收集 Palo Alto Networks 防火墙日志

支持的平台:

Palo Alto Networks Firewall

概览

本文档介绍了如何配置 syslog 和 Google SecOps 转发器来收集 Palo Alto Networks 防火墙日志。本文档还介绍了 Palo Alto Networks 防火墙日志字段如何映射到 Google SecOps 统一数据模型 (UDM) 字段。如需大致了解 Google SecOps 数据注入,请参阅将数据注入到 Google SecOps。 注入标签用于标识将原始日志数据标准化为结构化 UDM 格式的解析器。本文档中的信息适用于具有 PAN_FIREWALL 注入标签的解析器。

准备工作

  • 确保 Palo Alto Networks 防火墙产品已正确部署和配置。如需详细的设置说明,请参阅 PAN-OS 文档
  • 如需了解为收集 Palo Alto Networks 防火墙日志而部署的组件,请查看部署架构。每个客户部署都可能与此表示法不同,并且可能更复杂。下图展示了如何在 Palo Alto Networks 防火墙上配置 syslog,以及如何在 Linux 服务器上安装 Google SecOps 转发器,以将日志数据转发到 Google SecOps。解析器支持采用以下数据格式编写的日志:逗号分隔值 (CSV)、通用事件格式 (CEF) 和日志事件扩展格式 (LEEF)。

    部署架构

  • 验证 Google SecOps 解析器支持的日志格式和 PAN-OS 版本。下表列出了 Google SecOps 解析器支持的日志格式和相应的 PAN-OS 版本:

    日志格式 PAN-OS 版本
    CSV 10.1.3
    CEF 10.0.0
    LEEF 9.1.0
  • 验证 Google SecOps 解析器支持的 Palo Alto Networks 防火墙日志类型。 Google SecOps 解析器支持以下 Palo Alto Networks 防火墙日志类型:

    • 流量
    • 威胁
    • WildFire 提交内容
    • 隧道检查
    • 配置
    • 系统
    • HIP 匹配
    • IP-Tag
    • User-ID
    • 解密
    • 身份验证
    • 网址过滤
    • 数据过滤
    • GlobalProtect
    • 相关性
    • GTP
    • SCTP
    • 审核

    如需详细了解 Palo Alto Networks 防火墙日志类型,请参阅 PAN-OS 日志类型

  • 确保部署架构中的所有系统都配置为使用世界协调时间 (UTC) 时区。

  • 在使用 Palo Alto Networks 防火墙解析器之前,请先查看旧解析器与当前 Palo Alto Networks 防火墙解析器之间字段映射的变化。在迁移过程中,请确保依赖于原始字段的规则、搜索、信息中心或其他进程使用更新后的字段。

    例如,在之前的解析器版本中,category 日志字段映射到 security_result.description UDM 字段。在当前的 Palo Alto Networks 防火墙解析器中,category 日志字段会映射到 security_result.category_details UDM 字段。如果您迁移到当前的 Palo Alto Networks 防火墙解析器,并在规则中使用 category 字段,则需要修改规则以使用当前解析器的 security_result.category_details UDM 字段。

配置 syslog 和 Google Security Operations 转发器

如需配置 syslog 和 Google SecOps 转发器,请完成以下步骤:

  1. 如需监控 CSV 日志,请配置 syslog 服务器配置文件。如需了解详情,请参阅配置 Syslog 服务器配置文件。 配置 syslog 服务器配置文件时,请指定“默认”作为自定义日志格式。
  2. 如需监控 CEF 日志,请将 Palo Alto Networks 防火墙配置为转发 CEF 日志。如需了解详情,请下载 PAN-OS CEF 集成指南 PDF,并参阅“配置 Palo Alto Networks NGFW 以输出 CEF 事件”部分。
  3. 如需监控 LEEF 日志,请配置 syslog 服务器配置文件。如需了解详情,请参阅以 LEEF 格式转发自定义日志
  4. 配置 Google SecOps 转发器,以将日志发送到 Google Security Operations。 如需了解详情,请参阅在 Linux 上安装和配置转发器。以下是 Google SecOps 转发器配置示例:

      - syslog:
          common:
            enabled: true
            data_type: PAN_FIREWALL
            batch_n_seconds: 10
            batch_n_bytes: 1048576
          tcp_address: 0.0.0.0:10518
          connection_timeout_sec: 60
    

在 PAN 防火墙上配置 syslog 转发

创建 syslog 服务器配置文件

  1. 登录 Palo Alto Networks 防火墙管理控制台
  2. 依次前往设备 > 服务器配置文件 > Syslog
  3. 点击添加以创建新的服务器配置文件。
  4. 提供以下配置详细信息:
    • 名称:输入一个描述性名称(例如 Google SecOps BindPlane)。
    • 位置:选择此配置文件可用的虚拟系统 (vsys) 或共享
  5. 点击服务器 > 添加,以配置 Syslog 服务器。
  6. 提供以下服务器配置详细信息:
    • 名称:输入服务器的描述性名称(例如 BindPlane Agent)。
    • Syslog 服务器:输入 BindPlane 代理 IP 地址。
    • 传输:根据 BindPlane Agent 配置选择 UDPTCP(默认值为 UDP)。
    • 端口:输入 BindPlane 代理端口号(例如 514)。
    • 格式:根据您的需求,选择 BSD(默认)或 IETF
    • 设备:根据需要选择 LOG_USER(默认)或其他设备。
  7. 点击 OK 以保存 syslog 服务器配置文件。

