.
- Espera a que la confirmación se complete correctamente.
- Verifica que los registros se envíen al agente de Bindplane. Para ello, consulta la consola de Google SecOps en busca de registros entrantes del firewall de Palo Alto Networks.
Reenvía registros a Google SecOps con el agente de BindPlane
- Instala y configura una máquina virtual de Linux.
- Instala y configura el agente de BindPlane en Linux para reenviar registros a Google SecOps. Para obtener más información sobre cómo instalar y configurar el agente de Bindplane, consulta las instrucciones de instalación y configuración del agente de Bindplane.
Si tienes problemas para crear feeds, comunícate con el equipo de asistencia de Google SecOps.
Formatos de registro admitidos
El analizador de firewall de Palo Alto Networks admite registros en formato LEEF,CEF y CSV.
Registros de muestra admitidos
LEEF
<14>Jan 22 02:20:19 device_host LEEF:1.0|Palo Alto Networks|PAN-OS Syslog Integration|10.2.12-h4|Microsoft MSOFFICE(52033)|ReceiveTime=2025/01/22 02:20:18|SerialNumber=01250100xxxx|cat=THREAT|Subtype=wildfire|devTime=Jan 22 2025 08:20:18 GMT|src=198.50.100.1|dst=198.50.100.2|srcPostNAT=198.50.100.3|dstPostNAT=198.50.100.4|RuleName=AZURE-US-NEW-CNF_Inbound_To_Azure-ALLOW|usrName=|SourceUser=|DestinationUser=|Application=smtp-base|VirtualSystem=vsys1|SourceZone=McD-Global-Zone|DestinationZone=Azure-Zone|IngressInterface=ae1.111|EgressInterface=ae2.409|LogForwardingProfile=Default-Traffic-Logging|SessionID=35331795|RepeatCount=1|srcPort=21578|dstPort=25|srcPostNATPort=0|dstPostNATPort=0|Flags=0x2000|proto=tcp|action=allow|Miscellaneous=\"......3...................xls\"|ThreatID=Microsoft MSOFFICE(52033)|URLCategory=malicious|sev=4|Severity=high|Direction=client-to-server|sequence=7462614601465681755|ActionFlags=0x8000000000000000|SourceLocation=198.50.100.1-198.50.100.255|DestinationLocation=United States|ContentType=|PCAP_ID=0|FileDigest=0ea04c99bf188c2e4207f60f92ca7c6f5088c7943ee63f45c50032bbd2bf7ea9|Cloud=demo.com|URLIndex=1|RequestMethod=|FileType=ms-office|Sender=sender@ab.myownpersonaldomain.com|Subject=\"............:.................................................................................-.........(Name)-2025-01-22...............:Y107202501220005, ............:........................, ...............:.........\"|Recipient=abc@demo.myownpersonaldomain.com|ReportID=117022282776|DeviceGroupHierarchyL1=143|DeviceGroupHierarchyL2=144|DeviceGroupHierarchyL3=39|DeviceGroupHierarchyL4=0|vSrcName=|DeviceName=device_host|SrcUUID=|DstUUID=|TunnelID=0|MonitorTag=|ParentSessionID=0|ParentStartTime=|TunnelType=N/A|ThreatCategory=N/A|ContentVer=WildFire-0CEF
14>1 2024-04-04T16:21:56+02:00 FW-PERIMETRAL-AVG-01 - - - - CEF:0|Palo Alto Networks|PAN-OS|10.1.10-h2|end|TRAFFIC|1|src=198.51.100.1 dst=198.51.100.2 srcTranslatedAddress=198.51.100.3 dstTranslatedAddress=198.51.100.4 rule=FW_USER_NATS2_APP suser= duser= app=bittorrent vs=vsys1 sz=INSIDE dz=EXTERNAL InboundInterface=ae2.2266 OutboundInterface=ae1 lp=log_forwarding sid=2935823 cnt=1 spt=6881 dpt=51413 srcTranslatedPort=0 dstTranslatedPort=0 flags=0x7a proto=udp act=allow tbytes=475 in=150 out=325 pkt=2 pktReceived=1 pktSent=1 start=Apr 04 2024 14:21:56 GMT stime=1206 urlcat=any externalId=externalId reason=aged-out DGl1=11 DGl2=161 DGl3=0 DGl4=0 VsysName=STONESOFT dvchost=FW-PERIMETRAL-AVG-01 cat=from-policy ActionFlags=0x8000000000000000 srcUUID= dstUUID= TunnelID=0 MonitorTag= ParentSessionID=0 ParentStartTime= TunnelType=N/A SCTPAssocID=0 SCTPChunks=0 SCTPChunkSent=0 SCTPChunksRcv=0 RuleUUID=746c3eb6-3d51-4679-8438-bd0e00e170a8 HTTP2Con=0 LinkChange=0 PolicyID= LinkDetail= SDWANCluster= SDWANDevice= SDWANClustype= SDWANSite= DynamicUsrgrp= XFFIP= srcDevCat= srcDevProf= srcDevModel= srcDevVendor= srcDevOS= srcDevOSv= srcHostname= srcMac= dstDevCat= dstDevProf= dstDevModel= dstDevVendor= dstDevOS= dstDevOSv= dstHostname= dstMac= ContainerName= PODNamespace= PODName= srcEDL= dstEDL= GPHostID= EPSerial= srcDAG= dstDAG= HASessionOwner= TimeHighRes=2024-04-04T16:21:56.250+02:00 ASServiceType= ASServiceDiff="CSV
1,2021/10/24 15:30:07,,CONFIG,0,2561,2021/10/24 15:30:07,198.51.100.0,,set,admin,Web,Succeeded, network virtual-router VR1,,VR1 { ecmp { algorithm { ip-modulo ; } } protocol { bgp { routing-options { graceful-restart { enable yes; } } enable no; } rip { enable no; } ospf { enable no; } ospfv3 { enable no; } } routing-table { ip { static-route { vr1-log { path-monitor { enable no; failure-condition any; hold-time 2; } nexthop { ip-address 198.51.100.0; } bfd { profile None; } interface ethernet1/1; metric 10; destination 0.0.0.0/0; route-table { unicast ; } } } } } interface [ ethernet1/1 ethernet1/2 ]; } ,7022390503849066572,0x0,0,0,0,0,,PA-VM,0,
Referencia de la asignación de campos: Campos de registros a campos del UDM
En esta sección, se explica cómo el analizador asigna los campos de registro del firewall de Palo Alto Networks a los campos de eventos del UDM de Google SecOps para cada tipo de registro. La clave de la etiqueta de Google SecOps hace referencia al nombre de la clave asignada al campo Labels.key del UDM.
Por ejemplo, en el caso del campo "Sistema virtual", el nombre del campo es "cs3" en formato CEF y "VirtualSystem" en formato LEEF. El campo del UDM "about.labels.key" contiene el valor "vsys", y el campo del UDM "about.labels.value" contiene el valor de ese campo. Algunos de los nombres de campos de CEF o LEEF no tienen un nombre correspondiente a los nombres de campos del CSV. En esos casos, si agregas tu propio nombre de variable en el formato de registro personalizado del perfil de syslog, el analizador no lo asignará al campo del UDM.
Consulta las siguientes secciones para obtener referencias de asignación de cada tipo de registro:
- Sistema
- Config
- Amenaza/incendio
- Tráfico
- ID de usuario
- HIP match
- Etiqueta de IP
- Desencriptación
- Túnel
- Authentication
- URL
- Datos
- GlobalProtect
- Correlación
- GTP
- SCTP
- Auditar
Sistema
En la siguiente tabla, se enumeran los campos de registro del tipo de registro del sistema y sus campos de UDM correspondientes.
| Campo CSV | Campo de CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si no está presente "Generate Time") |
|
| Número de serie (serie) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | cat | metadata.product_event_type se establece en "%{type} - %{subtype}". | |
| Tipo de amenaza o contenido (subtipo) | subtype (encabezado) | Subtipo | metadata.product_event_type se establece en "%{type} - %{subtype}". | |
| Hora de generación (time_generated o cef-formatted-time_generated) | metadata.event_timestamp | |||
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| ID del evento (eventid) | cat | eventid | additional.fields.key y additional.fields.value.string_value | |
| Objeto (objeto) | fname | Nombre del archivo | objeto | target.resource.name |
| Módulo (module) | flexString2 | Módulo | module | additional.fields.key y additional.fields.value.string_value |
| Gravedad (severity) | $number-of-severity(header) | Gravedad | security_result.severity y security_result.severity_details | |
| Descripción (opaca) | msg | msg | metadata.description | |
| principal_user_userid (este campo se extrae del campo msg) | principal.user.userid | |||
| principal_ip3 (este campo se extrae del campo msg) | principal.ip | |||
| Motivo (este campo se extrae del campo msg) | security_result.description | |||
| server_address (este campo se extrae del campo msg) | target.ip | |||
| server_profile (este campo se extrae del campo msg) | additional.fields.key y additional.fields.value.string_value | |||
| Número de secuencia (seqno) | externalId | secuencia | metadata.product_log_id | |
| Marcas de acción (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_1 a dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value |
| Nombre del sistema virtual (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nombre del dispositivo (device_name) | dvchost | DeviceName | target.hostname | |
| Marca de tiempo de alta resolución (high_res_timestamp) | anOSTimeGeneratedHighResolution | additional.fields.key y additional.fields.value.string_value |
Configuración
En la siguiente tabla, se enumeran los campos de registro del tipo de registro de configuración y sus campos de UDM correspondientes.
| Campo CSV | Campo de CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si no está presente "Generate Time") |
|
| Número de serie (serie) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | cat | metadata.product_event_type | |
| Tipo de amenaza o contenido (subtipo) | subtype (encabezado) | metadata.product_event_type | ||
| Hora de generación (time_generated o cef-formatted-time_generated) | metadata.event_timestamp | |||
| Host (host) | shost | src | principal.ip/hostname | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| Comando (cmd) | actúa | msg | cmd | principal.process.command_line |
| Administrador (admin) | duser | usrName | principal.user.userid | |
| Cliente (client) | destinationServiceName | cliente | principal.application | |
| Resultado (result) | ID de firma (encabezado)(motivo) | Resultado | security_result.summary | |
| Ruta de configuración (ruta) | msg | ConfigurationPath | principal.process.command_line | |
| Antes del cambio, detalle (before_change_detail) | cs1 | BeforeChangeDetail | before_change_detail | target.resource.attribute.labels.key/value |
| Detalle posterior al cambio (after_change_detail) | cs2 | AfterChangeDetail | after_change_detail | target.resource.attribute.labels.key/value |
| Número de secuencia (seqno) | externalId | secuencia | metadata.product_log_id | |
| Marcas de acción (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_1 a dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value |
| Nombre del sistema virtual (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nombre del dispositivo (device_name) | dvchost | DeviceName | target.hostname | |
| Grupo de dispositivos (dg_id) | PanOSFWDeviceGroup | target.asset.attribute.labels.key/value | dg_id | principal.asset.attribute.labels.key/value |
| Comentario de auditoría (comment) | PanOSPolicyAuditComment | comentario | additional.fields.key y additional.fields.value.string_value | |
| Marca de tiempo de alta resolución (high_res_timestamp) | additional.fields.key y additional.fields.value.string_value | |||
| Gravedad (severity) | number-of-severity(header) | security_result.severity y security_result.severity_details |
Amenaza/WildFire
En la siguiente tabla, se enumeran los campos de registro del tipo de registro Threat/WildFire y sus campos de UDM correspondientes.
| Campo CSV | Campo de CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si no está presente "Generate Time") |
|
| Número de serie | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | cat | metadata.product_event_type | |
| Tipo de amenaza o contenido (subtipo) | cat/subtype (encabezado) | Subtipo | metadata.product_event_type | |
| Fecha y hora de generación (time_generated o cef-formatted-time_generated) | metadata.event_timestamp | |||
| Dirección de origen (src) | src | src | principal.ip | |
| Dirección de destino (dst) | DST | DST | target.ip | |
| IP de origen de NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP de destino de NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Nombre de la regla (rule) | cs1 | RuleName | security_result.rule_name | |
| Usuario de origen (srcuser) | suser | SourceUser / usrName | principal.user.userid | |
| Usuario de destino (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplicación (app) | app | Aplicación | target.application | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona de origen (desde) | cs4 | SourceZone | de | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Zona de destino (a) | cs5 | DestinationZone | a | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
| Interfaz entrante (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Interfaz de salida (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
| Acción de registro (conjunto de registros) | cs6 | LogForwardingProfile | logset | additional.fields.key y additional.fields.value.string_value |
| ID de sesión (sessionid) | cn1 | SessionID | network.session_id | |
| Recuento de repeticiones (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key y additional.fields.value.string_value |
| Puerto de origen (sport) | spt | srcPort | principal.port | |
| Puerto de destino (dport) | dpt | dstPort | target.port | |
| Puerto de origen de NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Puerto de destino de NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Marcas (flags) | flexString1 | Marcas | flags | additional.fields.key y additional.fields.value.string_value |
| Protocolo de IP (proto) | protocolo | protocolo | network.ip_protocol | |
| Acción (action) | actúa | acción | security_result.action_details
security_result.action |
|
| URL o nombre de archivo (varios) | solicitud | Varios | target.file.names (si el subtipo es "file", "virus", "wildfire-virus" o "wildfire", el campo "misc" se asigna a target.file.names) target.url (si el subtipo es "url", el campo "misc" se asigna a target.url y target.hostname) |
|
| Nombre de la amenaza o el contenido (threatid) | cat | ThreatID | security_result.threat_name | |
| Categoría (category) | cs2 | URLCategory | security_result.category_details | |
| Gravedad (severity) | number-of-severity(header) | Gravedad | security_result.severity y security_result.severity_details | |
| Dirección (direction) | flexString2 | Dirección | network.direction | |
| Número de secuencia (seqno) | externalId | secuencia | metadata.product_log_id | |
| Marcas de acción (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value |
| País de origen (srcloc) | SourceLocation | principal.location.country_or_region | ||
| País de destino (dstloc) | DestinationLocation | target.location.country_or_region | ||
| Tipo de contenido (contenttype) | ContentType | contenttype | additional.fields.key y additional.fields.value.string_value | |
| ID de PCAP (pcap_id) | ID del archivo | PCAP_ID | pcap_id | additional.fields.key y additional.fields.value.string_value |
| Resumen del archivo (filedigest) | fileHash | FileDigest | target.file.sha1/md5/sha256 | |
| Nube (cloud) | filePath | Nube | nube | additional.fields.key y additional.fields.value.string_value |
| Índice de URL (url_idx) | URLIndex | url_idx | additional.fields.key y additional.fields.value.string_value | |
| Usuario-agente (user_agent) | network.http.user_agent | |||
| Tipo de archivo (filetype) | fileType | FileType | target.file.mime_type | |
| X-Forwarded-For (xff) | principal.ip | |||
| Referer (referer) | network.http.referral_url | |||
| Remitente (sender) | suid | Remitente | network.email.from | |
| Asunto (subject) | msg | Asunto | network.email.subject | |
| Destinatario (recipient) | duid | Destinatario | network.email.to | |
| ID del informe (reportid) | oldFileId | ReportID | reportid | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_1 a dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value |
| Nombre del sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nombre del dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| UUID de la VM de origen (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id | |
| UUID de la VM de destino (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id | |
| Método HTTP (http_method) | RequestMethod | network.http.method | ||
| ID/IMSI del túnel (tunnel_id/imsi) | PanOSTunnelID | TunnelID | tunnel_id/imsi | additional.fields.key y additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag/imei) | PanOSMonitorTag | MonitorTag | monitortag/imei | additional.fields.key y additional.fields.value.string_value |
| ID de sesión principal (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Hora de inicio de la sesión principal (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key y additional.fields.value.string_value |
| Tipo de túnel (tunnel) | PanOSTunnelType | TunnelType | túnel | additional.fields.key y additional.fields.value.string_value |
| Categoría de amenaza (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| Versión del contenido (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key y additional.fields.value.string_value |
| ID de asociación de SCTP (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key y additional.fields.value.string_value | |
| ID de protocolo de carga útil (ppid) | PanOSPPID | ppid | additional.fields.key y additional.fields.value.string_value | |
| Encabezados HTTP (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Lista de categorías de URL (url_category_list) | PanOSURLCatList | url_category_list | additional.fields.key y additional.fields.value.string_value | |
| UUID de la regla (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| Conexión HTTP/2 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| Nombre del grupo de usuarios dinámico (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Dirección XFF (xff_ip) | PanXFFIP | principal.ip | ||
| Categoría del dispositivo fuente (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Perfil del dispositivo fuente (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Modelo del dispositivo fuente (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Proveedor del dispositivo fuente (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Familia del SO del dispositivo fuente (src_osfamily) | PanSrcDeviceOS | src_osfamily | principal.platform | |
| Versión del SO del dispositivo de origen (src_osversion) | PanSrcDeviceOSv | principal.platform_version | ||
| Nombre de host de origen (src_host) | PanSrcHostname | principal.hostname | ||
| Dirección MAC de origen (src_mac) | PanSrcMac | principal.mac | ||
| Categoría del dispositivo de destino (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Perfil del dispositivo de destino (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Modelo de dispositivo de destino (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Proveedor del dispositivo de destino (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Familia del SO del dispositivo de destino (dst_osfamily) | PanDstDeviceOS | dst_osfamily | target.platform | |
| Versión del SO del dispositivo de destino (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Nombre de host de destino (dst_host) | PanDstHostname | target.hostname | ||
| Dirección MAC de destino (dst_mac) | PanDstMac | target.mac | ||
| ID del contenedor (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| Espacio de nombres del POD (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| Nombre del POD (pod_name) | PanPODName | pod_name | target.resource.name | |
| Lista dinámica externa de origen (src_edl) | PanSrcEDL | src_edl | additional.fields.key y additional.fields.value.string_value | |
| Lista dinámica externa de destino (dst_edl) | PanDstEDL | dst_edl | additional.fields.key y additional.fields.value.string_value | |
| ID del host (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Número de serie del dispositivo del usuario (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| EDL de dominio (domain_edl) | PanDomainEDL | domain_edl | additional.fields.key y additional.fields.value.string_value | |
| Grupo de direcciones dinámicas de origen (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Grupo de direcciones dinámicas de destino (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| Hash parcial (partial_hash) | PanPartialHash | partial_hash | additional.fields.key y additional.fields.value.string_value | |
| Marca de tiempo de alta resolución (high_res timestamp) | PanTimeHighRes | Marca de tiempo de alta resolución | additional.fields.key y additional.fields.value.string_value | |
| Motivo (reason) | PanReasonFilteringAction | Reason | security_result.summary | |
| Justificación (justification) | PanJustification | justificación | additional.fields.key y additional.fields.value.string_value | |
| Un tipo de servicio de segmentación (nssai_sst) | PanASServiceType | nssai_sst | additional.fields.key y additional.fields.value.string_value | |
| Subcategoría de la aplicación (subcategory_of_app) | subcategory_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Categoría de la aplicación (category_of_app) | category_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Tecnología de la aplicación (technology_of_app) | technology_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Riesgo de la aplicación (risk_of_app) | risk_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Característica de la aplicación (characteristic_of_app) | characteristic_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Contenedor de la aplicación (container_of_app) | container_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Aplicación SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Aplicación con túnel (tunneled_app) | additional.fields.key y additional.fields.value.string_value | |||
| Tipo de flujo (flow_type) | additional.fields.key y additional.fields.value.string_value | |||
| Nombre del clúster (cluster_name) | intermediary.resource.name | |||
| Estado de aprobación de la aplicación (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key y additional.fields.value.string_value |
Tráfico
En la siguiente tabla, se enumeran los campos de registro del tipo de registro de tráfico y sus campos de UDM correspondientes.
