Mengumpulkan log firewall Palo Alto Networks
Firewall Palo Alto Networks
Ringkasan
Dokumen ini menjelaskan cara mengonfigurasi syslog dan penerus Google SecOps untuk mengumpulkan log firewall Palo Alto Networks. Dokumen ini juga menjelaskan cara kolom log firewall Palo Alto Networks dipetakan ke kolom Model Data Terpadu (UDM) Google SecOps. Untuk mengetahui ringkasan tentang penyerapan data Google SecOps, lihat Penyerapan data ke Google SecOps. Label penyerapan mengidentifikasi parser yang menormalisasi data log mentah ke format UDM terstruktur. Informasi dalam dokumen ini berlaku untuk parser dengan label penyerapan PAN_FIREWALL.
Sebelum memulai
- Pastikan produk firewall Palo Alto Networks di-deploy dan dikonfigurasi dengan benar. Untuk petunjuk penyiapan mendetail, lihat Dokumentasi PAN-OS.
Untuk memahami komponen yang di-deploy untuk mengumpulkan log firewall Palo Alto Networks, tinjau arsitektur deployment. Setiap deployment pelanggan mungkin berbeda dari representasi ini dan mungkin lebih kompleks. Diagram berikut menunjukkan cara mengonfigurasi syslog di firewall Palo Alto Networks dan menginstal penerus Google SecOps di server Linux untuk meneruskan data log ke Google SecOps. Parser mendukung log yang ditulis dalam format data berikut: Comma Separated Values (CSV), Common Event Format (CEF), dan Log Event Extended Format (LEEF).
Verifikasi format log dan versi PAN-OS yang didukung parser Google SecOps. Tabel berikut mencantumkan format log dan versi PAN-OS yang sesuai yang didukung oleh parser Google SecOps:
Format log Versi PAN-OS CSV 10.1.3 CEF 10.0.0 LEEF 9.1.0 Verifikasi jenis log firewall Palo Alto Networks yang didukung oleh parser Google SecOps. Parser Google SecOps mendukung jenis log firewall Palo Alto Networks berikut:
- Traffic
- Ancaman
- Pengiriman WildFire
- Pemeriksaan terowongan
- Konfigurasi
- Sistem
- Pencocokan HIP
- IP-Tag
- User-ID
- Dekripsi
- Autentikasi
- Pemfilteran URL
- Pemfilteran data
- GlobalProtect
- Korelasi
- GTP
- SCTP
- Audit
Untuk mengetahui informasi selengkapnya tentang jenis log firewall Palo Alto Networks, lihat Jenis log PAN-OS.
Pastikan semua sistem dalam arsitektur deployment dikonfigurasi dalam zona waktu UTC.
Sebelum menggunakan parser firewall Palo Alto Networks, tinjau perubahan dalam pemetaan kolom antara parser sebelumnya dan parser firewall Palo Alto Networks saat ini. Sebagai bagian dari migrasi, pastikan aturan, penelusuran, dasbor, atau proses lain yang bergantung pada kolom asli menggunakan kolom yang diperbarui.
Misalnya, pada versi parser sebelumnya, kolom log
categorydipetakan ke kolom UDMsecurity_result.description. Di parser firewall Palo Alto Networks saat ini, kolom logcategorydipetakan ke kolom UDMsecurity_result.category_details. Jika Anda bermigrasi ke parser firewall Palo Alto Networks saat ini dan menggunakan kolomcategorydalam aturan, Anda harus mengubah aturan untuk menggunakan kolom UDMsecurity_result.category_detailsdari parser saat ini.
Mengonfigurasi syslog dan penerus Google Security Operations
Untuk mengonfigurasi syslog dan penerus Google SecOps, selesaikan langkah-langkah berikut:
- Untuk memantau log CSV, konfigurasi profil server syslog. Untuk mengetahui informasi selengkapnya, lihat Mengonfigurasi profil server syslog. Saat mengonfigurasi profil server syslog, tentukan "Default" sebagai format log kustom.
- Untuk memantau log CEF, konfigurasi firewall Palo Alto Networks untuk meneruskan log CEF. Untuk mengetahui informasi selengkapnya, download PDF panduan Integrasi CEF PAN-OS dan lihat bagian "Konfigurasi NGFW Palo Alto Networks untuk menghasilkan peristiwa CEF".
- Untuk memantau log LEEF, konfigurasi profil server syslog. Untuk mengetahui informasi selengkapnya, lihat Penerusan log kustom dalam format LEEF.
Konfigurasi penerusan Google SecOps untuk mengirim log ke Google Security Operations. Untuk mengetahui informasi selengkapnya, lihat Menginstal dan mengonfigurasi penerusan di Linux. Berikut adalah contoh konfigurasi penerus Google SecOps:
- syslog: common: enabled: true data_type: PAN_FIREWALL batch_n_seconds: 10 batch_n_bytes: 1048576 tcp_address: 0.0.0.0:10518 connection_timeout_sec: 60
Mengonfigurasi penerusan syslog di PAN Firewall
Membuat profil server syslog
- Login ke Konsol Pengelolaan Firewall Palo Alto Networks.
- Buka Perangkat > Profil Server > Syslog.
- Klik Tambahkan untuk membuat profil server baru.
- Berikan detail konfigurasi berikut:
- Name: Masukkan nama deskriptif (misalnya,
Google SecOps BindPlane). - Lokasi: Pilih sistem virtual (vsys) atau Bersama tempat profil ini akan tersedia.
- Name: Masukkan nama deskriptif (misalnya,
- Klik Servers > Add untuk mengonfigurasi server syslog.
- Berikan detail konfigurasi server berikut:
- Name: Masukkan nama deskriptif untuk server (misalnya,
BindPlane Agent). - Server Syslog: Masukkan alamat IP Agen BindPlane.
- Transport: Pilih UDP atau TCP, bergantung pada konfigurasi BindPlane Agent Anda (UDP adalah default).
- Port: Masukkan nomor port Agen BindPlane (misalnya,
514). - Format: Pilih BSD (default) atau IETF, bergantung pada persyaratan Anda.
- Fasilitas: Pilih LOG_USER (default) atau fasilitas lain sesuai kebutuhan.
- Name: Masukkan nama deskriptif untuk server (misalnya,
- Klik OK untuk menyimpan profil server syslog.
Opsional: Mengonfigurasi format log kustom untuk CEF atau LEEF
Jika Anda memerlukan log CEF (Common Event Format) atau LEEF (Log Event Extended Format) dan bukan CSV:
- Di Profil Server Syslog, pilih tab Custom Log Format.
- Konfigurasi format log kustom untuk setiap jenis log (Config, System, Threat, Traffic, URL, Data, WildFire, Tunnel, Authentication, User-ID, HIP Match).
- Untuk konfigurasi format CEF, lihat Panduan Konfigurasi CEF Palo Alto Networks.
- Klik OK untuk menyimpan konfigurasi.
Membuat profil penerusan log
- Buka Objects > Log Forwarding.
- Klik Tambahkan untuk membuat profil penerusan log baru.
- Berikan detail konfigurasi berikut:
- Nama: Masukkan nama profil (misalnya,
Google SecOps Forwarding). Jika Anda ingin firewall otomatis menetapkan profil ini ke aturan dan zona keamanan baru, beri namadefault.
- Nama: Masukkan nama profil (misalnya,
- Untuk setiap jenis log yang ingin Anda teruskan (Traffic, Threat, WildFire Submission, URL Filtering, Data Filtering, Tunnel, Authentication), konfigurasikan hal berikut:
- Klik Tambahkan di bagian jenis log yang sesuai.
- Syslog: Pilih profil server syslog yang Anda buat (misalnya,
Google SecOps BindPlane). - Tingkat Keparahan Log: Pilih tingkat keparahan yang akan diteruskan (misalnya, Semua).
- Klik OK untuk menyimpan profil penerusan log.
Menerapkan profil penerusan log ke kebijakan keamanan
- Buka Kebijakan > Keamanan.
- Pilih aturan keamanan yang ingin Anda aktifkan penerusan log-nya.
- Klik aturan untuk mengeditnya.
- Buka tab Tindakan.
- Di menu Log Forwarding, pilih profil penerusan log yang Anda buat (misalnya,
Google SecOps Forwarding). - Klik OK untuk menyimpan konfigurasi kebijakan keamanan.
Mengonfigurasi setelan log untuk log sistem
- Buka Perangkat > Setelan Log.
- Untuk setiap jenis log (Sistem, Konfigurasi, User-ID, HIP Match, Global Protect, IP-Tag, SCTP) dan tingkat keparahan, pilih profil server syslog yang Anda buat.
- Klik Oke untuk menyimpan setelan log.
Lakukan commit perubahan
- Klik Commit di bagian atas antarmuka web firewall.
- Tunggu hingga commit berhasil diselesaikan.
- Pastikan log dikirim ke agen Bindplane dengan memeriksa konsol Google SecOps untuk log firewall Palo Alto Networks yang masuk.
Meneruskan Log ke Google SecOps menggunakan agen Bindplane
- Instal dan siapkan Mesin Virtual Linux.
- Instal dan konfigurasi agen BindPlane di Linux untuk meneruskan log ke Google SecOps. Untuk mengetahui informasi selengkapnya tentang cara menginstal dan mengonfigurasi agen BindPlane, lihat petunjuk penginstalan dan konfigurasi agen BindPlane.
Jika Anda mengalami masalah saat membuat feed, hubungi dukungan SecOps Google.
Format log yang didukung
Parser firewall Palo Alto Networks mendukung log dalam format LEEF, CEF, dan CSV.
Contoh log yang didukung
LEEF
<14>Jan 22 02:20:19 device_host LEEF:1.0|Palo Alto Networks|PAN-OS Syslog Integration|10.2.12-h4|Microsoft MSOFFICE(52033)|ReceiveTime=2025/01/22 02:20:18|SerialNumber=01250100xxxx|cat=THREAT|Subtype=wildfire|devTime=Jan 22 2025 08:20:18 GMT|src=198.50.100.1|dst=198.50.100.2|srcPostNAT=198.50.100.3|dstPostNAT=198.50.100.4|RuleName=AZURE-US-NEW-CNF_Inbound_To_Azure-ALLOW|usrName=|SourceUser=|DestinationUser=|Application=smtp-base|VirtualSystem=vsys1|SourceZone=McD-Global-Zone|DestinationZone=Azure-Zone|IngressInterface=ae1.111|EgressInterface=ae2.409|LogForwardingProfile=Default-Traffic-Logging|SessionID=35331795|RepeatCount=1|srcPort=21578|dstPort=25|srcPostNATPort=0|dstPostNATPort=0|Flags=0x2000|proto=tcp|action=allow|Miscellaneous=\"......3...................xls\"|ThreatID=Microsoft MSOFFICE(52033)|URLCategory=malicious|sev=4|Severity=high|Direction=client-to-server|sequence=7462614601465681755|ActionFlags=0x8000000000000000|SourceLocation=198.50.100.1-198.50.100.255|DestinationLocation=United States|ContentType=|PCAP_ID=0|FileDigest=0ea04c99bf188c2e4207f60f92ca7c6f5088c7943ee63f45c50032bbd2bf7ea9|Cloud=demo.com|URLIndex=1|RequestMethod=|FileType=ms-office|Sender=sender@ab.myownpersonaldomain.com|Subject=\"............:.................................................................................-.........(Name)-2025-01-22...............:Y107202501220005, ............:........................, ...............:.........\"|Recipient=abc@demo.myownpersonaldomain.com|ReportID=117022282776|DeviceGroupHierarchyL1=143|DeviceGroupHierarchyL2=144|DeviceGroupHierarchyL3=39|DeviceGroupHierarchyL4=0|vSrcName=|DeviceName=device_host|SrcUUID=|DstUUID=|TunnelID=0|MonitorTag=|ParentSessionID=0|ParentStartTime=|TunnelType=N/A|ThreatCategory=N/A|ContentVer=WildFire-0CEF
14>1 2024-04-04T16:21:56+02:00 FW-PERIMETRAL-AVG-01 - - - - CEF:0|Palo Alto Networks|PAN-OS|10.1.10-h2|end|TRAFFIC|1|src=198.51.100.1 dst=198.51.100.2 srcTranslatedAddress=198.51.100.3 dstTranslatedAddress=198.51.100.4 rule=FW_USER_NATS2_APP suser= duser= app=bittorrent vs=vsys1 sz=INSIDE dz=EXTERNAL InboundInterface=ae2.2266 OutboundInterface=ae1 lp=log_forwarding sid=2935823 cnt=1 spt=6881 dpt=51413 srcTranslatedPort=0 dstTranslatedPort=0 flags=0x7a proto=udp act=allow tbytes=475 in=150 out=325 pkt=2 pktReceived=1 pktSent=1 start=Apr 04 2024 14:21:56 GMT stime=1206 urlcat=any externalId=externalId reason=aged-out DGl1=11 DGl2=161 DGl3=0 DGl4=0 VsysName=STONESOFT dvchost=FW-PERIMETRAL-AVG-01 cat=from-policy ActionFlags=0x8000000000000000 srcUUID= dstUUID= TunnelID=0 MonitorTag= ParentSessionID=0 ParentStartTime= TunnelType=N/A SCTPAssocID=0 SCTPChunks=0 SCTPChunkSent=0 SCTPChunksRcv=0 RuleUUID=746c3eb6-3d51-4679-8438-bd0e00e170a8 HTTP2Con=0 LinkChange=0 PolicyID= LinkDetail= SDWANCluster= SDWANDevice= SDWANClustype= SDWANSite= DynamicUsrgrp= XFFIP= srcDevCat= srcDevProf= srcDevModel= srcDevVendor= srcDevOS= srcDevOSv= srcHostname= srcMac= dstDevCat= dstDevProf= dstDevModel= dstDevVendor= dstDevOS= dstDevOSv= dstHostname= dstMac= ContainerName= PODNamespace= PODName= srcEDL= dstEDL= GPHostID= EPSerial= srcDAG= dstDAG= HASessionOwner= TimeHighRes=2024-04-04T16:21:56.250+02:00 ASServiceType= ASServiceDiff="CSV
1,2021/10/24 15:30:07,,CONFIG,0,2561,2021/10/24 15:30:07,198.51.100.0,,set,admin,Web,Succeeded, network virtual-router VR1,,VR1 { ecmp { algorithm { ip-modulo ; } } protocol { bgp { routing-options { graceful-restart { enable yes; } } enable no; } rip { enable no; } ospf { enable no; } ospfv3 { enable no; } } routing-table { ip { static-route { vr1-log { path-monitor { enable no; failure-condition any; hold-time 2; } nexthop { ip-address 198.51.100.0; } bfd { profile None; } interface ethernet1/1; metric 10; destination 0.0.0.0/0; route-table { unicast ; } } } } } interface [ ethernet1/1 ethernet1/2 ]; } ,7022390503849066572,0x0,0,0,0,0,,PA-VM,0,
Referensi pemetaan kolom: Kolom log ke kolom UDM
Bagian ini menjelaskan cara parser memetakan kolom log firewall Palo Alto Networks ke kolom peristiwa UDM Google SecOps untuk setiap jenis log. Kunci label Google SecOps mengacu pada nama kunci yang dipetakan ke kolom UDM Labels.key.
Misalnya, untuk kolom "Virtual System", nama kolomnya adalah "cs3" dalam format CEF dan "VirtualSystem" dalam format LEEF. Kolom UDM "about.labels.key" berisi nilai "vsys" dan kolom UDM "about.labels.value" berisi nilai kolom tersebut. Beberapa nama kolom CEF atau LEEF tidak memiliki nama yang sesuai dengan nama kolom CSV. Dalam kasus tersebut, jika Anda menambahkan nama variabel Anda sendiri dalam format log kustom di profil syslog, parser tidak akan memetakannya ke kolom UDM.
