Raccogliere i log del firewall Palo Alto Networks
Firewall Palo Alto Networks
Panoramica
Questo documento descrive come configurare syslog e un forwarder Google SecOps per raccogliere i log del firewall Palo Alto Networks. Questo documento spiega anche come i campi dei log del firewall Palo Alto Networks vengono mappati ai campi Unified Data Model (UDM) di Google SecOps. Per una panoramica sull'importazione dati in Google SecOps, consulta Importazione dei dati in Google SecOps. Un'etichetta di importazione identifica il parser che normalizza i dati dei log non elaborati in formato UDM strutturato. Le informazioni contenute in questo documento si applicano al parser con l'etichetta di importazione PAN_FIREWALL.
Prima di iniziare
- Assicurati che il prodotto firewall Palo Alto Networks sia implementato e configurato correttamente. Per istruzioni di configurazione dettagliate, consulta la documentazione di PAN-OS.
Per comprendere i componenti di cui è stato eseguito il deployment per raccogliere i log del firewall Palo Alto Networks, esamina l'architettura di deployment. Ogni implementazione del cliente potrebbe differire da questa rappresentazione e potrebbe essere più complessa. Il seguente diagramma mostra come configurare syslog su un firewall Palo Alto Networks e installare un forwarder Google SecOps su un server Linux per inoltrare i dati di log a Google SecOps. Il parser supporta i log scritti nei seguenti formati di dati: valori separati da virgole (CSV), Common Event Format (CEF) e Log Event Extended Format (LEEF).
Verifica i formati dei log e le versioni di PAN-OS supportati dal parser Google SecOps. La tabella seguente elenca i formati dei log e le versioni di PAN-OS corrispondenti supportate dal parser Google SecOps:
Formato log Versione PAN-OS CSV 10.1.3 CEF 10.0.0 LEEF 9.1.0 Verifica i tipi di log del firewall Palo Alto Networks supportati dal parser Google SecOps. Il parser di Google SecOps supporta i seguenti tipi di log del firewall Palo Alto Networks:
- Traffico
- Minaccia
- Invii di WildFire
- Ispezione tunnel
- Configurazione
- Sistema
- Corrispondenza HIP
- IP-Tag
- User-ID
- Decriptazione
- Autenticazione
- Filtro degli URL
- Filtro dei dati
- GlobalProtect
- Correlazione
- GTP
- SCTP
- Controlla
Per ulteriori informazioni sui tipi di log del firewall Palo Alto Networks, consulta Tipi di log PAN-OS.
Assicurati che tutti i sistemi nell'architettura di deployment siano configurati nel fuso orario UTC.
Prima di utilizzare il parser del firewall Palo Alto Networks, esamina le modifiche apportate ai mapping dei campi tra il parser precedente e quello attuale del firewall Palo Alto Networks. Nell'ambito della migrazione, assicurati che le regole, le ricerche, i dashboard o altri processi che dipendono dai campi originali utilizzino i campi aggiornati.
Ad esempio, nella versione precedente del parser, il campo log
categoryè mappato al campo UDMsecurity_result.description. Nell'attuale parser del firewall Palo Alto Networks, il campo logcategoryè mappato al campo UDMsecurity_result.category_details. Se esegui la migrazione all'attuale parser firewall Palo Alto Networks e utilizzi il campocategorynelle regole, devi modificare le regole in modo che utilizzino il camposecurity_result.category_detailsUDM del parser attuale.
Configura syslog e il forwarder Google Security Operations
Per configurare syslog e il forwarder Google SecOps, completa i seguenti passaggi:
- Per monitorare i log CSV, configura il profilo del server syslog. Per saperne di più, consulta Configurare il profilo del server syslog. Quando configuri il profilo del server syslog, specifica "Predefinito" come formato log personalizzato.
- Per monitorare i log CEF, configura il firewall Palo Alto Networks per inoltrarli. Per ulteriori informazioni, scarica la guida all'integrazione CEF di PAN-OS in formato PDF e consulta la sezione "Configurazione di Palo Alto Networks NGFW per l'output di eventi CEF".
- Per monitorare i log LEEF, configura il profilo del server syslog. Per saperne di più, consulta Invio personalizzato dei log in formato LEEF.
Configura il forwarder Google SecOps per inviare i log a Google Security Operations. Per ulteriori informazioni, vedi Installazione e configurazione del forwarder su Linux. Di seguito è riportato un esempio di configurazione dell'agente di inoltro Google SecOps:
- syslog: common: enabled: true data_type: PAN_FIREWALL batch_n_seconds: 10 batch_n_bytes: 1048576 tcp_address: 0.0.0.0:10518 connection_timeout_sec: 60
Configura l'inoltro di syslog sul firewall PAN
Crea un profilo server syslog
- Accedi alla console di gestione del firewall Palo Alto Networks.
- Vai a Dispositivo > Profili server > Syslog.
- Fai clic su Aggiungi per creare un nuovo profilo server.
- Fornisci i seguenti dettagli di configurazione:
- Nome: inserisci un nome descrittivo (ad esempio,
Google SecOps BindPlane). - Posizione: seleziona il sistema virtuale (vsys) o Condiviso in cui sarà disponibile questo profilo.
- Nome: inserisci un nome descrittivo (ad esempio,
- Fai clic su Server > Aggiungi per configurare il server syslog.
- Fornisci i seguenti dettagli di configurazione del server:
- Nome: inserisci un nome descrittivo per il server (ad esempio,
BindPlane Agent). - Server Syslog: inserisci l'indirizzo IP dell'agente BindPlane.
- Trasporto: seleziona UDP o TCP, a seconda della configurazione di BindPlane Agent (UDP è l'impostazione predefinita).
- Porta: inserisci il numero di porta dell'agente BindPlane (ad esempio,
514). - Formato: seleziona BSD (impostazione predefinita) o IETF, a seconda dei tuoi requisiti.
- Struttura: seleziona LOG_USER (impostazione predefinita) o un'altra struttura, se necessario.
- Nome: inserisci un nome descrittivo per il server (ad esempio,
- Fai clic su OK per salvare il profilo del server syslog.
(Facoltativo) Configura il formato log personalizzato per CEF o LEEF
Se hai bisogno di log CEF (Common Event Format) o LEEF (Log Event Extended Format) anziché CSV:
- Nel profilo del server Syslog, seleziona la scheda Formato log personalizzato.
- Configura il formato log personalizzato per ogni tipo di log (Config, System, Threat, Traffic, URL, Data, WildFire, Tunnel, Authentication, User-ID, HIP Match).
- Per la configurazione del formato CEF, consulta la Guida alla configurazione CEF di Palo Alto Networks.
- Fai clic su Ok per salvare la configurazione.
Creare un profilo di inoltro dei log
- Vai a Oggetti > Inoltro log.
- Fai clic su Aggiungi per creare un nuovo profilo di inoltro dei log.
- Fornisci i seguenti dettagli di configurazione:
- Nome: inserisci un nome del profilo (ad esempio
Google SecOps Forwarding). Se vuoi che il firewall assegni automaticamente questo profilo a nuove regole e zone di sicurezza, chiamalodefault.
- Nome: inserisci un nome del profilo (ad esempio
- Per ogni tipo di log che vuoi inoltrare (traffico, minaccia, invio WildFire, filtro URL, filtro dati, tunnel, autenticazione), configura quanto segue:
- Fai clic su Aggiungi nella sezione del tipo di log corrispondente.
- Syslog: seleziona il profilo del server Syslog che hai creato (ad esempio,
Google SecOps BindPlane). - Gravità log: seleziona i livelli di gravità da inoltrare (ad esempio Tutti).
- Fai clic su Ok per salvare il profilo di inoltro dei log.
Applica il profilo di inoltro dei log ai criteri di sicurezza
- Vai a Norme > Sicurezza.
- Seleziona le regole di sicurezza per le quali vuoi attivare l'inoltro dei log.
- Fai clic sulla regola per modificarla.
- Vai alla scheda Azioni.
- Nel menu Log Forwarding, seleziona il profilo di inoltro dei log che hai creato (ad esempio,
Google SecOps Forwarding). - Fai clic su Ok per salvare la configurazione della norma di sicurezza.
Configura le impostazioni dei log per i log di sistema
- Vai a Dispositivo > Impostazioni log.
- Per ogni tipo di log (Sistema, Configurazione, User-ID, Corrispondenza HIP, Global Protect, IP-Tag, SCTP) e livello di gravità, seleziona il profilo del server syslog che hai creato.
- Fai clic su Ok per salvare le impostazioni dei log.
Esegui il commit delle modifiche
- Fai clic su Commit nella parte superiore dell'interfaccia web del firewall.
- Attendi il completamento del commit.
- Verifica che i log vengano inviati all'agente Bindplane controllando la console Google SecOps per i log del firewall Palo Alto Networks in entrata.
Inoltrare i log a Google SecOps utilizzando l'agente Bindplane
- Installa e configura una macchina virtuale Linux.
- Installa e configura l'agente Bindplane su Linux per inoltrare i log a Google SecOps. Per saperne di più su come installare e configurare l'agente Bindplane, consulta le istruzioni di installazione e configurazione dell'agente Bindplane.
Se riscontri problemi durante la creazione dei feed, contatta l'assistenza Google SecOps.
Formati di log supportati
Il parser firewall Palo Alto Networks supporta i log in formato LEEF,CEF e CSV.
Log di esempio supportati
LEEF
<14>Jan 22 02:20:19 device_host LEEF:1.0|Palo Alto Networks|PAN-OS Syslog Integration|10.2.12-h4|Microsoft MSOFFICE(52033)|ReceiveTime=2025/01/22 02:20:18|SerialNumber=01250100xxxx|cat=THREAT|Subtype=wildfire|devTime=Jan 22 2025 08:20:18 GMT|src=198.50.100.1|dst=198.50.100.2|srcPostNAT=198.50.100.3|dstPostNAT=198.50.100.4|RuleName=AZURE-US-NEW-CNF_Inbound_To_Azure-ALLOW|usrName=|SourceUser=|DestinationUser=|Application=smtp-base|VirtualSystem=vsys1|SourceZone=McD-Global-Zone|DestinationZone=Azure-Zone|IngressInterface=ae1.111|EgressInterface=ae2.409|LogForwardingProfile=Default-Traffic-Logging|SessionID=35331795|RepeatCount=1|srcPort=21578|dstPort=25|srcPostNATPort=0|dstPostNATPort=0|Flags=0x2000|proto=tcp|action=allow|Miscellaneous=\"......3...................xls\"|ThreatID=Microsoft MSOFFICE(52033)|URLCategory=malicious|sev=4|Severity=high|Direction=client-to-server|sequence=7462614601465681755|ActionFlags=0x8000000000000000|SourceLocation=198.50.100.1-198.50.100.255|DestinationLocation=United States|ContentType=|PCAP_ID=0|FileDigest=0ea04c99bf188c2e4207f60f92ca7c6f5088c7943ee63f45c50032bbd2bf7ea9|Cloud=demo.com|URLIndex=1|RequestMethod=|FileType=ms-office|Sender=sender@ab.myownpersonaldomain.com|Subject=\"............:.................................................................................-.........(Name)-2025-01-22...............:Y107202501220005, ............:........................, ...............:.........\"|Recipient=abc@demo.myownpersonaldomain.com|ReportID=117022282776|DeviceGroupHierarchyL1=143|DeviceGroupHierarchyL2=144|DeviceGroupHierarchyL3=39|DeviceGroupHierarchyL4=0|vSrcName=|DeviceName=device_host|SrcUUID=|DstUUID=|TunnelID=0|MonitorTag=|ParentSessionID=0|ParentStartTime=|TunnelType=N/A|ThreatCategory=N/A|ContentVer=WildFire-0CEF
14>1 2024-04-04T16:21:56+02:00 FW-PERIMETRAL-AVG-01 - - - - CEF:0|Palo Alto Networks|PAN-OS|10.1.10-h2|end|TRAFFIC|1|src=198.51.100.1 dst=198.51.100.2 srcTranslatedAddress=198.51.100.3 dstTranslatedAddress=198.51.100.4 rule=FW_USER_NATS2_APP suser= duser= app=bittorrent vs=vsys1 sz=INSIDE dz=EXTERNAL InboundInterface=ae2.2266 OutboundInterface=ae1 lp=log_forwarding sid=2935823 cnt=1 spt=6881 dpt=51413 srcTranslatedPort=0 dstTranslatedPort=0 flags=0x7a proto=udp act=allow tbytes=475 in=150 out=325 pkt=2 pktReceived=1 pktSent=1 start=Apr 04 2024 14:21:56 GMT stime=1206 urlcat=any externalId=externalId reason=aged-out DGl1=11 DGl2=161 DGl3=0 DGl4=0 VsysName=STONESOFT dvchost=FW-PERIMETRAL-AVG-01 cat=from-policy ActionFlags=0x8000000000000000 srcUUID= dstUUID= TunnelID=0 MonitorTag= ParentSessionID=0 ParentStartTime= TunnelType=N/A SCTPAssocID=0 SCTPChunks=0 SCTPChunkSent=0 SCTPChunksRcv=0 RuleUUID=746c3eb6-3d51-4679-8438-bd0e00e170a8 HTTP2Con=0 LinkChange=0 PolicyID= LinkDetail= SDWANCluster= SDWANDevice= SDWANClustype= SDWANSite= DynamicUsrgrp= XFFIP= srcDevCat= srcDevProf= srcDevModel= srcDevVendor= srcDevOS= srcDevOSv= srcHostname= srcMac= dstDevCat= dstDevProf= dstDevModel= dstDevVendor= dstDevOS= dstDevOSv= dstHostname= dstMac= ContainerName= PODNamespace= PODName= srcEDL= dstEDL= GPHostID= EPSerial= srcDAG= dstDAG= HASessionOwner= TimeHighRes=2024-04-04T16:21:56.250+02:00 ASServiceType= ASServiceDiff="CSV
1,2021/10/24 15:30:07,,CONFIG,0,2561,2021/10/24 15:30:07,198.51.100.0,,set,admin,Web,Succeeded, network virtual-router VR1,,VR1 { ecmp { algorithm { ip-modulo ; } } protocol { bgp { routing-options { graceful-restart { enable yes; } } enable no; } rip { enable no; } ospf { enable no; } ospfv3 { enable no; } } routing-table { ip { static-route { vr1-log { path-monitor { enable no; failure-condition any; hold-time 2; } nexthop { ip-address 198.51.100.0; } bfd { profile None; } interface ethernet1/1; metric 10; destination 0.0.0.0/0; route-table { unicast ; } } } } } interface [ ethernet1/1 ethernet1/2 ]; } ,7022390503849066572,0x0,0,0,0,0,,PA-VM,0,
Riferimento per la mappatura dei campi: campi dei log e campi UDM
Questa sezione spiega come il parser mappa i campi dei log del firewall Palo Alto Networks ai campi degli eventi UDM di Google SecOps per ogni tipo di log. La chiave dell'etichetta Google SecOps si riferisce al nome della chiave mappata al campo UDM Labels.key.
Ad esempio, nel caso del campo "Virtual System", il nome del campo è "cs3" nel formato CEF e "VirtualSystem" nel formato LEEF. Il campo UDM "about.labels.key" contiene il valore "vsys" e il campo UDM "about.labels.value" contiene il valore di questo campo. Alcuni nomi di campi CEF o LEEF non hanno un nome corrispondente ai nomi dei campi CSV. In questi casi, se aggiungi il tuo nome variabile nel formato log personalizzato nel profilo syslog, il parser non lo mappa al campo UDM.