| Campo CSV | Campo de CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si no está presente "Generate Time") |
|
| Número de serie (serie) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | cat/Type | metadata.product_event_type | |
| Tipo de amenaza o contenido (subtipo) | subtype (encabezado) | Subtipo | metadata.product_event_type | |
| Hora de generación (time_generated o cef-formatted-time_generated) | start | metadata.event_timestamp | ||
| Dirección de origen (src) | src | src | principal.ip | |
| Dirección de destino (dst) | DST | DST | target.ip | |
| IP de origen de NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP de destino de NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Nombre de la regla (rule) | cs1 | RuleName | security_result.rule_name | |
| Usuario de origen (srcuser) | suser | SourceUser | principal.user.userid | |
| Usuario de destino (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplicación (app) | app | Aplicación | target.application | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona de origen (desde) | cs4 | SourceZone | de | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Zona de destino (a) | cs5 | DestinationZone | a | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
| Interfaz entrante (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Interfaz de salida (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
| Acción de registro (conjunto de registros) | cs6 | LogForwardingProfile | logset | additional.fields.key y additional.fields.value.string_value |
| ID de sesión (sessionid) | cn1 | SessionID | network.session_id | |
| Recuento de repeticiones (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key y additional.fields.value.string_value |
| Puerto de origen (sport) | spt | srcPort | principal.port | |
| Puerto de destino (dport) | dpt | dstPort | target.port | |
| Puerto de origen de NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Puerto de destino de NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Marcas (flags) | flexString1 | Marcas | flags | additional.fields.key y additional.fields.value.string_value |
| Protocolo de IP (proto) | protocolo | protocolo | network.ip_protocol | |
| Acción (action) | actúa | acción | security_result.action_details
security_result.action |
|
| Bytes (bytes) | flexNumber1 | totalBytes | bytes | additional.fields.key y additional.fields.value.string_value |
| Bytes enviados (bytes_sent) | en | srcBytes | network.sent_bytes | |
| Bytes recibidos (bytes_received) | descifrar? | dstBytes | network.received_bytes | |
| Paquetes (packets) | cn2 | totalPackets | paquetes | additional.fields.key y additional.fields.value.string_value |
| Hora de inicio (start) | StartTime | start | additional.fields.key y additional.fields.value.string_value | |
| Tiempo transcurrido (elapsed) | cn3 | ElapsedTime | Transcurrido | network.session_duration.seconds |
| Categoría (category) | cs2 | URLCategory | security_result.category / security_result.category_details | |
| Número de secuencia (seqno) | externalId | secuencia | metadata.product_log_id | |
| Marcas de acción (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value |
| País de origen (srcloc) | SourceLocation | principal.location.country_or_region | ||
| País de destino (dstloc) | DestinationLocation | target.location.country_or_region | ||
| Paquetes enviados (pkts_sent) | PanOSPacketsSent | srcPackets | pkts_sent | network.sent_packets |
| Paquetes recibidos (pkts_received) | PanOSPacketsReceived | dstPackets | pkts_received | network.received_packets |
| Motivo de finalización de la sesión (session_end_reason) | Reason | SessionEndReason | security_result.summary | |
| Jerarquía del grupo de dispositivos 1 (dg_hier_level_1 a dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos2 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos 3 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value |
| Nombre del sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nombre del dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| Fuente de la acción (action_source) | cat | ActionSource | action_source | additional.fields.key y additional.fields.value.string_value |
| UUID de la VM de origen (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id | |
| UUID de la VM de destino (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id | |
| ID de túnel/IMSI (tunnelid/imsi) | PanOSTunnelID | TunnelID | tunnelid/imsi | additional.fields.key y additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag/imei) | PanOSMonitorTag | MonitorTag | monitortag/imei | additional.fields.key y additional.fields.value.string_value |
| ID de sesión principal (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Hora de inicio principal (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key y additional.fields.value.string_value |
| Tipo de túnel (tunnel) | PanOSTunnelType | TunnelType | túnel | additional.fields.key y additional.fields.value.string_value |
| ID de asociación de SCTP (assoc_id) | PanOSSCTPAssocID | assoc_id | additional.fields.key y additional.fields.value.string_value | |
| Fragmentos de SCTP (chunks) | PanOSSCTPChunks | fragmentos | additional.fields.key y additional.fields.value.string_value | |
| Fragmentos SCTP enviados (chunks_sent) | PanOSSCTPChunkSent | chunks_sent | additional.fields.key y additional.fields.value.string_value | |
| Fragmentos SCTP recibidos (chunks_received) | PanOSSCTPChunksRcv | chunks_received | additional.fields.key y additional.fields.value.string_value | |
| UUID de la regla (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| Conexión HTTP/2 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| Recuento de cambios de vínculo (link_change_count) | PanLinkChange | link_change_count | additional.fields.key y additional.fields.value.string_value | |
| ID de la política (policy_id) | PanPolicyID | policy_id | additional.fields.key y additional.fields.value.string_value | |
| Interruptores de vínculos (link_switches) | PanLinkDetail | link_switches | additional.fields.key y additional.fields.value.string_value | |
| Clúster de SD-WAN (sdwan_cluster) | PanSDWANCluster | sdwan_cluster | additional.fields.key y additional.fields.value.string_value | |
| Tipo de dispositivo SD-WAN (sdwan_device_type) | PanSDWANDevice | sdwan_device_type | additional.fields.key y additional.fields.value.string_value | |
| Tipo de clúster de SD-WAN (sdwan_cluster_type) | PanSDWANClustype | sdwan_cluster_type | additional.fields.key y additional.fields.value.string_value | |
| Sitio de SD-WAN (sdwan_site) | PanSDWANSite | sdwan_site | additional.fields.key y additional.fields.value.string_value | |
| Nombre del grupo de usuarios dinámico (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | additional.fields.key y additional.fields.value.string_value | |
| Dirección XFF (xff_ip) | PanXFFIP | principal.ip | ||
| Categoría del dispositivo fuente (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Perfil del dispositivo fuente (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Modelo del dispositivo fuente (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Proveedor del dispositivo fuente (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Familia del SO del dispositivo fuente (src_osfamily) | PanSrcDeviceOS | principal.platform | ||
| Versión del SO del dispositivo de origen (src_osversion) | PanSrcDeviceOSv | principal.asset.software.version | ||
| Nombre de host de origen (src_host) | PanSrcHostname | principal.hostname | ||
| Dirección MAC de origen (src_mac) | PanSrcMac | principal.mac | ||
| Categoría del dispositivo de destino (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Perfil del dispositivo de destino (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Modelo de dispositivo de destino (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Proveedor del dispositivo de destino (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Familia del SO del dispositivo de destino (dst_osfamily) | PanDstDeviceOS | dst_osfamily | target.platform | |
| Versión del SO del dispositivo de destino (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Nombre de host de destino (dst_host) | PanDstHostname | target.hostname | ||
| Dirección MAC de destino (dst_mac) | PanDstMac | target.mac | ||
| ID del contenedor (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| Espacio de nombres del POD (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| Nombre del POD (pod_name) | PanPODName | pod_name | target.resource.name | |
| Lista dinámica externa de origen (src_edl) | PanSrcEDL | src_edl | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Lista dinámica externa de destino (dst_edl) | PanDstEDL | dst_edl | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
|
| ID del host (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Número de serie del dispositivo del usuario (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| Grupo de direcciones dinámicas de origen (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Grupo de direcciones dinámicas de destino (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| Propietario de la sesión (session_owner) | PanHASessionOwner | session_owner | additional.fields.key y additional.fields.value.string_value | |
| Marca de tiempo de alta resolución (high_res_timestamp) | PanTimeHighRes | additional.fields.key y additional.fields.value.string_value | ||
| Un tipo de servicio de Slice (nsdsai_sst) | PanASServiceType | nsdsai_sst | additional.fields.key y additional.fields.value.string_value | |
| Un diferenciador de Slice (nsdsai_sd) | PanASServiceDiff | nsdsai_sd | additional.fields.key y additional.fields.value.string_value | |
| Subcategoría de la aplicación (subcategory_of_app) | subcategory_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Categoría de la aplicación (category_of_app) | category_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Tecnología de la aplicación (technology_of_app) | technology_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Riesgo de la aplicación (risk_of_app) | security_result.severity | |||
| Característica de la aplicación (characteristic_of_app) | characteristic_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Contenedor de la aplicación (container_of_app) | container_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Aplicación SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Estado de aprobación de la aplicación (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Subcategoría de la aplicación (subcategory_of_app) | subcategory_of_app1 | additional.fields.key y additional.fields.value.string_value | ||
| Gravedad (severity) | number-of-severity(header) | security_result.severity y security_result.severity_details |
User-ID
En la siguiente tabla, se enumeran los campos de registro del tipo de registro user-id y sus campos de UDM correspondientes.
| Campo CSV | Campo de CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si no está presente "Generate Time") |
|
| Número de serie (serie) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | cat | metadata.product_event_type | |
| Tipo de amenaza o contenido (subtipo) | subtype (encabezado) | Subtipo | metadata.product_event_type | |
| Hora de generación (time_generated o cef-formatted-time_generated) | metadata.event_timestamp | |||
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| IP de origen (ip) | src | src | principal.ip | |
| Usuario (user) | duser | usrName | target.user.userid
target.administrative_domain target.user.email_addresses |
|
| Nombre de la fuente de datos (datasourcename) | cs4 | DataSourceName | datasourcename | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| ID del evento (eventid) | EventID | eventid | additional.fields.key y additional.fields.value.string_value | |
| Recuento de repeticiones (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key y additional.fields.value.string_value |
| Umbral de tiempo de espera (timeout) | cn3 | TimeoutThreshold | timeout | additional.fields.key y additional.fields.value.string_value |
| Puerto de origen (beginport) | spt | srcPort | principal.port | |
| Puerto de destino (endport) | dpt | dstPort | target.port | |
| Fuente de datos | cs5 | DataSource | fuente de datos | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Tipo de fuente de datos (datasourcetype) | cs6 | DataSourceType | datasourcetype | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Número de secuencia (seqno) | externalId | secuencia | metadata.product_log_id | |
| Marcas de acción (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value |
| Nombre del sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nombre del dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| ID de sistema virtual (vsys_id) | cn2 | VirtualSystemID | intermediary.resource.product_object_id | |
| Tipo de factor (factortype) | cs1 | FactorType | factortype | additional.fields.key y additional.fields.value.string_value |
| Hora de finalización del factor (factorcompletiontime) | end | FactorCompletionTime | factorcompletiontime | additional.fields.key y additional.fields.value.string_value |
| Número de factor (factorno) | cn1 | FactorNumber | factorno | additional.fields.key y additional.fields.value.string_value |
| Marcas de grupos de usuarios (ugflags) | PanOSUGFlags | ugflags | additional.fields.key y additional.fields.value.string_value | |
| Usuario por fuente (userbysource) | PanOSUserBySource | target.user.userid
target.administrative_domain target.user.email_addresses |
||
| Marca de tiempo de alta resolución (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key y additional.fields.value.string_value | ||
| Fuente de datos de origen (origindatasource) | additional.fields.key y additional.fields.value.string_value | |||
| Nombre del clúster (cluster_name) | principal.resource.name | |||
| Gravedad (severity) | number-of-severity(header) | security_result.severity y security_result.severity_details |
Coincidencia de HIP
En la siguiente tabla, se enumeran los campos de registro del tipo de registro de coincidencia de HIP y sus campos de UDM correspondientes.
| Campo CSV | Campo de CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si no está presente "Generate Time") |
|
| Número de serie (serie) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | cat | metadata.product_event_type | |
| Tipo de amenaza o contenido (subtipo) | subtype (encabezado) | Subtipo | ||
| Hora de generación (time_generated o cef-formatted-time_generated) | start | startTime | metadata.event_timestamp | |
| Usuario de origen (srcuser) | suser | usrName | principal.user.userid | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| Nombre de la máquina (machinename) | shost | identHostName | principal.hostname | |
| Sistema operativo (os) | cs2 | SO | principal.asset.platform_software.platform | |
| Dirección de origen (src) | src | identsrc | principal.ip | |
| HIP (matchname) | cat | HIP | matchname | target.resource.attribute.labels.key/value additional.fields.key y additional.fields.value.string_value |
| Recuento de repeticiones (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key y additional.fields.value.string_value |
| Tipo de HIP (matchtype) | ID de clase de evento del dispositivo (encabezado) | HIPType | matchtype | target.resource.attribute.labels.key/value additional.fields.key y additional.fields.value.string_value |
| Número de secuencia (seqno) | externalId | secuencia | metadata.product_log_id | |
| Marcas de acción (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value |
| Nombre del sistema virtual (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nombre del dispositivo (device_name) | dvchost | DeviceName | target.hostname | |
| ID de sistema virtual (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id | |
| Dirección del sistema IPv6 (srcipv6) | c6a2 | srcipv6 | principal.asset.ip | |
| ID del host (hostid) | PanOSHostID | principal.asset.asset_id | ||
| Número de serie del dispositivo del usuario (serialnumber) | PanOSEndpointSerialNumber | principal.asset.hardware.serial_number | ||
| Dirección MAC del dispositivo (mac) | PanOSEndpointMac | principal.asset.mac | ||
| Marca de tiempo de alta resolución (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key y additional.fields.value.string_value | ||
| Nombre del clúster (cluster_name) | principal.resource.name | |||
| Gravedad (severity) | number-of-severity(header) | security_result.severity y security_result.severity_details |
Etiqueta de IP
En la siguiente tabla, se enumeran los campos de registro del tipo de registro de etiquetas de IP y sus campos de UDM correspondientes.