Lihat bagian berikut untuk referensi pemetaan setiap jenis log:
- Sistem
- Config
- Ancaman/kebakaran hutan
- Traffic
- ID Pengguna
- Pencocokan HIP
- Tag IP
- Dekripsi
- Tunnel
- Authentication
- URL
- Data
- GlobalProtect
- Korelasi
- GTP
- SCTP
- Audit
Sistem
Tabel berikut mencantumkan kolom log jenis log sistem dan kolom UDM yang sesuai.
| Kolom CSV | Kolom CEF | Kolom LEEF | Kunci label Google Security Operations | Kolom UDM |
|---|---|---|---|---|
| Waktu Penerimaan (receive_time atau cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (jika "Generate Time" tidak ada) |
|
| Nomor Seri (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Jenis (type) | type (Header) | cat | metadata.product_event_type ditetapkan ke "%{type} - %{subtype}". | |
| Jenis Ancaman/Konten (subjenis) | subjenis (Header) | Subjenis | metadata.product_event_type ditetapkan ke "%{type} - %{subtype}". | |
| Waktu yang Dihasilkan (time_generated atau cef-formatted-time_generated) | metadata.event_timestamp | |||
| Sistem Virtual (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| ID Acara (eventid) | cat | eventid | additional.fields.key dan additional.fields.value.string_value | |
| Objek (object) | fname | Nama file | objek | target.resource.name |
| Modul (modul) | flexString2 | Modul | modul | additional.fields.key dan additional.fields.value.string_value |
| Tingkat keparahan (severity) | $number-of-severity(header) | Keparahan | security_result.severity dan security_result.severity_details | |
| Deskripsi (buram) | msg | msg | metadata.description | |
| principal_user_userid (Kolom ini diekstrak dari kolom msg) | principal.user.userid | |||
| principal_ip3 (Kolom ini diekstrak dari kolom msg) | principal.ip | |||
| Alasan (Kolom ini diekstrak dari kolom msg) | security_result.description | |||
| server_address (Kolom ini diekstrak dari kolom msg.) | target.ip | |||
| server_profile (Kolom ini diekstrak dari kolom msg.) | additional.fields.key dan additional.fields.value.string_value | |||
| Nomor Urut (seqno) | externalId | urutan | metadata.product_log_id | |
| Flag Tindakan (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_1 hingga dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key dan additional.fields.value.string_value |
| Nama Sistem Virtual (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nama Perangkat (device_name) | dvchost | DeviceName | target.hostname | |
| Stempel Waktu Resolusi Tinggi (high_res_timestamp) | anOSTimeGeneratedHighResolution | additional.fields.key dan additional.fields.value.string_value |
Konfigurasi
Tabel berikut mencantumkan kolom log jenis log config dan kolom UDM yang sesuai.
| Kolom CSV | Kolom CEF | Kolom LEEF | Kunci label Google Security Operations | Kolom UDM |
|---|---|---|---|---|
| Waktu Penerimaan (receive_time atau cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (jika "Generate Time" tidak ada) |
|
| Nomor Seri (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Jenis (type) | type (Header) | cat | metadata.product_event_type | |
| Jenis Ancaman/Konten (subjenis) | subjenis (Header) | metadata.product_event_type | ||
| Waktu yang Dihasilkan (time_generated atau cef-formatted-time_generated) | metadata.event_timestamp | |||
| Host (host) | shost | src | principal.ip/hostname | |
| Sistem Virtual (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| Perintah (cmd) | act | msg | cmd | principal.process.command_line |
| Admin (admin) | duser | usrName | principal.user.userid | |
| Klien (client) | destinationServiceName | klien | principal.application | |
| Hasil (result) | ID Tanda Tangan (Header)(alasan) | Hasil | security_result.summary | |
| Jalur Konfigurasi (path) | msg | ConfigurationPath | principal.process.command_line | |
| Detail Sebelum Perubahan (before_change_detail) | cs1 | BeforeChangeDetail | before_change_detail | target.resource.attribute.labels.key/value |
| Detail Perubahan Setelah (after_change_detail) | cs2 | AfterChangeDetail | after_change_detail | target.resource.attribute.labels.key/value |
| Nomor Urut (seqno) | externalId | urutan | metadata.product_log_id | |
| Flag Tindakan (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_1 hingga dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key dan additional.fields.value.string_value |
| Nama Sistem Virtual (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nama Perangkat (device_name) | dvchost | DeviceName | target.hostname | |
| Grup Perangkat (dg_id) | PanOSFWDeviceGroup | target.asset.attribute.labels.key/value | dg_id | principal.asset.attribute.labels.key/value |
| Komentar Audit (comment) | PanOSPolicyAuditComment | komentar | additional.fields.key dan additional.fields.value.string_value | |
| Stempel Waktu Resolusi Tinggi (high_res_timestamp) | additional.fields.key dan additional.fields.value.string_value | |||
| Tingkat keparahan (severity) | number-of-severity(header) | security_result.severity dan security_result.severity_details |
Ancaman/WildFire
Tabel berikut mencantumkan kolom log jenis log Threat/WildFire dan kolom UDM yang sesuai.
| Kolom CSV | Kolom CEF | Kolom LEEF | Kunci label Google Security Operations | Kolom UDM |
|---|---|---|---|---|
| Waktu Penerimaan (receive_time atau cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (jika "Generate Time" tidak ada) |
|
| Nomor Seri (serial #) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Jenis (type) | type (Header) | cat | metadata.product_event_type | |
| Jenis Ancaman/Konten (subjenis) | cat/subtype (Header) | Subjenis | metadata.product_event_type | |
| Waktu Pembuatan (time_generated atau cef-formatted-time_generated) | metadata.event_timestamp | |||
| Alamat sumber (src) | src | src | principal.ip | |
| Alamat tujuan (dst) | dst | dst | target.ip | |
| IP Sumber NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP Tujuan NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Nama Aturan (rule) | cs1 | RuleName | security_result.rule_name | |
| Pengguna Sumber (srcuser) | suser | SourceUser / usrName | principal.user.userid | |
| Pengguna Tujuan (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplikasi (aplikasi) | aplikasi | Aplikasi | target.application | |
| Sistem Virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona Sumber (dari) | cs4 | SourceZone | dari | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
| Zona Tujuan (ke) | cs5 | DestinationZone | sampai | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
| Antarmuka Masuk (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
| Antarmuka Keluar (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
| Tindakan Log (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key dan additional.fields.value.string_value |
| ID Sesi (sessionid) | cn1 | SessionID | network.session_id | |
| Jumlah Pengulangan (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key dan additional.fields.value.string_value |
| Port Sumber (sport) | spt | srcPort | principal.port | |
| Port Tujuan (dport) | dpt | dstPort | target.port | |
| Port Sumber NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Port Tujuan NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Tanda (flags) | flexString1 | Flag | flag | additional.fields.key dan additional.fields.value.string_value |
| Protokol IP (proto) | proto | proto | network.ip_protocol | |
| Tindakan (action) | act | tindakan | security_result.action_details
security_result.action |
|
| URL/Nama file (lain-lain) | permintaan | Lain-lain | target.file.names (jika subjenisnya adalah 'file', 'virus', 'wildfire-virus', atau 'wildfire', maka kolom `misc` dipetakan ke target.file.names) target.url (jika subjenisnya adalah 'url', kolom `misc` dipetakan ke target.url dan target.hostname) |
|
| Nama Ancaman/Konten (threatid) | cat | ThreatID | security_result.threat_name | |
| Kategori (category) | cs2 | URLCategory | security_result.category_details | |
| Tingkat keparahan (severity) | number-of-severity(header) | Keparahan | security_result.severity dan security_result.severity_details | |
| Arah (direction) | flexString2 | Arah | network.direction | |
| Nomor Urut (seqno) | externalId | urutan | metadata.product_log_id | |
| Flag Tindakan (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key dan additional.fields.value.string_value |
| Negara Sumber (srcloc) | SourceLocation | principal.location.country_or_region | ||
| Negara Tujuan (dstloc) | DestinationLocation | target.location.country_or_region | ||
| Jenis Konten (contenttype) | ContentType | contenttype | additional.fields.key dan additional.fields.value.string_value | |
| ID PCAP (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key dan additional.fields.value.string_value |
| Ringkasan File (filedigest) | fileHash | FileDigest | target.file.sha1/md5/sha256 | |
| Cloud (cloud) | filePath | Cloud | cloud | additional.fields.key dan additional.fields.value.string_value |
| Indeks URL (url_idx) | URLIndex | url_idx | additional.fields.key dan additional.fields.value.string_value | |
| Agen Pengguna (user_agent) | network.http.user_agent | |||
| Jenis File (filetype) | fileType | FileType | target.file.mime_type | |
| X-Forwarded-For (xff) | principal.ip | |||
| Perujuk (referer) | network.http.referral_url | |||
| Pengirim (sender) | suid | Pengirim | network.email.from | |
| Subjek (subject) | msg | Subjek | network.email.subject | |
| Penerima (recipient) | duid | Penerima | network.email.to | |
| ID Laporan (reportid) | oldFileId | ReportID | reportid | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_1 hingga dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key dan additional.fields.value.string_value |
| Nama Sistem Virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nama Perangkat (device_name) | dvchost | DeviceName | intermediary.hostname | |
| UUID VM Sumber (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id | |
| UUID VM tujuan (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id | |
| Metode HTTP (http_method) | RequestMethod | network.http.method | ||
| ID/IMSI tunnel (tunnel_id/imsi) | PanOSTunnelID | TunnelID | tunnel_id/imsi | additional.fields.key dan additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag/imei) | PanOSMonitorTag | MonitorTag | monitortag/imei | additional.fields.key dan additional.fields.value.string_value |
| ID Sesi Induk (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Waktu Mulai Sesi Orang Tua (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key dan additional.fields.value.string_value |
| Jenis Tunnel (tunnel) | PanOSTunnelType | TunnelType | tunnel | additional.fields.key dan additional.fields.value.string_value |
| Kategori Ancaman (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| Versi Konten (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key dan additional.fields.value.string_value |
| ID Asosiasi SCTP (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key dan additional.fields.value.string_value | |
| ID Protokol Payload (ppid) | PanOSPPID | ppid | additional.fields.key dan additional.fields.value.string_value | |
| Header HTTP (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Daftar Kategori URL (url_category_list) | PanOSURLCatList | url_category_list | additional.fields.key dan additional.fields.value.string_value | |
| UUID Aturan (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| Koneksi HTTP/2 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| Nama Grup Pengguna Dinamis (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
|
| Alamat XFF (xff_ip) | PanXFFIP | principal.ip | ||
| Kategori Perangkat Sumber (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Profil Perangkat Sumber (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
|
| Model Perangkat Sumber (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Vendor Perangkat Sumber (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Grup OS Perangkat Sumber (src_osfamily) | PanSrcDeviceOS | src_osfamily | principal.platform | |
| Versi OS Perangkat Sumber (src_osversion) | PanSrcDeviceOSv | principal.platform_version | ||
| Nama Host Sumber (src_host) | PanSrcHostname | principal.hostname | ||
| Alamat MAC Sumber (src_mac) | PanSrcMac | principal.mac | ||
| Kategori Perangkat Tujuan (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Profil Perangkat Tujuan (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
|
| Model Perangkat Tujuan (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Vendor Perangkat Tujuan (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Keluarga OS Perangkat Tujuan (dst_osfamily) | PanDstDeviceOS | dst_osfamily | target.platform | |
| Versi OS Perangkat Tujuan (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Nama Host Tujuan (dst_host) | PanDstHostname | target.hostname | ||
| Alamat MAC Tujuan (dst_mac) | PanDstMac | target.mac | ||
| ID Penampung (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| Namespace POD (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| Nama POD (pod_name) | PanPODName | pod_name | target.resource.name | |
| Daftar Dinamis Eksternal Sumber (src_edl) | PanSrcEDL | src_edl | additional.fields.key dan additional.fields.value.string_value | |
| Daftar Dinamis Eksternal Tujuan (dst_edl) | PanDstEDL | dst_edl | additional.fields.key dan additional.fields.value.string_value | |
| ID Host (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Nomor Seri Perangkat Pengguna (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| EDL domain (domain_edl) | PanDomainEDL | domain_edl | additional.fields.key dan additional.fields.value.string_value | |
| Grup Alamat Dinamis Sumber (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Grup Alamat Dinamis Tujuan (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| Hash Parsial (partial_hash) | PanPartialHash | partial_hash | additional.fields.key dan additional.fields.value.string_value | |
| Stempel Waktu Resolusi Tinggi (high_res timestamp) | PanTimeHighRes | stempel waktu resolusi tinggi | additional.fields.key dan additional.fields.value.string_value | |
| Alasan (reason) | PanReasonFilteringAction | alasan | security_result.summary | |
| Justifikasi (justifikasi) | PanJustification | perataan kanan kiri | additional.fields.key dan additional.fields.value.string_value | |
| Jenis Layanan Slice (nssai_sst) | PanASServiceType | nssai_sst | additional.fields.key dan additional.fields.value.string_value | |
| Subkategori Aplikasi (subcategory_of_app) | subcategory_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Kategori Aplikasi (category_of_app) | category_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Teknologi Aplikasi (technology_of_app) | technology_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Risiko Aplikasi (risk_of_app) | risk_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Karakteristik Aplikasi (characteristic_of_app) | characteristic_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Penampung Aplikasi (container_of_app) | container_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| SaaS Aplikasi (is_saas_of_app) | is_saas_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Aplikasi yang Ditunnelkan (tunneled_app) | additional.fields.key dan additional.fields.value.string_value | |||
| Jenis Alur (flow_type) | additional.fields.key dan additional.fields.value.string_value | |||
| Nama Cluster (cluster_name) | intermediary.resource.name | |||
| Status Aplikasi yang Tidak Diizinkan (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key dan additional.fields.value.string_value |
Traffic
Tabel berikut mencantumkan kolom log jenis log traffic dan kolom UDM yang sesuai.
| Kolom CSV | Kolom CEF | Kolom LEEF | Kunci label Google Security Operations | Kolom UDM |
|---|---|---|---|---|
| Waktu Penerimaan (receive_time atau cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (jika "Generate Time" tidak ada) |
|
| Nomor Seri (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Jenis (type) | type (Header) | cat/Type | metadata.product_event_type | |
| Jenis Ancaman/Konten (subjenis) | subjenis (Header) | Subjenis | metadata.product_event_type | |
| Waktu yang Dihasilkan (time_generated atau cef-formatted-time_generated) | mulai | metadata.event_timestamp | ||
| Alamat Sumber (src) | src | src | principal.ip | |
| Alamat Tujuan (dst) | dst | dst | target.ip | |
| IP Sumber NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP Tujuan NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Nama Aturan (rule) | cs1 | RuleName | security_result.rule_name | |
| Pengguna Sumber (srcuser) | suser | SourceUser | principal.user.userid | |
| Pengguna Tujuan (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplikasi (aplikasi) | aplikasi | Aplikasi | target.application | |
| Sistem Virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona Sumber (dari) | cs4 | SourceZone | dari | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
| Zona Tujuan (ke) | cs5 | DestinationZone | sampai | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
| Antarmuka Masuk (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
| Antarmuka Keluar (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
| Tindakan Log (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key dan additional.fields.value.string_value |
| ID Sesi (sessionid) | cn1 | SessionID | network.session_id | |
| Jumlah Pengulangan (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key dan additional.fields.value.string_value |
| Port Sumber (sport) | spt | srcPort | principal.port | |
| Port Tujuan (dport) | dpt | dstPort | target.port | |
| Port Sumber NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Port Tujuan NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Tanda (flags) | flexString1 | Flag | flag | additional.fields.key dan additional.fields.value.string_value |
| Protokol IP (proto) | proto | proto | network.ip_protocol | |
| Tindakan (action) | act | tindakan | security_result.action_details
security_result.action |
|
| Byte (byte) | flexNumber1 | totalBytes | byte | additional.fields.key dan additional.fields.value.string_value |
| Byte Terkirim (bytes_sent) | di | srcBytes | network.sent_bytes | |
| Byte Diterima (bytes_received) | keluar | dstBytes | network.received_bytes | |
| Paket (packets) | cn2 | totalPackets | paket | additional.fields.key dan additional.fields.value.string_value |
| Waktu Mulai (start) | StartTime | mulai | additional.fields.key dan additional.fields.value.string_value | |
| Waktu Berlalu (elapsed) | cn3 | ElapsedTime | berlalu | network.session_duration.seconds |
| Kategori (category) | cs2 | URLCategory | security_result.category / security_result.category_details | |
| Nomor Urut (seqno) | externalId | urutan | metadata.product_log_id | |
| Flag Tindakan (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key dan additional.fields.value.string_value |
| Negara Sumber (srcloc) | SourceLocation | principal.location.country_or_region | ||
| Negara Tujuan (dstloc) | DestinationLocation | target.location.country_or_region | ||
| Paket Terkirim (pkts_sent) | PanOSPacketsSent | srcPackets | pkts_sent | network.sent_packets |
| Paket Diterima (pkts_received) | PanOSPacketsReceived | dstPackets | pkts_received | network.received_packets |
| Alasan Akhir Sesi (session_end_reason) | alasan | SessionEndReason | security_result.summary | |
| Hierarki Grup Perangkat1 (dg_hier_level_1 hingga dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat2 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat3 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key dan additional.fields.value.string_value |
| Nama Sistem Virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nama Perangkat (device_name) | dvchost | DeviceName | intermediary.hostname | |
| Sumber Tindakan (action_source) | cat | ActionSource | action_source | additional.fields.key dan additional.fields.value.string_value |
| UUID VM Sumber (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id | |
| UUID VM tujuan (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id | |
| ID Tunnel/IMSI (tunnelid/imsi) | PanOSTunnelID | TunnelID | tunnelid/imsi | additional.fields.key dan additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag/imei) | PanOSMonitorTag | MonitorTag | monitortag/imei | additional.fields.key dan additional.fields.value.string_value |
| ID Sesi Induk (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Waktu Mulai Induk (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key dan additional.fields.value.string_value |
| Jenis Tunnel (tunnel) | PanOSTunnelType | TunnelType | tunnel | additional.fields.key dan additional.fields.value.string_value |
| ID Asosiasi SCTP (assoc_id) | PanOSSCTPAssocID | assoc_id | additional.fields.key dan additional.fields.value.string_value | |
| Potongan SCTP (chunks) | PanOSSCTPChunks | potongan | additional.fields.key dan additional.fields.value.string_value | |
| SCTP Chunks Sent (chunks_sent) | PanOSSCTPChunkSent | chunks_sent | additional.fields.key dan additional.fields.value.string_value | |
| SCTP Chunks yang Diterima (chunks_received) | PanOSSCTPChunksRcv | chunks_received | additional.fields.key dan additional.fields.value.string_value | |
| UUID Aturan (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| Koneksi HTTP/2 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| Jumlah Penutup Aplikasi (link_change_count) | PanLinkChange | link_change_count | additional.fields.key dan additional.fields.value.string_value | |
| ID Kebijakan (policy_id) | PanPolicyID | policy_id | additional.fields.key dan additional.fields.value.string_value | |
| Sakelar Link (link_switches) | PanLinkDetail | link_switches | additional.fields.key dan additional.fields.value.string_value | |
| Cluster SD-WAN (sdwan_cluster) | PanSDWANCluster | sdwan_cluster | additional.fields.key dan additional.fields.value.string_value | |
| Jenis Perangkat SD-WAN (sdwan_device_type) | PanSDWANDevice | sdwan_device_type | additional.fields.key dan additional.fields.value.string_value | |
| Jenis Cluster SD-WAN (sdwan_cluster_type) | PanSDWANClustype | sdwan_cluster_type | additional.fields.key dan additional.fields.value.string_value | |
| Situs SD-WAN (sdwan_site) | PanSDWANSite | sdwan_site | additional.fields.key dan additional.fields.value.string_value | |
| Nama Grup Pengguna Dinamis (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | additional.fields.key dan additional.fields.value.string_value | |
| Alamat XFF (xff_ip) | PanXFFIP | principal.ip | ||
| Kategori Perangkat Sumber (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Profil Perangkat Sumber (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
|
| Model Perangkat Sumber (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Vendor Perangkat Sumber (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Grup OS Perangkat Sumber (src_osfamily) | PanSrcDeviceOS | principal.platform | ||
| Versi OS Perangkat Sumber (src_osversion) | PanSrcDeviceOSv | principal.asset.software.version | ||
| Nama Host Sumber (src_host) | PanSrcHostname | principal.hostname | ||
| Alamat MAC Sumber (src_mac) | PanSrcMac | principal.mac | ||
| Kategori Perangkat Tujuan (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Profil Perangkat Tujuan (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
|
| Model Perangkat Tujuan (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Vendor Perangkat Tujuan (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Keluarga OS Perangkat Tujuan (dst_osfamily) | PanDstDeviceOS | dst_osfamily | target.platform | |
| Versi OS Perangkat Tujuan (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Nama Host Tujuan (dst_host) | PanDstHostname | target.hostname | ||
| Alamat MAC Tujuan (dst_mac) | PanDstMac | target.mac | ||
| ID Penampung (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| Namespace POD (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| Nama POD (pod_name) | PanPODName | pod_name | target.resource.name | |
| Daftar Dinamis Eksternal Sumber (src_edl) | PanSrcEDL | src_edl | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
|
| Daftar Dinamis Eksternal Tujuan (dst_edl) | PanDstEDL | dst_edl | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
|
| ID Host (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Nomor Seri Perangkat Pengguna (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| Grup Alamat Dinamis Sumber (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Grup Alamat Dinamis Tujuan (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| Pemilik Sesi (session_owner) | PanHASessionOwner | session_owner | additional.fields.key dan additional.fields.value.string_value | |
| Stempel Waktu Resolusi Tinggi (high_res_timestamp) | PanTimeHighRes | additional.fields.key dan additional.fields.value.string_value | ||
| Jenis Layanan Slice (nsdsai_sst) | PanASServiceType | nsdsai_sst | additional.fields.key dan additional.fields.value.string_value | |
| Pembeda Slice (nsdsai_sd) | PanASServiceDiff | nsdsai_sd | additional.fields.key dan additional.fields.value.string_value | |
| Subkategori Aplikasi (subcategory_of_app) | subcategory_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Kategori Aplikasi (category_of_app) | category_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Teknologi Aplikasi (technology_of_app) | technology_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Risiko Aplikasi (risk_of_app) | security_result.severity | |||
| Karakteristik Aplikasi (characteristic_of_app) | characteristic_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Penampung Aplikasi (container_of_app) | container_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| SaaS Aplikasi (is_saas_of_app) | is_saas_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Status Aplikasi yang Tidak Diizinkan (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Subkategori Aplikasi (subcategory_of_app) | subcategory_of_app1 | additional.fields.key dan additional.fields.value.string_value | ||
| Tingkat keparahan (severity) | number-of-severity(header) | security_result.severity dan security_result.severity_details |
User-ID
Tabel berikut mencantumkan kolom log jenis log user-id dan kolom UDM yang sesuai.
