Recolha registos de firewall da Palo Alto Networks
Firewall da Palo Alto Networks
Vista geral
Este documento descreve como pode configurar o syslog e um encaminhador do Google SecOps para recolher registos da firewall da Palo Alto Networks. Este documento também explica como os campos de registo da firewall da Palo Alto Networks são mapeados para os campos do modelo de dados unificado (UDM) do Google SecOps. Para uma vista geral sobre a ingestão de dados do Google SecOps, consulte o artigo Ingestão de dados no Google SecOps. Uma etiqueta de carregamento identifica o analisador que normaliza os dados de registo não processados para o formato UDM estruturado. As informações neste documento aplicam-se ao analisador com a etiqueta de carregamento PAN_FIREWALL.
Antes de começar
- Certifique-se de que o produto de firewall da Palo Alto Networks está implementado e configurado corretamente. Para ver instruções de configuração detalhadas, consulte a documentação do PAN-OS.
Para compreender os componentes implementados para recolher registos da firewall da Palo Alto Networks, reveja a arquitetura de implementação. Cada implementação do cliente pode diferir desta representação e pode ser mais complexa. O diagrama seguinte mostra como pode configurar o syslog numa firewall da Palo Alto Networks e instalar um encaminhador do Google SecOps num servidor Linux para encaminhar dados de registo para o Google SecOps. O analisador suporta registos escritos nos seguintes formatos de dados: valores separados por vírgulas (CSV), formato de evento comum (CEF) e formato de evento de registo alargado (LEEF).
Verifique os formatos de registo e as versões do PAN-OS suportados pelo analisador do Google SecOps. A tabela seguinte indica os formatos de registo e as versões do PAN-OS correspondentes suportadas pelo analisador do Google SecOps:
Formato do registo Versão do PAN-OS CSV 10.1.3 CEF 10.0.0 LEEF 9.1.0 Valide os tipos de registos da firewall da Palo Alto Networks que o analisador do Google SecOps suporta. O analisador do Google SecOps suporta os seguintes tipos de registos de firewall da Palo Alto Networks:
- Trânsito
- Ameaça
- Envios do WildFire
- Inspeção de túneis
- Configuração
- Sistema
- Correspondência de HIP
- IP-Tag
- User-ID
- Desencriptação
- Autenticação
- Filtragem de URLs
- Filtragem de dados
- GlobalProtect
- Correlação
- GTP
- SCTP
- Auditoria
Para mais informações sobre os tipos de registos da firewall da Palo Alto Networks, consulte Tipos de registos do PAN-OS.
Certifique-se de que todos os sistemas na arquitetura de implementação estão configurados no fuso horário UTC.
Antes de usar o analisador do firewall da Palo Alto Networks, reveja as alterações nas associações de campos entre o analisador anterior e o analisador do firewall da Palo Alto Networks atual. Como parte da migração, certifique-se de que as regras, as pesquisas, os painéis de controlo ou outros processos que dependem dos campos originais usam os campos atualizados.
Por exemplo, na versão anterior do analisador, o campo de registo
categoryé mapeado para o campo UDMsecurity_result.description. No analisador do firewall da Palo Alto Networks atual, o campo de registocategoryé mapeado para o campo UDMsecurity_result.category_details. Se migrar para o analisador de firewall da Palo Alto Networks atual e usar o campocategorynas suas regras, tem de modificar as regras para usar o camposecurity_result.category_detailsUDM do analisador atual.
Configure o syslog e o encaminhador do Google Security Operations
Para configurar o syslog e o encaminhador do Google SecOps, conclua os seguintes passos:
- Para monitorizar registos CSV, configure o perfil do servidor syslog. Para mais informações, consulte o artigo Configure o perfil do servidor syslog. Quando configurar o perfil do servidor syslog, especifique "Predefinição" como o formato de registo personalizado.
- Para monitorizar registos CEF, configure a firewall da Palo Alto Networks para encaminhar registos CEF. Para mais informações, transfira o PDF do guia de integração de CEF do PAN-OS e consulte a secção "Configuração do NGFW da Palo Alto Networks para gerar eventos CEF".
- Para monitorizar registos LEEF, configure o perfil do servidor syslog. Para mais informações, consulte o artigo Encaminhamento de registos personalizados no formato LEEF.
Configure o encaminhador do Google SecOps para enviar registos para o Google Security Operations. Para mais informações, consulte o artigo Instalar e configurar o encaminhador no Linux. Segue-se um exemplo de uma configuração de encaminhador do Google SecOps:
- syslog: common: enabled: true data_type: PAN_FIREWALL batch_n_seconds: 10 batch_n_bytes: 1048576 tcp_address: 0.0.0.0:10518 connection_timeout_sec: 60
Configure o encaminhamento de syslog na firewall da PAN
Crie um perfil de servidor syslog
- Inicie sessão na consola de gestão da firewall da Palo Alto Networks.
- Aceda a Dispositivo > Perfis do servidor > Syslog.
- Clique em Adicionar para criar um novo perfil de servidor.
- Forneça os seguintes detalhes de configuração:
- Nome: introduza um nome descritivo (por exemplo,
Google SecOps BindPlane). - Localização: selecione o sistema virtual (vsys) ou Partilhado onde este perfil vai estar disponível.
- Nome: introduza um nome descritivo (por exemplo,
- Clique em Servidores > Adicionar para configurar o servidor syslog.
- Indique os seguintes detalhes de configuração do servidor:
- Nome: introduza um nome descritivo para o servidor (por exemplo,
BindPlane Agent). - Servidor Syslog: introduza o endereço IP do agente BindPlane.
- Transporte: selecione UDP ou TCP, consoante a configuração do agente BindPlane (UDP é a predefinição).
- Porta: introduza o número da porta do agente BindPlane (por exemplo,
514). - Formato: selecione BSD (predefinição) ou IETF, consoante os seus requisitos.
- Facility: selecione LOG_USER (predefinição) ou outra funcionalidade, conforme necessário.
- Nome: introduza um nome descritivo para o servidor (por exemplo,
- Clique em OK para guardar o perfil do servidor syslog.
Opcional: configure o formato de registo personalizado para CEF ou LEEF
Se precisar de registos CEF (Common Event Format) ou LEEF (Log Event Extended Format) em vez de CSV:
- No perfil do servidor Syslog, selecione o separador Formato de registo personalizado.
- Configure o formato de registo personalizado para cada tipo de registo (Config, System, Threat, Traffic, URL, Data, WildFire, Tunnel, Authentication, User-ID, HIP Match).
- Para a configuração do formato CEF, consulte o guia de configuração do CEF da Palo Alto Networks.
- Clique em OK para guardar a configuração.
Crie um perfil de encaminhamento de registos
- Aceda a Objetos > Encaminhamento de registos.
- Clique em Adicionar para criar um novo perfil de encaminhamento de registos.
- Forneça os seguintes detalhes de configuração:
- Nome: introduza um nome de perfil (por exemplo,
Google SecOps Forwarding). Se quiser que a firewall atribua automaticamente este perfil a novas regras e zonas de segurança, atribua-lhe o nomedefault.
- Nome: introduza um nome de perfil (por exemplo,
- Para cada tipo de registo que quer encaminhar (Tráfego, Ameaça, Envio do WildFire, Filtragem de URLs, Filtragem de dados, Túnel, Autenticação), configure o seguinte:
- Clique em Adicionar na secção do tipo de registo respetiva.
- Syslog: selecione o perfil do servidor syslog que criou (por exemplo,
Google SecOps BindPlane). - Gravidade do registo: selecione os níveis de gravidade a encaminhar (por exemplo, Tudo).
- Clique em OK para guardar o perfil de encaminhamento de registos.
Aplique o perfil de encaminhamento de registos às políticas de segurança
- Aceda a Políticas > Segurança.
- Selecione as regras de segurança para as quais quer ativar o encaminhamento de registos.
- Clique na regra para a editar.
- Aceda ao separador Ações.
- No menu Encaminhamento de registos, selecione o perfil de encaminhamento de registos que criou (por exemplo,
Google SecOps Forwarding). - Clique em OK para guardar a configuração da política de segurança.
Configure as definições de registo para registos do sistema
- Aceda a Dispositivo > Definições de registo.
- Para cada tipo de registo (Sistema, Configuração, ID do utilizador, HIP Match, Global Protect, IP-Tag, SCTP) e nível de gravidade, selecione o perfil do servidor Syslog que criou.
- Clique em OK para guardar as definições de registo.
Confirme as alterações
- Clique em Confirmar na parte superior da interface Web da firewall.
- Aguarde até que a confirmação seja concluída com êxito.
- Verifique se os registos estão a ser enviados para o agente do Bindplane verificando se existem registos de firewall da Palo Alto Networks na consola do Google SecOps.
Encaminhe registos para o Google SecOps através do agente Bindplane
- Instale e configure uma máquina virtual Linux.
- Instale e configure o agente Bindplane no Linux para encaminhar registos para o Google SecOps. Para mais informações sobre como instalar e configurar o agente Bindplane, consulte as instruções de instalação e configuração do agente Bindplane.
Se tiver problemas ao criar feeds, contacte o apoio técnico da Google SecOps.
Formatos de registo suportados
O analisador do firewall da Palo Alto Networks suporta registos nos formatos LEEF,CEF e CSV.
Registos de exemplo suportados
LEEF
<14>Jan 22 02:20:19 device_host LEEF:1.0|Palo Alto Networks|PAN-OS Syslog Integration|10.2.12-h4|Microsoft MSOFFICE(52033)|ReceiveTime=2025/01/22 02:20:18|SerialNumber=01250100xxxx|cat=THREAT|Subtype=wildfire|devTime=Jan 22 2025 08:20:18 GMT|src=198.50.100.1|dst=198.50.100.2|srcPostNAT=198.50.100.3|dstPostNAT=198.50.100.4|RuleName=AZURE-US-NEW-CNF_Inbound_To_Azure-ALLOW|usrName=|SourceUser=|DestinationUser=|Application=smtp-base|VirtualSystem=vsys1|SourceZone=McD-Global-Zone|DestinationZone=Azure-Zone|IngressInterface=ae1.111|EgressInterface=ae2.409|LogForwardingProfile=Default-Traffic-Logging|SessionID=35331795|RepeatCount=1|srcPort=21578|dstPort=25|srcPostNATPort=0|dstPostNATPort=0|Flags=0x2000|proto=tcp|action=allow|Miscellaneous=\"......3...................xls\"|ThreatID=Microsoft MSOFFICE(52033)|URLCategory=malicious|sev=4|Severity=high|Direction=client-to-server|sequence=7462614601465681755|ActionFlags=0x8000000000000000|SourceLocation=198.50.100.1-198.50.100.255|DestinationLocation=United States|ContentType=|PCAP_ID=0|FileDigest=0ea04c99bf188c2e4207f60f92ca7c6f5088c7943ee63f45c50032bbd2bf7ea9|Cloud=demo.com|URLIndex=1|RequestMethod=|FileType=ms-office|Sender=sender@ab.myownpersonaldomain.com|Subject=\"............:.................................................................................-.........(Name)-2025-01-22...............:Y107202501220005, ............:........................, ...............:.........\"|Recipient=abc@demo.myownpersonaldomain.com|ReportID=117022282776|DeviceGroupHierarchyL1=143|DeviceGroupHierarchyL2=144|DeviceGroupHierarchyL3=39|DeviceGroupHierarchyL4=0|vSrcName=|DeviceName=device_host|SrcUUID=|DstUUID=|TunnelID=0|MonitorTag=|ParentSessionID=0|ParentStartTime=|TunnelType=N/A|ThreatCategory=N/A|ContentVer=WildFire-0CEF
14>1 2024-04-04T16:21:56+02:00 FW-PERIMETRAL-AVG-01 - - - - CEF:0|Palo Alto Networks|PAN-OS|10.1.10-h2|end|TRAFFIC|1|src=198.51.100.1 dst=198.51.100.2 srcTranslatedAddress=198.51.100.3 dstTranslatedAddress=198.51.100.4 rule=FW_USER_NATS2_APP suser= duser= app=bittorrent vs=vsys1 sz=INSIDE dz=EXTERNAL InboundInterface=ae2.2266 OutboundInterface=ae1 lp=log_forwarding sid=2935823 cnt=1 spt=6881 dpt=51413 srcTranslatedPort=0 dstTranslatedPort=0 flags=0x7a proto=udp act=allow tbytes=475 in=150 out=325 pkt=2 pktReceived=1 pktSent=1 start=Apr 04 2024 14:21:56 GMT stime=1206 urlcat=any externalId=externalId reason=aged-out DGl1=11 DGl2=161 DGl3=0 DGl4=0 VsysName=STONESOFT dvchost=FW-PERIMETRAL-AVG-01 cat=from-policy ActionFlags=0x8000000000000000 srcUUID= dstUUID= TunnelID=0 MonitorTag= ParentSessionID=0 ParentStartTime= TunnelType=N/A SCTPAssocID=0 SCTPChunks=0 SCTPChunkSent=0 SCTPChunksRcv=0 RuleUUID=746c3eb6-3d51-4679-8438-bd0e00e170a8 HTTP2Con=0 LinkChange=0 PolicyID= LinkDetail= SDWANCluster= SDWANDevice= SDWANClustype= SDWANSite= DynamicUsrgrp= XFFIP= srcDevCat= srcDevProf= srcDevModel= srcDevVendor= srcDevOS= srcDevOSv= srcHostname= srcMac= dstDevCat= dstDevProf= dstDevModel= dstDevVendor= dstDevOS= dstDevOSv= dstHostname= dstMac= ContainerName= PODNamespace= PODName= srcEDL= dstEDL= GPHostID= EPSerial= srcDAG= dstDAG= HASessionOwner= TimeHighRes=2024-04-04T16:21:56.250+02:00 ASServiceType= ASServiceDiff="CSV
1,2021/10/24 15:30:07,,CONFIG,0,2561,2021/10/24 15:30:07,198.51.100.0,,set,admin,Web,Succeeded, network virtual-router VR1,,VR1 { ecmp { algorithm { ip-modulo ; } } protocol { bgp { routing-options { graceful-restart { enable yes; } } enable no; } rip { enable no; } ospf { enable no; } ospfv3 { enable no; } } routing-table { ip { static-route { vr1-log { path-monitor { enable no; failure-condition any; hold-time 2; } nexthop { ip-address 198.51.100.0; } bfd { profile None; } interface ethernet1/1; metric 10; destination 0.0.0.0/0; route-table { unicast ; } } } } } interface [ ethernet1/1 ethernet1/2 ]; } ,7022390503849066572,0x0,0,0,0,0,,PA-VM,0,
Referência de mapeamento de campos: mapeamento de campos de registos para campos de UDM
Esta secção explica como o analisador mapeia os campos de registo da firewall da Palo Alto Networks para os campos de eventos da UDM do Google SecOps para cada tipo de registo. A chave da etiqueta do Google SecOps refere-se ao nome da chave mapeada para o campo UDM Labels.key.
Por exemplo, no caso do campo "Virtual System", o nome do campo é "cs3" no formato CEF e "VirtualSystem" no formato LEEF. O campo UDM "about.labels.key" contém o valor "vsys" e o campo UDM "about.labels.value" contém o valor desse campo. Alguns dos nomes dos campos CEF ou LEEF não têm um nome correspondente aos nomes dos campos CSV. Nestes casos, se adicionar o seu próprio nome de variável no formato de registo personalizado no perfil do syslog, o analisador não o mapeia para o campo UDM.