Per il riferimento alla mappatura di ogni tipo di log, consulta le seguenti sezioni:
- Sistema
- Configurazione
- Minaccia/incendio boschivo
- Traffico
- ID utente
- HIP match
- Tag IP
- Decrittografia
- Tunnel
- Autenticazione
- URL
- Dati
- GlobalProtect
- Correlazione
- GTP
- SCTP
- Controlli
Sistema
La tabella seguente elenca i campi di log del tipo di log di sistema e i campi UDM corrispondenti.
| Campo CSV | Campo CEF | Campo LEEF | Chiave dell'etichetta Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Ora di ricezione (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" è assente) |
|
| Numero di serie | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Tipo (type) | type (intestazione) | gatto | metadata.product_event_type è impostato su "%{type} - %{subtype}". | |
| Tipo di minaccia/contenuti (sottotipo) | sottotipo (intestazione) | Sottotipo | metadata.product_event_type è impostato su "%{type} - %{subtype}". | |
| Ora di generazione (time_generated o cef-formatted-time_generated) | metadata.event_timestamp | |||
| Sistema virtuale (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| ID evento (eventid) | gatto | eventid | additional.fields.key e additional.fields.value.string_value | |
| Oggetto (oggetto) | fname | Nome del file | oggetto | target.resource.name |
| Modulo (modulo) | flexString2 | Modulo | modulo | additional.fields.key e additional.fields.value.string_value |
| Gravità (severity) | $number-of-severity(header) | Gravità | security_result.severity e security_result.severity_details | |
| Descrizione (opaca) | msg | msg | metadata.description | |
| principal_user_userid (questo campo viene estratto dal campo msg) | principal.user.userid | |||
| principal_ip3 (questo campo viene estratto dal campo msg) | principal.ip | |||
| Motivo (questo campo viene estratto dal campo msg) | security_result.description | |||
| server_address (questo campo viene estratto dal campo msg). | target.ip | |||
| server_profile (questo campo viene estratto dal campo msg) | additional.fields.key e additional.fields.value.string_value | |||
| Numero di sequenza (seqno) | externalId | sequenza | metadata.product_log_id | |
| Flag azioni (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Gerarchia dei gruppi di dispositivi (dg_hier_level_1 a dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome sistema virtuale (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nome dispositivo (device_name) | dvchost | DeviceName | target.hostname | |
| Timestamp ad alta risoluzione (high_res_timestamp) | anOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value |
Configurazione
La tabella seguente elenca i campi di log del tipo di log di configurazione e i relativi campi UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chiave dell'etichetta Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Ora di ricezione (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" è assente) |
|
| Numero di serie | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Tipo (type) | type (intestazione) | gatto | metadata.product_event_type | |
| Tipo di minaccia/contenuti (sottotipo) | sottotipo (intestazione) | metadata.product_event_type | ||
| Ora di generazione (time_generated o cef-formatted-time_generated) | metadata.event_timestamp | |||
| Host (host) | spettro | src | principal.ip/hostname | |
| Sistema virtuale (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| Comando (cmd) | atto | msg | cmd | principal.process.command_line |
| Amministratore (admin) | duser | usrName | principal.user.userid | |
| Cliente (client) | destinationServiceName | client | principal.application | |
| Risultato (risultato) | ID firma (intestazione)(motivo) | Risultato | security_result.summary | |
| Percorso di configurazione (percorso) | msg | ConfigurationPath | principal.process.command_line | |
| Before Change Detail (before_change_detail) | cs1 | BeforeChangeDetail | before_change_detail | target.resource.attribute.labels.key/value |
| After Change Detail (after_change_detail) | cs2 | AfterChangeDetail | after_change_detail | target.resource.attribute.labels.key/value |
| Numero di sequenza (seqno) | externalId | sequenza | metadata.product_log_id | |
| Flag azioni (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Gerarchia dei gruppi di dispositivi (dg_hier_level_1 a dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome sistema virtuale (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nome dispositivo (device_name) | dvchost | DeviceName | target.hostname | |
| Gruppo di dispositivi (dg_id) | PanOSFWDeviceGroup | target.asset.attribute.labels.key/value | dg_id | principal.asset.attribute.labels.key/value |
| Commento di controllo (commento) | PanOSPolicyAuditComment | commento | additional.fields.key e additional.fields.value.string_value | |
| Timestamp ad alta risoluzione (high_res_timestamp) | additional.fields.key e additional.fields.value.string_value | |||
| Gravità (severity) | number-of-severity(header) | security_result.severity e security_result.severity_details |
Threat/WildFire
La tabella seguente elenca i campi di log del tipo di log Threat/WildFire e i relativi campi UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chiave dell'etichetta Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Ora di ricezione (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" è assente) |
|
| Numero di serie | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (intestazione) | gatto | metadata.product_event_type | |
| Tipo di minaccia/contenuti (sottotipo) | cat/subtype (intestazione) | Sottotipo | metadata.product_event_type | |
| Genera ora (time_generated o cef-formatted-time_generated) | metadata.event_timestamp | |||
| Indirizzo di origine (src) | src | src | principal.ip | |
| Indirizzo di destinazione (dst) | dst | dst | target.ip | |
| IP di origine NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP di destinazione NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Nome regola (regola) | cs1 | RuleName | security_result.rule_name | |
| Utente di origine (srcuser) | suser | SourceUser / usrName | principal.user.userid | |
| Utente di destinazione (dstuser) | duser | DestinationUser | target.user.userid | |
| Applicazione (app) | app | Applicazione | target.application | |
| Sistema virtuale (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona di origine (da) | cs4 | SourceZone | da | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Zona di destinazione (a) | cs5 | DestinationZone | a | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Interfaccia in entrata (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Interfaccia in uscita (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Azione di log (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key e additional.fields.value.string_value |
| ID sessione (sessionid) | cn1 | SessionID | network.session_id | |
| Ripeti conteggio (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Porta di origine (sport) | spt | srcPort | principal.port | |
| Porta di destinazione (dport) | dpt | dstPort | target.port | |
| Porta di origine NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Porta di destinazione NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Flag (flags) | flexString1 | Bandiere | flags | additional.fields.key e additional.fields.value.string_value |
| Protocollo IP (proto) | proto | proto | network.ip_protocol | |
| Azione (azione) | atto | azione | security_result.action_details
security_result.action |
|
| URL/Nome file (varie) | richiesta | Vari | target.file.names (se il sottotipo è "file", "virus", "wildfire-virus" o "wildfire", il campo "misc" viene mappato su target.file.names) target.url (se il sottotipo è "url", il campo "misc" viene mappato su target.url e target.hostname) |
|
| Nome minaccia/contenuto (threatid) | gatto | ThreatID | security_result.threat_name | |
| Categoria (categoria) | cs2 | URLCategory | security_result.category_details | |
| Gravità (severity) | number-of-severity(header) | Gravità | security_result.severity e security_result.severity_details | |
| Direzione (direction) | flexString2 | Direzione | network.direction | |
| Numero di sequenza (seqno) | externalId | sequenza | metadata.product_log_id | |
| Flag azioni (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Paese di origine (srcloc) | SourceLocation | principal.location.country_or_region | ||
| Paese di destinazione (dstloc) | DestinationLocation | target.location.country_or_region | ||
| Tipo di contenuti (contenttype) | ContentType | contenttype | additional.fields.key e additional.fields.value.string_value | |
| ID PCAP (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key e additional.fields.value.string_value |
| File Digest (filedigest) | fileHash | FileDigest | target.file.sha1/md5/sha256 | |
| Cloud (cloud) | filePath | Cloud | cloud | additional.fields.key e additional.fields.value.string_value |
| Indice URL (url_idx) | URLIndex | url_idx | additional.fields.key e additional.fields.value.string_value | |
| User agent (user_agent) | network.http.user_agent | |||
| Tipo di file (filetype) | fileType | FileType | target.file.mime_type | |
| X-Forwarded-For (xff) | principal.ip | |||
| Referer (referer) | network.http.referral_url | |||
| Mittente (mittente) | suid | Mittente | network.email.from | |
| Oggetto (oggetto) | msg | Oggetto | network.email.subject | |
| Destinatario (destinatario) | duid | Destinatario | network.email.to | |
| ID report (reportid) | oldFileId | ReportID | reportid | additional.fields.key e additional.fields.value.string_value |
| Gerarchia dei gruppi di dispositivi (dg_hier_level_1 a dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome sistema virtuale (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nome dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| UUID VM di origine (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id | |
| UUID VM di destinazione (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id | |
| Metodo HTTP (http_method) | RequestMethod | network.http.method | ||
| ID tunnel/IMSI (tunnel_id/imsi) | PanOSTunnelID | TunnelID | tunnel_id/imsi | additional.fields.key e additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag/imei) | PanOSMonitorTag | MonitorTag | monitortag/imei | additional.fields.key e additional.fields.value.string_value |
| ID sessione principale (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Ora di inizio della sessione principale (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key e additional.fields.value.string_value |
| Tipo di tunnel (tunnel) | PanOSTunnelType | TunnelType | tunnel | additional.fields.key e additional.fields.value.string_value |
| Categoria minaccia (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| Versione contenuto (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key e additional.fields.value.string_value |
| ID associazione SCTP (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key e additional.fields.value.string_value | |
| ID protocollo payload (ppid) | PanOSPPID | ppid | additional.fields.key e additional.fields.value.string_value | |
| Intestazioni HTTP (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Elenco categorie di URL (url_category_list) | PanOSURLCatList | url_category_list | additional.fields.key e additional.fields.value.string_value | |
| UUID regola (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| Connessione HTTP/2 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| Nome gruppo di utenti dinamico (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Indirizzo XFF (xff_ip) | PanXFFIP | principal.ip | ||
| Categoria dispositivo di origine (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Profilo del dispositivo di origine (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modello del dispositivo di origine (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Fornitore del dispositivo di origine (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Famiglia di sistemi operativi del dispositivo di origine (src_osfamily) | PanSrcDeviceOS | src_osfamily | principal.platform | |
| Versione del sistema operativo del dispositivo di origine (src_osversion) | PanSrcDeviceOSv | principal.platform_version | ||
| Nome host di origine (src_host) | PanSrcHostname | principal.hostname | ||
| Indirizzo MAC di origine (src_mac) | PanSrcMac | principal.mac | ||
| Categoria dispositivo di destinazione (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Profilo del dispositivo di destinazione (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modello del dispositivo di destinazione (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Fornitore del dispositivo di destinazione (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Famiglia di sistemi operativi del dispositivo di destinazione (dst_osfamily) | PanDstDeviceOS | dst_osfamily | target.platform | |
| Versione del sistema operativo del dispositivo di destinazione (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Nome host di destinazione (dst_host) | PanDstHostname | target.hostname | ||
| Indirizzo MAC di destinazione (dst_mac) | PanDstMac | target.mac | ||
| ID contenitore (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| Spazio dei nomi POD (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| Nome POD (pod_name) | PanPODName | pod_name | target.resource.name | |
| Elenco dinamico esterno di origine (src_edl) | PanSrcEDL | src_edl | additional.fields.key e additional.fields.value.string_value | |
| Elenco dinamico esterno di destinazione (dst_edl) | PanDstEDL | dst_edl | additional.fields.key e additional.fields.value.string_value | |
| ID host (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Numero di serie del dispositivo utente (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| Elenco di domini (domain_edl) | PanDomainEDL | domain_edl | additional.fields.key e additional.fields.value.string_value | |
| Gruppo di indirizzi dinamici di origine (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Gruppo di indirizzi dinamici di destinazione (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| Hash parziale (partial_hash) | PanPartialHash | partial_hash | additional.fields.key e additional.fields.value.string_value | |
| Timestamp ad alta risoluzione (high_res timestamp) | PanTimeHighRes | timestamp ad alta risoluzione | additional.fields.key e additional.fields.value.string_value | |
| Motivo (motivo) | PanReasonFilteringAction | motivo | security_result.summary | |
| Motivazione (giustificazione) | PanJustification | giustificazione | additional.fields.key e additional.fields.value.string_value | |
| Un tipo di servizio di sezione (nssai_sst) | PanASServiceType | nssai_sst | additional.fields.key e additional.fields.value.string_value | |
| Sottocategoria dell'applicazione (subcategory_of_app) | subcategory_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Categoria applicazione (category_of_app) | category_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia dell'applicazione (technology_of_app) | technology_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Rischio applicazione (risk_of_app) | risk_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Caratteristica dell'applicazione (characteristic_of_app) | characteristic_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Container dell'applicazione (container_of_app) | container_of_app | additional.fields.key e additional.fields.value.string_value | ||
| SaaS dell'applicazione (is_saas_of_app) | is_saas_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Applicazione sottoposta a tunneling (tunneled_app) | additional.fields.key e additional.fields.value.string_value | |||
| Tipo di flusso (flow_type) | additional.fields.key e additional.fields.value.string_value | |||
| Nome cluster (cluster_name) | intermediary.resource.name | |||
| Stato sanzionato dell'applicazione (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key e additional.fields.value.string_value |
Traffico
La tabella seguente elenca i campi di log del tipo di log del traffico e i campi UDM corrispondenti.
| Campo CSV | Campo CEF | Campo LEEF | Chiave dell'etichetta Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Ora di ricezione (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" è assente) |
|
| Numero di serie | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (intestazione) | cat/Type | metadata.product_event_type | |
| Tipo di minaccia/contenuti (sottotipo) | sottotipo (intestazione) | Sottotipo | metadata.product_event_type | |
| Ora di generazione (time_generated o cef-formatted-time_generated) | start | metadata.event_timestamp | ||
| Indirizzo di origine (src) | src | src | principal.ip | |
| Indirizzo di destinazione (dst) | dst | dst | target.ip | |
| IP di origine NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP di destinazione NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Nome regola (regola) | cs1 | RuleName | security_result.rule_name | |
| Utente di origine (srcuser) | suser | SourceUser | principal.user.userid | |
| Utente di destinazione (dstuser) | duser | DestinationUser | target.user.userid | |
| Applicazione (app) | app | Applicazione | target.application | |
| Sistema virtuale (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona di origine (da) | cs4 | SourceZone | da | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Zona di destinazione (a) | cs5 | DestinationZone | a | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Interfaccia in entrata (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Interfaccia in uscita (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Azione di log (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key e additional.fields.value.string_value |
| ID sessione (sessionid) | cn1 | SessionID | network.session_id | |
| Ripeti conteggio (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Porta di origine (sport) | spt | srcPort | principal.port | |
| Porta di destinazione (dport) | dpt | dstPort | target.port | |
| Porta di origine NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Porta di destinazione NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Flag (flags) | flexString1 | Bandiere | flags | additional.fields.key e additional.fields.value.string_value |
| Protocollo IP (proto) | proto | proto | network.ip_protocol | |
| Azione (azione) | atto | azione | security_result.action_details
security_result.action |
|
| Byte (byte) | flexNumber1 | totalBytes | byte | additional.fields.key e additional.fields.value.string_value |
| Byte inviati (bytes_sent) | in | srcBytes | network.sent_bytes | |
| Byte ricevuti (bytes_received) | troppo complessi per essere capiti? | dstBytes | network.received_bytes | |
| Pacchetti (bustine) | cn2 | totalPackets | pacchetti | additional.fields.key e additional.fields.value.string_value |
| Ora di inizio (inizio) | StartTime | start | additional.fields.key e additional.fields.value.string_value | |
| Tempo trascorso (trascorso) | cn3 | ElapsedTime | trascorso | network.session_duration.seconds |
| Categoria (categoria) | cs2 | URLCategory | security_result.category / security_result.category_details | |
| Numero di sequenza (seqno) | externalId | sequenza | metadata.product_log_id | |
| Flag azioni (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Paese di origine (srcloc) | SourceLocation | principal.location.country_or_region | ||
| Paese di destinazione (dstloc) | DestinationLocation | target.location.country_or_region | ||
| Pacchetti inviati (pkts_sent) | PanOSPacketsSent | srcPackets | pkts_sent | network.sent_packets |
| Pacchetti ricevuti (pkts_received) | PanOSPacketsReceived | dstPackets | pkts_received | network.received_packets |
| Motivo di fine della sessione (session_end_reason) | motivo | SessionEndReason | security_result.summary | |
| Gerarchia del gruppo di dispositivi 1 (dg_hier_level_1 a dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia dei gruppi di dispositivi 2 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi 3 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome sistema virtuale (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nome dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| Origine azione (action_source) | gatto | ActionSource | action_source | additional.fields.key e additional.fields.value.string_value |
| UUID VM di origine (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id | |
| UUID VM di destinazione (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id | |
| Tunnel ID/IMSI (tunnelid/imsi) | PanOSTunnelID | TunnelID | tunnelid/imsi | additional.fields.key e additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag/imei) | PanOSMonitorTag | MonitorTag | monitortag/imei | additional.fields.key e additional.fields.value.string_value |
| ID sessione principale (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Ora di inizio del genitore (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key e additional.fields.value.string_value |
| Tipo di tunnel (tunnel) | PanOSTunnelType | TunnelType | tunnel | additional.fields.key e additional.fields.value.string_value |
| ID associazione SCTP (assoc_id) | PanOSSCTPAssocID | assoc_id | additional.fields.key e additional.fields.value.string_value | |
| Segmenti SCTP (chunks) | PanOSSCTPChunks | pezzi | additional.fields.key e additional.fields.value.string_value | |
| Segmenti SCTP inviati (chunks_sent) | PanOSSCTPChunkSent | chunks_sent | additional.fields.key e additional.fields.value.string_value | |
| Chunk SCTP ricevuti (chunks_received) | PanOSSCTPChunksRcv | chunks_received | additional.fields.key e additional.fields.value.string_value | |
| UUID regola (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| Connessione HTTP/2 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| Conteggio flap app (link_change_count) | PanLinkChange | link_change_count | additional.fields.key e additional.fields.value.string_value | |
| ID policy (policy_id) | PanPolicyID | policy_id | additional.fields.key e additional.fields.value.string_value | |
| Interruttori per link (link_switches) | PanLinkDetail | link_switches | additional.fields.key e additional.fields.value.string_value | |
| Cluster SD-WAN (sdwan_cluster) | PanSDWANCluster | sdwan_cluster | additional.fields.key e additional.fields.value.string_value | |
| Tipo di dispositivo SD-WAN (sdwan_device_type) | PanSDWANDevice | sdwan_device_type | additional.fields.key e additional.fields.value.string_value | |
| Tipo di cluster SD-WAN (sdwan_cluster_type) | PanSDWANClustype | sdwan_cluster_type | additional.fields.key e additional.fields.value.string_value | |
| Sito SD-WAN (sdwan_site) | PanSDWANSite | sdwan_site | additional.fields.key e additional.fields.value.string_value | |
| Nome gruppo di utenti dinamico (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | additional.fields.key e additional.fields.value.string_value | |
| Indirizzo XFF (xff_ip) | PanXFFIP | principal.ip | ||
| Categoria dispositivo di origine (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Profilo del dispositivo di origine (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modello del dispositivo di origine (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Fornitore del dispositivo di origine (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Famiglia di sistemi operativi del dispositivo di origine (src_osfamily) | PanSrcDeviceOS | principal.platform | ||