| Campo CSV | Campo de CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si no está presente "Generate Time") |
|
| Número de serie (serie) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | cat | metadata.product_event_type | |
| Tipo de amenaza o contenido (subtipo) | subtype (encabezado) | Subtipo | metadata.product_event_type | |
| Hora de generación (time_generated o cef-formatted-time_generated) | GenerateTime | metadata.event_timestamp | ||
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| IP de origen (ip) | src | src | principal.ip | |
| Nombre de la etiqueta (tag_name) | PanOSTagName | TagName | tag_name | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| ID del evento (event_id) | PanOSEventID | EventID | event_id | additional.fields.key y additional.fields.value.string_value |
| Recuento de repeticiones (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key y additional.fields.value.string_value |
| Tiempo de espera (timeout) | PanOSTimeout | TimeoutThreshold | timeout | additional.fields.key y additional.fields.value.string_value |
| Nombre de la fuente de datos (datasourcename) | PanOSDataSourceName | DataSourceName | datasourcename | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Tipo de fuente de datos (datasource_type) | PanOSDataSourceType | DataSource | datasource_type | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Subtipo de fuente de datos (datasource_subtype) | PanOSDataSourceSubType | DataSourceType | datasource_subtype | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Número de secuencia (seqno) | externalId | secuencia | metadata.product_log_id | |
| Marcas de acción (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value |
| Nombre del sistema virtual (vsys_name) | PanOsVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nombre del dispositivo (device_name) | dvchost | DeviceName | target.hostname | |
| ID de sistema virtual (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id | |
| Marca de tiempo de alta resolución (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key y additional.fields.value.string_value | ||
| Gravedad (severity) | number-of-severity(header) | security_result.severity y security_result.severity_details | ||
| Nombre del clúster (cluster_name) | principal.resource.name |
Desencriptación
En la siguiente tabla, se enumeran los campos de registro del tipo de registro de desencriptación y sus campos de UDM correspondientes.
| Campo CSV | Campo de CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | rt | metadata.collected_timestamp,
metadata.event_timestamp (si no está presente "Generate Time") |
||
| Número de serie (serie) | PanOSDeviceSN | intermediary.asset.hardware.serial_number | ||
| Tipo (type) | type (Header) | metadata.product_event_type | ||
| Tipo de amenaza o contenido (subtipo) | subtype (encabezado) | metadata.product_event_type | ||
| Versión de configuración (config_ver) | PanOSConfigVersion | config_ver | additional.fields.key y additional.fields.value.string_value | |
| Fecha y hora de generación (time_generated) | PanOSLogTimeStamp | metadata.event_timestamp | ||
| Dirección de origen (src) | src | principal.ip | ||
| Dirección de destino (dst) | DST | target.ip | ||
| IP de origen de NAT (natsrc) | sourceTranslatedAddress | principa.nat_ip | ||
| IP de destino de NAT (natdst) | destinationTranslatedAddress | target.nat_ip | ||
| Regla (rule) | cs1 | security_result.rule_name | ||
| Usuario de origen (srcuser) | suser | principal.user.userid | ||
| Usuario de destino (dstuser) | duser | target.user.userid | ||
| Aplicación (app) | app | network.application_protocol | ||
| Sistema virtual (vsys) | cs3 | vsys | intermediary.asset.attribute.labels.key/value | |
| Zona de origen (desde) | cs4 | de | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Zona de destino (a) | cs5 | a | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Interfaz entrante (inbound_if) | deviceInboundInterface | inbound_if | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Interfaz de salida (outbound_if) | deviceOutboundInterface | outbound_if | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Acción de registro (conjunto de registros) | cs6 | logset | additional.fields.key y additional.fields.value.string_value | |
| Hora de registro (time_received) | PanOSTimeReceivedManagementPlane | - | ||
| ID de sesión (sessionid) | cn1 | network.session_id | ||
| Recuento de repeticiones (repeatcnt) | PanOSCountOfRepeats/RepeatCount | repeatcnt | additional.fields.key y additional.fields.value.string_value | |
| Puerto de origen (sport) | spt | principal.port | ||
| Puerto de destino (dport) | dpt | target.port | ||
| Puerto de origen de NAT (natsport) | sourceTranslatedPort | principal.nat_port | ||
| Puerto de destino de NAT (natdport) | destinationTranslatedPort | target.nat_port | ||
| Marcas (flags) | flexString1 | flags | additional.fields.key y additional.fields.value.string_value | |
| Protocolo de IP (proto) | protocolo | network.ip_protocol | ||
| Acción (action) | actúa | security_result.action_details
security_result.action |
||
| Túnel (tunnel) | PanOSTunnel | túnel | additional.fields.key y additional.fields.value.string_value | |
| UUID de la VM de origen (src_uuid) | PanOSSourceUUID | principal.asset.product_object_id | ||
| UUID de la VM de destino (dst_uuid) | PanOSDestinationUUID | target.asset.product_object_id | ||
| UUID de la regla (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| Etapa de cliente a firewall (hs_stage_c2f) | PanOSClientToFirewall | hs_stage_c2f | additional.fields.key y additional.fields.value.string_value | |
| Etapa de Firewall a servidor (hs_stage_f2s) | PanOSFirewallToServer | hs_stage_f2s | additional.fields.key y additional.fields.value.string_value | |
| Versión de TLS (tls_version) | PanOSTLSVersion | network.tls.version | ||
| Algoritmo de intercambio de claves (tls_keyxchg) | PanOSTLSKeyExchange | tls_keyxchg | additional.fields.key y additional.fields.value.string_value | |
| Algoritmo de encriptación (tls_enc) | PanOSTLSEncryptionAlgorithm | tls_enc | additional.fields.key y additional.fields.value.string_value | |
| Algoritmo de hash (tls_auth) | PanOSTLSAuth | tls_auth | additional.fields.key y additional.fields.value.string_value | |
| Nombre de la política (policy_name) | PanOSPolicyName | policy_name | additional.fields.key y additional.fields.value.string_value | |
| Curva elíptica (ec_curve) | PanOSEllipticCurve | network.tls.curve | ||
| Índice de error (err_index) | PanOSErrorIndex | err_index | additional.fields.key y additional.fields.value.string_value | |
| Estado de raíz (root_status) | PanOSRootStatus | root_status | additional.fields.key y additional.fields.value.string_value | |
| Estado de la cadena (chain_status) | PanOSChainStatus | chain_status | additional.fields.key y additional.fields.value.string_value | |
| Tipo de proxy (proxy_type) | PanOSProxyType | proxy_type | additional.fields.key y additional.fields.value.string_value | |
| Número de serie del certificado (cert_serial) | PanOSCertificateSerial | network.tls.server.certificate.serial | ||
| Huella digital del certificado (huella digital) | PanOSFingerprint | network.tls.server.certificate.md5/sha1/sha256 | ||
| Fecha de inicio del certificado (notbefore) | PanOSTimeNotBefore | network.tls.server.certificate.not_before | ||
| Fecha de finalización del certificado (notafter) | PanOSTimeNotAfter | network.tls.server.certificate.not_after | ||
| Versión del certificado (cert_ver) | PanOSCertificateVersion | network.tls.server.certificate.version | ||
| Tamaño del certificado (cert_size) | PanOSCertificateSize | cert_size | additional.fields.key y additional.fields.value.string_value | |
| Longitud del nombre común (cn_len) | PanOSCommonNameLength | cn_len | additional.fields.key y additional.fields.value.string_value | |
| Longitud del nombre común de la entidad emisora (issuer_len) | PanOSIssuerNameLength | issuer_len | additional.fields.key y additional.fields.value.string_value | |
| Longitud del nombre común de la raíz (rootcn_len) | PanOSRootCNLength | rootcn_len | additional.fields.key y additional.fields.value.string_value | |
| Longitud del SNI (sni_len) | PanOSSNILength | sni_len | additional.fields.key y additional.fields.value.string_value | |
| Marcas de certificado (cert_flags) | PanOSCertificateFlags | cert_flags | additional.fields.key y additional.fields.value.string_value | |
| Nombre común del asunto (cn) | PanOSCommonName | cn | additional.fields.key y additional.fields.value.string_value | |
| Nombre común de la entidad emisora (issuer_cn) | PanOSIssuerCommonName | network.tls.server.certificate.issuer | ||
| Nombre común de la raíz (root_cn) | PanOSRootCommonName | root_cn | additional.fields.key y additional.fields.value.string_value | |
| Indicación del nombre del servidor
(sni) |
network.tls.client.server_name | |||
| Error (error) | PanOSErrorMessage | error | additional.fields.key y additional.fields.value.string_value | |
| ID del contenedor (container_id) | PanOSContainerID | container_id | intermediary.resource.product_object_id | |
| Espacio de nombres del POD (pod_namespace) | PanOSContainerNameSpace | pod_namespace | target.resource.attribute.labels.key/value additional.fields.key y additional.fields.value.string_value |
|
| Nombre del POD (pod_name) | PanOSContainerName | pod_name | target.resource.name | |
| Lista dinámica externa de origen (src_edl) | PanOSSourceEDL | src_edl | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Lista dinámica externa de destino (dst_edl) | PanOSDestinationEDL | dst_edl | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Grupo de direcciones dinámicas de origen (src_dag) | PanOSSourceDynamicAddressGroup | principal.group.group_display_name | ||
| Grupo de direcciones dinámicas de destino (dst_dag) | PanOSDestinationDynamicAddressGroup | target.group.group_display_name | ||
| Marca de tiempo de alta resolución (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key y additional.fields.value.string_value | ||
| Categoría del dispositivo fuente (src_category) | PanOSSourceDeviceCategory | src_category | principal.asset.category | |
| Perfil del dispositivo fuente (src_profile) | PanOSSourceDeviceProfile | src_profile | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Modelo del dispositivo fuente (src_model) | PanOSSourceDeviceModel | src_model | principal.asset.hardware.model | |
| Proveedor del dispositivo fuente (src_vendor) | PanOSSourceDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Familia del SO del dispositivo fuente (src_osfamily) | PanOSSourceDeviceOSFamily | principal.platform | ||
| Versión del SO del dispositivo de origen (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | ||
| Nombre de host de origen (src_host) | PanOSSourceDeviceHost | principal.hostname | ||
| Dirección MAC de origen (src_mac) | PanOSSourceDeviceMac | principal.mac | ||
| Categoría del dispositivo de destino (dst_category) | PanOSDestinationDeviceCategory | dst_category | target.asset.category | |
| Perfil del dispositivo de destino (dst_profile) | PanOSDestinationDeviceProfile | dst_profile | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Modelo de dispositivo de destino (dst_model) | PanOSDestinationDeviceModel | dst_model | target.asset.hardware.model | |
| Proveedor del dispositivo de destino (dst_vendor) | PanOSDestinationDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Familia del SO del dispositivo de destino (dst_osfamily) | PanOSDestinationDeviceOSFamily | dst_osfamily | target.platform | |
| Versión del SO del dispositivo de destino (dst_osversion) | PanOSDestinationDeviceOSVersion | target.platform_version | ||
| Nombre de host de destino (dst_host) | PanOSDestinationDeviceHost | target.hostname | ||
| Dirección MAC de destino (dst_mac) | PanOSDestinationDeviceMac | target.mac | ||
| Número de secuencia (seqno) | PanOSLogTypeSeqNo | metadata.product_log_id | ||
| Marcas de acción (actionflags) | PanOSActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value | |
| Jerarquía del grupo de dispositivos (dg_hier_level_1) | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value | |
| Jerarquía del grupo de dispositivos (dg_hier_level_2) | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value | |
| Jerarquía del grupo de dispositivos (dg_hier_level_3) | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value | |
| Jerarquía del grupo de dispositivos (dg_hier_level_4) | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value | |
| Nombre del sistema virtual (vsys_name) | intermediary.asset.attribute.labels.key/value | |||
| Nombre del dispositivo (device_name) | intermediary.hostname | |||
| ID de sistema virtual (vsys_id) | intermediary.resource.product_object_id | |||
| Subcategoría de la aplicación (subcategory_of_app) | subcategory_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Categoría de la aplicación (category_of_app) | category_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Tecnología de la aplicación (technology_of_app) | technology_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Riesgo de la aplicación (risk_of_app) | security_result.severity | |||
| Característica de la aplicación (characteristic_of_app) | characteristic_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Contenedor de la aplicación (container_of_app) | container_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Aplicación SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Estado de aprobación de la aplicación (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Gravedad (severity) | number-of-severity(header) | security_result.severity y security_result.severity_details |
Túnel
En la siguiente tabla, se enumeran los campos de registro del tipo de registro de túnel y sus campos de UDM correspondientes.
| Campo CSV | Campo de CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si no está presente "Generate Time") |
|
| Número de serie (serie) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | cat | metadata.product_event_type | |
| Tipo de amenaza o contenido (subtipo) | subtype (encabezado) | Subtipo | metadata.product_event_type | |
| Hora de generación (time_generated o cef-formatted-time_generated) | metadata.event_timestamp | |||
| Dirección de origen (src) | src | src | principal.ip | |
| Dirección de destino (dst) | DST | DST | target.ip | |
| IP de origen de NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP de destino de NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Nombre de la regla (rule) | cs1 | RuleName | security_result.rule_name | |
| Usuario de origen (srcuser) | suser | SourceUser / usrName | principal.user.userid | |
| Usuario de destino (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplicación (app) | app | Aplicación | network.application_protocol | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona de origen (desde) | cs4 | SourceZone | de | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Zona de destino (a) | cs5 | DestinationZone | a | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
| Interfaz entrante (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Interfaz de salida (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
| Acción de registro (conjunto de registros) | cs6 | LogForwardingProfile | logset | additional.fields.key y additional.fields.value.string_value |
| ID de sesión (sessionid) | cn1 | SessionID | network.session_id | |
| Recuento de repeticiones (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key y additional.fields.value.string_value |
| Puerto de origen (sport) | spt | srcPort | principal.port | |
| Puerto de destino (dport) | dpt | dstPort | target.port | |
| Puerto de origen de NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Puerto de destino de NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Marcas (flags) | flexString1 | Marcas | flags | additional.fields.key y additional.fields.value.string_value |
| Protocolo de IP (proto) | protocolo | protocolo | network.ip_protocol | |
| Acción (action) | actúa | acción | security_result.action_details
security_result.action |
|
| Gravedad (severity) | number-of-severity(header) | security_result.severity y security_result.severity_details | ||
| Número de secuencia (seqno) | externalId | secuencia | metadata.product_log_id | |
| Marcas de acción (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value |
| Ubicación de origen (srcloc) | principal.location.country_or_region | |||
| Ubicación de destino (dstloc) | target.location.country_or_region | |||
| Jerarquía del grupo de dispositivos (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value |
| Nombre del sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nombre del dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| ID del túnel (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key y additional.fields.value.string_value |
| Etiqueta de monitoreo (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key y additional.fields.value.string_value |
| ID de sesión principal (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Hora de inicio principal (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key y additional.fields.value.string_value |
| Tipo de túnel (tunnel) | cs2 | TunnelType | túnel | additional.fields.key y additional.fields.value.string_value |
| Bytes (bytes) | flexNumber1 | totalBytes | bytes | additional.fields.key y additional.fields.value.string_value |
| Bytes enviados (bytes_sent) | en | srcBytes | network.sent_bytes | |
| Bytes recibidos (bytes_received) | descifrar? | dstBytes | network.received_bytes | |
| Paquetes (packets) | cn2 | totalPackets | paquetes | additional.fields.key y additional.fields.value.string_value |
| Paquetes enviados (pkts_sent) | PanOSPacketsSent | srcPackets | pkts_sent | network.sent_packets |
| Paquetes recibidos (pkts_received) | PanOSPacketsReceived | dstPackets | pkts_received | network.received_packets |
| Encapsulamiento máximo (max_encap) | flexNumber2 | MaximumEncapsulation | max_encap | additional.fields.key y additional.fields.value.string_value |
| Protocolo desconocido (unknown_proto) | cfp1 | UnknownProtocol | unknown_proto | additional.fields.key y additional.fields.value.string_value |
| Verificación estricta (strict_check) | cfp2 | StrictChecking | strict_check | additional.fields.key y additional.fields.value.string_value |
| Fragmento de túnel (tunnel_fragment) | PanOSTunnelFragment | TunnelFragment | tunnel_fragment | additional.fields.key y additional.fields.value.string_value |
| Sesiones creadas (sessions_created) | cfp3 | SessionsCreated | sessions_created | additional.fields.key y additional.fields.value.string_value |
| Sesiones cerradas (sessions_closed) | cfp4 | SessionsClosed | sessions_closed | additional.fields.key y additional.fields.value.string_value |
| Motivo de finalización de la sesión (session_end_reason) | Reason | SessionEndReason | security_result.summary | |
| Fuente de la acción (action_source) | cat | ActionSource | action_source | additional.fields.key y additional.fields.value.string_value |
| Hora de inicio (start) | startTime | start | additional.fields.key y additional.fields.value.string_value | |
| Tiempo transcurrido (elapsed) | cn3 | ElapsedTime | Transcurrido | network.session_duration.seconds |
| Regla de inspección de túnel (tunnel_insp_rule) | PanOSTunneInspectionRule | security_result.rule_name = "Tunnel Inspection Rule: %{PanOSTunnelInspectionRule}" | ||
| IP del usuario remoto (remote_user_ip) | PanOSRmtUserIP | principal.ip | ||
| ID de usuario remoto (remote_user_id) | PanOSRmtUserID | remote_user_id | principal.user.userid | |
| UUID de la regla de seguridad (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| ID de PCAP (pcap_id) | PanOSPcapID | pcap_id | additional.fields.key y additional.fields.value.string_value | |
| Nombre del grupo de usuarios dinámico (dynusergroup_name) | PanDynamicUsrgrp | principal.group.group_display_name | ||
| Lista dinámica externa de origen (src_edl) | PanOSSourceEDL | src_edl | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Lista dinámica externa de destino (dst_edl) | PanOSDestinationEDL | dst_edl | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Marca de tiempo de alta resolución (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key y additional.fields.value.string_value | ||
| Un diferenciador de segmentos (nssai_sd) | nssai_sd | additional.fields.key y additional.fields.value.string_value | ||
| Un tipo de servicio de segmentación (nssai_sd) | nssai_sd1 | additional.fields.key y additional.fields.value.string_value | ||
| ID de sesión de PDU (pdu_session_id) | pdu_session_id | additional.fields.key y additional.fields.value.string_value | ||
| Subcategoría de la aplicación (subcategory_of_app) | subcategory_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Categoría de la aplicación (category_of_app) | category_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Tecnología de la aplicación (technology_of_app) | technology_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Riesgo de la aplicación (risk_of_app) | risk_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Característica de la aplicación (characteristic_of_app) | characteristic_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Contenedor de la aplicación (container_of_app) | container_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Aplicación SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Aplicación con túnel (tunneled_app) | additional.fields.key y additional.fields.value.string_value | |||
| Descargado (offloaded) | additional.fields.key y additional.fields.value.string_value | |||
| Tipo de flujo (flow_type) | additional.fields.key y additional.fields.value.string_value | |||
| Nombre del clúster (cluster_name) |
principal.resource.name |
|||
| Estado de aprobación de la aplicación (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key y additional.fields.value.string_value |
Autenticación
En la siguiente tabla, se enumeran los campos de registro del tipo de registro de autenticación y sus campos de UDM correspondientes.