Consulte as secções seguintes para obter uma referência de mapeamento de cada tipo de registo:
- Sistema
- Config
- Ameaça/incêndio florestal
- Tráfego
- ID do utilizador
- Correspondência de HIP
- Etiqueta de IP
- Desencriptação
- Túnel
- Autenticação
- URL
- Dados
- GlobalProtect
- Correlação
- GTP
- SCTP
- Auditoria
Sistema
A tabela seguinte apresenta os campos de registo do tipo de registo do sistema e os respetivos campos do UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave de etiqueta do Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Hora de receção (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|
| Número de série (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Tipo (type) | tipo (cabeçalho) | gato | metadata.product_event_type está definido como "%{type} - %{subtype}". | |
| Tipo de ameaça/conteúdo (subtipo) | subtipo (cabeçalho) | Subtipo | metadata.product_event_type está definido como "%{type} - %{subtype}". | |
| Hora de geração (time_generated ou cef-formatted-time_generated) | metadata.event_timestamp | |||
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| ID do evento (eventid) | gato | eventid | additional.fields.key e additional.fields.value.string_value | |
| Objeto (objeto) | fname | Nome do ficheiro | objeto | target.resource.name |
| Módulo (module) | flexString2 | Módulo | módulo | additional.fields.key e additional.fields.value.string_value |
| Gravidade (gravidade) | $number-of-severity(header) | Gravidade | security_result.severity e security_result.severity_details | |
| Descrição (opaca) | msg | msg | metadata.description | |
| principal_user_userid (este campo é extraído do campo msg) | principal.user.userid | |||
| principal_ip3 (este campo é extraído do campo msg) | principal.ip | |||
| Motivo (este campo é extraído do campo msg) | security_result.description | |||
| server_address (Este campo é extraído do campo msg.) | target.ip | |||
| server_profile (Este campo é extraído do campo msg.) | additional.fields.key e additional.fields.value.string_value | |||
| Número de sequência (seqno) | externalId | sequência | metadata.product_log_id | |
| Sinalizadores de ações (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_1 a dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome do sistema virtual (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nome do dispositivo (device_name) | dvchost | DeviceName | target.hostname | |
| Indicação de tempo de alta resolução (high_res_timestamp) | anOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value |
Configuração
A tabela seguinte apresenta os campos de registo do tipo de registo de configuração e os respetivos campos do UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave de etiqueta do Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Hora de receção (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|
| Número de série (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Tipo (type) | tipo (cabeçalho) | gato | metadata.product_event_type | |
| Tipo de ameaça/conteúdo (subtipo) | subtipo (cabeçalho) | metadata.product_event_type | ||
| Hora de geração (time_generated ou cef-formatted-time_generated) | metadata.event_timestamp | |||
| Anfitrião (host) | shost | src | principal.ip/hostname | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| Comando (cmd) | agir | msg | cmd | principal.process.command_line |
| Administrador (admin) | duser | usrName | principal.user.userid | |
| Cliente (cliente) | destinationServiceName | cliente | principal.application | |
| Resultado (resultado) | ID da assinatura (cabeçalho)(motivo) | Resultado | security_result.summary | |
| Caminho de configuração (caminho) | msg | ConfigurationPath | principal.process.command_line | |
| Detalhe antes da alteração (before_change_detail) | cs1 | BeforeChangeDetail | before_change_detail | target.resource.attribute.labels.key/value |
| Detalhe da alteração (after_change_detail) | cs2 | AfterChangeDetail | after_change_detail | target.resource.attribute.labels.key/value |
| Número de sequência (seqno) | externalId | sequência | metadata.product_log_id | |
| Sinalizadores de ações (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_1 a dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome do sistema virtual (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nome do dispositivo (device_name) | dvchost | DeviceName | target.hostname | |
| Grupo de dispositivos (dg_id) | PanOSFWDeviceGroup | target.asset.attribute.labels.key/value | dg_id | principal.asset.attribute.labels.key/value |
| Comentário de auditoria (comment) | PanOSPolicyAuditComment | comentário | additional.fields.key e additional.fields.value.string_value | |
| Indicação de tempo de alta resolução (high_res_timestamp) | additional.fields.key e additional.fields.value.string_value | |||
| Gravidade (gravidade) | number-of-severity(header) | security_result.severity e security_result.severity_details |
Ameaça/WildFire
A tabela seguinte lista os campos de registo do tipo de registo Threat/WildFire e os respetivos campos da UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave de etiqueta do Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Hora de receção (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|
| Número de série | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | tipo (cabeçalho) | gato | metadata.product_event_type | |
| Tipo de ameaça/conteúdo (subtipo) | cat/subtype (cabeçalho) | Subtipo | metadata.product_event_type | |
| Hora de geração (time_generated ou cef-formatted-time_generated) | metadata.event_timestamp | |||
| Endereço de origem (src) | src | src | principal.ip | |
| Endereço de destino (dst) | dst | dst | target.ip | |
| IP de origem da NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP de destino do NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Nome da regra (regra) | cs1 | RuleName | security_result.rule_name | |
| Utilizador de origem (srcuser) | suser | SourceUser / usrName | principal.user.userid | |
| Utilizador de destino (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplicação (app) | app | Aplicação | target.application | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona de origem (de) | cs4 | SourceZone | de | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Zona de destino (para) | cs5 | DestinationZone | a | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Interface de entrada (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Interface de saída (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Ação de registo (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key e additional.fields.value.string_value |
| ID da sessão (sessionid) | cn1 | SessionID | network.session_id | |
| Número de repetições (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Porta de origem (sport) | spt | srcPort | principal.port | |
| Porta de destino (dport) | dpt | dstPort | target.port | |
| Porta de origem NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Porta de destino NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Flags (flags) | flexString1 | Bandeiras | flags | additional.fields.key e additional.fields.value.string_value |
| Protocolo IP (proto) | proto | proto | network.ip_protocol | |
| Ação (action) | agir | ação | security_result.action_details
security_result.action |
|
| URL/nome do ficheiro (diversos) | pedido | Diversos | target.file.names (se o subtipo for "file", "virus", "wildfire-virus" ou "wildfire", o campo `misc` é mapeado para target.file.names) target.url (se o subtipo for "url", o campo "misc" é mapeado para target.url e target.hostname) |
|
| Nome da ameaça/conteúdo (threatid) | gato | ThreatID | security_result.threat_name | |
| Categoria (categoria) | cs2 | URLCategory | security_result.category_details | |
| Gravidade (gravidade) | number-of-severity(header) | Gravidade | security_result.severity e security_result.severity_details | |
| Direção (direction) | flexString2 | Direção | network.direction | |
| Número de sequência (seqno) | externalId | sequência | metadata.product_log_id | |
| Sinalizadores de ações (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| País de origem (srcloc) | SourceLocation | principal.location.country_or_region | ||
| País de destino (dstloc) | DestinationLocation | target.location.country_or_region | ||
| Tipo de conteúdo (contenttype) | ContentType | contenttype | additional.fields.key e additional.fields.value.string_value | |
| ID do PCAP (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key e additional.fields.value.string_value |
| Resumo do ficheiro (filedigest) | fileHash | FileDigest | target.file.sha1/md5/sha256 | |
| Nuvem (nuvem) | filePath | Google Cloud | nuvem | additional.fields.key e additional.fields.value.string_value |
| Índice de URL (url_idx) | URLIndex | url_idx | additional.fields.key e additional.fields.value.string_value | |
| Agente do utilizador (user_agent) | network.http.user_agent | |||
| Tipo de ficheiro (filetype) | fileType | FileType | target.file.mime_type | |
| X-Forwarded-For (xff) | principal.ip | |||
| Referenciador (referer) | network.http.referral_url | |||
| Remetente (remetente) | suid | Remetente | network.email.from | |
| Assunto (assunto) | msg | Assunto | network.email.subject | |
| Destinatário (destinatário) | duid | Destinatário | network.email.to | |
| ID do relatório (reportid) | oldFileId | ReportID | reportid | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_1 a dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome do sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nome do dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| UUID da VM de origem (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id | |
| UUID da VM de destino (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id | |
| Método HTTP (http_method) | RequestMethod | network.http.method | ||
| ID do túnel/IMSI (tunnel_id/imsi) | PanOSTunnelID | TunnelID | tunnel_id/imsi | additional.fields.key e additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag/imei) | PanOSMonitorTag | MonitorTag | monitortag/imei | additional.fields.key e additional.fields.value.string_value |
| ID da sessão principal (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Hora de início da sessão principal (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key e additional.fields.value.string_value |
| Tipo de túnel (túnel) | PanOSTunnelType | TunnelType | túnel | additional.fields.key e additional.fields.value.string_value |
| Categoria de ameaça (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| Versão do conteúdo (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key e additional.fields.value.string_value |
| ID de associação SCTP (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key e additional.fields.value.string_value | |
| ID do protocolo de carga útil (ppid) | PanOSPPID | ppid | additional.fields.key e additional.fields.value.string_value | |
| Cabeçalhos HTTP (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Lista de categorias de URLs (url_category_list) | PanOSURLCatList | url_category_list | additional.fields.key e additional.fields.value.string_value | |
| UUID da regra (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| Ligação HTTP/2 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| Nome do grupo de utilizadores dinâmico (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Endereço XFF (xff_ip) | PanXFFIP | principal.ip | ||
| Categoria do dispositivo de origem (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Perfil do dispositivo de origem (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modelo do dispositivo de origem (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Fornecedor do dispositivo de origem (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Família de SO do dispositivo de origem (src_osfamily) | PanSrcDeviceOS | src_osfamily | principal.platform | |
| Versão do SO do dispositivo de origem (src_osversion) | PanSrcDeviceOSv | principal.platform_version | ||
| Nome do anfitrião de origem (src_host) | PanSrcHostname | principal.hostname | ||
| Endereço MAC de origem (src_mac) | PanSrcMac | principal.mac | ||
| Categoria do dispositivo de destino (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Perfil do dispositivo de destino (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modelo do dispositivo de destino (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Fornecedor do dispositivo de destino (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Família de SO do dispositivo de destino (dst_osfamily) | PanDstDeviceOS | dst_osfamily | target.platform | |
| Versão do SO do dispositivo de destino (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Nome do anfitrião de destino (dst_host) | PanDstHostname | target.hostname | ||
| Endereço MAC de destino (dst_mac) | PanDstMac | target.mac | ||
| ID do contentor (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| Espaço de nomes do POD (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| Nome do POD (pod_name) | PanPODName | pod_name | target.resource.name | |
| Lista dinâmica externa de origem (src_edl) | PanSrcEDL | src_edl | additional.fields.key e additional.fields.value.string_value | |
| Lista dinâmica externa de destino (dst_edl) | PanDstEDL | dst_edl | additional.fields.key e additional.fields.value.string_value | |
| ID do anfitrião (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Número de série do dispositivo do utilizador (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| EDL de domínio (domain_edl) | PanDomainEDL | domain_edl | additional.fields.key e additional.fields.value.string_value | |
| Grupo de endereços dinâmicos de origem (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Grupo de endereços dinâmicos de destino (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| Hash parcial (partial_hash) | PanPartialHash | partial_hash | additional.fields.key e additional.fields.value.string_value | |
| Indicação de tempo de alta resolução (high_res timestamp) | PanTimeHighRes | Indicação de tempo de alta resolução | additional.fields.key e additional.fields.value.string_value | |
| Motivo (motivo) | PanReasonFilteringAction | motivo | security_result.summary | |
| Justificação (justification) | PanJustification | justificação | additional.fields.key e additional.fields.value.string_value | |
| Um tipo de serviço de divisão (nssai_sst) | PanASServiceType | nssai_sst | additional.fields.key e additional.fields.value.string_value | |
| Subcategoria da aplicação (subcategory_of_app) | subcategory_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Categoria de aplicações (category_of_app) | category_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia da aplicação (technology_of_app) | technology_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Risco da aplicação (risk_of_app) | risk_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Caraterística da aplicação (characteristic_of_app) | characteristic_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Contentor de aplicações (container_of_app) | container_of_app | additional.fields.key e additional.fields.value.string_value | ||
| SaaS de aplicação (is_saas_of_app) | is_saas_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Aplicação com túnel (tunneled_app) | additional.fields.key e additional.fields.value.string_value | |||
| Tipo de fluxo (flow_type) | additional.fields.key e additional.fields.value.string_value | |||
| Nome do cluster (cluster_name) | intermediary.resource.name | |||
| Estado sancionado da aplicação (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key e additional.fields.value.string_value |
Trânsito
A tabela seguinte apresenta os campos de registo do tipo de registo de tráfego e os respetivos campos da UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave de etiqueta do Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Hora de receção (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|
| Número de série (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | tipo (cabeçalho) | cat/Type | metadata.product_event_type | |
| Tipo de ameaça/conteúdo (subtipo) | subtipo (cabeçalho) | Subtipo | metadata.product_event_type | |
| Hora de geração (time_generated ou cef-formatted-time_generated) | iniciar | metadata.event_timestamp | ||
| Endereço de origem (src) | src | src | principal.ip | |
| Endereço de destino (dst) | dst | dst | target.ip | |
| IP de origem da NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP de destino do NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Nome da regra (regra) | cs1 | RuleName | security_result.rule_name | |
| Utilizador de origem (srcuser) | suser | SourceUser | principal.user.userid | |
| Utilizador de destino (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplicação (app) | app | Aplicação | target.application | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona de origem (de) | cs4 | SourceZone | de | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Zona de destino (para) | cs5 | DestinationZone | a | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Interface de entrada (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Interface de saída (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Ação de registo (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key e additional.fields.value.string_value |
| ID da sessão (sessionid) | cn1 | SessionID | network.session_id | |
| Número de repetições (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Porta de origem (sport) | spt | srcPort | principal.port | |
| Porta de destino (dport) | dpt | dstPort | target.port | |
| Porta de origem NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Porta de destino NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Flags (flags) | flexString1 | Bandeiras | flags | additional.fields.key e additional.fields.value.string_value |
| Protocolo IP (proto) | proto | proto | network.ip_protocol | |
| Ação (action) | agir | ação | security_result.action_details
security_result.action |
|
| Bytes (bytes) | flexNumber1 | totalBytes | bytes | additional.fields.key e additional.fields.value.string_value |
| Bytes enviados (bytes_sent) | em | srcBytes | network.sent_bytes | |
| Bytes recebidos (bytes_received) | fora | dstBytes | network.received_bytes | |
| Pacotes (packets) | cn2 | totalPackets | pacotes | additional.fields.key e additional.fields.value.string_value |
| Hora de início (início) | StartTime | iniciar | additional.fields.key e additional.fields.value.string_value | |
| Tempo decorrido (decorrido) | cn3 | ElapsedTime | decorrido | network.session_duration.seconds |
| Categoria (categoria) | cs2 | URLCategory | security_result.category / security_result.category_details | |
| Número de sequência (seqno) | externalId | sequência | metadata.product_log_id | |
| Sinalizadores de ações (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| País de origem (srcloc) | SourceLocation | principal.location.country_or_region | ||
| País de destino (dstloc) | DestinationLocation | target.location.country_or_region | ||
| Pacotes enviados (pkts_sent) | PanOSPacketsSent | srcPackets | pkts_sent | network.sent_packets |
| Pacotes recebidos (pkts_received) | PanOSPacketsReceived | dstPackets | pkts_received | network.received_packets |
| Motivo do fim da sessão (session_end_reason) | motivo | SessionEndReason | security_result.summary | |
| Hierarquia do grupo de dispositivos 1 (dg_hier_level_1 a dg_hier_level_4) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos 2 (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos3 (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome do sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nome do dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| Origem da ação (action_source) | gato | ActionSource | action_source | additional.fields.key e additional.fields.value.string_value |
| UUID da VM de origem (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id | |
| UUID da VM de destino (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id | |
| ID do túnel/IMSI (tunnelid/imsi) | PanOSTunnelID | TunnelID | tunnelid/imsi | additional.fields.key e additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag/imei) | PanOSMonitorTag | MonitorTag | monitortag/imei | additional.fields.key e additional.fields.value.string_value |
| ID da sessão principal (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Hora de início principal (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key e additional.fields.value.string_value |
| Tipo de túnel (túnel) | PanOSTunnelType | TunnelType | túnel | additional.fields.key e additional.fields.value.string_value |
| ID de associação SCTP (assoc_id) | PanOSSCTPAssocID | assoc_id | additional.fields.key e additional.fields.value.string_value | |
| Blocos SCTP (blocos) | PanOSSCTPChunks | pedaços | additional.fields.key e additional.fields.value.string_value | |
| SCTP Chunks Sent (chunks_sent) | PanOSSCTPChunkSent | chunks_sent | additional.fields.key e additional.fields.value.string_value | |
| SCTP Chunks Received (chunks_received) | PanOSSCTPChunksRcv | chunks_received | additional.fields.key e additional.fields.value.string_value | |
| UUID da regra (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| Ligação HTTP/2 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| Número de alterações rápidas da app (link_change_count) | PanLinkChange | link_change_count | additional.fields.key e additional.fields.value.string_value | |
| ID da política (policy_id) | PanPolicyID | policy_id | additional.fields.key e additional.fields.value.string_value | |
| Interruptores de links (link_switches) | PanLinkDetail | link_switches | additional.fields.key e additional.fields.value.string_value | |
| Cluster SD-WAN (sdwan_cluster) | PanSDWANCluster | sdwan_cluster | additional.fields.key e additional.fields.value.string_value | |
| Tipo de dispositivo SD-WAN (sdwan_device_type) | PanSDWANDevice | sdwan_device_type | additional.fields.key e additional.fields.value.string_value | |
| Tipo de cluster SD-WAN (sdwan_cluster_type) | PanSDWANClustype | sdwan_cluster_type | additional.fields.key e additional.fields.value.string_value | |