| Versione del sistema operativo del dispositivo di origine (src_osversion) | PanSrcDeviceOSv | principal.asset.software.version | ||
| Nome host di origine (src_host) | PanSrcHostname | principal.hostname | ||
| Indirizzo MAC di origine (src_mac) | PanSrcMac | principal.mac | ||
| Categoria dispositivo di destinazione (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Profilo del dispositivo di destinazione (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modello del dispositivo di destinazione (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Fornitore del dispositivo di destinazione (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Famiglia di sistemi operativi del dispositivo di destinazione (dst_osfamily) | PanDstDeviceOS | dst_osfamily | target.platform | |
| Versione del sistema operativo del dispositivo di destinazione (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Nome host di destinazione (dst_host) | PanDstHostname | target.hostname | ||
| Indirizzo MAC di destinazione (dst_mac) | PanDstMac | target.mac | ||
| ID contenitore (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| Spazio dei nomi POD (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| Nome POD (pod_name) | PanPODName | pod_name | target.resource.name | |
| Elenco dinamico esterno di origine (src_edl) | PanSrcEDL | src_edl | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Elenco dinamico esterno di destinazione (dst_edl) | PanDstEDL | dst_edl | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| ID host (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Numero di serie del dispositivo utente (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| Gruppo di indirizzi dinamici di origine (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Gruppo di indirizzi dinamici di destinazione (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| Proprietario della sessione (session_owner) | PanHASessionOwner | session_owner | additional.fields.key e additional.fields.value.string_value | |
| Timestamp ad alta risoluzione (high_res_timestamp) | PanTimeHighRes | additional.fields.key e additional.fields.value.string_value | ||
| Un tipo di servizio di sezione (nsdsai_sst) | PanASServiceType | nsdsai_sst | additional.fields.key e additional.fields.value.string_value | |
| Un elemento di differenziazione della sezione (nsdsai_sd) | PanASServiceDiff | nsdsai_sd | additional.fields.key e additional.fields.value.string_value | |
| Sottocategoria dell'applicazione (subcategory_of_app) | subcategory_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Categoria applicazione (category_of_app) | category_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia dell'applicazione (technology_of_app) | technology_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Rischio applicazione (risk_of_app) | security_result.severity | |||
| Caratteristica dell'applicazione (characteristic_of_app) | characteristic_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Container dell'applicazione (container_of_app) | container_of_app | additional.fields.key e additional.fields.value.string_value | ||
| SaaS dell'applicazione (is_saas_of_app) | is_saas_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Stato sanzionato dell'applicazione (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Sottocategoria dell'applicazione (subcategory_of_app) | subcategory_of_app1 | additional.fields.key e additional.fields.value.string_value | ||
| Gravità (severity) | number-of-severity(header) | security_result.severity e security_result.severity_details |
User-ID
La tabella seguente elenca i campi del log del tipo di log user-id e i relativi campi UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chiave dell'etichetta Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Ora di ricezione (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" è assente) |
|
| Numero di serie | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (intestazione) | gatto | metadata.product_event_type | |
| Tipo di minaccia/contenuti (sottotipo) | sottotipo (intestazione) | Sottotipo | metadata.product_event_type | |
| Ora di generazione (time_generated o cef-formatted-time_generated) | metadata.event_timestamp | |||
| Sistema virtuale (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| IP di origine (ip) | src | src | principal.ip | |
| Utente (utente) | duser | usrName | target.user.userid
target.administrative_domain target.user.email_addresses |
|
| Nome origine dati (datasourcename) | cs4 | DataSourceName | datasourcename | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| ID evento (eventid) | EventID | eventid | additional.fields.key e additional.fields.value.string_value | |
| Ripeti conteggio (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Soglia di timeout | cn3 | TimeoutThreshold | timeout | additional.fields.key e additional.fields.value.string_value |
| Porta di origine (beginport) | spt | srcPort | principal.port | |
| Porta di destinazione (endport) | dpt | dstPort | target.port | |
| Origine dati | cs5 | DataSource | origine dati | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Tipo di origine dati (datasourcetype) | cs6 | DataSourceType | datasourcetype | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Numero di sequenza (seqno) | externalId | sequenza | metadata.product_log_id | |
| Flag azioni (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome sistema virtuale (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nome dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| ID sistema virtuale (vsys_id) | cn2 | VirtualSystemID | intermediary.resource.product_object_id | |
| Tipo di fattore (factortype) | cs1 | FactorType | factortype | additional.fields.key e additional.fields.value.string_value |
| Tempo di completamento del fattore (factorcompletiontime) | end | FactorCompletionTime | factorcompletiontime | additional.fields.key e additional.fields.value.string_value |
| Numero fattore (factorno) | cn1 | FactorNumber | factorno | additional.fields.key e additional.fields.value.string_value |
| Flag dei gruppi utente (ugflags) | PanOSUGFlags | ugflags | additional.fields.key e additional.fields.value.string_value | |
| Utente per sorgente (userbysource) | PanOSUserBySource | target.user.userid
target.administrative_domain target.user.email_addresses |
||
| Timestamp ad alta risoluzione (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value | ||
| Origine dati (origindatasource) | additional.fields.key e additional.fields.value.string_value | |||
| Nome cluster (cluster_name) | principal.resource.name | |||
| Gravità (severity) | number-of-severity(header) | security_result.severity e security_result.severity_details |
Corrispondenza HIP
La seguente tabella elenca i campi di log del tipo di log di corrispondenza HIP e i relativi campi UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chiave dell'etichetta Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Ora di ricezione (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" è assente) |
|
| Numero di serie | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Tipo (type) | type (intestazione) | gatto | metadata.product_event_type | |
| Tipo di minaccia/contenuti (sottotipo) | sottotipo (intestazione) | Sottotipo | ||
| Ora di generazione (time_generated o cef-formatted-time_generated) | start | startTime | metadata.event_timestamp | |
| Utente di origine (srcuser) | suser | usrName | principal.user.userid | |
| Sistema virtuale (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| Nome macchina (machinename) | spettro | identHostName | principal.hostname | |
| Sistema operativo | cs2 | Sistema operativo | principal.asset.platform_software.platform | |
| Indirizzo di origine (src) | src | identsrc | principal.ip | |
| HIP (matchname) | gatto | HIP | matchname | target.resource.attribute.labels.key/value additional.fields.key e additional.fields.value.string_value |
| Ripeti conteggio (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Tipo di HIP (matchtype) | ID classe evento dispositivo (intestazione) | HIPType | matchtype | target.resource.attribute.labels.key/value additional.fields.key e additional.fields.value.string_value |
| Numero di sequenza (seqno) | externalId | sequenza | metadata.product_log_id | |
| Flag azioni (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome sistema virtuale (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nome dispositivo (device_name) | dvchost | DeviceName | target.hostname | |
| ID sistema virtuale (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id | |
| Indirizzo di sistema IPv6 (srcipv6) | c6a2 | srcipv6 | principal.asset.ip | |
| ID host (hostid) | PanOSHostID | principal.asset.asset_id | ||
| Numero di serie del dispositivo utente (serialnumber) | PanOSEndpointSerialNumber | principal.asset.hardware.serial_number | ||
| Indirizzo MAC del dispositivo (mac) | PanOSEndpointMac | principal.asset.mac | ||
| Timestamp ad alta risoluzione (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value | ||
| Nome cluster (cluster_name) | principal.resource.name | |||
| Gravità (severity) | number-of-severity(header) | security_result.severity e security_result.severity_details |
Tag IP
La tabella seguente elenca i campi di log del tipo di log Tag IP e i campi UDM corrispondenti.
| Campo CSV | Campo CEF | Campo LEEF | Chiave dell'etichetta Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Ora di ricezione (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" è assente) |
|
| Numero di serie | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Tipo (type) | type (intestazione) | gatto | metadata.product_event_type | |
| Tipo di minaccia/contenuti (sottotipo) | sottotipo (intestazione) | Sottotipo | metadata.product_event_type | |
| Ora di generazione (time_generated o cef-formatted-time_generated) | GenerateTime | metadata.event_timestamp | ||
| Sistema virtuale (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| IP di origine (ip) | src | src | principal.ip | |
| Nome tag (tag_name) | PanOSTagName | TagName | tag_name | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| ID evento (event_id) | PanOSEventID | EventID | event_id | additional.fields.key e additional.fields.value.string_value |
| Ripeti conteggio (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Timeout (timeout) | PanOSTimeout | TimeoutThreshold | timeout | additional.fields.key e additional.fields.value.string_value |
| Nome origine dati (datasourcename) | PanOSDataSourceName | DataSourceName | datasourcename | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Tipo di origine dati (datasource_type) | PanOSDataSourceType | DataSource | datasource_type | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Sottotipo di origine dati (datasource_subtype) | PanOSDataSourceSubType | DataSourceType | datasource_subtype | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Numero di sequenza (seqno) | externalId | sequenza | metadata.product_log_id | |
| Flag azioni (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome sistema virtuale (vsys_name) | PanOsVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nome dispositivo (device_name) | dvchost | DeviceName | target.hostname | |
| ID sistema virtuale (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id | |
| Timestamp ad alta risoluzione (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value | ||
| Gravità (severity) | number-of-severity(header) | security_result.severity e security_result.severity_details | ||
| Nome cluster (cluster_name) | principal.resource.name |
Decriptazione
La tabella seguente elenca i campi di log del tipo di log di decriptazione e i relativi campi UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chiave dell'etichetta Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Ora di ricezione (receive_time o cef-formatted-receive_time) | rt | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" è assente) |
||
| Numero di serie | PanOSDeviceSN | intermediary.asset.hardware.serial_number | ||
| Tipo (type) | type (intestazione) | metadata.product_event_type | ||
| Tipo di minaccia/contenuti (sottotipo) | sottotipo (intestazione) | metadata.product_event_type | ||
| Versione configurazione (config_ver) | PanOSConfigVersion | config_ver | additional.fields.key e additional.fields.value.string_value | |
| Genera ora (time_generated) | PanOSLogTimeStamp | metadata.event_timestamp | ||
| Indirizzo di origine (src) | src | principal.ip | ||
| Indirizzo di destinazione (dst) | dst | target.ip | ||
| IP di origine NAT (natsrc) | sourceTranslatedAddress | principa.nat_ip | ||
| IP di destinazione NAT (natdst) | destinationTranslatedAddress | target.nat_ip | ||
| Rule (regola) | cs1 | security_result.rule_name | ||
| Utente di origine (srcuser) | suser | principal.user.userid | ||
| Utente di destinazione (dstuser) | duser | target.user.userid | ||
| Applicazione (app) | app | network.application_protocol | ||
| Sistema virtuale (vsys) | cs3 | vsys | intermediary.asset.attribute.labels.key/value | |
| Zona di origine (da) | cs4 | da | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Zona di destinazione (a) | cs5 | a | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Interfaccia in entrata (inbound_if) | deviceInboundInterface | inbound_if | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Interfaccia in uscita (outbound_if) | deviceOutboundInterface | outbound_if | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Azione di log (logset) | cs6 | logset | additional.fields.key e additional.fields.value.string_value | |
| Orario log (time_received) | PanOSTimeReceivedManagementPlane | - | ||
| ID sessione (sessionid) | cn1 | network.session_id | ||
| Ripeti conteggio (repeatcnt) | PanOSCountOfRepeats/RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value | |
| Porta di origine (sport) | spt | principal.port | ||
| Porta di destinazione (dport) | dpt | target.port | ||
| Porta di origine NAT (natsport) | sourceTranslatedPort | principal.nat_port | ||
| Porta di destinazione NAT (natdport) | destinationTranslatedPort | target.nat_port | ||
| Flag (flags) | flexString1 | flags | additional.fields.key e additional.fields.value.string_value | |
| Protocollo IP (proto) | proto | network.ip_protocol | ||
| Azione (azione) | atto | security_result.action_details
security_result.action |
||
| Tunnel (tunnel) | PanOSTunnel | tunnel | additional.fields.key e additional.fields.value.string_value | |
| UUID VM di origine (src_uuid) | PanOSSourceUUID | principal.asset.product_object_id | ||
| UUID VM di destinazione (dst_uuid) | PanOSDestinationUUID | target.asset.product_object_id | ||
| UUID per la regola (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| Stage for Client to Firewall (hs_stage_c2f) | PanOSClientToFirewall | hs_stage_c2f | additional.fields.key e additional.fields.value.string_value | |
| Stage for Firewall to Server (hs_stage_f2s) | PanOSFirewallToServer | hs_stage_f2s | additional.fields.key e additional.fields.value.string_value | |
| Versione TLS (tls_version) | PanOSTLSVersion | network.tls.version | ||
| Algoritmo di scambio di chiavi (tls_keyxchg) | PanOSTLSKeyExchange | tls_keyxchg | additional.fields.key e additional.fields.value.string_value | |
| Algoritmo di crittografia (tls_enc) | PanOSTLSEncryptionAlgorithm | tls_enc | additional.fields.key e additional.fields.value.string_value | |
| Algoritmo di hash (tls_auth) | PanOSTLSAuth | tls_auth | additional.fields.key e additional.fields.value.string_value | |
| Nome della policy (policy_name) | PanOSPolicyName | policy_name | additional.fields.key e additional.fields.value.string_value | |
| Curva ellittica (ec_curve) | PanOSEllipticCurve | network.tls.curve | ||
| Indice di errori (err_index) | PanOSErrorIndex | err_index | additional.fields.key e additional.fields.value.string_value | |
| Stato root (root_status) | PanOSRootStatus | root_status | additional.fields.key e additional.fields.value.string_value | |
| Stato della catena (chain_status) | PanOSChainStatus | chain_status | additional.fields.key e additional.fields.value.string_value | |
| Tipo di proxy (proxy_type) | PanOSProxyType | proxy_type | additional.fields.key e additional.fields.value.string_value | |
| Numero di serie del certificato (cert_serial) | PanOSCertificateSerial | network.tls.server.certificate.serial | ||
| Impronta digitale certificato | PanOSFingerprint | network.tls.server.certificate.md5/sha1/sha256 | ||
| Data di inizio del certificato (notbefore) | PanOSTimeNotBefore | network.tls.server.certificate.not_before | ||
| Data di fine validità del certificato (notafter) | PanOSTimeNotAfter | network.tls.server.certificate.not_after | ||
| Versione del certificato (cert_ver) | PanOSCertificateVersion | network.tls.server.certificate.version | ||
| Dimensioni certificato (cert_size) | PanOSCertificateSize | cert_size | additional.fields.key e additional.fields.value.string_value | |
| Lunghezza del nome comune (cn_len) | PanOSCommonNameLength | cn_len | additional.fields.key e additional.fields.value.string_value | |
| Lunghezza del nome comune dell'emittente (issuer_len) | PanOSIssuerNameLength | issuer_len | additional.fields.key e additional.fields.value.string_value | |
| Lunghezza del nome comune della radice (rootcn_len) | PanOSRootCNLength | rootcn_len | additional.fields.key e additional.fields.value.string_value | |
| Lunghezza snippet (sni_len) | PanOSSNILength | sni_len | additional.fields.key e additional.fields.value.string_value | |
| Flag del certificato (cert_flags) | PanOSCertificateFlags | cert_flags | additional.fields.key e additional.fields.value.string_value | |
| Nome comune del soggetto (cn) | PanOSCommonName | cn | additional.fields.key e additional.fields.value.string_value | |
| Nome comune dell'emittente (issuer_cn) | PanOSIssuerCommonName | network.tls.server.certificate.issuer | ||
| Nome comune della radice (root_cn) | PanOSRootCommonName | root_cn | additional.fields.key e additional.fields.value.string_value | |
| Server Name Indication
(sni) |
network.tls.client.server_name | |||
| Errore (errore) | PanOSErrorMessage | errore | additional.fields.key e additional.fields.value.string_value | |
| ID contenitore (container_id) | PanOSContainerID | container_id | intermediary.resource.product_object_id | |
| Spazio dei nomi POD (pod_namespace) | PanOSContainerNameSpace | pod_namespace | target.resource.attribute.labels.key/value additional.fields.key e additional.fields.value.string_value |
|
| Nome POD (pod_name) | PanOSContainerName | pod_name | target.resource.name | |
| Elenco dinamico esterno di origine (src_edl) | PanOSSourceEDL | src_edl | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Elenco dinamico esterno di destinazione (dst_edl) | PanOSDestinationEDL | dst_edl | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Gruppo di indirizzi dinamici di origine (src_dag) | PanOSSourceDynamicAddressGroup | principal.group.group_display_name | ||
| Gruppo di indirizzi dinamici di destinazione (dst_dag) | PanOSDestinationDynamicAddressGroup | target.group.group_display_name | ||
| Timestamp ad alta risoluzione (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value | ||
| Categoria del dispositivo di origine (src_category) | PanOSSourceDeviceCategory | src_category | principal.asset.category | |
| Profilo del dispositivo di origine (src_profile) | PanOSSourceDeviceProfile | src_profile | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modello del dispositivo di origine (src_model) | PanOSSourceDeviceModel | src_model | principal.asset.hardware.model | |
| Fornitore del dispositivo di origine (src_vendor) | PanOSSourceDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Famiglia di sistemi operativi del dispositivo di origine (src_osfamily) | PanOSSourceDeviceOSFamily | principal.platform | ||
| Versione del sistema operativo del dispositivo di origine (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | ||
| Nome host di origine (src_host) | PanOSSourceDeviceHost | principal.hostname | ||
| Indirizzo MAC di origine (src_mac) | PanOSSourceDeviceMac | principal.mac | ||
| Categoria dispositivo di destinazione (dst_category) | PanOSDestinationDeviceCategory | dst_category | target.asset.category | |
| Profilo del dispositivo di destinazione (dst_profile) | PanOSDestinationDeviceProfile | dst_profile | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modello del dispositivo di destinazione (dst_model) | PanOSDestinationDeviceModel | dst_model | target.asset.hardware.model | |
| Fornitore del dispositivo di destinazione (dst_vendor) | PanOSDestinationDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Famiglia di sistemi operativi del dispositivo di destinazione (dst_osfamily) | PanOSDestinationDeviceOSFamily | dst_osfamily | target.platform | |
| Versione del sistema operativo del dispositivo di destinazione (dst_osversion) | PanOSDestinationDeviceOSVersion | target.platform_version | ||
| Nome host di destinazione (dst_host) | PanOSDestinationDeviceHost | target.hostname | ||
| Indirizzo MAC di destinazione (dst_mac) | PanOSDestinationDeviceMac | target.mac | ||
| Numero di sequenza (seqno) | PanOSLogTypeSeqNo | metadata.product_log_id | ||
| Flag azioni (actionflags) | PanOSActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value | |
| Gerarchia del gruppo di dispositivi (dg_hier_level_1) | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value | |
| Gerarchia del gruppo di dispositivi (dg_hier_level_2) | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value | |
| Gerarchia del gruppo di dispositivi (dg_hier_level_3) | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value | |
| Gerarchia del gruppo di dispositivi (dg_hier_level_4) | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value | |
| Nome sistema virtuale (vsys_name) | intermediary.asset.attribute.labels.key/value | |||
| Nome dispositivo (device_name) | intermediary.hostname | |||
| ID sistema virtuale (vsys_id) | intermediary.resource.product_object_id | |||
| Sottocategoria dell'applicazione (subcategory_of_app) | subcategory_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Categoria applicazione (category_of_app) | category_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia dell'applicazione (technology_of_app) | technology_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Rischio applicazione (risk_of_app) | security_result.severity | |||
| Caratteristica dell'applicazione (characteristic_of_app) | characteristic_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Container dell'applicazione (container_of_app) | container_of_app | additional.fields.key e additional.fields.value.string_value | ||
| SaaS dell'applicazione (is_saas_of_app) | is_saas_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Stato sanzionato dell'applicazione (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Gravità (severity) | number-of-severity(header) | security_result.severity e security_result.severity_details |
Tunnel
La tabella seguente elenca i campi di log del tipo di log del tunnel e i relativi campi UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chiave dell'etichetta Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Ora di ricezione (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" è assente) |
|