可选:为 CEF 或 LEEF 配置自定义日志格式

如果您需要 CEF(通用事件格式)或 LEEF(日志事件扩展格式)日志,而不是 CSV 日志,请执行以下操作:

  1. 在 Syslog 服务器配置文件中,选择自定义日志格式标签页。
  2. 为每种日志类型(配置、系统、威胁、流量、网址、数据、WildFire、隧道、身份验证、User-ID、HIP 匹配)配置自定义日志格式。
  3. 如需了解 CEF 格式配置,请参阅 Palo Alto Networks CEF 配置指南
  4. 点击确定以保存配置。

创建日志转发配置文件

  1. 依次前往对象 > 日志转发
  2. 点击添加以创建新的日志转发配置文件。
  3. 提供以下配置详细信息:
    • 名称:输入配置文件的名称(例如 Google SecOps Forwarding)。如果您希望防火墙自动将此配置文件分配给新的安全规则和区域,请将其命名为 default
  4. 对于要转发的每种日志类型(流量、威胁、WildFire 提交、网址过滤、数据过滤、隧道、身份验证),请配置以下内容:
    • 在相应的日志类型部分中,点击添加
    • Syslog:选择您创建的 syslog 服务器配置文件(例如 Google SecOps BindPlane)。
    • 日志严重程度:选择要转发的严重程度级别(例如全部)。
  5. 点击确定以保存日志转发配置文件。

将日志转发配置文件应用于安全政策

  1. 依次前往政策 > 安全
  2. 选择要为其启用日志转发的安全规则。
  3. 点击相应规则即可进行修改。
  4. 前往操作标签页。
  5. 日志转发菜单中,选择您创建的日志转发配置文件(例如 Google SecOps Forwarding)。
  6. 点击确定以保存安全政策配置。

为系统日志配置日志设置

  1. 依次前往设备 > 日志设置
  2. 针对每种日志类型(系统、配置、User-ID、HIP Match、Global Protect、IP-Tag、SCTP)和严重程度级别,选择您创建的 syslog 服务器配置文件。
  3. 点击确定以保存日志设置。

提交更改

  1. 点击防火墙网页界面顶部的提交
  2. 等待提交成功完成。
  3. 通过在 Google SecOps 控制台中检查传入的 Palo Alto Networks 防火墙日志,验证日志是否已发送到 Bindplane 代理。

使用 Bindplane 代理将日志转发到 Google SecOps

  1. 安装并设置 Linux 虚拟机
  2. 在 Linux 上安装和配置 Bindplane 代理,以将日志转发到 Google SecOps。如需详细了解如何安装和配置 Bindplane 代理,请参阅Bindplane 代理安装和配置说明

如果您在创建 Feed 时遇到问题,请与 Google SecOps 支持团队联系。

支持的日志格式

Palo Alto Networks 防火墙解析器支持 LEEF、CEF 和 CSV 格式的日志。

支持的示例日志

  • LEEF

    <14>Jan 22 02:20:19 device_host LEEF:1.0|Palo Alto Networks|PAN-OS Syslog Integration|10.2.12-h4|Microsoft MSOFFICE(52033)|ReceiveTime=2025/01/22 02:20:18|SerialNumber=01250100xxxx|cat=THREAT|Subtype=wildfire|devTime=Jan 22 2025 08:20:18 GMT|src=198.50.100.1|dst=198.50.100.2|srcPostNAT=198.50.100.3|dstPostNAT=198.50.100.4|RuleName=AZURE-US-NEW-CNF_Inbound_To_Azure-ALLOW|usrName=|SourceUser=|DestinationUser=|Application=smtp-base|VirtualSystem=vsys1|SourceZone=McD-Global-Zone|DestinationZone=Azure-Zone|IngressInterface=ae1.111|EgressInterface=ae2.409|LogForwardingProfile=Default-Traffic-Logging|SessionID=35331795|RepeatCount=1|srcPort=21578|dstPort=25|srcPostNATPort=0|dstPostNATPort=0|Flags=0x2000|proto=tcp|action=allow|Miscellaneous=\"......3...................xls\"|ThreatID=Microsoft MSOFFICE(52033)|URLCategory=malicious|sev=4|Severity=high|Direction=client-to-server|sequence=7462614601465681755|ActionFlags=0x8000000000000000|SourceLocation=198.50.100.1-198.50.100.255|DestinationLocation=United States|ContentType=|PCAP_ID=0|FileDigest=0ea04c99bf188c2e4207f60f92ca7c6f5088c7943ee63f45c50032bbd2bf7ea9|Cloud=demo.com|URLIndex=1|RequestMethod=|FileType=ms-office|Sender=sender@ab.myownpersonaldomain.com|Subject=\"............:.................................................................................-.........(Name)-2025-01-22...............:Y107202501220005, ............:........................, ...............:.........\"|Recipient=abc@demo.myownpersonaldomain.com|ReportID=117022282776|DeviceGroupHierarchyL1=143|DeviceGroupHierarchyL2=144|DeviceGroupHierarchyL3=39|DeviceGroupHierarchyL4=0|vSrcName=|DeviceName=device_host|SrcUUID=|DstUUID=|TunnelID=0|MonitorTag=|ParentSessionID=0|ParentStartTime=|TunnelType=N/A|ThreatCategory=N/A|ContentVer=WildFire-0
    