| Campo CSV | Campo de CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si no está presente "Generate Time") |
|
| Número de serie (serie) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | cat | metadata.product_event_type | |
| Tipo de amenaza o contenido (subtipo) | subtype (encabezado) | Subtipo | metadata.product_event_type | |
| Hora de generación (time_generated o cef-formatted-time_generated) | metadata.event_timestamp | |||
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| IP de origen (ip) | src | src | principal.ip | |
| Usuario (user) | duser | usrName | target.user.userid | |
| Normalizar usuario (normalize_user) | cs2 | NormalizeUser | target.user.user_display_name | |
| Objeto (objeto) | fname | ObjectName | objeto | target.resource.name |
| Política de autenticación (authpolicy) | cs4 | AuthPolicy | authpolicy | additional.fields.key y additional.fields.value.string_value |
| Recuento de repeticiones (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key y additional.fields.value.string_value |
| ID de autenticación (authid) | cn2 | AuthenticationID | authid | additional.fields.key y additional.fields.value.string_value |
| Proveedor (vendor) | flexString2 | Proveedor | vendor | additional.fields.key y additional.fields.value.string_value |
| Acción de registro (conjunto de registros) | cs6 | LogForwardingProfile | logset | additional.fields.key y additional.fields.value.string_value |
| Perfil del servidor (serverprofile) | cs1 | ServerProfile | serverprofile | additional.fields.key y additional.fields.value.string_value |
| Descripción (desc) | PanOSDesc | AdditionalAuthInfo | security_result.description | |
| Tipo de cliente (clienttype) | cs5 | ClientType | clienttype | additional.fields.key y additional.fields.value.string_value |
| Tipo de evento (event) | msg | msg | extensions.auth.auth_details | |
| Número de factor (factorno) | cn1 | FactorNumber | factorno | additional.fields.key y additional.fields.value.string_value |
| Número de secuencia (seqno) | externalId | secuencia | metadata.product_log_id | |
| Marcas de acción (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value |
| Jerarquía del grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value |
| Nombre del sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nombre del dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| ID de sistema virtual (vsys_id) | intermediary.resource.product_object_id | |||
| Protocolo de autenticación (authproto) | authproto | additional.fields.key y additional.fields.value.string_value | ||
| UUID de la regla (rule_uuid) | PanOSRuleUUID/RuleUUID | security_result.rule_id | ||
| Marca de tiempo de alta resolución (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key y additional.fields.value.string_value | ||
| Categoría del dispositivo fuente (src_category) | PanOSSourceDeviceCategory | src_category | principal.asset.category | |
| Perfil del dispositivo fuente (src_profile) | PanOSSourceDeviceProfile | src_profile | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Modelo del dispositivo fuente (src_model) | PanOSSourceDeviceModel | src_model | principal.asset.hardware.model | |
| Proveedor del dispositivo fuente (src_vendor) | PanOSSourceDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Familia del SO del dispositivo fuente (src_osfamily) | PanOSSourceDeviceOSFamily | principal.asset.platform_software.platform principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
||
| Versión del SO del dispositivo de origen (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | ||
| Nombre de host de origen (src_host) | PanOSSourceHostname | principal.hostname | ||
| Dirección MAC de origen (src_mac) | PanOSSourceMac | principal.asset.mac | ||
| Región (región) | PanOSTrafficOriginRegion | principal.location.country_or_region | ||
| Usuario-agente (user_agent) | PanOSHTTPUserAgent | network.http.user_agent | ||
| ID de sesión(sessionid) | PanOSTrafficSessionID | network.session_id | ||
| Gravedad (severity) | number-of-severity(header) | security_result.severity y security_result.severity_details | ||
| Nombre del clúster (cluster_name) | principal.resource.name |
URL
En la siguiente tabla, se enumeran los campos de registro del tipo de registro de URL y sus campos de UDM correspondientes.
| Campo CSV | Campo de CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si no está presente "Generate Time") |
|
| Núm. de serie (serie) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | cat | metadata.product_event_type | |
| Tipo de amenaza o contenido (subtipo) | subtype (encabezado) | Subtipo | metadata.product_event_type | |
| Fecha de generación | metadata.event_timestamp | |||
| Dirección de origen (src) | src | src | principal.ip | |
| Dirección de destino (dst) | DST | DST | target.ip | |
| IP de origen de NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP de destino de NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Regla (rule) | cs1 | RuleName | security_result.rule_name | |
| Usuario de origen (srcuser) | suser | SourceUser | principal.user.userid | |
| Usuario de destino (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplicación (app) | app | Aplicación | network.application_protocol | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona de origen (desde) | cs4 | SourceZone | de | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Zona de destino (a) | cs5 | DestinationZone | a | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
| Interfaz entrante (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Interfaz de salida (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
| Acción de registro (conjunto de registros) | cs6 | LogForwardingProfile | logset | additional.fields.key y additional.fields.value.string_value |
| Tiempo registrado | time_logged | additional.fields.key y additional.fields.value.string_value | ||
| ID de sesión (sessionid) | cn1 | SessionID | network.session_id | |
| Recuento de repeticiones (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key y additional.fields.value.string_value |
| Puerto de origen (sport) | spt | srcPort | principal.port | |
| Puerto de destino (dport) | dpt | dstPort | target.port | |
| Puerto de origen de NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Puerto de destino de NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Marcas (flags) | flexString1 | Marcas | flags | additional.fields.key y additional.fields.value.string_value |
| Protocolo de IP (proto) | protocolo | protocolo | network.ip_protocol | |
| Acción (action) | actúa | acción | security_result.action_details
security_result.action |
|
| URL o nombre de archivo (varios) | Varios | target.file.names
target.url |
||
| Nombre de la amenaza o el contenido (threatid) | cat | ThreatID | security_result.threat_id | |
| Categoría (category) | cs2 | URLCategory | category | security_result.category_details |
| Gravedad (severity) | number-of-severity (encabezado) | Gravedad | security_result.severity
security_result.severity_details |
|
| Dirección (direction) | flexString2 | Dirección | network.direction | |
| Número de secuencia (seqno) | externalId | secuencia | metadata.product_log_id | |
| Marcas de acción (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value |
| País de origen (srcloc) | SourceLocation | principal.location.country_or_region | ||
| País de destino (dstloc) | DestinationLocation | target.location.country_or_region | ||
| contenttype (contenttype) | requestContext | ContentType | contenttype | additional.fields.key y additional.fields.value.string_value |
| pcap_id (pcap_id) | ID del archivo | PCAP_ID | pcap_id | additional.fields.key y additional.fields.value.string_value |
| filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | ||
| nube (cloud) | Nube | nube | additional.fields.key y additional.fields.value.string_value | |
| url_idx (url_idx) | URLIndex | url_idx | additional.fields.key y additional.fields.value.string_value | |
| user_agent (user_agent) | requestClientApplication | UserAgent | network.http.user_agent | |
| filetype (filetype) | target.file.mime_type | |||
| xff (xff) | PanOSXForwarderfor | identSrc | xff | principal.ip |
| Referencia (referer) | PanOSReferer | Referencia | network.http.referral_url | |
| remitente (sender) | network.email.from | |||
| Asunto (subject) | Asunto | network.email.subject | ||
| destinatario (recipient) | network.email.to | |||
| reportid (reportid) | reportid | additional.fields.key y additional.fields.value.string_value | ||
| DG Hierarchy Level 1 (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value |
| Nivel 2 de la jerarquía del DG (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value |
| Nivel 3 de la jerarquía de DG (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value |
| Nivel 4 de la jerarquía de DG (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value |
| Nombre del sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nombre del dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| file_url (file_url) | target.url | |||
| UUID de la VM de origen (src_uuid) | SrcUUID | principal.asset.product_object_id | ||
| UUID de la VM de destino (dst_uuid) | DstUUID | target.asset.product_object_id | ||
| http_method (http_method) | requestMethod | RequestMethod | network.http.method | |
| ID de túnel/IMSI (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key y additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key y additional.fields.value.string_value |
| ID de sesión principal (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Hora de inicio de la sesión principal (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key y additional.fields.value.string_value |
| Túnel (tunnel) | PanOSTunnelType | TunnelType | túnel | additional.fields.key y additional.fields.value.string_value |
| thr_category (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| contentver (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key y additional.fields.value.string_value |
| sig_flags (sig_flags) | sig_flags | additional.fields.key y additional.fields.value.string_value | ||
| ID de asociación de SCTP (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key y additional.fields.value.string_value | |
| ID de protocolo de carga útil (ppid) | PanOSPPID | ppid | additional.fields.key y additional.fields.value.string_value | |
| http_headers (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Lista de categorías de URL (url_category_list) | PanOSURLCatList | url_category_list | additional.fields.key y additional.fields.value.string_value | |
| UUID de la regla (rule_uuid) | PanOSRuleUUID | rule_uuid | security_result.rule_id | |
| Conexión HTTP/2 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| dynusergroup_name (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | additional.fields.key y additional.fields.value.string_value | |
| Dirección XFF (xff_ip) | PanXFFIP | principal.ip | ||
| Categoría del dispositivo fuente (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Perfil del dispositivo fuente (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Modelo del dispositivo fuente (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Proveedor del dispositivo fuente (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Familia del SO del dispositivo fuente (src_osfamily) | PanSrcDeviceOS | principal.platform | ||
| Versión del SO del dispositivo de origen (src_osversion) | PanSrcDeviceOSv | principal.platform_version | ||
| Nombre de host de origen (src_host) | PanSrcHostname | src_host | principal.hostname | |
| Dirección MAC de origen (src_mac) | PanSrcMac | principal.mac | ||
| Categoría del dispositivo de destino (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Perfil del dispositivo de destino (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Modelo de dispositivo de destino (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Proveedor del dispositivo de destino (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Familia del SO del dispositivo de destino (dst_osfamily) | PanDstDeviceOS | target.platform | ||
| Versión del SO del dispositivo de destino (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Nombre de host de destino (dst_host) | PanPODNamespace | target.hostname | ||
| Dirección MAC de destino (dst_mac) | PanDstMac | target.mac | ||
| ID del contenedor (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| Espacio de nombres del POD (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| Nombre del POD (pod_name) | PanPODName | pod_name | target.resource.name | |
| Lista dinámica externa de origen (src_edl) | PanSrcEDL | src_edl | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
|
| Lista dinámica externa de destino (dst_edl) | PanDstEDL | dst_edl | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
|
| ID del host (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Número de serie (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| domain_edl (domain_edl) | PanDomainEDL | domain_edl | additional.fields.key y additional.fields.value.string_value | |
| Grupo de direcciones dinámicas de origen (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Grupo de direcciones dinámicas de destino (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| partial_hash (partial_hash) | PanPartialHash | partial_hash | additional.fields.key y additional.fields.value.string_value | |
| Marca de tiempo en alta resolución (high_res_timestamp) | PanTimeHighRes | additional.fields.key y additional.fields.value.string_value | ||
| Motivo (reason) | PanReasonFilteringAction | Reason | security_result.summary | |
| justificación (justification) | PanJustification | justificación | additional.fields.key y additional.fields.value.string_value | |
| nssai_sst (nssai_sst) | PanASServiceType | nssai_sst | additional.fields.key y additional.fields.value.string_value | |
| Subcategoría de la app (subcategory_of_app) | subcategory_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Categoría de la app (category_of_app) | category_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Tecnología de la app (technology_of_app) | technology_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Riesgo de la app (risk_of_app) | risk_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Característica de la app (characteristic_of_app) | characteristic_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Contenedor de la app (container_of_app) | container_of_app | additional.fields.key y additional.fields.value.string_value | ||
| App con túnel (tunneled_app) | tunneled_app | additional.fields.key y additional.fields.value.string_value | ||
| SaaS de la app (is_saas_of_app) | is_saas_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Estado de la app con respecto a las sanciones (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key y additional.fields.value.string_value | ||
| ID del informe de Cloud (cloud_reportid) | additional.fields.key y additional.fields.value.string_value | |||
| Nombre del clúster (cluster_name) |
principal.resource.name |
|||
| Tipo de flujo (flow_type) | additional.fields.key y additional.fields.value.string_value |
Datos
En la siguiente tabla, se enumeran los campos de registro del tipo de registro de datos y sus campos de UDM correspondientes.