| Kolom CSV | Kolom CEF | Kolom LEEF | Kunci label Google Security Operations | Kolom UDM |
|---|---|---|---|---|
| Waktu Penerimaan (receive_time atau cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (jika "Generate Time" tidak ada) |
|
| Nomor Seri (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Jenis (type) | type (Header) | cat | metadata.product_event_type | |
| Jenis Ancaman/Konten (subjenis) | subjenis (Header) | Subjenis | metadata.product_event_type | |
| Waktu yang Dihasilkan (time_generated atau cef-formatted-time_generated) | metadata.event_timestamp | |||
| Sistem Virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| IP Sumber (ip) | src | src | principal.ip | |
| Pengguna (user) | duser | usrName | target.user.userid
target.administrative_domain target.user.email_addresses |
|
| Nama Sumber Data (datasourcename) | cs4 | DataSourceName | datasourcename | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
| ID Acara (eventid) | EventID | eventid | additional.fields.key dan additional.fields.value.string_value | |
| Jumlah Pengulangan (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key dan additional.fields.value.string_value |
| Batas Waktu Tunggu (waktu tunggu) | cn3 | TimeoutThreshold | timeout | additional.fields.key dan additional.fields.value.string_value |
| Port Sumber (beginport) | spt | srcPort | principal.port | |
| Port Tujuan (endport) | dpt | dstPort | target.port | |
| Sumber Data (datasource) | cs5 | DataSource | sumber data | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
| Jenis Sumber Data (datasourcetype) | cs6 | DataSourceType | datasourcetype | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
| Nomor Urut (seqno) | externalId | urutan | metadata.product_log_id | |
| Flag Tindakan (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key dan additional.fields.value.string_value |
| Nama Sistem Virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nama Perangkat (device_name) | dvchost | DeviceName | intermediary.hostname | |
| ID Sistem Virtual (vsys_id) | cn2 | VirtualSystemID | intermediary.resource.product_object_id | |
| Jenis Faktor (factortype) | cs1 | FactorType | factortype | additional.fields.key dan additional.fields.value.string_value |
| Waktu Penyelesaian Faktor (factorcompletiontime) | selesai | FactorCompletionTime | factorcompletiontime | additional.fields.key dan additional.fields.value.string_value |
| Nomor Faktor (factorno) | cn1 | FactorNumber | factorno | additional.fields.key dan additional.fields.value.string_value |
| Flag Grup Pengguna (ugflags) | PanOSUGFlags | ugflags | additional.fields.key dan additional.fields.value.string_value | |
| Pengguna menurut Sumber (userbysource) | PanOSUserBySource | target.user.userid
target.administrative_domain target.user.email_addresses |
||
| Stempel Waktu Resolusi Tinggi (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key dan additional.fields.value.string_value | ||
| Sumber Data Asal (origindatasource) | additional.fields.key dan additional.fields.value.string_value | |||
| Nama Cluster (cluster_name) | principal.resource.name | |||
| Tingkat keparahan (severity) | number-of-severity(header) | security_result.severity dan security_result.severity_details |
Pencocokan HIP
Tabel berikut mencantumkan kolom log jenis log kecocokan HIP dan kolom UDM yang sesuai.
| Kolom CSV | Kolom CEF | Kolom LEEF | Kunci label Google Security Operations | Kolom UDM |
|---|---|---|---|---|
| Waktu Penerimaan (receive_time atau cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (jika "Generate Time" tidak ada) |
|
| Nomor Seri (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Jenis (type) | type (Header) | cat | metadata.product_event_type | |
| Jenis Ancaman/Konten (subjenis) | subjenis (Header) | Subjenis | ||
| Waktu yang Dihasilkan (time_generated atau cef-formatted-time_generated) | mulai | startTime | metadata.event_timestamp | |
| Pengguna Sumber (srcuser) | suser | usrName | principal.user.userid | |
| Sistem Virtual (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| Nama Perangkat (machinename) | shost | identHostName | principal.hostname | |
| Sistem Operasi (os) | cs2 | OS | principal.asset.platform_software.platform | |
| Alamat Sumber (src) | src | identsrc | principal.ip | |
| HIP (matchname) | cat | HIP | matchname | target.resource.attribute.labels.key/value additional.fields.key dan additional.fields.value.string_value |
| Jumlah Pengulangan (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key dan additional.fields.value.string_value |
| Jenis HIP (matchtype) | ID Class Peristiwa Perangkat (Header) | HIPType | matchtype | target.resource.attribute.labels.key/value additional.fields.key dan additional.fields.value.string_value |
| Nomor Urut (seqno) | externalId | urutan | metadata.product_log_id | |
| Flag Tindakan (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key dan additional.fields.value.string_value |
| Nama Sistem Virtual (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nama Perangkat (device_name) | dvchost | DeviceName | target.hostname | |
| ID Sistem Virtual (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id | |
| Alamat Sistem IPv6 (srcipv6) | c6a2 | srcipv6 | principal.asset.ip | |
| ID Host (hostid) | PanOSHostID | principal.asset.asset_id | ||
| Nomor Seri Perangkat Pengguna (serialnumber) | PanOSEndpointSerialNumber | principal.asset.hardware.serial_number | ||
| Alamat MAC Perangkat (mac) | PanOSEndpointMac | principal.asset.mac | ||
| Stempel Waktu Resolusi Tinggi (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key dan additional.fields.value.string_value | ||
| Nama Cluster (cluster_name) | principal.resource.name | |||
| Tingkat keparahan (severity) | number-of-severity(header) | security_result.severity dan security_result.severity_details |
Tag IP
Tabel berikut mencantumkan kolom log jenis log tag IP dan kolom UDM yang sesuai.
| Kolom CSV | Kolom CEF | Kolom LEEF | Kunci label Google Security Operations | Kolom UDM |
|---|---|---|---|---|
| Waktu Penerimaan (receive_time atau cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (jika "Generate Time" tidak ada) |
|
| Nomor Seri (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Jenis (type) | type (Header) | cat | metadata.product_event_type | |
| Jenis Ancaman/Konten (subjenis) | subjenis (Header) | Subjenis | metadata.product_event_type | |
| Waktu yang Dihasilkan (time_generated atau cef-formatted-time_generated) | GenerateTime | metadata.event_timestamp | ||
| Sistem Virtual (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| IP Sumber (ip) | src | src | principal.ip | |
| Nama Tag (tag_name) | PanOSTagName | TagName | tag_name | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
| ID Acara (event_id) | PanOSEventID | EventID | event_id | additional.fields.key dan additional.fields.value.string_value |
| Jumlah Pengulangan (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key dan additional.fields.value.string_value |
| Waktu tunggu (timeout) | PanOSTimeout | TimeoutThreshold | timeout | additional.fields.key dan additional.fields.value.string_value |
| Nama Sumber Data (datasourcename) | PanOSDataSourceName | DataSourceName | datasourcename | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
| Jenis Sumber Data (datasource_type) | PanOSDataSourceType | DataSource | datasource_type | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
| Subjenis Sumber Data (datasource_subtype) | PanOSDataSourceSubType | DataSourceType | datasource_subtype | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
| Nomor Urut (seqno) | externalId | urutan | metadata.product_log_id | |
| Flag Tindakan (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key dan additional.fields.value.string_value |
| Nama Sistem Virtual (vsys_name) | PanOsVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nama Perangkat (device_name) | dvchost | DeviceName | target.hostname | |
| ID Sistem Virtual (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id | |
| Stempel Waktu Resolusi Tinggi (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key dan additional.fields.value.string_value | ||
| Tingkat keparahan (severity) | number-of-severity(header) | security_result.severity dan security_result.severity_details | ||
| Nama Cluster (cluster_name) | principal.resource.name |
Dekripsi
Tabel berikut mencantumkan kolom log jenis log dekripsi dan kolom UDM yang sesuai.
| Kolom CSV | Kolom CEF | Kolom LEEF | Kunci label Google Security Operations | Kolom UDM |
|---|---|---|---|---|
| Waktu Penerimaan (receive_time atau cef-formatted-receive_time) | rt | metadata.collected_timestamp,
metadata.event_timestamp (jika "Generate Time" tidak ada) |
||
| Nomor Seri (serial) | PanOSDeviceSN | intermediary.asset.hardware.serial_number | ||
| Jenis (type) | type (Header) | metadata.product_event_type | ||
| Jenis Ancaman/Konten (subjenis) | subjenis (Header) | metadata.product_event_type | ||
| Versi Konfigurasi (config_ver) | PanOSConfigVersion | config_ver | additional.fields.key dan additional.fields.value.string_value | |
| Waktu Pembuatan (time_generated) | PanOSLogTimeStamp | metadata.event_timestamp | ||
| Alamat Sumber (src) | src | principal.ip | ||
| Alamat Tujuan (dst) | dst | target.ip | ||
| IP Sumber NAT (natsrc) | sourceTranslatedAddress | principa.nat_ip | ||
| IP Tujuan NAT (natdst) | destinationTranslatedAddress | target.nat_ip | ||
| Aturan (rule) | cs1 | security_result.rule_name | ||
| Pengguna Sumber (srcuser) | suser | principal.user.userid | ||
| Pengguna Tujuan (dstuser) | duser | target.user.userid | ||
| Aplikasi (aplikasi) | aplikasi | network.application_protocol | ||
| Sistem Virtual (vsys) | cs3 | vsys | intermediary.asset.attribute.labels.key/value | |
| Zona Sumber (dari) | cs4 | dari | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
|
| Zona Tujuan (ke) | cs5 | sampai | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
|
| Antarmuka Masuk (inbound_if) | deviceInboundInterface | inbound_if | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
|
| Antarmuka Keluar (outbound_if) | deviceOutboundInterface | outbound_if | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
|
| Tindakan Log (logset) | cs6 | logset | additional.fields.key dan additional.fields.value.string_value | |
| Waktu Dicatat (time_received) | PanOSTimeReceivedManagementPlane | - | ||
| ID Sesi (sessionid) | cn1 | network.session_id | ||
| Jumlah Pengulangan (repeatcnt) | PanOSCountOfRepeats/RepeatCount | repeatcnt | additional.fields.key dan additional.fields.value.string_value | |
| Port Sumber (sport) | spt | principal.port | ||
| Port Tujuan (dport) | dpt | target.port | ||
| Port Sumber NAT (natsport) | sourceTranslatedPort | principal.nat_port | ||
| Port Tujuan NAT (natdport) | destinationTranslatedPort | target.nat_port | ||
| Tanda (flags) | flexString1 | flag | additional.fields.key dan additional.fields.value.string_value | |
| Protokol IP (proto) | proto | network.ip_protocol | ||
| Tindakan (action) | act | security_result.action_details
security_result.action |
||
| Tunnel (tunnel) | PanOSTunnel | tunnel | additional.fields.key dan additional.fields.value.string_value | |
| UUID VM Sumber (src_uuid) | PanOSSourceUUID | principal.asset.product_object_id | ||
| UUID VM tujuan (dst_uuid) | PanOSDestinationUUID | target.asset.product_object_id | ||
| UUID untuk aturan (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| Tahap Client to Firewall (hs_stage_c2f) | PanOSClientToFirewall | hs_stage_c2f | additional.fields.key dan additional.fields.value.string_value | |
| Tahap Firewall ke Server (hs_stage_f2s) | PanOSFirewallToServer | hs_stage_f2s | additional.fields.key dan additional.fields.value.string_value | |
| Versi TLS (tls_version) | PanOSTLSVersion | network.tls.version | ||
| Algoritma Pertukaran Kunci (tls_keyxchg) | PanOSTLSKeyExchange | tls_keyxchg | additional.fields.key dan additional.fields.value.string_value | |
| Algoritma Enkripsi (tls_enc) | PanOSTLSEncryptionAlgorithm | tls_enc | additional.fields.key dan additional.fields.value.string_value | |
| Algoritma Hash (tls_auth) | PanOSTLSAuth | tls_auth | additional.fields.key dan additional.fields.value.string_value | |
| Nama Kebijakan (policy_name) | PanOSPolicyName | policy_name | additional.fields.key dan additional.fields.value.string_value | |
| Kurva Eliptik (ec_curve) | PanOSEllipticCurve | network.tls.curve | ||
| Indeks Error (err_index) | PanOSErrorIndex | err_index | additional.fields.key dan additional.fields.value.string_value | |
| Status Root (root_status) | PanOSRootStatus | root_status | additional.fields.key dan additional.fields.value.string_value | |
| Status Rantai (chain_status) | PanOSChainStatus | chain_status | additional.fields.key dan additional.fields.value.string_value | |
| Jenis Proxy (proxy_type) | PanOSProxyType | proxy_type | additional.fields.key dan additional.fields.value.string_value | |
| Nomor Seri Sertifikat (cert_serial) | PanOSCertificateSerial | network.tls.server.certificate.serial | ||
| Sidik Jari Sertifikat (sidik jari) | PanOSFingerprint | network.tls.server.certificate.md5/sha1/sha256 | ||
| Tanggal Mulai Sertifikat (notbefore) | PanOSTimeNotBefore | network.tls.server.certificate.not_before | ||
| Tanggal Akhir Sertifikat (notafter) | PanOSTimeNotAfter | network.tls.server.certificate.not_after | ||
| Versi Sertifikat (cert_ver) | PanOSCertificateVersion | network.tls.server.certificate.version | ||
| Ukuran Sertifikat (cert_size) | PanOSCertificateSize | cert_size | additional.fields.key dan additional.fields.value.string_value | |
| Panjang Nama Umum (cn_len) | PanOSCommonNameLength | cn_len | additional.fields.key dan additional.fields.value.string_value | |
| Panjang Nama Umum Penerbit (issuer_len) | PanOSIssuerNameLength | issuer_len | additional.fields.key dan additional.fields.value.string_value | |
| Panjang Nama Umum Root (rootcn_len) | PanOSRootCNLength | rootcn_len | additional.fields.key dan additional.fields.value.string_value | |
| Panjang SNI (sni_len) | PanOSSNILength | sni_len | additional.fields.key dan additional.fields.value.string_value | |
| Tanda Sertifikat (cert_flags) | PanOSCertificateFlags | cert_flags | additional.fields.key dan additional.fields.value.string_value | |
| Nama Umum Subjek (cn) | PanOSCommonName | cn | additional.fields.key dan additional.fields.value.string_value | |
| Nama Umum Penerbit (issuer_cn) | PanOSIssuerCommonName | network.tls.server.certificate.issuer | ||
| Nama Umum Root (root_cn) | PanOSRootCommonName | root_cn | additional.fields.key dan additional.fields.value.string_value | |
| Indikasi Nama Server
(sni) |
network.tls.client.server_name | |||
| Error (error) | PanOSErrorMessage | error | additional.fields.key dan additional.fields.value.string_value | |
| ID Penampung (container_id) | PanOSContainerID | container_id | intermediary.resource.product_object_id | |
| Namespace POD (pod_namespace) | PanOSContainerNameSpace | pod_namespace | target.resource.attribute.labels.key/value additional.fields.key dan additional.fields.value.string_value |
|
| Nama POD (pod_name) | PanOSContainerName | pod_name | target.resource.name | |
| Daftar Dinamis Eksternal Sumber (src_edl) | PanOSSourceEDL | src_edl | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
|
| Daftar Dinamis Eksternal Tujuan (dst_edl) | PanOSDestinationEDL | dst_edl | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
|
| Grup Alamat Dinamis Sumber (src_dag) | PanOSSourceDynamicAddressGroup | principal.group.group_display_name | ||
| Grup Alamat Dinamis Tujuan (dst_dag) | PanOSDestinationDynamicAddressGroup | target.group.group_display_name | ||
| Stempel Waktu Resolusi Tinggi (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key dan additional.fields.value.string_value | ||
| Kategori Perangkat Sumber (src_category) | PanOSSourceDeviceCategory | src_category | principal.asset.category | |
| Profil Perangkat Sumber (src_profile) | PanOSSourceDeviceProfile | src_profile | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
|
| Model Perangkat Sumber (src_model) | PanOSSourceDeviceModel | src_model | principal.asset.hardware.model | |
| Vendor Perangkat Sumber (src_vendor) | PanOSSourceDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Grup OS Perangkat Sumber (src_osfamily) | PanOSSourceDeviceOSFamily | principal.platform | ||
| Versi OS Perangkat Sumber (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | ||
| Nama Host Sumber (src_host) | PanOSSourceDeviceHost | principal.hostname | ||
| Alamat MAC Sumber (src_mac) | PanOSSourceDeviceMac | principal.mac | ||
| Kategori Perangkat Tujuan (dst_category) | PanOSDestinationDeviceCategory | dst_category | target.asset.category | |
| Profil Perangkat Tujuan (dst_profile) | PanOSDestinationDeviceProfile | dst_profile | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
|
| Model Perangkat Tujuan (dst_model) | PanOSDestinationDeviceModel | dst_model | target.asset.hardware.model | |
| Vendor Perangkat Tujuan (dst_vendor) | PanOSDestinationDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Keluarga OS Perangkat Tujuan (dst_osfamily) | PanOSDestinationDeviceOSFamily | dst_osfamily | target.platform | |
| Versi OS Perangkat Tujuan (dst_osversion) | PanOSDestinationDeviceOSVersion | target.platform_version | ||
| Nama Host Tujuan (dst_host) | PanOSDestinationDeviceHost | target.hostname | ||
| Alamat MAC Tujuan (dst_mac) | PanOSDestinationDeviceMac | target.mac | ||
| Nomor Urut (seqno) | PanOSLogTypeSeqNo | metadata.product_log_id | ||
| Flag Tindakan (actionflags) | PanOSActionFlags | actionflags | additional.fields.key dan additional.fields.value.string_value | |
| Hierarki Grup Perangkat (dg_hier_level_1) | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key dan additional.fields.value.string_value | |
| Hierarki Grup Perangkat (dg_hier_level_2) | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key dan additional.fields.value.string_value | |
| Hierarki Grup Perangkat (dg_hier_level_3) | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key dan additional.fields.value.string_value | |
| Hierarki Grup Perangkat (dg_hier_level_4) | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key dan additional.fields.value.string_value | |
| Nama Sistem Virtual (vsys_name) | intermediary.asset.attribute.labels.key/value | |||
| Nama Perangkat (device_name) | intermediary.hostname | |||
| ID Sistem Virtual (vsys_id) | intermediary.resource.product_object_id | |||
| Subkategori Aplikasi (subcategory_of_app) | subcategory_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Kategori Aplikasi (category_of_app) | category_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Teknologi Aplikasi (technology_of_app) | technology_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Risiko Aplikasi (risk_of_app) | security_result.severity | |||
| Karakteristik Aplikasi (characteristic_of_app) | characteristic_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Penampung Aplikasi (container_of_app) | container_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| SaaS Aplikasi (is_saas_of_app) | is_saas_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Status Aplikasi yang Tidak Diizinkan (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Tingkat keparahan (severity) | number-of-severity(header) | security_result.severity dan security_result.severity_details |
Terowongan
Tabel berikut mencantumkan kolom log jenis log tunnel dan kolom UDM yang sesuai.