  • CEF

    14>1 2024-04-04T16:21:56+02:00 FW-PERIMETRAL-AVG-01 - - - - CEF:0|Palo Alto Networks|PAN-OS|10.1.10-h2|end|TRAFFIC|1|src=198.51.100.1 dst=198.51.100.2 srcTranslatedAddress=198.51.100.3 dstTranslatedAddress=198.51.100.4 rule=FW_USER_NATS2_APP suser= duser= app=bittorrent vs=vsys1 sz=INSIDE dz=EXTERNAL InboundInterface=ae2.2266 OutboundInterface=ae1 lp=log_forwarding sid=2935823 cnt=1 spt=6881 dpt=51413 srcTranslatedPort=0 dstTranslatedPort=0 flags=0x7a proto=udp act=allow tbytes=475 in=150 out=325 pkt=2 pktReceived=1 pktSent=1 start=Apr 04 2024 14:21:56 GMT stime=1206 urlcat=any externalId=externalId reason=aged-out DGl1=11 DGl2=161 DGl3=0 DGl4=0 VsysName=STONESOFT dvchost=FW-PERIMETRAL-AVG-01 cat=from-policy ActionFlags=0x8000000000000000 srcUUID= dstUUID= TunnelID=0 MonitorTag= ParentSessionID=0 ParentStartTime= TunnelType=N/A SCTPAssocID=0 SCTPChunks=0 SCTPChunkSent=0 SCTPChunksRcv=0 RuleUUID=746c3eb6-3d51-4679-8438-bd0e00e170a8 HTTP2Con=0 LinkChange=0 PolicyID= LinkDetail= SDWANCluster= SDWANDevice= SDWANClustype= SDWANSite= DynamicUsrgrp= XFFIP= srcDevCat= srcDevProf= srcDevModel= srcDevVendor= srcDevOS= srcDevOSv= srcHostname= srcMac= dstDevCat= dstDevProf= dstDevModel= dstDevVendor= dstDevOS= dstDevOSv= dstHostname= dstMac= ContainerName= PODNamespace= PODName= srcEDL= dstEDL= GPHostID= EPSerial= srcDAG= dstDAG= HASessionOwner= TimeHighRes=2024-04-04T16:21:56.250+02:00 ASServiceType= ASServiceDiff="
    
  • CSV

    1,2021/10/24 15:30:07,,CONFIG,0,2561,2021/10/24 15:30:07,198.51.100.0,,set,admin,Web,Succeeded, network virtual-router  VR1,,VR1  { ecmp { algorithm { ip-modulo ; } } protocol { bgp { routing-options { graceful-restart { enable yes; } } enable no; } rip { enable no; } ospf { enable no; } ospfv3 { enable no; } } routing-table { ip { static-route { vr1-log  { path-monitor { enable no; failure-condition any; hold-time 2; } nexthop { ip-address 198.51.100.0; } bfd { profile None; } interface ethernet1/1; metric 10; destination 0.0.0.0/0; route-table { unicast ; } } } } } interface [ ethernet1/1 ethernet1/2 ]; } ,7022390503849066572,0x0,0,0,0,0,,PA-VM,0,
    

字段映射参考信息:日志字段到 UDM 字段

本部分介绍了对于每种日志类型,解析器如何将 Palo Alto Networks 防火墙日志字段映射到 Google SecOps UDM 事件字段。Google SecOps 标签键是指映射到 Labels.key UDM 字段的键的名称。

例如,对于“虚拟系统”字段,在 CEF 格式中,字段名称为“cs3”,而在 LEEF 格式中,字段名称为“VirtualSystem”。UDM 字段“about.labels.key”包含值“vsys”,UDM 字段“about.labels.value”包含相应字段的值。 部分 CEF 或 LEEF 字段名称没有与 CSV 字段名称对应的名称。在这种情况下,如果您在 syslog 配置文件的自定义日志格式中添加自己的变量名称,解析器不会将其映射到 UDM 字段。

如需了解每种日志类型的映射参考信息,请参阅以下部分:

系统

下表列出了系统日志类型的日志字段及其对应的 UDM 字段。

CSV 字段 CEF 字段 LEEF 字段 Google Security Operations 标签键 UDM 字段
接收时间(receive_time 或 cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp(如果缺少“生成时间”)

序列号(序列) deviceExternalId SerialNumber target.asset.hardware.serial_number
类型(类型) type(标头) metadata.product_event_type 设置为“%{type} - %{subtype}”。
威胁/内容类型(子类型) 子类型(标头) 子类型 metadata.product_event_type 设置为“%{type} - %{subtype}”。
生成时间(time_generated 或 cef-formatted-time_generated) metadata.event_timestamp
虚拟系统 (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
活动 ID (eventid) eventid additional.fields.key 和 additional.fields.value.string_value
对象(对象) fname 文件名 object target.resource.name
模块(模块) flexString2 模块 模块 additional.fields.key 和 additional.fields.value.string_value
严重程度(严重程度) $number-of-severity(header) 严重程度 security_result.severity 和 security_result.severity_details
说明(不透明) 消息 消息 metadata.description
principal_user_userid(此字段提取自 msg 字段) principal.user.userid
principal_ip3(此字段是从 msg 字段中提取的) principal.ip
原因(此字段是从 msg 字段中提取的) security_result.description
server_address(此字段提取自 msg 字段。) target.ip
server_profile(此字段是从 msg 字段中提取的。) additional.fields.key 和 additional.fields.value.string_value
序列号 (seqno) externalId 序列 metadata.product_log_id
操作标志 (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
设备组层次结构(dg_hier_level_1 至 dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虚拟系统名称 (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
设备名称 (device_name) dvchost DeviceName target.hostname
高分辨率时间戳 (high_res_timestamp) anOSTimeGeneratedHighResolution additional.fields.key 和 additional.fields.value.string_value

