Recolha registos de firewall da Palo Alto Networks

Suportado em:

Firewall da Palo Alto Networks

Vista geral

Este documento descreve como pode configurar o syslog e um encaminhador do Google SecOps para recolher registos da firewall da Palo Alto Networks. Este documento também explica como os campos de registo da firewall da Palo Alto Networks são mapeados para os campos do modelo de dados unificado (UDM) do Google SecOps. Para uma vista geral sobre a ingestão de dados do Google SecOps, consulte o artigo Ingestão de dados no Google SecOps. Uma etiqueta de carregamento identifica o analisador que normaliza os dados de registo não processados para o formato UDM estruturado. As informações neste documento aplicam-se ao analisador com a etiqueta de carregamento PAN_FIREWALL.

Antes de começar

  • Certifique-se de que o produto de firewall da Palo Alto Networks está implementado e configurado corretamente. Para ver instruções de configuração detalhadas, consulte a documentação do PAN-OS.
  • Para compreender os componentes implementados para recolher registos da firewall da Palo Alto Networks, reveja a arquitetura de implementação. Cada implementação do cliente pode diferir desta representação e pode ser mais complexa. O diagrama seguinte mostra como pode configurar o syslog numa firewall da Palo Alto Networks e instalar um encaminhador do Google SecOps num servidor Linux para encaminhar dados de registo para o Google SecOps. O analisador suporta registos escritos nos seguintes formatos de dados: valores separados por vírgulas (CSV), formato de evento comum (CEF) e formato de evento de registo alargado (LEEF).

    Arquitetura de implementação

  • Verifique os formatos de registo e as versões do PAN-OS suportados pelo analisador do Google SecOps. A tabela seguinte indica os formatos de registo e as versões do PAN-OS correspondentes suportadas pelo analisador do Google SecOps:

    Formato do registo Versão do PAN-OS
    CSV 10.1.3
    CEF 10.0.0
    LEEF 9.1.0
  • Valide os tipos de registos da firewall da Palo Alto Networks que o analisador do Google SecOps suporta. O analisador do Google SecOps suporta os seguintes tipos de registos de firewall da Palo Alto Networks:

    • Trânsito
    • Ameaça
    • Envios do WildFire
    • Inspeção de túneis
    • Configuração
    • Sistema
    • Correspondência de HIP
    • IP-Tag
    • User-ID
    • Desencriptação
    • Autenticação
    • Filtragem de URLs
    • Filtragem de dados
    • GlobalProtect
    • Correlação
    • GTP
    • SCTP
    • Auditoria

    Para mais informações sobre os tipos de registos da firewall da Palo Alto Networks, consulte Tipos de registos do PAN-OS.

  • Certifique-se de que todos os sistemas na arquitetura de implementação estão configurados no fuso horário UTC.

  • Antes de usar o analisador do firewall da Palo Alto Networks, reveja as alterações nas associações de campos entre o analisador anterior e o analisador do firewall da Palo Alto Networks atual. Como parte da migração, certifique-se de que as regras, as pesquisas, os painéis de controlo ou outros processos que dependem dos campos originais usam os campos atualizados.

    Por exemplo, na versão anterior do analisador, o campo de registo category é mapeado para o campo UDM security_result.description. No analisador do firewall da Palo Alto Networks atual, o campo de registo category é mapeado para o campo UDM security_result.category_details. Se migrar para o analisador de firewall da Palo Alto Networks atual e usar o campo category nas suas regras, tem de modificar as regras para usar o campo security_result.category_details UDM do analisador atual.

Configure o syslog e o encaminhador do Google Security Operations

Para configurar o syslog e o encaminhador do Google SecOps, conclua os seguintes passos:

  1. Para monitorizar registos CSV, configure o perfil do servidor syslog. Para mais informações, consulte o artigo Configure o perfil do servidor syslog. Quando configurar o perfil do servidor syslog, especifique "Predefinição" como o formato de registo personalizado.
  2. Para monitorizar registos CEF, configure a firewall da Palo Alto Networks para encaminhar registos CEF. Para mais informações, transfira o PDF do guia de integração de CEF do PAN-OS e consulte a secção "Configuração do NGFW da Palo Alto Networks para gerar eventos CEF".
  3. Para monitorizar registos LEEF, configure o perfil do servidor syslog. Para mais informações, consulte o artigo Encaminhamento de registos personalizados no formato LEEF.
  4. Configure o encaminhador do Google SecOps para enviar registos para o Google Security Operations. Para mais informações, consulte o artigo Instalar e configurar o encaminhador no Linux. Segue-se um exemplo de uma configuração de encaminhador do Google SecOps:

      - syslog:
          common:
            enabled: true
            data_type: PAN_FIREWALL
            batch_n_seconds: 10
            batch_n_bytes: 1048576
          tcp_address: 0.0.0.0:10518
          connection_timeout_sec: 60
    

Configure o encaminhamento de syslog na firewall da PAN

Crie um perfil de servidor syslog

  1. Inicie sessão na consola de gestão da firewall da Palo Alto Networks.
  2. Aceda a Dispositivo > Perfis do servidor > Syslog.
  3. Clique em Adicionar para criar um novo perfil de servidor.
  4. Forneça os seguintes detalhes de configuração:
    • Nome: introduza um nome descritivo (por exemplo, Google SecOps BindPlane).
    • Localização: selecione o sistema virtual (vsys) ou Partilhado onde este perfil vai estar disponível.
  5. Clique em Servidores > Adicionar para configurar o servidor syslog.
  6. Indique os seguintes detalhes de configuração do servidor:
    • Nome: introduza um nome descritivo para o servidor (por exemplo, BindPlane Agent).
    • Servidor Syslog: introduza o endereço IP do agente BindPlane.
    • Transporte: selecione UDP ou TCP, consoante a configuração do agente BindPlane (UDP é a predefinição).
    • Porta: introduza o número da porta do agente BindPlane (por exemplo, 514).
    • Formato: selecione BSD (predefinição) ou IETF, consoante os seus requisitos.
    • Facility: selecione LOG_USER (predefinição) ou outra funcionalidade, conforme necessário.
  7. Clique em OK para guardar o perfil do servidor syslog.

Opcional: configure o formato de registo personalizado para CEF ou LEEF

Se precisar de registos CEF (Common Event Format) ou LEEF (Log Event Extended Format) em vez de CSV:

  1. No perfil do servidor Syslog, selecione o separador Formato de registo personalizado.
  2. Configure o formato de registo personalizado para cada tipo de registo (Config, System, Threat, Traffic, URL, Data, WildFire, Tunnel, Authentication, User-ID, HIP Match).
  3. Para a configuração do formato CEF, consulte o guia de configuração do CEF da Palo Alto Networks.
  4. Clique em OK para guardar a configuração.

Crie um perfil de encaminhamento de registos

  1. Aceda a Objetos > Encaminhamento de registos.
  2. Clique em Adicionar para criar um novo perfil de encaminhamento de registos.
  3. Forneça os seguintes detalhes de configuração:
    • Nome: introduza um nome de perfil (por exemplo, Google SecOps Forwarding). Se quiser que a firewall atribua automaticamente este perfil a novas regras e zonas de segurança, atribua-lhe o nome default.
  4. Para cada tipo de registo que quer encaminhar (Tráfego, Ameaça, Envio do WildFire, Filtragem de URLs, Filtragem de dados, Túnel, Autenticação), configure o seguinte:
    • Clique em Adicionar na secção do tipo de registo respetiva.
    • Syslog: selecione o perfil do servidor syslog que criou (por exemplo, Google SecOps BindPlane).
    • Gravidade do registo: selecione os níveis de gravidade a encaminhar (por exemplo, Tudo).
  5. Clique em OK para guardar o perfil de encaminhamento de registos.

Aplique o perfil de encaminhamento de registos às políticas de segurança

  1. Aceda a Políticas > Segurança.
  2. Selecione as regras de segurança para as quais quer ativar o encaminhamento de registos.
  3. Clique na regra para a editar.
  4. Aceda ao separador Ações.
  5. No menu Encaminhamento de registos, selecione o perfil de encaminhamento de registos que criou (por exemplo, Google SecOps Forwarding).
  6. Clique em OK para guardar a configuração da política de segurança.

Configure as definições de registo para registos do sistema

  1. Aceda a Dispositivo > Definições de registo.
  2. Para cada tipo de registo (Sistema, Configuração, ID do utilizador, HIP Match, Global Protect, IP-Tag, SCTP) e nível de gravidade, selecione o perfil do servidor Syslog que criou.
  3. Clique em OK para guardar as definições de registo.

Confirme as alterações

  1. Clique em Confirmar na parte superior da interface Web da firewall.
  2. Aguarde até que a confirmação seja concluída com êxito.
  3. Verifique se os registos estão a ser enviados para o agente do Bindplane verificando se existem registos de firewall da Palo Alto Networks na consola do Google SecOps.

Encaminhe registos para o Google SecOps através do agente Bindplane

  1. Instale e configure uma máquina virtual Linux.
  2. Instale e configure o agente Bindplane no Linux para encaminhar registos para o Google SecOps. Para mais informações sobre como instalar e configurar o agente Bindplane, consulte as instruções de instalação e configuração do agente Bindplane.

Se tiver problemas ao criar feeds, contacte o apoio técnico da Google SecOps.

Formatos de registo suportados

O analisador do firewall da Palo Alto Networks suporta registos nos formatos LEEF,CEF e CSV.

Registos de exemplo suportados

  • LEEF

    <14>Jan 22 02:20:19 device_host LEEF:1.0|Palo Alto Networks|PAN-OS Syslog Integration|10.2.12-h4|Microsoft MSOFFICE(52033)|ReceiveTime=2025/01/22 02:20:18|SerialNumber=01250100xxxx|cat=THREAT|Subtype=wildfire|devTime=Jan 22 2025 08:20:18 GMT|src=198.50.100.1|dst=198.50.100.2|srcPostNAT=198.50.100.3|dstPostNAT=198.50.100.4|RuleName=AZURE-US-NEW-CNF_Inbound_To_Azure-ALLOW|usrName=|SourceUser=|DestinationUser=|Application=smtp-base|VirtualSystem=vsys1|SourceZone=McD-Global-Zone|DestinationZone=Azure-Zone|IngressInterface=ae1.111|EgressInterface=ae2.409|LogForwardingProfile=Default-Traffic-Logging|SessionID=35331795|RepeatCount=1|srcPort=21578|dstPort=25|srcPostNATPort=0|dstPostNATPort=0|Flags=0x2000|proto=tcp|action=allow|Miscellaneous=\"......3...................xls\"|ThreatID=Microsoft MSOFFICE(52033)|URLCategory=malicious|sev=4|Severity=high|Direction=client-to-server|sequence=7462614601465681755|ActionFlags=0x8000000000000000|SourceLocation=198.50.100.1-198.50.100.255|DestinationLocation=United States|ContentType=|PCAP_ID=0|FileDigest=0ea04c99bf188c2e4207f60f92ca7c6f5088c7943ee63f45c50032bbd2bf7ea9|Cloud=demo.com|URLIndex=1|RequestMethod=|FileType=ms-office|Sender=sender@ab.myownpersonaldomain.com|Subject=\"............:.................................................................................-.........(Name)-2025-01-22...............:Y107202501220005, ............:........................, ...............:.........\"|Recipient=abc@demo.myownpersonaldomain.com|ReportID=117022282776|DeviceGroupHierarchyL1=143|DeviceGroupHierarchyL2=144|DeviceGroupHierarchyL3=39|DeviceGroupHierarchyL4=0|vSrcName=|DeviceName=device_host|SrcUUID=|DstUUID=|TunnelID=0|MonitorTag=|ParentSessionID=0|ParentStartTime=|TunnelType=N/A|ThreatCategory=N/A|ContentVer=WildFire-0
    
  • CEF

    14>1 2024-04-04T16:21:56+02:00 FW-PERIMETRAL-AVG-01 - - - - CEF:0|Palo Alto Networks|PAN-OS|10.1.10-h2|end|TRAFFIC|1|src=198.51.100.1 dst=198.51.100.2 srcTranslatedAddress=198.51.100.3 dstTranslatedAddress=198.51.100.4 rule=FW_USER_NATS2_APP suser= duser= app=bittorrent vs=vsys1 sz=INSIDE dz=EXTERNAL InboundInterface=ae2.2266 OutboundInterface=ae1 lp=log_forwarding sid=2935823 cnt=1 spt=6881 dpt=51413 srcTranslatedPort=0 dstTranslatedPort=0 flags=0x7a proto=udp act=allow tbytes=475 in=150 out=325 pkt=2 pktReceived=1 pktSent=1 start=Apr 04 2024 14:21:56 GMT stime=1206 urlcat=any externalId=externalId reason=aged-out DGl1=11 DGl2=161 DGl3=0 DGl4=0 VsysName=STONESOFT dvchost=FW-PERIMETRAL-AVG-01 cat=from-policy ActionFlags=0x8000000000000000 srcUUID= dstUUID= TunnelID=0 MonitorTag= ParentSessionID=0 ParentStartTime= TunnelType=N/A SCTPAssocID=0 SCTPChunks=0 SCTPChunkSent=0 SCTPChunksRcv=0 RuleUUID=746c3eb6-3d51-4679-8438-bd0e00e170a8 HTTP2Con=0 LinkChange=0 PolicyID= LinkDetail= SDWANCluster= SDWANDevice= SDWANClustype= SDWANSite= DynamicUsrgrp= XFFIP= srcDevCat= srcDevProf= srcDevModel= srcDevVendor= srcDevOS= srcDevOSv= srcHostname= srcMac= dstDevCat= dstDevProf= dstDevModel= dstDevVendor= dstDevOS= dstDevOSv= dstHostname= dstMac= ContainerName= PODNamespace= PODName= srcEDL= dstEDL= GPHostID= EPSerial= srcDAG= dstDAG= HASessionOwner= TimeHighRes=2024-04-04T16:21:56.250+02:00 ASServiceType= ASServiceDiff="
    
  • CSV

    1,2021/10/24 15:30:07,,CONFIG,0,2561,2021/10/24 15:30:07,198.51.100.0,,set,admin,Web,Succeeded, network virtual-router  VR1,,VR1  { ecmp { algorithm { ip-modulo ; } } protocol { bgp { routing-options { graceful-restart { enable yes; } } enable no; } rip { enable no; } ospf { enable no; } ospfv3 { enable no; } } routing-table { ip { static-route { vr1-log  { path-monitor { enable no; failure-condition any; hold-time 2; } nexthop { ip-address 198.51.100.0; } bfd { profile None; } interface ethernet1/1; metric 10; destination 0.0.0.0/0; route-table { unicast ; } } } } } interface [ ethernet1/1 ethernet1/2 ]; } ,7022390503849066572,0x0,0,0,0,0,,PA-VM,0,
    

Referência de mapeamento de campos: mapeamento de campos de registos para campos de UDM

Esta secção explica como o analisador mapeia os campos de registo da firewall da Palo Alto Networks para os campos de eventos da UDM do Google SecOps para cada tipo de registo. A chave da etiqueta do Google SecOps refere-se ao nome da chave mapeada para o campo UDM Labels.key.

Por exemplo, no caso do campo "Virtual System", o nome do campo é "cs3" no formato CEF e "VirtualSystem" no formato LEEF. O campo UDM "about.labels.key" contém o valor "vsys" e o campo UDM "about.labels.value" contém o valor desse campo. Alguns dos nomes dos campos CEF ou LEEF não têm um nome correspondente aos nomes dos campos CSV. Nestes casos, se adicionar o seu próprio nome de variável no formato de registo personalizado no perfil do syslog, o analisador não o mapeia para o campo UDM.

Consulte as secções seguintes para obter uma referência de mapeamento de cada tipo de registo:

Sistema

A tabela seguinte apresenta os campos de registo do tipo de registo do sistema e os respetivos campos do UDM.

Campo CSV Campo CEF Campo LEEF Chave de etiqueta do Google Security Operations Campo UDM
Hora de receção (receive_time ou cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Número de série (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Tipo (type) tipo (cabeçalho) gato metadata.product_event_type está definido como "%{type} - %{subtype}".
Tipo de ameaça/conteúdo (subtipo) subtipo (cabeçalho) Subtipo metadata.product_event_type está definido como "%{type} - %{subtype}".
Hora de geração (time_generated ou cef-formatted-time_generated) metadata.event_timestamp
Sistema virtual (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
ID do evento (eventid) gato eventid additional.fields.key e additional.fields.value.string_value
Objeto (objeto) fname Nome do ficheiro objeto target.resource.name
Módulo (module) flexString2 Módulo módulo additional.fields.key e additional.fields.value.string_value
Gravidade (gravidade) $number-of-severity(header) Gravidade security_result.severity e security_result.severity_details
Descrição (opaca) msg msg metadata.description
principal_user_userid (este campo é extraído do campo msg) principal.user.userid
principal_ip3 (este campo é extraído do campo msg) principal.ip
Motivo (este campo é extraído do campo msg) security_result.description
server_address (Este campo é extraído do campo msg.) target.ip
server_profile (Este campo é extraído do campo msg.) additional.fields.key e additional.fields.value.string_value
Número de sequência (seqno) externalId sequência metadata.product_log_id
Sinalizadores de ações (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_1 a dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
Nome do dispositivo (device_name) dvchost DeviceName target.hostname
Indicação de tempo de alta resolução (high_res_timestamp) anOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value

Configuração

A tabela seguinte apresenta os campos de registo do tipo de registo de configuração e os respetivos campos do UDM.