| Kolom CSV | Kolom CEF | Kolom LEEF | Kunci label Google Security Operations | Kolom UDM |
|---|---|---|---|---|
| Waktu Penerimaan (receive_time atau cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (jika "Generate Time" tidak ada) |
|
| Nomor Seri (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Jenis (type) | type (Header) | cat | metadata.product_event_type | |
| Jenis Ancaman/Konten (subjenis) | subjenis (Header) | Subjenis | metadata.product_event_type | |
| Waktu yang Dihasilkan (time_generated atau cef-formatted-time_generated) | metadata.event_timestamp | |||
| Alamat Sumber (src) | src | src | principal.ip | |
| Alamat Tujuan (dst) | dst | dst | target.ip | |
| IP Sumber NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP Tujuan NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Nama Aturan (rule) | cs1 | RuleName | security_result.rule_name | |
| Pengguna Sumber (srcuser) | suser | SourceUser / usrName | principal.user.userid | |
| Pengguna Tujuan (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplikasi (aplikasi) | aplikasi | Aplikasi | network.application_protocol | |
| Sistem Virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona Sumber (dari) | cs4 | SourceZone | dari | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
| Zona Tujuan (ke) | cs5 | DestinationZone | sampai | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
| Antarmuka Masuk (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
| Antarmuka Keluar (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
| Tindakan Log (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key dan additional.fields.value.string_value |
| ID Sesi (sessionid) | cn1 | SessionID | network.session_id | |
| Jumlah Pengulangan (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key dan additional.fields.value.string_value |
| Port Sumber (sport) | spt | srcPort | principal.port | |
| Port Tujuan (dport) | dpt | dstPort | target.port | |
| Port Sumber NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Port Tujuan NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Tanda (flags) | flexString1 | Flag | flag | additional.fields.key dan additional.fields.value.string_value |
| Protokol IP (proto) | proto | proto | network.ip_protocol | |
| Tindakan (action) | act | tindakan | security_result.action_details
security_result.action |
|
| Tingkat keparahan (severity) | number-of-severity(header) | security_result.severity dan security_result.severity_details | ||
| Nomor Urut (seqno) | externalId | urutan | metadata.product_log_id | |
| Flag Tindakan (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key dan additional.fields.value.string_value |
| Lokasi Sumber (srcloc) | principal.location.country_or_region | |||
| Lokasi Tujuan (dstloc) | target.location.country_or_region | |||
| Hierarki Grup Perangkat (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key dan additional.fields.value.string_value |
| Nama Sistem Virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nama Perangkat (device_name) | dvchost | DeviceName | intermediary.hostname | |
| ID Tunnel (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key dan additional.fields.value.string_value |
| Tag Monitor (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key dan additional.fields.value.string_value |
| ID Sesi Induk (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Waktu Mulai Induk (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key dan additional.fields.value.string_value |
| Jenis Tunnel (tunnel) | cs2 | TunnelType | tunnel | additional.fields.key dan additional.fields.value.string_value |
| Byte (byte) | flexNumber1 | totalBytes | byte | additional.fields.key dan additional.fields.value.string_value |
| Byte Terkirim (bytes_sent) | di | srcBytes | network.sent_bytes | |
| Byte Diterima (bytes_received) | keluar | dstBytes | network.received_bytes | |
| Paket (packets) | cn2 | totalPackets | paket | additional.fields.key dan additional.fields.value.string_value |
| Paket Terkirim (pkts_sent) | PanOSPacketsSent | srcPackets | pkts_sent | network.sent_packets |
| Paket Diterima (pkts_received) | PanOSPacketsReceived | dstPackets | pkts_received | network.received_packets |
| Enkapsulasi Maksimum (max_encap) | flexNumber2 | MaximumEncapsulation | max_encap | additional.fields.key dan additional.fields.value.string_value |
| Protokol Tidak Dikenal (unknown_proto) | cfp1 | UnknownProtocol | unknown_proto | additional.fields.key dan additional.fields.value.string_value |
| Pemeriksaan Ketat (strict_check) | cfp2 | StrictChecking | strict_check | additional.fields.key dan additional.fields.value.string_value |
| Fragmen Tunnel (tunnel_fragment) | PanOSTunnelFragment | TunnelFragment | tunnel_fragment | additional.fields.key dan additional.fields.value.string_value |
| Sesi Dibuat (sessions_created) | cfp3 | SessionsCreated | sessions_created | additional.fields.key dan additional.fields.value.string_value |
| Sesi Ditutup (sessions_closed) | cfp4 | SessionsClosed | sessions_closed | additional.fields.key dan additional.fields.value.string_value |
| Alasan Akhir Sesi (session_end_reason) | alasan | SessionEndReason | security_result.summary | |
| Sumber Tindakan (action_source) | cat | ActionSource | action_source | additional.fields.key dan additional.fields.value.string_value |
| Waktu Mulai (start) | startTime | mulai | additional.fields.key dan additional.fields.value.string_value | |
| Waktu Berlalu (elapsed) | cn3 | ElapsedTime | berlalu | network.session_duration.seconds |
| Aturan Inspeksi Tunnel (tunnel_insp_rule) | PanOSTunneInspectionRule | security_result.rule_name = "Tunnel Inspection Rule: %{PanOSTunnelInspectionRule}" | ||
| IP Pengguna Jarak Jauh (remote_user_ip) | PanOSRmtUserIP | principal.ip | ||
| ID Pengguna Jarak Jauh (remote_user_id) | PanOSRmtUserID | remote_user_id | principal.user.userid | |
| UUID Aturan Keamanan (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| ID PCAP (pcap_id) | PanOSPcapID | pcap_id | additional.fields.key dan additional.fields.value.string_value | |
| Nama Grup Pengguna Dinamis (dynusergroup_name) | PanDynamicUsrgrp | principal.group.group_display_name | ||
| Daftar Dinamis Eksternal Sumber (src_edl) | PanOSSourceEDL | src_edl | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
|
| Daftar Dinamis Eksternal Tujuan (dst_edl) | PanOSDestinationEDL | dst_edl | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
|
| Stempel Waktu Resolusi Tinggi (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key dan additional.fields.value.string_value | ||
| Pembeda Slice (nssai_sd) | nssai_sd | additional.fields.key dan additional.fields.value.string_value | ||
| Jenis Layanan Slice (nssai_sd) | nssai_sd1 | additional.fields.key dan additional.fields.value.string_value | ||
| ID Sesi PDU (pdu_session_id) | pdu_session_id | additional.fields.key dan additional.fields.value.string_value | ||
| Subkategori Aplikasi (subcategory_of_app) | subcategory_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Kategori Aplikasi (category_of_app) | category_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Teknologi Aplikasi (technology_of_app) | technology_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Risiko Aplikasi (risk_of_app) | risk_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Karakteristik Aplikasi (characteristic_of_app) | characteristic_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Penampung Aplikasi (container_of_app) | container_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| SaaS Aplikasi (is_saas_of_app) | is_saas_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Aplikasi yang Ditunnelkan (tunneled_app) | additional.fields.key dan additional.fields.value.string_value | |||
| Dikeluarkan (dikeluarkan) | additional.fields.key dan additional.fields.value.string_value | |||
| Jenis Alur (flow_type) | additional.fields.key dan additional.fields.value.string_value | |||
| Nama Cluster (cluster_name) |
principal.resource.name |
|||
| Status Aplikasi yang Tidak Diizinkan (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key dan additional.fields.value.string_value |
Autentikasi
Tabel berikut mencantumkan kolom log jenis log autentikasi dan kolom UDM yang sesuai.
| Kolom CSV | Kolom CEF | Kolom LEEF | Kunci label Google Security Operations | Kolom UDM |
|---|---|---|---|---|
| Waktu Penerimaan (receive_time atau cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (jika "Generate Time" tidak ada) |
|
| Nomor Seri (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Jenis (type) | type (Header) | cat | metadata.product_event_type | |
| Jenis Ancaman/Konten (subjenis) | subjenis (Header) | Subjenis | metadata.product_event_type | |
| Waktu yang Dihasilkan (time_generated atau cef-formatted-time_generated) | metadata.event_timestamp | |||
| Sistem Virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| IP Sumber (ip) | src | src | principal.ip | |
| Pengguna (user) | duser | usrName | target.user.userid | |
| Normalisasi Pengguna (normalize_user) | cs2 | NormalizeUser | target.user.user_display_name | |
| Objek (object) | fname | ObjectName | objek | target.resource.name |
| Kebijakan Autentikasi (authpolicy) | cs4 | AuthPolicy | authpolicy | additional.fields.key dan additional.fields.value.string_value |
| Jumlah Pengulangan (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key dan additional.fields.value.string_value |
| ID autentikasi (authid) | cn2 | AuthenticationID | authid | additional.fields.key dan additional.fields.value.string_value |
| Vendor (vendor) | flexString2 | Vendor | vendor | additional.fields.key dan additional.fields.value.string_value |
| Tindakan Log (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key dan additional.fields.value.string_value |
| Profil Server (serverprofile) | cs1 | ServerProfile | serverprofile | additional.fields.key dan additional.fields.value.string_value |
| Deskripsi (turun) | PanOSDesc | AdditionalAuthInfo | security_result.description | |
| Jenis Klien (clienttype) | cs5 | ClientType | clienttype | additional.fields.key dan additional.fields.value.string_value |
| Jenis Peristiwa (event) | msg | msg | extensions.auth.auth_details | |
| Nomor Faktor (factorno) | cn1 | FactorNumber | factorno | additional.fields.key dan additional.fields.value.string_value |
| Nomor Urut (seqno) | externalId | urutan | metadata.product_log_id | |
| Flag Tindakan (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key dan additional.fields.value.string_value |
| Hierarki Grup Perangkat (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key dan additional.fields.value.string_value |
| Nama Sistem Virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nama Perangkat (device_name) | dvchost | DeviceName | intermediary.hostname | |
| ID Sistem Virtual (vsys_id) | intermediary.resource.product_object_id | |||
| Authentication Protocol (authproto) | authproto | additional.fields.key dan additional.fields.value.string_value | ||
| UUID untuk aturan (rule_uuid) | PanOSRuleUUID/RuleUUID | security_result.rule_id | ||
| Stempel Waktu Resolusi Tinggi (high_res _timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key dan additional.fields.value.string_value | ||
| Kategori Perangkat Sumber (src_category) | PanOSSourceDeviceCategory | src_category | principal.asset.category | |
| Profil Perangkat Sumber (src_profile) | PanOSSourceDeviceProfile | src_profile | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
|
| Model Perangkat Sumber (src_model) | PanOSSourceDeviceModel | src_model | principal.asset.hardware.model | |
| Vendor Perangkat Sumber (src_vendor) | PanOSSourceDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Grup OS Perangkat Sumber (src_osfamily) | PanOSSourceDeviceOSFamily | principal.asset.platform_software.platform principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
||
| Versi OS Perangkat Sumber (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | ||
| Nama Host Sumber (src_host) | PanOSSourceHostname | principal.hostname | ||
| Alamat MAC Sumber (src_mac) | PanOSSourceMac | principal.asset.mac | ||
| Wilayah (region) | PanOSTrafficOriginRegion | principal.location.country_or_region | ||
| Agen Pengguna (user_agent) | PanOSHTTPUserAgent | network.http.user_agent | ||
| ID Sesi(sessionid) | PanOSTrafficSessionID | network.session_id | ||
| Tingkat keparahan (severity) | number-of-severity(header) | security_result.severity dan security_result.severity_details | ||
| Nama Cluster (cluster_name) | principal.resource.name |
URL
Tabel berikut mencantumkan kolom log jenis log URL dan kolom UDM yang sesuai.
| Kolom CSV | Kolom CEF | Kolom LEEF | Kunci label Google Security Operations | Kolom UDM |
|---|---|---|---|---|
| Waktu Penerimaan (cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (jika "Generate Time" tidak ada) |
|
| Nomor seri (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Jenis (type) | type (Header) | cat | metadata.product_event_type | |
| Jenis Ancaman/Konten (subjenis) | subjenis (Header) | Subjenis | metadata.product_event_type | |
| Buat Waktu | metadata.event_timestamp | |||
| Alamat sumber (src) | src | src | principal.ip | |
| Alamat tujuan (dst) | dst | dst | target.ip | |
| IP Sumber NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP Tujuan NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Aturan (rule) | cs1 | RuleName | security_result.rule_name | |
| Pengguna Sumber (srcuser) | suser | SourceUser | principal.user.userid | |
| Pengguna Tujuan (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplikasi (aplikasi) | aplikasi | Aplikasi | network.application_protocol | |
| Sistem Virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona Sumber (dari) | cs4 | SourceZone | dari | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
| Zona Tujuan (ke) | cs5 | DestinationZone | sampai | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
| Antarmuka Masuk (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
| Antarmuka Keluar (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
| Tindakan Log (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key dan additional.fields.value.string_value |
| Waktu yang Dicatat | time_logged | additional.fields.key dan additional.fields.value.string_value | ||
| ID Sesi (sessionid) | cn1 | SessionID | network.session_id | |
| Jumlah Pengulangan (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key dan additional.fields.value.string_value |
| Port Sumber (sport) | spt | srcPort | principal.port | |
| Port Tujuan (dport) | dpt | dstPort | target.port | |
| Port Sumber NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Port Tujuan NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Tanda (flags) | flexString1 | Flag | flag | additional.fields.key dan additional.fields.value.string_value |
| Protokol IP (proto) | proto | proto | network.ip_protocol | |
| Tindakan (action) | act | tindakan | security_result.action_details
security_result.action |
|
| URL/Nama file (lain-lain) | Lain-lain | target.file.names
target.url |
||
| Nama Ancaman/Konten (threatid) | cat | ThreatID | security_result.threat_id | |
| Kategori (category) | cs2 | URLCategory | category | security_result.category_details |
| Tingkat keparahan (severity) | number-of-severity (Header) | Keparahan | security_result.severity
security_result.severity_details |
|
| Arah (direction) | flexString2 | Arah | network.direction | |
| Nomor Urut (seqno) | externalId | urutan | metadata.product_log_id | |
| Flag Tindakan (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key dan additional.fields.value.string_value |
| Negara Sumber (srcloc) | SourceLocation | principal.location.country_or_region | ||
| Negara Tujuan (dstloc) | DestinationLocation | target.location.country_or_region | ||
| contenttype (contenttype) | requestContext | ContentType | contenttype | additional.fields.key dan additional.fields.value.string_value |
| pcap_id (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key dan additional.fields.value.string_value |
| filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | ||
| cloud (cloud) | Cloud | cloud | additional.fields.key dan additional.fields.value.string_value | |
| url_idx (url_idx) | URLIndex | url_idx | additional.fields.key dan additional.fields.value.string_value | |
| user_agent (user_agent) | requestClientApplication | UserAgent | network.http.user_agent | |
| filetype (jenis file) | target.file.mime_type | |||
| xff (xff) | PanOSXForwarderfor | identSrc | xff | principal.ip |
| perujuk (referer) | PanOSReferer | Referer | network.http.referral_url | |
| pengirim (sender) | network.email.from | |||
| subjek (subject) | Subjek | network.email.subject | ||
| penerima (penerima) | network.email.to | |||
| reportid (reportid) | reportid | additional.fields.key dan additional.fields.value.string_value | ||
| Tingkat Hierarki DG 1 (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key dan additional.fields.value.string_value |
| Level Hierarki DG 2 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key dan additional.fields.value.string_value |
| Level Hierarki DG 3 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key dan additional.fields.value.string_value |
| Level Hierarki DG 4 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key dan additional.fields.value.string_value |
| Nama Sistem Virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nama Perangkat (device_name) | dvchost | DeviceName | intermediary.hostname | |
| file_url (file_url) | target.url | |||
| UUID VM Sumber (src_uuid) | SrcUUID | principal.asset.product_object_id | ||
| UUID VM tujuan (dst_uuid) | DstUUID | target.asset.product_object_id | ||
| http_method (http_method) | requestMethod | RequestMethod | network.http.method | |
| ID/IMSI Tunnel (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key dan additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key dan additional.fields.value.string_value |
| ID Sesi Induk (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Waktu Mulai Sesi Orang Tua (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key dan additional.fields.value.string_value |
| Tunnel (tunnel) | PanOSTunnelType | TunnelType | tunnel | additional.fields.key dan additional.fields.value.string_value |
| thr_category (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| contentver (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key dan additional.fields.value.string_value |
| sig_flags (sig_flags) | sig_flags | additional.fields.key dan additional.fields.value.string_value | ||
| ID Asosiasi SCTP (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key dan additional.fields.value.string_value | |
| ID Protokol Payload (ppid) | PanOSPPID | ppid | additional.fields.key dan additional.fields.value.string_value | |
| http_headers (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Daftar Kategori URL (url_category_list) | PanOSURLCatList | url_category_list | additional.fields.key dan additional.fields.value.string_value | |
| UUID untuk aturan (rule_uuid) | PanOSRuleUUID | rule_uuid | security_result.rule_id | |
| Koneksi HTTP/2 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| dynusergroup_name (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | additional.fields.key dan additional.fields.value.string_value | |
| Alamat XFF (xff_ip) | PanXFFIP | principal.ip | ||
| Kategori Perangkat Sumber (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Profil Perangkat Sumber (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
|
| Model Perangkat Sumber (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Vendor Perangkat Sumber (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Grup OS Perangkat Sumber (src_osfamily) | PanSrcDeviceOS | principal.platform | ||
| Versi OS Perangkat Sumber (src_osversion) | PanSrcDeviceOSv | principal.platform_version | ||
| Nama Host Sumber (src_host) | PanSrcHostname | src_host | principal.hostname | |
| Alamat Mac Sumber (src_mac) | PanSrcMac | principal.mac | ||
| Kategori Perangkat Tujuan (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Profil Perangkat Tujuan (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
|
| Model Perangkat Tujuan (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Vendor Perangkat Tujuan (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Keluarga OS Perangkat Tujuan (dst_osfamily) | PanDstDeviceOS | target.platform | ||
| Versi OS Perangkat Tujuan (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Nama Host Tujuan (dst_host) | PanPODNamespace | target.hostname | ||
| Alamat Mac Tujuan (dst_mac) | PanDstMac | target.mac | ||
| ID Penampung (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| Namespace POD (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| Nama POD (pod_name) | PanPODName | pod_name | target.resource.name | |
| Daftar Dinamis Eksternal Sumber (src_edl) | PanSrcEDL | src_edl | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
|
| Daftar Dinamis Eksternal Tujuan (dst_edl) | PanDstEDL | dst_edl | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
|
| ID Host (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Nomor Seri (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| domain_edl (domain_edl) | PanDomainEDL | domain_edl | additional.fields.key dan additional.fields.value.string_value | |
| Grup Alamat Dinamis Sumber (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Grup Alamat Dinamis Tujuan (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| partial_hash (partial_hash) | PanPartialHash | partial_hash | additional.fields.key dan additional.fields.value.string_value | |
| Stempel Waktu Resolusi Tinggi (high_res_timestamp) | PanTimeHighRes | additional.fields.key dan additional.fields.value.string_value | ||
| Alasan (reason) | PanReasonFilteringAction | alasan | security_result.summary | |
| justifikasi (justifikasi) | PanJustification | perataan kanan kiri | additional.fields.key dan additional.fields.value.string_value | |
| nssai_sst (nssai_sst) | PanASServiceType | nssai_sst | additional.fields.key dan additional.fields.value.string_value | |
| Subkategori aplikasi (subcategory_of_app) | subcategory_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Kategori aplikasi (category_of_app) | category_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Teknologi aplikasi (technology_of_app) | technology_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Risiko aplikasi (risk_of_app) | risk_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Karakteristik aplikasi (characteristic_of_app) | characteristic_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Container aplikasi (container_of_app) | container_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Aplikasi yang di-tunnel (tunneled_app) | tunneled_app | additional.fields.key dan additional.fields.value.string_value | ||
| SaaS aplikasi (is_saas_of_app) | is_saas_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Status aplikasi yang tidak diizinkan (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| ID Laporan Cloud (cloud_reportid) | additional.fields.key dan additional.fields.value.string_value | |||
| Nama Cluster (cluster_name) |
principal.resource.name |
|||
| Jenis Alur (flow_type) | additional.fields.key dan additional.fields.value.string_value |
Data
Tabel berikut mencantumkan kolom log jenis log data dan kolom UDM yang sesuai.