| Site SD-WAN (sdwan_site) | PanSDWANSite | sdwan_site | additional.fields.key e additional.fields.value.string_value | |
| Nome do grupo de utilizadores dinâmico (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | additional.fields.key e additional.fields.value.string_value | |
| Endereço XFF (xff_ip) | PanXFFIP | principal.ip | ||
| Categoria do dispositivo de origem (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Perfil do dispositivo de origem (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modelo do dispositivo de origem (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Fornecedor do dispositivo de origem (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Família de SO do dispositivo de origem (src_osfamily) | PanSrcDeviceOS | principal.platform | ||
| Versão do SO do dispositivo de origem (src_osversion) | PanSrcDeviceOSv | principal.asset.software.version | ||
| Nome do anfitrião de origem (src_host) | PanSrcHostname | principal.hostname | ||
| Endereço MAC de origem (src_mac) | PanSrcMac | principal.mac | ||
| Categoria do dispositivo de destino (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Perfil do dispositivo de destino (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modelo do dispositivo de destino (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Fornecedor do dispositivo de destino (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Família de SO do dispositivo de destino (dst_osfamily) | PanDstDeviceOS | dst_osfamily | target.platform | |
| Versão do SO do dispositivo de destino (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Nome do anfitrião de destino (dst_host) | PanDstHostname | target.hostname | ||
| Endereço MAC de destino (dst_mac) | PanDstMac | target.mac | ||
| ID do contentor (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| Espaço de nomes do POD (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| Nome do POD (pod_name) | PanPODName | pod_name | target.resource.name | |
| Lista dinâmica externa de origem (src_edl) | PanSrcEDL | src_edl | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Lista dinâmica externa de destino (dst_edl) | PanDstEDL | dst_edl | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| ID do anfitrião (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Número de série do dispositivo do utilizador (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| Grupo de endereços dinâmicos de origem (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Grupo de endereços dinâmicos de destino (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| Proprietário da sessão (session_owner) | PanHASessionOwner | session_owner | additional.fields.key e additional.fields.value.string_value | |
| Indicação de tempo de alta resolução (high_res_timestamp) | PanTimeHighRes | additional.fields.key e additional.fields.value.string_value | ||
| Um tipo de serviço de divisão (nsdsai_sst) | PanASServiceType | nsdsai_sst | additional.fields.key e additional.fields.value.string_value | |
| Um diferenciador de fatia (nsdsai_sd) | PanASServiceDiff | nsdsai_sd | additional.fields.key e additional.fields.value.string_value | |
| Subcategoria da aplicação (subcategory_of_app) | subcategory_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Categoria de aplicações (category_of_app) | category_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia da aplicação (technology_of_app) | technology_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Risco da aplicação (risk_of_app) | security_result.severity | |||
| Caraterística da aplicação (characteristic_of_app) | characteristic_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Contentor de aplicações (container_of_app) | container_of_app | additional.fields.key e additional.fields.value.string_value | ||
| SaaS de aplicação (is_saas_of_app) | is_saas_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Estado sancionado da aplicação (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Subcategoria da aplicação (subcategory_of_app) | subcategory_of_app1 | additional.fields.key e additional.fields.value.string_value | ||
| Gravidade (gravidade) | number-of-severity(header) | security_result.severity e security_result.severity_details |
User-ID
A tabela seguinte lista os campos de registo do tipo de registo user-id e os respetivos campos da UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave de etiqueta do Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Hora de receção (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|
| Número de série (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | tipo (cabeçalho) | gato | metadata.product_event_type | |
| Tipo de ameaça/conteúdo (subtipo) | subtipo (cabeçalho) | Subtipo | metadata.product_event_type | |
| Hora de geração (time_generated ou cef-formatted-time_generated) | metadata.event_timestamp | |||
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| IP de origem (ip) | src | src | principal.ip | |
| Utilizador (user) | duser | usrName | target.user.userid
target.administrative_domain target.user.email_addresses |
|
| Nome da origem de dados (datasourcename) | cs4 | DataSourceName | datasourcename | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| ID do evento (eventid) | EventID | eventid | additional.fields.key e additional.fields.value.string_value | |
| Número de repetições (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Limite de tempo limite (tempo limite) | cn3 | TimeoutThreshold | tempo limite excedido | additional.fields.key e additional.fields.value.string_value |
| Porta de origem (beginport) | spt | srcPort | principal.port | |
| Porta de destino (endport) | dpt | dstPort | target.port | |
| Origem de dados | cs5 | DataSource | origem de dados | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Tipo de origem de dados (datasourcetype) | cs6 | DataSourceType | datasourcetype | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Número de sequência (seqno) | externalId | sequência | metadata.product_log_id | |
| Sinalizadores de ações (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome do sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nome do dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| ID do sistema virtual (vsys_id) | cn2 | VirtualSystemID | intermediary.resource.product_object_id | |
| Tipo de fator (factortype) | cs1 | FactorType | factortype | additional.fields.key e additional.fields.value.string_value |
| Tempo de conclusão da fatorização (factorcompletiontime) | fim | FactorCompletionTime | factorcompletiontime | additional.fields.key e additional.fields.value.string_value |
| Número do fator (factorno) | cn1 | FactorNumber | factorno | additional.fields.key e additional.fields.value.string_value |
| User Group Flags (ugflags) | PanOSUGFlags | ugflags | additional.fields.key e additional.fields.value.string_value | |
| Utilizador por origem (userbysource) | PanOSUserBySource | target.user.userid
target.administrative_domain target.user.email_addresses |
||
| Indicação de tempo de alta resolução (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value | ||
| Origem de dados (origindatasource) | additional.fields.key e additional.fields.value.string_value | |||
| Nome do cluster (cluster_name) | principal.resource.name | |||
| Gravidade (gravidade) | number-of-severity(header) | security_result.severity e security_result.severity_details |
Correspondência de HIP
A tabela seguinte apresenta os campos de registo do tipo de registo de correspondência de HIP e os respetivos campos de UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave de etiqueta do Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Hora de receção (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|
| Número de série (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Tipo (type) | tipo (cabeçalho) | gato | metadata.product_event_type | |
| Tipo de ameaça/conteúdo (subtipo) | subtipo (cabeçalho) | Subtipo | ||
| Hora de geração (time_generated ou cef-formatted-time_generated) | iniciar | startTime | metadata.event_timestamp | |
| Utilizador de origem (srcuser) | suser | usrName | principal.user.userid | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| Nome do computador (machinename) | shost | identHostName | principal.hostname | |
| Sistema operativo (os) | cs2 | SO | principal.asset.platform_software.platform | |
| Endereço de origem (src) | src | identsrc | principal.ip | |
| HIP (matchname) | gato | HIP | matchname | target.resource.attribute.labels.key/value additional.fields.key e additional.fields.value.string_value |
| Número de repetições (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Tipo de HIP (matchtype) | ID da classe de eventos do dispositivo (cabeçalho) | HIPType | matchtype | target.resource.attribute.labels.key/value additional.fields.key e additional.fields.value.string_value |
| Número de sequência (seqno) | externalId | sequência | metadata.product_log_id | |
| Sinalizadores de ações (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome do sistema virtual (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nome do dispositivo (device_name) | dvchost | DeviceName | target.hostname | |
| ID do sistema virtual (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id | |
| Endereço do sistema IPv6 (srcipv6) | c6a2 | srcipv6 | principal.asset.ip | |
| ID do anfitrião (hostid) | PanOSHostID | principal.asset.asset_id | ||
| Número de série do dispositivo do utilizador (serialnumber) | PanOSEndpointSerialNumber | principal.asset.hardware.serial_number | ||
| Endereço MAC do dispositivo (mac) | PanOSEndpointMac | principal.asset.mac | ||
| Indicação de tempo de alta resolução (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value | ||
| Nome do cluster (cluster_name) | principal.resource.name | |||
| Gravidade (gravidade) | number-of-severity(header) | security_result.severity e security_result.severity_details |
Etiqueta de IP
A tabela seguinte apresenta os campos de registo do tipo de registo de etiquetas de IP e os respetivos campos da UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave de etiqueta do Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Hora de receção (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|
| Número de série (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number | |
| Tipo (type) | tipo (cabeçalho) | gato | metadata.product_event_type | |
| Tipo de ameaça/conteúdo (subtipo) | subtipo (cabeçalho) | Subtipo | metadata.product_event_type | |
| Hora de geração (time_generated ou cef-formatted-time_generated) | GenerateTime | metadata.event_timestamp | ||
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | target.asset.attribute.labels.key/value |
| IP de origem (ip) | src | src | principal.ip | |
| Nome da etiqueta (tag_name) | PanOSTagName | TagName | tag_name | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| ID do evento (event_id) | PanOSEventID | EventID | event_id | additional.fields.key e additional.fields.value.string_value |
| Número de repetições (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Limite de tempo (timeout) | PanOSTimeout | TimeoutThreshold | tempo limite excedido | additional.fields.key e additional.fields.value.string_value |
| Nome da origem de dados (datasourcename) | PanOSDataSourceName | DataSourceName | datasourcename | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Tipo de origem de dados (datasource_type) | PanOSDataSourceType | DataSource | datasource_type | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Subtipo da origem de dados (datasource_subtype) | PanOSDataSourceSubType | DataSourceType | datasource_subtype | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Número de sequência (seqno) | externalId | sequência | metadata.product_log_id | |
| Sinalizadores de ações (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome do sistema virtual (vsys_name) | PanOsVsysName | vSrcName | target.asset.attribute.labels.key/value | |
| Nome do dispositivo (device_name) | dvchost | DeviceName | target.hostname | |
| ID do sistema virtual (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id | |
| Indicação de tempo de alta resolução (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value | ||
| Gravidade (gravidade) | number-of-severity(header) | security_result.severity e security_result.severity_details | ||
| Nome do cluster (cluster_name) | principal.resource.name |
Desencriptação
A tabela seguinte apresenta os campos de registo do tipo de registo de desencriptação e os respetivos campos do UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave de etiqueta do Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Hora de receção (receive_time ou cef-formatted-receive_time) | rt | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
||
| Número de série (serial) | PanOSDeviceSN | intermediary.asset.hardware.serial_number | ||
| Tipo (type) | tipo (cabeçalho) | metadata.product_event_type | ||
| Tipo de ameaça/conteúdo (subtipo) | subtipo (cabeçalho) | metadata.product_event_type | ||
| Versão da configuração (config_ver) | PanOSConfigVersion | config_ver | additional.fields.key e additional.fields.value.string_value | |
| Hora de geração (time_generated) | PanOSLogTimeStamp | metadata.event_timestamp | ||
| Endereço de origem (src) | src | principal.ip | ||
| Endereço de destino (dst) | dst | target.ip | ||
| IP de origem da NAT (natsrc) | sourceTranslatedAddress | principa.nat_ip | ||
| IP de destino do NAT (natdst) | destinationTranslatedAddress | target.nat_ip | ||
| Regra (regra) | cs1 | security_result.rule_name | ||
| Utilizador de origem (srcuser) | suser | principal.user.userid | ||
| Utilizador de destino (dstuser) | duser | target.user.userid | ||
| Aplicação (app) | app | network.application_protocol | ||
| Sistema virtual (vsys) | cs3 | vsys | intermediary.asset.attribute.labels.key/value | |
| Zona de origem (de) | cs4 | de | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Zona de destino (para) | cs5 | a | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Interface de entrada (inbound_if) | deviceInboundInterface | inbound_if | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Interface de saída (outbound_if) | deviceOutboundInterface | outbound_if | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Ação de registo (logset) | cs6 | logset | additional.fields.key e additional.fields.value.string_value | |
| Hora de registo (time_received) | PanOSTimeReceivedManagementPlane | - | ||
| ID da sessão (sessionid) | cn1 | network.session_id | ||
| Número de repetições (repeatcnt) | PanOSCountOfRepeats/RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value | |
| Porta de origem (sport) | spt | principal.port | ||
| Porta de destino (dport) | dpt | target.port | ||
| Porta de origem NAT (natsport) | sourceTranslatedPort | principal.nat_port | ||
| Porta de destino NAT (natdport) | destinationTranslatedPort | target.nat_port | ||
| Flags (flags) | flexString1 | flags | additional.fields.key e additional.fields.value.string_value | |
| Protocolo IP (proto) | proto | network.ip_protocol | ||
| Ação (action) | agir | security_result.action_details
security_result.action |
||
| Túnel (túnel) | PanOSTunnel | túnel | additional.fields.key e additional.fields.value.string_value | |
| UUID da VM de origem (src_uuid) | PanOSSourceUUID | principal.asset.product_object_id | ||
| UUID da VM de destino (dst_uuid) | PanOSDestinationUUID | target.asset.product_object_id | ||
| UUID da regra (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| Fase de cliente para firewall (hs_stage_c2f) | PanOSClientToFirewall | hs_stage_c2f | additional.fields.key e additional.fields.value.string_value | |
| Stage for Firewall to Server (hs_stage_f2s) | PanOSFirewallToServer | hs_stage_f2s | additional.fields.key e additional.fields.value.string_value | |
| Versão de TLS (tls_version) | PanOSTLSVersion | network.tls.version | ||
| Algoritmo de troca de chaves (tls_keyxchg) | PanOSTLSKeyExchange | tls_keyxchg | additional.fields.key e additional.fields.value.string_value | |
| Algoritmo de encriptação (tls_enc) | PanOSTLSEncryptionAlgorithm | tls_enc | additional.fields.key e additional.fields.value.string_value | |
| Algoritmo hash (tls_auth) | PanOSTLSAuth | tls_auth | additional.fields.key e additional.fields.value.string_value | |
| Nome da política (policy_name) | PanOSPolicyName | policy_name | additional.fields.key e additional.fields.value.string_value | |
| Curva elíptica (ec_curve) | PanOSEllipticCurve | network.tls.curve | ||
| Índice de erro (err_index) | PanOSErrorIndex | err_index | additional.fields.key e additional.fields.value.string_value | |
| Estado de acesso de superutilizador (root_status) | PanOSRootStatus | root_status | additional.fields.key e additional.fields.value.string_value | |
| Estado da cadeia (chain_status) | PanOSChainStatus | chain_status | additional.fields.key e additional.fields.value.string_value | |
| Tipo de proxy (proxy_type) | PanOSProxyType | proxy_type | additional.fields.key e additional.fields.value.string_value | |
| Número de série do certificado (cert_serial) | PanOSCertificateSerial | network.tls.server.certificate.serial | ||
| Impressão digital do certificado (impressão digital) | PanOSFingerprint | network.tls.server.certificate.md5/sha1/sha256 | ||
| Data de início do certificado (notbefore) | PanOSTimeNotBefore | network.tls.server.certificate.not_before | ||
| Data de fim do certificado (notafter) | PanOSTimeNotAfter | network.tls.server.certificate.not_after | ||
| Versão do certificado (cert_ver) | PanOSCertificateVersion | network.tls.server.certificate.version | ||
| Tamanho do certificado (cert_size) | PanOSCertificateSize | cert_size | additional.fields.key e additional.fields.value.string_value | |
| Comprimento do nome comum (cn_len) | PanOSCommonNameLength | cn_len | additional.fields.key e additional.fields.value.string_value | |
| Comprimento do nome comum do emissor (issuer_len) | PanOSIssuerNameLength | issuer_len | additional.fields.key e additional.fields.value.string_value | |
| Comprimento do nome comum da raiz (rootcn_len) | PanOSRootCNLength | rootcn_len | additional.fields.key e additional.fields.value.string_value | |
| Comprimento do SNI (sni_len) | PanOSSNILength | sni_len | additional.fields.key e additional.fields.value.string_value | |
| Sinalizadores de certificados (cert_flags) | PanOSCertificateFlags | cert_flags | additional.fields.key e additional.fields.value.string_value | |
| Nome comum do requerente (cn) | PanOSCommonName | cn | additional.fields.key e additional.fields.value.string_value | |
| Nome comum do emissor (issuer_cn) | PanOSIssuerCommonName | network.tls.server.certificate.issuer | ||
| Nome comum da raiz (root_cn) | PanOSRootCommonName | root_cn | additional.fields.key e additional.fields.value.string_value | |
| Indicação de Nome do Servidor
(sni) |
network.tls.client.server_name | |||
| Erro (erro) | PanOSErrorMessage | erro | additional.fields.key e additional.fields.value.string_value | |
| ID do contentor (container_id) | PanOSContainerID | container_id | intermediary.resource.product_object_id | |
| Espaço de nomes do POD (pod_namespace) | PanOSContainerNameSpace | pod_namespace | target.resource.attribute.labels.key/value additional.fields.key e additional.fields.value.string_value |
|
| Nome do POD (pod_name) | PanOSContainerName | pod_name | target.resource.name | |
| Lista dinâmica externa de origem (src_edl) | PanOSSourceEDL | src_edl | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Lista dinâmica externa de destino (dst_edl) | PanOSDestinationEDL | dst_edl | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Grupo de endereços dinâmicos de origem (src_dag) | PanOSSourceDynamicAddressGroup | principal.group.group_display_name | ||
| Grupo de endereços dinâmicos de destino (dst_dag) | PanOSDestinationDynamicAddressGroup | target.group.group_display_name | ||
| Indicação de tempo de alta resolução (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value | ||
| Categoria do dispositivo de origem (src_category) | PanOSSourceDeviceCategory | src_category | principal.asset.category | |
| Perfil do dispositivo de origem (src_profile) | PanOSSourceDeviceProfile | src_profile | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modelo do dispositivo de origem (src_model) | PanOSSourceDeviceModel | src_model | principal.asset.hardware.model | |
| Fornecedor do dispositivo de origem (src_vendor) | PanOSSourceDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Família de SO do dispositivo de origem (src_osfamily) | PanOSSourceDeviceOSFamily | principal.platform | ||
| Versão do SO do dispositivo de origem (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | ||
| Nome do anfitrião de origem (src_host) | PanOSSourceDeviceHost | principal.hostname | ||
| Endereço MAC de origem (src_mac) | PanOSSourceDeviceMac | principal.mac | ||
| Categoria do dispositivo de destino (dst_category) | PanOSDestinationDeviceCategory | dst_category | target.asset.category | |
| Perfil do dispositivo de destino (dst_profile) | PanOSDestinationDeviceProfile | dst_profile | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modelo do dispositivo de destino (dst_model) | PanOSDestinationDeviceModel | dst_model | target.asset.hardware.model | |
| Fornecedor do dispositivo de destino (dst_vendor) | PanOSDestinationDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Família de SO do dispositivo de destino (dst_osfamily) | PanOSDestinationDeviceOSFamily | dst_osfamily | target.platform | |
| Versão do SO do dispositivo de destino (dst_osversion) | PanOSDestinationDeviceOSVersion | target.platform_version | ||
| Nome do anfitrião de destino (dst_host) | PanOSDestinationDeviceHost | target.hostname | ||
| Endereço MAC de destino (dst_mac) | PanOSDestinationDeviceMac | target.mac | ||
| Número de sequência (seqno) | PanOSLogTypeSeqNo | metadata.product_log_id | ||
| Sinalizadores de ações (actionflags) | PanOSActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value | |
| Hierarquia do grupo de dispositivos (dg_hier_level_1) | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value | |
| Hierarquia do grupo de dispositivos (dg_hier_level_2) | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value | |