| Campo CSV | Campo de CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (si no está presente "Generate Time") |
|
| Núm. de serie (serie) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | cat | metadata.product_event_type | |
| Tipo de amenaza o contenido (subtipo) | subtype (encabezado) | Subtipo | metadata.product_event_type | |
| Fecha de generación | metadata.event_timestamp | |||
| Dirección de origen (src) | src | src | principal.ip | |
| Dirección de destino (dst) | DST | DST | target.ip | |
| IP de origen de NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP de destino de NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Regla (rule) | cs1 | RuleName | security_result.rule_name | |
| Usuario de origen (srcuser) | suser | SourceUser | principal.user.userid | |
| Usuario de destino (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplicación (app) | app | Aplicación | network.application_protocol | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona de origen (desde) | cs4 | SourceZone | de | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Zona de destino (a) | cs5 | DestinationZone | a | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
| Interfaz entrante (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
| Interfaz de salida (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
| Acción de registro (conjunto de registros) | cs6 | LogForwardingProfile | logset | additional.fields.key y additional.fields.value.string_value |
| Tiempo registrado | time_logged | additional.fields.key y additional.fields.value.string_value | ||
| ID de sesión (sessionid) | cn1 | SessionID | network.session_id | |
| Recuento de repeticiones (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key y additional.fields.value.string_value |
| Puerto de origen (sport) | spt | srcPort | principal.port | |
| Puerto de destino (dport) | dpt | dstPort | target.port | |
| Puerto de origen de NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Puerto de destino de NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Marcas (flags) | flexString1 | Marcas | flags | additional.fields.key y additional.fields.value.string_value |
| Protocolo de IP (proto) | protocolo | protocolo | network.ip_protocol | |
| Acción (action) | actúa | acción | security_result.action_details
security_result.action |
|
| URL o nombre de archivo (varios) | Varios | target.file.names
target.url |
||
| Nombre de la amenaza o el contenido (threatid) | cat | ThreatID | security_result.threat_id | |
| Categoría (category) | cs2 | URLCategory | category | security_result.category_details |
| Gravedad (severity) | number-of-severity (encabezado) | Gravedad | security_result.severity
security_result.severity_details |
|
| Dirección (direction) | flexString2 | Dirección | network.direction | |
| Número de secuencia (seqno) | externalId | secuencia | metadata.product_log_id | |
| Marcas de acción (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value |
| País de origen (srcloc) | SourceLocation | principal.location.country_or_region | ||
| País de destino (dstloc) | DestinationLocation | target.location.country_or_region | ||
| contenttype (contenttype) | ContentType | contenttype | additional.fields.key y additional.fields.value.string_value | |
| pcap_id (pcap_id) | ID del archivo | PCAP_ID | pcap_id | additional.fields.key y additional.fields.value.string_value |
| filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | ||
| nube (cloud) | Nube | nube | additional.fields.key y additional.fields.value.string_value | |
| url_idx (url_idx) | URLIndex | url_idx | additional.fields.key y additional.fields.value.string_value | |
| user_agent (user_agent) | network.http.user_agent | |||
| filetype (filetype) | target.file.mime_type | |||
| xff (xff) | xff | principal.ip | ||
| Referencia (referer) | network.http.referral_url | |||
| remitente (sender) | network.email.from | |||
| Asunto (subject) | Asunto | network.email.subject | ||
| destinatario (recipient) | network.email.to | |||
| reportid (reportid) | reportid | additional.fields.key y additional.fields.value.string_value | ||
| DG Hierarchy Level 1 (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value |
| Nivel 2 de la jerarquía del DG (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value |
| Nivel 3 de la jerarquía de DG (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value |
| Nivel 4 de la jerarquía de DG (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value |
| Nombre del sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nombre del dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| file_url (file_url) | target.url | |||
| UUID de la VM de origen (src_uuid) | SrcUUID | principal.asset.product_object_id | ||
| UUID de la VM de destino (dst_uuid) | DstUUID | target.asset.product_object_id | ||
| http_method (http_method) | RequestMethod | network.http.method | ||
| ID de túnel/IMSI (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key y additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key y additional.fields.value.string_value |
| ID de sesión principal (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Hora de inicio de la sesión principal (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key y additional.fields.value.string_value |
| Túnel (tunnel) | PanOSTunnelType | TunnelType | túnel | additional.fields.key y additional.fields.value.string_value |
| thr_category (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| contentver (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key y additional.fields.value.string_value |
| sig_flags (sig_flags) | sig_flags | additional.fields.key y additional.fields.value.string_value | ||
| ID de asociación de SCTP (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key y additional.fields.value.string_value | |
| ID de protocolo de carga útil (ppid) | PanOSPPID | ppid | additional.fields.key y additional.fields.value.string_value | |
| http_headers (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Lista de categorías de URL (url_category_list) | url_category_list | additional.fields.key y additional.fields.value.string_value | ||
| UUID de la regla (rule_uuid) | PanOSRuleUUID | rule_uuid | security_result.rule_id | |
| Conexión HTTP/2 (http2_connection) | http2_connection | network.application_protocol_version | ||
| dynusergroup_name (dynusergroup_name) | dynusergroup_name | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
||
| Dirección XFF (xff_ip) | principal.ip | |||
| Categoría del dispositivo fuente (src_category) | src_category | principal.asset.category | ||
| Perfil del dispositivo fuente (src_profile) | src_profile | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
||
| Modelo del dispositivo fuente (src_model) | src_model | principal.asset.hardware.model | ||
| Proveedor del dispositivo fuente (src_vendor) | src_vendor | principal.asset.hardware.manufacturer | ||
| Familia del SO del dispositivo fuente (src_osfamily) | principal.platform | |||
| Versión del SO del dispositivo de origen (src_osversion) | principal.platform_version | |||
| Nombre de host de origen (src_host) | src_host | principal.hostname | ||
| Dirección MAC de origen (src_mac) | principal.mac | |||
| Categoría del dispositivo de destino (dst_category) | dst_category | target.asset.category | ||
| Perfil del dispositivo de destino (dst_profile) | dst_profile | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
||
| Modelo de dispositivo de destino (dst_model) | dst_model | target.asset.hardware.model | ||
| Proveedor del dispositivo de destino (dst_vendor) | dst_vendor | target.asset.hardware.manufacturer | ||
| Familia del SO del dispositivo de destino (dst_osfamily) | target.platform | |||
| Versión del SO del dispositivo de destino (dst_osversion) | target.platform_version | |||
| Nombre de host de destino (dst_host) | target.hostname | |||
| Dirección MAC de destino (dst_mac) | target.mac | |||
| ID del contenedor (container_id) | container_id | intermediary.resource.product_object_id | ||
| Espacio de nombres del POD (pod_namespace) | pod_namespace | target.resource.attribute.labels.key/value | ||
| Nombre del POD (pod_name) | pod_name | target.resource.name | ||
| Lista dinámica externa de origen (src_edl) | src_edl | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
||
| Lista dinámica externa de destino (dst_edl) | dst_edl | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
||
| ID del host (hostid) | hostid | principal.asset.asset_id | ||
| Número de serie (serialnumber) | principal.asset.hardware.serial_number | |||
| domain_edl (domain_edl) | domain_edl | additional.fields.key y additional.fields.value.string_value | ||
| Grupo de direcciones dinámicas de origen (src_dag) | principal.group.group_display_name | |||
| Grupo de direcciones dinámicas de destino (dst_dag) | target.group.group_display_name | |||
| partial_hash (partial_hash) | partial_hash | additional.fields.key y additional.fields.value.string_value | ||
| Marca de tiempo en alta resolución (high_res_timestamp) | additional.fields.key y additional.fields.value.string_value | |||
| Motivo (reason) | Reason | security_result.summary | ||
| justificación (justification) | justificación | additional.fields.key y additional.fields.value.string_value | ||
| nssai_sst (nssai_sst) | nssai_sst | additional.fields.key y additional.fields.value.string_value | ||
| Subcategoría de la app (subcategory_of_app) | subcategory_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Categoría de la app (category_of_app) | category_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Tecnología de la app (technology_of_app) | technology_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Riesgo de la app (risk_of_app) | risk_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Característica de la app (characteristic_of_app) | characteristic_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Contenedor de la app (container_of_app) | container_of_app | additional.fields.key y additional.fields.value.string_value | ||
| App con túnel (tunneled_app) | tunneled_app | additional.fields.key y additional.fields.value.string_value | ||
| SaaS de la app (is_saas_of_app) | is_saas_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Estado de la app con respecto a las sanciones (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key y additional.fields.value.string_value | ||
| ID del informe de Cloud (cloud_reportid) | additional.fields.key y additional.fields.value.string_value | |||
| Nombre del clúster (cluster_name) | principal.resource.name | |||
| Tipo de flujo (flow_type) | additional.fields.key y additional.fields.value.string_value |
GlobalProtect
En la siguiente tabla, se enumeran los campos de registro del tipo de registro de GlobalProtect y sus campos de UDM correspondientes.
| Campo CSV | Campo de CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time) | rt | received_time | metadata.event_timestamp | |
| Núm. de serie (serie) | PanOSDeviceSN | intermediary_asset_hardware_serial_number | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (Header) | metadata.product_event_type | ||
| Tipo de amenaza o contenido (subtipo) | subtype (encabezado) | Subtipo | metadata.product_event_type | |
| Fecha y hora de generación (time_generated) | PanOSLogTimeStamp | generated_timestamp | metadata.event_timestamp | |
| Sistema virtual (vsys) | PanOSVirtualSystem | vsys | intermediary.asset.attribute.labels.key/value | |
| ID del evento (eventid) | PanOSEventID | event_id | additional.fields.key y additional.fields.value.string_value | |
| Etapa (stage) | PanOSStage | de este proceso, | additional.fields.key y additional.fields.value.string_value | |
| Método de autenticación (auth_method) | PanOSAuthMethod | extension_auth_auth_details | extensions.auth.auth_details | |
| Tipo de túnel (tunnel_type) | PanOSTunnelType | túnel | additional.fields.key y additional.fields.value.string_value | |
| Usuario de origen (srcuser) | PanOSSourceUserName | src_user | principal.user.email_address
principal.user.userid principal.administrative_domain |
|
| Región de origen (srcregion) | PanOSSourceRegion | src_region | principal.location.country_or_region | |
| Nombre de la máquina (machinename) | PanOSEndpointDeviceName | machine_name | principal.hostname | |
| IP pública (public_ip) | PanOSPublicIPv4 | principal.nat_ip | ||
| IPv6 pública (public_ipv6) | PanOSPublicIPv6 | principal.nat_ip | ||
| IP privada (private_ip) | PanOSPrivateIPv4 | principal.ip | ||
| IPv6 privada (private_ipv6) | PanOSPrivateIPv6 | principal.ip | ||
| ID del host (hostid) | PanOSHostID | hostid | principal.asset.asset_id | |
| Número de serie (serialnumber) | PanOSDeviceSN | principal.asset.hardware.serial_number | ||
| Versión del cliente (client_ver) | PanOSGlobalProtectClientVersion | client_ver | additional.fields.key y additional.fields.value.string_value | |
| SO del cliente (client_os) | PanOSEndpointOSType | principal.platform | ||
| Versión del SO del cliente (client_os_ver) | PanOSEndpointOSVersion | principal.platform_version | ||
| Recuento de repeticiones (repeatcnt) | PanOSCountOfRepeats | repeatcnt | additional.fields.key y additional.fields.value.string_value | |
| Motivo (reason) | PanOSQuarantineReason | security_result.summary | ||
| Error (error) | PanOSConnectionError | error | security_result.description | |
| Descripción (opaca) | PanOSDescription | security_result.description | ||
| Estado (status) | PanOSEventStatus | estado | additional.fields.key y additional.fields.value.string_value | |
| Ubicación (ubicación) | PanOSGPGatewayLocation | target.location.country_or_region | ||
| Duración del acceso (login_duration) | PanOSLoginDuration | network.session_duration | ||
| Método de conexión (connect_method) | PanOSConnectionMethod | connect_method | additional.fields.key y additional.fields.value.string_value | |
| Código de error (error_code) | PanOSConnectionErrorID | error_code | additional.fields.key y additional.fields.value.string_value | |
| Portal (portal) | PanOSPortal | portal | additional.fields.key y additional.fields.value.string_value | |
| Número de secuencia (seqno) | PanOSSequenceNo | metadata.product_log_id | ||
| Marcas de acción (actionflags) | PanOSActionFlags | actionflags | additional.fields.key y additional.fields.value.string_value | |
| Marca de tiempo de alta resolución (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key y additional.fields.value.string_value | ||
| Método de selección de puerta de enlace (selection_type) | PanOSGatewaySelectionType | selection_type | additional.fields.key y additional.fields.value.string_value | |
| Tiempo de respuesta de SSL (response_time) | PanOSSSLResponseTime | response_time | additional.fields.key y additional.fields.value.string_value | |
| Prioridad de la puerta de enlace (prioridad) | PanOSGatewayPriority | priority | additional.fields.key y additional.fields.value.string_value | |
| Puertas de enlace intentadas (attempted_gateways) | PanOSAttemptedGateways | attempted_gateways | additional.fields.key y additional.fields.value.string_value | |
| Nombre de la puerta de enlace (gateway) | PanOSAttemptedGateways | puerta de enlace | target.resource.name | |
| Jerarquía del grupo de dispositivos (dg_hier_level_1) | dg_hier_level_1 | additional.fields.key y additional.fields.value.string_value | ||
| Jerarquía del grupo de dispositivos (dg_hier_level_2) | dg_hier_level_2 | additional.fields.key y additional.fields.value.string_value | ||
| Jerarquía del grupo de dispositivos (dg_hier_level_3) | dg_hier_level_3 | additional.fields.key y additional.fields.value.string_value | ||
| Jerarquía del grupo de dispositivos (dg_hier_level_4) | dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value | ||
| Nombre del sistema virtual (vsys_name) | intermediary.asset.attribute.labels.key/value | |||
| Nombre del dispositivo (device_name) | intermediary.hostname | |||
| ID de sistema virtual (vsys_id) | intermediary.resource.product_object_id | |||
| Gravedad (severity) | number-of-severity(header) | security_result.severity y security_result.severity_details | ||
| Nombre del clúster (cluster_name) | principal.resource.name |
Correlación
En la siguiente tabla, se enumeran los campos de registro del tipo de registro Correlation y sus campos de UDM correspondientes.
| Campo CSV | Campo de CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de generación (time_generated o cef-formatted-time_generated) | startTime | generated_timestamp | metadata.event_timestamp | |
| Dirección de origen (src) | src | principal.ip | ||
| Usuario de origen (srcuser) | SourceUser / usrName | principal.user.userid | ||
| Sistema virtual (vsys) | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value | |
| Categoría (category) | security_result.category_details | |||
| Gravedad (severity) | Gravedad | security_result.severity y security_result.severity_details | ||
| Nivel 1 de la jerarquía del grupo de dispositivos | DeviceGroupHierarchyL1 | additional.fields.key y additional.fields.value.string_value | ||
| Nivel 2 de la jerarquía del grupo de dispositivos | DeviceGroupHierarchyL2 | additional.fields.key y additional.fields.value.string_value | ||
| Jerarquía del grupo de dispositivos, nivel 3 | DeviceGroupHierarchyL3 | additional.fields.key y additional.fields.value.string_value | ||
| Nivel 4 de la jerarquía del grupo de dispositivos | DeviceGroupHierarchyL4 | additional.fields.key y additional.fields.value.string_value | ||
| Nombre del sistema virtual (vsys_name) | vSrcName | intermediary.asset.attribute.labels.key/value | ||
| Nombre del dispositivo (device_name) | DeviceName | intermediary.hostname | ||
| ID de sistema virtual (vsys_id) | VirtualSystemID | intermediary.resource.product_object_id | ||
| Nombre del objeto (objectname) | ObjectName | target.resource.name | ||
| ID de objeto (object_id) | ObjectID | target.resource.product_object_id | ||
| Evidencia (evidence) | msg | security_result.summary |
GTP
En la siguiente tabla, se enumeran los campos de registro del tipo de registro gtp y sus campos de UDM correspondientes.