Campo CSV Campo CEF Campo LEEF Chave de etiqueta do Google Security Operations Campo UDM
Hora de receção (receive_time ou cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Número de série (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Tipo (type) tipo (cabeçalho) gato metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) subtipo (cabeçalho) metadata.product_event_type
Hora de geração (time_generated ou cef-formatted-time_generated) metadata.event_timestamp
Anfitrião (host) shost src principal.ip/hostname
Sistema virtual (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
Comando (cmd) agir msg cmd principal.process.command_line
Administrador (admin) duser usrName principal.user.userid
Cliente (cliente) destinationServiceName cliente principal.application
Resultado (resultado) ID da assinatura (cabeçalho)(motivo) Resultado security_result.summary
Caminho de configuração (caminho) msg ConfigurationPath principal.process.command_line
Detalhe antes da alteração (before_change_detail) cs1 BeforeChangeDetail before_change_detail target.resource.attribute.labels.key/value
Detalhe da alteração (after_change_detail) cs2 AfterChangeDetail after_change_detail target.resource.attribute.labels.key/value
Número de sequência (seqno) externalId sequência metadata.product_log_id
Sinalizadores de ações (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_1 a dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
Nome do dispositivo (device_name) dvchost DeviceName target.hostname
Grupo de dispositivos (dg_id) PanOSFWDeviceGroup target.asset.attribute.labels.key/value dg_id principal.asset.attribute.labels.key/value
Comentário de auditoria (comment) PanOSPolicyAuditComment comentário additional.fields.key e additional.fields.value.string_value
Indicação de tempo de alta resolução (high_res_timestamp) additional.fields.key e additional.fields.value.string_value
Gravidade (gravidade) number-of-severity(header) security_result.severity e security_result.severity_details

Ameaça/WildFire

A tabela seguinte lista os campos de registo do tipo de registo Threat/WildFire e os respetivos campos da UDM.

Campo CSV Campo CEF Campo LEEF Chave de etiqueta do Google Security Operations Campo UDM
Hora de receção (receive_time ou cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Número de série deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Tipo (type) tipo (cabeçalho) gato metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) cat/subtype (cabeçalho) Subtipo metadata.product_event_type
Hora de geração (time_generated ou cef-formatted-time_generated) metadata.event_timestamp
Endereço de origem (src) src src principal.ip
Endereço de destino (dst) dst dst target.ip
IP de origem da NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP de destino do NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Nome da regra (regra) cs1 RuleName security_result.rule_name
Utilizador de origem (srcuser) suser SourceUser / usrName principal.user.userid
Utilizador de destino (dstuser) duser DestinationUser target.user.userid
Aplicação (app) app Aplicação target.application
Sistema virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona de origem (de) cs4 SourceZone de

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Zona de destino (para) cs5 DestinationZone a

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de entrada (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de saída (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Ação de registo (logset) cs6 LogForwardingProfile logset additional.fields.key e additional.fields.value.string_value
ID da sessão (sessionid) cn1 SessionID network.session_id
Número de repetições (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Porta de origem (sport) spt srcPort principal.port
Porta de destino (dport) dpt dstPort target.port
Porta de origem NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Porta de destino NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Flags (flags) flexString1 Bandeiras flags additional.fields.key e additional.fields.value.string_value
Protocolo IP (proto) proto proto network.ip_protocol
Ação (action) agir ação security_result.action_details

security_result.action

URL/nome do ficheiro (diversos) pedido Diversos

target.file.names (se o subtipo for "file", "virus", "wildfire-virus" ou "wildfire", o campo `misc` é mapeado para target.file.names)

target.url (se o subtipo for "url", o campo "misc" é mapeado para target.url e target.hostname)

Nome da ameaça/conteúdo (threatid) gato ThreatID security_result.threat_name
Categoria (categoria) cs2 URLCategory security_result.category_details
Gravidade (gravidade) number-of-severity(header) Gravidade security_result.severity e security_result.severity_details
Direção (direction) flexString2 Direção network.direction
Número de sequência (seqno) externalId sequência metadata.product_log_id
Sinalizadores de ações (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
País de origem (srcloc) SourceLocation principal.location.country_or_region
País de destino (dstloc) DestinationLocation target.location.country_or_region
Tipo de conteúdo (contenttype) ContentType contenttype additional.fields.key e additional.fields.value.string_value
ID do PCAP (pcap_id) fileId PCAP_ID pcap_id additional.fields.key e additional.fields.value.string_value
Resumo do ficheiro (filedigest) fileHash FileDigest target.file.sha1/md5/sha256
Nuvem (nuvem) filePath Google Cloud nuvem additional.fields.key e additional.fields.value.string_value
Índice de URL (url_idx) URLIndex url_idx additional.fields.key e additional.fields.value.string_value
Agente do utilizador (user_agent) network.http.user_agent
Tipo de ficheiro (filetype) fileType FileType target.file.mime_type
X-Forwarded-For (xff) principal.ip
Referenciador (referer) network.http.referral_url
Remetente (remetente) suid Remetente network.email.from
Assunto (assunto) msg Assunto network.email.subject
Destinatário (destinatário) duid Destinatário network.email.to
ID do relatório (reportid) oldFileId ReportID reportid additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_1 a dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nome do dispositivo (device_name) dvchost DeviceName intermediary.hostname
UUID da VM de origem (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
UUID da VM de destino (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
Método HTTP (http_method) RequestMethod network.http.method
ID do túnel/IMSI (tunnel_id/imsi) PanOSTunnelID TunnelID tunnel_id/imsi additional.fields.key e additional.fields.value.string_value
Monitor Tag/IMEI (monitortag/imei) PanOSMonitorTag MonitorTag monitortag/imei additional.fields.key e additional.fields.value.string_value
ID da sessão principal (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Hora de início da sessão principal (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key e additional.fields.value.string_value
Tipo de túnel (túnel) PanOSTunnelType TunnelType túnel additional.fields.key e additional.fields.value.string_value
Categoria de ameaça (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
Versão do conteúdo (contentver) PanOSContentVer ContentVer contentver additional.fields.key e additional.fields.value.string_value
ID de associação SCTP (assoc_id) PanOSAssocID assoc_id additional.fields.key e additional.fields.value.string_value
ID do protocolo de carga útil (ppid) PanOSPPID ppid additional.fields.key e additional.fields.value.string_value
Cabeçalhos HTTP (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
Lista de categorias de URLs (url_category_list) PanOSURLCatList url_category_list additional.fields.key e additional.fields.value.string_value
UUID da regra (rule_uuid) PanOSRuleUUID security_result.rule_id
Ligação HTTP/2 (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
Nome do grupo de utilizadores dinâmico (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Endereço XFF (xff_ip) PanXFFIP principal.ip
Categoria do dispositivo de origem (src_category) PanSrcDeviceCat src_category principal.asset.category
Perfil do dispositivo de origem (src_profile) PanSrcDeviceProf src_profile

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Modelo do dispositivo de origem (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
Fornecedor do dispositivo de origem (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
Família de SO do dispositivo de origem (src_osfamily) PanSrcDeviceOS src_osfamily principal.platform
Versão do SO do dispositivo de origem (src_osversion) PanSrcDeviceOSv principal.platform_version
Nome do anfitrião de origem (src_host) PanSrcHostname principal.hostname
Endereço MAC de origem (src_mac) PanSrcMac principal.mac
Categoria do dispositivo de destino (dst_category) PanDstDeviceCat dst_category target.asset.category
Perfil do dispositivo de destino (dst_profile) PanDstDeviceProf dst_profile

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Modelo do dispositivo de destino (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
Fornecedor do dispositivo de destino (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
Família de SO do dispositivo de destino (dst_osfamily) PanDstDeviceOS dst_osfamily target.platform
Versão do SO do dispositivo de destino (dst_osversion) PanDstDeviceOSv target.platform_version
Nome do anfitrião de destino (dst_host) PanDstHostname target.hostname
Endereço MAC de destino (dst_mac) PanDstMac target.mac
ID do contentor (container_id) PanContainerName container_id intermediary.resource.product_object_id
Espaço de nomes do POD (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
Nome do POD (pod_name) PanPODName pod_name target.resource.name
Lista dinâmica externa de origem (src_edl) PanSrcEDL src_edl additional.fields.key e additional.fields.value.string_value
Lista dinâmica externa de destino (dst_edl) PanDstEDL dst_edl additional.fields.key e additional.fields.value.string_value
ID do anfitrião (hostid) PanGPHostID hostid principal.asset.asset_id
Número de série do dispositivo do utilizador (serialnumber) PanEPSerial principal.asset.hardware.serial_number
EDL de domínio (domain_edl) PanDomainEDL domain_edl additional.fields.key e additional.fields.value.string_value
Grupo de endereços dinâmicos de origem (src_dag) PanSrcDAG principal.group.group_display_name
Grupo de endereços dinâmicos de destino (dst_dag) PanDstDAG target.group.group_display_name
Hash parcial (partial_hash) PanPartialHash partial_hash additional.fields.key e additional.fields.value.string_value
Indicação de tempo de alta resolução (high_res timestamp) PanTimeHighRes Indicação de tempo de alta resolução additional.fields.key e additional.fields.value.string_value
Motivo (motivo) PanReasonFilteringAction motivo security_result.summary
Justificação (justification) PanJustification justificação additional.fields.key e additional.fields.value.string_value
Um tipo de serviço de divisão (nssai_sst) PanASServiceType nssai_sst additional.fields.key e additional.fields.value.string_value
Subcategoria da aplicação (subcategory_of_app) subcategory_of_app additional.fields.key e additional.fields.value.string_value
Categoria de aplicações (category_of_app) category_of_app additional.fields.key e additional.fields.value.string_value
Tecnologia da aplicação (technology_of_app) technology_of_app additional.fields.key e additional.fields.value.string_value
Risco da aplicação (risk_of_app) risk_of_app additional.fields.key e additional.fields.value.string_value
Caraterística da aplicação (characteristic_of_app) characteristic_of_app additional.fields.key e additional.fields.value.string_value
Contentor de aplicações (container_of_app) container_of_app additional.fields.key e additional.fields.value.string_value
SaaS de aplicação (is_saas_of_app) is_saas_of_app additional.fields.key e additional.fields.value.string_value
Aplicação com túnel (tunneled_app) additional.fields.key e additional.fields.value.string_value
Tipo de fluxo (flow_type) additional.fields.key e additional.fields.value.string_value
Nome do cluster (cluster_name) intermediary.resource.name
Estado sancionado da aplicação (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key e additional.fields.value.string_value

Trânsito

A tabela seguinte apresenta os campos de registo do tipo de registo de tráfego e os respetivos campos da UDM.

Campo CSV Campo CEF Campo LEEF Chave de etiqueta do Google Security Operations Campo UDM
Hora de receção (receive_time ou cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Número de série (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Tipo (type) tipo (cabeçalho) cat/Type metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) subtipo (cabeçalho) Subtipo metadata.product_event_type
Hora de geração (time_generated ou cef-formatted-time_generated) iniciar metadata.event_timestamp
Endereço de origem (src) src src principal.ip
Endereço de destino (dst) dst dst target.ip
IP de origem da NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP de destino do NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Nome da regra (regra) cs1 RuleName security_result.rule_name
Utilizador de origem (srcuser) suser SourceUser principal.user.userid
Utilizador de destino (dstuser) duser DestinationUser target.user.userid
Aplicação (app) app Aplicação target.application
Sistema virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona de origem (de) cs4 SourceZone de

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Zona de destino (para) cs5 DestinationZone a

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de entrada (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de saída (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Ação de registo (logset) cs6 LogForwardingProfile logset additional.fields.key e additional.fields.value.string_value
ID da sessão (sessionid) cn1 SessionID network.session_id
Número de repetições (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Porta de origem (sport) spt srcPort principal.port
Porta de destino (dport) dpt dstPort target.port
Porta de origem NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Porta de destino NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Flags (flags) flexString1 Bandeiras flags additional.fields.key e additional.fields.value.string_value
Protocolo IP (proto) proto proto network.ip_protocol
Ação (action) agir ação security_result.action_details

security_result.action

Bytes (bytes) flexNumber1 totalBytes bytes additional.fields.key e additional.fields.value.string_value
Bytes enviados (bytes_sent) em srcBytes network.sent_bytes
Bytes recebidos (bytes_received) fora dstBytes network.received_bytes
Pacotes (packets) cn2 totalPackets pacotes additional.fields.key e additional.fields.value.string_value
Hora de início (início) StartTime iniciar additional.fields.key e additional.fields.value.string_value
Tempo decorrido (decorrido) cn3 ElapsedTime decorrido network.session_duration.seconds
Categoria (categoria) cs2 URLCategory security_result.category / security_result.category_details
Número de sequência (seqno) externalId sequência metadata.product_log_id
Sinalizadores de ações (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
País de origem (srcloc) SourceLocation principal.location.country_or_region
País de destino (dstloc) DestinationLocation target.location.country_or_region
Pacotes enviados (pkts_sent) PanOSPacketsSent srcPackets pkts_sent network.sent_packets
Pacotes recebidos (pkts_received) PanOSPacketsReceived dstPackets pkts_received network.received_packets
Motivo do fim da sessão (session_end_reason) motivo SessionEndReason security_result.summary
Hierarquia do grupo de dispositivos 1 (dg_hier_level_1 a dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos 2 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos3 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nome do dispositivo (device_name) dvchost DeviceName intermediary.hostname
Origem da ação (action_source) gato ActionSource action_source additional.fields.key e additional.fields.value.string_value
UUID da VM de origem (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
UUID da VM de destino (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
ID do túnel/IMSI (tunnelid/imsi) PanOSTunnelID TunnelID tunnelid/imsi additional.fields.key e additional.fields.value.string_value
Monitor Tag/IMEI (monitortag/imei) PanOSMonitorTag MonitorTag monitortag/imei additional.fields.key e additional.fields.value.string_value
ID da sessão principal (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Hora de início principal (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key e additional.fields.value.string_value
Tipo de túnel (túnel) PanOSTunnelType TunnelType túnel additional.fields.key e additional.fields.value.string_value
ID de associação SCTP (assoc_id) PanOSSCTPAssocID assoc_id additional.fields.key e additional.fields.value.string_value
Blocos SCTP (blocos) PanOSSCTPChunks pedaços additional.fields.key e additional.fields.value.string_value
SCTP Chunks Sent (chunks_sent) PanOSSCTPChunkSent chunks_sent additional.fields.key e additional.fields.value.string_value
SCTP Chunks Received (chunks_received) PanOSSCTPChunksRcv chunks_received additional.fields.key e additional.fields.value.string_value
UUID da regra (rule_uuid) PanOSRuleUUID security_result.rule_id
Ligação HTTP/2 (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
Número de alterações rápidas da app (link_change_count) PanLinkChange link_change_count additional.fields.key e additional.fields.value.string_value
ID da política (policy_id) PanPolicyID policy_id additional.fields.key e additional.fields.value.string_value
Interruptores de links (link_switches) PanLinkDetail link_switches additional.fields.key e additional.fields.value.string_value
Cluster SD-WAN (sdwan_cluster) PanSDWANCluster sdwan_cluster additional.fields.key e additional.fields.value.string_value
Tipo de dispositivo SD-WAN (sdwan_device_type) PanSDWANDevice sdwan_device_type additional.fields.key e additional.fields.value.string_value
Tipo de cluster SD-WAN (sdwan_cluster_type) PanSDWANClustype sdwan_cluster_type additional.fields.key e additional.fields.value.string_value
Site SD-WAN (sdwan_site) PanSDWANSite sdwan_site additional.fields.key e additional.fields.value.string_value
Nome do grupo de utilizadores dinâmico (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name additional.fields.key e additional.fields.value.string_value
Endereço XFF (xff_ip) PanXFFIP principal.ip
Categoria do dispositivo de origem (src_category) PanSrcDeviceCat src_category principal.asset.category
Perfil do dispositivo de origem (src_profile) PanSrcDeviceProf src_profile