| Hierarquia do grupo de dispositivos (dg_hier_level_3) | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value | |
| Hierarquia do grupo de dispositivos (dg_hier_level_4) | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value | |
| Nome do sistema virtual (vsys_name) | intermediary.asset.attribute.labels.key/value | |||
| Nome do dispositivo (device_name) | intermediary.hostname | |||
| ID do sistema virtual (vsys_id) | intermediary.resource.product_object_id | |||
| Subcategoria da aplicação (subcategory_of_app) | subcategory_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Categoria de aplicações (category_of_app) | category_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia da aplicação (technology_of_app) | technology_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Risco da aplicação (risk_of_app) | security_result.severity | |||
| Caraterística da aplicação (characteristic_of_app) | characteristic_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Contentor de aplicações (container_of_app) | container_of_app | additional.fields.key e additional.fields.value.string_value | ||
| SaaS de aplicação (is_saas_of_app) | is_saas_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Estado sancionado da aplicação (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Gravidade (gravidade) | number-of-severity(header) | security_result.severity e security_result.severity_details |
Túnel
A tabela seguinte apresenta os campos de registo do tipo de registo de túnel e os respetivos campos do UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave de etiqueta do Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Hora de receção (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|
| Número de série (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | tipo (cabeçalho) | gato | metadata.product_event_type | |
| Tipo de ameaça/conteúdo (subtipo) | subtipo (cabeçalho) | Subtipo | metadata.product_event_type | |
| Hora de geração (time_generated ou cef-formatted-time_generated) | metadata.event_timestamp | |||
| Endereço de origem (src) | src | src | principal.ip | |
| Endereço de destino (dst) | dst | dst | target.ip | |
| IP de origem da NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP de destino do NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Nome da regra (regra) | cs1 | RuleName | security_result.rule_name | |
| Utilizador de origem (srcuser) | suser | SourceUser / usrName | principal.user.userid | |
| Utilizador de destino (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplicação (app) | app | Aplicação | network.application_protocol | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona de origem (de) | cs4 | SourceZone | de | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Zona de destino (para) | cs5 | DestinationZone | a | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Interface de entrada (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Interface de saída (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Ação de registo (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key e additional.fields.value.string_value |
| ID da sessão (sessionid) | cn1 | SessionID | network.session_id | |
| Número de repetições (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Porta de origem (sport) | spt | srcPort | principal.port | |
| Porta de destino (dport) | dpt | dstPort | target.port | |
| Porta de origem NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Porta de destino NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Flags (flags) | flexString1 | Bandeiras | flags | additional.fields.key e additional.fields.value.string_value |
| Protocolo IP (proto) | proto | proto | network.ip_protocol | |
| Ação (action) | agir | ação | security_result.action_details
security_result.action |
|
| Gravidade (gravidade) | number-of-severity(header) | security_result.severity e security_result.severity_details | ||
| Número de sequência (seqno) | externalId | sequência | metadata.product_log_id | |
| Sinalizadores de ações (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Localização da origem (srcloc) | principal.location.country_or_region | |||
| Localização de destino (dstloc) | target.location.country_or_region | |||
| Hierarquia do grupo de dispositivos (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome do sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nome do dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| ID do túnel (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key e additional.fields.value.string_value |
| Etiqueta de monitorização (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key e additional.fields.value.string_value |
| ID da sessão principal (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Hora de início principal (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key e additional.fields.value.string_value |
| Tipo de túnel (túnel) | cs2 | TunnelType | túnel | additional.fields.key e additional.fields.value.string_value |
| Bytes (bytes) | flexNumber1 | totalBytes | bytes | additional.fields.key e additional.fields.value.string_value |
| Bytes enviados (bytes_sent) | em | srcBytes | network.sent_bytes | |
| Bytes recebidos (bytes_received) | fora | dstBytes | network.received_bytes | |
| Pacotes (packets) | cn2 | totalPackets | pacotes | additional.fields.key e additional.fields.value.string_value |
| Pacotes enviados (pkts_sent) | PanOSPacketsSent | srcPackets | pkts_sent | network.sent_packets |
| Pacotes recebidos (pkts_received) | PanOSPacketsReceived | dstPackets | pkts_received | network.received_packets |
| Encapsulamento máximo (max_encap) | flexNumber2 | MaximumEncapsulation | max_encap | additional.fields.key e additional.fields.value.string_value |
| Protocolo desconhecido (unknown_proto) | cfp1 | UnknownProtocol | unknown_proto | additional.fields.key e additional.fields.value.string_value |
| Verificação rigorosa (strict_check) | cfp2 | StrictChecking | strict_check | additional.fields.key e additional.fields.value.string_value |
| Fragmento de túnel (tunnel_fragment) | PanOSTunnelFragment | TunnelFragment | tunnel_fragment | additional.fields.key e additional.fields.value.string_value |
| Sessões criadas (sessions_created) | cfp3 | SessionsCreated | sessions_created | additional.fields.key e additional.fields.value.string_value |
| Sessões fechadas (sessions_closed) | cfp4 | SessionsClosed | sessions_closed | additional.fields.key e additional.fields.value.string_value |
| Motivo do fim da sessão (session_end_reason) | motivo | SessionEndReason | security_result.summary | |
| Origem da ação (action_source) | gato | ActionSource | action_source | additional.fields.key e additional.fields.value.string_value |
| Hora de início (início) | startTime | iniciar | additional.fields.key e additional.fields.value.string_value | |
| Tempo decorrido (decorrido) | cn3 | ElapsedTime | decorrido | network.session_duration.seconds |
| Regra de inspeção de túnel (tunnel_insp_rule) | PanOSTunneInspectionRule | security_result.rule_name = "Tunnel Inspection Rule: %{PanOSTunnelInspectionRule}" | ||
| IP do utilizador remoto (remote_user_ip) | PanOSRmtUserIP | principal.ip | ||
| ID do utilizador remoto (remote_user_id) | PanOSRmtUserID | remote_user_id | principal.user.userid | |
| UUID da regra de segurança (rule_uuid) | PanOSRuleUUID | security_result.rule_id | ||
| ID do PCAP (pcap_id) | PanOSPcapID | pcap_id | additional.fields.key e additional.fields.value.string_value | |
| Nome do grupo de utilizadores dinâmico (dynusergroup_name) | PanDynamicUsrgrp | principal.group.group_display_name | ||
| Lista dinâmica externa de origem (src_edl) | PanOSSourceEDL | src_edl | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Lista dinâmica externa de destino (dst_edl) | PanOSDestinationEDL | dst_edl | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Indicação de tempo de alta resolução (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value | ||
| Um diferenciador de fatia (nssai_sd) | nssai_sd | additional.fields.key e additional.fields.value.string_value | ||
| Um tipo de serviço de fatia (nssai_sd) | nssai_sd1 | additional.fields.key e additional.fields.value.string_value | ||
| ID da sessão de PDU (pdu_session_id) | pdu_session_id | additional.fields.key e additional.fields.value.string_value | ||
| Subcategoria da aplicação (subcategory_of_app) | subcategory_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Categoria de aplicações (category_of_app) | category_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia da aplicação (technology_of_app) | technology_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Risco da aplicação (risk_of_app) | risk_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Caraterística da aplicação (characteristic_of_app) | characteristic_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Contentor de aplicações (container_of_app) | container_of_app | additional.fields.key e additional.fields.value.string_value | ||
| SaaS de aplicação (is_saas_of_app) | is_saas_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Aplicação com túnel (tunneled_app) | additional.fields.key e additional.fields.value.string_value | |||
| Descarregado (descarregado) | additional.fields.key e additional.fields.value.string_value | |||
| Tipo de fluxo (flow_type) | additional.fields.key e additional.fields.value.string_value | |||
| Nome do cluster (cluster_name) |
principal.resource.name |
|||
| Estado sancionado da aplicação (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key e additional.fields.value.string_value |
Autenticação
A tabela seguinte lista os campos de registo do tipo de registo de autenticação e os respetivos campos do UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave de etiqueta do Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Hora de receção (receive_time ou cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|
| Número de série (serial) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | tipo (cabeçalho) | gato | metadata.product_event_type | |
| Tipo de ameaça/conteúdo (subtipo) | subtipo (cabeçalho) | Subtipo | metadata.product_event_type | |
| Hora de geração (time_generated ou cef-formatted-time_generated) | metadata.event_timestamp | |||
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| IP de origem (ip) | src | src | principal.ip | |
| Utilizador (user) | duser | usrName | target.user.userid | |
| Normalizar utilizador (normalize_user) | cs2 | NormalizeUser | target.user.user_display_name | |
| Objeto (objeto) | fname | ObjectName | objeto | target.resource.name |
| Política de autenticação (authpolicy) | cs4 | AuthPolicy | authpolicy | additional.fields.key e additional.fields.value.string_value |
| Número de repetições (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| ID de autenticação (authid) | cn2 | AuthenticationID | authid | additional.fields.key e additional.fields.value.string_value |
| Fornecedor (fornecedor) | flexString2 | Fornecedor | fornecedor | additional.fields.key e additional.fields.value.string_value |
| Ação de registo (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key e additional.fields.value.string_value |
| Perfil do servidor (serverprofile) | cs1 | ServerProfile | serverprofile | additional.fields.key e additional.fields.value.string_value |
| Descrição (desc.) | PanOSDesc | AdditionalAuthInfo | security_result.description | |
| Tipo de cliente (clienttype) | cs5 | ClientType | clienttype | additional.fields.key e additional.fields.value.string_value |
| Tipo de evento (evento) | msg | msg | extensions.auth.auth_details | |
| Número do fator (factorno) | cn1 | FactorNumber | factorno | additional.fields.key e additional.fields.value.string_value |
| Número de sequência (seqno) | externalId | sequência | metadata.product_log_id | |
| Sinalizadores de ações (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Hierarquia do grupo de dispositivos (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome do sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nome do dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| ID do sistema virtual (vsys_id) | intermediary.resource.product_object_id | |||
| Protocolo de autenticação (authproto) | authproto | additional.fields.key e additional.fields.value.string_value | ||
| UUID da regra (rule_uuid) | PanOSRuleUUID/RuleUUID | security_result.rule_id | ||
| Indicação de tempo de alta resolução (high_res _timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value | ||
| Categoria do dispositivo de origem (src_category) | PanOSSourceDeviceCategory | src_category | principal.asset.category | |
| Perfil do dispositivo de origem (src_profile) | PanOSSourceDeviceProfile | src_profile | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modelo do dispositivo de origem (src_model) | PanOSSourceDeviceModel | src_model | principal.asset.hardware.model | |
| Fornecedor do dispositivo de origem (src_vendor) | PanOSSourceDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Família de SO do dispositivo de origem (src_osfamily) | PanOSSourceDeviceOSFamily | principal.asset.platform_software.platform principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Versão do SO do dispositivo de origem (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | ||
| Nome do anfitrião de origem (src_host) | PanOSSourceHostname | principal.hostname | ||
| Endereço MAC de origem (src_mac) | PanOSSourceMac | principal.asset.mac | ||
| Região (região) | PanOSTrafficOriginRegion | principal.location.country_or_region | ||
| Agente do utilizador (user_agent) | PanOSHTTPUserAgent | network.http.user_agent | ||
| ID da sessão(sessionid) | PanOSTrafficSessionID | network.session_id | ||
| Gravidade (gravidade) | number-of-severity(header) | security_result.severity e security_result.severity_details | ||
| Nome do cluster (cluster_name) | principal.resource.name |
URL
A tabela seguinte apresenta os campos de registo do tipo de registo de URL e os respetivos campos da UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave de etiqueta do Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Hora de receção (cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|
| N.º de série (série) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | tipo (cabeçalho) | gato | metadata.product_event_type | |
| Tipo de ameaça/conteúdo (subtipo) | subtipo (cabeçalho) | Subtipo | metadata.product_event_type | |
| Hora de geração | metadata.event_timestamp | |||
| Endereço de origem (src) | src | src | principal.ip | |
| Endereço de destino (dst) | dst | dst | target.ip | |
| IP de origem da NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP de destino do NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Regra (regra) | cs1 | RuleName | security_result.rule_name | |
| Utilizador de origem (srcuser) | suser | SourceUser | principal.user.userid | |
| Utilizador de destino (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplicação (app) | app | Aplicação | network.application_protocol | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona de origem (de) | cs4 | SourceZone | de | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Zona de destino (para) | cs5 | DestinationZone | a | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Interface de entrada (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Interface de saída (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Ação de registo (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key e additional.fields.value.string_value |
| Tempo registado | time_logged | additional.fields.key e additional.fields.value.string_value | ||
| ID da sessão (sessionid) | cn1 | SessionID | network.session_id | |
| Número de repetições (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Porta de origem (sport) | spt | srcPort | principal.port | |
| Porta de destino (dport) | dpt | dstPort | target.port | |
| Porta de origem NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Porta de destino NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Flags (flags) | flexString1 | Bandeiras | flags | additional.fields.key e additional.fields.value.string_value |
| Protocolo IP (proto) | proto | proto | network.ip_protocol | |
| Ação (action) | agir | ação | security_result.action_details
security_result.action |
|
| URL/nome do ficheiro (diversos) | Diversos | target.file.names
target.url |
||
| Nome da ameaça/conteúdo (threatid) | gato | ThreatID | security_result.threat_id | |
| Categoria (categoria) | cs2 | URLCategory | categoria | security_result.category_details |
| Gravidade (gravidade) | number-of-severity (cabeçalho) | Gravidade | security_result.severity
security_result.severity_details |
|
| Direção (direction) | flexString2 | Direção | network.direction | |
| Número de sequência (seqno) | externalId | sequência | metadata.product_log_id | |
| Sinalizadores de ações (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| País de origem (srcloc) | SourceLocation | principal.location.country_or_region | ||
| País de destino (dstloc) | DestinationLocation | target.location.country_or_region | ||
| contenttype (contenttype) | requestContext | ContentType | contenttype | additional.fields.key e additional.fields.value.string_value |
| pcap_id (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key e additional.fields.value.string_value |
| filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | ||
| nuvem (nuvem) | Google Cloud | nuvem | additional.fields.key e additional.fields.value.string_value | |
| url_idx (url_idx) | URLIndex | url_idx | additional.fields.key e additional.fields.value.string_value | |
| user_agent (user_agent) | requestClientApplication | UserAgent | network.http.user_agent | |
| filetype (filetype) | target.file.mime_type | |||
| xff (xff) | PanOSXForwarderfor | identSrc | xff | principal.ip |
| Referenciador (referer) | PanOSReferer | Referenciador | network.http.referral_url | |
| remetente (remetente) | network.email.from | |||
| subject (subject) | Assunto | network.email.subject | ||
| destinatário (destinatário) | network.email.to | |||
| reportid (reportid) | reportid | additional.fields.key e additional.fields.value.string_value | ||
| Nível 1 da hierarquia de grupos de anúncios (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Nível 2 da hierarquia de grupos de destino (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Nível 3 da hierarquia de grupos de destino (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Nível 4 da hierarquia de grupos de anúncios (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome do sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nome do dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| file_url (file_url) | target.url | |||
| UUID da VM de origem (src_uuid) | SrcUUID | principal.asset.product_object_id | ||
| UUID da VM de destino (dst_uuid) | DstUUID | target.asset.product_object_id | ||
| http_method (http_method) | requestMethod | RequestMethod | network.http.method | |
| ID do túnel/IMSI (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key e additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key e additional.fields.value.string_value |
| ID da sessão principal (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Hora de início da sessão principal (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key e additional.fields.value.string_value |
| Túnel (túnel) | PanOSTunnelType | TunnelType | túnel | additional.fields.key e additional.fields.value.string_value |
| thr_category (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| contentver (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key e additional.fields.value.string_value |
| sig_flags (sig_flags) | sig_flags | additional.fields.key e additional.fields.value.string_value | ||
| ID de associação SCTP (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key e additional.fields.value.string_value | |
| ID do protocolo de carga útil (ppid) | PanOSPPID | ppid | additional.fields.key e additional.fields.value.string_value | |
| http_headers (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Lista de categorias de URLs (url_category_list) | PanOSURLCatList | url_category_list | additional.fields.key e additional.fields.value.string_value | |
| UUID da regra (rule_uuid) | PanOSRuleUUID | rule_uuid | security_result.rule_id | |
| Ligação HTTP/2 (http2_connection) | PanOSHTTP2Con | http2_connection | network.application_protocol_version | |
| dynusergroup_name (dynusergroup_name) | PanDynamicUsrgrp | dynusergroup_name | additional.fields.key e additional.fields.value.string_value | |
| Endereço XFF (xff_ip) | PanXFFIP | principal.ip | ||
| Categoria do dispositivo de origem (src_category) | PanSrcDeviceCat | src_category | principal.asset.category | |
| Perfil do dispositivo de origem (src_profile) | PanSrcDeviceProf | src_profile | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modelo do dispositivo de origem (src_model) | PanSrcDeviceModel | src_model | principal.asset.hardware.model | |
| Fornecedor do dispositivo de origem (src_vendor) | PanSrcDeviceVendor | src_vendor | principal.asset.hardware.manufacturer | |
| Família de SO do dispositivo de origem (src_osfamily) | PanSrcDeviceOS | principal.platform | ||
| Versão do SO do dispositivo de origem (src_osversion) | PanSrcDeviceOSv | principal.platform_version | ||
| Nome do anfitrião de origem (src_host) | PanSrcHostname | src_host | principal.hostname | |
| Endereço MAC de origem (src_mac) | PanSrcMac | principal.mac | ||
| Categoria do dispositivo de destino (dst_category) | PanDstDeviceCat | dst_category | target.asset.category | |
| Perfil do dispositivo de destino (dst_profile) | PanDstDeviceProf | dst_profile | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Modelo do dispositivo de destino (dst_model) | PanDstDeviceModel | dst_model | target.asset.hardware.model | |
| Fornecedor do dispositivo de destino (dst_vendor) | PanDstDeviceVendor | dst_vendor | target.asset.hardware.manufacturer | |
| Família de SO do dispositivo de destino (dst_osfamily) | PanDstDeviceOS | target.platform | ||
| Versão do SO do dispositivo de destino (dst_osversion) | PanDstDeviceOSv | target.platform_version | ||
| Nome do anfitrião de destino (dst_host) | PanPODNamespace | target.hostname | ||