| Numero di serie | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (intestazione) | gatto | metadata.product_event_type | |
| Tipo di minaccia/contenuti (sottotipo) | sottotipo (intestazione) | Sottotipo | metadata.product_event_type | |
| Ora di generazione (time_generated o cef-formatted-time_generated) | metadata.event_timestamp | |||
| Indirizzo di origine (src) | src | src | principal.ip | |
| Indirizzo di destinazione (dst) | dst | dst | target.ip | |
| IP di origine NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP di destinazione NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Nome regola (regola) | cs1 | RuleName | security_result.rule_name | |
| Utente di origine (srcuser) | suser | SourceUser / usrName | principal.user.userid | |
| Utente di destinazione (dstuser) | duser | DestinationUser | target.user.userid | |
| Applicazione (app) | app | Applicazione | network.application_protocol | |
| Sistema virtuale (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona di origine (da) | cs4 | SourceZone | da | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Zona di destinazione (a) | cs5 | DestinationZone | a | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Interfaccia in entrata (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Interfaccia in uscita (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Azione di log (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key e additional.fields.value.string_value |
| ID sessione (sessionid) | cn1 | SessionID | network.session_id | |
| Ripeti conteggio (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Porta di origine (sport) | spt | srcPort | principal.port | |
| Porta di destinazione (dport) | dpt | dstPort | target.port | |
| Porta di origine NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Porta di destinazione NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Flag (flags) | flexString1 | Bandiere | flags | additional.fields.key e additional.fields.value.string_value |
| Protocollo IP (proto) | proto | proto | network.ip_protocol | |
| Azione (azione) | atto | azione | security_result.action_details
security_result.action |
|
| Gravità (severity) | number-of-severity(header) | security_result.severity e security_result.severity_details | ||
| Numero di sequenza (seqno) | externalId | sequenza | metadata.product_log_id | |
| Flag azioni (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Posizione di origine (srcloc) | principal.location.country_or_region | |||
| Località di destinazione (dstloc) | target.location.country_or_region | |||
| Gerarchia del gruppo di dispositivi (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome sistema virtuale (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nome dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| ID tunnel (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key e additional.fields.value.string_value |
| Monitor Tag (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key e additional.fields.value.string_value |
| ID sessione principale (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Ora di inizio del genitore (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key e additional.fields.value.string_value |
| Tipo di tunnel (tunnel) | cs2 | TunnelType | tunnel | additional.fields.key e additional.fields.value.string_value |
| Byte (byte) | flexNumber1 | totalBytes | byte | additional.fields.key e additional.fields.value.string_value |
| Byte inviati (bytes_sent) | in | srcBytes | network.sent_bytes | |
| Byte ricevuti (bytes_received) | troppo complessi per essere capiti? | dstBytes | network.received_bytes | |
| Pacchetti (bustine) | cn2 | totalPackets | pacchetti | additional.fields.key e additional.fields.value.string_value |
| Pacchetti inviati (pkts_sent) | PanOSPacketsSent | srcPackets | pkts_sent | network.sent_packets |
| Pacchetti ricevuti (pkts_received) | PanOSPacketsReceived | dstPackets | pkts_received | network.received_packets |
| Incapsulamento massimo (max_encap) | flexNumber2 | MaximumEncapsulation | max_encap | additional.fields.key e additional.fields.value.string_value |
| Protocollo sconosciuto (unknown_proto) | cfp1 | UnknownProtocol | unknown_proto | additional.fields.key e additional.fields.value.string_value |
| Controllo rigoroso (strict_check) | cfp2 | StrictChecking | strict_check | additional.fields.key e additional.fields.value.string_value |
| Frammento tunnel (tunnel_fragment) | PanOSTunnelFragment | TunnelFragment | tunnel_fragment | additional.fields.key e additional.fields.value.string_value |
| Sessioni create (sessions_created) | cfp3 | SessionsCreated | sessions_created | additional.fields.key e additional.fields.value.string_value |
| Sessioni chiuse (sessions_closed) | cfp4 | SessionsClosed | sessions_closed | additional.fields.key e additional.fields.value.string_value |
| Motivo di fine della sessione (session_end_reason) | motivo | SessionEndReason | security_result.summary | |
| Origine azione (action_source) | gatto | ActionSource | action_source | additional.fields.key e additional.fields.value.string_value |
| Ora di inizio (inizio) | startTime | start | additional.fields.key e additional.fields.value.string_value | |
| Tempo trascorso (trascorso) | cn3 | ElapsedTime | trascorso | network.session_duration.seconds |
| Regola di ispezione del tunnel (tunnel_insp_rule) | PanOSTunneInspectionRule | security_result.rule_name = "Tunnel Inspection Rule: %{PanOSTunnelInspectionRule}" | ||
| IP utente remoto (remote_user_ip) | PanOSRmtUserIP | principal.ip | ||
| ID utente remoto (remote_user_id) | PanOSRmtUserID | remote_user_id | principal.user.userid | |
| UUID della regola di sicurezza (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| ID PCAP (pcap_id) | PanOSPcapID | pcap_id | additional.fields.key e additional.fields.value.string_value | |
| Nome gruppo di utenti dinamico (dynusergroup_name) | PanDynamicUsrgrp | principal.group.group_display_name | ||
| Elenco dinamico esterno di origine (src_edl) | PanOSSourceEDL | src_edl | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Elenco dinamico esterno di destinazione (dst_edl) | PanOSDestinationEDL | dst_edl | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Timestamp ad alta risoluzione (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value | ||
| Un elemento di differenziazione della sezione (nssai_sd) | nssai_sd | additional.fields.key e additional.fields.value.string_value | ||
| Un tipo di servizio di sezione (nssai_sd) | nssai_sd1 | additional.fields.key e additional.fields.value.string_value | ||
| ID sessione PDU (pdu_session_id) | pdu_session_id | additional.fields.key e additional.fields.value.string_value | ||
| Sottocategoria dell'applicazione (subcategory_of_app) | subcategory_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Categoria applicazione (category_of_app) | category_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia dell'applicazione (technology_of_app) | technology_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Rischio applicazione (risk_of_app) | risk_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Caratteristica dell'applicazione (characteristic_of_app) | characteristic_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Container dell'applicazione (container_of_app) | container_of_app | additional.fields.key e additional.fields.value.string_value | ||
| SaaS dell'applicazione (is_saas_of_app) | is_saas_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Applicazione sottoposta a tunneling (tunneled_app) | additional.fields.key e additional.fields.value.string_value | |||
| Scaricato (offloaded) | additional.fields.key e additional.fields.value.string_value | |||
| Tipo di flusso (flow_type) | additional.fields.key e additional.fields.value.string_value | |||
| Nome cluster (cluster_name) |
principal.resource.name |
|||
| Stato sanzionato dell'applicazione (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key e additional.fields.value.string_value |
Autenticazione
La tabella seguente elenca i campi di log del tipo di log di autenticazione e i relativi campi UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chiave dell'etichetta Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Ora di ricezione (receive_time o cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" è assente) |
|
| Numero di serie | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (intestazione) | gatto | metadata.product_event_type | |
| Tipo di minaccia/contenuti (sottotipo) | sottotipo (intestazione) | Sottotipo | metadata.product_event_type | |
| Ora di generazione (time_generated o cef-formatted-time_generated) | metadata.event_timestamp | |||
| Sistema virtuale (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| IP di origine (ip) | src | src | principal.ip | |
| Utente (utente) | duser | usrName | target.user.userid | |
| Normalizza utente (normalize_user) | cs2 | NormalizeUser | target.user.user_display_name | |
| Oggetto (oggetto) | fname | ObjectName | oggetto | target.resource.name |
| Policy di autenticazione (authpolicy) | cs4 | AuthPolicy | authpolicy | additional.fields.key e additional.fields.value.string_value |
| Ripeti conteggio (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| ID autenticazione (authid) | cn2 | AuthenticationID | authid | additional.fields.key e additional.fields.value.string_value |
| Fornitore (vendor) | flexString2 | Fornitore | vendor | additional.fields.key e additional.fields.value.string_value |
| Azione di log (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key e additional.fields.value.string_value |
| Profilo server (serverprofile) | cs1 | ServerProfile | serverprofile | additional.fields.key e additional.fields.value.string_value |
| Descrizione (ordine decrescente) | PanOSDesc | AdditionalAuthInfo | security_result.description | |
| Tipo di client (clienttype) | cs5 | ClientType | clienttype | additional.fields.key e additional.fields.value.string_value |
| Tipo di evento (evento) | msg | msg | extensions.auth.auth_details | |
| Numero fattore (factorno) | cn1 | FactorNumber | factorno | additional.fields.key e additional.fields.value.string_value |
| Numero di sequenza (seqno) | externalId | sequenza | metadata.product_log_id | |
| Flag azioni (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Gerarchia del gruppo di dispositivi (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome sistema virtuale (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nome dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| ID sistema virtuale (vsys_id) | intermediary.resource.product_object_id | |||
| Authentication Protocol (authproto) | authproto | additional.fields.key e additional.fields.value.string_value | ||
| UUID per la regola (rule_uuid) | PanOSRuleUUID/RuleUUID | security_result.rule_id | ||
| Timestamp ad alta risoluzione (high_res _timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value | ||
| Categoria del dispositivo di origine (src_category) | PanOSSourceDeviceCategory | src_category | principal.asset.category | |
| Profilo del dispositivo di origine (src_profile) | PanOSSourceDeviceProfile | src_profile | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modello del dispositivo di origine (src_model) | PanOSSourceDeviceModel | src_model | principal.asset.hardware.model | |
| Fornitore del dispositivo di origine (src_vendor) | PanOSSourceDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Famiglia di sistemi operativi del dispositivo di origine (src_osfamily) | PanOSSourceDeviceOSFamily | principal.asset.platform_software.platform principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Versione del sistema operativo del dispositivo di origine (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | ||
| Nome host di origine (src_host) | PanOSSourceHostname | principal.hostname | ||
| Indirizzo MAC di origine (src_mac) | PanOSSourceMac | principal.asset.mac | ||
| Regione (regione) | PanOSTrafficOriginRegion | principal.location.country_or_region | ||
| User agent (user_agent) | PanOSHTTPUserAgent | network.http.user_agent | ||
| ID sessione(sessionid) | PanOSTrafficSessionID | network.session_id | ||
| Gravità (severity) | number-of-severity(header) | security_result.severity e security_result.severity_details | ||
| Nome cluster (cluster_name) | principal.resource.name |
URL
La seguente tabella elenca i campi di log del tipo di log URL e i relativi campi UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chiave dell'etichetta Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Ora di ricezione (cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" è assente) |
|
| N. di serie (seriale) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (intestazione) | gatto | metadata.product_event_type | |
| Tipo di minaccia/contenuti (sottotipo) | sottotipo (intestazione) | Sottotipo | metadata.product_event_type | |
| Genera orario | metadata.event_timestamp | |||
| Indirizzo di origine (src) | src | src | principal.ip | |
| Indirizzo di destinazione (dst) | dst | dst | target.ip | |
| IP di origine NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP di destinazione NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Rule (regola) | cs1 | RuleName | security_result.rule_name | |
| Utente di origine (srcuser) | suser | SourceUser | principal.user.userid | |
| Utente di destinazione (dstuser) | duser | DestinationUser | target.user.userid | |
| Applicazione (app) | app | Applicazione | network.application_protocol | |
| Sistema virtuale (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona di origine (da) | cs4 | SourceZone | da | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Zona di destinazione (a) | cs5 | DestinationZone | a | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Interfaccia in entrata (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Interfaccia in uscita (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Azione di log (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key e additional.fields.value.string_value |
| Tempo registrato | time_logged | additional.fields.key e additional.fields.value.string_value | ||
| ID sessione (sessionid) | cn1 | SessionID | network.session_id | |
| Ripeti conteggio (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Porta di origine (sport) | spt | srcPort | principal.port | |
| Porta di destinazione (dport) | dpt | dstPort | target.port | |
| Porta di origine NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Porta di destinazione NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Flag (flags) | flexString1 | Bandiere | flags | additional.fields.key e additional.fields.value.string_value |
| Protocollo IP (proto) | proto | proto | network.ip_protocol | |
| Azione (azione) | atto | azione | security_result.action_details
security_result.action |
|
| URL/Nome file (varie) | Vari | target.file.names
target.url |
||
| Nome minaccia/contenuto (threatid) | gatto | ThreatID | security_result.threat_id | |
| Categoria (categoria) | cs2 | URLCategory | categoria | security_result.category_details |
| Gravità (severity) | number-of-severity (intestazione) | Gravità | security_result.severity
security_result.severity_details |
|
| Direzione (direction) | flexString2 | Direzione | network.direction | |
| Numero di sequenza (seqno) | externalId | sequenza | metadata.product_log_id | |
| Flag azioni (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Paese di origine (srcloc) | SourceLocation | principal.location.country_or_region | ||
| Paese di destinazione (dstloc) | DestinationLocation | target.location.country_or_region | ||
| contenttype (contenttype) | requestContext | ContentType | contenttype | additional.fields.key e additional.fields.value.string_value |
| pcap_id (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key e additional.fields.value.string_value |
| filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | ||
| cloud (cloud) | Cloud | cloud | additional.fields.key e additional.fields.value.string_value | |
| url_idx (url_idx) | URLIndex | url_idx | additional.fields.key e additional.fields.value.string_value | |
| user_agent (user_agent) | requestClientApplication | UserAgent | network.http.user_agent | |
| filetype (filetype) | target.file.mime_type | |||
| xff (xff) | PanOSXForwarderfor | identSrc | xff | principal.ip |
| referrer (referer) | PanOSReferer | Referer | network.http.referral_url | |
| mittente (sender) | network.email.from | |||
| subject (subject) | Oggetto | network.email.subject | ||
| destinatario (destinatario) | network.email.to | |||
| reportid (reportid) | reportid | additional.fields.key e additional.fields.value.string_value | ||
| Livello 1 della gerarchia DG (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Livello 2 della gerarchia DG (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Livello 3 della gerarchia DG (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Livello 4 della gerarchia DG (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome sistema virtuale (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nome dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| file_url (file_url) | target.url | |||
| UUID VM di origine (src_uuid) | SrcUUID | principal.asset.product_object_id | ||
| UUID VM di destinazione (dst_uuid) | DstUUID | target.asset.product_object_id | ||
| http_method (http_method) | requestMethod | RequestMethod | network.http.method | |
| ID tunnel/IMSI (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key e additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key e additional.fields.value.string_value |
| ID sessione principale (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Ora di inizio della sessione principale (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key e additional.fields.value.string_value |
| Tunnel (tunnel) | PanOSTunnelType | TunnelType | tunnel | additional.fields.key e additional.fields.value.string_value |
| thr_category (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| contentver (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key e additional.fields.value.string_value |
| sig_flags (sig_flags) | sig_flags | additional.fields.key e additional.fields.value.string_value | ||
| ID associazione SCTP (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key e additional.fields.value.string_value | |
| ID protocollo payload (ppid) | PanOSPPID | ppid | additional.fields.key e additional.fields.value.string_value | |
| http_headers (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Elenco categorie di URL (url_category_list) | PanOSURLCatList | url_category_list | additional.fields.key e additional.fields.value.string_value | |
| UUID per la regola (rule_uuid) | PanOSRuleUUID | rule_uuid | security_result.rule_id | |
| Connessione HTTP/2 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| dynusergroup_name (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | additional.fields.key e additional.fields.value.string_value | |
| Indirizzo XFF (xff_ip) | PanXFFIP | principal.ip | ||
| Categoria dispositivo di origine (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Profilo del dispositivo di origine (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modello del dispositivo di origine (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Fornitore del dispositivo di origine (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Famiglia di sistemi operativi del dispositivo di origine (src_osfamily) | PanSrcDeviceOS | principal.platform | ||
| Versione del sistema operativo del dispositivo di origine (src_osversion) | PanSrcDeviceOSv | principal.platform_version | ||
| Nome host di origine (src_host) | PanSrcHostname | src_host | principal.hostname | |
| Indirizzo MAC di origine (src_mac) | PanSrcMac | principal.mac | ||
| Categoria dispositivo di destinazione (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Profilo del dispositivo di destinazione (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modello del dispositivo di destinazione (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Fornitore del dispositivo di destinazione (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Famiglia di sistemi operativi del dispositivo di destinazione (dst_osfamily) | PanDstDeviceOS | target.platform | ||
| Versione del sistema operativo del dispositivo di destinazione (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Nome host di destinazione (dst_host) | PanPODNamespace | target.hostname | ||
| Indirizzo MAC di destinazione (dst_mac) | PanDstMac | target.mac | ||
| ID contenitore (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| Spazio dei nomi POD (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| Nome POD (pod_name) | PanPODName | pod_name | target.resource.name | |
| Elenco dinamico esterno di origine (src_edl) | PanSrcEDL | src_edl | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Elenco dinamico esterno di destinazione (dst_edl) | PanDstEDL | dst_edl | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| ID host (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Numero di serie (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| domain_edl (domain_edl) | PanDomainEDL | domain_edl | additional.fields.key e additional.fields.value.string_value | |
| Gruppo di indirizzi dinamici di origine (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Gruppo di indirizzi dinamici di destinazione (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| partial_hash (partial_hash) | PanPartialHash | partial_hash | additional.fields.key e additional.fields.value.string_value | |
| Timestamp ad alta risoluzione (high_res_timestamp) | PanTimeHighRes | additional.fields.key e additional.fields.value.string_value | ||
| Motivo (motivo) | PanReasonFilteringAction | motivo | security_result.summary | |
| motivazione (giustificazione) | PanJustification | giustificazione | additional.fields.key e additional.fields.value.string_value | |
| nssai_sst (nssai_sst) | PanASServiceType | nssai_sst | additional.fields.key e additional.fields.value.string_value | |
| Sottocategoria dell'app (subcategory_of_app) | subcategory_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Categoria di app (category_of_app) | category_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia dell'app (technology_of_app) | technology_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Rischio app (risk_of_app) | risk_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Caratteristica dell'app (characteristic_of_app) | characteristic_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Container dell'app (container_of_app) | container_of_app | additional.fields.key e additional.fields.value.string_value | ||
| App con tunnel (tunneled_app) | tunneled_app | additional.fields.key e additional.fields.value.string_value | ||
| SaaS dell'app (is_saas_of_app) | is_saas_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Stato sanzionato dell'app (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key e additional.fields.value.string_value | ||
| ID report cloud (cloud_reportid) | additional.fields.key e additional.fields.value.string_value | |||
| Nome cluster (cluster_name) |
principal.resource.name |
|||
| Tipo di flusso (flow_type) | additional.fields.key e additional.fields.value.string_value |
Dati
La tabella seguente elenca i campi di log del tipo di log dei dati e i campi UDM corrispondenti.