配置

下表列出了配置日志类型的日志字段及其对应的 UDM 字段。

CSV 字段 CEF 字段 LEEF 字段 Google Security Operations 标签键 UDM 字段
接收时间(receive_time 或 cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp(如果缺少“生成时间”)

序列号(序列) deviceExternalId SerialNumber target.asset.hardware.serial_number
类型(类型) type(标头) metadata.product_event_type
威胁/内容类型(子类型) 子类型(标头) metadata.product_event_type
生成时间(time_generated 或 cef-formatted-time_generated) metadata.event_timestamp
主机 (host) shost src principal.ip/hostname
虚拟系统 (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
命令 (cmd) act 消息 cmd principal.process.command_line
管理员 (admin) duser usrName principal.user.userid
客户端(客户端) destinationServiceName 客户端 principal.application
结果(结果) 签名 ID(标头)(原因) 结果 security_result.summary
配置路径(路径) 消息 ConfigurationPath principal.process.command_line
更改前详情 (before_change_detail) cs1 BeforeChangeDetail before_change_detail target.resource.attribute.labels.key/value
更改后详细信息 (after_change_detail) cs2 AfterChangeDetail after_change_detail target.resource.attribute.labels.key/value
序列号 (seqno) externalId 序列 metadata.product_log_id
操作标志 (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
设备组层次结构(dg_hier_level_1 至 dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虚拟系统名称 (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
设备名称 (device_name) dvchost DeviceName target.hostname
设备组 (dg_id) PanOSFWDeviceGroup target.asset.attribute.labels.key/value dg_id principal.asset.attribute.labels.key/value
审核评论(评论) PanOSPolicyAuditComment 评论 additional.fields.key 和 additional.fields.value.string_value
高分辨率时间戳 (high_res_timestamp) additional.fields.key 和 additional.fields.value.string_value
严重程度(严重程度) number-of-severity(header) security_result.severity 和 security_result.severity_details

威胁/WildFire

下表列出了威胁/WildFire 日志类型的日志字段及其对应的 UDM 字段。

CSV 字段 CEF 字段 LEEF 字段 Google Security Operations 标签键 UDM 字段
接收时间(receive_time 或 cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp(如果缺少“生成时间”)

序列号(序列号) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
类型(类型) type(标头) metadata.product_event_type
威胁/内容类型(子类型) 类别/子类型(标题) 子类型 metadata.product_event_type
生成时间(time_generated 或 cef-formatted-time_generated) metadata.event_timestamp
来源地址 (src) src src principal.ip
目的地地址 (dst) dst dst target.ip
NAT 源 IP (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
NAT 目标 IP (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
规则名称(规则) cs1 RuleName security_result.rule_name
源用户 (srcuser) suser SourceUser / usrName principal.user.userid
目标用户 (dstuser) duser DestinationUser target.user.userid
应用(应用) 应用 应用 target.application
虚拟系统 (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
来源可用区(从) cs4 SourceZone from

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目标可用区(到) cs5 DestinationZone

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

入站接口 (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

出站接口 (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

日志操作 (logset) cs6 LogForwardingProfile logset additional.fields.key 和 additional.fields.value.string_value
会话 ID (sessionid) cn1 SessionID network.session_id
重复次数 (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key 和 additional.fields.value.string_value
来源端口 (sport) spt srcPort principal.port
目标端口 (dport) dpt dstPort target.port
NAT 源端口 (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
NAT 目标端口 (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
标志 (flags) flexString1 标志 标志 additional.fields.key 和 additional.fields.value.string_value
IP 协议 (proto) proto proto network.ip_protocol
操作(操作) act 操作 security_result.action_details

security_result.action

网址/文件名(其他) 请求 其他

target.file.names(如果子类型为“file”“virus”“wildfire-virus”或“wildfire”,则“misc”字段会映射到 target.file.names)

target.url(如果子类型为“url”,则“misc”字段会映射到 target.url 和 target.hostname)