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Modelo do dispositivo de origem (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
Fornecedor do dispositivo de origem (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
Família de SO do dispositivo de origem (src_osfamily) PanSrcDeviceOS principal.platform
Versão do SO do dispositivo de origem (src_osversion) PanSrcDeviceOSv principal.asset.software.version
Nome do anfitrião de origem (src_host) PanSrcHostname principal.hostname
Endereço MAC de origem (src_mac) PanSrcMac principal.mac
Categoria do dispositivo de destino (dst_category) PanDstDeviceCat dst_category target.asset.category
Perfil do dispositivo de destino (dst_profile) PanDstDeviceProf dst_profile

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Modelo do dispositivo de destino (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
Fornecedor do dispositivo de destino (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
Família de SO do dispositivo de destino (dst_osfamily) PanDstDeviceOS dst_osfamily target.platform
Versão do SO do dispositivo de destino (dst_osversion) PanDstDeviceOSv target.platform_version
Nome do anfitrião de destino (dst_host) PanDstHostname target.hostname
Endereço MAC de destino (dst_mac) PanDstMac target.mac
ID do contentor (container_id) PanContainerName container_id intermediary.resource.product_object_id
Espaço de nomes do POD (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
Nome do POD (pod_name) PanPODName pod_name target.resource.name
Lista dinâmica externa de origem (src_edl) PanSrcEDL src_edl

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Lista dinâmica externa de destino (dst_edl) PanDstEDL dst_edl

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

ID do anfitrião (hostid) PanGPHostID hostid principal.asset.asset_id
Número de série do dispositivo do utilizador (serialnumber) PanEPSerial principal.asset.hardware.serial_number
Grupo de endereços dinâmicos de origem (src_dag) PanSrcDAG principal.group.group_display_name
Grupo de endereços dinâmicos de destino (dst_dag) PanDstDAG target.group.group_display_name
Proprietário da sessão (session_owner) PanHASessionOwner session_owner additional.fields.key e additional.fields.value.string_value
Indicação de tempo de alta resolução (high_res_timestamp) PanTimeHighRes additional.fields.key e additional.fields.value.string_value
Um tipo de serviço de divisão (nsdsai_sst) PanASServiceType nsdsai_sst additional.fields.key e additional.fields.value.string_value
Um diferenciador de fatia (nsdsai_sd) PanASServiceDiff nsdsai_sd additional.fields.key e additional.fields.value.string_value
Subcategoria da aplicação (subcategory_of_app) subcategory_of_app additional.fields.key e additional.fields.value.string_value
Categoria de aplicações (category_of_app) category_of_app additional.fields.key e additional.fields.value.string_value
Tecnologia da aplicação (technology_of_app) technology_of_app additional.fields.key e additional.fields.value.string_value
Risco da aplicação (risk_of_app) security_result.severity
Caraterística da aplicação (characteristic_of_app) characteristic_of_app additional.fields.key e additional.fields.value.string_value
Contentor de aplicações (container_of_app) container_of_app additional.fields.key e additional.fields.value.string_value
SaaS de aplicação (is_saas_of_app) is_saas_of_app additional.fields.key e additional.fields.value.string_value
Estado sancionado da aplicação (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key e additional.fields.value.string_value
Subcategoria da aplicação (subcategory_of_app) subcategory_of_app1 additional.fields.key e additional.fields.value.string_value
Gravidade (gravidade) number-of-severity(header) security_result.severity e security_result.severity_details

User-ID

A tabela seguinte lista os campos de registo do tipo de registo user-id e os respetivos campos da UDM.

Campo CSV Campo CEF Campo LEEF Chave de etiqueta do Google Security Operations Campo UDM
Hora de receção (receive_time ou cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Número de série (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Tipo (type) tipo (cabeçalho) gato metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) subtipo (cabeçalho) Subtipo metadata.product_event_type
Hora de geração (time_generated ou cef-formatted-time_generated) metadata.event_timestamp
Sistema virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
IP de origem (ip) src src principal.ip
Utilizador (user) duser usrName target.user.userid

target.administrative_domain

target.user.email_addresses

Nome da origem de dados (datasourcename) cs4 DataSourceName datasourcename

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

ID do evento (eventid) EventID eventid additional.fields.key e additional.fields.value.string_value
Número de repetições (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Limite de tempo limite (tempo limite) cn3 TimeoutThreshold tempo limite excedido additional.fields.key e additional.fields.value.string_value
Porta de origem (beginport) spt srcPort principal.port
Porta de destino (endport) dpt dstPort target.port
Origem de dados cs5 DataSource origem de dados

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Tipo de origem de dados (datasourcetype) cs6 DataSourceType datasourcetype

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Número de sequência (seqno) externalId sequência metadata.product_log_id
Sinalizadores de ações (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nome do dispositivo (device_name) dvchost DeviceName intermediary.hostname
ID do sistema virtual (vsys_id) cn2 VirtualSystemID intermediary.resource.product_object_id
Tipo de fator (factortype) cs1 FactorType factortype additional.fields.key e additional.fields.value.string_value
Tempo de conclusão da fatorização (factorcompletiontime) fim FactorCompletionTime factorcompletiontime additional.fields.key e additional.fields.value.string_value
Número do fator (factorno) cn1 FactorNumber factorno additional.fields.key e additional.fields.value.string_value
User Group Flags (ugflags) PanOSUGFlags ugflags additional.fields.key e additional.fields.value.string_value
Utilizador por origem (userbysource) PanOSUserBySource target.user.userid

target.administrative_domain

target.user.email_addresses

Indicação de tempo de alta resolução (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value
Origem de dados (origindatasource) additional.fields.key e additional.fields.value.string_value
Nome do cluster (cluster_name) principal.resource.name
Gravidade (gravidade) number-of-severity(header) security_result.severity e security_result.severity_details

Correspondência de HIP

A tabela seguinte apresenta os campos de registo do tipo de registo de correspondência de HIP e os respetivos campos de UDM.

Campo CSV Campo CEF Campo LEEF Chave de etiqueta do Google Security Operations Campo UDM
Hora de receção (receive_time ou cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Número de série (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Tipo (type) tipo (cabeçalho) gato metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) subtipo (cabeçalho) Subtipo
Hora de geração (time_generated ou cef-formatted-time_generated) iniciar startTime metadata.event_timestamp
Utilizador de origem (srcuser) suser usrName principal.user.userid
Sistema virtual (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
Nome do computador (machinename) shost identHostName principal.hostname
Sistema operativo (os) cs2 SO principal.asset.platform_software.platform
Endereço de origem (src) src identsrc principal.ip
HIP (matchname) gato HIP matchname

target.resource.attribute.labels.key/value

additional.fields.key e additional.fields.value.string_value

Número de repetições (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Tipo de HIP (matchtype) ID da classe de eventos do dispositivo (cabeçalho) HIPType matchtype

target.resource.attribute.labels.key/value

additional.fields.key e additional.fields.value.string_value

Número de sequência (seqno) externalId sequência metadata.product_log_id
Sinalizadores de ações (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
Nome do dispositivo (device_name) dvchost DeviceName target.hostname
ID do sistema virtual (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
Endereço do sistema IPv6 (srcipv6) c6a2 srcipv6 principal.asset.ip
ID do anfitrião (hostid) PanOSHostID principal.asset.asset_id
Número de série do dispositivo do utilizador (serialnumber) PanOSEndpointSerialNumber principal.asset.hardware.serial_number
Endereço MAC do dispositivo (mac) PanOSEndpointMac principal.asset.mac
Indicação de tempo de alta resolução (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value
Nome do cluster (cluster_name) principal.resource.name
Gravidade (gravidade) number-of-severity(header) security_result.severity e security_result.severity_details

Etiqueta de IP

A tabela seguinte apresenta os campos de registo do tipo de registo de etiquetas de IP e os respetivos campos da UDM.

Campo CSV Campo CEF Campo LEEF Chave de etiqueta do Google Security Operations Campo UDM
Hora de receção (receive_time ou cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Número de série (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Tipo (type) tipo (cabeçalho) gato metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) subtipo (cabeçalho) Subtipo metadata.product_event_type
Hora de geração (time_generated ou cef-formatted-time_generated) GenerateTime metadata.event_timestamp
Sistema virtual (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
IP de origem (ip) src src principal.ip
Nome da etiqueta (tag_name) PanOSTagName TagName tag_name

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

ID do evento (event_id) PanOSEventID EventID event_id additional.fields.key e additional.fields.value.string_value
Número de repetições (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Limite de tempo (timeout) PanOSTimeout TimeoutThreshold tempo limite excedido additional.fields.key e additional.fields.value.string_value
Nome da origem de dados (datasourcename) PanOSDataSourceName DataSourceName datasourcename

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Tipo de origem de dados (datasource_type) PanOSDataSourceType DataSource datasource_type

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Subtipo da origem de dados (datasource_subtype) PanOSDataSourceSubType DataSourceType datasource_subtype

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Número de sequência (seqno) externalId sequência metadata.product_log_id
Sinalizadores de ações (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) PanOsVsysName vSrcName target.asset.attribute.labels.key/value
Nome do dispositivo (device_name) dvchost DeviceName target.hostname
ID do sistema virtual (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
Indicação de tempo de alta resolução (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value
Gravidade (gravidade) number-of-severity(header) security_result.severity e security_result.severity_details
Nome do cluster (cluster_name) principal.resource.name

Desencriptação

A tabela seguinte apresenta os campos de registo do tipo de registo de desencriptação e os respetivos campos do UDM.

Campo CSV Campo CEF Campo LEEF Chave de etiqueta do Google Security Operations Campo UDM
Hora de receção (receive_time ou cef-formatted-receive_time) rt metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Número de série (serial) PanOSDeviceSN intermediary.asset.hardware.serial_number
Tipo (type) tipo (cabeçalho) metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) subtipo (cabeçalho) metadata.product_event_type
Versão da configuração (config_ver) PanOSConfigVersion config_ver additional.fields.key e additional.fields.value.string_value
Hora de geração (time_generated) PanOSLogTimeStamp metadata.event_timestamp
Endereço de origem (src) src principal.ip
Endereço de destino (dst) dst target.ip
IP de origem da NAT (natsrc) sourceTranslatedAddress principa.nat_ip
IP de destino do NAT (natdst) destinationTranslatedAddress target.nat_ip
Regra (regra) cs1 security_result.rule_name
Utilizador de origem (srcuser) suser principal.user.userid
Utilizador de destino (dstuser) duser target.user.userid
Aplicação (app) app network.application_protocol
Sistema virtual (vsys) cs3 vsys intermediary.asset.attribute.labels.key/value
Zona de origem (de) cs4 de

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Zona de destino (para) cs5 a

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de entrada (inbound_if) deviceInboundInterface inbound_if

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de saída (outbound_if) deviceOutboundInterface outbound_if

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Ação de registo (logset) cs6 logset additional.fields.key e additional.fields.value.string_value
Hora de registo (time_received) PanOSTimeReceivedManagementPlane -
ID da sessão (sessionid) cn1 network.session_id
Número de repetições (repeatcnt) PanOSCountOfRepeats/RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Porta de origem (sport) spt principal.port
Porta de destino (dport) dpt target.port
Porta de origem NAT (natsport) sourceTranslatedPort principal.nat_port
Porta de destino NAT (natdport) destinationTranslatedPort target.nat_port
Flags (flags) flexString1 flags additional.fields.key e additional.fields.value.string_value
Protocolo IP (proto) proto network.ip_protocol
Ação (action) agir security_result.action_details

security_result.action

Túnel (túnel) PanOSTunnel túnel additional.fields.key e additional.fields.value.string_value
UUID da VM de origem (src_uuid) PanOSSourceUUID principal.asset.product_object_id
UUID da VM de destino (dst_uuid) PanOSDestinationUUID target.asset.product_object_id
UUID da regra (rule_uuid) PanOSRuleUUID security_result.rule_id
Fase de cliente para firewall (hs_stage_c2f) PanOSClientToFirewall hs_stage_c2f additional.fields.key e additional.fields.value.string_value
Stage for Firewall to Server (hs_stage_f2s) PanOSFirewallToServer hs_stage_f2s additional.fields.key e additional.fields.value.string_value
Versão de TLS (tls_version) PanOSTLSVersion network.tls.version
Algoritmo de troca de chaves (tls_keyxchg) PanOSTLSKeyExchange tls_keyxchg additional.fields.key e additional.fields.value.string_value
Algoritmo de encriptação (tls_enc) PanOSTLSEncryptionAlgorithm tls_enc additional.fields.key e additional.fields.value.string_value
Algoritmo hash (tls_auth) PanOSTLSAuth tls_auth additional.fields.key e additional.fields.value.string_value
Nome da política (policy_name) PanOSPolicyName policy_name additional.fields.key e additional.fields.value.string_value
Curva elíptica (ec_curve) PanOSEllipticCurve network.tls.curve
Índice de erro (err_index) PanOSErrorIndex err_index additional.fields.key e additional.fields.value.string_value
Estado de acesso de superutilizador (root_status) PanOSRootStatus root_status additional.fields.key e additional.fields.value.string_value
Estado da cadeia (chain_status) PanOSChainStatus chain_status additional.fields.key e additional.fields.value.string_value
Tipo de proxy (proxy_type) PanOSProxyType proxy_type additional.fields.key e additional.fields.value.string_value
Número de série do certificado (cert_serial) PanOSCertificateSerial network.tls.server.certificate.serial
Impressão digital do certificado (impressão digital) PanOSFingerprint network.tls.server.certificate.md5/sha1/sha256
Data de início do certificado (notbefore) PanOSTimeNotBefore network.tls.server.certificate.not_before
Data de fim do certificado (notafter) PanOSTimeNotAfter network.tls.server.certificate.not_after
Versão do certificado (cert_ver) PanOSCertificateVersion network.tls.server.certificate.version
Tamanho do certificado (cert_size) PanOSCertificateSize cert_size additional.fields.key e additional.fields.value.string_value
Comprimento do nome comum (cn_len) PanOSCommonNameLength cn_len additional.fields.key e additional.fields.value.string_value
Comprimento do nome comum do emissor (issuer_len) PanOSIssuerNameLength issuer_len additional.fields.key e additional.fields.value.string_value
Comprimento do nome comum da raiz (rootcn_len) PanOSRootCNLength rootcn_len additional.fields.key e additional.fields.value.string_value
Comprimento do SNI (sni_len) PanOSSNILength sni_len additional.fields.key e additional.fields.value.string_value
Sinalizadores de certificados (cert_flags) PanOSCertificateFlags cert_flags additional.fields.key e additional.fields.value.string_value
Nome comum do requerente (cn) PanOSCommonName cn additional.fields.key e additional.fields.value.string_value
Nome comum do emissor (issuer_cn) PanOSIssuerCommonName network.tls.server.certificate.issuer
Nome comum da raiz (root_cn) PanOSRootCommonName root_cn additional.fields.key e additional.fields.value.string_value
Indicação de Nome do Servidor

(sni)

network.tls.client.server_name
Erro (erro) PanOSErrorMessage erro additional.fields.key e additional.fields.value.string_value
ID do contentor (container_id) PanOSContainerID container_id intermediary.resource.product_object_id
Espaço de nomes do POD (pod_namespace) PanOSContainerNameSpace pod_namespace

target.resource.attribute.labels.key/value

additional.fields.key e additional.fields.value.string_value

Nome do POD (pod_name) PanOSContainerName pod_name target.resource.name
Lista dinâmica externa de origem (src_edl) PanOSSourceEDL src_edl

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Lista dinâmica externa de destino (dst_edl) PanOSDestinationEDL dst_edl

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Grupo de endereços dinâmicos de origem (src_dag) PanOSSourceDynamicAddressGroup principal.group.group_display_name
Grupo de endereços dinâmicos de destino (dst_dag) PanOSDestinationDynamicAddressGroup target.group.group_display_name
Indicação de tempo de alta resolução (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value
Categoria do dispositivo de origem (src_category) PanOSSourceDeviceCategory src_category principal.asset.category
Perfil do dispositivo de origem (src_profile) PanOSSourceDeviceProfile src_profile

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Modelo do dispositivo de origem (src_model) PanOSSourceDeviceModel src_model principal.asset.hardware.model
Fornecedor do dispositivo de origem (src_vendor) PanOSSourceDeviceVendor src_vendor principal.asset.hardware.manufacturer
Família de SO do dispositivo de origem (src_osfamily) PanOSSourceDeviceOSFamily principal.platform
Versão do SO do dispositivo de origem (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
Nome do anfitrião de origem (src_host) PanOSSourceDeviceHost principal.hostname
Endereço MAC de origem (src_mac) PanOSSourceDeviceMac principal.mac
Categoria do dispositivo de destino (dst_category) PanOSDestinationDeviceCategory dst_category target.asset.category
Perfil do dispositivo de destino (dst_profile) PanOSDestinationDeviceProfile dst_profile

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Modelo do dispositivo de destino (dst_model) PanOSDestinationDeviceModel dst_model target.asset.hardware.model
Fornecedor do dispositivo de destino (dst_vendor) PanOSDestinationDeviceVendor dst_vendor target.asset.hardware.manufacturer
Família de SO do dispositivo de destino (dst_osfamily) PanOSDestinationDeviceOSFamily dst_osfamily target.platform
Versão do SO do dispositivo de destino (dst_osversion) PanOSDestinationDeviceOSVersion target.platform_version
Nome do anfitrião de destino (dst_host) PanOSDestinationDeviceHost target.hostname
Endereço MAC de destino (dst_mac) PanOSDestinationDeviceMac target.mac
Número de sequência (seqno) PanOSLogTypeSeqNo metadata.product_log_id
Sinalizadores de ações (actionflags) PanOSActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_1) DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_2) DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_3) DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_4) DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) intermediary.asset.attribute.labels.key/value
Nome do dispositivo (device_name) intermediary.hostname
ID do sistema virtual (vsys_id) intermediary.resource.product_object_id
Subcategoria da aplicação (subcategory_of_app) subcategory_of_app additional.fields.key e additional.fields.value.string_value
Categoria de aplicações (category_of_app) category_of_app additional.fields.key e additional.fields.value.string_value
Tecnologia da aplicação (technology_of_app) technology_of_app additional.fields.key e additional.fields.value.string_value
Risco da aplicação (risk_of_app) security_result.severity
Caraterística da aplicação (characteristic_of_app) characteristic_of_app additional.fields.key e additional.fields.value.string_value
Contentor de aplicações (container_of_app) container_of_app additional.fields.key e additional.fields.value.string_value
SaaS de aplicação (is_saas_of_app) is_saas_of_app additional.fields.key e additional.fields.value.string_value
Estado sancionado da aplicação (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key e additional.fields.value.string_value
Gravidade (gravidade) number-of-severity(header) security_result.severity e security_result.severity_details

Túnel

A tabela seguinte apresenta os campos de registo do tipo de registo de túnel e os respetivos campos do UDM.