| Endereço MAC de destino (dst_mac) | PanDstMac | target.mac | ||
| ID do contentor (container_id) | PanContainerName | container_id | intermediary.resource.product_object_id | |
| Espaço de nomes do POD (pod_namespace) | PanPODNamespace | pod_namespace | target.resource.attribute.labels.key/value | |
| Nome do POD (pod_name) | PanPODName | pod_name | target.resource.name | |
| Lista dinâmica externa de origem (src_edl) | PanSrcEDL | src_edl | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
|
| Lista dinâmica externa de destino (dst_edl) | PanDstEDL | dst_edl | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
|
| ID do anfitrião (hostid) | PanGPHostID | hostid | principal.asset.asset_id | |
| Número de série (serialnumber) | PanEPSerial | principal.asset.hardware.serial_number | ||
| domain_edl (domain_edl) | PanDomainEDL | domain_edl | additional.fields.key e additional.fields.value.string_value | |
| Grupo de endereços dinâmicos de origem (src_dag) | PanSrcDAG | principal.group.group_display_name | ||
| Grupo de endereços dinâmicos de destino (dst_dag) | PanDstDAG | target.group.group_display_name | ||
| partial_hash (partial_hash) | PanPartialHash | partial_hash | additional.fields.key e additional.fields.value.string_value | |
| Data/hora de alta resolução (high_res_timestamp) | PanTimeHighRes | additional.fields.key e additional.fields.value.string_value | ||
| Motivo (motivo) | PanReasonFilteringAction | motivo | security_result.summary | |
| justificação (justification) | PanJustification | justificação | additional.fields.key e additional.fields.value.string_value | |
| nssai_sst (nssai_sst) | PanASServiceType | nssai_sst | additional.fields.key e additional.fields.value.string_value | |
| Subcategoria da app (subcategory_of_app) | subcategory_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Categoria da app (category_of_app) | category_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia da app (technology_of_app) | technology_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Risco da app (risk_of_app) | risk_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Caraterística da app (characteristic_of_app) | characteristic_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Contentor da app (container_of_app) | container_of_app | additional.fields.key e additional.fields.value.string_value | ||
| App com túnel (tunneled_app) | tunneled_app | additional.fields.key e additional.fields.value.string_value | ||
| SaaS da app (is_saas_of_app) | is_saas_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Estado sancionado da app (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key e additional.fields.value.string_value | ||
| ID do relatório da nuvem (cloud_reportid) | additional.fields.key e additional.fields.value.string_value | |||
| Nome do cluster (cluster_name) |
principal.resource.name |
|||
| Tipo de fluxo (flow_type) | additional.fields.key e additional.fields.value.string_value |
Dados
A tabela seguinte lista os campos de registo do tipo de registo de dados e os respetivos campos da UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave de etiqueta do Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Hora de receção (cef-formatted-receive_time) | rt | devTime | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|
| N.º de série (série) | deviceExternalId | SerialNumber | intermediary.asset.hardware.serial_number | |
| Tipo (type) | tipo (cabeçalho) | gato | metadata.product_event_type | |
| Tipo de ameaça/conteúdo (subtipo) | subtipo (cabeçalho) | Subtipo | metadata.product_event_type | |
| Hora de geração | metadata.event_timestamp | |||
| Endereço de origem (src) | src | src | principal.ip | |
| Endereço de destino (dst) | dst | dst | target.ip | |
| IP de origem da NAT (natsrc) | sourceTranslatedAddress | srcPostNAT | principal.nat_ip | |
| IP de destino do NAT (natdst) | destinationTranslatedAddress | dstPostNAT | target.nat_ip | |
| Regra (regra) | cs1 | RuleName | security_result.rule_name | |
| Utilizador de origem (srcuser) | suser | SourceUser | principal.user.userid | |
| Utilizador de destino (dstuser) | duser | DestinationUser | target.user.userid | |
| Aplicação (app) | app | Aplicação | network.application_protocol | |
| Sistema virtual (vsys) | cs3 | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value |
| Zona de origem (de) | cs4 | SourceZone | de | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Zona de destino (para) | cs5 | DestinationZone | a | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Interface de entrada (inbound_if) | deviceInboundInterface | IngressInterface | inbound_if | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
| Interface de saída (outbound_if) | deviceOutboundInterface | EgressInterface | outbound_if | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
| Ação de registo (logset) | cs6 | LogForwardingProfile | logset | additional.fields.key e additional.fields.value.string_value |
| Tempo registado | time_logged | additional.fields.key e additional.fields.value.string_value | ||
| ID da sessão (sessionid) | cn1 | SessionID | network.session_id | |
| Número de repetições (repeatcnt) | cnt | RepeatCount | repeatcnt | additional.fields.key e additional.fields.value.string_value |
| Porta de origem (sport) | spt | srcPort | principal.port | |
| Porta de destino (dport) | dpt | dstPort | target.port | |
| Porta de origem NAT (natsport) | sourceTranslatedPort | srcPostNATPort | principal.nat_port | |
| Porta de destino NAT (natdport) | destinationTranslatedPort | dstPostNATPort | target.nat_port | |
| Flags (flags) | flexString1 | Bandeiras | flags | additional.fields.key e additional.fields.value.string_value |
| Protocolo IP (proto) | proto | proto | network.ip_protocol | |
| Ação (action) | agir | ação | security_result.action_details
security_result.action |
|
| URL/nome do ficheiro (diversos) | Diversos | target.file.names
target.url |
||
| Nome da ameaça/conteúdo (threatid) | gato | ThreatID | security_result.threat_id | |
| Categoria (categoria) | cs2 | URLCategory | categoria | security_result.category_details |
| Gravidade (gravidade) | number-of-severity (cabeçalho) | Gravidade | security_result.severity
security_result.severity_details |
|
| Direção (direction) | flexString2 | Direção | network.direction | |
| Número de sequência (seqno) | externalId | sequência | metadata.product_log_id | |
| Sinalizadores de ações (actionflags) | PanOSActionFlags | ActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value |
| País de origem (srcloc) | SourceLocation | principal.location.country_or_region | ||
| País de destino (dstloc) | DestinationLocation | target.location.country_or_region | ||
| contenttype (contenttype) | ContentType | contenttype | additional.fields.key e additional.fields.value.string_value | |
| pcap_id (pcap_id) | fileId | PCAP_ID | pcap_id | additional.fields.key e additional.fields.value.string_value |
| filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | ||
| nuvem (nuvem) | Google Cloud | nuvem | additional.fields.key e additional.fields.value.string_value | |
| url_idx (url_idx) | URLIndex | url_idx | additional.fields.key e additional.fields.value.string_value | |
| user_agent (user_agent) | network.http.user_agent | |||
| filetype (filetype) | target.file.mime_type | |||
| xff (xff) | xff | principal.ip | ||
| Referenciador (referer) | network.http.referral_url | |||
| remetente (remetente) | network.email.from | |||
| subject (subject) | Assunto | network.email.subject | ||
| destinatário (destinatário) | network.email.to | |||
| reportid (reportid) | reportid | additional.fields.key e additional.fields.value.string_value | ||
| Nível 1 da hierarquia de grupos de anúncios (dg_hier_level_1) | PanOSDGl1 | DeviceGroupHierarchyL1 | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value |
| Nível 2 da hierarquia de grupos de destino (dg_hier_level_2) | PanOSDGl2 | DeviceGroupHierarchyL2 | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value |
| Nível 3 da hierarquia de grupos de destino (dg_hier_level_3) | PanOSDGl3 | DeviceGroupHierarchyL3 | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value |
| Nível 4 da hierarquia de grupos de anúncios (dg_hier_level_4) | PanOSDGl4 | DeviceGroupHierarchyL4 | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value |
| Nome do sistema virtual (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels.key/value | |
| Nome do dispositivo (device_name) | dvchost | DeviceName | intermediary.hostname | |
| file_url (file_url) | target.url | |||
| UUID da VM de origem (src_uuid) | SrcUUID | principal.asset.product_object_id | ||
| UUID da VM de destino (dst_uuid) | DstUUID | target.asset.product_object_id | ||
| http_method (http_method) | RequestMethod | network.http.method | ||
| ID do túnel/IMSI (tunnelid) | PanOSTunnelID | TunnelID | tunnelid | additional.fields.key e additional.fields.value.string_value |
| Monitor Tag/IMEI (monitortag) | PanOSMonitorTag | MonitorTag | monitortag | additional.fields.key e additional.fields.value.string_value |
| ID da sessão principal (parent_session_id) | PanOSParentSessionID | ParentSessionID | parent_session_id | network.parent_session_id |
| Hora de início da sessão principal (parent_start_time) | PanOSParentStartTime | ParentStartTime | parent_start_time | additional.fields.key e additional.fields.value.string_value |
| Túnel (túnel) | PanOSTunnelType | TunnelType | túnel | additional.fields.key e additional.fields.value.string_value |
| thr_category (thr_category) | PanOSThreatCategory | ThreatCategory | thr_category | security_result.detection_fields.key/value |
| contentver (contentver) | PanOSContentVer | ContentVer | contentver | additional.fields.key e additional.fields.value.string_value |
| sig_flags (sig_flags) | sig_flags | additional.fields.key e additional.fields.value.string_value | ||
| ID de associação SCTP (assoc_id) | PanOSAssocID | assoc_id | additional.fields.key e additional.fields.value.string_value | |
| ID do protocolo de carga útil (ppid) | PanOSPPID | ppid | additional.fields.key e additional.fields.value.string_value | |
| http_headers (http_headers) | PanOSHTTPHeader | http_headers | target.url.last_http_response_headers | |
| Lista de categorias de URLs (url_category_list) | url_category_list | additional.fields.key e additional.fields.value.string_value | ||
| UUID da regra (rule_uuid) | PanOSRuleUUID | rule_uuid | security_result.rule_id | |
| Ligação HTTP/2 (http2_connection) | http2_connection | network.application_protocol_version | ||
| dynusergroup_name (dynusergroup_name) | dynusergroup_name | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Endereço XFF (xff_ip) | principal.ip | |||
| Categoria do dispositivo de origem (src_category) | src_category | principal.asset.category | ||
| Perfil do dispositivo de origem (src_profile) | src_profile | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Modelo do dispositivo de origem (src_model) | src_model | principal.asset.hardware.model | ||
| Fornecedor do dispositivo de origem (src_vendor) | src_vendor | principal.asset.hardware.manufacturer | ||
| Família de SO do dispositivo de origem (src_osfamily) | principal.platform | |||
| Versão do SO do dispositivo de origem (src_osversion) | principal.platform_version | |||
| Nome do anfitrião de origem (src_host) | src_host | principal.hostname | ||
| Endereço MAC de origem (src_mac) | principal.mac | |||
| Categoria do dispositivo de destino (dst_category) | dst_category | target.asset.category | ||
| Perfil do dispositivo de destino (dst_profile) | dst_profile | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Modelo do dispositivo de destino (dst_model) | dst_model | target.asset.hardware.model | ||
| Fornecedor do dispositivo de destino (dst_vendor) | dst_vendor | target.asset.hardware.manufacturer | ||
| Família de SO do dispositivo de destino (dst_osfamily) | target.platform | |||
| Versão do SO do dispositivo de destino (dst_osversion) | target.platform_version | |||
| Nome do anfitrião de destino (dst_host) | target.hostname | |||
| Endereço MAC de destino (dst_mac) | target.mac | |||
| ID do contentor (container_id) | container_id | intermediary.resource.product_object_id | ||
| Espaço de nomes do POD (pod_namespace) | pod_namespace | target.resource.attribute.labels.key/value | ||
| Nome do POD (pod_name) | pod_name | target.resource.name | ||
| Lista dinâmica externa de origem (src_edl) | src_edl | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Lista dinâmica externa de destino (dst_edl) | dst_edl | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
||
| ID do anfitrião (hostid) | hostid | principal.asset.asset_id | ||
| Número de série (serialnumber) | principal.asset.hardware.serial_number | |||
| domain_edl (domain_edl) | domain_edl | additional.fields.key e additional.fields.value.string_value | ||
| Grupo de endereços dinâmicos de origem (src_dag) | principal.group.group_display_name | |||
| Grupo de endereços dinâmicos de destino (dst_dag) | target.group.group_display_name | |||
| partial_hash (partial_hash) | partial_hash | additional.fields.key e additional.fields.value.string_value | ||
| Data/hora de alta resolução (high_res_timestamp) | additional.fields.key e additional.fields.value.string_value | |||
| Motivo (motivo) | motivo | security_result.summary | ||
| justificação (justification) | justificação | additional.fields.key e additional.fields.value.string_value | ||
| nssai_sst (nssai_sst) | nssai_sst | additional.fields.key e additional.fields.value.string_value | ||
| Subcategoria da app (subcategory_of_app) | subcategory_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Categoria da app (category_of_app) | category_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia da app (technology_of_app) | technology_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Risco da app (risk_of_app) | risk_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Caraterística da app (characteristic_of_app) | characteristic_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Contentor da app (container_of_app) | container_of_app | additional.fields.key e additional.fields.value.string_value | ||
| App com túnel (tunneled_app) | tunneled_app | additional.fields.key e additional.fields.value.string_value | ||
| SaaS da app (is_saas_of_app) | is_saas_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Estado sancionado da app (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key e additional.fields.value.string_value | ||
| ID do relatório da nuvem (cloud_reportid) | additional.fields.key e additional.fields.value.string_value | |||
| Nome do cluster (cluster_name) | principal.resource.name | |||
| Tipo de fluxo (flow_type) | additional.fields.key e additional.fields.value.string_value |
GlobalProtect
A tabela seguinte apresenta os campos de registo do tipo de registo GlobalProtect e os respetivos campos da UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave de etiqueta do Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Hora de receção (receive_time) | rt | received_time | metadata.event_timestamp | |
| N.º de série (série) | PanOSDeviceSN | intermediary_asset_hardware_serial_number | intermediary.asset.hardware.serial_number | |
| Tipo (type) | tipo (cabeçalho) | metadata.product_event_type | ||
| Tipo de ameaça/conteúdo (subtipo) | subtipo (cabeçalho) | Subtipo | metadata.product_event_type | |
| Hora de geração (time_generated) | PanOSLogTimeStamp | generated_timestamp | metadata.event_timestamp | |
| Sistema virtual (vsys) | PanOSVirtualSystem | vsys | intermediary.asset.attribute.labels.key/value | |
| ID do evento (eventid) | PanOSEventID | event_id | additional.fields.key e additional.fields.value.string_value | |
| Fase (fase) | PanOSStage | armazenar dados em área intermediária | additional.fields.key e additional.fields.value.string_value | |
| Método de autenticação (auth_method) | PanOSAuthMethod | extension_auth_auth_details | extensions.auth.auth_details | |
| Tipo de túnel (tunnel_type) | PanOSTunnelType | túnel | additional.fields.key e additional.fields.value.string_value | |
| Utilizador de origem (srcuser) | PanOSSourceUserName | src_user | principal.user.email_address
principal.user.userid principal.administrative_domain |
|
| Região de origem (srcregion) | PanOSSourceRegion | src_region | principal.location.country_or_region | |
| Nome do computador (machinename) | PanOSEndpointDeviceName | machine_name | principal.hostname | |
| IP público (public_ip) | PanOSPublicIPv4 | principal.nat_ip | ||
| IPv6 público (public_ipv6) | PanOSPublicIPv6 | principal.nat_ip | ||
| IP privado (private_ip) | PanOSPrivateIPv4 | principal.ip | ||
| IPv6 privado (private_ipv6) | PanOSPrivateIPv6 | principal.ip | ||
| ID do anfitrião (hostid) | PanOSHostID | hostid | principal.asset.asset_id | |
| Número de série (serialnumber) | PanOSDeviceSN | principal.asset.hardware.serial_number | ||
| Versão do cliente (client_ver) | PanOSGlobalProtectClientVersion | client_ver | additional.fields.key e additional.fields.value.string_value | |
| SO do cliente (client_os) | PanOSEndpointOSType | principal.platform | ||
| Versão do SO do cliente (client_os_ver) | PanOSEndpointOSVersion | principal.platform_version | ||
| Número de repetições (repeatcnt) | PanOSCountOfRepeats | repeatcnt | additional.fields.key e additional.fields.value.string_value | |
| Motivo (motivo) | PanOSQuarantineReason | security_result.summary | ||
| Erro (erro) | PanOSConnectionError | erro | security_result.description | |
| Descrição (opaca) | PanOSDescription | security_result.description | ||
| Estado (estado) | PanOSEventStatus | estado | additional.fields.key e additional.fields.value.string_value | |
| Localização (localização) | PanOSGPGatewayLocation | target.location.country_or_region | ||
| Duração do início de sessão (login_duration) | PanOSLoginDuration | network.session_duration | ||
| Método de ligação (connect_method) | PanOSConnectionMethod | connect_method | additional.fields.key e additional.fields.value.string_value | |
| Código de erro (error_code) | PanOSConnectionErrorID | error_code | additional.fields.key e additional.fields.value.string_value | |
| Portal (portal) | PanOSPortal | portal | additional.fields.key e additional.fields.value.string_value | |
| Número de sequência (seqno) | PanOSSequenceNo | metadata.product_log_id | ||
| Sinalizadores de ações (actionflags) | PanOSActionFlags | actionflags | additional.fields.key e additional.fields.value.string_value | |
| Indicação de tempo de alta resolução (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key e additional.fields.value.string_value | ||
| Método de seleção do gateway (selection_type) | PanOSGatewaySelectionType | selection_type | additional.fields.key e additional.fields.value.string_value | |
| Tempo de resposta SSL (response_time) | PanOSSSLResponseTime | response_time | additional.fields.key e additional.fields.value.string_value | |
| Prioridade do gateway (prioridade) | PanOSGatewayPriority | prioridade | additional.fields.key e additional.fields.value.string_value | |
| Gateways tentados (attempted_gateways) | PanOSAttemptedGateways | attempted_gateways | additional.fields.key e additional.fields.value.string_value | |
| Nome do gateway (gateway) | PanOSAttemptedGateways | gateway | target.resource.name | |
| Hierarquia do grupo de dispositivos (dg_hier_level_1) | dg_hier_level_1 | additional.fields.key e additional.fields.value.string_value | ||
| Hierarquia do grupo de dispositivos (dg_hier_level_2) | dg_hier_level_2 | additional.fields.key e additional.fields.value.string_value | ||
| Hierarquia do grupo de dispositivos (dg_hier_level_3) | dg_hier_level_3 | additional.fields.key e additional.fields.value.string_value | ||
| Hierarquia do grupo de dispositivos (dg_hier_level_4) | dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value | ||
| Nome do sistema virtual (vsys_name) | intermediary.asset.attribute.labels.key/value | |||
| Nome do dispositivo (device_name) | intermediary.hostname | |||
| ID do sistema virtual (vsys_id) | intermediary.resource.product_object_id | |||
| Gravidade (gravidade) | number-of-severity(header) | security_result.severity e security_result.severity_details | ||
| Nome do cluster (cluster_name) | principal.resource.name |
Correlação
A tabela seguinte lista os campos de registo do tipo de registo de correlação e os respetivos campos UDM.
| Campo CSV | Campo CEF | Campo LEEF | Chave de etiqueta do Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Hora de geração (time_generated ou cef-formatted-time_generated) | startTime | generated_timestamp | metadata.event_timestamp | |
| Endereço de origem (src) | src | principal.ip | ||
| Utilizador de origem (srcuser) | SourceUser / usrName | principal.user.userid | ||
| Sistema virtual (vsys) | VirtualSystem | vsys | intermediary.asset.attribute.labels.key/value | |
| Categoria (categoria) | security_result.category_details | |||
| Gravidade (gravidade) | Gravidade | security_result.severity e security_result.severity_details | ||
| Nível 1 da hierarquia do grupo de dispositivos | DeviceGroupHierarchyL1 | additional.fields.key e additional.fields.value.string_value | ||
| Nível 2 da hierarquia do grupo de dispositivos | DeviceGroupHierarchyL2 | additional.fields.key e additional.fields.value.string_value | ||
| Nível 3 da hierarquia do grupo de dispositivos | DeviceGroupHierarchyL3 | additional.fields.key e additional.fields.value.string_value | ||
| Nível 4 da hierarquia do grupo de dispositivos | DeviceGroupHierarchyL4 | additional.fields.key e additional.fields.value.string_value | ||
| Nome do sistema virtual (vsys_name) | vSrcName | intermediary.asset.attribute.labels.key/value | ||
| Nome do dispositivo (device_name) | DeviceName | intermediary.hostname | ||
| ID do sistema virtual (vsys_id) | VirtualSystemID | intermediary.resource.product_object_id | ||
| Nome do objeto (objectname) | ObjectName | target.resource.name | ||
| ID do objeto (object_id) | ObjectID | target.resource.product_object_id | ||
| Provas (provas) | msg | security_result.summary |
GTP
A tabela seguinte apresenta os campos de registo do tipo de registo gtp e os respetivos campos UDM correspondentes.