威胁/内容名称 (threatid) ThreatID security_result.threat_name
类别(category) cs2 URLCategory security_result.category_details
严重程度(严重程度) number-of-severity(header) 严重程度 security_result.severity 和 security_result.severity_details
方向(direction) flexString2 方向 network.direction
序列号 (seqno) externalId 序列 metadata.product_log_id
操作标志 (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
来源国家/地区 (srcloc) SourceLocation principal.location.country_or_region
目的地国家/地区 (dstloc) DestinationLocation target.location.country_or_region
内容类型 (contenttype) ContentType contenttype additional.fields.key 和 additional.fields.value.string_value
PCAP ID (pcap_id) fileId PCAP_ID pcap_id additional.fields.key 和 additional.fields.value.string_value
文件摘要 (filedigest) fileHash FileDigest target.file.sha1/md5/sha256
云端(云) filePath Cloud additional.fields.key 和 additional.fields.value.string_value
网址索引 (url_idx) URLIndex url_idx additional.fields.key 和 additional.fields.value.string_value
用户代理 (user_agent) network.http.user_agent
文件类型 (filetype) fileType FileType target.file.mime_type
X-Forwarded-For (xff) principal.ip
引荐来源网址(referer) network.http.referral_url
发件人 (sender) suid 发件人 network.email.from
主题(主题) 消息 主题 network.email.subject
收件人(收件人) duid 收件人 network.email.to
报告 ID (reportid) oldFileId ReportID reportid additional.fields.key 和 additional.fields.value.string_value
设备组层次结构(dg_hier_level_1 至 dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虚拟系统名称 (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
设备名称 (device_name) dvchost DeviceName intermediary.hostname
源虚拟机的 UUID (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
目标虚拟机的 UUID (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
HTTP 方法 (http_method) RequestMethod network.http.method
隧道 ID/IMSI (tunnel_id/imsi) PanOSTunnelID TunnelID tunnel_id/imsi additional.fields.key 和 additional.fields.value.string_value
监控标记/IMEI (monitortag/imei) PanOSMonitorTag MonitorTag monitortag/imei additional.fields.key 和 additional.fields.value.string_value
父会话 ID (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
父会话开始时间 (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key 和 additional.fields.value.string_value
隧道类型(隧道) PanOSTunnelType TunnelType 隧道 additional.fields.key 和 additional.fields.value.string_value
威胁类别 (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
内容版本 (contentver) PanOSContentVer ContentVer contentver additional.fields.key 和 additional.fields.value.string_value
SCTP 关联 ID (assoc_id) PanOSAssocID assoc_id additional.fields.key 和 additional.fields.value.string_value
载荷协议 ID (ppid) PanOSPPID ppid additional.fields.key 和 additional.fields.value.string_value
HTTP 标头 (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
网址类别列表 (url_category_list) PanOSURLCatList url_category_list additional.fields.key 和 additional.fields.value.string_value
规则 UUID (rule_uuid) PanOSRuleUUID security_result.rule_id
HTTP/2 连接 (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
动态用户组名称 (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

XFF 地址 (xff_ip) PanXFFIP principal.ip
来源设备类别 (src_category) PanSrcDeviceCat src_category principal.asset.category
源设备配置文件 (src_profile) PanSrcDeviceProf src_profile

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

源设备型号 (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
源设备供应商 (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
源设备操作系统系列 (src_osfamily) PanSrcDeviceOS src_osfamily principal.platform
源设备操作系统版本 (src_osversion) PanSrcDeviceOSv principal.platform_version
来源主机名 (src_host) PanSrcHostname principal.hostname
源 MAC 地址 (src_mac) PanSrcMac principal.mac
目标设备类别 (dst_category) PanDstDeviceCat dst_category target.asset.category
目标设备配置文件 (dst_profile) PanDstDeviceProf dst_profile

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

目标设备型号 (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
目标设备供应商 (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
目标设备操作系统系列 (dst_osfamily) PanDstDeviceOS dst_osfamily target.platform
目标设备操作系统版本 (dst_osversion) PanDstDeviceOSv target.platform_version
目标主机名 (dst_host) PanDstHostname target.hostname
目标 MAC 地址 (dst_mac) PanDstMac target.mac
容器 ID (container_id) PanContainerName container_id intermediary.resource.product_object_id
POD 命名空间 (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
POD 名称 (pod_name) PanPODName pod_name target.resource.name
来源外部动态列表 (src_edl) PanSrcEDL src_edl additional.fields.key 和 additional.fields.value.string_value
目标外部动态列表 (dst_edl) PanDstEDL dst_edl additional.fields.key 和 additional.fields.value.string_value
主机 ID (hostid) PanGPHostID hostid principal.asset.asset_id
用户设备序列号 (serialnumber) PanEPSerial principal.asset.hardware.serial_number
网域 EDL (domain_edl) PanDomainEDL domain_edl additional.fields.key 和 additional.fields.value.string_value
源动态地址组 (src_dag) PanSrcDAG principal.group.group_display_name
目标动态地址组 (dst_dag) PanDstDAG target.group.group_display_name
部分哈希 (partial_hash) PanPartialHash partial_hash additional.fields.key 和 additional.fields.value.string_value
高分辨率时间戳(high_res 时间戳) PanTimeHighRes 高分辨率时间戳 additional.fields.key 和 additional.fields.value.string_value
原因 (reason) PanReasonFilteringAction 原因 security_result.summary
理由(理由) PanJustification 对齐方式 additional.fields.key 和 additional.fields.value.string_value
切片服务类型 (nssai_sst) PanASServiceType nssai_sst additional.fields.key 和 additional.fields.value.string_value
应用子类别 (subcategory_of_app) subcategory_of_app additional.fields.key 和 additional.fields.value.string_value
应用类别 (category_of_app) category_of_app additional.fields.key 和 additional.fields.value.string_value
应用技术 (technology_of_app) technology_of_app additional.fields.key 和 additional.fields.value.string_value
应用风险 (risk_of_app) risk_of_app additional.fields.key 和 additional.fields.value.string_value
应用特征 (characteristic_of_app) characteristic_of_app additional.fields.key 和 additional.fields.value.string_value
应用容器 (container_of_app) container_of_app additional.fields.key 和 additional.fields.value.string_value
应用 SaaS (is_saas_of_app) is_saas_of_app additional.fields.key 和 additional.fields.value.string_value
隧道应用 (tunneled_app) additional.fields.key 和 additional.fields.value.string_value
流量类型 (flow_type) additional.fields.key 和 additional.fields.value.string_value
集群名称 (cluster_name) intermediary.resource.name
应用受制裁状态 (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key 和 additional.fields.value.string_value