Campo CSV Campo CEF Campo LEEF Chave de etiqueta do Google Security Operations Campo UDM
Hora de receção (receive_time ou cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Número de série (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Tipo (type) tipo (cabeçalho) gato metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) subtipo (cabeçalho) Subtipo metadata.product_event_type
Hora de geração (time_generated ou cef-formatted-time_generated) metadata.event_timestamp
Endereço de origem (src) src src principal.ip
Endereço de destino (dst) dst dst target.ip
IP de origem da NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP de destino do NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Nome da regra (regra) cs1 RuleName security_result.rule_name
Utilizador de origem (srcuser) suser SourceUser / usrName principal.user.userid
Utilizador de destino (dstuser) duser DestinationUser target.user.userid
Aplicação (app) app Aplicação network.application_protocol
Sistema virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona de origem (de) cs4 SourceZone de

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Zona de destino (para) cs5 DestinationZone a

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de entrada (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de saída (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Ação de registo (logset) cs6 LogForwardingProfile logset additional.fields.key e additional.fields.value.string_value
ID da sessão (sessionid) cn1 SessionID network.session_id
Número de repetições (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Porta de origem (sport) spt srcPort principal.port
Porta de destino (dport) dpt dstPort target.port
Porta de origem NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Porta de destino NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Flags (flags) flexString1 Bandeiras flags additional.fields.key e additional.fields.value.string_value
Protocolo IP (proto) proto proto network.ip_protocol
Ação (action) agir ação security_result.action_details

security_result.action

Gravidade (gravidade) number-of-severity(header) security_result.severity e security_result.severity_details
Número de sequência (seqno) externalId sequência metadata.product_log_id
Sinalizadores de ações (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Localização da origem (srcloc) principal.location.country_or_region
Localização de destino (dstloc) target.location.country_or_region
Hierarquia do grupo de dispositivos (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nome do dispositivo (device_name) dvchost DeviceName intermediary.hostname
ID do túnel (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key e additional.fields.value.string_value
Etiqueta de monitorização (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key e additional.fields.value.string_value
ID da sessão principal (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Hora de início principal (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key e additional.fields.value.string_value
Tipo de túnel (túnel) cs2 TunnelType túnel additional.fields.key e additional.fields.value.string_value
Bytes (bytes) flexNumber1 totalBytes bytes additional.fields.key e additional.fields.value.string_value
Bytes enviados (bytes_sent) em srcBytes network.sent_bytes
Bytes recebidos (bytes_received) fora dstBytes network.received_bytes
Pacotes (packets) cn2 totalPackets pacotes additional.fields.key e additional.fields.value.string_value
Pacotes enviados (pkts_sent) PanOSPacketsSent srcPackets pkts_sent network.sent_packets
Pacotes recebidos (pkts_received) PanOSPacketsReceived dstPackets pkts_received network.received_packets
Encapsulamento máximo (max_encap) flexNumber2 MaximumEncapsulation max_encap additional.fields.key e additional.fields.value.string_value
Protocolo desconhecido (unknown_proto) cfp1 UnknownProtocol unknown_proto additional.fields.key e additional.fields.value.string_value
Verificação rigorosa (strict_check) cfp2 StrictChecking strict_check additional.fields.key e additional.fields.value.string_value
Fragmento de túnel (tunnel_fragment) PanOSTunnelFragment TunnelFragment tunnel_fragment additional.fields.key e additional.fields.value.string_value
Sessões criadas (sessions_created) cfp3 SessionsCreated sessions_created additional.fields.key e additional.fields.value.string_value
Sessões fechadas (sessions_closed) cfp4 SessionsClosed sessions_closed additional.fields.key e additional.fields.value.string_value
Motivo do fim da sessão (session_end_reason) motivo SessionEndReason security_result.summary
Origem da ação (action_source) gato ActionSource action_source additional.fields.key e additional.fields.value.string_value
Hora de início (início) startTime iniciar additional.fields.key e additional.fields.value.string_value
Tempo decorrido (decorrido) cn3 ElapsedTime decorrido network.session_duration.seconds
Regra de inspeção de túnel (tunnel_insp_rule) PanOSTunneInspectionRule security_result.rule_name = "Tunnel Inspection Rule: %{PanOSTunnelInspectionRule}"
IP do utilizador remoto (remote_user_ip) PanOSRmtUserIP principal.ip
ID do utilizador remoto (remote_user_id) PanOSRmtUserID remote_user_id principal.user.userid
UUID da regra de segurança (rule_uuid) PanOSRuleUUID security_result.rule_id
ID do PCAP (pcap_id) PanOSPcapID pcap_id additional.fields.key e additional.fields.value.string_value
Nome do grupo de utilizadores dinâmico (dynusergroup_name) PanDynamicUsrgrp principal.group.group_display_name
Lista dinâmica externa de origem (src_edl) PanOSSourceEDL src_edl

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Lista dinâmica externa de destino (dst_edl) PanOSDestinationEDL dst_edl

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Indicação de tempo de alta resolução (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value
Um diferenciador de fatia (nssai_sd) nssai_sd additional.fields.key e additional.fields.value.string_value
Um tipo de serviço de fatia (nssai_sd) nssai_sd1 additional.fields.key e additional.fields.value.string_value
ID da sessão de PDU (pdu_session_id) pdu_session_id additional.fields.key e additional.fields.value.string_value
Subcategoria da aplicação (subcategory_of_app) subcategory_of_app additional.fields.key e additional.fields.value.string_value
Categoria de aplicações (category_of_app) category_of_app additional.fields.key e additional.fields.value.string_value
Tecnologia da aplicação (technology_of_app) technology_of_app additional.fields.key e additional.fields.value.string_value
Risco da aplicação (risk_of_app) risk_of_app additional.fields.key e additional.fields.value.string_value
Caraterística da aplicação (characteristic_of_app) characteristic_of_app additional.fields.key e additional.fields.value.string_value
Contentor de aplicações (container_of_app) container_of_app additional.fields.key e additional.fields.value.string_value
SaaS de aplicação (is_saas_of_app) is_saas_of_app additional.fields.key e additional.fields.value.string_value
Aplicação com túnel (tunneled_app) additional.fields.key e additional.fields.value.string_value
Descarregado (descarregado) additional.fields.key e additional.fields.value.string_value
Tipo de fluxo (flow_type) additional.fields.key e additional.fields.value.string_value
Nome do cluster (cluster_name)

principal.resource.name

Estado sancionado da aplicação (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key e additional.fields.value.string_value

Autenticação

A tabela seguinte lista os campos de registo do tipo de registo de autenticação e os respetivos campos do UDM.

Campo CSV Campo CEF Campo LEEF Chave de etiqueta do Google Security Operations Campo UDM
Hora de receção (receive_time ou cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Número de série (serial) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Tipo (type) tipo (cabeçalho) gato metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) subtipo (cabeçalho) Subtipo metadata.product_event_type
Hora de geração (time_generated ou cef-formatted-time_generated) metadata.event_timestamp
Sistema virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
IP de origem (ip) src src principal.ip
Utilizador (user) duser usrName target.user.userid
Normalizar utilizador (normalize_user) cs2 NormalizeUser target.user.user_display_name
Objeto (objeto) fname ObjectName objeto target.resource.name
Política de autenticação (authpolicy) cs4 AuthPolicy authpolicy additional.fields.key e additional.fields.value.string_value
Número de repetições (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
ID de autenticação (authid) cn2 AuthenticationID authid additional.fields.key e additional.fields.value.string_value
Fornecedor (fornecedor) flexString2 Fornecedor fornecedor additional.fields.key e additional.fields.value.string_value
Ação de registo (logset) cs6 LogForwardingProfile logset additional.fields.key e additional.fields.value.string_value
Perfil do servidor (serverprofile) cs1 ServerProfile serverprofile additional.fields.key e additional.fields.value.string_value
Descrição (desc.) PanOSDesc AdditionalAuthInfo security_result.description
Tipo de cliente (clienttype) cs5 ClientType clienttype additional.fields.key e additional.fields.value.string_value
Tipo de evento (evento) msg msg extensions.auth.auth_details
Número do fator (factorno) cn1 FactorNumber factorno additional.fields.key e additional.fields.value.string_value
Número de sequência (seqno) externalId sequência metadata.product_log_id
Sinalizadores de ações (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nome do dispositivo (device_name) dvchost DeviceName intermediary.hostname
ID do sistema virtual (vsys_id) intermediary.resource.product_object_id
Protocolo de autenticação (authproto) authproto additional.fields.key e additional.fields.value.string_value
UUID da regra (rule_uuid) PanOSRuleUUID/RuleUUID security_result.rule_id
Indicação de tempo de alta resolução (high_res _timestamp) PanOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value
Categoria do dispositivo de origem (src_category) PanOSSourceDeviceCategory src_category principal.asset.category
Perfil do dispositivo de origem (src_profile) PanOSSourceDeviceProfile src_profile

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Modelo do dispositivo de origem (src_model) PanOSSourceDeviceModel src_model principal.asset.hardware.model
Fornecedor do dispositivo de origem (src_vendor) PanOSSourceDeviceVendor src_vendor principal.asset.hardware.manufacturer
Família de SO do dispositivo de origem (src_osfamily) PanOSSourceDeviceOSFamily

principal.asset.platform_software.platform

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Versão do SO do dispositivo de origem (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
Nome do anfitrião de origem (src_host) PanOSSourceHostname principal.hostname
Endereço MAC de origem (src_mac) PanOSSourceMac principal.asset.mac
Região (região) PanOSTrafficOriginRegion principal.location.country_or_region
Agente do utilizador (user_agent) PanOSHTTPUserAgent network.http.user_agent
ID da sessão(sessionid) PanOSTrafficSessionID network.session_id
Gravidade (gravidade) number-of-severity(header) security_result.severity e security_result.severity_details
Nome do cluster (cluster_name) principal.resource.name

URL

A tabela seguinte apresenta os campos de registo do tipo de registo de URL e os respetivos campos da UDM.

Campo CSV Campo CEF Campo LEEF Chave de etiqueta do Google Security Operations Campo UDM
Hora de receção (cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

N.º de série (série) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Tipo (type) tipo (cabeçalho) gato metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) subtipo (cabeçalho) Subtipo metadata.product_event_type
Hora de geração metadata.event_timestamp
Endereço de origem (src) src src principal.ip
Endereço de destino (dst) dst dst target.ip
IP de origem da NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP de destino do NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Regra (regra) cs1 RuleName security_result.rule_name
Utilizador de origem (srcuser) suser SourceUser principal.user.userid
Utilizador de destino (dstuser) duser DestinationUser target.user.userid
Aplicação (app) app Aplicação network.application_protocol
Sistema virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona de origem (de) cs4 SourceZone de

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Zona de destino (para) cs5 DestinationZone a

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de entrada (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de saída (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Ação de registo (logset) cs6 LogForwardingProfile logset additional.fields.key e additional.fields.value.string_value
Tempo registado time_logged additional.fields.key e additional.fields.value.string_value
ID da sessão (sessionid) cn1 SessionID network.session_id
Número de repetições (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Porta de origem (sport) spt srcPort principal.port
Porta de destino (dport) dpt dstPort target.port
Porta de origem NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Porta de destino NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Flags (flags) flexString1 Bandeiras flags additional.fields.key e additional.fields.value.string_value
Protocolo IP (proto) proto proto network.ip_protocol
Ação (action) agir ação security_result.action_details

security_result.action

URL/nome do ficheiro (diversos) Diversos target.file.names

target.url

Nome da ameaça/conteúdo (threatid) gato ThreatID security_result.threat_id
Categoria (categoria) cs2 URLCategory categoria security_result.category_details
Gravidade (gravidade) number-of-severity (cabeçalho) Gravidade security_result.severity

security_result.severity_details

Direção (direction) flexString2 Direção network.direction
Número de sequência (seqno) externalId sequência metadata.product_log_id
Sinalizadores de ações (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
País de origem (srcloc) SourceLocation principal.location.country_or_region
País de destino (dstloc) DestinationLocation target.location.country_or_region
contenttype (contenttype) requestContext ContentType contenttype additional.fields.key e additional.fields.value.string_value
pcap_id (pcap_id) fileId PCAP_ID pcap_id additional.fields.key e additional.fields.value.string_value
filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
nuvem (nuvem) Google Cloud nuvem additional.fields.key e additional.fields.value.string_value
url_idx (url_idx) URLIndex url_idx additional.fields.key e additional.fields.value.string_value
user_agent (user_agent) requestClientApplication UserAgent network.http.user_agent
filetype (filetype) target.file.mime_type
xff (xff) PanOSXForwarderfor identSrc xff principal.ip
Referenciador (referer) PanOSReferer Referenciador network.http.referral_url
remetente (remetente) network.email.from
subject (subject) Assunto network.email.subject
destinatário (destinatário) network.email.to
reportid (reportid) reportid additional.fields.key e additional.fields.value.string_value
Nível 1 da hierarquia de grupos de anúncios (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Nível 2 da hierarquia de grupos de destino (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Nível 3 da hierarquia de grupos de destino (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Nível 4 da hierarquia de grupos de anúncios (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nome do dispositivo (device_name) dvchost DeviceName intermediary.hostname
file_url (file_url) target.url
UUID da VM de origem (src_uuid) SrcUUID principal.asset.product_object_id
UUID da VM de destino (dst_uuid) DstUUID target.asset.product_object_id
http_method (http_method) requestMethod RequestMethod network.http.method
ID do túnel/IMSI (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key e additional.fields.value.string_value
Monitor Tag/IMEI (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key e additional.fields.value.string_value
ID da sessão principal (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Hora de início da sessão principal (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key e additional.fields.value.string_value
Túnel (túnel) PanOSTunnelType TunnelType túnel additional.fields.key e additional.fields.value.string_value
thr_category (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
contentver (contentver) PanOSContentVer ContentVer contentver additional.fields.key e additional.fields.value.string_value
sig_flags (sig_flags) sig_flags additional.fields.key e additional.fields.value.string_value
ID de associação SCTP (assoc_id) PanOSAssocID assoc_id additional.fields.key e additional.fields.value.string_value
ID do protocolo de carga útil (ppid) PanOSPPID ppid additional.fields.key e additional.fields.value.string_value
http_headers (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
Lista de categorias de URLs (url_category_list) PanOSURLCatList url_category_list additional.fields.key e additional.fields.value.string_value
UUID da regra (rule_uuid) PanOSRuleUUID rule_uuid security_result.rule_id
Ligação HTTP/2 (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
dynusergroup_name (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name additional.fields.key e additional.fields.value.string_value
Endereço XFF (xff_ip) PanXFFIP principal.ip
Categoria do dispositivo de origem (src_category) PanSrcDeviceCat src_category principal.asset.category
Perfil do dispositivo de origem (src_profile) PanSrcDeviceProf src_profile