| Kolom CSV | Kolom CEF | Kolom LEEF | Kunci label Google Security Operations | Kolom UDM |
|---|---|---|---|---|
| Waktu Penerimaan (cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (jika "Generate Time" tidak ada) |
|
| Nomor seri (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Jenis (type) | type (Header) | cat | metadata.product_event_type | |
| Jenis Ancaman/Konten (subjenis) | subjenis (Header) | Subjenis | metadata.product_event_type | |
| Buat Waktu | metadata.event_timestamp | |||
| Alamat sumber (src) | src | src | principal.ip | |
| Alamat tujuan (dst) | dst | dst | target.ip | |
| IP Sumber NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP Tujuan NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Aturan (rule) | cs1 | RuleName | security_result.rule_name | |
| Pengguna Sumber (srcuser) | suser | SourceUser | principal.user.userid | |
| Pengguna Tujuan (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplikasi (aplikasi) | aplikasi | Aplikasi | network.application_protocol | |
| Sistem Virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona Sumber (dari) | cs4 | SourceZone | dari | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
| Zona Tujuan (ke) | cs5 | DestinationZone | sampai | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
| Antarmuka Masuk (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
| Antarmuka Keluar (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
| Tindakan Log (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key dan additional.fields.value.string_value |
| Waktu yang Dicatat | time_logged | additional.fields.key dan additional.fields.value.string_value | ||
| ID Sesi (sessionid) | cn1 | SessionID | network.session_id | |
| Jumlah Pengulangan (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key dan additional.fields.value.string_value |
| Port Sumber (sport) | spt | srcPort | principal.port | |
| Port Tujuan (dport) | dpt | dstPort | target.port | |
| Port Sumber NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Port Tujuan NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Tanda (flags) | flexString1 | Flag | flag | additional.fields.key dan additional.fields.value.string_value |
| Protokol IP (proto) | proto | proto | network.ip_protocol | |
| Tindakan (action) | act | tindakan | security_result.action_details
security_result.action |
|
| URL/Nama file (lain-lain) | Lain-lain | target.file.names
target.url |
||
| Nama Ancaman/Konten (threatid) | cat | ThreatID | security_result.threat_id | |
| Kategori (category) | cs2 | URLCategory | category | security_result.category_details |
| Tingkat keparahan (severity) | number-of-severity (Header) | Keparahan | security_result.severity
security_result.severity_details |
|
| Arah (direction) | flexString2 | Arah | network.direction | |
| Nomor Urut (seqno) | externalId | urutan | metadata.product_log_id | |
| Flag Tindakan (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key dan additional.fields.value.string_value |
| Negara Sumber (srcloc) | SourceLocation | principal.location.country_or_region | ||
| Negara Tujuan (dstloc) | DestinationLocation | target.location.country_or_region | ||
| contenttype (contenttype) | ContentType | contenttype | additional.fields.key dan additional.fields.value.string_value | |
| pcap_id (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key dan additional.fields.value.string_value |
| filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | ||
| cloud (cloud) | Cloud | cloud | additional.fields.key dan additional.fields.value.string_value | |
| url_idx (url_idx) | URLIndex | url_idx | additional.fields.key dan additional.fields.value.string_value | |
| user_agent (user_agent) | network.http.user_agent | |||
| filetype (jenis file) | target.file.mime_type | |||
| xff (xff) | xff | principal.ip | ||
| perujuk (referer) | network.http.referral_url | |||
| pengirim (sender) | network.email.from | |||
| subjek (subject) | Subjek | network.email.subject | ||
| penerima (penerima) | network.email.to | |||
| reportid (reportid) | reportid | additional.fields.key dan additional.fields.value.string_value | ||
| Tingkat Hierarki DG 1 (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key dan additional.fields.value.string_value |
| Level Hierarki DG 2 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key dan additional.fields.value.string_value |
| Level Hierarki DG 3 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key dan additional.fields.value.string_value |
| Level Hierarki DG 4 (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key dan additional.fields.value.string_value |
| Nama Sistem Virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nama Perangkat (device_name) | dvchost | DeviceName | intermediary.hostname | |
| file_url (file_url) | target.url | |||
| UUID VM Sumber (src_uuid) | SrcUUID | principal.asset.product_object_id | ||
| UUID VM tujuan (dst_uuid) | DstUUID | target.asset.product_object_id | ||
| http_method (http_method) | RequestMethod | network.http.method | ||
| ID/IMSI Tunnel (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key dan additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key dan additional.fields.value.string_value |
| ID Sesi Induk (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Waktu Mulai Sesi Orang Tua (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key dan additional.fields.value.string_value |
| Tunnel (tunnel) | PanOSTunnelType | TunnelType | tunnel | additional.fields.key dan additional.fields.value.string_value |
| thr_category (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| contentver (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key dan additional.fields.value.string_value |
| sig_flags (sig_flags) | sig_flags | additional.fields.key dan additional.fields.value.string_value | ||
| ID Asosiasi SCTP (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key dan additional.fields.value.string_value | |
| ID Protokol Payload (ppid) | PanOSPPID | ppid | additional.fields.key dan additional.fields.value.string_value | |
| http_headers (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Daftar Kategori URL (url_category_list) | url_category_list | additional.fields.key dan additional.fields.value.string_value | ||
| UUID untuk aturan (rule_uuid) | PanOSRuleUUID | rule_uuid | security_result.rule_id | |
| Koneksi HTTP/2 (http2_connection) | http2_connection | network.application_protocol_version | ||
| dynusergroup_name (dynusergroup_name) | dynusergroup_name | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
||
| Alamat XFF (xff_ip) | principal.ip | |||
| Kategori Perangkat Sumber (src_category) | src_category | principal.asset.category | ||
| Profil Perangkat Sumber (src_profile) | src_profile | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
||
| Model Perangkat Sumber (src_model) | src_model | principal.asset.hardware.model | ||
| Vendor Perangkat Sumber (src_vendor) | src_vendor | principal.asset.hardware.manufacturer | ||
| Grup OS Perangkat Sumber (src_osfamily) | principal.platform | |||
| Versi OS Perangkat Sumber (src_osversion) | principal.platform_version | |||
| Nama Host Sumber (src_host) | src_host | principal.hostname | ||
| Alamat Mac Sumber (src_mac) | principal.mac | |||
| Kategori Perangkat Tujuan (dst_category) | dst_category | target.asset.category | ||
| Profil Perangkat Tujuan (dst_profile) | dst_profile | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
||
| Model Perangkat Tujuan (dst_model) | dst_model | target.asset.hardware.model | ||
| Vendor Perangkat Tujuan (dst_vendor) | dst_vendor | target.asset.hardware.manufacturer | ||
| Keluarga OS Perangkat Tujuan (dst_osfamily) | target.platform | |||
| Versi OS Perangkat Tujuan (dst_osversion) | target.platform_version | |||
| Nama Host Tujuan (dst_host) | target.hostname | |||
| Alamat Mac Tujuan (dst_mac) | target.mac | |||
| ID Penampung (container_id) | container_id | intermediary.resource.product_object_id | ||
| Namespace POD (pod_namespace) | pod_namespace | target.resource.attribute.labels.key/value | ||
| Nama POD (pod_name) | pod_name | target.resource.name | ||
| Daftar Dinamis Eksternal Sumber (src_edl) | src_edl | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
||
| Daftar Dinamis Eksternal Tujuan (dst_edl) | dst_edl | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
||
| ID Host (hostid) | hostid | principal.asset.asset_id | ||
| Nomor Seri (serialnumber) | principal.asset.hardware.serial_number | |||
| domain_edl (domain_edl) | domain_edl | additional.fields.key dan additional.fields.value.string_value | ||
| Grup Alamat Dinamis Sumber (src_dag) | principal.group.group_display_name | |||
| Grup Alamat Dinamis Tujuan (dst_dag) | target.group.group_display_name | |||
| partial_hash (partial_hash) | partial_hash | additional.fields.key dan additional.fields.value.string_value | ||
| Stempel Waktu Resolusi Tinggi (high_res_timestamp) | additional.fields.key dan additional.fields.value.string_value | |||
| Alasan (reason) | alasan | security_result.summary | ||
| justifikasi (justifikasi) | perataan kanan kiri | additional.fields.key dan additional.fields.value.string_value | ||
| nssai_sst (nssai_sst) | nssai_sst | additional.fields.key dan additional.fields.value.string_value | ||
| Subkategori aplikasi (subcategory_of_app) | subcategory_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Kategori aplikasi (category_of_app) | category_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Teknologi aplikasi (technology_of_app) | technology_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Risiko aplikasi (risk_of_app) | risk_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Karakteristik aplikasi (characteristic_of_app) | characteristic_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Container aplikasi (container_of_app) | container_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Aplikasi yang di-tunnel (tunneled_app) | tunneled_app | additional.fields.key dan additional.fields.value.string_value | ||
| SaaS aplikasi (is_saas_of_app) | is_saas_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Status aplikasi yang tidak diizinkan (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| ID Laporan Cloud (cloud_reportid) | additional.fields.key dan additional.fields.value.string_value | |||
| Nama Cluster (cluster_name) | principal.resource.name | |||
| Jenis Alur (flow_type) | additional.fields.key dan additional.fields.value.string_value |
GlobalProtect
Tabel berikut mencantumkan kolom log jenis log GlobalProtect dan kolom UDM yang sesuai.
| Kolom CSV | Kolom CEF | Kolom LEEF | Kunci label Google Security Operations | Kolom UDM |
|---|---|---|---|---|
| Waktu Diterima (receive_time) | rt | received_time | metadata.event_timestamp | |
| Nomor seri (serial) | PanOSDeviceSN | intermediary_asset_hardware_serial_number | intermediary.asset.hardware.serial_number | |
| Jenis (type) | type (Header) | metadata.product_event_type | ||
| Jenis Ancaman/Konten (subjenis) | subjenis (Header) | Subjenis | metadata.product_event_type | |
| Waktu Pembuatan (time_generated) | PanOSLogTimeStamp | generated_timestamp | metadata.event_timestamp | |
| Sistem Virtual (vsys) | PanOSVirtualSystem | vsys | intermediary.asset.attribute.labels.key/value | |
| ID Acara (eventid) | PanOSEventID | event_id | additional.fields.key dan additional.fields.value.string_value | |
| Tahap (stage) | PanOSStage | tahap | additional.fields.key dan additional.fields.value.string_value | |
| Metode Autentikasi (auth_method) | PanOSAuthMethod | extension_auth_auth_details | extensions.auth.auth_details | |
| Jenis Tunnel (tunnel_type) | PanOSTunnelType | tunnel | additional.fields.key dan additional.fields.value.string_value | |
| Pengguna Sumber (srcuser) | PanOSSourceUserName | src_user | principal.user.email_address
principal.user.userid principal.administrative_domain |
|
| Wilayah Sumber (srcregion) | PanOSSourceRegion | src_region | principal.location.country_or_region | |
| Nama Perangkat (machinename) | PanOSEndpointDeviceName | machine_name | principal.hostname | |
| IP Publik (public_ip) | PanOSPublicIPv4 | principal.nat_ip | ||
| IPv6 publik (public_ipv6) | PanOSPublicIPv6 | principal.nat_ip | ||
| IP Pribadi (private_ip) | PanOSPrivateIPv4 | principal.ip | ||
| IPv6 pribadi (private_ipv6) | PanOSPrivateIPv6 | principal.ip | ||
| ID Host (hostid) | PanOSHostID | hostid | principal.asset.asset_id | |
| Nomor Seri (serialnumber) | PanOSDeviceSN | principal.asset.hardware.serial_number | ||
| Versi Klien (client_ver) | PanOSGlobalProtectClientVersion | client_ver | additional.fields.key dan additional.fields.value.string_value | |
| OS Klien (client_os) | PanOSEndpointOSType | principal.platform | ||
| Versi OS Klien (client_os_ver) | PanOSEndpointOSVersion | principal.platform_version | ||
| Jumlah Pengulangan (repeatcnt) | PanOSCountOfRepeats | repeatcnt | additional.fields.key dan additional.fields.value.string_value | |
| Alasan (reason) | PanOSQuarantineReason | security_result.summary | ||
| Error (error) | PanOSConnectionError | error | security_result.description | |
| Deskripsi (buram) | PanOSDescription | security_result.description | ||
| Status (status) | PanOSEventStatus | status | additional.fields.key dan additional.fields.value.string_value | |
| Lokasi (location) | PanOSGPGatewayLocation | target.location.country_or_region | ||
| Durasi Login (login_duration) | PanOSLoginDuration | network.session_duration | ||
| Metode Koneksi (connect_method) | PanOSConnectionMethod | connect_method | additional.fields.key dan additional.fields.value.string_value | |
| Kode Error (error_code) | PanOSConnectionErrorID | error_code | additional.fields.key dan additional.fields.value.string_value | |
| Portal (portal) | PanOSPortal | portal | additional.fields.key dan additional.fields.value.string_value | |
| Nomor Urut (seqno) | PanOSSequenceNo | metadata.product_log_id | ||
| Flag Tindakan (actionflags) | PanOSActionFlags | actionflags | additional.fields.key dan additional.fields.value.string_value | |
| Stempel Waktu Resolusi Tinggi (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key dan additional.fields.value.string_value | ||
| Metode Pemilihan Gateway (selection_type) | PanOSGatewaySelectionType | selection_type | additional.fields.key dan additional.fields.value.string_value | |
| Waktu Respons SSL (response_time) | PanOSSSLResponseTime | response_time | additional.fields.key dan additional.fields.value.string_value | |
| Prioritas Gateway (prioritas) | PanOSGatewayPriority | priority | additional.fields.key dan additional.fields.value.string_value | |
| Gateway yang Dicoba (attempted_gateways) | PanOSAttemptedGateways | attempted_gateways | additional.fields.key dan additional.fields.value.string_value | |
| Nama Gateway (gateway) | PanOSAttemptedGateways | gateway | target.resource.name | |
| Hierarki Grup Perangkat (dg_hier_level_1) | dg_hier_level_1 | additional.fields.key dan additional.fields.value.string_value | ||
| Hierarki Grup Perangkat (dg_hier_level_2) | dg_hier_level_2 | additional.fields.key dan additional.fields.value.string_value | ||
| Hierarki Grup Perangkat (dg_hier_level_3) | dg_hier_level_3 | additional.fields.key dan additional.fields.value.string_value | ||
| Hierarki Grup Perangkat (dg_hier_level_4) | dg_hier_level_4 | additional.fields.key dan additional.fields.value.string_value | ||
| Nama Sistem Virtual (vsys_name) | intermediary.asset.attribute.labels.key/value | |||
| Nama Perangkat (device_name) | intermediary.hostname | |||
| ID Sistem Virtual (vsys_id) | intermediary.resource.product_object_id | |||
| Tingkat keparahan (severity) | number-of-severity(header) | security_result.severity dan security_result.severity_details | ||
| Nama Cluster (cluster_name) | principal.resource.name |
Korelasi
Tabel berikut mencantumkan kolom log jenis log Korelasi dan kolom UDM yang sesuai.