流量

下表列出了流量日志类型的日志字段及其对应的 UDM 字段。

CSV 字段 CEF 字段 LEEF 字段 Google Security Operations 标签键 UDM 字段
接收时间(receive_time 或 cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp(如果缺少“生成时间”)

序列号(序列) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
类型(类型) type(标头) cat/Type metadata.product_event_type
威胁/内容类型(子类型) 子类型(标头) 子类型 metadata.product_event_type
生成时间(time_generated 或 cef-formatted-time_generated) 开始 metadata.event_timestamp
来源地址 (src) src src principal.ip
目的地地址 (dst) dst dst target.ip
NAT 源 IP (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
NAT 目标 IP (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
规则名称(规则) cs1 RuleName security_result.rule_name
源用户 (srcuser) suser SourceUser principal.user.userid
目标用户 (dstuser) duser DestinationUser target.user.userid
应用(应用) 应用 应用 target.application
虚拟系统 (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
来源可用区(从) cs4 SourceZone from

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目标可用区(到) cs5 DestinationZone

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

入站接口 (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

出站接口 (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

日志操作 (logset) cs6 LogForwardingProfile logset additional.fields.key 和 additional.fields.value.string_value
会话 ID (sessionid) cn1 SessionID network.session_id
重复次数 (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key 和 additional.fields.value.string_value
来源端口 (sport) spt srcPort principal.port
目标端口 (dport) dpt dstPort target.port
NAT 源端口 (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
NAT 目标端口 (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
标志 (flags) flexString1 标志 标志 additional.fields.key 和 additional.fields.value.string_value
IP 协议 (proto) proto proto network.ip_protocol
操作(操作) act 操作 security_result.action_details

security_result.action

字节(字节) flexNumber1 totalBytes 字节 additional.fields.key 和 additional.fields.value.string_value
发送的字节数 (bytes_sent) srcBytes network.sent_bytes
接收的字节数 (bytes_received) out dstBytes network.received_bytes
数据包(数据包) cn2 totalPackets 数据包 additional.fields.key 和 additional.fields.value.string_value
开始时间(开始) StartTime 开始 additional.fields.key 和 additional.fields.value.string_value
已用时间(已用) cn3 ElapsedTime 已用时间 network.session_duration.seconds
类别(category) cs2 URLCategory security_result.category / security_result.category_details
序列号 (seqno) externalId 序列 metadata.product_log_id
操作标志 (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
来源国家/地区 (srcloc) SourceLocation principal.location.country_or_region
目的地国家/地区 (dstloc) DestinationLocation target.location.country_or_region
发送的数据包数 (pkts_sent) PanOSPacketsSent srcPackets pkts_sent network.sent_packets
接收的数据包数量 (pkts_received) PanOSPacketsReceived dstPackets pkts_received network.received_packets
会话结束原因 (session_end_reason) 原因 SessionEndReason security_result.summary
设备组层次结构 1(dg_hier_level_1 至 dg_hier_level_4) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 2 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 3 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虚拟系统名称 (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
设备名称 (device_name) dvchost DeviceName intermediary.hostname
操作来源 (action_source) ActionSource action_source additional.fields.key 和 additional.fields.value.string_value
源虚拟机的 UUID (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
目标虚拟机的 UUID (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
隧道 ID/IMSI (tunnelid/imsi) PanOSTunnelID TunnelID tunnelid/imsi additional.fields.key 和 additional.fields.value.string_value
监控标记/IMEI (monitortag/imei) PanOSMonitorTag MonitorTag monitortag/imei additional.fields.key 和 additional.fields.value.string_value
父会话 ID (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
父开始时间 (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key 和 additional.fields.value.string_value
隧道类型(隧道) PanOSTunnelType TunnelType 隧道 additional.fields.key 和 additional.fields.value.string_value
SCTP 关联 ID (assoc_id) PanOSSCTPAssocID assoc_id additional.fields.key 和 additional.fields.value.string_value
SCTP 块(块) PanOSSCTPChunks additional.fields.key 和 additional.fields.value.string_value
发送的 SCTP 数据块数 (chunks_sent) PanOSSCTPChunkSent chunks_sent additional.fields.key 和 additional.fields.value.string_value
接收到的 SCTP 数据块 (chunks_received) PanOSSCTPChunksRcv chunks_received additional.fields.key 和 additional.fields.value.string_value
规则 UUID (rule_uuid) PanOSRuleUUID security_result.rule_id
HTTP/2 连接 (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
应用抖动次数 (link_change_count) PanLinkChange link_change_count additional.fields.key 和 additional.fields.value.string_value
政策 ID (policy_id) PanPolicyID policy_id additional.fields.key 和 additional.fields.value.string_value
链接开关 (link_switches) PanLinkDetail link_switches additional.fields.key 和 additional.fields.value.string_value
SD-WAN 集群 (sdwan_cluster) PanSDWANCluster sdwan_cluster additional.fields.key 和 additional.fields.value.string_value
SD-WAN 设备类型 (sdwan_device_type) PanSDWANDevice sdwan_device_type additional.fields.key 和 additional.fields.value.string_value
SD-WAN 集群类型 (sdwan_cluster_type) PanSDWANClustype sdwan_cluster_type additional.fields.key 和 additional.fields.value.string_value
SD-WAN 网站 (sdwan_site) PanSDWANSite sdwan_site additional.fields.key 和 additional.fields.value.string_value
动态用户组名称 (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name additional.fields.key 和 additional.fields.value.string_value
XFF 地址 (xff_ip) PanXFFIP principal.ip
来源设备类别 (src_category) PanSrcDeviceCat src_category principal.asset.category
源设备配置文件 (src_profile) PanSrcDeviceProf src_profile