| Campo CSV | Campo CEF | Campo LEEF | Chiave dell'etichetta Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Ora di ricezione (cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" è assente) |
|
| N. di serie (seriale) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (intestazione) | gatto | metadata.product_event_type | |
| Tipo di minaccia/contenuti (sottotipo) | sottotipo (intestazione) | Sottotipo | metadata.product_event_type | |
| Genera orario | metadata.event_timestamp | |||
| Indirizzo di origine (src) | src | src | principal.ip | |
| Indirizzo di destinazione (dst) | dst | dst | target.ip | |
| IP di origine NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP di destinazione NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Rule (regola) | cs1 | RuleName | security_result.rule_name | |
| Utente di origine (srcuser) | suser | SourceUser | principal.user.userid | |
| Utente di destinazione (dstuser) | duser | DestinationUser | target.user.userid | |
| Applicazione (app) | app | Applicazione | network.application_protocol | |
| Sistema virtuale (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona di origine (da) | cs4 | SourceZone | da | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Zona di destinazione (a) | cs5 | DestinationZone | a | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Interfaccia in entrata (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Interfaccia in uscita (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Azione di log (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key e additional.fields.value.string_value |
| Tempo registrato | time_logged | additional.fields.key e additional.fields.value.string_value | ||
| ID sessione (sessionid) | cn1 | SessionID | network.session_id | |
| Ripeti conteggio (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Porta di origine (sport) | spt | srcPort | principal.port | |
| Porta di destinazione (dport) | dpt | dstPort | target.port | |
| Porta di origine NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Porta di destinazione NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Flag (flags) | flexString1 | Bandiere | flags | additional.fields.key e additional.fields.value.string_value |
| Protocollo IP (proto) | proto | proto | network.ip_protocol | |
| Azione (azione) | atto | azione | security_result.action_details
security_result.action |
|
| URL/Nome file (varie) | Vari | target.file.names
target.url |
||
| Nome minaccia/contenuto (threatid) | gatto | ThreatID | security_result.threat_id | |
| Categoria (categoria) | cs2 | URLCategory | categoria | security_result.category_details |
| Gravità (severity) | number-of-severity (intestazione) | Gravità | security_result.severity
security_result.severity_details |
|
| Direzione (direction) | flexString2 | Direzione | network.direction | |
| Numero di sequenza (seqno) | externalId | sequenza | metadata.product_log_id | |
| Flag azioni (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Paese di origine (srcloc) | SourceLocation | principal.location.country_or_region | ||
| Paese di destinazione (dstloc) | DestinationLocation | target.location.country_or_region | ||
| contenttype (contenttype) | ContentType | contenttype | additional.fields.key e additional.fields.value.string_value | |
| pcap_id (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key e additional.fields.value.string_value |
| filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | ||
| cloud (cloud) | Cloud | cloud | additional.fields.key e additional.fields.value.string_value | |
| url_idx (url_idx) | URLIndex | url_idx | additional.fields.key e additional.fields.value.string_value | |
| user_agent (user_agent) | network.http.user_agent | |||
| filetype (filetype) | target.file.mime_type | |||
| xff (xff) | xff | principal.ip | ||
| referer (referer) | network.http.referral_url | |||
| mittente (sender) | network.email.from | |||
| subject (subject) | Oggetto | network.email.subject | ||
| destinatario (destinatario) | network.email.to | |||
| reportid (reportid) | reportid | additional.fields.key e additional.fields.value.string_value | ||
| Livello 1 della gerarchia DG (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Livello 2 della gerarchia DG (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Livello 3 della gerarchia DG (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Livello 4 della gerarchia DG (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome sistema virtuale (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nome dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| file_url (file_url) | target.url | |||
| UUID VM di origine (src_uuid) | SrcUUID | principal.asset.product_object_id | ||
| UUID VM di destinazione (dst_uuid) | DstUUID | target.asset.product_object_id | ||
| http_method (http_method) | RequestMethod | network.http.method | ||
| ID tunnel/IMSI (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key e additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key e additional.fields.value.string_value |
| ID sessione principale (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Ora di inizio della sessione principale (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key e additional.fields.value.string_value |
| Tunnel (tunnel) | PanOSTunnelType | TunnelType | tunnel | additional.fields.key e additional.fields.value.string_value |
| thr_category (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| contentver (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key e additional.fields.value.string_value |
| sig_flags (sig_flags) | sig_flags | additional.fields.key e additional.fields.value.string_value | ||
| ID associazione SCTP (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key e additional.fields.value.string_value | |
| ID protocollo payload (ppid) | PanOSPPID | ppid | additional.fields.key e additional.fields.value.string_value | |
| http_headers (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Elenco categorie di URL (url_category_list) | url_category_list | additional.fields.key e additional.fields.value.string_value | ||
| UUID per la regola (rule_uuid) | PanOSRuleUUID | rule_uuid | security_result.rule_id | |
| Connessione HTTP/2 (http2_connection) | http2_connection | network.application_protocol_version | ||
| dynusergroup_name (dynusergroup_name) | dynusergroup_name | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Indirizzo XFF (xff_ip) | principal.ip | |||
| Categoria dispositivo di origine (src_category) | src_category | principal.asset.category | ||
| Profilo del dispositivo di origine (src_profile) | src_profile | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Modello del dispositivo di origine (src_model) | src_model | principal.asset.hardware.model | ||
| Fornitore del dispositivo di origine (src_vendor) | src_vendor | principal.asset.hardware.manufacturer | ||
| Famiglia di sistemi operativi del dispositivo di origine (src_osfamily) | principal.platform | |||
| Versione del sistema operativo del dispositivo di origine (src_osversion) | principal.platform_version | |||
| Nome host di origine (src_host) | src_host | principal.hostname | ||
| Indirizzo MAC di origine (src_mac) | principal.mac | |||
| Categoria dispositivo di destinazione (dst_category) | dst_category | target.asset.category | ||
| Profilo del dispositivo di destinazione (dst_profile) | dst_profile | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Modello del dispositivo di destinazione (dst_model) | dst_model | target.asset.hardware.model | ||
| Fornitore del dispositivo di destinazione (dst_vendor) | dst_vendor | target.asset.hardware.manufacturer | ||
| Famiglia di sistemi operativi del dispositivo di destinazione (dst_osfamily) | target.platform | |||
| Versione del sistema operativo del dispositivo di destinazione (dst_osversion) | target.platform_version | |||
| Nome host di destinazione (dst_host) | target.hostname | |||
| Indirizzo MAC di destinazione (dst_mac) | target.mac | |||
| ID contenitore (container_id) | container_id | intermediary.resource.product_object_id | ||
| Spazio dei nomi POD (pod_namespace) | pod_namespace | target.resource.attribute.labels.key/value | ||
| Nome POD (pod_name) | pod_name | target.resource.name | ||
| Elenco dinamico esterno di origine (src_edl) | src_edl | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Elenco dinamico esterno di destinazione (dst_edl) | dst_edl | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
||
| ID host (hostid) | hostid | principal.asset.asset_id | ||
| Numero di serie (serialnumber) | principal.asset.hardware.serial_number | |||
| domain_edl (domain_edl) | domain_edl | additional.fields.key e additional.fields.value.string_value | ||
| Gruppo di indirizzi dinamici di origine (src_dag) | principal.group.group_display_name | |||
| Gruppo di indirizzi dinamici di destinazione (dst_dag) | target.group.group_display_name | |||
| partial_hash (partial_hash) | partial_hash | additional.fields.key e additional.fields.value.string_value | ||
| Timestamp ad alta risoluzione (high_res_timestamp) | additional.fields.key e additional.fields.value.string_value | |||
| Motivo (motivo) | motivo | security_result.summary | ||
| motivazione (giustificazione) | giustificazione | additional.fields.key e additional.fields.value.string_value | ||
| nssai_sst (nssai_sst) | nssai_sst | additional.fields.key e additional.fields.value.string_value | ||
| Sottocategoria dell'app (subcategory_of_app) | subcategory_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Categoria di app (category_of_app) | category_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia dell'app (technology_of_app) | technology_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Rischio app (risk_of_app) | risk_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Caratteristica dell'app (characteristic_of_app) | characteristic_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Container dell'app (container_of_app) | container_of_app | additional.fields.key e additional.fields.value.string_value | ||
| App con tunnel (tunneled_app) | tunneled_app | additional.fields.key e additional.fields.value.string_value | ||
| SaaS dell'app (is_saas_of_app) | is_saas_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Stato sanzionato dell'app (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key e additional.fields.value.string_value | ||
| ID report cloud (cloud_reportid) | additional.fields.key e additional.fields.value.string_value | |||
| Nome cluster (cluster_name) | principal.resource.name | |||
| Tipo di flusso (flow_type) | additional.fields.key e additional.fields.value.string_value |
GlobalProtect
La tabella seguente elenca i campi di log del tipo di log GlobalProtect e i relativi campi UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chiave dell'etichetta Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Ora di ricezione (receive_time) | rt | received_time | metadata.event_timestamp | |
| N. di serie (seriale) | PanOSDeviceSN | intermediary_asset_hardware_serial_number | intermediary.asset.hardware.serial_number | |
| Tipo (type) | type (intestazione) | metadata.product_event_type | ||
| Tipo di minaccia/contenuti (sottotipo) | sottotipo (intestazione) | Sottotipo | metadata.product_event_type | |
| Generate Time (time_generated) | PanOSLogTimeStamp | generated_timestamp | metadata.event_timestamp | |
| Sistema virtuale (vsys) | PanOSVirtualSystem | vsys | intermediary.asset.attribute.labels.key/value | |
| ID evento (eventid) | PanOSEventID | event_id | additional.fields.key e additional.fields.value.string_value | |
| Stage (stage) | PanOSStage | fase | additional.fields.key e additional.fields.value.string_value | |
| Metodo di autenticazione (auth_method) | PanOSAuthMethod | extension_auth_auth_details | extensions.auth.auth_details | |
| Tipo di tunnel (tunnel_type) | PanOSTunnelType | tunnel | additional.fields.key e additional.fields.value.string_value | |
| Utente di origine (srcuser) | PanOSSourceUserName | src_user | principal.user.email_address
principal.user.userid principal.administrative_domain |
|
| Regione di origine (srcregion) | PanOSSourceRegion | src_region | principal.location.country_or_region | |
| Nome macchina (machinename) | PanOSEndpointDeviceName | machine_name | principal.hostname | |
| IP pubblico (public_ip) | PanOSPublicIPv4 | principal.nat_ip | ||
| IPv6 pubblico (public_ipv6) | PanOSPublicIPv6 | principal.nat_ip | ||
| IP privato (private_ip) | PanOSPrivateIPv4 | principal.ip | ||
| IPv6 privato (private_ipv6) | PanOSPrivateIPv6 | principal.ip | ||
| ID host (hostid) | PanOSHostID | hostid | principal.asset.asset_id | |
| Numero di serie (serialnumber) | PanOSDeviceSN | principal.asset.hardware.serial_number | ||
| Versione client (client_ver) | PanOSGlobalProtectClientVersion | client_ver | additional.fields.key e additional.fields.value.string_value | |
| Sistema operativo client (client_os) | PanOSEndpointOSType | principal.platform | ||
| Versione del sistema operativo client (client_os_ver) | PanOSEndpointOSVersion | principal.platform_version | ||
| Ripeti conteggio (repeatcnt) | PanOSCountOfRepeats | repeatcnt | additional.fields.key e additional.fields.value.string_value | |
| Motivo (motivo) | PanOSQuarantineReason | security_result.summary | ||
| Errore (errore) | PanOSConnectionError | errore | security_result.description | |
| Descrizione (opaca) | PanOSDescription | security_result.description | ||
| Stato (stato) | PanOSEventStatus | stato | additional.fields.key e additional.fields.value.string_value | |
| Località (posizione) | PanOSGPGatewayLocation | target.location.country_or_region | ||
| Durata dell'accesso (login_duration) | PanOSLoginDuration | network.session_duration | ||
| Metodo di connessione (connect_method) | PanOSConnectionMethod | connect_method | additional.fields.key e additional.fields.value.string_value | |
| Codice di errore (error_code) | PanOSConnectionErrorID | error_code | additional.fields.key e additional.fields.value.string_value | |
| Portale (portale) | PanOSPortal | portale | additional.fields.key e additional.fields.value.string_value | |
| Numero di sequenza (seqno) | PanOSSequenceNo | metadata.product_log_id | ||
| Flag azioni (actionflags) | PanOSActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value | |
| Timestamp ad alta risoluzione (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value | ||
| Metodo di selezione del gateway (selection_type) | PanOSGatewaySelectionType | selection_type | additional.fields.key e additional.fields.value.string_value | |
| Tempo di risposta SSL (response_time) | PanOSSSLResponseTime | response_time | additional.fields.key e additional.fields.value.string_value | |
| Priorità gateway (priorità) | PanOSGatewayPriority | priorità | additional.fields.key e additional.fields.value.string_value | |
| Tentativi di gateway (attempted_gateways) | PanOSAttemptedGateways | attempted_gateways | additional.fields.key e additional.fields.value.string_value | |
| Nome gateway (gateway) | PanOSAttemptedGateways | gateway | target.resource.name | |
| Gerarchia del gruppo di dispositivi (dg_hier_level_1) | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value | ||
| Gerarchia del gruppo di dispositivi (dg_hier_level_2) | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value | ||
| Gerarchia del gruppo di dispositivi (dg_hier_level_3) | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value | ||
| Gerarchia del gruppo di dispositivi (dg_hier_level_4) | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value | ||
| Nome sistema virtuale (vsys_name) | intermediary.asset.attribute.labels.key/value | |||
| Nome dispositivo (device_name) | intermediary.hostname | |||
| ID sistema virtuale (vsys_id) | intermediary.resource.product_object_id | |||
| Gravità (severity) | number-of-severity(header) | security_result.severity e security_result.severity_details | ||
| Nome cluster (cluster_name) | principal.resource.name |
Correlazione
La tabella seguente elenca i campi di log del tipo di log di correlazione e i campi UDM corrispondenti.