| Kolom CSV | Kolom CEF | Kolom LEEF | Kunci label Google Security Operations | Kolom UDM |
|---|---|---|---|---|
| Waktu yang Dihasilkan (time_generated atau cef-formatted-time_generated) | startTime | generated_timestamp | metadata.event_timestamp | |
| Alamat Sumber (src) | src | principal.ip | ||
| Pengguna Sumber (srcuser) | SourceUser / usrName | principal.user.userid | ||
| Sistem Virtual (vsys) | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value | |
| Kategori (category) | security_result.category_details | |||
| Tingkat keparahan (severity) | Keparahan | security_result.severity dan security_result.severity_details | ||
| Hierarki Grup Perangkat Level 1 | DeviceGroupHierarchyL1 | additional.fields.key dan additional.fields.value.string_value | ||
| Hierarki Grup Perangkat Level 2 | DeviceGroupHierarchyL2 | additional.fields.key dan additional.fields.value.string_value | ||
| Hierarki Grup Perangkat Level 3 | DeviceGroupHierarchyL3 | additional.fields.key dan additional.fields.value.string_value | ||
| Hierarki Grup Perangkat Level 4 | DeviceGroupHierarchyL4 | additional.fields.key dan additional.fields.value.string_value | ||
| Nama Sistem Virtual (vsys_name) | vSrcName | intermediary.asset.attribute.labels.key/value | ||
| Nama Perangkat (device_name) | DeviceName | intermediary.hostname | ||
| ID Sistem Virtual (vsys_id) | VirtualSystemID | intermediary.resource.product_object_id | ||
| Nama Objek (objectname) | ObjectName | target.resource.name | ||
| ID Objek (object_id) | ObjectID | target.resource.product_object_id | ||
| Bukti (evidence) | msg | security_result.summary |
GTP
Tabel berikut mencantumkan kolom log jenis log gtp dan kolom UDM yang sesuai.
| Kolom CSV | Kolom CEF | Kolom LEEF | Kunci label Google Security Operations | Kolom UDM |
|---|---|---|---|---|
| Waktu Penerimaan (receive_time atau cef-formatted-receive_time) | metadata.collected_timestamp,
metadata.event_timestamp (jika "Generate Time" tidak ada) |
|||
| Nomor Seri (serial) | intermediary.asset.hardware.serial_number | |||
| Jenis (type) | metadata.product_event_type | |||
| Jenis Ancaman/Konten (subjenis) | metadata.product_event_type | |||
| Waktu yang Dihasilkan (time_generated atau cef-formatted-time_generated) | metadata.event_timestamp | |||
| Alamat Sumber (src) | principal.ip | |||
| Alamat Tujuan (dst) | target.ip | |||
| Nama Aturan (rule) | security_result.rule_name | |||
| Aplikasi (aplikasi) | network.application_protocol | |||
| Sistem Virtual (vsys) | vsys | intermediary.asset.attribute.labels.key/value | ||
| Zona Sumber (dari) | dari | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
||
| Zona Tujuan (ke) | sampai | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
||
| Antarmuka Masuk (inbound_if) | inbound_if | principal.labels.key dan principal.labels.value additional.fields.key dan additional.fields.value.string_value |
||
| Antarmuka Keluar (outbound_if) | outbound_if | target.labels.key dan target.labels.value additional.fields.key dan additional.fields.value.string_value |
||
| Tindakan Log (logset) | logset | additional.fields.key dan additional.fields.value.string_value | ||
| ID Sesi (sessionid) | network.session_id | |||
| Port Sumber (sport) | principal.port | |||
| Port Tujuan (dport) | target.port | |||
| Protokol IP (proto) | network.ip_protocol | |||
| Tindakan (action) | security_result.action_details
security_result.action |
|||
| Jenis Peristiwa GTP (event_type) | gtp_event_type | additional.fields.key dan additional.fields.value.string_value | ||
| MSISDN (msisdn) | msisdn | additional.fields.key dan additional.fields.value.string_value | ||
| Nama Poin Akses (apn) | apn | additional.fields.key dan additional.fields.value.string_value | ||
| Teknologi Akses Radio (rat) | tikus | additional.fields.key dan additional.fields.value.string_value | ||
| Jenis Pesan GTP (msg_type) | gtp_msg_type | additional.fields.key dan additional.fields.value.string_value | ||
| Alamat IP Akhir (end_ip_adr) | principal.ip | |||
| Tunnel Endpoint Identifier1 (teid1) | teid1 | additional.fields.key dan additional.fields.value.string_value | ||
| Tunnel Endpoint Identifier2 (teid2) | teid2 | additional.fields.key dan additional.fields.value.string_value | ||
| Antarmuka GTP (gtp_interface) | gtp_interface | additional.fields.key dan additional.fields.value.string_value | ||
| Penyebab GTP (cause_code) | gtp_cause_code | additional.fields.key dan additional.fields.value.string_value | ||
| Tingkat keparahan (severity) | security_result.severity dan security_result.severity_details | |||
| MCC Jaringan Penayangan (mcc) | mcc | additional.fields.key dan additional.fields.value.string_value | ||
| Menyajikan MNC Jaringan (mnc) | mnc | additional.fields.key dan additional.fields.value.string_value | ||
| Kode Area (area_code) | area_code | additional.fields.key dan additional.fields.value.string_value | ||
| ID Sel (cell_id) | cell_id | additional.fields.key dan additional.fields.value.string_value | ||
| Kode Acara GTP (event_code) | event_code | additional.fields.key dan additional.fields.value.string_value | ||
| Lokasi Sumber (srcloc) | principal.location.country_or_region | |||
| Lokasi Tujuan (dstloc) | target.location.country_or_region | |||
| ID/IMSI Tunnel (imsi) | tunnelid | additional.fields.key dan additional.fields.value.string_value | ||
| Tag/IMEI Monitor (imei) | monitortag | additional.fields.key dan additional.fields.value.string_value | ||
| Waktu Mulai (start) | mulai | additional.fields.key dan additional.fields.value.string_value | ||
| Waktu Berlalu (elapsed) | network.session_duration.seconds | |||
| Aturan Inspeksi Tunnel (tunnel_insp_rule) | tunnel_insp_rule | security_result.detection_fields.key/value | ||
| IP Pengguna Jarak Jauh (remote_user_ip) | principal.ip | |||
| ID Pengguna Jarak Jauh (remote_user_id) | remote_user_id | principal.user.userid | ||
| UUID untuk aturan (rule_uuid) | security_result.rule_id | |||
| ID PCAP (pcap_id) | pcap_id | additional.fields.key dan additional.fields.value.string_value | ||
| Stempel Waktu Resolusi Tinggi (high_res_timestamp) | additional.fields.key dan additional.fields.value.string_value | |||
| Jenis Layanan Slice (nsdsai_sst) | nsdsai_sst | additional.fields.key dan additional.fields.value.string_value | ||
| Pembeda Slice (nsdsai_sd) | nsdsai_sd | additional.fields.key dan additional.fields.value.string_value | ||
| Subkategori Aplikasi (subcategory_of_app) | subcategory_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Kategori Aplikasi (category_of_app) | category_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Teknologi Aplikasi (technology_of_app) | technology_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Risiko Aplikasi (risk_of_app) | risk_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Karakteristik Aplikasi (characteristic_of_app) | characteristic_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Penampung Aplikasi (container_of_app) | container_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| SaaS Aplikasi (is_saas_of_app) | is_saas_of_app | additional.fields.key dan additional.fields.value.string_value | ||
| Status Aplikasi yang Tidak Diizinkan (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key dan additional.fields.value.string_value |
SCTP
| Kolom CSV | Kolom CEF | Kolom LEEF | Kunci label Google Security Operations | Kolom UDM |
|---|---|---|---|---|
| Waktu Penerimaan (receive_time atau cef-formatted-receive_time) | receive_time atau cef-formatted-receive_time | metadata.collected_timestamp | ||
| Nomor Seri (serial) | serial | intermediary.asset.hardware.serial_number | ||
| Jenis (type) | jenis | metadata.product_event_type | ||
| Waktu yang Dihasilkan (time_generated atau cef-formatted-time_generated) | time_generated atau cef-formatted-time_generated | metadata.event_timestamp | ||
| Alamat Sumber (src) | src | principal.ip | ||
| Alamat Tujuan (dst) | dst | target.ip | ||
| Nama Aturan (rule) | aturan | security_result.rule_name | ||
| Zona Sumber (dari) | dari | additional.fields.key dan additional.fields.value.string_value | ||
| Zona Tujuan (ke) | sampai | additional.fields.key dan additional.fields.value.string_value | ||
| Antarmuka Masuk (inbound_if) | inbound_if | additional.fields.key dan additional.fields.value.string_value | ||
| Antarmuka Keluar (outbound_if) | outbound_if | additional.fields.key dan additional.fields.value.string_value | ||
| Tindakan Log (logset) | logset | additional.fields.key dan additional.fields.value.string_value | ||
| ID Sesi (sessionid) | sessionid | network.session_id | ||
| Jumlah Pengulangan (repeatcnt) | repeatcnt | additional.fields.key dan additional.fields.value.string_value | ||
| Port Sumber (sport) | olahraga | principal.port | ||
| Port Tujuan (dport) | dport | target.port | ||
| Protokol IP (proto) | proto | network.ip_protocol (enum) | ||
| Tindakan (action) | tindakan | security_result.action_details security_result.action |
||
| Hierarki Grup Perangkat (dg_hier_level_1 hingga dg_hier_level_4) | dg_hier_level_1 hingga dg_hier_level_4 | additional.fields.key dan additional.fields.value.string_value | ||
| Nama Perangkat (device_name) | device_name | intermediary.hostname | ||
| Nomor Urut (seqno) | seqno | metadata.product_log_id | ||
| ID Asosiasi SCTP (assoc_id) | assoc_id | additional.fields.key dan additional.fields.value.string_value | ||
| ID Protokol Payload (ppid) | ppid | additional.fields.key dan additional.fields.value.string_value | ||
| Tingkat keparahan (severity) | tingkat keseriusan, | security_result.severity dan security_result.severity_details | ||
| Jenis Chunk SCTP (sctp_chunk_type) | sctp_chunk_type | additional.fields.key dan additional.fields.value.string_value | ||
| Jenis Peristiwa SCTP (sctp_event_type) | sctp_event_type | additional.fields.key dan additional.fields.value.string_value | ||
| Tag Verifikasi SCTP 1 (verif_tag_1) | verif_tag_1 | additional.fields.key dan additional.fields.value.string_value | ||
| Tag Verifikasi SCTP 2 (verif_tag_2) | verif_tag_2 | additional.fields.key dan additional.fields.value.string_value | ||
| Kode Penyebab SCTP (sctp_cause_code) | sctp_cause_code | additional.fields.key dan additional.fields.value.string_value | ||
| ID Aplikasi Diameter (diam_app_id) | diam_app_id | additional.fields.key dan additional.fields.value.string_value | ||
| Kode Perintah Diameter (diam_cmd_code) | diam_cmd_code | additional.fields.key dan additional.fields.value.string_value | ||
| Kode AVP Diameter (diam_avp_code) | diam_avp_code | additional.fields.key dan additional.fields.value.string_value | ||
| ID Aliran SCTP (stream_id) | stream_id | additional.fields.key dan additional.fields.value.string_value | ||
| Alasan Berakhirnya Asosiasi SCTP (assoc_end_reason) | assoc_end_reason | additional.fields.key dan additional.fields.value.string_value | ||
| Kode Operasi (op_code) | op_code | additional.fields.key dan additional.fields.value.string_value | ||
| SSN Pihak Pemanggil SCCP (sccp_calling_ssn) | sccp_calling_ssn | additional.fields.key dan additional.fields.value.string_value | ||
| Judul Global Pihak Pemanggil SCCP (sccp_calling_gt) | sccp_calling_gt | additional.fields.key dan additional.fields.value.string_value | ||
| Filter SCTP (sctp_filter) | sctp_filter | additional.fields.key dan additional.fields.value.string_value | ||
| Potongan SCTP (chunks) | potongan | additional.fields.key dan additional.fields.value.string_value | ||
| SCTP Chunks Sent (chunks_sent) | chunks_sent | additional.fields.key dan additional.fields.value.string_value | ||
| SCTP Chunks yang Diterima (chunks_received) | chunks_received | additional.fields.key dan additional.fields.value.string_value | ||
| Paket (packets) | paket | additional.fields.key dan additional.fields.value.string_value | ||
| UUID untuk aturan (rule_uuid) | rule_uuid | security_result.rule_id | ||
| Sistem Virtual (vsys) | vsys | intermediary.asset.attribute.labels.key/value | ||
| Nama Sistem Virtual (vsys_name) | vsys_name | intermediary.asset.attribute.labels.key/value | ||
| Paket Terkirim (pkts_sent) | pkts_sent | network.sent_packets | ||
| Paket Diterima (pkts_received) | pkts_received | network.received_packets |
Audit
| Kolom CSV | Kolom CEF | Kolom LEEF | Kunci label Google Security Operations | Kolom UDM |
|---|---|---|---|---|
| Buat Waktu | metadata.event_timestamp | |||
| Jenis Ancaman/Konten (subjenis) | metadata.product_event_type | |||
| ID acara | principal.application | |||
| Objek | principal.user.userid | |||
| Perintah CLI | principal.process.command_line | |||
| Keparahan | security_result.severity | |||
| Nomor Seri | intermediary.asset.hardware.serial_number |
Referensi pemetaan kolom: Jenis log ke jenis peristiwa UDM
Tabel berikut mencantumkan jenis log firewall Palo Alto Networks dan jenis peristiwa UDM yang sesuai.
| Jenis log | Jenis peristiwa UDM |
| Traffic | NETWORK_CONNECTION |
| Ancaman | NETWORK_CONNECTION |
| Pemfilteran URL | NETWORK_CONNECTION |
| WildFire | NETWORK_CONNECTION
Log pengiriman WildFire adalah subtipe dari jenis log Ancaman dan menggunakan format syslog yang sama. |
| Pemfilteran Data | NETWORK_CONNECTION |
| Terowongan | NETWORK_CONNECTION |
| GTP | NETWORK_CONNECTION |
| Konfigurasi | SETTING_MODIFICATION/SETTING_CREATION/SETTING_DELETION/SETTING_UNCATEGORIZED
Nilai kolom "Command (cmd)" menentukan pemetaan jenis peristiwa UDM. Jika nilai kolom cmd adalah add atau clone, SETTING_CREATION akan disetel. Jika nilai kolom cmd adalah delete, SETTING_DELETION akan disetel. Jika nilai kolom cmd adalah edit, move, rename, set, atau commit, SETTING_MODIFICATION akan ditetapkan. Jika nilai kolom cmd tidak berisi nilai apa pun, SETTING_UNCATEGORIZED akan ditetapkan. |
| Sistem |
Jika nilai subjenis adalah "dhcp", maka NETWORK_DHCP akan disetel. Jika nilai subjenis adalah "auth", USER_LOGIN akan disetel. Jika nilai deskripsi adalah "logged in", maka USER_LOGIN akan ditetapkan. Jika nilai deskripsi adalah "logged out", maka USER_LOGOUT akan disetel. Untuk nilai subtype lainnya, GENERIC_EVENT ditetapkan. |
| Pencocokan HIP | NETWORK_CONNECTION |
| Tag IP | GENERIC_EVENT |
| User-ID | USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED
Jika nilai subjenis adalah "login", USER_LOGIN akan disetel. Jika nilai subjenis adalah "logout", USER_LOGOUT akan disetel. Jika subtipe tidak berisi nilai apa pun, USER_UNCATEGORIZED akan ditetapkan. |
| Dekripsi | NETWORK_CONNECTION |
| Authentication | GENERIC_EVENT |
| SCTP | NETWORK_CONNECTION |
| Audit | GENERIC_EVENT |
Delta Pemetaan UDM
Referensi Perbedaan Pemetaan UDM: Firewall Palo Alto Networks
Tabel berikut mencantumkan perbedaan antara Pemetaan UDM Lama Palo Alto Networks Firewall dan Pemetaan UDM Baru Palo Alto Networks Firewall.