| Campo CSV | Campo de CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | metadata.collected_timestamp,
metadata.event_timestamp (si no está presente "Generate Time") |
|||
| Número de serie (serie) | intermediary.asset.hardware.serial_number | |||
| Tipo (type) | metadata.product_event_type | |||
| Tipo de amenaza o contenido (subtipo) | metadata.product_event_type | |||
| Hora de generación (time_generated o cef-formatted-time_generated) | metadata.event_timestamp | |||
| Dirección de origen (src) | principal.ip | |||
| Dirección de destino (dst) | target.ip | |||
| Nombre de la regla (rule) | security_result.rule_name | |||
| Aplicación (app) | network.application_protocol | |||
| Sistema virtual (vsys) | vsys | intermediary.asset.attribute.labels.key/value | ||
| Zona de origen (desde) | de | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
||
| Zona de destino (a) | a | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
||
| Interfaz entrante (inbound_if) | inbound_if | principal.labels.key y principal.labels.value additional.fields.key y additional.fields.value.string_value |
||
| Interfaz de salida (outbound_if) | outbound_if | target.labels.key y target.labels.value additional.fields.key y additional.fields.value.string_value |
||
| Acción de registro (conjunto de registros) | logset | additional.fields.key y additional.fields.value.string_value | ||
| ID de sesión (sessionid) | network.session_id | |||
| Puerto de origen (sport) | principal.port | |||
| Puerto de destino (dport) | target.port | |||
| Protocolo de IP (proto) | network.ip_protocol | |||
| Acción (action) | security_result.action_details
security_result.action |
|||
| Tipo de evento de GTP (event_type) | gtp_event_type | additional.fields.key y additional.fields.value.string_value | ||
| MSISDN (msisdn) | msisdn | additional.fields.key y additional.fields.value.string_value | ||
| Nombre de punto de acceso (apn) | apn | additional.fields.key y additional.fields.value.string_value | ||
| Tecnología de acceso por radio (RAT) | rata | additional.fields.key y additional.fields.value.string_value | ||
| Tipo de mensaje de GTP (msg_type) | gtp_msg_type | additional.fields.key y additional.fields.value.string_value | ||
| Dirección IP final (end_ip_adr) | principal.ip | |||
| Identificador de extremo de túnel 1 (teid1) | teid1 | additional.fields.key y additional.fields.value.string_value | ||
| Identificador de extremo de túnel 2 (teid2) | teid2 | additional.fields.key y additional.fields.value.string_value | ||
| Interfaz de GTP (gtp_interface) | gtp_interface | additional.fields.key y additional.fields.value.string_value | ||
| Causa del GTP (cause_code) | gtp_cause_code | additional.fields.key y additional.fields.value.string_value | ||
| Gravedad (severity) | security_result.severity y security_result.severity_details | |||
| MCC de la red de publicación (mcc) | mcc | additional.fields.key y additional.fields.value.string_value | ||
| MNC de la red de publicación (mnc) | mnc | additional.fields.key y additional.fields.value.string_value | ||
| Código de área (area_code) | area_code | additional.fields.key y additional.fields.value.string_value | ||
| ID de celda (cell_id) | cell_id | additional.fields.key y additional.fields.value.string_value | ||
| Código de evento de GTP (event_code) | event_code | additional.fields.key y additional.fields.value.string_value | ||
| Ubicación de origen (srcloc) | principal.location.country_or_region | |||
| Ubicación de destino (dstloc) | target.location.country_or_region | |||
| ID de túnel/IMSI (imsi) | tunnelid | additional.fields.key y additional.fields.value.string_value | ||
| Etiqueta de supervisión/IMEI (imei) | monitortag | additional.fields.key y additional.fields.value.string_value | ||
| Hora de inicio (start) | start | additional.fields.key y additional.fields.value.string_value | ||
| Tiempo transcurrido (elapsed) | network.session_duration.seconds | |||
| Regla de inspección del túnel (tunnel_insp_rule) | tunnel_insp_rule | security_result.detection_fields.key/value | ||
| IP del usuario remoto (remote_user_ip) | principal.ip | |||
| ID de usuario remoto (remote_user_id) | remote_user_id | principal.user.userid | ||
| UUID de la regla (rule_uuid) | security_result.rule_id | |||
| ID de PCAP (pcap_id) | pcap_id | additional.fields.key y additional.fields.value.string_value | ||
| Marca de tiempo de alta resolución (high_res_timestamp) | additional.fields.key y additional.fields.value.string_value | |||
| Un tipo de servicio de Slice (nsdsai_sst) | nsdsai_sst | additional.fields.key y additional.fields.value.string_value | ||
| Un diferenciador de Slice (nsdsai_sd) | nsdsai_sd | additional.fields.key y additional.fields.value.string_value | ||
| Subcategoría de la aplicación (subcategory_of_app) | subcategory_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Categoría de la aplicación (category_of_app) | category_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Tecnología de la aplicación (technology_of_app) | technology_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Riesgo de la aplicación (risk_of_app) | risk_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Característica de la aplicación (characteristic_of_app) | characteristic_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Contenedor de la aplicación (container_of_app) | container_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Aplicación SaaS (is_saas_of_app) | is_saas_of_app | additional.fields.key y additional.fields.value.string_value | ||
| Estado de aprobación de la aplicación (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key y additional.fields.value.string_value |
SCTP
| Campo CSV | Campo de CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Hora de recepción (receive_time o cef-formatted-receive_time) | receive_time o cef-formatted-receive_time | metadata.collected_timestamp | ||
| Número de serie (serie) | serial | intermediary.asset.hardware.serial_number | ||
| Tipo (type) | tipo | metadata.product_event_type | ||
| Hora de generación (time_generated o cef-formatted-time_generated) | time_generated o cef-formatted-time_generated | metadata.event_timestamp | ||
| Dirección de origen (src) | src | principal.ip | ||
| Dirección de destino (dst) | DST | target.ip | ||
| Nombre de la regla (rule) | regla | security_result.rule_name | ||
| Zona de origen (desde) | de | additional.fields.key y additional.fields.value.string_value | ||
| Zona de destino (a) | a | additional.fields.key y additional.fields.value.string_value | ||
| Interfaz entrante (inbound_if) | inbound_if | additional.fields.key y additional.fields.value.string_value | ||
| Interfaz de salida (outbound_if) | outbound_if | additional.fields.key y additional.fields.value.string_value | ||
| Acción de registro (conjunto de registros) | logset | additional.fields.key y additional.fields.value.string_value | ||
| ID de sesión (sessionid) | sessionid | network.session_id | ||
| Recuento de repeticiones (repeatcnt) | repeatcnt | additional.fields.key y additional.fields.value.string_value | ||
| Puerto de origen (sport) | deporte | principal.port | ||
| Puerto de destino (dport) | dport | target.port | ||
| Protocolo de IP (proto) | protocolo | network.ip_protocol (enum) | ||
| Acción (action) | acción | security_result.action_details security_result.action |
||
| Jerarquía del grupo de dispositivos (dg_hier_level_1 a dg_hier_level_4) | dg_hier_level_1 a dg_hier_level_4 | additional.fields.key y additional.fields.value.string_value | ||
| Nombre del dispositivo (device_name) | device_name | intermediary.hostname | ||
| Número de secuencia (seqno) | seqno | metadata.product_log_id | ||
| ID de asociación de SCTP (assoc_id) | assoc_id | additional.fields.key y additional.fields.value.string_value | ||
| ID de protocolo de carga útil (ppid) | ppid | additional.fields.key y additional.fields.value.string_value | ||
| Gravedad (severity) | gravedad, | security_result.severity y security_result.severity_details | ||
| Tipo de fragmento SCTP (sctp_chunk_type) | sctp_chunk_type | additional.fields.key y additional.fields.value.string_value | ||
| Tipo de evento de SCTP (sctp_event_type) | sctp_event_type | additional.fields.key y additional.fields.value.string_value | ||
| Etiqueta de verificación 1 de SCTP (verif_tag_1) | verif_tag_1 | additional.fields.key y additional.fields.value.string_value | ||
| Etiqueta de verificación de SCTP 2 (verif_tag_2) | verif_tag_2 | additional.fields.key y additional.fields.value.string_value | ||
| Código de causa de SCTP (sctp_cause_code) | sctp_cause_code | additional.fields.key y additional.fields.value.string_value | ||
| ID de la app de Diameter (diam_app_id) | diam_app_id | additional.fields.key y additional.fields.value.string_value | ||
| Código de comando de diámetro (diam_cmd_code) | diam_cmd_code | additional.fields.key y additional.fields.value.string_value | ||
| Código de AVP de diámetro (diam_avp_code) | diam_avp_code | additional.fields.key y additional.fields.value.string_value | ||
| ID de transmisión de SCTP (stream_id) | stream_id | additional.fields.key y additional.fields.value.string_value | ||
| Motivo de finalización de la asociación de SCTP (assoc_end_reason) | assoc_end_reason | additional.fields.key y additional.fields.value.string_value | ||
| Código de operación (op_code) | op_code | additional.fields.key y additional.fields.value.string_value | ||
| SSN de la parte llamante de SCCP (sccp_calling_ssn) | sccp_calling_ssn | additional.fields.key y additional.fields.value.string_value | ||
| Título global de la parte llamadora de SCCP (sccp_calling_gt) | sccp_calling_gt | additional.fields.key y additional.fields.value.string_value | ||
| Filtro SCTP (sctp_filter) | sctp_filter | additional.fields.key y additional.fields.value.string_value | ||
| Fragmentos de SCTP (chunks) | fragmentos | additional.fields.key y additional.fields.value.string_value | ||
| Fragmentos SCTP enviados (chunks_sent) | chunks_sent | additional.fields.key y additional.fields.value.string_value | ||
| Fragmentos SCTP recibidos (chunks_received) | chunks_received | additional.fields.key y additional.fields.value.string_value | ||
| Paquetes (packets) | paquetes | additional.fields.key y additional.fields.value.string_value | ||
| UUID de la regla (rule_uuid) | rule_uuid | security_result.rule_id | ||
| Sistema virtual (vsys) | vsys | intermediary.asset.attribute.labels.key/value | ||
| Nombre del sistema virtual (vsys_name) | vsys_name | intermediary.asset.attribute.labels.key/value | ||
| Paquetes enviados (pkts_sent) | pkts_sent | network.sent_packets | ||
| Paquetes recibidos (pkts_received) | pkts_received | network.received_packets |
Auditoría
| Campo CSV | Campo de CEF | Campo LEEF | Clave de etiqueta de Google Security Operations | Campo de UDM |
|---|---|---|---|---|
| Fecha de generación | metadata.event_timestamp | |||
| Tipo de amenaza o contenido (subtipo) | metadata.product_event_type | |||
| ID del evento | principal.application | |||
| Objeto | principal.user.userid | |||
| Comando de la CLI | principal.process.command_line | |||
| Gravedad | security_result.severity | |||
| Número de serie | intermediary.asset.hardware.serial_number |
Referencia de asignación de campos: Tipos de registros a tipo de evento de UDM
En la siguiente tabla, se enumeran los tipos de registros de firewall de Palo Alto Networks y sus tipos de eventos de UDM correspondientes.
| Tipo de registro | Tipo de evento de UDM |
| Tráfico | NETWORK_CONNECTION |
| Amenaza | NETWORK_CONNECTION |
| Filtrado de URLs | NETWORK_CONNECTION |
| WildFire | NETWORK_CONNECTION
Los registros de envíos de WildFire son un subtipo del tipo de registro de amenazas y usan el mismo formato de syslog. |
| Filtrado de datos | NETWORK_CONNECTION |
| Túnel | NETWORK_CONNECTION |
| GTP | NETWORK_CONNECTION |
| Configuración | SETTING_MODIFICATION/SETTING_CREATION/SETTING_DELETION/SETTING_UNCATEGORIZED
El valor del campo "Comando (cmd)" determina la asignación del tipo de evento del UDM. Si el valor del campo cmd es add o clone, se establece SETTING_CREATION. Si el valor del campo cmd es delete, se establece SETTING_DELETION. Si el valor del campo cmd es edit, move, rename, set o commit, se establece SETTING_MODIFICATION. Si el valor del campo cmd no contiene ningún valor, se establece SETTING_UNCATEGORIZED. |
| Sistema |
Si el valor del subtipo es "dhcp", se establece NETWORK_DHCP. Si el valor del subtipo es "auth", se establece USER_LOGIN. Si el valor de la descripción es "logged in", se establece USER_LOGIN. Si el valor de la descripción es "logged out", se establece USER_LOGOUT. Para otros valores del subtipo, se establece GENERIC_EVENT. |
| HIP Match | NETWORK_CONNECTION |
| Etiqueta de IP | GENERIC_EVENT |
| User-ID | USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED
Si el valor del subtipo es "login", se establece USER_LOGIN. Si el valor del subtipo es "logout", se establece USER_LOGOUT. Si el subtipo no contiene ningún valor, se establece USER_UNCATEGORIZED. |
| Desencriptación | NETWORK_CONNECTION |
| Autenticación | GENERIC_EVENT |
| SCTP | NETWORK_CONNECTION |
| Auditoría | GENERIC_EVENT |
Delta de asignación de UDM
Referencia del delta de la asignación del UDM: Firewall de Palo Alto Networks
En la siguiente tabla, se muestra la diferencia entre la asignación de UDM anterior de Palo Alto Networks Firewall y la asignación de UDM nueva de Palo Alto Networks Firewall.