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Modelo do dispositivo de origem (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
Fornecedor do dispositivo de origem (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
Família de SO do dispositivo de origem (src_osfamily) PanSrcDeviceOS principal.platform
Versão do SO do dispositivo de origem (src_osversion) PanSrcDeviceOSv principal.platform_version
Nome do anfitrião de origem (src_host) PanSrcHostname src_host principal.hostname
Endereço MAC de origem (src_mac) PanSrcMac principal.mac
Categoria do dispositivo de destino (dst_category) PanDstDeviceCat dst_category target.asset.category
Perfil do dispositivo de destino (dst_profile) PanDstDeviceProf dst_profile

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Modelo do dispositivo de destino (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
Fornecedor do dispositivo de destino (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
Família de SO do dispositivo de destino (dst_osfamily) PanDstDeviceOS target.platform
Versão do SO do dispositivo de destino (dst_osversion) PanDstDeviceOSv target.platform_version
Nome do anfitrião de destino (dst_host) PanPODNamespace target.hostname
Endereço MAC de destino (dst_mac) PanDstMac target.mac
ID do contentor (container_id) PanContainerName container_id intermediary.resource.product_object_id
Espaço de nomes do POD (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
Nome do POD (pod_name) PanPODName pod_name target.resource.name
Lista dinâmica externa de origem (src_edl) PanSrcEDL src_edl

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Lista dinâmica externa de destino (dst_edl) PanDstEDL dst_edl

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

ID do anfitrião (hostid) PanGPHostID hostid principal.asset.asset_id
Número de série (serialnumber) PanEPSerial principal.asset.hardware.serial_number
domain_edl (domain_edl) PanDomainEDL domain_edl additional.fields.key e additional.fields.value.string_value
Grupo de endereços dinâmicos de origem (src_dag) PanSrcDAG principal.group.group_display_name
Grupo de endereços dinâmicos de destino (dst_dag) PanDstDAG target.group.group_display_name
partial_hash (partial_hash) PanPartialHash partial_hash additional.fields.key e additional.fields.value.string_value
Data/hora de alta resolução (high_res_timestamp) PanTimeHighRes additional.fields.key e additional.fields.value.string_value
Motivo (motivo) PanReasonFilteringAction motivo security_result.summary
justificação (justification) PanJustification justificação additional.fields.key e additional.fields.value.string_value
nssai_sst (nssai_sst) PanASServiceType nssai_sst additional.fields.key e additional.fields.value.string_value
Subcategoria da app (subcategory_of_app) subcategory_of_app additional.fields.key e additional.fields.value.string_value
Categoria da app (category_of_app) category_of_app additional.fields.key e additional.fields.value.string_value
Tecnologia da app (technology_of_app) technology_of_app additional.fields.key e additional.fields.value.string_value
Risco da app (risk_of_app) risk_of_app additional.fields.key e additional.fields.value.string_value
Caraterística da app (characteristic_of_app) characteristic_of_app additional.fields.key e additional.fields.value.string_value
Contentor da app (container_of_app) container_of_app additional.fields.key e additional.fields.value.string_value
App com túnel (tunneled_app) tunneled_app additional.fields.key e additional.fields.value.string_value
SaaS da app (is_saas_of_app) is_saas_of_app additional.fields.key e additional.fields.value.string_value
Estado sancionado da app (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key e additional.fields.value.string_value
ID do relatório da nuvem (cloud_reportid) additional.fields.key e additional.fields.value.string_value
Nome do cluster (cluster_name)

principal.resource.name

Tipo de fluxo (flow_type) additional.fields.key e additional.fields.value.string_value

Dados

A tabela seguinte lista os campos de registo do tipo de registo de dados e os respetivos campos da UDM.

Campo CSV Campo CEF Campo LEEF Chave de etiqueta do Google Security Operations Campo UDM
Hora de receção (cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

N.º de série (série) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
Tipo (type) tipo (cabeçalho) gato metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) subtipo (cabeçalho) Subtipo metadata.product_event_type
Hora de geração metadata.event_timestamp
Endereço de origem (src) src src principal.ip
Endereço de destino (dst) dst dst target.ip
IP de origem da NAT (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
IP de destino do NAT (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
Regra (regra) cs1 RuleName security_result.rule_name
Utilizador de origem (srcuser) suser SourceUser principal.user.userid
Utilizador de destino (dstuser) duser DestinationUser target.user.userid
Aplicação (app) app Aplicação network.application_protocol
Sistema virtual (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Zona de origem (de) cs4 SourceZone de

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Zona de destino (para) cs5 DestinationZone a

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de entrada (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de saída (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Ação de registo (logset) cs6 LogForwardingProfile logset additional.fields.key e additional.fields.value.string_value
Tempo registado time_logged additional.fields.key e additional.fields.value.string_value
ID da sessão (sessionid) cn1 SessionID network.session_id
Número de repetições (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key e additional.fields.value.string_value
Porta de origem (sport) spt srcPort principal.port
Porta de destino (dport) dpt dstPort target.port
Porta de origem NAT (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
Porta de destino NAT (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
Flags (flags) flexString1 Bandeiras flags additional.fields.key e additional.fields.value.string_value
Protocolo IP (proto) proto proto network.ip_protocol
Ação (action) agir ação security_result.action_details

security_result.action

URL/nome do ficheiro (diversos) Diversos target.file.names

target.url

Nome da ameaça/conteúdo (threatid) gato ThreatID security_result.threat_id
Categoria (categoria) cs2 URLCategory categoria security_result.category_details
Gravidade (gravidade) number-of-severity (cabeçalho) Gravidade security_result.severity

security_result.severity_details

Direção (direction) flexString2 Direção network.direction
Número de sequência (seqno) externalId sequência metadata.product_log_id
Sinalizadores de ações (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key e additional.fields.value.string_value
País de origem (srcloc) SourceLocation principal.location.country_or_region
País de destino (dstloc) DestinationLocation target.location.country_or_region
contenttype (contenttype) ContentType contenttype additional.fields.key e additional.fields.value.string_value
pcap_id (pcap_id) fileId PCAP_ID pcap_id additional.fields.key e additional.fields.value.string_value
filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
nuvem (nuvem) Google Cloud nuvem additional.fields.key e additional.fields.value.string_value
url_idx (url_idx) URLIndex url_idx additional.fields.key e additional.fields.value.string_value
user_agent (user_agent) network.http.user_agent
filetype (filetype) target.file.mime_type
xff (xff) xff principal.ip
Referenciador (referer) network.http.referral_url
remetente (remetente) network.email.from
subject (subject) Assunto network.email.subject
destinatário (destinatário) network.email.to
reportid (reportid) reportid additional.fields.key e additional.fields.value.string_value
Nível 1 da hierarquia de grupos de anúncios (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Nível 2 da hierarquia de grupos de destino (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Nível 3 da hierarquia de grupos de destino (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Nível 4 da hierarquia de grupos de anúncios (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
Nome do dispositivo (device_name) dvchost DeviceName intermediary.hostname
file_url (file_url) target.url
UUID da VM de origem (src_uuid) SrcUUID principal.asset.product_object_id
UUID da VM de destino (dst_uuid) DstUUID target.asset.product_object_id
http_method (http_method) RequestMethod network.http.method
ID do túnel/IMSI (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key e additional.fields.value.string_value
Monitor Tag/IMEI (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key e additional.fields.value.string_value
ID da sessão principal (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
Hora de início da sessão principal (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key e additional.fields.value.string_value
Túnel (túnel) PanOSTunnelType TunnelType túnel additional.fields.key e additional.fields.value.string_value
thr_category (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
contentver (contentver) PanOSContentVer ContentVer contentver additional.fields.key e additional.fields.value.string_value
sig_flags (sig_flags) sig_flags additional.fields.key e additional.fields.value.string_value
ID de associação SCTP (assoc_id) PanOSAssocID assoc_id additional.fields.key e additional.fields.value.string_value
ID do protocolo de carga útil (ppid) PanOSPPID ppid additional.fields.key e additional.fields.value.string_value
http_headers (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
Lista de categorias de URLs (url_category_list) url_category_list additional.fields.key e additional.fields.value.string_value
UUID da regra (rule_uuid) PanOSRuleUUID rule_uuid security_result.rule_id
Ligação HTTP/2 (http2_connection) http2_connection network.application_protocol_version
dynusergroup_name (dynusergroup_name) dynusergroup_name

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Endereço XFF (xff_ip) principal.ip
Categoria do dispositivo de origem (src_category) src_category principal.asset.category
Perfil do dispositivo de origem (src_profile) src_profile

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Modelo do dispositivo de origem (src_model) src_model principal.asset.hardware.model
Fornecedor do dispositivo de origem (src_vendor) src_vendor principal.asset.hardware.manufacturer
Família de SO do dispositivo de origem (src_osfamily) principal.platform
Versão do SO do dispositivo de origem (src_osversion) principal.platform_version
Nome do anfitrião de origem (src_host) src_host principal.hostname
Endereço MAC de origem (src_mac) principal.mac
Categoria do dispositivo de destino (dst_category) dst_category target.asset.category
Perfil do dispositivo de destino (dst_profile) dst_profile

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Modelo do dispositivo de destino (dst_model) dst_model target.asset.hardware.model
Fornecedor do dispositivo de destino (dst_vendor) dst_vendor target.asset.hardware.manufacturer
Família de SO do dispositivo de destino (dst_osfamily) target.platform
Versão do SO do dispositivo de destino (dst_osversion) target.platform_version
Nome do anfitrião de destino (dst_host) target.hostname
Endereço MAC de destino (dst_mac) target.mac
ID do contentor (container_id) container_id intermediary.resource.product_object_id
Espaço de nomes do POD (pod_namespace) pod_namespace target.resource.attribute.labels.key/value
Nome do POD (pod_name) pod_name target.resource.name
Lista dinâmica externa de origem (src_edl) src_edl

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Lista dinâmica externa de destino (dst_edl) dst_edl

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

ID do anfitrião (hostid) hostid principal.asset.asset_id
Número de série (serialnumber) principal.asset.hardware.serial_number
domain_edl (domain_edl) domain_edl additional.fields.key e additional.fields.value.string_value
Grupo de endereços dinâmicos de origem (src_dag) principal.group.group_display_name
Grupo de endereços dinâmicos de destino (dst_dag) target.group.group_display_name
partial_hash (partial_hash) partial_hash additional.fields.key e additional.fields.value.string_value
Data/hora de alta resolução (high_res_timestamp) additional.fields.key e additional.fields.value.string_value
Motivo (motivo) motivo security_result.summary
justificação (justification) justificação additional.fields.key e additional.fields.value.string_value
nssai_sst (nssai_sst) nssai_sst additional.fields.key e additional.fields.value.string_value
Subcategoria da app (subcategory_of_app) subcategory_of_app additional.fields.key e additional.fields.value.string_value
Categoria da app (category_of_app) category_of_app additional.fields.key e additional.fields.value.string_value
Tecnologia da app (technology_of_app) technology_of_app additional.fields.key e additional.fields.value.string_value
Risco da app (risk_of_app) risk_of_app additional.fields.key e additional.fields.value.string_value
Caraterística da app (characteristic_of_app) characteristic_of_app additional.fields.key e additional.fields.value.string_value
Contentor da app (container_of_app) container_of_app additional.fields.key e additional.fields.value.string_value
App com túnel (tunneled_app) tunneled_app additional.fields.key e additional.fields.value.string_value
SaaS da app (is_saas_of_app) is_saas_of_app additional.fields.key e additional.fields.value.string_value
Estado sancionado da app (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key e additional.fields.value.string_value
ID do relatório da nuvem (cloud_reportid) additional.fields.key e additional.fields.value.string_value
Nome do cluster (cluster_name) principal.resource.name
Tipo de fluxo (flow_type) additional.fields.key e additional.fields.value.string_value

GlobalProtect

A tabela seguinte apresenta os campos de registo do tipo de registo GlobalProtect e os respetivos campos da UDM.

Campo CSV Campo CEF Campo LEEF Chave de etiqueta do Google Security Operations Campo UDM
Hora de receção (receive_time) rt received_time metadata.event_timestamp
N.º de série (série) PanOSDeviceSN intermediary_asset_hardware_serial_number intermediary.asset.hardware.serial_number
Tipo (type) tipo (cabeçalho) metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) subtipo (cabeçalho) Subtipo metadata.product_event_type
Hora de geração (time_generated) PanOSLogTimeStamp generated_timestamp metadata.event_timestamp
Sistema virtual (vsys) PanOSVirtualSystem vsys intermediary.asset.attribute.labels.key/value
ID do evento (eventid) PanOSEventID event_id additional.fields.key e additional.fields.value.string_value
Fase (fase) PanOSStage armazenar dados em área intermediária additional.fields.key e additional.fields.value.string_value
Método de autenticação (auth_method) PanOSAuthMethod extension_auth_auth_details extensions.auth.auth_details
Tipo de túnel (tunnel_type) PanOSTunnelType túnel additional.fields.key e additional.fields.value.string_value
Utilizador de origem (srcuser) PanOSSourceUserName src_user principal.user.email_address

principal.user.userid

principal.administrative_domain

Região de origem (srcregion) PanOSSourceRegion src_region principal.location.country_or_region
Nome do computador (machinename) PanOSEndpointDeviceName machine_name principal.hostname
IP público (public_ip) PanOSPublicIPv4 principal.nat_ip
IPv6 público (public_ipv6) PanOSPublicIPv6 principal.nat_ip
IP privado (private_ip) PanOSPrivateIPv4 principal.ip
IPv6 privado (private_ipv6) PanOSPrivateIPv6 principal.ip
ID do anfitrião (hostid) PanOSHostID hostid principal.asset.asset_id
Número de série (serialnumber) PanOSDeviceSN principal.asset.hardware.serial_number
Versão do cliente (client_ver) PanOSGlobalProtectClientVersion client_ver additional.fields.key e additional.fields.value.string_value
SO do cliente (client_os) PanOSEndpointOSType principal.platform
Versão do SO do cliente (client_os_ver) PanOSEndpointOSVersion principal.platform_version
Número de repetições (repeatcnt) PanOSCountOfRepeats repeatcnt additional.fields.key e additional.fields.value.string_value
Motivo (motivo) PanOSQuarantineReason security_result.summary
Erro (erro) PanOSConnectionError erro security_result.description
Descrição (opaca) PanOSDescription security_result.description
Estado (estado) PanOSEventStatus estado additional.fields.key e additional.fields.value.string_value
Localização (localização) PanOSGPGatewayLocation target.location.country_or_region
Duração do início de sessão (login_duration) PanOSLoginDuration network.session_duration
Método de ligação (connect_method) PanOSConnectionMethod connect_method additional.fields.key e additional.fields.value.string_value
Código de erro (error_code) PanOSConnectionErrorID error_code additional.fields.key e additional.fields.value.string_value
Portal (portal) PanOSPortal portal additional.fields.key e additional.fields.value.string_value
Número de sequência (seqno) PanOSSequenceNo metadata.product_log_id
Sinalizadores de ações (actionflags) PanOSActionFlags actionflags additional.fields.key e additional.fields.value.string_value
Indicação de tempo de alta resolução (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key e additional.fields.value.string_value
Método de seleção do gateway (selection_type) PanOSGatewaySelectionType selection_type additional.fields.key e additional.fields.value.string_value
Tempo de resposta SSL (response_time) PanOSSSLResponseTime response_time additional.fields.key e additional.fields.value.string_value
Prioridade do gateway (prioridade) PanOSGatewayPriority prioridade additional.fields.key e additional.fields.value.string_value
Gateways tentados (attempted_gateways) PanOSAttemptedGateways attempted_gateways additional.fields.key e additional.fields.value.string_value
Nome do gateway (gateway) PanOSAttemptedGateways gateway target.resource.name
Hierarquia do grupo de dispositivos (dg_hier_level_1) dg_hier_level_1 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_2) dg_hier_level_2 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_3) dg_hier_level_3 additional.fields.key e additional.fields.value.string_value
Hierarquia do grupo de dispositivos (dg_hier_level_4) dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) intermediary.asset.attribute.labels.key/value
Nome do dispositivo (device_name) intermediary.hostname
ID do sistema virtual (vsys_id) intermediary.resource.product_object_id
Gravidade (gravidade) number-of-severity(header) security_result.severity e security_result.severity_details
Nome do cluster (cluster_name) principal.resource.name

Correlação

A tabela seguinte lista os campos de registo do tipo de registo de correlação e os respetivos campos UDM.