| Campo CSV | Campo CEF | Campo LEEF | Chave de etiqueta do Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Hora de receção (receive_time ou cef-formatted-receive_time) | metadata.collected_timestamp,
metadata.event_timestamp (se "Generate Time" estiver ausente) |
|||
| Número de série (serial) | intermediary.asset.hardware.serial_number | |||
| Tipo (type) | metadata.product_event_type | |||
| Tipo de ameaça/conteúdo (subtipo) | metadata.product_event_type | |||
| Hora de geração (time_generated ou cef-formatted-time_generated) | metadata.event_timestamp | |||
| Endereço de origem (src) | principal.ip | |||
| Endereço de destino (dst) | target.ip | |||
| Nome da regra (regra) | security_result.rule_name | |||
| Aplicação (app) | network.application_protocol | |||
| Sistema virtual (vsys) | vsys | intermediary.asset.attribute.labels.key/value | ||
| Zona de origem (de) | de | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Zona de destino (para) | a | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Interface de entrada (inbound_if) | inbound_if | principal.labels.key e principal.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Interface de saída (outbound_if) | outbound_if | target.labels.key e target.labels.value additional.fields.key e additional.fields.value.string_value |
||
| Ação de registo (logset) | logset | additional.fields.key e additional.fields.value.string_value | ||
| ID da sessão (sessionid) | network.session_id | |||
| Porta de origem (sport) | principal.port | |||
| Porta de destino (dport) | target.port | |||
| Protocolo IP (proto) | network.ip_protocol | |||
| Ação (action) | security_result.action_details
security_result.action |
|||
| Tipo de evento de GTP (event_type) | gtp_event_type | additional.fields.key e additional.fields.value.string_value | ||
| MSISDN (msisdn) | msisdn | additional.fields.key e additional.fields.value.string_value | ||
| Nome do Ponto de Acesso (APN) | apn | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia de acesso por rádio (rat) | rato | additional.fields.key e additional.fields.value.string_value | ||
| Tipo de mensagem de GTP (msg_type) | gtp_msg_type | additional.fields.key e additional.fields.value.string_value | ||
| Endereço IP final (end_ip_adr) | principal.ip | |||
| Identificador do ponto final do túnel 1 (teid1) | teid1 | additional.fields.key e additional.fields.value.string_value | ||
| Identificador do ponto final do túnel 2 (teid2) | teid2 | additional.fields.key e additional.fields.value.string_value | ||
| Interface GTP (gtp_interface) | gtp_interface | additional.fields.key e additional.fields.value.string_value | ||
| GTP Cause (cause_code) | gtp_cause_code | additional.fields.key e additional.fields.value.string_value | ||
| Gravidade (gravidade) | security_result.severity e security_result.severity_details | |||
| MCC da rede de serviço (mcc) | mcc | additional.fields.key e additional.fields.value.string_value | ||
| Serving Network MNC (mnc) | mnc | additional.fields.key e additional.fields.value.string_value | ||
| Indicativo de área (area_code) | area_code | additional.fields.key e additional.fields.value.string_value | ||
| ID da célula (cell_id) | cell_id | additional.fields.key e additional.fields.value.string_value | ||
| Código do evento GTP (event_code) | event_code | additional.fields.key e additional.fields.value.string_value | ||
| Localização da origem (srcloc) | principal.location.country_or_region | |||
| Localização de destino (dstloc) | target.location.country_or_region | |||
| ID do túnel/IMSI (imsi) | tunnelid | additional.fields.key e additional.fields.value.string_value | ||
| Monitorizar etiqueta/IMEI (imei) | monitortag | additional.fields.key e additional.fields.value.string_value | ||
| Hora de início (início) | iniciar | additional.fields.key e additional.fields.value.string_value | ||
| Tempo decorrido (decorrido) | network.session_duration.seconds | |||
| Tunnel Inspection RuleTunnel (tunnel_insp_rule) | tunnel_insp_rule | security_result.detection_fields.key/value | ||
| IP do utilizador remoto (remote_user_ip) | principal.ip | |||
| ID do utilizador remoto (remote_user_id) | remote_user_id | principal.user.userid | ||
| UUID da regra (rule_uuid) | security_result.rule_id | |||
| ID do PCAP (pcap_id) | pcap_id | additional.fields.key e additional.fields.value.string_value | ||
| Indicação de tempo de alta resolução (high_res_timestamp) | additional.fields.key e additional.fields.value.string_value | |||
| Um tipo de serviço de divisão (nsdsai_sst) | nsdsai_sst | additional.fields.key e additional.fields.value.string_value | ||
| Um diferenciador de fatia (nsdsai_sd) | nsdsai_sd | additional.fields.key e additional.fields.value.string_value | ||
| Subcategoria da aplicação (subcategory_of_app) | subcategory_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Categoria de aplicações (category_of_app) | category_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Tecnologia da aplicação (technology_of_app) | technology_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Risco da aplicação (risk_of_app) | risk_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Caraterística da aplicação (characteristic_of_app) | characteristic_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Contentor de aplicações (container_of_app) | container_of_app | additional.fields.key e additional.fields.value.string_value | ||
| SaaS de aplicação (is_saas_of_app) | is_saas_of_app | additional.fields.key e additional.fields.value.string_value | ||
| Estado sancionado da aplicação (sanctioned_state_of_app) | sanctioned_state_of_app | additional.fields.key e additional.fields.value.string_value |
SCTP
| Campo CSV | Campo CEF | Campo LEEF | Chave de etiqueta do Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Hora de receção (receive_time ou cef-formatted-receive_time) | receive_time ou cef-formatted-receive_time | metadata.collected_timestamp | ||
| Número de série (serial) | número de série | intermediary.asset.hardware.serial_number | ||
| Tipo (type) | escrever | metadata.product_event_type | ||
| Hora de geração (time_generated ou cef-formatted-time_generated) | time_generated ou cef-formatted-time_generated | metadata.event_timestamp | ||
| Endereço de origem (src) | src | principal.ip | ||
| Endereço de destino (dst) | dst | target.ip | ||
| Nome da regra (regra) | regra | security_result.rule_name | ||
| Zona de origem (de) | de | additional.fields.key e additional.fields.value.string_value | ||
| Zona de destino (para) | a | additional.fields.key e additional.fields.value.string_value | ||
| Interface de entrada (inbound_if) | inbound_if | additional.fields.key e additional.fields.value.string_value | ||
| Interface de saída (outbound_if) | outbound_if | additional.fields.key e additional.fields.value.string_value | ||
| Ação de registo (logset) | logset | additional.fields.key e additional.fields.value.string_value | ||
| ID da sessão (sessionid) | sessionid | network.session_id | ||
| Número de repetições (repeatcnt) | repeatcnt | additional.fields.key e additional.fields.value.string_value | ||
| Porta de origem (sport) | desporto | principal.port | ||
| Porta de destino (dport) | dport | target.port | ||
| Protocolo IP (proto) | proto | network.ip_protocol (enum) | ||
| Ação (action) | ação | security_result.action_details security_result.action |
||
| Hierarquia do grupo de dispositivos (dg_hier_level_1 a dg_hier_level_4) | dg_hier_level_1 a dg_hier_level_4 | additional.fields.key e additional.fields.value.string_value | ||
| Nome do dispositivo (device_name) | device_name | intermediary.hostname | ||
| Número de sequência (seqno) | seqno | metadata.product_log_id | ||
| ID de associação SCTP (assoc_id) | assoc_id | additional.fields.key e additional.fields.value.string_value | ||
| ID do protocolo de carga útil (ppid) | ppid | additional.fields.key e additional.fields.value.string_value | ||
| Gravidade (gravidade) | gravidade | security_result.severity e security_result.severity_details | ||
| Tipo de fragmento SCTP (sctp_chunk_type) | sctp_chunk_type | additional.fields.key e additional.fields.value.string_value | ||
| Tipo de evento SCTP (sctp_event_type) | sctp_event_type | additional.fields.key e additional.fields.value.string_value | ||
| Etiqueta de validação SCTP 1 (verif_tag_1) | verif_tag_1 | additional.fields.key e additional.fields.value.string_value | ||
| Etiqueta de validação SCTP 2 (verif_tag_2) | verif_tag_2 | additional.fields.key e additional.fields.value.string_value | ||
| Código de motivo do SCTP (sctp_cause_code) | sctp_cause_code | additional.fields.key e additional.fields.value.string_value | ||
| ID da app Diameter (diam_app_id) | diam_app_id | additional.fields.key e additional.fields.value.string_value | ||
| Código de comando do diâmetro (diam_cmd_code) | diam_cmd_code | additional.fields.key e additional.fields.value.string_value | ||
| Código AVP do diâmetro (diam_avp_code) | diam_avp_code | additional.fields.key e additional.fields.value.string_value | ||
| ID da stream SCTP (stream_id) | stream_id | additional.fields.key e additional.fields.value.string_value | ||
| Motivo do fim da associação SCTP (assoc_end_reason) | assoc_end_reason | additional.fields.key e additional.fields.value.string_value | ||
| Código de operação (op_code) | op_code | additional.fields.key e additional.fields.value.string_value | ||
| SCCP Calling Party SSN (sccp_calling_ssn) | sccp_calling_ssn | additional.fields.key e additional.fields.value.string_value | ||
| Título global da parte chamadora do SCCP (sccp_calling_gt) | sccp_calling_gt | additional.fields.key e additional.fields.value.string_value | ||
| Filtro SCTP (sctp_filter) | sctp_filter | additional.fields.key e additional.fields.value.string_value | ||
| Blocos SCTP (blocos) | pedaços | additional.fields.key e additional.fields.value.string_value | ||
| SCTP Chunks Sent (chunks_sent) | chunks_sent | additional.fields.key e additional.fields.value.string_value | ||
| SCTP Chunks Received (chunks_received) | chunks_received | additional.fields.key e additional.fields.value.string_value | ||
| Pacotes (packets) | pacotes | additional.fields.key e additional.fields.value.string_value | ||
| UUID da regra (rule_uuid) | rule_uuid | security_result.rule_id | ||
| Sistema virtual (vsys) | vsys | intermediary.asset.attribute.labels.key/value | ||
| Nome do sistema virtual (vsys_name) | vsys_name | intermediary.asset.attribute.labels.key/value | ||
| Pacotes enviados (pkts_sent) | pkts_sent | network.sent_packets | ||
| Pacotes recebidos (pkts_received) | pkts_received | network.received_packets |
Auditoria
| Campo CSV | Campo CEF | Campo LEEF | Chave de etiqueta do Google Security Operations | Campo UDM |
|---|---|---|---|---|
| Hora de geração | metadata.event_timestamp | |||
| Tipo de ameaça/conteúdo (subtipo) | metadata.product_event_type | |||
| ID do evento | principal.application | |||
| Objeto | principal.user.userid | |||
| Comando da CLI | principal.process.command_line | |||
| Gravidade | security_result.severity | |||
| Número de série | intermediary.asset.hardware.serial_number |
Referência de mapeamento de campos: tipos de registos para o tipo de evento da UDM
A tabela seguinte apresenta os tipos de registos da firewall da Palo Alto Networks e os respetivos tipos de eventos da UDM.
| Tipo de registo | Tipo de evento UDM |
| Trânsito | NETWORK_CONNECTION |
| Ameaça | NETWORK_CONNECTION |
| Filtragem de URLs | NETWORK_CONNECTION |
| WildFire | NETWORK_CONNECTION
Os registos de envios do WildFire são um subtipo do tipo de registo de ameaças e usam o mesmo formato de syslog. |
| Filtragem de dados | NETWORK_CONNECTION |
| Túnel | NETWORK_CONNECTION |
| GTP | NETWORK_CONNECTION |
| Configuração | SETTING_MODIFICATION/SETTING_CREATION/SETTING_DELETION/SETTING_UNCATEGORIZED
O valor do campo "Comando (cmd)" determina o mapeamento do tipo de evento da UDM. Se o valor do campo cmd for add ou clone, SETTING_CREATION é definido. Se o valor do campo cmd for delete, SETTING_DELETION é definido. Se o valor do campo cmd for edit, move, rename, set ou commit, SETTING_MODIFICATION é definido. Se o valor do campo cmd não contiver valores, é definido SETTING_UNCATEGORIZED |
| Sistema |
Se o valor do subtipo for "dhcp", é definido NETWORK_DHCP. Se o valor do subtipo for "auth", USER_LOGIN é definido. Se o valor da descrição for "logged in", USER_LOGIN é definido. Se o valor da descrição for "logged out", USER_LOGOUT é definido. Para outros valores do subtipo, é definido GENERIC_EVENT. |
| HIP Match | NETWORK_CONNECTION |
| Etiqueta de IP | GENERIC_EVENT |
| User-ID | USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED
Se o valor do subtipo for "login", USER_LOGIN é definido. Se o valor do subtipo for "logout", é definido USER_LOGOUT. Se o subtipo não contiver nenhum valor, é definido USER_UNCATEGORIZED. |
| Desencriptação | NETWORK_CONNECTION |
| Autenticação | GENERIC_EVENT |
| SCTP | NETWORK_CONNECTION |
| Auditoria | GENERIC_EVENT |
Delta de mapeamento do UDM
Referência do delta de mapeamento da UDM: firewall da Palo Alto Networks
A tabela seguinte apresenta a diferença entre o mapeamento do UDM antigo de Palo Alto Networks Firewall e o mapeamento do UDM novo de Palo Alto Networks Firewall.
UDM Event Type Delta
| Log type | Old UDM Event Type | New UDM Event Type |
| WildFire | NETWORK_CONNECTION | SCAN_UNCATEGORIZED |
| Data Filtering | NETWORK_CONNECTION | NETWORK_UNCATEGORIZED |
| Authentication | STATUS_UPDATE | STATUS_UNCATEGORIZED |
UDM Field Mapping Delta
| Log Type | Old UDM Mapping | CSV Log Field | CEF Log Field | LEEF Log Field | New UDM Mapping |
|---|---|---|---|---|---|
| System | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| System | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| System | about.labels.key/value additional.fields.key/value.string_value | Object (object) | fname | Filename | target.resource.name |
| System | Description (opaque) | msg | msg | metadata.description | |
| System | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| System | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| Config | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| Config | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| Config | principal.process.command_line | Configuration Path (path) | msg | ConfigurationPath | principal.process.command_line |
| Config | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| Config | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| Config | principal.asset.attribute.labels.key/value | Device Group (dg_id) | PanOSFWDeviceGroup | target.asset.attribute.labels | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Threat/Wildfire | target.file.full_path target.url target.hostname | URL/Filename (misc) | request | Miscellaneous | target.file.names target.url |
| Threat/Wildfire | about.file.sha1/md5/sha256 | File Digest (filedigest) | fileHash | FileDigest | target.file.sha1/md5/sha256 |
| Threat/Wildfire | about.file.mime_type | File Type (filetype) | fileType | FileType | target.file.mime_type |
| Threat/Wildfire | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Threat/Wildfire | principal.user.product_object_id | Source VM UUID (src_uuid) | PanOSSrcUUID | SrcUUID | principal.asset.product_object_id |
| Threat/Wildfire | target.user.product_object_id | Destination VM UUID (dst_uuid) | PanOSDstUUID | DstUUID | target.asset.product_object_id |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | HTTP Headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| Threat/Wildfire | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| Threat/Wildfire | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| Threat/Wildfire | principal.asset.software.version | Source Device OS Version (src_osversion) | PanSrcDeviceOSv | principal.platform_version | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| Threat/Wildfire | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| Threat/Wildfire | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| Threat/Wildfire | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Threat/Wildfire | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | PanReasonFilteringAction | security_result.summary | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Packets Sent (pkts_sent) | PanOSPacketsSent | srcPackets | network.sent_packets |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Packets Received (pkts_received) | PanOSPacketsReceived | dstPackets | network.received_packets |
| Traffic | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| Traffic | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| Traffic | principal.asset.platform_software.platform(enum) principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| Traffic | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| Traffic | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| Traffic | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| Traffic | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| User-ID | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| User-ID | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| User-ID | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | intermediary.resource.product_object_id |
| User-ID | principal.user.userid principal.administrative_domain principal.user.email_addresses | User by Source (userbysource) | PanOSUserBySource | target.user.userid target.user.email_addresses | |
| User-ID | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| HIP Match | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | HIP (matchname) | cat | HIP | target.resource.attribute.labels |
| HIP Match | about.labels.key/value additional.fields.key/value.string_value | HIP Type (matchtype) | Device Event Class ID (Header) | HIPType | target.resource.attribute.labels |
| HIP Match | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | target.asset.attribute.labels |
| HIP Match | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| HIP Match | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id |
| HIP Match | principal.asset.product_object_id | Host ID (hostid) | PanOSHostID | principal.asset.asset_id | |
| HIP Match | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| IP-Tag | intermediary.asset.hardware.serial_number | Serial Number (serial) | deviceExternalId | SerialNumber | target.asset.hardware.serial_number |
| IP-Tag | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | target.asset.attribute.labels |
| IP-Tag | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOsVsysName | vSrcName | target.asset.attribute.labels |
| IP-Tag | intermediary.hostname | Device Name (device_name) | dvchost | DeviceName | target.hostname |
| IP-Tag | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | cn2 | VirtualSystemID | target.resource.product_object_id |
| IP-Tag | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Decryption | target.application | Application (app) | app | network.application_protocol | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | intermediary.asset.attribute.labels | |
| Decryption | principal.asset.asset_id | Source VM UUID (src_uuid) | PanOSSourceUUID | principal.asset.product_object_id | |
| Decryption | target.asset.asset_id | Destination VM UUID (dst_uuid) | PanOSDestinationUUID | target.asset.product_object_id | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanOSContainerID | intermediary.resource.product_object_id | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanOSContainerNameSpace | target.resource.attribute.labels additional.fields.key/value.string_value | |
| Decryption | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanOSContainerName | target.resource.name | |
| Decryption | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanOSSourceDeviceCategory | principal.asset.category | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanOSSourceDeviceModel | principal.asset.hardware.model | |
| Decryption | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanOSSourceDeviceVendor | principal.asset.hardware.manufacturer | |
| Decryption | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanOSSourceDeviceOSFamily | principal.platform | |
| Decryption | principal.asset.software.version | Source Device OS Version (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanOSDestinationDeviceCategory | target.asset.category | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanOSDestinationDeviceModel | target.asset.hardware.model | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanOSDestinationDeviceVendor | target.asset.hardware.manufacturer | |
| Decryption | target.labels.key/value additional.fields.key/value.string_value | Destination Device OS Family (dst_osfamily) | PanOSDestinationDeviceOSFamily | target.platform | |
| Decryption | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanOSDestinationDeviceOSVersion | target.platform_version | |
| Decryption | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | intermediary.asset.attribute.labels | ||
| Decryption | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Tunnel | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Packets Sent (pkts_sent) | PanOSPacketsSent | srcPackets | network.sent_packets |
| Tunnel | about.labels.key/value additional.fields.key/value.string_value | Packets Received (pkts_received) | PanOSPacketsReceived | dstPackets | network.received_packets |
| Tunnel | target.ip | Remote User IP (remote_user_ip) | PanOSRmtUserIP | principal.ip | |
| Tunnel | target.labels.key/value additional.fields.key/value.string_value | Remote User ID (remote_user_id) | PanOSRmtUserID | principal.user.userid | |
| Tunnel | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Authentication | target.user.user_display_name | Normalize User (normalize_user) | cs2 | NormalizeUser | target.user.user_display_name |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Object (object) | fname | ObjectName | target.resource.name |
| Authentication | about.labels.key/value additional.fields.key/value.string_value | Authentication Policy (authpolicy) | cs4 | AuthPolicy | additional.fields.key/value.string_value |
| Authentication | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Authentication | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| Authentication | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res _timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanOSSourceDeviceCategory | principal.asset.category | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanOSSourceDeviceModel | principal.asset.hardware.model | |
| Authentication | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanOSSourceDeviceVendor | principal.asset.hardware.manufacturer | |
| Authentication | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanOSSourceDeviceOSFamily | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | |
| Authentication | principal.asset.software.version | Source Device OS Version (src_osversion) | PanOSSourceDeviceOSVersion | principal.platform_version | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| URL | target.file.full_path target.url | URL/Filename (misc) | Miscellaneous | target.file.names target.url | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Category (category) | cs2 | URLCategory | security_result.category_details |
| URL | about.file.sha1/md5/sha256 | filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | |
| URL | about.file.mime_type | filetype (filetype) | target.file.mime_type | ||
| URL | about.labels.key/value additional.fields.key/value.string_value | xff (xff) | PanOSXForwarderfor | identSrc | principal.ip |
| URL | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| URL | about.url | file_url (file_url) | target.url | ||
| URL | principal.asset.asset_id | Source VM UUID (src_uuid) | SrcUUID | principal.asset.product_object_id | |
| URL | target.asset.asset_id | Destination VM UUID (dst_uuid) | DstUUID | target.asset.product_object_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | http_headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| URL | about.labels.key/value additional.fields.key/value.string_value | UUID for rule (rule_uuid) | PanOSRuleUUID | security_result.rule_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | PanOSHTTP2Con | network.application_protocol_version | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | PanSrcDeviceCat | principal.asset.category | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | PanSrcDeviceModel | principal.asset.hardware.model | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | PanSrcDeviceVendor | principal.asset.hardware.manufacturer | |
| URL | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | PanSrcDeviceOS | principal.platform | |
| URL | principal.asset.software.version | Source Device OS Version (src_osversion) | PanSrcDeviceOSv | principal.platform_version | |
| URL | principal.labels.key/value additional.fields.key/value.string_value | Source Hostname (src_host) | PanSrcHostname | principal.hostname | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | PanDstDeviceCat | target.asset.category | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | PanDstDeviceModel | target.asset.hardware.model | |
| URL | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | PanDstDeviceVendor | target.asset.hardware.manufacturer | |
| URL | target.asset.platform_software.platform target.labels.key/value | Destination Device OS Family (dst_osfamily) | PanDstDeviceOS | target.platform | |
| URL | target.asset.software.version | Destination Device OS Version (dst_osversion) | PanDstDeviceOSv | target.platform_version | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | PanContainerName | intermediary.resource.product_object_id | |
| URL | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | PanPODNamespace | target.resource.attribute.labels | |
| URL | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | PanPODName | target.resource.name | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | PanGPHostID | principal.asset.asset_id | |
| URL | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Res Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| URL | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | PanReasonFilteringAction | security_result.summary | |
| Data | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | cs3 | VirtualSystem | intermediary.asset.attribute.labels |
| Data | target.file.full_path target.url | URL/Filename (misc) | Miscellaneous | target.file.names target.url | |
| Data | about.labels.key/value additional.fields.key/value.string_value | Category (category) | cs2 | URLCategory | security_result.category_details |
| Data | about.file.sha1/md5/sha256 | filedigest (filedigest) | FileDigest | target.file.sha1/md5/sha256 | |
| Data | about.file.mime_type | filetype (filetype) | target.file.mime_type | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | xff (xff) | principal.ip | ||
| Data | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | PanOSVsysName | vSrcName | intermediary.asset.attribute.labels |
| Data | about.url | file_url (file_url) | target.url | ||
| Data | principal.asset.asset_id | Source VM UUID (src_uuid) | SrcUUID | principal.asset.product_object_id | |
| Data | target.asset.asset_id | Destination VM UUID (dst_uuid) | DstUUID | target.asset.product_object_id | |
| Data | about.labels.key/value additional.fields.key/value.string_value | http_headers (http_headers) | PanOSHTTPHeader | target.url.last_http_response_headers | |
| Data | about.labels.key/value additional.fields.key/value.string_value | UUID for rule (rule_uuid) | PanOSRuleUUID | security_result.rule_id | |
| Data | about.labels.key/value additional.fields.key/value.string_value | HTTP/2 Connection (http2_connection) | network.application_protocol_version | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Category (src_category) | principal.asset.category | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Model (src_model) | principal.asset.hardware.model | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Device Vendor (src_vendor) | principal.asset.hardware.manufacturer | ||
| Data | principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value | Source Device OS Family (src_osfamily) | principal.platform | ||
| Data | principal.asset.software.version | Source Device OS Version (src_osversion) | principal.platform_version | ||
| Data | principal.labels.key/value additional.fields.key/value.string_value | Source Hostname (src_host) | principal.hostname | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Category (dst_category) | target.asset.category | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Model (dst_model) | target.asset.hardware.model | ||
| Data | target.labels.key/value additional.fields.key/value.string_value | Destination Device Vendor (dst_vendor) | target.asset.hardware.manufacturer | ||
| Data | target.asset.platform_software.platform target.labels.key/value | Destination Device OS Family (dst_osfamily) | target.platform | ||
| Data | target.asset.software.version | Destination Device OS Version (dst_osversion) | target.platform_version | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Container ID (container_id) | intermediary.resource.product_object_id | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | POD Namespace (pod_namespace) | target.resource.attribute.labels | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | POD Name (pod_name) | target.resource.name | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Host ID (hostid) | principal.asset.asset_id | ||
| Data | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Res Timestamp (high_res_timestamp) | additional.fields.key/value.string_value | ||
| Data | about.labels.key/value additional.fields.key/value.string_value | Reason (reason) | security_result.summary | ||
| GlobalProtect | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | PanOSVirtualSystem | intermediary.asset.attribute.labels | |
| GlobalProtect | principal.user.email_address principal.user.userid principal.administrative_domain | Source User (srcuser) | PanOSSourceUserName | target.user.email_address target.user.userid | |
| GlobalProtect | principal.asset.platform_software.platform(enum) | Client OS (client_os) | PanOSEndpointOSType | principal.platform | |
| GlobalProtect | principal.asset.platform_software.platform_version | Client OS Version (client_os_ver) | PanOSEndpointOSVersion | principal.platform_version | |
| GlobalProtect | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | PanOSTimeGeneratedHighResolution | additional.fields.key/value.string_value | |
| GlobalProtect | about.labels.key/value additional.fields.key/value.string_value | Gateway Name (gateway) | PanOSAttemptedGateways | target.resource.name | |
| GlobalProtect | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | intermediary.asset.attribute.labels | ||
| GlobalProtect | target.hostname | Device Name (device_name) | intermediary.hostname | ||
| GlobalProtect | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | intermediary.resource.product_object_id | ||
| CORRELATION | about.labels.key/value additional.fields.key/value.string_value | Virtual System (vsys) | VirtualSystem | intermediary.asset.attribute.labels | |
| CORRELATION | principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE | Virtual System Name (vsys_name) | vSrcName | intermediary.asset.attribute.labels | |
| CORRELATION | principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id | Virtual System ID (vsys_id) | VirtualSystemID | intermediary.resource.product_object_id | |
| GTP | additional.fields.key/value.string_value | Virtual System (vsys) | intermediary.asset.attribute.labels | ||
| GTP | target.ip | Remote User IP (remote_user_ip) | principal.ip | ||
| GTP | additional.fields.key/value.string_value | Remote User ID (remote_user_id) | principal.user.userid | ||
| GTP | metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) | High Resolution Timestamp (high_res_timestamp) | additional.fields.key/value.string_value |
Palo Alto Networks Firewall Strata Logging Service
Vista geral
O Strata Logging Service da Palo Alto Networks® oferece armazenamento e agregação de registos centralizados baseados na nuvem para as suas firewalls no local, virtuais (nuvem privada e nuvem pública), para o Prisma Access e para serviços fornecidos na nuvem, como o Cortex XDR.O Strata Logging Service é seguro, resiliente e tolerante a falhas, e garante que os seus dados de registo estão atualizados e disponíveis quando precisar deles. Fornece uma infraestrutura de registo escalável que alivia a necessidade de planear e implementar coletores de registos para satisfazer as suas necessidades de retenção de registos. Se já tiver coletores de registos no local, o novo serviço de registo do Strata pode complementar a sua configuração existente. Pode aumentar a sua infraestrutura de recolha de registos existente com o serviço de registo Strata baseado na nuvem para expandir a capacidade operacional à medida que a sua empresa cresce ou para satisfazer as necessidades de capacidade de novas localizações.Com este serviço, a Palo Alto Networks cuida da manutenção e monitorização contínuas da infraestrutura de registo para que possa concentrar-se na sua empresa.