| Campo CSV | Campo CEF | Campo LEEF | Chiave dell'etichetta Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Ora di generazione (time_generated o cef-formatted-time_generated) | startTime | generated_timestamp | metadata.event_timestamp | |
| Indirizzo di origine (src) | src | principal.ip | ||
| Utente di origine (srcuser) | SourceUser / usrName | principal.user.userid | ||
| Sistema virtuale (vsys) | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value | |
| Categoria (categoria) | security_result.category_details | |||
| Gravità (severity) | Gravità | security_result.severity e security_result.severity_details | ||
| Livello 1 della gerarchia del gruppo di dispositivi | DeviceGroupHierarchyL1 | additional.fields.key e additional.fields.value.string_value | ||
| Livello 2 della gerarchia del gruppo di dispositivi | DeviceGroupHierarchyL2 | additional.fields.key e additional.fields.value.string_value | ||
| Livello 3 della gerarchia del gruppo di dispositivi | DeviceGroupHierarchyL3 | additional.fields.key e additional.fields.value.string_value | ||
| Livello 4 della gerarchia dei gruppi di dispositivi | DeviceGroupHierarchyL4 | additional.fields.key e additional.fields.value.string_value | ||
| Nome sistema virtuale (vsys_name) | vSrcName | intermediary.asset.attribute.labels.key/value | ||
| Nome dispositivo (device_name) | DeviceName | intermediary.hostname | ||
| ID sistema virtuale (vsys_id) | VirtualSystemID | intermediary.resource.product_object_id | ||
| Nome oggetto (objectname) | ObjectName | target.resource.name | ||
| ID oggetto (object_id) | ObjectID | target.resource.product_object_id | ||
| Prove (evidence) | msg | security_result.summary |
GTP
La tabella seguente elenca i campi di log del tipo di log gtp e i relativi campi UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chiave dell'etichetta Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Ora di ricezione (receive_time o cef-formatted-receive_time) | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" è assente) |
|||
| Numero di serie (seriale) | intermediary.asset.hardware.serial_number | |||
| Tipo (type) | metadata.product_event_type | |||
| Tipo di minaccia/contenuti (sottotipo) | metadata.product_event_type | |||
| Ora di generazione (time_generated o cef-formatted-time_generated) | metadata.event_timestamp | |||
| Indirizzo di origine (src) | principal.ip | |||
| Indirizzo di destinazione (dst) | target.ip | |||
| Nome regola (regola) | security_result.rule_name | |||
| Applicazione (app) | network.application_protocol | |||
| Sistema virtuale (vsys) | vsys | intermediary.asset.attribute.labels.key/value | ||
| Zona di origine (da) | da | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Zona di destinazione (a) | a | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Interfaccia in entrata (inbound_if) | inbound_if | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Interfaccia in uscita (outbound_if) | outbound_if | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Azione di log (logset) | logset | additional.fields.key e additional.fields.value.string_value | ||
| ID sessione (sessionid) | network.session_id | |||
| Porta di origine (sport) | principal.port | |||
| Porta di destinazione (dport) | target.port | |||
| Protocollo IP (proto) | network.ip_protocol | |||
| Azione (azione) | security_result.action_details
security_result.action |
|||
| Tipo di evento GTP (event_type) | gtp_event_type | additional.fields.key e additional.fields.value.string_value | ||
| MSISDN (msisdn) | msisdn | additional.fields.key e additional.fields.value.string_value | ||
| Nome punto di accesso (APN) | apn | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia di accesso radio (RAT) | topo | additional.fields.key e additional.fields.value.string_value | ||
| Tipo di messaggio GTP (msg_type) | gtp_msg_type | additional.fields.key e additional.fields.value.string_value | ||
| Indirizzo IP finale (end_ip_adr) | principal.ip | |||
| Tunnel Endpoint Identifier1 (teid1) | teid1 | additional.fields.key e additional.fields.value.string_value | ||
| Identificatore endpoint tunnel 2 (teid2) | teid2 | additional.fields.key e additional.fields.value.string_value | ||
| Interfaccia GTP (gtp_interface) | gtp_interface | additional.fields.key e additional.fields.value.string_value | ||
| Causa GTP (cause_code) | gtp_cause_code | additional.fields.key e additional.fields.value.string_value | ||
| Gravità (severity) | security_result.severity e security_result.severity_details | |||
| Codice MCC di rete (mcc) | mcc | additional.fields.key e additional.fields.value.string_value | ||
| Serving Network MNC (mnc) | mnc | additional.fields.key e additional.fields.value.string_value | ||
| Prefisso (area_code) | area_code | additional.fields.key e additional.fields.value.string_value | ||
| ID cella (cell_id) | cell_id | additional.fields.key e additional.fields.value.string_value | ||
| Codice evento GTP (event_code) | event_code | additional.fields.key e additional.fields.value.string_value | ||
| Posizione di origine (srcloc) | principal.location.country_or_region | |||
| Località di destinazione (dstloc) | target.location.country_or_region | |||
| ID tunnel/IMSI (imsi) | tunnelid | additional.fields.key e additional.fields.value.string_value | ||
| Monitor Tag/IMEI (imei) | monitortag | additional.fields.key e additional.fields.value.string_value | ||
| Ora di inizio (inizio) | start | additional.fields.key e additional.fields.value.string_value | ||
| Tempo trascorso (trascorso) | network.session_duration.seconds | |||
| Tunnel Inspection RuleTunnel (tunnel_insp_rule) | tunnel_insp_rule | security_result.detection_fields.key/value | ||
| IP utente remoto (remote_user_ip) | principal.ip | |||
| ID utente remoto (remote_user_id) | remote_user_id | principal.user.userid | ||
| UUID per la regola (rule_uuid) | security_result.rule_id | |||
| ID PCAP (pcap_id) | pcap_id | additional.fields.key e additional.fields.value.string_value | ||
| Timestamp ad alta risoluzione (high_res_timestamp) | additional.fields.key e additional.fields.value.string_value | |||
| Un tipo di servizio di sezione (nsdsai_sst) | nsdsai_sst | additional.fields.key e additional.fields.value.string_value | ||
| Un elemento di differenziazione della sezione (nsdsai_sd) | nsdsai_sd | additional.fields.key e additional.fields.value.string_value | ||
| Sottocategoria dell'applicazione (subcategory_of_app) | subcategory_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Categoria applicazione (category_of_app) | category_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia dell'applicazione (technology_of_app) | technology_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Rischio applicazione (risk_of_app) | risk_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Caratteristica dell'applicazione (characteristic_of_app) | characteristic_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Container dell'applicazione (container_of_app) | container_of_app | additional.fields.key e additional.fields.value.string_value | ||
| SaaS dell'applicazione (is_saas_of_app) | is_saas_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Stato sanzionato dell'applicazione (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key e additional.fields.value.string_value |
SCTP
| Campo CSV | Campo CEF | Campo LEEF | Chiave dell'etichetta Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Ora di ricezione (receive_time o cef-formatted-receive_time) | receive_time o cef-formatted-receive_time | metadata.collected_timestamp | ||
| Numero di serie | serial | intermediary.asset.hardware.serial_number | ||
| Tipo (type) | tipo | metadata.product_event_type | ||
| Ora di generazione (time_generated o cef-formatted-time_generated) | time_generated o cef-formatted-time_generated | metadata.event_timestamp | ||
| Indirizzo di origine (src) | src | principal.ip | ||
| Indirizzo di destinazione (dst) | dst | target.ip | ||
| Nome regola (regola) | regola | security_result.rule_name | ||
| Zona di origine (da) | da | additional.fields.key e additional.fields.value.string_value | ||
| Zona di destinazione (a) | a | additional.fields.key e additional.fields.value.string_value | ||
| Interfaccia in entrata (inbound_if) | inbound_if | additional.fields.key e additional.fields.value.string_value | ||
| Interfaccia in uscita (outbound_if) | outbound_if | additional.fields.key e additional.fields.value.string_value | ||
| Azione di log (logset) | logset | additional.fields.key e additional.fields.value.string_value | ||
| ID sessione (sessionid) | sessionid | network.session_id | ||
| Ripeti conteggio (repeatcnt) | repeatcnt | additional.fields.key e additional.fields.value.string_value | ||
| Porta di origine (sport) | sport | principal.port | ||
| Porta di destinazione (dport) | dport | target.port | ||
| Protocollo IP (proto) | proto | network.ip_protocol (enum) | ||
| Azione (azione) | azione | security_result.action_details security_result.action |
||
| Gerarchia dei gruppi di dispositivi (dg_hier_level_1 a dg_hier_level_4) | dg_hier_level_1 to dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value | ||
| Nome dispositivo (device_name) | device_name | intermediary.hostname | ||
| Numero di sequenza (seqno) | seqno | metadata.product_log_id | ||
| ID associazione SCTP (assoc_id) | assoc_id | additional.fields.key e additional.fields.value.string_value | ||
| ID protocollo payload (ppid) | ppid | additional.fields.key e additional.fields.value.string_value | ||
| Gravità (severity) | gravità | security_result.severity e security_result.severity_details | ||
| Tipo di chunk SCTP (sctp_chunk_type) | sctp_chunk_type | additional.fields.key e additional.fields.value.string_value | ||
| Tipo di evento SCTP (sctp_event_type) | sctp_event_type | additional.fields.key e additional.fields.value.string_value | ||
| Tag di verifica SCTP 1 (verif_tag_1) | verif_tag_1 | additional.fields.key e additional.fields.value.string_value | ||
| Tag di verifica SCTP 2 (verif_tag_2) | verif_tag_2 | additional.fields.key e additional.fields.value.string_value | ||
| Codice di causa SCTP (sctp_cause_code) | sctp_cause_code | additional.fields.key e additional.fields.value.string_value | ||
| ID app diametro (diam_app_id) | diam_app_id | additional.fields.key e additional.fields.value.string_value | ||
| Codice comando diametro (diam_cmd_code) | diam_cmd_code | additional.fields.key e additional.fields.value.string_value | ||
| Diameter AVP Code (diam_avp_code) | diam_avp_code | additional.fields.key e additional.fields.value.string_value | ||
| ID stream SCTP (stream_id) | stream_id | additional.fields.key e additional.fields.value.string_value | ||
| Motivo di fine dell'associazione SCTP (assoc_end_reason) | assoc_end_reason | additional.fields.key e additional.fields.value.string_value | ||
| Codice operativo (op_code) | op_code | additional.fields.key e additional.fields.value.string_value | ||
| SCCP Calling Party SSN (sccp_calling_ssn) | sccp_calling_ssn | additional.fields.key e additional.fields.value.string_value | ||
| SCCP Calling Party Global Title (sccp_calling_gt) | sccp_calling_gt | additional.fields.key e additional.fields.value.string_value | ||
| Filtro SCTP (sctp_filter) | sctp_filter | additional.fields.key e additional.fields.value.string_value | ||
| Segmenti SCTP (chunk) | pezzi | additional.fields.key e additional.fields.value.string_value | ||
| Segmenti SCTP inviati (chunks_sent) | chunks_sent | additional.fields.key e additional.fields.value.string_value | ||
| Chunk SCTP ricevuti (chunks_received) | chunks_received | additional.fields.key e additional.fields.value.string_value | ||
| Pacchetti (pacchetti) | pacchetti | additional.fields.key e additional.fields.value.string_value | ||
| UUID per la regola (rule_uuid) | rule_uuid | security_result.rule_id | ||
| Sistema virtuale (vsys) | vsys | intermediary.asset.attribute.labels.key/value | ||
| Nome sistema virtuale (vsys_name) | vsys_name | intermediary.asset.attribute.labels.key/value | ||
| Pacchetti inviati (pkts_sent) | pkts_sent | network.sent_packets | ||
| Pacchetti ricevuti (pkts_received) | pkts_received | network.received_packets |
Controlla
| Campo CSV | Campo CEF | Campo LEEF | Chiave dell'etichetta Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Genera orario | metadata.event_timestamp | |||
| Tipo di minaccia/contenuti (sottotipo) | metadata.product_event_type | |||
| ID evento | principal.application | |||
| Oggetto | principal.user.userid | |||
| Comando CLI | principal.process.command_line | |||
| Gravità | security_result.severity | |||
| Numero di serie | intermediary.asset.hardware.serial_number |
Riferimento per la mappatura dei campi: tipi di log e tipo di evento UDM
La tabella seguente elenca i tipi di log del firewall Palo Alto Networks e i relativi tipi di eventi UDM.
| Tipo di log | Tipo di evento UDM |
| Traffico | NETWORK_CONNECTION |
| Minaccia | NETWORK_CONNECTION |
| Filtro degli URL | NETWORK_CONNECTION |
| WildFire | NETWORK_CONNECTION
I log di invio di WildFire sono un sottotipo del tipo di log delle minacce e utilizzano lo stesso formato syslog. |
| Filtro dei dati | NETWORK_CONNECTION |
| Tunnel | NETWORK_CONNECTION |
| GTP | NETWORK_CONNECTION |
| Configurazione | SETTING_MODIFICATION/SETTING_CREATION/SETTING_DELETION/SETTING_UNCATEGORIZED
Il valore del campo "Command (cmd)" determina la mappatura del tipo di evento UDM. Se il valore del campo cmd è add o clone, viene impostato SETTING_CREATION. Se il valore del campo cmd è delete, viene impostato SETTING_DELETION. Se il valore del campo cmd è edit, move, rename, set o commit, SETTING_MODIFICATION è impostato. Se il valore del campo cmd non contiene valori, viene impostato SETTING_UNCATEGORIZED. |
| Sistema |
Se il valore del sottotipo è "dhcp", viene impostato NETWORK_DHCP. Se il valore del sottotipo è "auth", viene impostato USER_LOGIN. Se il valore della descrizione è "logged in", viene impostato USER_LOGIN. Se il valore della descrizione è "logged out", viene impostato USER_LOGOUT. Per gli altri valori del sottotipo, viene impostato GENERIC_EVENT. |
| HIP Match | NETWORK_CONNECTION |
| Tag IP | GENERIC_EVENT |
| User-ID | USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED
Se il valore del sottotipo è "login", viene impostato USER_LOGIN. Se il valore del sottotipo è "logout", viene impostato USER_LOGOUT. Se il sottotipo non contiene alcun valore, viene impostato USER_UNCATEGORIZED. |
| Decriptazione | NETWORK_CONNECTION |
| Autenticazione | GENERIC_EVENT |
| SCTP | NETWORK_CONNECTION |
| Controlla | GENERIC_EVENT |
Delta di mappatura UDM
Riferimento delta mappatura UDM: firewall Palo Alto Networks
La tabella seguente elenca la differenza tra la vecchia mappatura UDM di Palo Alto Networks Firewall e la nuova mappatura UDM di Palo Alto Networks Firewall.