Campo CSV Campo CEF Campo LEEF Chave de etiqueta do Google Security Operations Campo UDM
Hora de geração (time_generated ou cef-formatted-time_generated) startTime generated_timestamp metadata.event_timestamp
Endereço de origem (src) src principal.ip
Utilizador de origem (srcuser) SourceUser / usrName principal.user.userid
Sistema virtual (vsys) VirtualSystem vsys intermediary.asset.attribute.labels.key/value
Categoria (categoria) security_result.category_details
Gravidade (gravidade) Gravidade security_result.severity e security_result.severity_details
Nível 1 da hierarquia do grupo de dispositivos DeviceGroupHierarchyL1 additional.fields.key e additional.fields.value.string_value
Nível 2 da hierarquia do grupo de dispositivos DeviceGroupHierarchyL2 additional.fields.key e additional.fields.value.string_value
Nível 3 da hierarquia do grupo de dispositivos DeviceGroupHierarchyL3 additional.fields.key e additional.fields.value.string_value
Nível 4 da hierarquia do grupo de dispositivos DeviceGroupHierarchyL4 additional.fields.key e additional.fields.value.string_value
Nome do sistema virtual (vsys_name) vSrcName intermediary.asset.attribute.labels.key/value
Nome do dispositivo (device_name) DeviceName intermediary.hostname
ID do sistema virtual (vsys_id) VirtualSystemID intermediary.resource.product_object_id
Nome do objeto (objectname) ObjectName target.resource.name
ID do objeto (object_id) ObjectID target.resource.product_object_id
Provas (provas) msg security_result.summary

GTP

A tabela seguinte apresenta os campos de registo do tipo de registo gtp e os respetivos campos UDM correspondentes.

Campo CSV Campo CEF Campo LEEF Chave de etiqueta do Google Security Operations Campo UDM
Hora de receção (receive_time ou cef-formatted-receive_time) metadata.collected_timestamp,

metadata.event_timestamp (se "Generate Time" estiver ausente)

Número de série (serial) intermediary.asset.hardware.serial_number
Tipo (type) metadata.product_event_type
Tipo de ameaça/conteúdo (subtipo) metadata.product_event_type
Hora de geração (time_generated ou cef-formatted-time_generated) metadata.event_timestamp
Endereço de origem (src) principal.ip
Endereço de destino (dst) target.ip
Nome da regra (regra) security_result.rule_name
Aplicação (app) network.application_protocol
Sistema virtual (vsys) vsys intermediary.asset.attribute.labels.key/value
Zona de origem (de) de

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Zona de destino (para) a

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de entrada (inbound_if) inbound_if

principal.labels.key e principal.labels.value

additional.fields.key e additional.fields.value.string_value

Interface de saída (outbound_if) outbound_if

target.labels.key e target.labels.value

additional.fields.key e additional.fields.value.string_value

Ação de registo (logset) logset additional.fields.key e additional.fields.value.string_value
ID da sessão (sessionid) network.session_id
Porta de origem (sport) principal.port
Porta de destino (dport) target.port
Protocolo IP (proto) network.ip_protocol
Ação (action) security_result.action_details

security_result.action

Tipo de evento de GTP (event_type) gtp_event_type additional.fields.key e additional.fields.value.string_value
MSISDN (msisdn) msisdn additional.fields.key e additional.fields.value.string_value
Nome do Ponto de Acesso (APN) apn additional.fields.key e additional.fields.value.string_value
Tecnologia de acesso por rádio (rat) rato additional.fields.key e additional.fields.value.string_value
Tipo de mensagem de GTP (msg_type) gtp_msg_type additional.fields.key e additional.fields.value.string_value
Endereço IP final (end_ip_adr) principal.ip
Identificador do ponto final do túnel 1 (teid1) teid1 additional.fields.key e additional.fields.value.string_value
Identificador do ponto final do túnel 2 (teid2) teid2 additional.fields.key e additional.fields.value.string_value
Interface GTP (gtp_interface) gtp_interface additional.fields.key e additional.fields.value.string_value
GTP Cause (cause_code) gtp_cause_code additional.fields.key e additional.fields.value.string_value
Gravidade (gravidade) security_result.severity e security_result.severity_details
MCC da rede de serviço (mcc) mcc additional.fields.key e additional.fields.value.string_value
Serving Network MNC (mnc) mnc additional.fields.key e additional.fields.value.string_value
Indicativo de área (area_code) area_code additional.fields.key e additional.fields.value.string_value
ID da célula (cell_id) cell_id additional.fields.key e additional.fields.value.string_value
Código do evento GTP (event_code) event_code additional.fields.key e additional.fields.value.string_value
Localização da origem (srcloc) principal.location.country_or_region
Localização de destino (dstloc) target.location.country_or_region
ID do túnel/IMSI (imsi) tunnelid additional.fields.key e additional.fields.value.string_value
Monitorizar etiqueta/IMEI (imei) monitortag additional.fields.key e additional.fields.value.string_value
Hora de início (início) iniciar additional.fields.key e additional.fields.value.string_value
Tempo decorrido (decorrido) network.session_duration.seconds
Tunnel Inspection RuleTunnel (tunnel_insp_rule) tunnel_insp_rule security_result.detection_fields.key/value
IP do utilizador remoto (remote_user_ip) principal.ip
ID do utilizador remoto (remote_user_id) remote_user_id principal.user.userid
UUID da regra (rule_uuid) security_result.rule_id
ID do PCAP (pcap_id) pcap_id additional.fields.key e additional.fields.value.string_value
Indicação de tempo de alta resolução (high_res_timestamp) additional.fields.key e additional.fields.value.string_value
Um tipo de serviço de divisão (nsdsai_sst) nsdsai_sst additional.fields.key e additional.fields.value.string_value
Um diferenciador de fatia (nsdsai_sd) nsdsai_sd additional.fields.key e additional.fields.value.string_value
Subcategoria da aplicação (subcategory_of_app) subcategory_of_app additional.fields.key e additional.fields.value.string_value
Categoria de aplicações (category_of_app) category_of_app additional.fields.key e additional.fields.value.string_value
Tecnologia da aplicação (technology_of_app) technology_of_app additional.fields.key e additional.fields.value.string_value
Risco da aplicação (risk_of_app) risk_of_app additional.fields.key e additional.fields.value.string_value
Caraterística da aplicação (characteristic_of_app) characteristic_of_app additional.fields.key e additional.fields.value.string_value
Contentor de aplicações (container_of_app) container_of_app additional.fields.key e additional.fields.value.string_value
SaaS de aplicação (is_saas_of_app) is_saas_of_app additional.fields.key e additional.fields.value.string_value
Estado sancionado da aplicação (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key e additional.fields.value.string_value

SCTP

Campo CSV Campo CEF Campo LEEF Chave de etiqueta do Google Security Operations Campo UDM
Hora de receção (receive_time ou cef-formatted-receive_time) receive_time ou cef-formatted-receive_time metadata.collected_timestamp
Número de série (serial) número de série intermediary.asset.hardware.serial_number
Tipo (type) escrever metadata.product_event_type
Hora de geração (time_generated ou cef-formatted-time_generated) time_generated ou cef-formatted-time_generated metadata.event_timestamp
Endereço de origem (src) src principal.ip
Endereço de destino (dst) dst target.ip
Nome da regra (regra) regra security_result.rule_name
Zona de origem (de) de additional.fields.key e additional.fields.value.string_value
Zona de destino (para) a additional.fields.key e additional.fields.value.string_value
Interface de entrada (inbound_if) inbound_if additional.fields.key e additional.fields.value.string_value
Interface de saída (outbound_if) outbound_if additional.fields.key e additional.fields.value.string_value
Ação de registo (logset) logset additional.fields.key e additional.fields.value.string_value
ID da sessão (sessionid) sessionid network.session_id
Número de repetições (repeatcnt) repeatcnt additional.fields.key e additional.fields.value.string_value
Porta de origem (sport) desporto principal.port
Porta de destino (dport) dport target.port
Protocolo IP (proto) proto network.ip_protocol (enum)
Ação (action) ação security_result.action_details
security_result.action
Hierarquia do grupo de dispositivos (dg_hier_level_1 a dg_hier_level_4) dg_hier_level_1 a dg_hier_level_4 additional.fields.key e additional.fields.value.string_value
Nome do dispositivo (device_name) device_name intermediary.hostname
Número de sequência (seqno) seqno metadata.product_log_id
ID de associação SCTP (assoc_id) assoc_id additional.fields.key e additional.fields.value.string_value
ID do protocolo de carga útil (ppid) ppid additional.fields.key e additional.fields.value.string_value
Gravidade (gravidade) gravidade security_result.severity e security_result.severity_details
Tipo de fragmento SCTP (sctp_chunk_type) sctp_chunk_type additional.fields.key e additional.fields.value.string_value
Tipo de evento SCTP (sctp_event_type) sctp_event_type additional.fields.key e additional.fields.value.string_value
Etiqueta de validação SCTP 1 (verif_tag_1) verif_tag_1 additional.fields.key e additional.fields.value.string_value
Etiqueta de validação SCTP 2 (verif_tag_2) verif_tag_2 additional.fields.key e additional.fields.value.string_value
Código de motivo do SCTP (sctp_cause_code) sctp_cause_code additional.fields.key e additional.fields.value.string_value
ID da app Diameter (diam_app_id) diam_app_id additional.fields.key e additional.fields.value.string_value
Código de comando do diâmetro (diam_cmd_code) diam_cmd_code additional.fields.key e additional.fields.value.string_value
Código AVP do diâmetro (diam_avp_code) diam_avp_code additional.fields.key e additional.fields.value.string_value
ID da stream SCTP (stream_id) stream_id additional.fields.key e additional.fields.value.string_value
Motivo do fim da associação SCTP (assoc_end_reason) assoc_end_reason additional.fields.key e additional.fields.value.string_value
Código de operação (op_code) op_code additional.fields.key e additional.fields.value.string_value
SCCP Calling Party SSN (sccp_calling_ssn) sccp_calling_ssn additional.fields.key e additional.fields.value.string_value
Título global da parte chamadora do SCCP (sccp_calling_gt) sccp_calling_gt additional.fields.key e additional.fields.value.string_value
Filtro SCTP (sctp_filter) sctp_filter additional.fields.key e additional.fields.value.string_value
Blocos SCTP (blocos) pedaços additional.fields.key e additional.fields.value.string_value
SCTP Chunks Sent (chunks_sent) chunks_sent additional.fields.key e additional.fields.value.string_value
SCTP Chunks Received (chunks_received) chunks_received additional.fields.key e additional.fields.value.string_value
Pacotes (packets) pacotes additional.fields.key e additional.fields.value.string_value
UUID da regra (rule_uuid) rule_uuid security_result.rule_id
Sistema virtual (vsys) vsys intermediary.asset.attribute.labels.key/value
Nome do sistema virtual (vsys_name) vsys_name intermediary.asset.attribute.labels.key/value
Pacotes enviados (pkts_sent) pkts_sent network.sent_packets
Pacotes recebidos (pkts_received) pkts_received network.received_packets

Auditoria

Campo CSV Campo CEF Campo LEEF Chave de etiqueta do Google Security Operations Campo UDM
Hora de geração metadata.event_timestamp
Tipo de ameaça/conteúdo (subtipo) metadata.product_event_type
ID do evento principal.application
Objeto principal.user.userid
Comando da CLI principal.process.command_line
Gravidade security_result.severity
Número de série intermediary.asset.hardware.serial_number

Referência de mapeamento de campos: tipos de registos para o tipo de evento da UDM

A tabela seguinte apresenta os tipos de registos da firewall da Palo Alto Networks e os respetivos tipos de eventos da UDM.

Tipo de registo Tipo de evento UDM
Trânsito NETWORK_CONNECTION
Ameaça NETWORK_CONNECTION
Filtragem de URLs NETWORK_CONNECTION
WildFire NETWORK_CONNECTION

Os registos de envios do WildFire são um subtipo do tipo de registo de ameaças e usam o mesmo formato de syslog.

Filtragem de dados NETWORK_CONNECTION
Túnel NETWORK_CONNECTION
GTP NETWORK_CONNECTION
Configuração SETTING_MODIFICATION/SETTING_CREATION/SETTING_DELETION/SETTING_UNCATEGORIZED

O valor do campo "Comando (cmd)" determina o mapeamento do tipo de evento da UDM. Se o valor do campo cmd for add ou clone, SETTING_CREATION é definido.

Se o valor do campo cmd for delete, SETTING_DELETION é definido.

Se o valor do campo cmd for edit, move, rename, set ou commit, SETTING_MODIFICATION é definido.

Se o valor do campo cmd não contiver valores, é definido SETTING_UNCATEGORIZED

Sistema

Se o valor do subtipo for "dhcp", é definido NETWORK_DHCP.

Se o valor do subtipo for "auth", USER_LOGIN é definido.

Se o valor da descrição for "logged in", USER_LOGIN é definido.

Se o valor da descrição for "logged out", USER_LOGOUT é definido.

Para outros valores do subtipo, é definido GENERIC_EVENT.

HIP Match NETWORK_CONNECTION
Etiqueta de IP GENERIC_EVENT
User-ID USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED

Se o valor do subtipo for "login", USER_LOGIN é definido.

Se o valor do subtipo for "logout", é definido USER_LOGOUT.

Se o subtipo não contiver nenhum valor, é definido USER_UNCATEGORIZED.

Desencriptação NETWORK_CONNECTION
Autenticação GENERIC_EVENT
SCTP NETWORK_CONNECTION
Auditoria GENERIC_EVENT

Delta de mapeamento do UDM

Referência do delta de mapeamento da UDM: firewall da Palo Alto Networks

A tabela seguinte apresenta a diferença entre o mapeamento do UDM antigo de Palo Alto Networks Firewall e o mapeamento do UDM novo de Palo Alto Networks Firewall.

UDM Event Type Delta

Log type Old UDM Event Type New UDM Event Type
WildFire NETWORK_CONNECTION SCAN_UNCATEGORIZED
Data Filtering NETWORK_CONNECTION NETWORK_UNCATEGORIZED
Authentication STATUS_UPDATE STATUS_UNCATEGORIZED