Valide os formatos de registos e as versões do PAN-OS suportados pelo analisador do Strata Logging Service. A tabela seguinte indica os formatos de registo e as versões do PAN-OS correspondentes que o analisador do Strata Logging Service suporta:
Formato do registo Versão do PAN-OS JSON 12.1 Valide os tipos de registos da firewall da Palo Alto Networks que o analisador do Google SecOps suporta. O analisador do Google SecOps suporta os seguintes tipos de registos de firewall da Palo Alto Networks:
- Trânsito
- Ameaça
- Inspeção de túneis
- Sistema
- Correspondência de HIP
- IP-Tag
- User-ID
- Desencriptação
- Autenticação
- Filtragem de URLs
- GlobalProtect
Implementação do serviço de registo do Strata
- Certifique-se de que o produto de firewall da Palo Alto Networks está implementado e configurado corretamente. Para obter instruções de configuração detalhadas, consulte a documentação do PAN-OS e, em seguida, siga este documento de implementação antes de enviar registos para o serviço de registo do Strata Pré-requisitos de implementação do serviço de registo do Strata
Comece a enviar registos para o serviço de registo do Strata:
Para começar a enviar registos para o serviço de registo do Strata, siga estes passos:
- Instale uma versão do PAN-OS® suportada
- Ative o serviço de registo do Strata: a ativação do serviço de registo do Strata inclui o aprovisionamento do certificado de que as firewalls precisam para estabelecer ligação segura ao serviço de registo do Strata.
- Integre firewalls no serviço de registo do Strata com ou sem o Panorama
Para ver passos de integração detalhados, consulte a documentação.
Encaminhe registos do serviço de registo do Strata
Para satisfazer as suas necessidades de armazenamento, relatórios e monitorização a longo prazo, ou legais e de conformidade, pode configurar o serviço de registo do Strata para encaminhar registos para um servidor HTTPS ou para os seguintes SIEMs:
- Exabeam
- Google Chronicle
- Microsoft Sentinel
- Coletor de eventos de HTTP (HEC) do Splunk
Use o método de encaminhamento HTTPS para encaminhar os registos através do serviço de registo do Strata. Para obter informações detalhadas, siga esta documentação.
Formatos de registo suportados
O analisador de firewall do serviço de registo do Palo Alto Networks Strata suporta registos no formato JSON.
Registos de exemplo suportados
JSON
{"source": "Palo Alto Networks FLS LF", "host": "dummy-loghost", "time": "1730265996460", "event": {"TimeReceived": "2024-10-30T05:25:50.000000Z", "DeviceSN": "no-serial", "LogType": "TRAFFIC", "Subtype": "end", "ConfigVersion": "10.2", "TimeGenerated": "2024-10-30T05:25:40.000000Z", "SourceAddress": "198.51.100.6", "DestinationAddress": "198.51.100.6", "NATSource": "", "NATDestination": "", "Rule": "egress-dns-ping-traceroute", "SourceUser": null, "DestinationUser": null, "Application": "dns-base", "VirtualLocation": "vsys1", "FromZone": "VA8280-RN", "ToZone": "inter-fw", "InboundInterface": "tunnel.101", "OutboundInterface": "tunnel.4005", "LogSetting": "Cortex Data Lake", "SessionID": 754194, "RepeatCount": 1, "SourcePort": 53578, "DestinationPort": 53, "NATSourcePort": 0, "NATDestinationPort": 0, "Protocol": "udp", "Action": "allow", "Bytes": 214, "BytesSent": 72, "BytesReceived": 142, "PacketsTotal": 2, "SessionStartTime": "2024-10-30T05:25:10.000000Z", "SessionDuration": 0, "URLCategory": "any", "SequenceNo": 7382192512716388639, "SourceLocation": "198.51.100.6-198.51.255.255", "DestinationLocation": "198.51.100.6-198.51.255.255", "PacketsSent": 1, "PacketsReceived": 1, "SessionEndReason": "aged-out", "DGHierarchyLevel1": 65537, "DGHierarchyLevel2": 65538, "DGHierarchyLevel3": 65541, "DGHierarchyLevel4": 0, "VirtualSystemName": "", "DeviceName": "VA8280-RN", "ActionSource": "from-policy", "SourceUUID": null, "DestinationUUID": null, "IMSI": 0, "IMEI": null, "ParentSessionID": 0, "ParentStarttime": "1970-01-01T00:00:00.000000Z", "Tunnel": "N/A", "EndpointAssociationID": 72057594037927936, "ChunksTotal": 0, "ChunksSent": 0, "ChunksReceived": 0, "RuleUUID": "95cfc3cc-cb00-4758-af1d-de9ab5f07f97", "HTTP2Connection": 0, "LinkChangeCount": 0, "SDWANPolicyName": null, "LinkSwitches": null, "SDWANCluster": null, "SDWANDeviceType": null, "SDWANClusterType": null, "SDWANSite": null, "DynamicUserGroupName": null, "X-Forwarded-ForIP": null, "SourceDeviceCategory": null, "SourceDeviceProfile": null, "SourceDeviceModel": null, "SourceDeviceVendor": null, "SourceDeviceOSFamily": null, "SourceDeviceOSVersion": null, "SourceDeviceHost": null, "SourceDeviceMac": null, "DestinationDeviceCategory": null, "DestinationDeviceProfile": null, "DestinationDeviceModel": null, "DestinationDeviceVendor": null, "DestinationDeviceOSFamily": null, "DestinationDeviceOSVersion": null, "DestinationDeviceHost": null, "DestinationDeviceMac": null, "ContainerID": null, "ContainerNameSpace": null, "ContainerName": null, "SourceEDL": null, "DestinationEDL": null, "GPHostID": null, "EndpointSerialNumber": null, "SourceDynamicAddressGroup": null, "DestinationDynamicAddressGroup": null, "HASessionOwner": null, "TimeGeneratedHighResolution": "2024-10-30T05:25:41.009000Z", "NSSAINetworkSliceType": null, "NSSAINetworkSliceDifferentiator": null}}"
Referência de mapeamento de campos: mapeamento de campos de registos para campos de UDM
Esta secção explica como o analisador mapeia os campos de registo da firewall do Palo Alto Networks Strata Logging Service para os campos de eventos da UDM da Google para cada tipo de registo.
Consulte as secções seguintes para obter uma referência de mapeamento de cada tipo de registo:
- Sistema
- Ameaça
- Tráfego
- ID do utilizador
- Correspondência de HIP
- Etiqueta de IP
- Desencriptação
- Túnel
- Autenticação
- URL
- GlobalProtect
- SCTP
- Auditoria
Sistema
A tabela seguinte lista os campos de registo do tipo de registo do sistema e os respetivos campos da UDM.
| Log field | UDM mapping |
|---|---|
| AgentContentVersion | additional.fields.key/value.string_value |
| AgentDataCollectionStatus | target.resource.attribute.labels |
| AgentID | target.resource.attribute.labels |
| AgentIsolationStatus | target.resource.attribute.labels |
| AgentStatus | target.resource.attribute.labels |
| AgentVersion | target.asset.software.version |
| ConfigVersion | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DeviceGroup | target.group.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EndpointCPUArchitecture | target.asset.hardware.cpu_platform |
| EndpointDeviceDomain | target.asset.administrative_domain |
| EndpointDeviceName | target.asset.hostname |
| EndpointIPaddress | target.asset.ip |
| VDIEndpoint | target.asset.attribute.labels |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointOSVersion | target.platform_version |
| AgentTimeZoneOffset | additional.fields.key/value.string_value |
| EndpointUserDomain | additional.fields.key/value.string_value |
| EndpointUserName | target.user.user_display_name |
| EndpointUserUUID | target.user.userid |
| EventComponent | additional.fields.key/value.string_value |
| EventDescription | metadata.description |
| EventName | additional.fields.key/value.string_value |
| EventTime | metadata.event_timestamp |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogCategory | security_result.category_details |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| LogSourceID | target.resource.attribute.labels |
| LogSourceName | observer.asset.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| LogTime | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Severity | security_result.severity |
| Subtype | metadata.product_event_type |
| Template | target.resource.attribute.labels |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
Ameaça
A tabela seguinte apresenta os campos de registo do tipo de registo de ameaças e os respetivos campos do UDM.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| ApplianceOrCloud | additional.fields.key/value.string_value |
| CloudHostname | additional.fields.key/value.string_value |
| CloudReportID | security_result.detection_fields.key/value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DirectionOfAttack | security_result.detection_fields.key/value |
| DomainEDL | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| FileName | target.file.names |
| FileHash | target.file.sha1 |
| FileType | additional.fields.key/value.string_value |
| FileURL | target.url |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HostID | principal.asset.asset_id |
| HTTP2Connection | network.application_protocol_version |
| HTTPMethod | network.http.method |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| LocalDeepLearningAnalyzed | additional.fields.key/value.string_value |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| PartialHash | additional.fields.key/value.string_value |
| PayloadProtocolID | additional.fields.key/value.string_value |
| Packet | additional.fields.key/value.string_value |
| PacketID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| RecipientEmail | target.user.email_addresses |
| ReportID | security_result.detection_fields.key/value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SenderEmail | principal.user.email_addresses |
| SequenceNo | metadata.product_log_id |
| SessionID | network.session_id |
| Severity | security_result.severity |
| SigFlags | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| EmailSubject | network.email.subject |
| ApplicationTechnology | additional.fields.key/value.string_value |
| ThreatCategory | security_result.detection_fields.key/value.key/value |
| ThreatID | security_result.threat_id |
| ThreatName | security_result.threat_name |
| ThreatNameFirewall | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLDomain | target.domain.name |
| URLCounter | additional.fields.key/value.string_value |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| Verdict | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-ForIP | principal.ip |
Trânsito
A tabela seguinte apresenta os campos de registo do tipo de registo de tráfego e os respetivos campos da UDM.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| ActionSource | additional.fields.key/value.string_value |
| AIFwdError | additional.fields.key/value.string_value |
| AITraffic | additional.fields.key/value.string_value |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| BytesReceived | network.received_bytes |
| BytesSent | network.sent_bytes |
| Bytes | additional.fields.key/value.string_value |
| ChunksReceived | additional.fields.key/value.string_value |
| ChunksSent | additional.fields.key/value.string_value |
| ChunksTotal | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| EndpointAssociationID | additional.fields.key/value.string_value |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HASessionOwner | additional.fields.key/value.string_value |
| GPHostID | additional.fields.key/value.string_value |
| HTTP2Connection | network.application_protocol_version |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsOffloaded | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| LinkChangeCount | additional.fields.key/value.string_value |
| LinkSwitches | additional.fields.key/value.string_value |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| SDWANPolicyName | additional.fields.key/value.string_value |
| Protocol | network.ip_protocol |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SDWANFECRatio | additional.fields.key/value.string_value |
| SDWANCluster | additional.fields.key/value.string_value |
| SDWANClusterType | additional.fields.key/value.string_value |
| SDWANDeviceType | additional.fields.key/value.string_value |
| SDWANSite | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionStartTime | additional.fields.key/value.string_value |
| SessionTracker | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| SessionDuration | network.session_duration |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLCategory | target.url_metadata.categories |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-ForIP | principal.ip |
User-ID
A tabela seguinte apresenta os campos de registo do tipo de registo User-ID e os respetivos campos da UDM.
| Log field | UDM mapping |
|---|---|
| AuthFactorNo | security_result.detection_fields.key/value |
| AuthenticatedUserDomain | target.user.administrative_domain |
| AuthenticatedUserName | target.user.userid |
| AuthenticatedUserUUID | target.user.product_object_id |
| ConfigVersion | additional.fields.key/value.string_value |
| CountofRepeats | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationPort | target.port |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EventID | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsDuplicateUser | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MappingDataSource | additional.fields.key/value.string_value |
| MappingDataSourceName | additional.fields.key/value.string_value |
| MappingDataSourceType | additional.fields.key/value.string_value |
| MappingTimeout | additional.fields.key/value.string_value |
| MFAFactorType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SourceIP | principal.ip |
| SourcePort | principal.port |
| Subtype | metadata.product_event_type |
| Tag | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| UGFlags | additional.fields.key/value.string_value |
| User | target.user.userid |
| UserGroupFound | additional.fields.key/value.string_value |
| UserIdentifiedBySource | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Correspondência de HIP
A tabela seguinte apresenta os campos de registo do tipo de registo de correspondência de HIP e os respetivos campos de UDM.
| Log field | UDM mapping |
|---|---|
| ConfigVersion | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EndpointDeviceName | principal.asset.hostname |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| HipMatchName | target.resource.attribute.labels |
| HipMatchType | target.resource.attribute.labels |
| HostID | principal.asset.asset_id |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | metadata.product_event_type |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Source | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceIP | principal.ip |
| SourceIPv6 | principal.ip |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| TimestampDeviceIdentification | principal.asset.first_seen_time |
| UUID | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
Etiqueta de IP
A tabela seguinte apresenta os campos de registo do tipo de registo de etiquetas de IP e os respetivos campos da UDM.
| Log field | UDM mapping |
|---|---|
| ConfigVersion | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| TenantID | metadata.product_deployment_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| EventID | additional.fields.key/value.string_value |
| IPSubnetRange | network.ip_subnet_range |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSetting | target.resource.attribute.labels |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MappingDataSource | additional.fields.key/value.string_value |
| MappingDataSourceSubType | additional.fields.key/value.string_value |
| MappingDataSourceType | additional.fields.key/value.string_value |
| MappingTimeout | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| RuleMatched | security_result.rule_name |
| RuleMatchedUUID | security_result.rule_id |
| SequenceNo | metadata.product_log_id |
| SourceIP | principal.ip |
| Subtype | metadata.product_event_type |
| TagName | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | target.asset.attribute.labels |
| VirtualSystemID | target.resource.product_object_id |
| VirtualSystemName | target.asset.attribute.labels |
Desencriptação
A tabela seguinte lista os campos de registo do tipo de registo de descifragem e os respetivos campos da UDM.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| CertificateFlags | additional.fields.key/value.string_value |
| CertificateSerial | network.tls.server.certificate.serial |
| CertificateSize | additional.fields.key/value.string_value |
| CertificateVersion | network.tls.server.certificate.version |
| ChainStatus | additional.fields.key/value.string_value |
| ApplicationCharacteristics | additional.fields.key/value.string_value |
| ClientToFirewall | additional.fields.key/value.string_value |
| CommonName | additional.fields.key/value.string_value |
| CommonNameLength | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| Cpadding | additional.fields.key/value.string_value |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| Domain | target.hostname |
| EllipticCurve | network.tls.curve |
| ErrorIndex | additional.fields.key/value.string_value |
| ErrorMessage | additional.fields.key/value.string_value |
| Fingerprint | network.tls.server.certificate.md5/sha1/sha256 |
| FirewallToClient | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsCertECDSA | additional.fields.key/value.string_value |
| IsCertRSA | additional.fields.key/value.string_value |
| IsCertCNTruncated | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| IsForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsIssuerCNTruncated | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| IsNAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| PacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsResumeSession | additional.fields.key/value.string_value |
| IsRootCNTruncated | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSNITruncated | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| IssuerCommonName | network.tls.server.certificate.issuer |
| IssuerNameLength | additional.fields.key/value.string_value |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| TimeNotAfter | additional.fields.key/value.string_value |
| TimeNotBefore | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| Padding | additional.fields.key/value.string_value |
| Padding3 | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| PolicyName | additional.fields.key/value.string_value |
| Protocol | network.ip_protocol |
| ProxyType | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| RootCommonName | additional.fields.key/value.string_value |
| RootCNLength | additional.fields.key/value.string_value |
| RootStatus | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SessionID | network.session_id |
| ServerNameIndication | network.tls.client.server_name |
| SNILength | additional.fields.key/value.string_value |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeReceivedManagementPlane | additional.fields.key/value.string_value |
| TLSAuth | additional.fields.key/value.string_value |
| TLSEncryptionAlgorithm | additional.fields.key/value.string_value |
| TLSKeyExchange | additional.fields.key/value.string_value |
| TLSVersion | network.tls.version |
| ToZone | additional.fields.key/value.string_value |
| Tpadding | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| Vpadding | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Túnel
A tabela seguinte apresenta os campos de registo do tipo de registo de túnel e os respetivos campos da UDM.