UDM Event Type Delta
| Log type | Old UDM Event Type | New UDM Event Type |
| WildFire | NETWORK_CONNECTION | SCAN_UNCATEGORIZED |
| Data Filtering | NETWORK_CONNECTION | NETWORK_UNCATEGORIZED |
| Authentication | STATUS_UPDATE | STATUS_UNCATEGORIZED |
UDM Field Mapping Delta
| Log Type | Old UDM Mapping | CSV Log Field | CEF Log Field | LEEF Log Field | New UDM Mapping |
|---|---|---|---|---|---|
| System | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| System | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| System | about.labels.key/value additional.fields.key/value.string_value | Object (object) | fname | Filename | target.resource.name |
| System | Description (opaque) | msg | msg | metadata.description | |
| System | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| System | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| Config | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| Config | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| Config | principal.process.command_line | Configuration Path (path) | msg | ConfigurationPath | principal.process.command_line |
| Config | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| Config | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| Config | principal.asset.attribute.labels.key/value | Device Group (dg_id) | PanOSFWDeviceGroup | target.asset.attribute.labels | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Threat/Wildfire | target.file.full_path target.url target.hostname | URL/Filename (misc) | request | Miscellaneous | target.file.names target.url |
| Threat/Wildfire | about.file.sha1/md5/sha256 | File Digest (filedigest) | fileHash | FileDigest | target.file.sha1/md5/sha256 |
| Threat/Wildfire | about.file.mime_type | File Type (filetype) | fileType | FileType | target.file.mime_type |
| Threat/Wildfire | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Threat/Wildfire | principal.user.product_object_id | Source VM UUID (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id |
| Threat/Wildfire | target.user.product_object_id | Destination VM UUID (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | HTTP Headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| Threat/Wildfire | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| Threat/Wildfire | principal.asset.software.version | Source Device OS Version (src_osversion) | PanSrcDeviceOSv | principal.platform_version | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| Threat/Wildfire | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| Threat/Wildfire | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | PanReasonFilteringAction | security_result.summary | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Packets Sent (pkts_sent) | PanOSPacketsSent | srcPackets | network.sent_packets |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Packets Received (pkts_received) | PanOSPacketsReceived | dstPackets | network.received_packets |
| Traffic | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| Traffic | principal.asset.platform_software.platform(enum) principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| Traffic | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| Traffic | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| User-ID | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| User-ID | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| User-ID | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | intermediary.resource.product_object_id |
| User-ID | principal.user.userid principal.administrative_domain principal.user.email_addresses | User by Source (userbysource) | PanOSUserBySource | target.user.userid target.user.email_addresses | |
| User-ID | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| HIP Match | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | HIP (matchname) | cat | HIP | target.resource.attribute.labels |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | HIP Type (matchtype) | Device Event Class ID (Header) | HIPType | target.resource.attribute.labels |
| HIP Match | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| HIP Match | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| HIP Match | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id |
| HIP Match | principal.asset.product_object_id | Host ID (hostid) | PanOSHostID | principal.asset.asset_id | |
| HIP Match | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| IP-Tag | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| IP-Tag | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| IP-Tag | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOsVsysName | vSrcName | target.asset.attribute.labels |
| IP-Tag | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| IP-Tag | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id |
| IP-Tag | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Decryption | target.application | Application (app) | app | network.application_protocol | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | intermediary.asset.attribute.labels | |
| Decryption | principal.asset.asset_id | Source VM UUID (src_uuid) | PanOSSourceUUID | principal.asset.product_object_id | |
| Decryption | target.asset.asset_id | Destination VM UUID (dst_uuid) | PanOSDestinationUUID | target.asset.product_object_id | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanOSContainerID | intermediary.resource.product_object_id | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanOSContainerNameSpace | target.resource.attribute.labels additional.fields.key/value.string_value | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanOSContainerName | target.resource.name | |
| Decryption | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanOSSourceDeviceCategory | principal.asset.category | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanOSSourceDeviceModel | principal.asset.hardware.model | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanOSSourceDeviceVendor | principal.asset.hardware.manufacturer | |
| Decryption | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanOSSourceDeviceOSFamily | principal.platform | |
| Decryption | principal.asset.software.version | Source Device OS Version (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanOSDestinationDeviceCategory | target.asset.category | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanOSDestinationDeviceModel | target.asset.hardware.model | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanOSDestinationDeviceVendor | target.asset.hardware.manufacturer | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanOSDestinationDeviceOSFamily | target.platform | |
| Decryption | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanOSDestinationDeviceOSVersion | target.platform_version | |
| Decryption | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | intermediary.asset.attribute.labels | ||
| Decryption | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Tunnel | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Packets Sent (pkts_sent) | PanOSPacketsSent | srcPackets | network.sent_packets |
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Packets Received (pkts_received) | PanOSPacketsReceived | dstPackets | network.received_packets |
| Tunnel | target.ip | Remote User IP (remote_user_ip) | PanOSRmtUserIP | principal.ip | |
| Tunnel | target.labels.key/value additional.fields.key/value.string_value | Remote User ID (remote_user_id) | PanOSRmtUserID | principal.user.userid | |
| Tunnel | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Authentication | target.user.user_display_name | Normalize User (normalize_user) | cs2 | NormalizeUser | target.user.user_display_name |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Object (object) | fname | ObjectName | target.resource.name |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Authentication Policy (authpolicy) | cs4 | AuthPolicy | additional.fields.key/value.string_value |
| Authentication | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Authentication | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| Authentication | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res _timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanOSSourceDeviceCategory | principal.asset.category | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanOSSourceDeviceModel | principal.asset.hardware.model | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanOSSourceDeviceVendor | principal.asset.hardware.manufacturer | |
| Authentication | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanOSSourceDeviceOSFamily | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | |
| Authentication | principal.asset.software.version | Source Device OS Version (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| URL | target.file.full_path target.url | URL/Filename (misc) | Miscellaneous | target.file.names target.url | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Category (category) | cs2 | URLCategory | security_result.category_details |
| URL | about.file.sha1/md5/sha256 | filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | |
| URL | about.file.mime_type | filetype (filetype) | target.file.mime_type | ||
| URL | about.labels.key/value additional.fields.key/value.string_value | xff (xff) | PanOSXForwarderfor | identSrc | principal.ip |
| URL | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| URL | about.url | file_url (file_url) | target.url | ||
| URL | principal.asset.asset_id | Source VM UUID (src_uuid) | SrcUUID | principal.asset.product_object_id | |
| URL | target.asset.asset_id | Destination VM UUID (dst_uuid) | DstUUID | target.asset.product_object_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | http_headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| URL | about.labels.key/value additional.fields.key/value.string_value | UUID for rule (rule_uuid) | PanOSRuleUUID | security_result.rule_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| URL | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| URL | principal.asset.software.version | Source Device OS Version (src_osversion) | PanSrcDeviceOSv | principal.platform_version | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Hostname (src_host) | PanSrcHostname | principal.hostname | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| URL | target.asset.platform_software.platform target.labels.key/value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| URL | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| URL | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| URL | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Res Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | PanReasonFilteringAction | security_result.summary | |
| Data | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Data | target.file.full_path target.url | URL/Filename (misc) | Miscellaneous | target.file.names target.url | |
| Data | about.labels.key/value additional.fields.key/value.string_value | Category (category) | cs2 | URLCategory | security_result.category_details |
| Data | about.file.sha1/md5/sha256 | filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | |
| Data | about.file.mime_type | filetype (filetype) | target.file.mime_type | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | xff (xff) | principal.ip | ||
| Data | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Data | about.url | file_url (file_url) | target.url | ||
| Data | principal.asset.asset_id | Source VM UUID (src_uuid) | SrcUUID | principal.asset.product_object_id | |
| Data | target.asset.asset_id | Destination VM UUID (dst_uuid) | DstUUID | target.asset.product_object_id | |
| Data | about.labels.key/value additional.fields.key/value.string_value | http_headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| Data | about.labels.key/value additional.fields.key/value.string_value | UUID for rule (rule_uuid) | PanOSRuleUUID | security_result.rule_id | |
| Data | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | network.application_protocol_version | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | principal.asset.category | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | principal.asset.hardware.model | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | principal.asset.hardware.manufacturer | ||
| Data | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | principal.platform | ||
| Data | principal.asset.software.version | Source Device OS Version (src_osversion) | principal.platform_version | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Hostname (src_host) | principal.hostname | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | target.asset.category | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | target.asset.hardware.model | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | target.asset.hardware.manufacturer | ||
| Data | target.asset.platform_software.platform target.labels.key/value | Destination Device OS Family (dst_osfamily) | target.platform | ||
| Data | target.asset.software.version | Destination Device OS Version (dst_osversion) | target.platform_version | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | intermediary.resource.product_object_id | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | target.resource.attribute.labels | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | target.resource.name | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | principal.asset.asset_id | ||
| Data | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Res Timestamp (high_res_timestamp) | additional.fields.key/value.string_value | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | security_result.summary | ||
| GlobalProtect | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | PanOSVirtualSystem | intermediary.asset.attribute.labels | |
| GlobalProtect | principal.user.email_address principal.user.userid principal.administrative_domain | Source User (srcuser) | PanOSSourceUserName | target.user.email_address target.user.userid | |
| GlobalProtect | principal.asset.platform_software.platform(enum) | Client OS (client_os) | PanOSEndpointOSType | principal.platform | |
| GlobalProtect | principal.asset.platform_software.platform_version | Client OS Version (client_os_ver) | PanOSEndpointOSVersion | principal.platform_version | |
| GlobalProtect | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| GlobalProtect | about.labels.key/value additional.fields.key/value.string_value | Gateway Name (gateway) | PanOSAttemptedGateways | target.resource.name | |
| GlobalProtect | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | intermediary.asset.attribute.labels | ||
| GlobalProtect | target.hostname | Device Name (device_name) | intermediary.hostname | ||
| GlobalProtect | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| CORRELATION | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | VirtualSystem | intermediary.asset.attribute.labels | |
| CORRELATION | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | vSrcName | intermediary.asset.attribute.labels | |
| CORRELATION | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | VirtualSystemID | intermediary.resource.product_object_id | |
| GTP | additional.fields.key/value.string_value | Virtual System (vsys) | intermediary.asset.attribute.labels | ||
| GTP | target.ip | Remote User IP (remote_user_ip) | principal.ip | ||
| GTP | additional.fields.key/value.string_value | Remote User ID (remote_user_id) | principal.user.userid | ||
| GTP | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | additional.fields.key/value.string_value |
Servizio di logging di Strata Firewall di Palo Alto Networks
Panoramica
Palo Alto Networks® Strata Logging Service fornisce archiviazione e aggregazione centralizzate dei log basate su cloud per i firewall on-premise, virtuali (cloud privato e cloud pubblico), per Prisma Access e per i servizi forniti dal cloud come Cortex XDR.Strata Logging Service è sicuro, resiliente e tollerante agli errori e garantisce che i dati di logging siano aggiornati e disponibili quando ne hai bisogno. Fornisce un'infrastruttura di logging scalabile che elimina la necessità di pianificare e implementare raccoglitori di log per soddisfare le tue esigenze di conservazione dei log. Se hai già raccoglitori di log on-premise, il nuovo servizio di logging Strata può integrare la configurazione esistente. Puoi ampliare l'infrastruttura di raccolta dei log esistente con il servizio Strata Logging basato sul cloud per espandere la capacità operativa man mano che la tua attività cresce o per soddisfare le esigenze di capacità per le nuove sedi.Con questo servizio, Palo Alto Networks si occupa della manutenzione e del monitoraggio continui dell'infrastruttura di logging, in modo che tu possa concentrarti sulla tua attività.
Verifica i formati dei log e le versioni di PAN-OS supportati dal parser del servizio di logging Strata. La tabella seguente elenca i formati dei log e le versioni di PAN-OS corrispondenti supportate dal parser del servizio di logging Strata:
Formato log Versione PAN-OS JSON 12.1 Verifica i tipi di log del firewall Palo Alto Networks supportati dal parser Google SecOps. Il parser di Google SecOps supporta i seguenti tipi di log del firewall Palo Alto Networks:
- Traffico
- Minaccia
- Ispezione tunnel
- Sistema
- Corrispondenza HIP
- IP-Tag
- User-ID
- Decriptazione
- Autenticazione
- Filtro degli URL
- GlobalProtect
Deployment del servizio di logging di Strata
- Assicurati che il prodotto firewall Palo Alto Networks sia implementato e configurato correttamente. Per istruzioni di configurazione dettagliate, consulta la documentazione PAN-OS, quindi segui questo documento di deployment prima di inviare i log al servizio di logging Strata Prerequisiti per il deployment del servizio di logging Strata
Inizia a inviare log al servizio di logging Strata:
Per iniziare a inviare i log al servizio di logging Strata, segui questi passaggi:
- Installare una versione supportata di PAN-OS®
- Attiva il servizio di logging Strata: l'attivazione del servizio di logging Strata include il provisioning del certificato necessario ai firewall per connettersi in modo sicuro al servizio di logging Strata.
- Esegui l'onboarding dei firewall in Strata Logging Service con o senza Panorama
Per la procedura di onboarding dettagliata, consulta la documentazione.
Inoltra i log dal servizio Strata Logging
Per soddisfare le esigenze di archiviazione, generazione di report e monitoraggio a lungo termine o legali e di conformità, puoi configurare Strata Logging Service per inoltrare i log a un server HTTPS o ai seguenti SIEM:
- Exabeam
- Google Chronicle
- Microsoft Sentinel
- Raccolta eventi HTTP (HEC) Splunk
Utilizza il metodo di inoltro HTTPS per inoltrare i log utilizzando il servizio di logging Strata. Per informazioni dettagliate, consulta questa documentazione.
Formati di log supportati
Il parser firewall del servizio di logging Strata di Palo Alto Networks supporta i log in formato JSON.
Log di esempio supportati
JSON
{"source": "Palo Alto Networks FLS LF", "host": "dummy-loghost", "time": "1730265996460", "event": {"TimeReceived": "2024-10-30T05:25:50.000000Z", "DeviceSN": "no-serial", "LogType": "TRAFFIC", "Subtype": "end", "ConfigVersion": "10.2", "TimeGenerated": "2024-10-30T05:25:40.000000Z", "SourceAddress": "198.51.100.6", "DestinationAddress": "198.51.100.6", "NATSource": "", "NATDestination": "", "Rule": "egress-dns-ping-traceroute", "SourceUser": null, "DestinationUser": null, "Application": "dns-base", "VirtualLocation": "vsys1", "FromZone": "VA8280-RN", "ToZone": "inter-fw", "InboundInterface": "tunnel.101", "OutboundInterface": "tunnel.4005", "LogSetting": "Cortex Data Lake", "SessionID": 754194, "RepeatCount": 1, "SourcePort": 53578, "DestinationPort": 53, "NATSourcePort": 0, "NATDestinationPort": 0, "Protocol": "udp", "Action": "allow", "Bytes": 214, "BytesSent": 72, "BytesReceived": 142, "PacketsTotal": 2, "SessionStartTime": "2024-10-30T05:25:10.000000Z", "SessionDuration": 0, "URLCategory": "any", "SequenceNo": 7382192512716388639, "SourceLocation": "198.51.100.6-198.51.255.255", "DestinationLocation": "198.51.100.6-198.51.255.255", "PacketsSent": 1, "PacketsReceived": 1, "SessionEndReason": "aged-out", "DGHierarchyLevel1": 65537, "DGHierarchyLevel2": 65538, "DGHierarchyLevel3": 65541, "DGHierarchyLevel4": 0, "VirtualSystemName": "", "DeviceName": "VA8280-RN", "ActionSource": "from-policy", "SourceUUID": null, "DestinationUUID": null, "IMSI": 0, "IMEI": null, "ParentSessionID": 0, "ParentStarttime": "1970-01-01T00:00:00.000000Z", "Tunnel": "N/A", "EndpointAssociationID": 72057594037927936, "ChunksTotal": 0, "ChunksSent": 0, "ChunksReceived": 0, "RuleUUID": "95cfc3cc-cb00-4758-af1d-de9ab5f07f97", "HTTP2Connection": 0, "LinkChangeCount": 0, "SDWANPolicyName": null, "LinkSwitches": null, "SDWANCluster": null, "SDWANDeviceType": null, "SDWANClusterType": null, "SDWANSite": null, "DynamicUserGroupName": null, "X-Forwarded-ForIP": null, "SourceDeviceCategory": null, "SourceDeviceProfile": null, "SourceDeviceModel": null, "SourceDeviceVendor": null, "SourceDeviceOSFamily": null, "SourceDeviceOSVersion": null, "SourceDeviceHost": null, "SourceDeviceMac": null, "DestinationDeviceCategory": null, "DestinationDeviceProfile": null, "DestinationDeviceModel": null, "DestinationDeviceVendor": null, "DestinationDeviceOSFamily": null, "DestinationDeviceOSVersion": null, "DestinationDeviceHost": null, "DestinationDeviceMac": null, "ContainerID": null, "ContainerNameSpace": null, "ContainerName": null, "SourceEDL": null, "DestinationEDL": null, "GPHostID": null, "EndpointSerialNumber": null, "SourceDynamicAddressGroup": null, "DestinationDynamicAddressGroup": null, "HASessionOwner": null, "TimeGeneratedHighResolution": "2024-10-30T05:25:41.009000Z", "NSSAINetworkSliceType": null, "NSSAINetworkSliceDifferentiator": null}}"
Riferimento per la mappatura dei campi: campi dei log e campi UDM
Questa sezione spiega come il parser mappa i campi dei log del firewall di Palo Alto Networks Strata Logging Service ai campi degli eventi UDM di Google per ogni tipo di log.
Per il riferimento alla mappatura di ogni tipo di log, consulta le seguenti sezioni:
- Sistema
- Minaccia
- Traffico
- ID utente
- HIP match
- Tag IP
- Decrittografia
- Tunnel
- Autenticazione
- URL
- GlobalProtect
- SCTP
- Controlli
Sistema
La tabella seguente elenca i campi di log del tipo di log di sistema e i campi UDM corrispondenti.
| Log field | UDM mapping |
|---|---|
| AgentContentVersion | additional.fields.key/value.string_value |
| AgentDataCollectionStatus | target.resource.attribute.labels |
| AgentID | target.resource.attribute.labels |
| AgentIsolationStatus | target.resource.attribute.labels |
| AgentStatus | target.resource.attribute.labels |
| AgentVersion | target.asset.software.version |
| ConfigVersion | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DeviceGroup | target.group.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EndpointCPUArchitecture | target.asset.hardware.cpu_platform |
| EndpointDeviceDomain | target.asset.administrative_domain |
| EndpointDeviceName | target.asset.hostname |
| EndpointIPaddress | target.asset.ip |
| VDIEndpoint | target.asset.attribute.labels |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointOSVersion | target.platform_version |
| AgentTimeZoneOffset | additional.fields.key/value.string_value |
| EndpointUserDomain | additional.fields.key/value.string_value |
| EndpointUserName | target.user.user_display_name |
| EndpointUserUUID | target.user.userid |
| EventComponent | additional.fields.key/value.string_value |
| EventDescription | metadata.description |
| EventName | additional.fields.key/value.string_value |
| EventTime | metadata.event_timestamp |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogCategory | security_result.category_details |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| LogSourceID | target.resource.attribute.labels |
| LogSourceName | observer.asset.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| LogTime | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Severity | security_result.severity |
| Subtype | metadata.product_event_type |
| Template | target.resource.attribute.labels |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
Minaccia
La tabella seguente elenca i campi di log del tipo di log Minaccia e i relativi campi UDM.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| ApplianceOrCloud | additional.fields.key/value.string_value |
| CloudHostname | additional.fields.key/value.string_value |
| CloudReportID | security_result.detection_fields.key/value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DirectionOfAttack | security_result.detection_fields.key/value |
| DomainEDL | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| FileName | target.file.names |
| FileHash | target.file.sha1 |
| FileType | additional.fields.key/value.string_value |
| FileURL | target.url |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HostID | principal.asset.asset_id |
| HTTP2Connection | network.application_protocol_version |
| HTTPMethod | network.http.method |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| LocalDeepLearningAnalyzed | additional.fields.key/value.string_value |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| PartialHash | additional.fields.key/value.string_value |
| PayloadProtocolID | additional.fields.key/value.string_value |
| Packet | additional.fields.key/value.string_value |
| PacketID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| RecipientEmail | target.user.email_addresses |
| ReportID | security_result.detection_fields.key/value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SenderEmail | principal.user.email_addresses |
| SequenceNo | metadata.product_log_id |
| SessionID | network.session_id |
| Severity | security_result.severity |
| SigFlags | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| EmailSubject | network.email.subject |
| ApplicationTechnology | additional.fields.key/value.string_value |
| ThreatCategory | security_result.detection_fields.key/value.key/value |
| ThreatID | security_result.threat_id |
| ThreatName | security_result.threat_name |
| ThreatNameFirewall | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLDomain | target.domain.name |
| URLCounter | additional.fields.key/value.string_value |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| Verdict | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-ForIP | principal.ip |
Traffico
La tabella seguente elenca i campi di log del tipo di log sul traffico e i campi UDM corrispondenti.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| ActionSource | additional.fields.key/value.string_value |
| AIFwdError | additional.fields.key/value.string_value |
| AITraffic | additional.fields.key/value.string_value |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| BytesReceived | network.received_bytes |
| BytesSent | network.sent_bytes |
| Bytes | additional.fields.key/value.string_value |
| ChunksReceived | additional.fields.key/value.string_value |
| ChunksSent | additional.fields.key/value.string_value |
| ChunksTotal | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| EndpointAssociationID | additional.fields.key/value.string_value |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HASessionOwner | additional.fields.key/value.string_value |
| GPHostID | additional.fields.key/value.string_value |
| HTTP2Connection | network.application_protocol_version |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsOffloaded | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| LinkChangeCount | additional.fields.key/value.string_value |
| LinkSwitches | additional.fields.key/value.string_value |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| SDWANPolicyName | additional.fields.key/value.string_value |
| Protocol | network.ip_protocol |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SDWANFECRatio | additional.fields.key/value.string_value |
| SDWANCluster | additional.fields.key/value.string_value |
| SDWANClusterType | additional.fields.key/value.string_value |
| SDWANDeviceType | additional.fields.key/value.string_value |
| SDWANSite | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionStartTime | additional.fields.key/value.string_value |
| SessionTracker | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| SessionDuration | network.session_duration |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLCategory | target.url_metadata.categories |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-ForIP | principal.ip |
User-ID
La tabella seguente elenca i campi di log del tipo di log User-ID e i relativi campi UDM.