UDM Field Mapping Delta

Log Type Old UDM Mapping CSV Log Field CEF Log Field LEEF Log Field New UDM Mapping
System intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
System about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
System about.labels.key/value additional.fields.key/value.string_value Object (object) fname Filename target.resource.name
System Description (opaque) msg msg metadata.description
System principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
System intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
Config intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Config about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
Config principal.process.command_line Configuration Path (path) msg ConfigurationPath principal.process.command_line
Config principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
Config intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
Config principal.asset.attribute.labels.key/value Device Group (dg_id) PanOSFWDeviceGroup target.asset.attribute.labels
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Threat/Wildfire target.file.full_path target.url target.hostname URL/Filename (misc) request Miscellaneous target.file.names target.url
Threat/Wildfire about.file.sha1/md5/sha256 File Digest (filedigest) fileHash FileDigest target.file.sha1/md5/sha256
Threat/Wildfire about.file.mime_type File Type (filetype) fileType FileType target.file.mime_type
Threat/Wildfire principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Threat/Wildfire principal.user.product_object_id Source VM UUID (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
Threat/Wildfire target.user.product_object_id Destination VM UUID (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value HTTP Headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
Threat/Wildfire principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
Threat/Wildfire principal.asset.software.version Source Device OS Version (src_osversion) PanSrcDeviceOSv principal.platform_version
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
Threat/Wildfire target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
Threat/Wildfire metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Reason (reason) PanReasonFilteringAction security_result.summary
Traffic about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value Packets Sent (pkts_sent) PanOSPacketsSent srcPackets network.sent_packets
Traffic about.labels.key/value additional.fields.key/value.string_value Packets Received (pkts_received) PanOSPacketsReceived dstPackets network.received_packets
Traffic principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
Traffic principal.asset.platform_software.platform(enum) principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
Traffic target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
Traffic about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
Traffic about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
Traffic about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
Traffic metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
User-ID about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
User-ID principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
User-ID principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID intermediary.resource.product_object_id
User-ID principal.user.userid principal.administrative_domain principal.user.email_addresses User by Source (userbysource) PanOSUserBySource target.user.userid target.user.email_addresses
User-ID metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
HIP Match intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
HIP Match about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
HIP Match about.labels.key/value additional.fields.key/value.string_value HIP (matchname) cat HIP target.resource.attribute.labels
HIP Match about.labels.key/value additional.fields.key/value.string_value HIP Type (matchtype) Device Event Class ID (Header) HIPType target.resource.attribute.labels
HIP Match principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
HIP Match intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
HIP Match principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
HIP Match principal.asset.product_object_id Host ID (hostid) PanOSHostID principal.asset.asset_id
HIP Match metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
IP-Tag intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
IP-Tag about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
IP-Tag principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOsVsysName vSrcName target.asset.attribute.labels
IP-Tag intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
IP-Tag principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
IP-Tag metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Decryption target.application Application (app) app network.application_protocol
Decryption about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 intermediary.asset.attribute.labels
Decryption principal.asset.asset_id Source VM UUID (src_uuid) PanOSSourceUUID principal.asset.product_object_id
Decryption target.asset.asset_id Destination VM UUID (dst_uuid) PanOSDestinationUUID target.asset.product_object_id
Decryption about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanOSContainerID intermediary.resource.product_object_id
Decryption about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanOSContainerNameSpace target.resource.attribute.labels additional.fields.key/value.string_value
Decryption about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanOSContainerName target.resource.name
Decryption metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanOSSourceDeviceCategory principal.asset.category
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanOSSourceDeviceModel principal.asset.hardware.model
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanOSSourceDeviceVendor principal.asset.hardware.manufacturer
Decryption principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanOSSourceDeviceOSFamily principal.platform
Decryption principal.asset.software.version Source Device OS Version (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanOSDestinationDeviceCategory target.asset.category
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanOSDestinationDeviceModel target.asset.hardware.model
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanOSDestinationDeviceVendor target.asset.hardware.manufacturer
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanOSDestinationDeviceOSFamily target.platform
Decryption target.asset.software.version Destination Device OS Version (dst_osversion) PanOSDestinationDeviceOSVersion target.platform_version
Decryption principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) intermediary.asset.attribute.labels
Decryption principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
Tunnel about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Tunnel principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Tunnel about.labels.key/value additional.fields.key/value.string_value Packets Sent (pkts_sent) PanOSPacketsSent srcPackets network.sent_packets
Tunnel about.labels.key/value additional.fields.key/value.string_value Packets Received (pkts_received) PanOSPacketsReceived dstPackets network.received_packets
Tunnel target.ip Remote User IP (remote_user_ip) PanOSRmtUserIP principal.ip
Tunnel target.labels.key/value additional.fields.key/value.string_value Remote User ID (remote_user_id) PanOSRmtUserID principal.user.userid
Tunnel metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Authentication about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Authentication target.user.user_display_name Normalize User (normalize_user) cs2 NormalizeUser target.user.user_display_name
Authentication about.labels.key/value additional.fields.key/value.string_value Object (object) fname ObjectName target.resource.name
Authentication about.labels.key/value additional.fields.key/value.string_value Authentication Policy (authpolicy) cs4 AuthPolicy additional.fields.key/value.string_value
Authentication principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Authentication principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
Authentication metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res _timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanOSSourceDeviceCategory principal.asset.category
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanOSSourceDeviceModel principal.asset.hardware.model
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanOSSourceDeviceVendor principal.asset.hardware.manufacturer
Authentication principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanOSSourceDeviceOSFamily principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value
Authentication principal.asset.software.version Source Device OS Version (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
URL about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
URL target.file.full_path target.url URL/Filename (misc) Miscellaneous target.file.names target.url
URL about.labels.key/value additional.fields.key/value.string_value Category (category) cs2 URLCategory security_result.category_details
URL about.file.sha1/md5/sha256 filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
URL about.file.mime_type filetype (filetype) target.file.mime_type
URL about.labels.key/value additional.fields.key/value.string_value xff (xff) PanOSXForwarderfor identSrc principal.ip
URL principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
URL about.url file_url (file_url) target.url
URL principal.asset.asset_id Source VM UUID (src_uuid) SrcUUID principal.asset.product_object_id
URL target.asset.asset_id Destination VM UUID (dst_uuid) DstUUID target.asset.product_object_id
URL about.labels.key/value additional.fields.key/value.string_value http_headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
URL about.labels.key/value additional.fields.key/value.string_value UUID for rule (rule_uuid) PanOSRuleUUID security_result.rule_id
URL about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
URL principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
URL principal.asset.software.version Source Device OS Version (src_osversion) PanSrcDeviceOSv principal.platform_version
URL principal.labels.key/value additional.fields.key/value.string_value Source Hostname (src_host) PanSrcHostname principal.hostname
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
URL target.asset.platform_software.platform target.labels.key/value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
URL target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
URL about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
URL about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
URL about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
URL about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
URL metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Res Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
URL about.labels.key/value additional.fields.key/value.string_value Reason (reason) PanReasonFilteringAction security_result.summary
Data about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Data target.file.full_path target.url URL/Filename (misc) Miscellaneous target.file.names target.url
Data about.labels.key/value additional.fields.key/value.string_value Category (category) cs2 URLCategory security_result.category_details
Data about.file.sha1/md5/sha256 filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
Data about.file.mime_type filetype (filetype) target.file.mime_type
Data about.labels.key/value additional.fields.key/value.string_value xff (xff) principal.ip
Data principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Data about.url file_url (file_url) target.url
Data principal.asset.asset_id Source VM UUID (src_uuid) SrcUUID principal.asset.product_object_id
Data target.asset.asset_id Destination VM UUID (dst_uuid) DstUUID target.asset.product_object_id
Data about.labels.key/value additional.fields.key/value.string_value http_headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
Data about.labels.key/value additional.fields.key/value.string_value UUID for rule (rule_uuid) PanOSRuleUUID security_result.rule_id
Data about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) network.application_protocol_version
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) principal.asset.category
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) principal.asset.hardware.model
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) principal.asset.hardware.manufacturer
Data principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) principal.platform
Data principal.asset.software.version Source Device OS Version (src_osversion) principal.platform_version
Data principal.labels.key/value additional.fields.key/value.string_value Source Hostname (src_host) principal.hostname
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) target.asset.category
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) target.asset.hardware.model
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) target.asset.hardware.manufacturer
Data target.asset.platform_software.platform target.labels.key/value Destination Device OS Family (dst_osfamily) target.platform
Data target.asset.software.version Destination Device OS Version (dst_osversion) target.platform_version
Data about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) intermediary.resource.product_object_id
Data about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) target.resource.attribute.labels
Data about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) target.resource.name
Data about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) principal.asset.asset_id
Data metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Res Timestamp (high_res_timestamp) additional.fields.key/value.string_value
Data about.labels.key/value additional.fields.key/value.string_value Reason (reason) security_result.summary
GlobalProtect about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) PanOSVirtualSystem intermediary.asset.attribute.labels
GlobalProtect principal.user.email_address principal.user.userid principal.administrative_domain Source User (srcuser) PanOSSourceUserName target.user.email_address target.user.userid
GlobalProtect principal.asset.platform_software.platform(enum) Client OS (client_os) PanOSEndpointOSType principal.platform
GlobalProtect principal.asset.platform_software.platform_version Client OS Version (client_os_ver) PanOSEndpointOSVersion principal.platform_version
GlobalProtect metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
GlobalProtect about.labels.key/value additional.fields.key/value.string_value Gateway Name (gateway) PanOSAttemptedGateways target.resource.name
GlobalProtect principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) intermediary.asset.attribute.labels
GlobalProtect target.hostname Device Name (device_name) intermediary.hostname
GlobalProtect principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
CORRELATION about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) VirtualSystem intermediary.asset.attribute.labels
CORRELATION principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) vSrcName intermediary.asset.attribute.labels
CORRELATION principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) VirtualSystemID intermediary.resource.product_object_id
GTP additional.fields.key/value.string_value Virtual System (vsys) intermediary.asset.attribute.labels
GTP target.ip Remote User IP (remote_user_ip) principal.ip
GTP additional.fields.key/value.string_value Remote User ID (remote_user_id) principal.user.userid
GTP metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) additional.fields.key/value.string_value

Palo Alto Networks Firewall Strata Logging Service

Vista geral

O Strata Logging Service da Palo Alto Networks® oferece armazenamento e agregação de registos centralizados baseados na nuvem para as suas firewalls no local, virtuais (nuvem privada e nuvem pública), para o Prisma Access e para serviços fornecidos na nuvem, como o Cortex XDR.O Strata Logging Service é seguro, resiliente e tolerante a falhas, e garante que os seus dados de registo estão atualizados e disponíveis quando precisar deles. Fornece uma infraestrutura de registo escalável que alivia a necessidade de planear e implementar coletores de registos para satisfazer as suas necessidades de retenção de registos. Se já tiver coletores de registos no local, o novo serviço de registo do Strata pode complementar a sua configuração existente. Pode aumentar a sua infraestrutura de recolha de registos existente com o serviço de registo Strata baseado na nuvem para expandir a capacidade operacional à medida que a sua empresa cresce ou para satisfazer as necessidades de capacidade de novas localizações.Com este serviço, a Palo Alto Networks cuida da manutenção e monitorização contínuas da infraestrutura de registo para que possa concentrar-se na sua empresa.

  • Valide os formatos de registos e as versões do PAN-OS suportados pelo analisador do Strata Logging Service. A tabela seguinte indica os formatos de registo e as versões do PAN-OS correspondentes que o analisador do Strata Logging Service suporta:

    Formato do registo Versão do PAN-OS
    JSON 12.1
  • Valide os tipos de registos da firewall da Palo Alto Networks que o analisador do Google SecOps suporta. O analisador do Google SecOps suporta os seguintes tipos de registos de firewall da Palo Alto Networks:

    • Trânsito
    • Ameaça
    • Inspeção de túneis
    • Sistema
    • Correspondência de HIP
    • IP-Tag
    • User-ID
    • Desencriptação
    • Autenticação
    • Filtragem de URLs
    • GlobalProtect

Implementação do serviço de registo do Strata

Comece a enviar registos para o serviço de registo do Strata:

Para começar a enviar registos para o serviço de registo do Strata, siga estes passos:

  1. Instale uma versão do PAN-OS® suportada
  2. Ative o serviço de registo do Strata: a ativação do serviço de registo do Strata inclui o aprovisionamento do certificado de que as firewalls precisam para estabelecer ligação segura ao serviço de registo do Strata.
  3. Integre firewalls no serviço de registo do Strata com ou sem o Panorama

Para ver passos de integração detalhados, consulte a documentação.

Encaminhe registos do serviço de registo do Strata

Para satisfazer as suas necessidades de armazenamento, relatórios e monitorização a longo prazo, ou legais e de conformidade, pode configurar o serviço de registo do Strata para encaminhar registos para um servidor HTTPS ou para os seguintes SIEMs:

  1. Exabeam
  2. Google Chronicle
  3. Microsoft Sentinel
  4. Coletor de eventos de HTTP (HEC) do Splunk

Use o método de encaminhamento HTTPS para encaminhar os registos através do serviço de registo do Strata. Para obter informações detalhadas, siga esta documentação.

Formatos de registo suportados

O analisador de firewall do serviço de registo do Palo Alto Networks Strata suporta registos no formato JSON.

Registos de exemplo suportados

  • JSON

    {"source": "Palo Alto Networks FLS LF", "host": "dummy-loghost", "time": "1730265996460", "event": {"TimeReceived": "2024-10-30T05:25:50.000000Z", "DeviceSN": "no-serial", "LogType": "TRAFFIC", "Subtype": "end", "ConfigVersion": "10.2", "TimeGenerated": "2024-10-30T05:25:40.000000Z", "SourceAddress": "198.51.100.6", "DestinationAddress": "198.51.100.6", "NATSource": "", "NATDestination": "", "Rule": "egress-dns-ping-traceroute", "SourceUser": null, "DestinationUser": null, "Application": "dns-base", "VirtualLocation": "vsys1", "FromZone": "VA8280-RN", "ToZone": "inter-fw", "InboundInterface": "tunnel.101", "OutboundInterface": "tunnel.4005", "LogSetting": "Cortex Data Lake", "SessionID": 754194, "RepeatCount": 1, "SourcePort": 53578, "DestinationPort": 53, "NATSourcePort": 0, "NATDestinationPort": 0, "Protocol": "udp", "Action": "allow", "Bytes": 214, "BytesSent": 72, "BytesReceived": 142, "PacketsTotal": 2, "SessionStartTime": "2024-10-30T05:25:10.000000Z", "SessionDuration": 0, "URLCategory": "any", "SequenceNo": 7382192512716388639, "SourceLocation": "198.51.100.6-198.51.255.255", "DestinationLocation": "198.51.100.6-198.51.255.255", "PacketsSent": 1, "PacketsReceived": 1, "SessionEndReason": "aged-out", "DGHierarchyLevel1": 65537, "DGHierarchyLevel2": 65538, "DGHierarchyLevel3": 65541, "DGHierarchyLevel4": 0, "VirtualSystemName": "", "DeviceName": "VA8280-RN", "ActionSource": "from-policy", "SourceUUID": null, "DestinationUUID": null, "IMSI": 0, "IMEI": null, "ParentSessionID": 0, "ParentStarttime": "1970-01-01T00:00:00.000000Z", "Tunnel": "N/A", "EndpointAssociationID": 72057594037927936, "ChunksTotal": 0, "ChunksSent": 0, "ChunksReceived": 0, "RuleUUID": "95cfc3cc-cb00-4758-af1d-de9ab5f07f97", "HTTP2Connection": 0, "LinkChangeCount": 0, "SDWANPolicyName": null, "LinkSwitches": null, "SDWANCluster": null, "SDWANDeviceType": null, "SDWANClusterType": null, "SDWANSite": null, "DynamicUserGroupName": null, "X-Forwarded-ForIP": null, "SourceDeviceCategory": null, "SourceDeviceProfile": null, "SourceDeviceModel": null, "SourceDeviceVendor": null, "SourceDeviceOSFamily": null, "SourceDeviceOSVersion": null, "SourceDeviceHost": null, "SourceDeviceMac": null, "DestinationDeviceCategory": null, "DestinationDeviceProfile": null, "DestinationDeviceModel": null, "DestinationDeviceVendor": null, "DestinationDeviceOSFamily": null, "DestinationDeviceOSVersion": null, "DestinationDeviceHost": null, "DestinationDeviceMac": null, "ContainerID": null, "ContainerNameSpace": null, "ContainerName": null, "SourceEDL": null, "DestinationEDL": null, "GPHostID": null, "EndpointSerialNumber": null, "SourceDynamicAddressGroup": null, "DestinationDynamicAddressGroup": null, "HASessionOwner": null, "TimeGeneratedHighResolution": "2024-10-30T05:25:41.009000Z", "NSSAINetworkSliceType": null, "NSSAINetworkSliceDifferentiator": null}}"
    

Referência de mapeamento de campos: mapeamento de campos de registos para campos de UDM

Esta secção explica como o analisador mapeia os campos de registo da firewall do Palo Alto Networks Strata Logging Service para os campos de eventos da UDM da Google para cada tipo de registo.

Consulte as secções seguintes para obter uma referência de mapeamento de cada tipo de registo:

Sistema

A tabela seguinte lista os campos de registo do tipo de registo do sistema e os respetivos campos da UDM.

Log field UDM mapping
AgentContentVersion additional.fields.key/value.string_value
AgentDataCollectionStatus target.resource.attribute.labels
AgentID target.resource.attribute.labels
AgentIsolationStatus target.resource.attribute.labels
AgentStatus target.resource.attribute.labels
AgentVersion target.asset.software.version
ConfigVersion additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DeviceGroup target.group.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EndpointCPUArchitecture target.asset.hardware.cpu_platform
EndpointDeviceDomain target.asset.administrative_domain
EndpointDeviceName target.asset.hostname
EndpointIPaddress target.asset.ip
VDIEndpoint target.asset.attribute.labels
EndpointOSType additional.fields.key/value.string_value
EndpointOSVersion target.platform_version
AgentTimeZoneOffset additional.fields.key/value.string_value
EndpointUserDomain additional.fields.key/value.string_value
EndpointUserName target.user.user_display_name
EndpointUserUUID target.user.userid
EventComponent additional.fields.key/value.string_value
EventDescription metadata.description
EventName additional.fields.key/value.string_value
EventTime metadata.event_timestamp
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogCategory security_result.category_details
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
LogSourceID target.resource.attribute.labels
LogSourceName observer.asset.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
LogTime metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Severity security_result.severity
Subtype metadata.product_event_type
Template target.resource.attribute.labels
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

Ameaça

A tabela seguinte apresenta os campos de registo do tipo de registo de ameaças e os respetivos campos do UDM.