UDM Event Type Delta
| Log type | Old UDM Event Type | New UDM Event Type |
| WildFire | NETWORK_CONNECTION | SCAN_UNCATEGORIZED |
| Data Filtering | NETWORK_CONNECTION | NETWORK_UNCATEGORIZED |
| Authentication | STATUS_UPDATE | STATUS_UNCATEGORIZED |
UDM Field Mapping Delta
| Log Type | Old UDM Mapping | CSV Log Field | CEF Log Field | LEEF Log Field | New UDM Mapping |
|---|---|---|---|---|---|
| System | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| System | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| System | about.labels.key/value additional.fields.key/value.string_value | Object (object) | fname | Filename | target.resource.name |
| System | Description (opaque) | msg | msg | metadata.description | |
| System | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| System | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| Config | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| Config | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| Config | principal.process.command_line | Configuration Path (path) | msg | ConfigurationPath | principal.process.command_line |
| Config | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| Config | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| Config | principal.asset.attribute.labels.key/value | Device Group (dg_id) | PanOSFWDeviceGroup | target.asset.attribute.labels | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Threat/Wildfire | target.file.full_path target.url target.hostname | URL/Filename (misc) | request | Miscellaneous | target.file.names target.url |
| Threat/Wildfire | about.file.sha1/md5/sha256 | File Digest (filedigest) | fileHash | FileDigest | target.file.sha1/md5/sha256 |
| Threat/Wildfire | about.file.mime_type | File Type (filetype) | fileType | FileType | target.file.mime_type |
| Threat/Wildfire | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Threat/Wildfire | principal.user.product_object_id | Source VM UUID (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id |
| Threat/Wildfire | target.user.product_object_id | Destination VM UUID (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | HTTP Headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| Threat/Wildfire | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| Threat/Wildfire | principal.asset.software.version | Source Device OS Version (src_osversion) | PanSrcDeviceOSv | principal.platform_version | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| Threat/Wildfire | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| Threat/Wildfire | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | PanReasonFilteringAction | security_result.summary | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Packets Sent (pkts_sent) | PanOSPacketsSent | srcPackets | network.sent_packets |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Packets Received (pkts_received) | PanOSPacketsReceived | dstPackets | network.received_packets |
| Traffic | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| Traffic | principal.asset.platform_software.platform(enum) principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| Traffic | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| Traffic | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| User-ID | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| User-ID | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| User-ID | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | intermediary.resource.product_object_id |
| User-ID | principal.user.userid principal.administrative_domain principal.user.email_addresses | User by Source (userbysource) | PanOSUserBySource | target.user.userid target.user.email_addresses | |
| User-ID | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| HIP Match | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | HIP (matchname) | cat | HIP | target.resource.attribute.labels |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | HIP Type (matchtype) | Device Event Class ID (Header) | HIPType | target.resource.attribute.labels |
| HIP Match | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| HIP Match | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| HIP Match | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id |
| HIP Match | principal.asset.product_object_id | Host ID (hostid) | PanOSHostID | principal.asset.asset_id | |
| HIP Match | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| IP-Tag | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| IP-Tag | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| IP-Tag | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOsVsysName | vSrcName | target.asset.attribute.labels |
| IP-Tag | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| IP-Tag | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id |
| IP-Tag | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Decryption | target.application | Application (app) | app | network.application_protocol | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | intermediary.asset.attribute.labels | |
| Decryption | principal.asset.asset_id | Source VM UUID (src_uuid) | PanOSSourceUUID | principal.asset.product_object_id | |
| Decryption | target.asset.asset_id | Destination VM UUID (dst_uuid) | PanOSDestinationUUID | target.asset.product_object_id | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanOSContainerID | intermediary.resource.product_object_id | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanOSContainerNameSpace | target.resource.attribute.labels additional.fields.key/value.string_value | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanOSContainerName | target.resource.name | |
| Decryption | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanOSSourceDeviceCategory | principal.asset.category | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanOSSourceDeviceModel | principal.asset.hardware.model | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanOSSourceDeviceVendor | principal.asset.hardware.manufacturer | |
| Decryption | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanOSSourceDeviceOSFamily | principal.platform | |
| Decryption | principal.asset.software.version | Source Device OS Version (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanOSDestinationDeviceCategory | target.asset.category | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanOSDestinationDeviceModel | target.asset.hardware.model | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanOSDestinationDeviceVendor | target.asset.hardware.manufacturer | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanOSDestinationDeviceOSFamily | target.platform | |
| Decryption | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanOSDestinationDeviceOSVersion | target.platform_version | |
| Decryption | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | intermediary.asset.attribute.labels | ||
| Decryption | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Tunnel | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Packets Sent (pkts_sent) | PanOSPacketsSent | srcPackets | network.sent_packets |
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Packets Received (pkts_received) | PanOSPacketsReceived | dstPackets | network.received_packets |
| Tunnel | target.ip | Remote User IP (remote_user_ip) | PanOSRmtUserIP | principal.ip | |
| Tunnel | target.labels.key/value additional.fields.key/value.string_value | Remote User ID (remote_user_id) | PanOSRmtUserID | principal.user.userid | |
| Tunnel | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Authentication | target.user.user_display_name | Normalize User (normalize_user) | cs2 | NormalizeUser | target.user.user_display_name |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Object (object) | fname | ObjectName | target.resource.name |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Authentication Policy (authpolicy) | cs4 | AuthPolicy | additional.fields.key/value.string_value |
| Authentication | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Authentication | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| Authentication | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res _timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanOSSourceDeviceCategory | principal.asset.category | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanOSSourceDeviceModel | principal.asset.hardware.model | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanOSSourceDeviceVendor | principal.asset.hardware.manufacturer | |
| Authentication | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanOSSourceDeviceOSFamily | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | |
| Authentication | principal.asset.software.version | Source Device OS Version (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| URL | target.file.full_path target.url | URL/Filename (misc) | Miscellaneous | target.file.names target.url | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Category (category) | cs2 | URLCategory | security_result.category_details |
| URL | about.file.sha1/md5/sha256 | filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | |
| URL | about.file.mime_type | filetype (filetype) | target.file.mime_type | ||
| URL | about.labels.key/value additional.fields.key/value.string_value | xff (xff) | PanOSXForwarderfor | identSrc | principal.ip |
| URL | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| URL | about.url | file_url (file_url) | target.url | ||
| URL | principal.asset.asset_id | Source VM UUID (src_uuid) | SrcUUID | principal.asset.product_object_id | |
| URL | target.asset.asset_id | Destination VM UUID (dst_uuid) | DstUUID | target.asset.product_object_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | http_headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| URL | about.labels.key/value additional.fields.key/value.string_value | UUID for rule (rule_uuid) | PanOSRuleUUID | security_result.rule_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| URL | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| URL | principal.asset.software.version | Source Device OS Version (src_osversion) | PanSrcDeviceOSv | principal.platform_version | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Hostname (src_host) | PanSrcHostname | principal.hostname | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| URL | target.asset.platform_software.platform target.labels.key/value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| URL | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| URL | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| URL | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Res Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | PanReasonFilteringAction | security_result.summary | |
| Data | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Data | target.file.full_path target.url | URL/Filename (misc) | Miscellaneous | target.file.names target.url | |
| Data | about.labels.key/value additional.fields.key/value.string_value | Category (category) | cs2 | URLCategory | security_result.category_details |
| Data | about.file.sha1/md5/sha256 | filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | |
| Data | about.file.mime_type | filetype (filetype) | target.file.mime_type | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | xff (xff) | principal.ip | ||
| Data | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Data | about.url | file_url (file_url) | target.url | ||
| Data | principal.asset.asset_id | Source VM UUID (src_uuid) | SrcUUID | principal.asset.product_object_id | |
| Data | target.asset.asset_id | Destination VM UUID (dst_uuid) | DstUUID | target.asset.product_object_id | |
| Data | about.labels.key/value additional.fields.key/value.string_value | http_headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| Data | about.labels.key/value additional.fields.key/value.string_value | UUID for rule (rule_uuid) | PanOSRuleUUID | security_result.rule_id | |
| Data | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | network.application_protocol_version | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | principal.asset.category | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | principal.asset.hardware.model | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | principal.asset.hardware.manufacturer | ||
| Data | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | principal.platform | ||
| Data | principal.asset.software.version | Source Device OS Version (src_osversion) | principal.platform_version | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Hostname (src_host) | principal.hostname | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | target.asset.category | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | target.asset.hardware.model | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | target.asset.hardware.manufacturer | ||
| Data | target.asset.platform_software.platform target.labels.key/value | Destination Device OS Family (dst_osfamily) | target.platform | ||
| Data | target.asset.software.version | Destination Device OS Version (dst_osversion) | target.platform_version | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | intermediary.resource.product_object_id | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | target.resource.attribute.labels | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | target.resource.name | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | principal.asset.asset_id | ||
| Data | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Res Timestamp (high_res_timestamp) | additional.fields.key/value.string_value | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | security_result.summary | ||
| GlobalProtect | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | PanOSVirtualSystem | intermediary.asset.attribute.labels | |
| GlobalProtect | principal.user.email_address principal.user.userid principal.administrative_domain | Source User (srcuser) | PanOSSourceUserName | target.user.email_address target.user.userid | |
| GlobalProtect | principal.asset.platform_software.platform(enum) | Client OS (client_os) | PanOSEndpointOSType | principal.platform | |
| GlobalProtect | principal.asset.platform_software.platform_version | Client OS Version (client_os_ver) | PanOSEndpointOSVersion | principal.platform_version | |
| GlobalProtect | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| GlobalProtect | about.labels.key/value additional.fields.key/value.string_value | Gateway Name (gateway) | PanOSAttemptedGateways | target.resource.name | |
| GlobalProtect | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | intermediary.asset.attribute.labels | ||
| GlobalProtect | target.hostname | Device Name (device_name) | intermediary.hostname | ||
| GlobalProtect | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| CORRELATION | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | VirtualSystem | intermediary.asset.attribute.labels | |
| CORRELATION | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | vSrcName | intermediary.asset.attribute.labels | |
| CORRELATION | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | VirtualSystemID | intermediary.resource.product_object_id | |
| GTP | additional.fields.key/value.string_value | Virtual System (vsys) | intermediary.asset.attribute.labels | ||
| GTP | target.ip | Remote User IP (remote_user_ip) | principal.ip | ||
| GTP | additional.fields.key/value.string_value | Remote User ID (remote_user_id) | principal.user.userid | ||
| GTP | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | additional.fields.key/value.string_value |
Palo Alto Networks Firewall Strata Logging Service
Ringkasan
Strata Logging Service dari Palo Alto Networks® menyediakan penyimpanan dan penggabungan log terpusat berbasis cloud untuk firewall lokal, virtual (cloud pribadi dan cloud publik), untuk Prisma Access, dan untuk layanan yang disediakan cloud seperti Cortex XDR.Strata Logging Service aman, tangguh, dan toleran terhadap kesalahan, serta memastikan data logging Anda selalu terbaru dan tersedia saat Anda membutuhkannya. Layanan ini menyediakan infrastruktur logging yang skalabel sehingga Anda tidak perlu merencanakan dan men-deploy Pengumpul Log untuk memenuhi kebutuhan retensi log Anda. Jika Anda sudah memiliki Pengumpul Log on-premise, Strata Logging Service baru dapat melengkapi penyiapan yang ada. Anda dapat meningkatkan infrastruktur pengumpulan log yang ada dengan Strata Logging Service berbasis cloud untuk memperluas kapasitas operasional seiring pertumbuhan bisnis Anda, atau untuk memenuhi kebutuhan kapasitas lokasi baru.Dengan layanan ini, Palo Alto Networks menangani pemeliharaan dan pemantauan infrastruktur logging yang berkelanjutan sehingga Anda dapat berfokus pada bisnis Anda.
Verifikasi format log dan versi PAN-OS yang didukung oleh parser Strata Logging Service. Tabel berikut mencantumkan format log dan versi PAN-OS yang sesuai yang didukung oleh parser Strata Logging Service:
Format log Versi PAN-OS JSON 12.1 Verifikasi jenis log firewall Palo Alto Networks yang didukung oleh parser Google SecOps. Parser Google SecOps mendukung jenis log firewall Palo Alto Networks berikut:
- Traffic
- Ancaman
- Pemeriksaan terowongan
- Sistem
- Pencocokan HIP
- IP-Tag
- User-ID
- Dekripsi
- Autentikasi
- Pemfilteran URL
- GlobalProtect
Deployment Layanan Logging Strata
- Pastikan produk firewall Palo Alto Networks di-deploy dan dikonfigurasi dengan benar. Untuk petunjuk penyiapan mendetail, lihat Dokumentasi PAN-OS, lalu ikuti dokumen deployment ini sebelum mengirim log ke layanan logging strata Prasyarat Deployment Strata Logging Service
Mulai Mengirim Log ke Strata Logging Service:
Untuk Mulai Mengirim Log ke Strata Logging Service, ikuti langkah-langkah berikut:
- Menginstal versi PAN-OS® yang didukung
- Aktifkan Strata Logging Service- Mengaktifkan Strata Logging Service mencakup penyediaan sertifikat yang diperlukan firewall untuk terhubung secara aman ke Strata Logging Service.
- Mengaktifkan firewall ke Strata Logging Service dengan atau tanpa Panorama
Untuk mengetahui langkah-langkah aktivasi yang mendetail, lihat Dokumentasi.
Meneruskan Log dari Strata Logging Service
Untuk memenuhi kebutuhan penyimpanan, pelaporan, dan pemantauan jangka panjang, atau kebutuhan hukum dan kepatuhan, Anda dapat mengonfigurasi Strata Logging Service untuk meneruskan log ke server HTTPS atau ke SIEM berikut:
- Exabeam
- Google Chronicle
- Microsoft Sentinel
- Splunk HTTP Event Collector (HEC)
Gunakan metode penerusan HTTPS untuk meneruskan log menggunakan Strata Logging Service. Untuk informasi mendetail, baca Dokumentasi ini.
Format log yang didukung
Parser firewall Palo Alto Networks Strata Logging Service mendukung log dalam format JSON.
Contoh log yang didukung
JSON
{"source": "Palo Alto Networks FLS LF", "host": "dummy-loghost", "time": "1730265996460", "event": {"TimeReceived": "2024-10-30T05:25:50.000000Z", "DeviceSN": "no-serial", "LogType": "TRAFFIC", "Subtype": "end", "ConfigVersion": "10.2", "TimeGenerated": "2024-10-30T05:25:40.000000Z", "SourceAddress": "198.51.100.6", "DestinationAddress": "198.51.100.6", "NATSource": "", "NATDestination": "", "Rule": "egress-dns-ping-traceroute", "SourceUser": null, "DestinationUser": null, "Application": "dns-base", "VirtualLocation": "vsys1", "FromZone": "VA8280-RN", "ToZone": "inter-fw", "InboundInterface": "tunnel.101", "OutboundInterface": "tunnel.4005", "LogSetting": "Cortex Data Lake", "SessionID": 754194, "RepeatCount": 1, "SourcePort": 53578, "DestinationPort": 53, "NATSourcePort": 0, "NATDestinationPort": 0, "Protocol": "udp", "Action": "allow", "Bytes": 214, "BytesSent": 72, "BytesReceived": 142, "PacketsTotal": 2, "SessionStartTime": "2024-10-30T05:25:10.000000Z", "SessionDuration": 0, "URLCategory": "any", "SequenceNo": 7382192512716388639, "SourceLocation": "198.51.100.6-198.51.255.255", "DestinationLocation": "198.51.100.6-198.51.255.255", "PacketsSent": 1, "PacketsReceived": 1, "SessionEndReason": "aged-out", "DGHierarchyLevel1": 65537, "DGHierarchyLevel2": 65538, "DGHierarchyLevel3": 65541, "DGHierarchyLevel4": 0, "VirtualSystemName": "", "DeviceName": "VA8280-RN", "ActionSource": "from-policy", "SourceUUID": null, "DestinationUUID": null, "IMSI": 0, "IMEI": null, "ParentSessionID": 0, "ParentStarttime": "1970-01-01T00:00:00.000000Z", "Tunnel": "N/A", "EndpointAssociationID": 72057594037927936, "ChunksTotal": 0, "ChunksSent": 0, "ChunksReceived": 0, "RuleUUID": "95cfc3cc-cb00-4758-af1d-de9ab5f07f97", "HTTP2Connection": 0, "LinkChangeCount": 0, "SDWANPolicyName": null, "LinkSwitches": null, "SDWANCluster": null, "SDWANDeviceType": null, "SDWANClusterType": null, "SDWANSite": null, "DynamicUserGroupName": null, "X-Forwarded-ForIP": null, "SourceDeviceCategory": null, "SourceDeviceProfile": null, "SourceDeviceModel": null, "SourceDeviceVendor": null, "SourceDeviceOSFamily": null, "SourceDeviceOSVersion": null, "SourceDeviceHost": null, "SourceDeviceMac": null, "DestinationDeviceCategory": null, "DestinationDeviceProfile": null, "DestinationDeviceModel": null, "DestinationDeviceVendor": null, "DestinationDeviceOSFamily": null, "DestinationDeviceOSVersion": null, "DestinationDeviceHost": null, "DestinationDeviceMac": null, "ContainerID": null, "ContainerNameSpace": null, "ContainerName": null, "SourceEDL": null, "DestinationEDL": null, "GPHostID": null, "EndpointSerialNumber": null, "SourceDynamicAddressGroup": null, "DestinationDynamicAddressGroup": null, "HASessionOwner": null, "TimeGeneratedHighResolution": "2024-10-30T05:25:41.009000Z", "NSSAINetworkSliceType": null, "NSSAINetworkSliceDifferentiator": null}}"
Referensi pemetaan kolom: Kolom log ke kolom UDM
Bagian ini menjelaskan cara parser memetakan kolom log firewall Palo Alto Networks Strata Logging Service ke kolom peristiwa Google UDM untuk setiap jenis log.