UDM Event Type Delta
| Log type | Old UDM Event Type | New UDM Event Type |
| WildFire | NETWORK_CONNECTION | SCAN_UNCATEGORIZED |
| Data Filtering | NETWORK_CONNECTION | NETWORK_UNCATEGORIZED |
| Authentication | STATUS_UPDATE | STATUS_UNCATEGORIZED |
UDM Field Mapping Delta
| Log Type | Old UDM Mapping | CSV Log Field | CEF Log Field | LEEF Log Field | New UDM Mapping |
|---|---|---|---|---|---|
| System | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| System | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| System | about.labels.key/value additional.fields.key/value.string_value | Object (object) | fname | Filename | target.resource.name |
| System | Description (opaque) | msg | msg | metadata.description | |
| System | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| System | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| Config | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| Config | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| Config | principal.process.command_line | Configuration Path (path) | msg | ConfigurationPath | principal.process.command_line |
| Config | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| Config | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| Config | principal.asset.attribute.labels.key/value | Device Group (dg_id) | PanOSFWDeviceGroup | target.asset.attribute.labels | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Threat/Wildfire | target.file.full_path target.url target.hostname | URL/Filename (misc) | request | Miscellaneous | target.file.names target.url |
| Threat/Wildfire | about.file.sha1/md5/sha256 | File Digest (filedigest) | fileHash | FileDigest | target.file.sha1/md5/sha256 |
| Threat/Wildfire | about.file.mime_type | File Type (filetype) | fileType | FileType | target.file.mime_type |
| Threat/Wildfire | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Threat/Wildfire | principal.user.product_object_id | Source VM UUID (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id |
| Threat/Wildfire | target.user.product_object_id | Destination VM UUID (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | HTTP Headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| Threat/Wildfire | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| Threat/Wildfire | principal.asset.software.version | Source Device OS Version (src_osversion) | PanSrcDeviceOSv | principal.platform_version | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| Threat/Wildfire | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| Threat/Wildfire | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | PanReasonFilteringAction | security_result.summary | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Packets Sent (pkts_sent) | PanOSPacketsSent | srcPackets | network.sent_packets |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Packets Received (pkts_received) | PanOSPacketsReceived | dstPackets | network.received_packets |
| Traffic | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| Traffic | principal.asset.platform_software.platform(enum) principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| Traffic | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| Traffic | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| User-ID | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| User-ID | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| User-ID | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | intermediary.resource.product_object_id |
| User-ID | principal.user.userid principal.administrative_domain principal.user.email_addresses | User by Source (userbysource) | PanOSUserBySource | target.user.userid target.user.email_addresses | |
| User-ID | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| HIP Match | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | HIP (matchname) | cat | HIP | target.resource.attribute.labels |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | HIP Type (matchtype) | Device Event Class ID (Header) | HIPType | target.resource.attribute.labels |
| HIP Match | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| HIP Match | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| HIP Match | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id |
| HIP Match | principal.asset.product_object_id | Host ID (hostid) | PanOSHostID | principal.asset.asset_id | |
| HIP Match | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| IP-Tag | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| IP-Tag | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| IP-Tag | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOsVsysName | vSrcName | target.asset.attribute.labels |
| IP-Tag | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| IP-Tag | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id |
| IP-Tag | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Decryption | target.application | Application (app) | app | network.application_protocol | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | intermediary.asset.attribute.labels | |
| Decryption | principal.asset.asset_id | Source VM UUID (src_uuid) | PanOSSourceUUID | principal.asset.product_object_id | |
| Decryption | target.asset.asset_id | Destination VM UUID (dst_uuid) | PanOSDestinationUUID | target.asset.product_object_id | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanOSContainerID | intermediary.resource.product_object_id | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanOSContainerNameSpace | target.resource.attribute.labels additional.fields.key/value.string_value | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanOSContainerName | target.resource.name | |
| Decryption | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanOSSourceDeviceCategory | principal.asset.category | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanOSSourceDeviceModel | principal.asset.hardware.model | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanOSSourceDeviceVendor | principal.asset.hardware.manufacturer | |
| Decryption | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanOSSourceDeviceOSFamily | principal.platform | |
| Decryption | principal.asset.software.version | Source Device OS Version (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanOSDestinationDeviceCategory | target.asset.category | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanOSDestinationDeviceModel | target.asset.hardware.model | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanOSDestinationDeviceVendor | target.asset.hardware.manufacturer | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanOSDestinationDeviceOSFamily | target.platform | |
| Decryption | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanOSDestinationDeviceOSVersion | target.platform_version | |
| Decryption | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | intermediary.asset.attribute.labels | ||
| Decryption | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Tunnel | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Packets Sent (pkts_sent) | PanOSPacketsSent | srcPackets | network.sent_packets |
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Packets Received (pkts_received) | PanOSPacketsReceived | dstPackets | network.received_packets |
| Tunnel | target.ip | Remote User IP (remote_user_ip) | PanOSRmtUserIP | principal.ip | |
| Tunnel | target.labels.key/value additional.fields.key/value.string_value | Remote User ID (remote_user_id) | PanOSRmtUserID | principal.user.userid | |
| Tunnel | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Authentication | target.user.user_display_name | Normalize User (normalize_user) | cs2 | NormalizeUser | target.user.user_display_name |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Object (object) | fname | ObjectName | target.resource.name |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Authentication Policy (authpolicy) | cs4 | AuthPolicy | additional.fields.key/value.string_value |
| Authentication | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Authentication | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| Authentication | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res _timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanOSSourceDeviceCategory | principal.asset.category | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanOSSourceDeviceModel | principal.asset.hardware.model | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanOSSourceDeviceVendor | principal.asset.hardware.manufacturer | |
| Authentication | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanOSSourceDeviceOSFamily | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | |
| Authentication | principal.asset.software.version | Source Device OS Version (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| URL | target.file.full_path target.url | URL/Filename (misc) | Miscellaneous | target.file.names target.url | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Category (category) | cs2 | URLCategory | security_result.category_details |
| URL | about.file.sha1/md5/sha256 | filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | |
| URL | about.file.mime_type | filetype (filetype) | target.file.mime_type | ||
| URL | about.labels.key/value additional.fields.key/value.string_value | xff (xff) | PanOSXForwarderfor | identSrc | principal.ip |
| URL | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| URL | about.url | file_url (file_url) | target.url | ||
| URL | principal.asset.asset_id | Source VM UUID (src_uuid) | SrcUUID | principal.asset.product_object_id | |
| URL | target.asset.asset_id | Destination VM UUID (dst_uuid) | DstUUID | target.asset.product_object_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | http_headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| URL | about.labels.key/value additional.fields.key/value.string_value | UUID for rule (rule_uuid) | PanOSRuleUUID | security_result.rule_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| URL | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| URL | principal.asset.software.version | Source Device OS Version (src_osversion) | PanSrcDeviceOSv | principal.platform_version | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Hostname (src_host) | PanSrcHostname | principal.hostname | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| URL | target.asset.platform_software.platform target.labels.key/value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| URL | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| URL | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| URL | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Res Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | PanReasonFilteringAction | security_result.summary | |
| Data | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Data | target.file.full_path target.url | URL/Filename (misc) | Miscellaneous | target.file.names target.url | |
| Data | about.labels.key/value additional.fields.key/value.string_value | Category (category) | cs2 | URLCategory | security_result.category_details |
| Data | about.file.sha1/md5/sha256 | filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | |
| Data | about.file.mime_type | filetype (filetype) | target.file.mime_type | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | xff (xff) | principal.ip | ||
| Data | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Data | about.url | file_url (file_url) | target.url | ||
| Data | principal.asset.asset_id | Source VM UUID (src_uuid) | SrcUUID | principal.asset.product_object_id | |
| Data | target.asset.asset_id | Destination VM UUID (dst_uuid) | DstUUID | target.asset.product_object_id | |
| Data | about.labels.key/value additional.fields.key/value.string_value | http_headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| Data | about.labels.key/value additional.fields.key/value.string_value | UUID for rule (rule_uuid) | PanOSRuleUUID | security_result.rule_id | |
| Data | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | network.application_protocol_version | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | principal.asset.category | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | principal.asset.hardware.model | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | principal.asset.hardware.manufacturer | ||
| Data | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | principal.platform | ||
| Data | principal.asset.software.version | Source Device OS Version (src_osversion) | principal.platform_version | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Hostname (src_host) | principal.hostname | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | target.asset.category | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | target.asset.hardware.model | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | target.asset.hardware.manufacturer | ||
| Data | target.asset.platform_software.platform target.labels.key/value | Destination Device OS Family (dst_osfamily) | target.platform | ||
| Data | target.asset.software.version | Destination Device OS Version (dst_osversion) | target.platform_version | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | intermediary.resource.product_object_id | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | target.resource.attribute.labels | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | target.resource.name | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | principal.asset.asset_id | ||
| Data | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Res Timestamp (high_res_timestamp) | additional.fields.key/value.string_value | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | security_result.summary | ||
| GlobalProtect | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | PanOSVirtualSystem | intermediary.asset.attribute.labels | |
| GlobalProtect | principal.user.email_address principal.user.userid principal.administrative_domain | Source User (srcuser) | PanOSSourceUserName | target.user.email_address target.user.userid | |
| GlobalProtect | principal.asset.platform_software.platform(enum) | Client OS (client_os) | PanOSEndpointOSType | principal.platform | |
| GlobalProtect | principal.asset.platform_software.platform_version | Client OS Version (client_os_ver) | PanOSEndpointOSVersion | principal.platform_version | |
| GlobalProtect | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| GlobalProtect | about.labels.key/value additional.fields.key/value.string_value | Gateway Name (gateway) | PanOSAttemptedGateways | target.resource.name | |
| GlobalProtect | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | intermediary.asset.attribute.labels | ||
| GlobalProtect | target.hostname | Device Name (device_name) | intermediary.hostname | ||
| GlobalProtect | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| CORRELATION | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | VirtualSystem | intermediary.asset.attribute.labels | |
| CORRELATION | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | vSrcName | intermediary.asset.attribute.labels | |
| CORRELATION | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | VirtualSystemID | intermediary.resource.product_object_id | |
| GTP | additional.fields.key/value.string_value | Virtual System (vsys) | intermediary.asset.attribute.labels | ||
| GTP | target.ip | Remote User IP (remote_user_ip) | principal.ip | ||
| GTP | additional.fields.key/value.string_value | Remote User ID (remote_user_id) | principal.user.userid | ||
| GTP | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | additional.fields.key/value.string_value |
Servicio de registro de Strata Firewall de Palo Alto Networks
Descripción general
El servicio de registro de Strata de Palo Alto Networks® proporciona almacenamiento y agregación de registros centralizados basados en la nube para tus firewalls locales y virtuales (nube privada y nube pública), para Prisma Access y para servicios entregados en la nube, como Cortex XDR.El servicio de registro de Strata es seguro, resiliente y tolerante a fallas, y garantiza que tus datos de registro estén actualizados y disponibles cuando los necesites. Proporciona una infraestructura de registro escalable que alivia la necesidad de planificar e implementar colectores de registros para satisfacer tus necesidades de retención de registros. Si ya tienes recopiladores de registros locales, el nuevo servicio de registro de Strata puede complementar tu configuración existente. Puedes aumentar tu infraestructura existente de recopilación de registros con el servicio de registro de Strata basado en la nube para expandir la capacidad operativa a medida que crece tu empresa o para satisfacer las necesidades de capacidad de las ubicaciones nuevas.Con este servicio, Palo Alto Networks se encarga del mantenimiento y la supervisión continuos de la infraestructura de registro para que puedas concentrarte en tu empresa.
Verifica los formatos de registro y las versiones de PAN-OS que admite el analizador del servicio de registro de Strata. En la siguiente tabla, se enumeran los formatos de registro y las versiones correspondientes de PAN-OS que admite el analizador del servicio de registro de Strata:
Formato de registro Versión de PAN-OS JSON 12.1 Verifica los tipos de registros del firewall de Palo Alto Networks que admite el analizador de SecOps de Google. El analizador de SecOps de Google admite los siguientes tipos de registros de firewall de Palo Alto Networks:
- Tráfico
- Amenaza
- Inspección de túneles
- Sistema
- Coincidencia de HIP
- IP-Tag
- User-ID
- Desencriptación
- Autenticación
- Filtros de URL
- GlobalProtect
Implementación del servicio de registro de Strata
- Asegúrate de que el producto de firewall de Palo Alto Networks esté implementado y configurado correctamente. Para obtener instrucciones de configuración detalladas, consulta la Documentación de PAN-OS y, luego, sigue este documento de implementación antes de enviar registros al servicio de registro de Strata Requisitos previos para la implementación del servicio de registro de Strata.
Comienza a enviar registros al servicio de Strata Logging:
Para comenzar a enviar registros al servicio de Strata Logging, sigue estos pasos:
- Instala una versión compatible de PAN-OS®
- Activa el servicio de registro de Strata: La activación del servicio de registro de Strata incluye el aprovisionamiento del certificado que los firewalls necesitan para conectarse de forma segura al servicio de registro de Strata.
- Incorpora firewalls al servicio de registro de Strata con o sin Panorama
Para conocer los pasos detallados de incorporación, consulta la Documentación.
Reenvía registros del servicio de registro de Strata
Para satisfacer tus necesidades de almacenamiento, informes y supervisión a largo plazo, o bien de cumplimiento y legales, puedes configurar el Servicio de registro de Strata para que reenvíe los registros a un servidor HTTPS o a los siguientes SIEM:
- Exabeam
- Google Chronicle
- Microsoft Sentinel
- Recopilador de eventos HTTP (HEC) de Splunk
Usa el método de reenvío HTTPS para reenviar los registros con el Servicio de registro de Strata. Para obtener información detallada, consulta esta documentación.
Formatos de registro admitidos
El analizador de firewall de Strata Logging Service de Palo Alto Networks admite registros en formato JSON.
Registros de muestra admitidos
JSON
{"source": "Palo Alto Networks FLS LF", "host": "dummy-loghost", "time": "1730265996460", "event": {"TimeReceived": "2024-10-30T05:25:50.000000Z", "DeviceSN": "no-serial", "LogType": "TRAFFIC", "Subtype": "end", "ConfigVersion": "10.2", "TimeGenerated": "2024-10-30T05:25:40.000000Z", "SourceAddress": "198.51.100.6", "DestinationAddress": "198.51.100.6", "NATSource": "", "NATDestination": "", "Rule": "egress-dns-ping-traceroute", "SourceUser": null, "DestinationUser": null, "Application": "dns-base", "VirtualLocation": "vsys1", "FromZone": "VA8280-RN", "ToZone": "inter-fw", "InboundInterface": "tunnel.101", "OutboundInterface": "tunnel.4005", "LogSetting": "Cortex Data Lake", "SessionID": 754194, "RepeatCount": 1, "SourcePort": 53578, "DestinationPort": 53, "NATSourcePort": 0, "NATDestinationPort": 0, "Protocol": "udp", "Action": "allow", "Bytes": 214, "BytesSent": 72, "BytesReceived": 142, "PacketsTotal": 2, "SessionStartTime": "2024-10-30T05:25:10.000000Z", "SessionDuration": 0, "URLCategory": "any", "SequenceNo": 7382192512716388639, "SourceLocation": "198.51.100.6-198.51.255.255", "DestinationLocation": "198.51.100.6-198.51.255.255", "PacketsSent": 1, "PacketsReceived": 1, "SessionEndReason": "aged-out", "DGHierarchyLevel1": 65537, "DGHierarchyLevel2": 65538, "DGHierarchyLevel3": 65541, "DGHierarchyLevel4": 0, "VirtualSystemName": "", "DeviceName": "VA8280-RN", "ActionSource": "from-policy", "SourceUUID": null, "DestinationUUID": null, "IMSI": 0, "IMEI": null, "ParentSessionID": 0, "ParentStarttime": "1970-01-01T00:00:00.000000Z", "Tunnel": "N/A", "EndpointAssociationID": 72057594037927936, "ChunksTotal": 0, "ChunksSent": 0, "ChunksReceived": 0, "RuleUUID": "95cfc3cc-cb00-4758-af1d-de9ab5f07f97", "HTTP2Connection": 0, "LinkChangeCount": 0, "SDWANPolicyName": null, "LinkSwitches": null, "SDWANCluster": null, "SDWANDeviceType": null, "SDWANClusterType": null, "SDWANSite": null, "DynamicUserGroupName": null, "X-Forwarded-ForIP": null, "SourceDeviceCategory": null, "SourceDeviceProfile": null, "SourceDeviceModel": null, "SourceDeviceVendor": null, "SourceDeviceOSFamily": null, "SourceDeviceOSVersion": null, "SourceDeviceHost": null, "SourceDeviceMac": null, "DestinationDeviceCategory": null, "DestinationDeviceProfile": null, "DestinationDeviceModel": null, "DestinationDeviceVendor": null, "DestinationDeviceOSFamily": null, "DestinationDeviceOSVersion": null, "DestinationDeviceHost": null, "DestinationDeviceMac": null, "ContainerID": null, "ContainerNameSpace": null, "ContainerName": null, "SourceEDL": null, "DestinationEDL": null, "GPHostID": null, "EndpointSerialNumber": null, "SourceDynamicAddressGroup": null, "DestinationDynamicAddressGroup": null, "HASessionOwner": null, "TimeGeneratedHighResolution": "2024-10-30T05:25:41.009000Z", "NSSAINetworkSliceType": null, "NSSAINetworkSliceDifferentiator": null}}"
Referencia de la asignación de campos: Campos de registros a campos del UDM
En esta sección, se explica cómo el analizador asigna los campos de registro del firewall del servicio de registro de Strata de Palo Alto Networks a los campos de eventos del UDM de Google para cada tipo de registro.