| Log field | UDM mapping |
|---|---|
| AccessPointName | additional.fields.key/value.string_value |
| Action | security_result.action |
| ActionSource | additional.fields.key/value.string_value |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| BytesReceived | network.received_bytes |
| BytesSent | network.sent_bytes |
| Bytes | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| LoggingServiceID | additional.fields.key/value.string_value |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MobileAreaCode | additional.fields.key/value.string_value |
| MobileBaseStationCode | additional.fields.key/value.string_value |
| MobileCountryCode | additional.fields.key/value.string_value |
| MobileIP | additional.fields.key/value.string_value |
| MobileNetworkCode | additional.fields.key/value.string_value |
| MobileSubscriberISDN | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceDifferentiator | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsDroppedMax | additional.fields.key/value.string_value |
| PacketsDroppedStrict | additional.fields.key/value.string_value |
| PacketsDroppedTunnel | additional.fields.key/value.string_value |
| PacketsDroppedProtocol | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| ProtocolDataUnitsessionID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| RadioAccessTechnology | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionStartTime | additional.fields.key/value.string_value |
| SessionTracker | additional.fields.key/value.string_value |
| Severity | security_result.severity |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| StandardPortsOfApp | additional.fields.key/value.string_value |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| SessionDuration | network.session_duration |
| Tunnel | additional.fields.key/value.string_value |
| TunnelCauseCode | additional.fields.key/value.string_value |
| TunnelEndpointID1 | additional.fields.key/value.string_value |
| TunnelEndpointID2 | additional.fields.key/value.string_value |
| TunnelEventCode | additional.fields.key/value.string_value |
| TunnelEventType | additional.fields.key/value.string_value |
| TunnelInspectionRule | additional.fields.key/value.string_value |
| TunnelInterface | additional.fields.key/value.string_value |
| TunnelMessageType | additional.fields.key/value.string_value |
| TunnelRemoteIMSIID | additional.fields.key/value.string_value |
| TunnelRemoteUserIP | principal.ip |
| TunnelSessionsClosed | additional.fields.key/value.string_value |
| TunnelSessionsCreated | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URLCategory | target.url_metadata.categories |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Autenticação
A tabela seguinte lista os campos de registo do tipo de registo de autenticação e os respetivos campos UDM.
| Log field | UDM mapping |
|---|---|
| AuthenticationDescription | security_result.description |
| AuthEvent | metadata.description |
| AuthFactorNo | security_result.detection_fields.key/value |
| AuthenticationPolicy | security_result.detection_fields.key/value |
| AuthenticationProtocol | additional.fields.key/value.string_value |
| AuthServerProfile | additional.fields.key/value.string_value |
| AuthenticatedUserDomain | target.administrative_domain |
| AuthenticatedUserName | target.user.userid |
| AuthenticatedUserUUID | target.user.product_object_id |
| ClientType | additional.fields.key/value.string_value |
| ClientTypeName | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| Location | target.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogType | additional.fields.key/value.string_value |
| MFAAuthenticationID | additional.fields.key/value.string_value |
| MFAVendor | additional.fields.key/value.string_value |
| NormalizeUser | target.user.user_display_name |
| Object | target.resource.name |
| RuleMatched | security_result.rule_name |
| RuleMatchedUUID | security_result.rule_id |
| AuthCacheServiceRegion | additional.fields.key/value.string_value |
| SessionID | network.session_id |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceIP | principal.ip |
| TimeGenerated | metadata.event_timestamp |
| User | target.user.userid |
| UserAgentString | network.http.user_agent |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| Subtype | metadata.product_event_type |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
URL
A tabela seguinte apresenta os campos de registo do tipo de registo de URL e os respetivos campos da UDM.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| ApplicationCategory | additional.fields.key/value.string_value |
| ApplicationSubcategory | additional.fields.key/value.string_value |
| CloudHostname | additional.fields.key/value.string_value |
| CloudReportID | security_result.detection_fields.key/value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ApplicationContainer | additional.fields.key/value.string_value |
| ContentType | additional.fields.key/value.string_value |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceCategory | target.asset.category |
| DestinationDeviceClass | additional.fields.key/value.string_value |
| DestinationDeviceHost | target.asset.hostname |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceOSFamily | additional.fields.key/value.string_value |
| DestinationDeviceOSVersion | target.platform_version |
| DestinationDeviceProfile | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationAddress | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DirectionOfAttack | security_result.detection_fields.key/value |
| DynamicUserGroupName | additional.fields.key/value.string_value |
| EndpointSerialNumber | principal.asset.hardware.serial_number |
| FileURL | target.url |
| FlowType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| HostID | principal.asset.asset_id |
| HTTP2Connection | network.application_protocol_version |
| HTTPHeaders | additional.fields.key/value.string_value |
| HTTPMethod | network.http.method |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| InlineMLVerdict | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecrypted | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| IsEncrypted | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsSaaSApplication | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLDenied | additional.fields.key/value.string_value |
| K8SClusterID | target.resource.attribute.labels |
| Location | observer.location.country_or_region |
| LogSetting | intermediary.resource.attribute.labels |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| IMEI | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| NonStandardDestinationPort | additional.fields.key/value.string_value |
| NSSAINetworkSliceType | additional.fields.key/value.string_value |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| ParentSessionID | network.parent_session_id |
| ParentStarttime | additional.fields.key/value.string_value |
| Packet | additional.fields.key/value.string_value |
| PacketID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| Referer | network.http.referral_url |
| HTTPRefererFQDN | additional.fields.key/value.string_value |
| HTTPRefererPort | additional.fields.key/value.string_value |
| HTTPRefererProtocol | additional.fields.key/value.string_value |
| HTTPRefererURLPath | additional.fields.key/value.string_value |
| ApplicationRisk | additional.fields.key/value.string_value |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SanctionedStateOfApp | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionID | network.session_id |
| Severity | security_result.severity |
| SigFlags | additional.fields.key/value.string_value |
| SourceDeviceCategory | principal.asset.category |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceHost | principal.hostname |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceOSFamily | additional.fields.key/value.string_value |
| SourceDeviceOSVersion | principal.platform_version |
| SourceDeviceProfile | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceAddress | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| ApplicationTechnology | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| TunneledApplication | additional.fields.key/value.string_value |
| IMSI | additional.fields.key/value.string_value |
| URL | target.url_metadata.URL |
| URLCategory | target.url_metadata.categories |
| URLCategoryList | additional.fields.key/value.string_value |
| URLDomain | target.domain.name |
| URLCounter | additional.fields.key/value.string_value |
| UserAgent | network.http.user_agent |
| Users | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
| X-Forwarded-For | additional.fields.key/value.string_value |
| X-Forwarded-ForIP | principal.ip |
GlobalProtect
A tabela seguinte apresenta os campos de registo do tipo de registo GlobalProtect e os respetivos campos da UDM.
| Log field | UDM mapping |
|---|---|
| AttemptedGateways | additional.fields.key/value.string_value |
| AuthMethod | extensions.auth.auth_details |
| ConnectionMethod | additional.fields.key/value.string_value |
| ConnectionErrorID | additional.fields.key/value.string_value |
| ConnectionError | additional.fields.key/value.string_value |
| CountOfRepeats | additional.fields.key/value.string_value |
| EndpointDeviceName | principal.asset.hostname |
| GlobalProtectClientVersion | additional.fields.key/value.string_value |
| EndpointOSType | additional.fields.key/value.string_value |
| EndpointSN | principal.asset.hardware.serial_number |
| EventIDValue | additional.fields.key/value.string_value |
| Gateway | target.resource.name |
| GatewayPriority | additional.fields.key/value.string_value |
| GatewaySelectionType | additional.fields.key/value.string_value |
| GlobalProtectGatewayLocation | target.location.country_or_region |
| HostID | principal.asset.asset_id |
| LogSource | intermediary.resource.attribute.labels |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LoginDuration | network.session_duration |
| Description | security_result.description |
| Portal | target.hostname |
| PrivateIPv4 | principal.ip |
| PrivateIPv6 | principal.ip |
| ProjectName | additional.fields.key/value.string_value |
| PublicIPv4 | principal.nat_ip |
| PublicIPv6 | principal.nat_ip |
| QuarantineReason | security_result.summary |
| SequenceNo | metadata.product_log_id |
| SourceRegion | principal.location.country_or_region |
| SourceUserName | principal.user.user_display_name |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SSLResponseTime | additional.fields.key/value.string_value |
| Stage | additional.fields.key/value.string_value |
| EventStatus | additional.fields.key/value.string_value |
| LogSubtype | metadata.product_event_type |
| TunnelType | additional.fields.key/value.string_value |
| VirtualSystem | intermediary.asset.attribute.labels |
| VirtualSystemName | intermediary.asset.attribute.labels |
| EndpointOSVersion | principal.platform_version |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsPrismaNetworks | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | metadata.product_event_type |
| PanoramaSN | observer.asset.hardware.serial_number |
| PlatformType | additional.fields.key/value.string_value |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VirtualSystemID | intermediary.resource.product_object_id |
SCTP
A tabela seguinte indica os campos de registo do tipo de registo SCTP e os respetivos campos UDM.
| Log field | UDM mapping |
|---|---|
| Action | security_result.action |
| Application | target.application |
| AssocationEndReason | additional.fields.key/value.string_value |
| ChunksReceived | additional.fields.key/value.string_value |
| ChunksSent | additional.fields.key/value.string_value |
| ChunksTotal | additional.fields.key/value.string_value |
| ConfigVersion | additional.fields.key/value.string_value |
| ContainerID | intermediary.resource.product_object_id |
| ContentVersion | additional.fields.key/value.string_value |
| RepeatCount | additional.fields.key/value.string_value |
| CortexDataLakeTenantID | metadata.product_deployment_id |
| DestinationDeviceClass | target.asset.category |
| DestinationDeviceMac | target.asset.mac |
| DestinationDeviceModel | target.asset.hardware.model |
| DestinationDeviceOS | additional.fields.key/value.string_value |
| DestinationDeviceVendor | target.asset.hardware.manufacturer |
| DestinationDynamicAddressGroup | target.group.group_display_name |
| DestinationEDL | additional.fields.key/value.string_value |
| DestinationIP | target.ip |
| DestinationLocation | target.location.country_or_region |
| DestinationPort | target.port |
| DestinationUser | target.user.userid |
| DestinationUserDomain | target.administrative_domain |
| DestinationUserName | target.user.user_display_name |
| DestinationUserUUID | target.user.product_object_id |
| DestinationUUID | target.resource.product_object_id |
| DGHierarchyLevel1 | additional.fields.key/value.string_value |
| DGHierarchyLevel2 | additional.fields.key/value.string_value |
| DGHierarchyLevel3 | additional.fields.key/value.string_value |
| DGHierarchyLevel4 | additional.fields.key/value.string_value |
| DiamAppID | additional.fields.key/value.string_value |
| DiamAvpCode | additional.fields.key/value.string_value |
| DiameterCommandCode | additional.fields.key/value.string_value |
| DiameterRequestFlag | additional.fields.key/value.string_value |
| DeviceName | principal.asset.hostname |
| SCTPEventType | additional.fields.key/value.string_value |
| FromZone | additional.fields.key/value.string_value |
| InboundInterface | additional.fields.key/value.string_value |
| InboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| InboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| InboundInterfaceDetailsType | additional.fields.key/value.string_value |
| InboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| CaptivePortal | additional.fields.key/value.string_value |
| IsClienttoServer | additional.fields.key/value.string_value |
| IsContainer | additional.fields.key/value.string_value |
| IsDecryptMirror | additional.fields.key/value.string_value |
| IsDecryptedPayloadForward | additional.fields.key/value.string_value |
| IsDecryptedLog | additional.fields.key/value.string_value |
| IsDuplicateLog | additional.fields.key/value.string_value |
| LogExported | additional.fields.key/value.string_value |
| LogForwarded | additional.fields.key/value.string_value |
| IsIPV6 | additional.fields.key/value.string_value |
| IsInspectionBeforeSession | additional.fields.key/value.string_value |
| IsMptcpOn | additional.fields.key/value.string_value |
| NAT | additional.fields.key/value.string_value |
| IsNonStandardDestinationPort | additional.fields.key/value.string_value |
| IsPacketCapture | additional.fields.key/value.string_value |
| IsPhishing | additional.fields.key/value.string_value |
| IsPrismaNetwork | additional.fields.key/value.string_value |
| IsPrismaUsers | additional.fields.key/value.string_value |
| IsProxy | additional.fields.key/value.string_value |
| IsReconExcluded | additional.fields.key/value.string_value |
| IsServertoClient | additional.fields.key/value.string_value |
| IsSourceXForwarded | additional.fields.key/value.string_value |
| IsSystemReturn | additional.fields.key/value.string_value |
| IsTransaction | additional.fields.key/value.string_value |
| IsTunnelInspected | additional.fields.key/value.string_value |
| IsURLFiltering | additional.fields.key/value.string_value |
| IsWildfire | additional.fields.key/value.string_value |
| LogAction | additional.fields.key/value.string_value |
| LogSourceGroupID | intermediary.resource.attribute.labels |
| DeviceSN | intermediary.asset.hardware.serial_number |
| DeviceName | intermediary.hostname |
| LogSourceTimeZoneOffset | additional.fields.key/value.string_value |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| MapAppCode | additional.fields.key/value.string_value |
| NATDestination | target.nat_ip |
| NATDestinationPort | target.nat_port |
| NATSource | principal.nat_ip |
| NATSourcePort | principal.nat_port |
| OutboundInterface | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsPort | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsSlot | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsType | additional.fields.key/value.string_value |
| OutboundInterfaceDetailsUnit | additional.fields.key/value.string_value |
| PacketsReceived | network.received_packets |
| PacketsSent | network.sent_packets |
| PacketsTotal | additional.fields.key/value.string_value |
| PanoramaSN | observer.asset.hardware.serial_number |
| PayloadProtocolID | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| ContainerName | target.resource.name |
| ContainerNameSpace | target.resource.attribute.labels |
| Protocol | network.ip_protocol |
| Rule | security_result.rule_name |
| RuleUUID | security_result.rule_id |
| SccpCallingGt | additional.fields.key/value.string_value |
| SccpCallingSSN | additional.fields.key/value.string_value |
| SctpCauseCode | additional.fields.key/value.string_value |
| SctpChunkType | additional.fields.key/value.string_value |
| SctpFilter | additional.fields.key/value.string_value |
| SequenceNo | metadata.product_log_id |
| SessionOwnerMidx | additional.fields.key/value.string_value |
| SessionEndReason | security_result.summary |
| SessionID | network.session_id |
| SessionTracker | additional.fields.key/value.string_value |
| Severity | security_result.severity |
| SourceDeviceClass | additional.fields.key/value.string_value |
| SourceDeviceMac | principal.asset.mac |
| SourceDeviceModel | principal.asset.hardware.model |
| SourceDeviceOS | additional.fields.key/value.string_value |
| SourceDeviceVendor | principal.asset.hardware.manufacturer |
| SourceDynamicAddressGroup | principal.group.group_display_name |
| SourceEDL | additional.fields.key/value.string_value |
| SourceIP | principal.ip |
| SourceLocation | principal.location.country_or_region |
| SourcePort | principal.port |
| SourceUser | principal.user.userid |
| SourceUserDomain | principal.administrative_domain |
| SourceUserName | principal.user.user_display_name |
| SourceUserUUID | principal.user.product_object_id |
| SourceUUID | principal.resource.product_object_id |
| Subtype | metadata.product_event_type |
| TimeGenerated | metadata.event_timestamp |
| TimeGeneratedHighResolution | additional.fields.key/value.string_value |
| ToZone | additional.fields.key/value.string_value |
| Tunnel | additional.fields.key/value.string_value |
| VendorName | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
| VerificationTag1 | additional.fields.key/value.string_value |
| VerificationTag2 | additional.fields.key/value.string_value |
| VirtualLocation | intermediary.asset.attribute.labels |
| VirtualSystemID | intermediary.resource.product_object_id |
| VirtualSystemName | intermediary.asset.attribute.labels |
Auditoria
A tabela seguinte apresenta os campos de registo do tipo de registo de auditoria e os respetivos campos da UDM.
| Log field | UDM mapping |
|---|---|
| EventCategory | network.http.method |
| EventDescription | metadata.description |
| EventDestinationURL | target.url |
| EventDestinationUserUserID | target.user.userid |
| DestinationVendor | additional.fields.key/value.string_value |
| EventDetails | additional.fields.key/value.string_value |
| EventID | metadata.product_log_id |
| EventName | additional.fields.key/value.string_value |
| EventResult | security_result.summary |
| EventSourceUserUserID | principal.user.userid |
| EventTime | metadata.event_timestamp |
| LogSource | target.resource.attribute.labels |
| LogSourceGroupID | target.resource.attribute.labels |
| DeviceSN | target.asset.hardware.serial_number |
| DeviceName | target.hostname |
| TimeReceived | metadata.collected_timestamp |
| LogType | additional.fields.key/value.string_value |
| PlatformType | additional.fields.key/value.string_value |
| Subtype | metadata.product_event_type |
| TSGID | additional.fields.key/value.string_value |
| Vendor | additional.fields.key/value.string_value |
| VendorSeverity | security_result.severity_details |
Referência de mapeamento de campos: tipos de registos para o tipo de evento da UDM
A tabela seguinte indica os tipos de registos de firewall do serviço de registo do Palo Alto Networks Strata e os respetivos tipos de eventos do UDM.
| Tipo de registo | Tipo de evento UDM |
| Trânsito | NETWORK_CONNECTION |
| Ameaça | NETWORK_CONNECTION |
| Filtragem de URLs | NETWORK_CONNECTION |
| Túnel | NETWORK_CONNECTION |
| Sistema |
Se o valor do subtipo for "dhcp", é definido NETWORK_DHCP. Se o valor do subtipo for "auth", USER_LOGIN é definido. Se o valor da descrição for "logged in", USER_LOGIN é definido. Se o valor da descrição for "logged out", USER_LOGOUT é definido. Para outros valores do subtipo, é definido GENERIC_EVENT. |
| HIP Match | NETWORK_CONNECTION |
| Etiqueta de IP | GENERIC_EVENT |
| User-ID | USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED
Se o valor do subtipo for "login", USER_LOGIN é definido. Se o valor do subtipo for "logout", é definido USER_LOGOUT. Se o subtipo não contiver nenhum valor, é definido USER_UNCATEGORIZED. |
| Desencriptação | NETWORK_CONNECTION |
| Autenticação | STATUS_UNCATEGORIZED |
| Globalprotect | USER_LOGIN/USER_LOGOUT/USER_RESOURCE_ACCESS
Se o valor do subtipo for "auth", USER_LOGIN é definido. Se o valor do subtipo for "logout", é definido USER_LOGOUT. Se o subtipo não contiver nenhum valor, é definido USER_RESOURCE_ACCESS. |
| SCTP | NETWORK_CONNECTION |
| Auditoria | NETWORK_CONNECTION |
O que se segue?
Precisa de mais ajuda? Receba respostas de membros da comunidade e profissionais da Google SecOps.