| Log field | UDM mapping |
|---|---|
| AuthFactorNo | security_result.detection_fields.key/value |
| AuthenticatedUserDomain | target.user.administrative_domain |
| AuthenticatedUserName | target.user.userid |
| AuthenticatedUserUUID | target.user.product_object_id |
| ConfigVersion | additional.fields.key/value.string_value |
| CountofRepeats | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationPort | target.port |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EventID | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsDuplicateUser | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MappingDataSource | additional.fields.key/value.string_value |
| MappingDataSourceName | additional.fields.key/value.string_value |
| MappingDataSourceType | additional.fields.key/value.string_value |
| MappingTimeout | additional.fields.key/value.string_value |
| MFAFactorType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SourceIP | principal.ip |
| SourcePort | principal.port |
| Subtype | metadata.product_event_type |
| Tag | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| UGFlags | additional.fields.key/value.string_value |
| User | target.user.userid |
| UserGroupFound | additional.fields.key/value.string_value |
| UserIdentifiedBySource | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Corrispondenza HIP
La seguente tabella elenca i campi di log del tipo di log di corrispondenza HIP e i relativi campi UDM.
| Log field | UDM mapping |
|---|---|
| ConfigVersion | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EndpointDeviceName | principal.asset.hostname |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| HipMatchName | target.resource.attribute.labels |
| HipMatchType | target.resource.attribute.labels |
| HostID | principal.asset.asset_id |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | metadata.product_event_type |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Source | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceIP | principal.ip |
| SourceIPv6 | principal.ip |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| TimestampDeviceIdentification | principal.asset.first_seen_time |
| UUID | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
Tag IP
La tabella seguente elenca i campi di log del tipo di log tag IP e i campi UDM corrispondenti.
| Log field | UDM mapping |
|---|---|
| ConfigVersion | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EventID | additional.fields.key/value.string_value |
| IPSubnetRange | network.ip_subnet_range |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSetting | target.resource.attribute.labels |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MappingDataSource | additional.fields.key/value.string_value |
| MappingDataSourceSubType | additional.fields.key/value.string_value |
| MappingDataSourceType | additional.fields.key/value.string_value |
| MappingTimeout | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| RuleMatched | security_result.rule_name |
| RuleMatchedUUID | security_result.rule_id |
| SequenceNo | metadata.product_log_id |
| SourceIP | principal.ip |
| Subtype | metadata.product_event_type |
| TagName | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
Decriptazione
La tabella seguente elenca i campi di log del tipo di log Decryption e i relativi campi UDM.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| CertificateFlags | additional.fields.key/value.string_value |
| CertificateSerial | network.tls.server.certificate.serial |
| CertificateSize | additional.fields.key/value.string_value |
| CertificateVersion | network.tls.server.certificate.version |
| ChainStatus | additional.fields.key/value.string_value |
| ApplicationCharacteristics | additional.fields.key/value.string_value |
| ClientToFirewall | additional.fields.key/value.string_value |
| CommonName | additional.fields.key/value.string_value |
| CommonNameLength | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| Cpadding | additional.fields.key/value.string_value |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| Domain | target.hostname |
| EllipticCurve | network.tls.curve |
| ErrorIndex | additional.fields.key/value.string_value |
| ErrorMessage | additional.fields.key/value.string_value |
| Fingerprint | network.tls.server.certificate.md5/sha1/sha256 |
| FirewallToClient | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsCertECDSA | additional.fields.key/value.string_value |
| IsCertRSA | additional.fields.key/value.string_value |
| IsCertCNTruncated | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| IsForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsIssuerCNTruncated | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| IsNAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| PacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsResumeSession | additional.fields.key/value.string_value |
| IsRootCNTruncated | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSNITruncated | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| IssuerCommonName | network.tls.server.certificate.issuer |
| IssuerNameLength | additional.fields.key/value.string_value |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| TimeNotAfter | additional.fields.key/value.string_value |
| TimeNotBefore | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| Padding | additional.fields.key/value.string_value |
| Padding3 | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| PolicyName | additional.fields.key/value.string_value |
| Protocol | network.ip_protocol |
| ProxyType | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| RootCommonName | additional.fields.key/value.string_value |
| RootCNLength | additional.fields.key/value.string_value |
| RootStatus | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SessionID | network.session_id |
| ServerNameIndication | network.tls.client.server_name |
| SNILength | additional.fields.key/value.string_value |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeReceivedManagementPlane | additional.fields.key/value.string_value |
| TLSAuth | additional.fields.key/value.string_value |
| TLSEncryptionAlgorithm | additional.fields.key/value.string_value |
| TLSKeyExchange | additional.fields.key/value.string_value |
| TLSVersion | network.tls.version |
| ToZone | additional.fields.key/value.string_value |
| Tpadding | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| Vpadding | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Tunnel
La tabella seguente elenca i campi di log del tipo di log Tunnel e i relativi campi UDM.
| Log field | UDM mapping |
|---|---|
| AccessPointName | additional.fields.key/value.string_value |
| Action | security_result.action |
| ActionSource | additional.fields.key/value.string_value |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| BytesReceived | network.received_bytes |
| BytesSent | network.sent_bytes |
| Bytes | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| LoggingServiceID | additional.fields.key/value.string_value |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MobileAreaCode | additional.fields.key/value.string_value |
| MobileBaseStationCode | additional.fields.key/value.string_value |
| MobileCountryCode | additional.fields.key/value.string_value |
| MobileIP | additional.fields.key/value.string_value |
| MobileNetworkCode | additional.fields.key/value.string_value |
| MobileSubscriberISDN | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceDifferentiator | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsDroppedMax | additional.fields.key/value.string_value |
| PacketsDroppedStrict | additional.fields.key/value.string_value |
| PacketsDroppedTunnel | additional.fields.key/value.string_value |
| PacketsDroppedProtocol | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| ProtocolDataUnitsessionID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| RadioAccessTechnology | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionStartTime | additional.fields.key/value.string_value |
| SessionTracker | additional.fields.key/value.string_value |
| Severity | security_result.severity |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| StandardPortsOfApp | additional.fields.key/value.string_value |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| SessionDuration | network.session_duration |
| Tunnel | additional.fields.key/value.string_value |
| TunnelCauseCode | additional.fields.key/value.string_value |
| TunnelEndpointID1 | additional.fields.key/value.string_value |
| TunnelEndpointID2 | additional.fields.key/value.string_value |
| TunnelEventCode | additional.fields.key/value.string_value |
| TunnelEventType | additional.fields.key/value.string_value |
| TunnelInspectionRule | additional.fields.key/value.string_value |
| TunnelInterface | additional.fields.key/value.string_value |
| TunnelMessageType | additional.fields.key/value.string_value |
| TunnelRemoteIMSIID | additional.fields.key/value.string_value |
| TunnelRemoteUserIP | principal.ip |
| TunnelSessionsClosed | additional.fields.key/value.string_value |
| TunnelSessionsCreated | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLCategory | target.url_metadata.categories |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Autenticazione
La tabella seguente elenca i campi di log del tipo di log di autenticazione e i relativi campi UDM corrispondenti.
| Log field | UDM mapping |
|---|---|
| AuthenticationDescription | security_result.description |
| AuthEvent | metadata.description |
| AuthFactorNo | security_result.detection_fields.key/value |
| AuthenticationPolicy | security_result.detection_fields.key/value |
| AuthenticationProtocol | additional.fields.key/value.string_value |
| AuthServerProfile | additional.fields.key/value.string_value |
| AuthenticatedUserDomain | target.administrative_domain |
| AuthenticatedUserName | target.user.userid |
| AuthenticatedUserUUID | target.user.product_object_id |
| ClientType | additional.fields.key/value.string_value |
| ClientTypeName | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| Location | target.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogType | additional.fields.key/value.string_value |
| MFAAuthenticationID | additional.fields.key/value.string_value |
| MFAVendor | additional.fields.key/value.string_value |
| NormalizeUser | target.user.user_display_name |
| Object | target.resource.name |
| RuleMatched | security_result.rule_name |
| RuleMatchedUUID | security_result.rule_id |
| AuthCacheServiceRegion | additional.fields.key/value.string_value |
| SessionID | network.session_id |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceIP | principal.ip |
| TimeGenerated | metadata.event_timestamp |
| User | target.user.userid |
| UserAgentString | network.http.user_agent |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Subtype | metadata.product_event_type |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
URL
La seguente tabella elenca i campi di log del tipo di log URL e i relativi campi UDM.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| CloudHostname | additional.fields.key/value.string_value |
| CloudReportID | security_result.detection_fields.key/value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentType | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DirectionOfAttack | security_result.detection_fields.key/value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| FileURL | target.url |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HostID | principal.asset.asset_id |
| HTTP2Connection | network.application_protocol_version |
| HTTPHeaders | additional.fields.key/value.string_value |
| HTTPMethod | network.http.method |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| InlineMLVerdict | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| Packet | additional.fields.key/value.string_value |
| PacketID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| Referer | network.http.referral_url |
| HTTPRefererFQDN | additional.fields.key/value.string_value |
| HTTPRefererPort | additional.fields.key/value.string_value |
| HTTPRefererProtocol | additional.fields.key/value.string_value |
| HTTPRefererURLPath | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionID | network.session_id |
| Severity | security_result.severity |
| SigFlags | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URL | target.url_metadata.URL |
| URLCategory | target.url_metadata.categories |
| URLCategoryList | additional.fields.key/value.string_value |
| URLDomain | target.domain.name |
| URLCounter | additional.fields.key/value.string_value |
| UserAgent | network.http.user_agent |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-For | additional.fields.key/value.string_value |
| X-Forwarded-ForIP | principal.ip |
GlobalProtect
La tabella seguente elenca i campi di log del tipo di log GlobalProtect e i relativi campi UDM.
| Log field | UDM mapping |
|---|---|
| AttemptedGateways | additional.fields.key/value.string_value |
| AuthMethod | extensions.auth.auth_details |
| ConnectionMethod | additional.fields.key/value.string_value |
| ConnectionErrorID | additional.fields.key/value.string_value |
| ConnectionError | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| EndpointDeviceName | principal.asset.hostname |
| GlobalProtectClientVersion | additional.fields.key/value.string_value |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointSN | principal.asset.hardware.serial_number |
| EventIDValue | additional.fields.key/value.string_value |
| Gateway | target.resource.name |
| GatewayPriority | additional.fields.key/value.string_value |
| GatewaySelectionType | additional.fields.key/value.string_value |
| GlobalProtectGatewayLocation | target.location.country_or_region |
| HostID | principal.asset.asset_id |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LoginDuration | network.session_duration |
| Description | security_result.description |
| Portal | target.hostname |
| PrivateIPv4 | principal.ip |
| PrivateIPv6 | principal.ip |
| ProjectName | additional.fields.key/value.string_value |
| PublicIPv4 | principal.nat_ip |
| PublicIPv6 | principal.nat_ip |
| QuarantineReason | security_result.summary |
| SequenceNo | metadata.product_log_id |
| SourceRegion | principal.location.country_or_region |
| SourceUserName | principal.user.user_display_name |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SSLResponseTime | additional.fields.key/value.string_value |
| Stage | additional.fields.key/value.string_value |
| EventStatus | additional.fields.key/value.string_value |
| LogSubtype | metadata.product_event_type |
| TunnelType | additional.fields.key/value.string_value |
| VirtualSystem | intermediary.asset.attribute.labels |
| VirtualSystemName | intermediary.asset.attribute.labels |
| EndpointOSVersion | principal.platform_version |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | metadata.product_event_type |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualSystemID | intermediary.resource.product_object_id |
SCTP
La tabella seguente elenca i campi di log del tipo di log SCTP e i relativi campi UDM.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| AssocationEndReason | additional.fields.key/value.string_value |
| ChunksReceived | additional.fields.key/value.string_value |
| ChunksSent | additional.fields.key/value.string_value |
| ChunksTotal | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceClass | target.asset.category |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationIP | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DiamAppID | additional.fields.key/value.string_value |
| DiamAvpCode | additional.fields.key/value.string_value |
| DiameterCommandCode | additional.fields.key/value.string_value |
| DiameterRequestFlag | additional.fields.key/value.string_value |
| DeviceName | principal.asset.hostname |
| SCTPEventType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLFiltering | additional.fields.key/value.string_value |
| IsWildfire | additional.fields.key/value.string_value |
| LogAction | additional.fields.key/value.string_value |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MapAppCode | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PayloadProtocolID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SccpCallingGt | additional.fields.key/value.string_value |
| SccpCallingSSN | additional.fields.key/value.string_value |
| SctpCauseCode | additional.fields.key/value.string_value |
| SctpChunkType | additional.fields.key/value.string_value |
| SctpFilter | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionTracker | additional.fields.key/value.string_value |
| Severity | security_result.severity |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceIP | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VerificationTag1 | additional.fields.key/value.string_value |
| VerificationTag2 | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Controlla
La tabella seguente elenca i campi di log del tipo Audit log e i relativi campi UDM corrispondenti.
| Log field | UDM mapping |
|---|---|
| EventCategory | network.http.method |
| EventDescription | metadata.description |
| EventDestinationURL | target.url |
| EventDestinationUserUserID | target.user.userid |
| DestinationVendor | additional.fields.key/value.string_value |
| EventDetails | additional.fields.key/value.string_value |
| EventID | metadata.product_log_id |
| EventName | additional.fields.key/value.string_value |
| EventResult | security_result.summary |
| EventSourceUserUserID | principal.user.userid |
| EventTime | metadata.event_timestamp |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| Subtype | metadata.product_event_type |
| TSGID | additional.fields.key/value.string_value |
| Vendor | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
Riferimento per la mappatura dei campi: tipi di log e tipo di evento UDM
La tabella seguente elenca i tipi di log firewall del servizio di logging Strata di Palo Alto Networks e i tipi di eventi UDM corrispondenti.
| Tipo di log | Tipo di evento UDM |
| Traffico | NETWORK_CONNECTION |
| Minaccia | NETWORK_CONNECTION |
| Filtro degli URL | NETWORK_CONNECTION |
| Tunnel | NETWORK_CONNECTION |
| Sistema |
Se il valore del sottotipo è "dhcp", viene impostato NETWORK_DHCP. Se il valore del sottotipo è "auth", viene impostato USER_LOGIN. Se il valore della descrizione è "logged in", viene impostato USER_LOGIN. Se il valore della descrizione è "logged out", viene impostato USER_LOGOUT. Per gli altri valori del sottotipo, viene impostato GENERIC_EVENT. |
| HIP Match | NETWORK_CONNECTION |
| Tag IP | GENERIC_EVENT |
| User-ID | USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED
Se il valore del sottotipo è "login", viene impostato USER_LOGIN. Se il valore del sottotipo è "logout", viene impostato USER_LOGOUT. Se il sottotipo non contiene alcun valore, viene impostato USER_UNCATEGORIZED. |
| Decriptazione | NETWORK_CONNECTION |
| Autenticazione | STATUS_UNCATEGORIZED |
| Globalprotect | USER_LOGIN/USER_LOGOUT/USER_RESOURCE_ACCESS
Se il valore del sottotipo è "auth", viene impostato USER_LOGIN. Se il valore del sottotipo è "logout", viene impostato USER_LOGOUT. Se il sottotipo non contiene alcun valore, viene impostato USER_RESOURCE_ACCESS. |
| SCTP | NETWORK_CONNECTION |
| Controlla | NETWORK_CONNECTION |
Passaggi successivi
Hai bisogno di ulteriore assistenza? Ricevi risposte dai membri della community e dai professionisti di Google SecOps.