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

源设备型号 (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
源设备供应商 (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
源设备操作系统系列 (src_osfamily) PanSrcDeviceOS principal.platform
源设备操作系统版本 (src_osversion) PanSrcDeviceOSv principal.asset.software.version
来源主机名 (src_host) PanSrcHostname principal.hostname
源 MAC 地址 (src_mac) PanSrcMac principal.mac
目标设备类别 (dst_category) PanDstDeviceCat dst_category target.asset.category
目标设备配置文件 (dst_profile) PanDstDeviceProf dst_profile

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

目标设备型号 (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
目标设备供应商 (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
目标设备操作系统系列 (dst_osfamily) PanDstDeviceOS dst_osfamily target.platform
目标设备操作系统版本 (dst_osversion) PanDstDeviceOSv target.platform_version
目标主机名 (dst_host) PanDstHostname target.hostname
目标 MAC 地址 (dst_mac) PanDstMac target.mac
容器 ID (container_id) PanContainerName container_id intermediary.resource.product_object_id
POD 命名空间 (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
POD 名称 (pod_name) PanPODName pod_name target.resource.name
来源外部动态列表 (src_edl) PanSrcEDL src_edl

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目标外部动态列表 (dst_edl) PanDstEDL dst_edl

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

主机 ID (hostid) PanGPHostID hostid principal.asset.asset_id
用户设备序列号 (serialnumber) PanEPSerial principal.asset.hardware.serial_number
源动态地址组 (src_dag) PanSrcDAG principal.group.group_display_name
目标动态地址组 (dst_dag) PanDstDAG target.group.group_display_name
会话所有者 (session_owner) PanHASessionOwner session_owner additional.fields.key 和 additional.fields.value.string_value
高分辨率时间戳 (high_res_timestamp) PanTimeHighRes additional.fields.key 和 additional.fields.value.string_value
切片服务类型 (nsdsai_sst) PanASServiceType nsdsai_sst additional.fields.key 和 additional.fields.value.string_value
Slice 区分器 (nsdsai_sd) PanASServiceDiff nsdsai_sd additional.fields.key 和 additional.fields.value.string_value
应用子类别 (subcategory_of_app) subcategory_of_app additional.fields.key 和 additional.fields.value.string_value
应用类别 (category_of_app) category_of_app additional.fields.key 和 additional.fields.value.string_value
应用技术 (technology_of_app) technology_of_app additional.fields.key 和 additional.fields.value.string_value
应用风险 (risk_of_app) security_result.severity
应用特征 (characteristic_of_app) characteristic_of_app additional.fields.key 和 additional.fields.value.string_value
应用容器 (container_of_app) container_of_app additional.fields.key 和 additional.fields.value.string_value
应用 SaaS (is_saas_of_app) is_saas_of_app additional.fields.key 和 additional.fields.value.string_value
应用受制裁状态 (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key 和 additional.fields.value.string_value
应用子类别 (subcategory_of_app) subcategory_of_app1 additional.fields.key 和 additional.fields.value.string_value
严重程度(严重程度) number-of-severity(header) security_result.severity 和 security_result.severity_details

User-ID

下表列出了用户 ID 日志类型的日志字段及其对应的 UDM 字段。

CSV 字段 CEF 字段 LEEF 字段 Google Security Operations 标签键 UDM 字段
接收时间(receive_time 或 cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp(如果缺少“生成时间”)

序列号(序列) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
类型(类型) type(标头) metadata.product_event_type
威胁/内容类型(子类型) 子类型(标头) 子类型 metadata.product_event_type
生成时间(time_generated 或 cef-formatted-time_generated) metadata.event_timestamp
虚拟系统 (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
来源 IP (ip) src src principal.ip
用户 (user) duser usrName target.user.userid

target.administrative_domain

target.user.email_addresses

数据源名称 (datasourcename) cs4 DataSourceName datasourcename

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

活动 ID (eventid) EventID eventid additional.fields.key 和 additional.fields.value.string_value
重复次数 (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key 和 additional.fields.value.string_value
超时阈值(超时) cn3 TimeoutThreshold 超时 additional.fields.key 和 additional.fields.value.string_value
来源端口 (beginport) spt srcPort principal.port
目标端口 (endport) dpt dstPort target.port
数据源 (datasource) cs5 DataSource 数据源

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

数据源类型 (datasourcetype) cs6 DataSourceType datasourcetype

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

序列号 (seqno) externalId 序列 metadata.product_log_id
操作标志 (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虚拟系统名称 (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
设备名称 (device_name) dvchost DeviceName intermediary.hostname
虚拟系统 ID (vsys_id) cn2 VirtualSystemID intermediary.resource.product_object_id
因子类型 (factortype) cs1 FactorType factortype additional.fields.key 和 additional.fields.value.string_value
因子完成时间 (factorcompletiontime) 结束 FactorCompletionTime factorcompletiontime additional.fields.key 和 additional.fields.value.string_value
Factor Number (factorno) cn1 FactorNumber factorno additional.fields.key 和 additional.fields.value.string_value
用户组标志 (ugflags) PanOSUGFlags ugflags additional.fields.key 和 additional.fields.value.string_value
按来源细分的用户 (userbysource) PanOSUserBySource target.user.userid

target.administrative_domain

target.user.email_addresses

高分辨率时间戳(high_res 时间戳) PanOSTimeGeneratedHighResolution additional.fields.key 和 additional.fields.value.string_value
原始数据源 (origindatasource) additional.fields.key 和 additional.fields.value.string_value
集群名称 (cluster_name) principal.resource.name
严重程度(严重程度) number-of-severity(header) security_result.severity 和 security_result.severity_details