Lihat bagian berikut untuk referensi pemetaan setiap jenis log:
- Sistem
- Ancaman
- Traffic
- ID Pengguna
- Pencocokan HIP
- Tag IP
- Dekripsi
- Tunnel
- Authentication
- URL
- GlobalProtect
- SCTP
- Audit
Sistem
Tabel berikut mencantumkan kolom log jenis log Sistem dan kolom UDM yang sesuai.
| Log field | UDM mapping |
|---|---|
| AgentContentVersion | additional.fields.key/value.string_value |
| AgentDataCollectionStatus | target.resource.attribute.labels |
| AgentID | target.resource.attribute.labels |
| AgentIsolationStatus | target.resource.attribute.labels |
| AgentStatus | target.resource.attribute.labels |
| AgentVersion | target.asset.software.version |
| ConfigVersion | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DeviceGroup | target.group.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EndpointCPUArchitecture | target.asset.hardware.cpu_platform |
| EndpointDeviceDomain | target.asset.administrative_domain |
| EndpointDeviceName | target.asset.hostname |
| EndpointIPaddress | target.asset.ip |
| VDIEndpoint | target.asset.attribute.labels |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointOSVersion | target.platform_version |
| AgentTimeZoneOffset | additional.fields.key/value.string_value |
| EndpointUserDomain | additional.fields.key/value.string_value |
| EndpointUserName | target.user.user_display_name |
| EndpointUserUUID | target.user.userid |
| EventComponent | additional.fields.key/value.string_value |
| EventDescription | metadata.description |
| EventName | additional.fields.key/value.string_value |
| EventTime | metadata.event_timestamp |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogCategory | security_result.category_details |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| LogSourceID | target.resource.attribute.labels |
| LogSourceName | observer.asset.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| LogTime | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Severity | security_result.severity |
| Subtype | metadata.product_event_type |
| Template | target.resource.attribute.labels |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
Ancaman
Tabel berikut mencantumkan kolom log jenis log Ancaman dan kolom UDM yang sesuai.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| ApplianceOrCloud | additional.fields.key/value.string_value |
| CloudHostname | additional.fields.key/value.string_value |
| CloudReportID | security_result.detection_fields.key/value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DirectionOfAttack | security_result.detection_fields.key/value |
| DomainEDL | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| FileName | target.file.names |
| FileHash | target.file.sha1 |
| FileType | additional.fields.key/value.string_value |
| FileURL | target.url |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HostID | principal.asset.asset_id |
| HTTP2Connection | network.application_protocol_version |
| HTTPMethod | network.http.method |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| LocalDeepLearningAnalyzed | additional.fields.key/value.string_value |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| PartialHash | additional.fields.key/value.string_value |
| PayloadProtocolID | additional.fields.key/value.string_value |
| Packet | additional.fields.key/value.string_value |
| PacketID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| RecipientEmail | target.user.email_addresses |
| ReportID | security_result.detection_fields.key/value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SenderEmail | principal.user.email_addresses |
| SequenceNo | metadata.product_log_id |
| SessionID | network.session_id |
| Severity | security_result.severity |
| SigFlags | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| EmailSubject | network.email.subject |
| ApplicationTechnology | additional.fields.key/value.string_value |
| ThreatCategory | security_result.detection_fields.key/value.key/value |
| ThreatID | security_result.threat_id |
| ThreatName | security_result.threat_name |
| ThreatNameFirewall | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLDomain | target.domain.name |
| URLCounter | additional.fields.key/value.string_value |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| Verdict | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-ForIP | principal.ip |
Traffic
Tabel berikut mencantumkan kolom log jenis Log traffic dan kolom UDM yang sesuai.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| ActionSource | additional.fields.key/value.string_value |
| AIFwdError | additional.fields.key/value.string_value |
| AITraffic | additional.fields.key/value.string_value |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| BytesReceived | network.received_bytes |
| BytesSent | network.sent_bytes |
| Bytes | additional.fields.key/value.string_value |
| ChunksReceived | additional.fields.key/value.string_value |
| ChunksSent | additional.fields.key/value.string_value |
| ChunksTotal | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| EndpointAssociationID | additional.fields.key/value.string_value |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HASessionOwner | additional.fields.key/value.string_value |
| GPHostID | additional.fields.key/value.string_value |
| HTTP2Connection | network.application_protocol_version |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsOffloaded | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| LinkChangeCount | additional.fields.key/value.string_value |
| LinkSwitches | additional.fields.key/value.string_value |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| SDWANPolicyName | additional.fields.key/value.string_value |
| Protocol | network.ip_protocol |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SDWANFECRatio | additional.fields.key/value.string_value |
| SDWANCluster | additional.fields.key/value.string_value |
| SDWANClusterType | additional.fields.key/value.string_value |
| SDWANDeviceType | additional.fields.key/value.string_value |
| SDWANSite | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionStartTime | additional.fields.key/value.string_value |
| SessionTracker | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| SessionDuration | network.session_duration |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLCategory | target.url_metadata.categories |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-ForIP | principal.ip |
User-ID
Tabel berikut mencantumkan kolom log jenis log User-ID dan kolom UDM yang sesuai.
| Log field | UDM mapping |
|---|---|
| AuthFactorNo | security_result.detection_fields.key/value |
| AuthenticatedUserDomain | target.user.administrative_domain |
| AuthenticatedUserName | target.user.userid |
| AuthenticatedUserUUID | target.user.product_object_id |
| ConfigVersion | additional.fields.key/value.string_value |
| CountofRepeats | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationPort | target.port |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EventID | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsDuplicateUser | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MappingDataSource | additional.fields.key/value.string_value |
| MappingDataSourceName | additional.fields.key/value.string_value |
| MappingDataSourceType | additional.fields.key/value.string_value |
| MappingTimeout | additional.fields.key/value.string_value |
| MFAFactorType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SourceIP | principal.ip |
| SourcePort | principal.port |
| Subtype | metadata.product_event_type |
| Tag | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| UGFlags | additional.fields.key/value.string_value |
| User | target.user.userid |
| UserGroupFound | additional.fields.key/value.string_value |
| UserIdentifiedBySource | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Pencocokan HIP
Tabel berikut mencantumkan kolom log jenis log kecocokan HIP dan kolom UDM yang sesuai.
| Log field | UDM mapping |
|---|---|
| ConfigVersion | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EndpointDeviceName | principal.asset.hostname |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| HipMatchName | target.resource.attribute.labels |
| HipMatchType | target.resource.attribute.labels |
| HostID | principal.asset.asset_id |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | metadata.product_event_type |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Source | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceIP | principal.ip |
| SourceIPv6 | principal.ip |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| TimestampDeviceIdentification | principal.asset.first_seen_time |
| UUID | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
Tag IP
Tabel berikut mencantumkan kolom log jenis log tag IP dan kolom UDM yang sesuai.
| Log field | UDM mapping |
|---|---|
| ConfigVersion | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EventID | additional.fields.key/value.string_value |
| IPSubnetRange | network.ip_subnet_range |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSetting | target.resource.attribute.labels |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MappingDataSource | additional.fields.key/value.string_value |
| MappingDataSourceSubType | additional.fields.key/value.string_value |
| MappingDataSourceType | additional.fields.key/value.string_value |
| MappingTimeout | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| RuleMatched | security_result.rule_name |
| RuleMatchedUUID | security_result.rule_id |
| SequenceNo | metadata.product_log_id |
| SourceIP | principal.ip |
| Subtype | metadata.product_event_type |
| TagName | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
Dekripsi
Tabel berikut mencantumkan kolom log jenis log Dekripsi dan kolom UDM yang sesuai.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| CertificateFlags | additional.fields.key/value.string_value |
| CertificateSerial | network.tls.server.certificate.serial |
| CertificateSize | additional.fields.key/value.string_value |
| CertificateVersion | network.tls.server.certificate.version |
| ChainStatus | additional.fields.key/value.string_value |
| ApplicationCharacteristics | additional.fields.key/value.string_value |
| ClientToFirewall | additional.fields.key/value.string_value |
| CommonName | additional.fields.key/value.string_value |
| CommonNameLength | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| Cpadding | additional.fields.key/value.string_value |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| Domain | target.hostname |
| EllipticCurve | network.tls.curve |
| ErrorIndex | additional.fields.key/value.string_value |
| ErrorMessage | additional.fields.key/value.string_value |
| Fingerprint | network.tls.server.certificate.md5/sha1/sha256 |
| FirewallToClient | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsCertECDSA | additional.fields.key/value.string_value |
| IsCertRSA | additional.fields.key/value.string_value |
| IsCertCNTruncated | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| IsForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsIssuerCNTruncated | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| IsNAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| PacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsResumeSession | additional.fields.key/value.string_value |
| IsRootCNTruncated | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSNITruncated | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| IssuerCommonName | network.tls.server.certificate.issuer |
| IssuerNameLength | additional.fields.key/value.string_value |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| TimeNotAfter | additional.fields.key/value.string_value |
| TimeNotBefore | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| Padding | additional.fields.key/value.string_value |
| Padding3 | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| PolicyName | additional.fields.key/value.string_value |
| Protocol | network.ip_protocol |
| ProxyType | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| RootCommonName | additional.fields.key/value.string_value |
| RootCNLength | additional.fields.key/value.string_value |
| RootStatus | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SessionID | network.session_id |
| ServerNameIndication | network.tls.client.server_name |
| SNILength | additional.fields.key/value.string_value |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeReceivedManagementPlane | additional.fields.key/value.string_value |
| TLSAuth | additional.fields.key/value.string_value |
| TLSEncryptionAlgorithm | additional.fields.key/value.string_value |
| TLSKeyExchange | additional.fields.key/value.string_value |
| TLSVersion | network.tls.version |
| ToZone | additional.fields.key/value.string_value |
| Tpadding | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| Vpadding | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Terowongan
Tabel berikut mencantumkan kolom log jenis log Tunnel dan kolom UDM yang sesuai.
| Log field | UDM mapping |
|---|---|
| AccessPointName | additional.fields.key/value.string_value |
| Action | security_result.action |
| ActionSource | additional.fields.key/value.string_value |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| BytesReceived | network.received_bytes |
| BytesSent | network.sent_bytes |
| Bytes | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| LoggingServiceID | additional.fields.key/value.string_value |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MobileAreaCode | additional.fields.key/value.string_value |
| MobileBaseStationCode | additional.fields.key/value.string_value |
| MobileCountryCode | additional.fields.key/value.string_value |
| MobileIP | additional.fields.key/value.string_value |
| MobileNetworkCode | additional.fields.key/value.string_value |
| MobileSubscriberISDN | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceDifferentiator | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsDroppedMax | additional.fields.key/value.string_value |
| PacketsDroppedStrict | additional.fields.key/value.string_value |
| PacketsDroppedTunnel | additional.fields.key/value.string_value |
| PacketsDroppedProtocol | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| ProtocolDataUnitsessionID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| RadioAccessTechnology | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionStartTime | additional.fields.key/value.string_value |
| SessionTracker | additional.fields.key/value.string_value |
| Severity | security_result.severity |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| StandardPortsOfApp | additional.fields.key/value.string_value |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| SessionDuration | network.session_duration |
| Tunnel | additional.fields.key/value.string_value |
| TunnelCauseCode | additional.fields.key/value.string_value |
| TunnelEndpointID1 | additional.fields.key/value.string_value |
| TunnelEndpointID2 | additional.fields.key/value.string_value |
| TunnelEventCode | additional.fields.key/value.string_value |
| TunnelEventType | additional.fields.key/value.string_value |
| TunnelInspectionRule | additional.fields.key/value.string_value |
| TunnelInterface | additional.fields.key/value.string_value |
| TunnelMessageType | additional.fields.key/value.string_value |
| TunnelRemoteIMSIID | additional.fields.key/value.string_value |
| TunnelRemoteUserIP | principal.ip |
| TunnelSessionsClosed | additional.fields.key/value.string_value |
| TunnelSessionsCreated | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLCategory | target.url_metadata.categories |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Autentikasi
Tabel berikut mencantumkan kolom log jenis log Autentikasi dan kolom UDM yang sesuai.
| Log field | UDM mapping |
|---|---|
| AuthenticationDescription | security_result.description |
| AuthEvent | metadata.description |
| AuthFactorNo | security_result.detection_fields.key/value |
| AuthenticationPolicy | security_result.detection_fields.key/value |
| AuthenticationProtocol | additional.fields.key/value.string_value |
| AuthServerProfile | additional.fields.key/value.string_value |
| AuthenticatedUserDomain | target.administrative_domain |
| AuthenticatedUserName | target.user.userid |
| AuthenticatedUserUUID | target.user.product_object_id |
| ClientType | additional.fields.key/value.string_value |
| ClientTypeName | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| Location | target.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogType | additional.fields.key/value.string_value |
| MFAAuthenticationID | additional.fields.key/value.string_value |
| MFAVendor | additional.fields.key/value.string_value |
| NormalizeUser | target.user.user_display_name |
| Object | target.resource.name |
| RuleMatched | security_result.rule_name |
| RuleMatchedUUID | security_result.rule_id |
| AuthCacheServiceRegion | additional.fields.key/value.string_value |
| SessionID | network.session_id |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceIP | principal.ip |
| TimeGenerated | metadata.event_timestamp |
| User | target.user.userid |
| UserAgentString | network.http.user_agent |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Subtype | metadata.product_event_type |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
URL
Tabel berikut mencantumkan kolom log jenis log URL dan kolom UDM yang sesuai.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| CloudHostname | additional.fields.key/value.string_value |
| CloudReportID | security_result.detection_fields.key/value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentType | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DirectionOfAttack | security_result.detection_fields.key/value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| FileURL | target.url |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HostID | principal.asset.asset_id |
| HTTP2Connection | network.application_protocol_version |
| HTTPHeaders | additional.fields.key/value.string_value |
| HTTPMethod | network.http.method |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| InlineMLVerdict | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| Packet | additional.fields.key/value.string_value |
| PacketID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| Referer | network.http.referral_url |
| HTTPRefererFQDN | additional.fields.key/value.string_value |
| HTTPRefererPort | additional.fields.key/value.string_value |
| HTTPRefererProtocol | additional.fields.key/value.string_value |
| HTTPRefererURLPath | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionID | network.session_id |
| Severity | security_result.severity |
| SigFlags | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URL | target.url_metadata.URL |
| URLCategory | target.url_metadata.categories |
| URLCategoryList | additional.fields.key/value.string_value |
| URLDomain | target.domain.name |
| URLCounter | additional.fields.key/value.string_value |
| UserAgent | network.http.user_agent |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-For | additional.fields.key/value.string_value |
| X-Forwarded-ForIP | principal.ip |
GlobalProtect
Tabel berikut mencantumkan kolom log jenis log GlobalProtect dan kolom UDM yang sesuai.
| Log field | UDM mapping |
|---|---|
| AttemptedGateways | additional.fields.key/value.string_value |
| AuthMethod | extensions.auth.auth_details |
| ConnectionMethod | additional.fields.key/value.string_value |
| ConnectionErrorID | additional.fields.key/value.string_value |
| ConnectionError | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| EndpointDeviceName | principal.asset.hostname |
| GlobalProtectClientVersion | additional.fields.key/value.string_value |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointSN | principal.asset.hardware.serial_number |
| EventIDValue | additional.fields.key/value.string_value |
| Gateway | target.resource.name |
| GatewayPriority | additional.fields.key/value.string_value |
| GatewaySelectionType | additional.fields.key/value.string_value |
| GlobalProtectGatewayLocation | target.location.country_or_region |
| HostID | principal.asset.asset_id |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LoginDuration | network.session_duration |
| Description | security_result.description |
| Portal | target.hostname |
| PrivateIPv4 | principal.ip |
| PrivateIPv6 | principal.ip |
| ProjectName | additional.fields.key/value.string_value |
| PublicIPv4 | principal.nat_ip |
| PublicIPv6 | principal.nat_ip |
| QuarantineReason | security_result.summary |
| SequenceNo | metadata.product_log_id |
| SourceRegion | principal.location.country_or_region |
| SourceUserName | principal.user.user_display_name |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SSLResponseTime | additional.fields.key/value.string_value |
| Stage | additional.fields.key/value.string_value |
| EventStatus | additional.fields.key/value.string_value |
| LogSubtype | metadata.product_event_type |
| TunnelType | additional.fields.key/value.string_value |
| VirtualSystem | intermediary.asset.attribute.labels |
| VirtualSystemName | intermediary.asset.attribute.labels |
| EndpointOSVersion | principal.platform_version |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | metadata.product_event_type |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualSystemID | intermediary.resource.product_object_id |
SCTP
Tabel berikut mencantumkan kolom log jenis log SCTP dan kolom UDM yang sesuai.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| AssocationEndReason | additional.fields.key/value.string_value |
| ChunksReceived | additional.fields.key/value.string_value |
| ChunksSent | additional.fields.key/value.string_value |
| ChunksTotal | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceClass | target.asset.category |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationIP | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DiamAppID | additional.fields.key/value.string_value |
| DiamAvpCode | additional.fields.key/value.string_value |
| DiameterCommandCode | additional.fields.key/value.string_value |
| DiameterRequestFlag | additional.fields.key/value.string_value |
| DeviceName | principal.asset.hostname |
| SCTPEventType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLFiltering | additional.fields.key/value.string_value |
| IsWildfire | additional.fields.key/value.string_value |
| LogAction | additional.fields.key/value.string_value |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MapAppCode | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PayloadProtocolID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SccpCallingGt | additional.fields.key/value.string_value |
| SccpCallingSSN | additional.fields.key/value.string_value |
| SctpCauseCode | additional.fields.key/value.string_value |
| SctpChunkType | additional.fields.key/value.string_value |
| SctpFilter | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionTracker | additional.fields.key/value.string_value |
| Severity | security_result.severity |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceIP | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VerificationTag1 | additional.fields.key/value.string_value |
| VerificationTag2 | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Audit
Tabel berikut mencantumkan kolom log jenis Log audit dan kolom UDM yang sesuai.
| Log field | UDM mapping |
|---|---|
| EventCategory | network.http.method |
| EventDescription | metadata.description |
| EventDestinationURL | target.url |
| EventDestinationUserUserID | target.user.userid |
| DestinationVendor | additional.fields.key/value.string_value |
| EventDetails | additional.fields.key/value.string_value |
| EventID | metadata.product_log_id |
| EventName | additional.fields.key/value.string_value |
| EventResult | security_result.summary |
| EventSourceUserUserID | principal.user.userid |
| EventTime | metadata.event_timestamp |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| Subtype | metadata.product_event_type |
| TSGID | additional.fields.key/value.string_value |
| Vendor | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
Referensi pemetaan kolom: Jenis log ke jenis peristiwa UDM
Tabel berikut mencantumkan jenis log firewall Palo Alto Networks Strata Logging Service dan jenis peristiwa UDM yang sesuai.
| Jenis log | Jenis peristiwa UDM |
| Traffic | NETWORK_CONNECTION |
| Ancaman | NETWORK_CONNECTION |
| Pemfilteran URL | NETWORK_CONNECTION |
| Terowongan | NETWORK_CONNECTION |
| Sistem |
Jika nilai subjenis adalah "dhcp", maka NETWORK_DHCP akan disetel. Jika nilai subjenis adalah "auth", USER_LOGIN akan disetel. Jika nilai deskripsi adalah "logged in", maka USER_LOGIN akan ditetapkan. Jika nilai deskripsi adalah "logged out", maka USER_LOGOUT akan disetel. Untuk nilai subtype lainnya, GENERIC_EVENT ditetapkan. |
| Pencocokan HIP | NETWORK_CONNECTION |
| Tag IP | GENERIC_EVENT |
| User-ID | USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED
Jika nilai subjenis adalah "login", USER_LOGIN akan disetel. Jika nilai subjenis adalah "logout", USER_LOGOUT akan disetel. Jika subtipe tidak berisi nilai apa pun, USER_UNCATEGORIZED akan ditetapkan. |
| Dekripsi | NETWORK_CONNECTION |
| Authentication | STATUS_UNCATEGORIZED |
| Globalprotect | USER_LOGIN/USER_LOGOUT/USER_RESOURCE_ACCESS
Jika nilai subjenis adalah "auth", maka USER_LOGIN akan disetel. Jika nilai subjenis adalah "logout", USER_LOGOUT akan disetel. Jika subtype tidak berisi nilai apa pun, USER_RESOURCE_ACCESS akan ditetapkan. |
| SCTP | NETWORK_CONNECTION |
| Audit | NETWORK_CONNECTION |
Langkah berikutnya
Perlu bantuan lain? Dapatkan jawaban dari anggota Komunitas dan profesional Google SecOps.