Consulta las siguientes secciones para obtener referencias de asignación de cada tipo de registro:
- Sistema
- Amenaza
- Tráfico
- ID de usuario
- HIP match
- Etiqueta de IP
- Desencriptación
- Túnel
- Authentication
- URL
- GlobalProtect
- SCTP
- Auditar
Sistema
En la siguiente tabla, se enumeran los campos de registro del tipo de registro del sistema y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| AgentContentVersion | additional.fields.key/value.string_value |
| AgentDataCollectionStatus | target.resource.attribute.labels |
| AgentID | target.resource.attribute.labels |
| AgentIsolationStatus | target.resource.attribute.labels |
| AgentStatus | target.resource.attribute.labels |
| AgentVersion | target.asset.software.version |
| ConfigVersion | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DeviceGroup | target.group.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EndpointCPUArchitecture | target.asset.hardware.cpu_platform |
| EndpointDeviceDomain | target.asset.administrative_domain |
| EndpointDeviceName | target.asset.hostname |
| EndpointIPaddress | target.asset.ip |
| VDIEndpoint | target.asset.attribute.labels |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointOSVersion | target.platform_version |
| AgentTimeZoneOffset | additional.fields.key/value.string_value |
| EndpointUserDomain | additional.fields.key/value.string_value |
| EndpointUserName | target.user.user_display_name |
| EndpointUserUUID | target.user.userid |
| EventComponent | additional.fields.key/value.string_value |
| EventDescription | metadata.description |
| EventName | additional.fields.key/value.string_value |
| EventTime | metadata.event_timestamp |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogCategory | security_result.category_details |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| LogSourceID | target.resource.attribute.labels |
| LogSourceName | observer.asset.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| LogTime | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Severity | security_result.severity |
| Subtype | metadata.product_event_type |
| Template | target.resource.attribute.labels |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
Amenaza
En la siguiente tabla, se enumeran los campos de registro del tipo de registro de amenazas y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| ApplianceOrCloud | additional.fields.key/value.string_value |
| CloudHostname | additional.fields.key/value.string_value |
| CloudReportID | security_result.detection_fields.key/value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DirectionOfAttack | security_result.detection_fields.key/value |
| DomainEDL | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| FileName | target.file.names |
| FileHash | target.file.sha1 |
| FileType | additional.fields.key/value.string_value |
| FileURL | target.url |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HostID | principal.asset.asset_id |
| HTTP2Connection | network.application_protocol_version |
| HTTPMethod | network.http.method |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| LocalDeepLearningAnalyzed | additional.fields.key/value.string_value |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| PartialHash | additional.fields.key/value.string_value |
| PayloadProtocolID | additional.fields.key/value.string_value |
| Packet | additional.fields.key/value.string_value |
| PacketID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| RecipientEmail | target.user.email_addresses |
| ReportID | security_result.detection_fields.key/value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SenderEmail | principal.user.email_addresses |
| SequenceNo | metadata.product_log_id |
| SessionID | network.session_id |
| Severity | security_result.severity |
| SigFlags | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| EmailSubject | network.email.subject |
| ApplicationTechnology | additional.fields.key/value.string_value |
| ThreatCategory | security_result.detection_fields.key/value.key/value |
| ThreatID | security_result.threat_id |
| ThreatName | security_result.threat_name |
| ThreatNameFirewall | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLDomain | target.domain.name |
| URLCounter | additional.fields.key/value.string_value |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| Verdict | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-ForIP | principal.ip |
Tráfico
En la siguiente tabla, se enumeran los campos de registro del tipo de registro de tráfico y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| ActionSource | additional.fields.key/value.string_value |
| AIFwdError | additional.fields.key/value.string_value |
| AITraffic | additional.fields.key/value.string_value |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| BytesReceived | network.received_bytes |
| BytesSent | network.sent_bytes |
| Bytes | additional.fields.key/value.string_value |
| ChunksReceived | additional.fields.key/value.string_value |
| ChunksSent | additional.fields.key/value.string_value |
| ChunksTotal | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| EndpointAssociationID | additional.fields.key/value.string_value |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HASessionOwner | additional.fields.key/value.string_value |
| GPHostID | additional.fields.key/value.string_value |
| HTTP2Connection | network.application_protocol_version |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsOffloaded | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| LinkChangeCount | additional.fields.key/value.string_value |
| LinkSwitches | additional.fields.key/value.string_value |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| SDWANPolicyName | additional.fields.key/value.string_value |
| Protocol | network.ip_protocol |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SDWANFECRatio | additional.fields.key/value.string_value |
| SDWANCluster | additional.fields.key/value.string_value |
| SDWANClusterType | additional.fields.key/value.string_value |
| SDWANDeviceType | additional.fields.key/value.string_value |
| SDWANSite | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionStartTime | additional.fields.key/value.string_value |
| SessionTracker | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| SessionDuration | network.session_duration |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLCategory | target.url_metadata.categories |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-ForIP | principal.ip |
User-ID
En la siguiente tabla, se enumeran los campos de registro del tipo de registro User-ID y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| AuthFactorNo | security_result.detection_fields.key/value |
| AuthenticatedUserDomain | target.user.administrative_domain |
| AuthenticatedUserName | target.user.userid |
| AuthenticatedUserUUID | target.user.product_object_id |
| ConfigVersion | additional.fields.key/value.string_value |
| CountofRepeats | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationPort | target.port |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EventID | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsDuplicateUser | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MappingDataSource | additional.fields.key/value.string_value |
| MappingDataSourceName | additional.fields.key/value.string_value |
| MappingDataSourceType | additional.fields.key/value.string_value |
| MappingTimeout | additional.fields.key/value.string_value |
| MFAFactorType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SourceIP | principal.ip |
| SourcePort | principal.port |
| Subtype | metadata.product_event_type |
| Tag | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| UGFlags | additional.fields.key/value.string_value |
| User | target.user.userid |
| UserGroupFound | additional.fields.key/value.string_value |
| UserIdentifiedBySource | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Coincidencia de HIP
En la siguiente tabla, se enumeran los campos de registro del tipo de registro de coincidencia de HIP y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| ConfigVersion | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EndpointDeviceName | principal.asset.hostname |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| HipMatchName | target.resource.attribute.labels |
| HipMatchType | target.resource.attribute.labels |
| HostID | principal.asset.asset_id |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | metadata.product_event_type |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Source | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceIP | principal.ip |
| SourceIPv6 | principal.ip |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| TimestampDeviceIdentification | principal.asset.first_seen_time |
| UUID | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
Etiqueta de IP
En la siguiente tabla, se enumeran los campos de registro del tipo de registro de etiquetas de IP y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| ConfigVersion | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EventID | additional.fields.key/value.string_value |
| IPSubnetRange | network.ip_subnet_range |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSetting | target.resource.attribute.labels |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MappingDataSource | additional.fields.key/value.string_value |
| MappingDataSourceSubType | additional.fields.key/value.string_value |
| MappingDataSourceType | additional.fields.key/value.string_value |
| MappingTimeout | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| RuleMatched | security_result.rule_name |
| RuleMatchedUUID | security_result.rule_id |
| SequenceNo | metadata.product_log_id |
| SourceIP | principal.ip |
| Subtype | metadata.product_event_type |
| TagName | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
Desencriptación
En la siguiente tabla, se enumeran los campos de registro del tipo de registro Decryption y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| CertificateFlags | additional.fields.key/value.string_value |
| CertificateSerial | network.tls.server.certificate.serial |
| CertificateSize | additional.fields.key/value.string_value |
| CertificateVersion | network.tls.server.certificate.version |
| ChainStatus | additional.fields.key/value.string_value |
| ApplicationCharacteristics | additional.fields.key/value.string_value |
| ClientToFirewall | additional.fields.key/value.string_value |
| CommonName | additional.fields.key/value.string_value |
| CommonNameLength | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| Cpadding | additional.fields.key/value.string_value |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| Domain | target.hostname |
| EllipticCurve | network.tls.curve |
| ErrorIndex | additional.fields.key/value.string_value |
| ErrorMessage | additional.fields.key/value.string_value |
| Fingerprint | network.tls.server.certificate.md5/sha1/sha256 |
| FirewallToClient | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsCertECDSA | additional.fields.key/value.string_value |
| IsCertRSA | additional.fields.key/value.string_value |
| IsCertCNTruncated | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| IsForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsIssuerCNTruncated | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| IsNAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| PacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsResumeSession | additional.fields.key/value.string_value |
| IsRootCNTruncated | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSNITruncated | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| IssuerCommonName | network.tls.server.certificate.issuer |
| IssuerNameLength | additional.fields.key/value.string_value |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| TimeNotAfter | additional.fields.key/value.string_value |
| TimeNotBefore | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| Padding | additional.fields.key/value.string_value |
| Padding3 | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| PolicyName | additional.fields.key/value.string_value |
| Protocol | network.ip_protocol |
| ProxyType | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| RootCommonName | additional.fields.key/value.string_value |
| RootCNLength | additional.fields.key/value.string_value |
| RootStatus | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SessionID | network.session_id |
| ServerNameIndication | network.tls.client.server_name |
| SNILength | additional.fields.key/value.string_value |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeReceivedManagementPlane | additional.fields.key/value.string_value |
| TLSAuth | additional.fields.key/value.string_value |
| TLSEncryptionAlgorithm | additional.fields.key/value.string_value |
| TLSKeyExchange | additional.fields.key/value.string_value |
| TLSVersion | network.tls.version |
| ToZone | additional.fields.key/value.string_value |
| Tpadding | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| Vpadding | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Túnel
En la siguiente tabla, se enumeran los campos de registro del tipo de registro Túnel y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| AccessPointName | additional.fields.key/value.string_value |
| Action | security_result.action |
| ActionSource | additional.fields.key/value.string_value |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| BytesReceived | network.received_bytes |
| BytesSent | network.sent_bytes |
| Bytes | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| LoggingServiceID | additional.fields.key/value.string_value |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MobileAreaCode | additional.fields.key/value.string_value |
| MobileBaseStationCode | additional.fields.key/value.string_value |
| MobileCountryCode | additional.fields.key/value.string_value |
| MobileIP | additional.fields.key/value.string_value |
| MobileNetworkCode | additional.fields.key/value.string_value |
| MobileSubscriberISDN | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceDifferentiator | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsDroppedMax | additional.fields.key/value.string_value |
| PacketsDroppedStrict | additional.fields.key/value.string_value |
| PacketsDroppedTunnel | additional.fields.key/value.string_value |
| PacketsDroppedProtocol | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| ProtocolDataUnitsessionID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| RadioAccessTechnology | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionStartTime | additional.fields.key/value.string_value |
| SessionTracker | additional.fields.key/value.string_value |
| Severity | security_result.severity |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| StandardPortsOfApp | additional.fields.key/value.string_value |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| SessionDuration | network.session_duration |
| Tunnel | additional.fields.key/value.string_value |
| TunnelCauseCode | additional.fields.key/value.string_value |
| TunnelEndpointID1 | additional.fields.key/value.string_value |
| TunnelEndpointID2 | additional.fields.key/value.string_value |
| TunnelEventCode | additional.fields.key/value.string_value |
| TunnelEventType | additional.fields.key/value.string_value |
| TunnelInspectionRule | additional.fields.key/value.string_value |
| TunnelInterface | additional.fields.key/value.string_value |
| TunnelMessageType | additional.fields.key/value.string_value |
| TunnelRemoteIMSIID | additional.fields.key/value.string_value |
| TunnelRemoteUserIP | principal.ip |
| TunnelSessionsClosed | additional.fields.key/value.string_value |
| TunnelSessionsCreated | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLCategory | target.url_metadata.categories |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Autenticación
En la siguiente tabla, se enumeran los campos de registro del tipo de registro Authentication y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| AuthenticationDescription | security_result.description |
| AuthEvent | metadata.description |
| AuthFactorNo | security_result.detection_fields.key/value |
| AuthenticationPolicy | security_result.detection_fields.key/value |
| AuthenticationProtocol | additional.fields.key/value.string_value |
| AuthServerProfile | additional.fields.key/value.string_value |
| AuthenticatedUserDomain | target.administrative_domain |
| AuthenticatedUserName | target.user.userid |
| AuthenticatedUserUUID | target.user.product_object_id |
| ClientType | additional.fields.key/value.string_value |
| ClientTypeName | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| Location | target.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogType | additional.fields.key/value.string_value |
| MFAAuthenticationID | additional.fields.key/value.string_value |
| MFAVendor | additional.fields.key/value.string_value |
| NormalizeUser | target.user.user_display_name |
| Object | target.resource.name |
| RuleMatched | security_result.rule_name |
| RuleMatchedUUID | security_result.rule_id |
| AuthCacheServiceRegion | additional.fields.key/value.string_value |
| SessionID | network.session_id |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceIP | principal.ip |
| TimeGenerated | metadata.event_timestamp |
| User | target.user.userid |
| UserAgentString | network.http.user_agent |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Subtype | metadata.product_event_type |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
URL
En la siguiente tabla, se enumeran los campos de registro del tipo de registro de URL y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| CloudHostname | additional.fields.key/value.string_value |
| CloudReportID | security_result.detection_fields.key/value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentType | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DirectionOfAttack | security_result.detection_fields.key/value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| FileURL | target.url |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HostID | principal.asset.asset_id |
| HTTP2Connection | network.application_protocol_version |
| HTTPHeaders | additional.fields.key/value.string_value |
| HTTPMethod | network.http.method |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| InlineMLVerdict | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| Packet | additional.fields.key/value.string_value |
| PacketID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| Referer | network.http.referral_url |
| HTTPRefererFQDN | additional.fields.key/value.string_value |
| HTTPRefererPort | additional.fields.key/value.string_value |
| HTTPRefererProtocol | additional.fields.key/value.string_value |
| HTTPRefererURLPath | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionID | network.session_id |
| Severity | security_result.severity |
| SigFlags | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URL | target.url_metadata.URL |
| URLCategory | target.url_metadata.categories |
| URLCategoryList | additional.fields.key/value.string_value |
| URLDomain | target.domain.name |
| URLCounter | additional.fields.key/value.string_value |
| UserAgent | network.http.user_agent |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-For | additional.fields.key/value.string_value |
| X-Forwarded-ForIP | principal.ip |
GlobalProtect
En la siguiente tabla, se enumeran los campos de registro del tipo de registro de GlobalProtect y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| AttemptedGateways | additional.fields.key/value.string_value |
| AuthMethod | extensions.auth.auth_details |
| ConnectionMethod | additional.fields.key/value.string_value |
| ConnectionErrorID | additional.fields.key/value.string_value |
| ConnectionError | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| EndpointDeviceName | principal.asset.hostname |
| GlobalProtectClientVersion | additional.fields.key/value.string_value |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointSN | principal.asset.hardware.serial_number |
| EventIDValue | additional.fields.key/value.string_value |
| Gateway | target.resource.name |
| GatewayPriority | additional.fields.key/value.string_value |
| GatewaySelectionType | additional.fields.key/value.string_value |
| GlobalProtectGatewayLocation | target.location.country_or_region |
| HostID | principal.asset.asset_id |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LoginDuration | network.session_duration |
| Description | security_result.description |
| Portal | target.hostname |
| PrivateIPv4 | principal.ip |
| PrivateIPv6 | principal.ip |
| ProjectName | additional.fields.key/value.string_value |
| PublicIPv4 | principal.nat_ip |
| PublicIPv6 | principal.nat_ip |
| QuarantineReason | security_result.summary |
| SequenceNo | metadata.product_log_id |
| SourceRegion | principal.location.country_or_region |
| SourceUserName | principal.user.user_display_name |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SSLResponseTime | additional.fields.key/value.string_value |
| Stage | additional.fields.key/value.string_value |
| EventStatus | additional.fields.key/value.string_value |
| LogSubtype | metadata.product_event_type |
| TunnelType | additional.fields.key/value.string_value |
| VirtualSystem | intermediary.asset.attribute.labels |
| VirtualSystemName | intermediary.asset.attribute.labels |
| EndpointOSVersion | principal.platform_version |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | metadata.product_event_type |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualSystemID | intermediary.resource.product_object_id |
SCTP
En la siguiente tabla, se enumeran los campos de registro del tipo de registro SCTP y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| AssocationEndReason | additional.fields.key/value.string_value |
| ChunksReceived | additional.fields.key/value.string_value |
| ChunksSent | additional.fields.key/value.string_value |
| ChunksTotal | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceClass | target.asset.category |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationIP | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DiamAppID | additional.fields.key/value.string_value |
| DiamAvpCode | additional.fields.key/value.string_value |
| DiameterCommandCode | additional.fields.key/value.string_value |
| DiameterRequestFlag | additional.fields.key/value.string_value |
| DeviceName | principal.asset.hostname |
| SCTPEventType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLFiltering | additional.fields.key/value.string_value |
| IsWildfire | additional.fields.key/value.string_value |
| LogAction | additional.fields.key/value.string_value |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MapAppCode | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PayloadProtocolID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SccpCallingGt | additional.fields.key/value.string_value |
| SccpCallingSSN | additional.fields.key/value.string_value |
| SctpCauseCode | additional.fields.key/value.string_value |
| SctpChunkType | additional.fields.key/value.string_value |
| SctpFilter | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionTracker | additional.fields.key/value.string_value |
| Severity | security_result.severity |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceIP | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VerificationTag1 | additional.fields.key/value.string_value |
| VerificationTag2 | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Auditoría
En la siguiente tabla, se enumeran los campos de registro del tipo Registro de auditoría y sus campos de UDM correspondientes.
| Log field | UDM mapping |
|---|---|
| EventCategory | network.http.method |
| EventDescription | metadata.description |
| EventDestinationURL | target.url |
| EventDestinationUserUserID | target.user.userid |
| DestinationVendor | additional.fields.key/value.string_value |
| EventDetails | additional.fields.key/value.string_value |
| EventID | metadata.product_log_id |
| EventName | additional.fields.key/value.string_value |
| EventResult | security_result.summary |
| EventSourceUserUserID | principal.user.userid |
| EventTime | metadata.event_timestamp |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| Subtype | metadata.product_event_type |
| TSGID | additional.fields.key/value.string_value |
| Vendor | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
Referencia de asignación de campos: Tipos de registros a tipo de evento de UDM
En la siguiente tabla, se enumeran los tipos de registros del firewall del servicio de registro de Strata de Palo Alto Networks y sus tipos de eventos de UDM correspondientes.
| Tipo de registro | Tipo de evento de UDM |
| Tráfico | NETWORK_CONNECTION |
| Amenaza | NETWORK_CONNECTION |
| Filtrado de URLs | NETWORK_CONNECTION |
| Túnel | NETWORK_CONNECTION |
| Sistema |
Si el valor del subtipo es "dhcp", se establece NETWORK_DHCP. Si el valor del subtipo es "auth", se establece USER_LOGIN. Si el valor de la descripción es "logged in", se establece USER_LOGIN. Si el valor de la descripción es "logged out", se establece USER_LOGOUT. Para otros valores del subtipo, se establece GENERIC_EVENT. |
| HIP Match | NETWORK_CONNECTION |
| Etiqueta de IP | GENERIC_EVENT |
| User-ID | USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED
Si el valor del subtipo es "login", se establece USER_LOGIN. Si el valor del subtipo es "logout", se establece USER_LOGOUT. Si el subtipo no contiene ningún valor, se establece USER_UNCATEGORIZED. |
| Desencriptación | NETWORK_CONNECTION |
| Autenticación | STATUS_UNCATEGORIZED |
| Globalprotect | USER_LOGIN/USER_LOGOUT/USER_RESOURCE_ACCESS
Si el valor del subtipo es "auth", se establece USER_LOGIN. Si el valor del subtipo es "logout", se establece USER_LOGOUT. Si el subtipo no contiene ningún valor, se establece USER_RESOURCE_ACCESS. |
| SCTP | NETWORK_CONNECTION |
| Auditoría | NETWORK_CONNECTION |
¿Qué sigue?
¿Necesitas más ayuda? Obtén respuestas de miembros de la comunidad y profesionales de Google SecOps.