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
ApplianceOrCloud additional.fields.key/value.string_value
CloudHostname additional.fields.key/value.string_value
CloudReportID security_result.detection_fields.key/value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DirectionOfAttack security_result.detection_fields.key/value
DomainEDL additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
FileName target.file.names
FileHash target.file.sha1
FileType additional.fields.key/value.string_value
FileURL target.url
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HostID principal.asset.asset_id
HTTP2Connection network.application_protocol_version
HTTPMethod network.http.method
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
LocalDeepLearningAnalyzed additional.fields.key/value.string_value
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
PartialHash additional.fields.key/value.string_value
PayloadProtocolID additional.fields.key/value.string_value
Packet additional.fields.key/value.string_value
PacketID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
RecipientEmail target.user.email_addresses
ReportID security_result.detection_fields.key/value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SenderEmail principal.user.email_addresses
SequenceNo metadata.product_log_id
SessionID network.session_id
Severity security_result.severity
SigFlags additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
EmailSubject network.email.subject
ApplicationTechnology additional.fields.key/value.string_value
ThreatCategory security_result.detection_fields.key/value.key/value
ThreatID security_result.threat_id
ThreatName security_result.threat_name
ThreatNameFirewall additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLDomain target.domain.name
URLCounter additional.fields.key/value.string_value
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
Verdict additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-ForIP principal.ip

Trânsito

A tabela seguinte apresenta os campos de registo do tipo de registo de tráfego e os respetivos campos da UDM.

Log field UDM mapping
Action security_result.action
ActionSource additional.fields.key/value.string_value
AIFwdError additional.fields.key/value.string_value
AITraffic additional.fields.key/value.string_value
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
BytesReceived network.received_bytes
BytesSent network.sent_bytes
Bytes additional.fields.key/value.string_value
ChunksReceived additional.fields.key/value.string_value
ChunksSent additional.fields.key/value.string_value
ChunksTotal additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
EndpointAssociationID additional.fields.key/value.string_value
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HASessionOwner additional.fields.key/value.string_value
GPHostID additional.fields.key/value.string_value
HTTP2Connection network.application_protocol_version
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsOffloaded additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
LinkChangeCount additional.fields.key/value.string_value
LinkSwitches additional.fields.key/value.string_value
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
SDWANPolicyName additional.fields.key/value.string_value
Protocol network.ip_protocol
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SDWANFECRatio additional.fields.key/value.string_value
SDWANCluster additional.fields.key/value.string_value
SDWANClusterType additional.fields.key/value.string_value
SDWANDeviceType additional.fields.key/value.string_value
SDWANSite additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionStartTime additional.fields.key/value.string_value
SessionTracker additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
SessionDuration network.session_duration
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLCategory target.url_metadata.categories
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-ForIP principal.ip

User-ID

A tabela seguinte apresenta os campos de registo do tipo de registo User-ID e os respetivos campos da UDM.

Log field UDM mapping
AuthFactorNo security_result.detection_fields.key/value
AuthenticatedUserDomain target.user.administrative_domain
AuthenticatedUserName target.user.userid
AuthenticatedUserUUID target.user.product_object_id
ConfigVersion additional.fields.key/value.string_value
CountofRepeats additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationPort target.port
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EventID additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsDuplicateUser additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MappingDataSource additional.fields.key/value.string_value
MappingDataSourceName additional.fields.key/value.string_value
MappingDataSourceType additional.fields.key/value.string_value
MappingTimeout additional.fields.key/value.string_value
MFAFactorType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SourceIP principal.ip
SourcePort principal.port
Subtype metadata.product_event_type
Tag additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
UGFlags additional.fields.key/value.string_value
User target.user.userid
UserGroupFound additional.fields.key/value.string_value
UserIdentifiedBySource additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Correspondência de HIP

A tabela seguinte apresenta os campos de registo do tipo de registo de correspondência de HIP e os respetivos campos de UDM.

Log field UDM mapping
ConfigVersion additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EndpointDeviceName principal.asset.hostname
EndpointOSType additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
HipMatchName target.resource.attribute.labels
HipMatchType target.resource.attribute.labels
HostID principal.asset.asset_id
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType metadata.product_event_type
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Source additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceIP principal.ip
SourceIPv6 principal.ip
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
TimestampDeviceIdentification principal.asset.first_seen_time
UUID additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

Etiqueta de IP

A tabela seguinte apresenta os campos de registo do tipo de registo de etiquetas de IP e os respetivos campos da UDM.

Log field UDM mapping
ConfigVersion additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EventID additional.fields.key/value.string_value
IPSubnetRange network.ip_subnet_range
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSetting target.resource.attribute.labels
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MappingDataSource additional.fields.key/value.string_value
MappingDataSourceSubType additional.fields.key/value.string_value
MappingDataSourceType additional.fields.key/value.string_value
MappingTimeout additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
RuleMatched security_result.rule_name
RuleMatchedUUID security_result.rule_id
SequenceNo metadata.product_log_id
SourceIP principal.ip
Subtype metadata.product_event_type
TagName additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

Desencriptação

A tabela seguinte lista os campos de registo do tipo de registo de descifragem e os respetivos campos da UDM.

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
CertificateFlags additional.fields.key/value.string_value
CertificateSerial network.tls.server.certificate.serial
CertificateSize additional.fields.key/value.string_value
CertificateVersion network.tls.server.certificate.version
ChainStatus additional.fields.key/value.string_value
ApplicationCharacteristics additional.fields.key/value.string_value
ClientToFirewall additional.fields.key/value.string_value
CommonName additional.fields.key/value.string_value
CommonNameLength additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
Cpadding additional.fields.key/value.string_value
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
Domain target.hostname
EllipticCurve network.tls.curve
ErrorIndex additional.fields.key/value.string_value
ErrorMessage additional.fields.key/value.string_value
Fingerprint network.tls.server.certificate.md5/sha1/sha256
FirewallToClient additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsCertECDSA additional.fields.key/value.string_value
IsCertRSA additional.fields.key/value.string_value
IsCertCNTruncated additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
IsForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsIssuerCNTruncated additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
IsNAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
PacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsResumeSession additional.fields.key/value.string_value
IsRootCNTruncated additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSNITruncated additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
IssuerCommonName network.tls.server.certificate.issuer
IssuerNameLength additional.fields.key/value.string_value
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
TimeNotAfter additional.fields.key/value.string_value
TimeNotBefore additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
Padding additional.fields.key/value.string_value
Padding3 additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
PolicyName additional.fields.key/value.string_value
Protocol network.ip_protocol
ProxyType additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
RootCommonName additional.fields.key/value.string_value
RootCNLength additional.fields.key/value.string_value
RootStatus additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SessionID network.session_id
ServerNameIndication network.tls.client.server_name
SNILength additional.fields.key/value.string_value
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceOS additional.fields.key/value.string_value
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
ApplicationTechnology additional.fields.key/value.string_value
TimeReceivedManagementPlane additional.fields.key/value.string_value
TLSAuth additional.fields.key/value.string_value
TLSEncryptionAlgorithm additional.fields.key/value.string_value
TLSKeyExchange additional.fields.key/value.string_value
TLSVersion network.tls.version
ToZone additional.fields.key/value.string_value
Tpadding additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
Vpadding additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SourceDeviceCategory principal.asset.category
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Túnel

A tabela seguinte apresenta os campos de registo do tipo de registo de túnel e os respetivos campos da UDM.

Log field UDM mapping
AccessPointName additional.fields.key/value.string_value
Action security_result.action
ActionSource additional.fields.key/value.string_value
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
BytesReceived network.received_bytes
BytesSent network.sent_bytes
Bytes additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
LoggingServiceID additional.fields.key/value.string_value
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MobileAreaCode additional.fields.key/value.string_value
MobileBaseStationCode additional.fields.key/value.string_value
MobileCountryCode additional.fields.key/value.string_value
MobileIP additional.fields.key/value.string_value
MobileNetworkCode additional.fields.key/value.string_value
MobileSubscriberISDN additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceDifferentiator additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsDroppedMax additional.fields.key/value.string_value
PacketsDroppedStrict additional.fields.key/value.string_value
PacketsDroppedTunnel additional.fields.key/value.string_value
PacketsDroppedProtocol additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
ProtocolDataUnitsessionID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
RadioAccessTechnology additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionStartTime additional.fields.key/value.string_value
SessionTracker additional.fields.key/value.string_value
Severity security_result.severity
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
StandardPortsOfApp additional.fields.key/value.string_value
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
SessionDuration network.session_duration
Tunnel additional.fields.key/value.string_value
TunnelCauseCode additional.fields.key/value.string_value
TunnelEndpointID1 additional.fields.key/value.string_value
TunnelEndpointID2 additional.fields.key/value.string_value
TunnelEventCode additional.fields.key/value.string_value
TunnelEventType additional.fields.key/value.string_value
TunnelInspectionRule additional.fields.key/value.string_value
TunnelInterface additional.fields.key/value.string_value
TunnelMessageType additional.fields.key/value.string_value
TunnelRemoteIMSIID additional.fields.key/value.string_value
TunnelRemoteUserIP principal.ip
TunnelSessionsClosed additional.fields.key/value.string_value
TunnelSessionsCreated additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLCategory target.url_metadata.categories
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Autenticação

A tabela seguinte lista os campos de registo do tipo de registo de autenticação e os respetivos campos UDM.

Log field UDM mapping
AuthenticationDescription security_result.description
AuthEvent metadata.description
AuthFactorNo security_result.detection_fields.key/value
AuthenticationPolicy security_result.detection_fields.key/value
AuthenticationProtocol additional.fields.key/value.string_value
AuthServerProfile additional.fields.key/value.string_value
AuthenticatedUserDomain target.administrative_domain
AuthenticatedUserName target.user.userid
AuthenticatedUserUUID target.user.product_object_id
ClientType additional.fields.key/value.string_value
ClientTypeName additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
IsPrismaNetworks additional.fields.key/value.string_value
Location target.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogType additional.fields.key/value.string_value
MFAAuthenticationID additional.fields.key/value.string_value
MFAVendor additional.fields.key/value.string_value
NormalizeUser target.user.user_display_name
Object target.resource.name
RuleMatched security_result.rule_name
RuleMatchedUUID security_result.rule_id
AuthCacheServiceRegion additional.fields.key/value.string_value
SessionID network.session_id
SourceDeviceCategory principal.asset.category
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceIP principal.ip
TimeGenerated metadata.event_timestamp
User target.user.userid
UserAgentString network.http.user_agent
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Subtype metadata.product_event_type
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

URL

A tabela seguinte apresenta os campos de registo do tipo de registo de URL e os respetivos campos da UDM.

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
CloudHostname additional.fields.key/value.string_value
CloudReportID security_result.detection_fields.key/value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentType additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DirectionOfAttack security_result.detection_fields.key/value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
FileURL target.url
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HostID principal.asset.asset_id
HTTP2Connection network.application_protocol_version
HTTPHeaders additional.fields.key/value.string_value
HTTPMethod network.http.method
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
InlineMLVerdict additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
Packet additional.fields.key/value.string_value
PacketID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
Referer network.http.referral_url
HTTPRefererFQDN additional.fields.key/value.string_value
HTTPRefererPort additional.fields.key/value.string_value
HTTPRefererProtocol additional.fields.key/value.string_value
HTTPRefererURLPath additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionID network.session_id
Severity security_result.severity
SigFlags additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URL target.url_metadata.URL
URLCategory target.url_metadata.categories
URLCategoryList additional.fields.key/value.string_value
URLDomain target.domain.name
URLCounter additional.fields.key/value.string_value
UserAgent network.http.user_agent
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-For additional.fields.key/value.string_value
X-Forwarded-ForIP principal.ip

GlobalProtect

A tabela seguinte apresenta os campos de registo do tipo de registo GlobalProtect e os respetivos campos da UDM.

Log field UDM mapping
AttemptedGateways additional.fields.key/value.string_value
AuthMethod extensions.auth.auth_details
ConnectionMethod additional.fields.key/value.string_value
ConnectionErrorID additional.fields.key/value.string_value
ConnectionError additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
EndpointDeviceName principal.asset.hostname
GlobalProtectClientVersion additional.fields.key/value.string_value
EndpointOSType additional.fields.key/value.string_value
EndpointSN principal.asset.hardware.serial_number
EventIDValue additional.fields.key/value.string_value
Gateway target.resource.name
GatewayPriority additional.fields.key/value.string_value
GatewaySelectionType additional.fields.key/value.string_value
GlobalProtectGatewayLocation target.location.country_or_region
HostID principal.asset.asset_id
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LoginDuration network.session_duration
Description security_result.description
Portal target.hostname
PrivateIPv4 principal.ip
PrivateIPv6 principal.ip
ProjectName additional.fields.key/value.string_value
PublicIPv4 principal.nat_ip
PublicIPv6 principal.nat_ip
QuarantineReason security_result.summary
SequenceNo metadata.product_log_id
SourceRegion principal.location.country_or_region
SourceUserName principal.user.user_display_name
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SSLResponseTime additional.fields.key/value.string_value
Stage additional.fields.key/value.string_value
EventStatus additional.fields.key/value.string_value
LogSubtype metadata.product_event_type
TunnelType additional.fields.key/value.string_value
VirtualSystem intermediary.asset.attribute.labels
VirtualSystemName intermediary.asset.attribute.labels
EndpointOSVersion principal.platform_version
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType metadata.product_event_type
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualSystemID intermediary.resource.product_object_id

SCTP

A tabela seguinte indica os campos de registo do tipo de registo SCTP e os respetivos campos UDM.

Log field UDM mapping
Action security_result.action
Application target.application
AssocationEndReason additional.fields.key/value.string_value
ChunksReceived additional.fields.key/value.string_value
ChunksSent additional.fields.key/value.string_value
ChunksTotal additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceClass target.asset.category
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationIP target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DiamAppID additional.fields.key/value.string_value
DiamAvpCode additional.fields.key/value.string_value
DiameterCommandCode additional.fields.key/value.string_value
DiameterRequestFlag additional.fields.key/value.string_value
DeviceName principal.asset.hostname
SCTPEventType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLFiltering additional.fields.key/value.string_value
IsWildfire additional.fields.key/value.string_value
LogAction additional.fields.key/value.string_value
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MapAppCode additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PayloadProtocolID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
Rule security_result.rule_name
RuleUUID security_result.rule_id
SccpCallingGt additional.fields.key/value.string_value
SccpCallingSSN additional.fields.key/value.string_value
SctpCauseCode additional.fields.key/value.string_value
SctpChunkType additional.fields.key/value.string_value
SctpFilter additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionTracker additional.fields.key/value.string_value
Severity security_result.severity
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceIP principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VerificationTag1 additional.fields.key/value.string_value
VerificationTag2 additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

Auditoria

A tabela seguinte apresenta os campos de registo do tipo de registo de auditoria e os respetivos campos da UDM.

Log field UDM mapping
EventCategory network.http.method
EventDescription metadata.description
EventDestinationURL target.url
EventDestinationUserUserID target.user.userid
DestinationVendor additional.fields.key/value.string_value
EventDetails additional.fields.key/value.string_value
EventID metadata.product_log_id
EventName additional.fields.key/value.string_value
EventResult security_result.summary
EventSourceUserUserID principal.user.userid
EventTime metadata.event_timestamp
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
Subtype metadata.product_event_type
TSGID additional.fields.key/value.string_value
Vendor additional.fields.key/value.string_value
VendorSeverity security_result.severity_details

Referência de mapeamento de campos: tipos de registos para o tipo de evento da UDM

A tabela seguinte indica os tipos de registos de firewall do serviço de registo do Palo Alto Networks Strata e os respetivos tipos de eventos do UDM.

Tipo de registo Tipo de evento UDM
Trânsito NETWORK_CONNECTION
Ameaça NETWORK_CONNECTION
Filtragem de URLs NETWORK_CONNECTION
Túnel NETWORK_CONNECTION
Sistema

Se o valor do subtipo for "dhcp", é definido NETWORK_DHCP.

Se o valor do subtipo for "auth", USER_LOGIN é definido.

Se o valor da descrição for "logged in", USER_LOGIN é definido.

Se o valor da descrição for "logged out", USER_LOGOUT é definido.

Para outros valores do subtipo, é definido GENERIC_EVENT.

HIP Match NETWORK_CONNECTION
Etiqueta de IP GENERIC_EVENT
User-ID USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED

Se o valor do subtipo for "login", USER_LOGIN é definido.

Se o valor do subtipo for "logout", é definido USER_LOGOUT.

Se o subtipo não contiver nenhum valor, é definido USER_UNCATEGORIZED.

Desencriptação NETWORK_CONNECTION
Autenticação STATUS_UNCATEGORIZED
Globalprotect USER_LOGIN/USER_LOGOUT/USER_RESOURCE_ACCESS

Se o valor do subtipo for "auth", USER_LOGIN é definido.

Se o valor do subtipo for "logout", é definido USER_LOGOUT.

Se o subtipo não contiver nenhum valor, é definido USER_RESOURCE_ACCESS.

SCTP NETWORK_CONNECTION
Auditoria NETWORK_CONNECTION

O que se segue?

Precisa de mais ajuda? Receba respostas de membros da comunidade e profissionais da Google SecOps.