HIP 匹配

下表列出了 HIP 匹配日志类型的日志字段及其对应的 UDM 字段。

CSV 字段 CEF 字段 LEEF 字段 Google Security Operations 标签键 UDM 字段
接收时间(receive_time 或 cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp(如果缺少“生成时间”)

序列号(序列) deviceExternalId SerialNumber target.asset.hardware.serial_number
类型(类型) type(标头) metadata.product_event_type
威胁/内容类型(子类型) 子类型(标头) 子类型
生成时间(time_generated 或 cef-formatted-time_generated) 开始 startTime metadata.event_timestamp
源用户 (srcuser) suser usrName principal.user.userid
虚拟系统 (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
机器名称 (machinename) shost identHostName principal.hostname
操作系统 (os) cs2 操作系统 principal.asset.platform_software.platform
来源地址 (src) src identsrc principal.ip
HIP(匹配名称) HIP matchname

target.resource.attribute.labels.key/value

additional.fields.key 和 additional.fields.value.string_value

重复次数 (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key 和 additional.fields.value.string_value
HIP 类型(matchtype) 设备事件类 ID(标头) HIPType matchtype

target.resource.attribute.labels.key/value

additional.fields.key 和 additional.fields.value.string_value

序列号 (seqno) externalId 序列 metadata.product_log_id
操作标志 (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虚拟系统名称 (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels.key/value
设备名称 (device_name) dvchost DeviceName target.hostname
虚拟系统 ID (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
IPv6 系统地址 (srcipv6) c6a2 srcipv6 principal.asset.ip
主机 ID (hostid) PanOSHostID principal.asset.asset_id
用户设备序列号 (serialnumber) PanOSEndpointSerialNumber principal.asset.hardware.serial_number
设备 MAC 地址 (mac) PanOSEndpointMac principal.asset.mac
高分辨率时间戳 (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key 和 additional.fields.value.string_value
集群名称 (cluster_name) principal.resource.name
严重程度(严重程度) number-of-severity(header) security_result.severity 和 security_result.severity_details

IP 代码

下表列出了 IP 标记日志类型的日志字段及其对应的 UDM 字段。

CSV 字段 CEF 字段 LEEF 字段 Google Security Operations 标签键 UDM 字段
接收时间(receive_time 或 cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp(如果缺少“生成时间”)

序列号(序列) deviceExternalId SerialNumber target.asset.hardware.serial_number
类型(类型) type(标头) metadata.product_event_type
威胁/内容类型(子类型) 子类型(标头) 子类型 metadata.product_event_type
生成时间(time_generated 或 cef-formatted-time_generated) GenerateTime metadata.event_timestamp
虚拟系统 (vsys) cs3 VirtualSystem vsys target.asset.attribute.labels.key/value
来源 IP (ip) src src principal.ip
代码名称 (tag_name) PanOSTagName TagName tag_name

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

活动 ID (event_id) PanOSEventID EventID event_id additional.fields.key 和 additional.fields.value.string_value
重复次数 (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key 和 additional.fields.value.string_value
超时(超时) PanOSTimeout TimeoutThreshold 超时 additional.fields.key 和 additional.fields.value.string_value
数据源名称 (datasourcename) PanOSDataSourceName DataSourceName datasourcename

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

数据源类型 (datasource_type) PanOSDataSourceType DataSource datasource_type

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

数据源子类型 (datasource_subtype) PanOSDataSourceSubType DataSourceType datasource_subtype

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

序列号 (seqno) externalId 序列 metadata.product_log_id
操作标志 (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虚拟系统名称 (vsys_name) PanOsVsysName vSrcName target.asset.attribute.labels.key/value
设备名称 (device_name) dvchost DeviceName target.hostname
虚拟系统 ID (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
高分辨率时间戳(high_res 时间戳) PanOSTimeGeneratedHighResolution additional.fields.key 和 additional.fields.value.string_value
严重程度(严重程度) number-of-severity(header) security_result.severity 和 security_result.severity_details
集群名称 (cluster_name) principal.resource.name

解密

下表列出了解密日志类型的日志字段及其对应的 UDM 字段。

CSV 字段 CEF 字段 LEEF 字段 Google Security Operations 标签键 UDM 字段
接收时间(receive_time 或 cef-formatted-receive_time) rt metadata.collected_timestamp,

metadata.event_timestamp(如果缺少“生成时间”)

序列号(序列) PanOSDeviceSN intermediary.asset.hardware.serial_number
类型(类型) type(标头) metadata.product_event_type
威胁/内容类型(子类型) 子类型(标头) metadata.product_event_type
配置版本 (config_ver) PanOSConfigVersion config_ver additional.fields.key 和 additional.fields.value.string_value
生成时间 (time_generated) PanOSLogTimeStamp metadata.event_timestamp
来源地址 (src) src principal.ip
目的地地址 (dst) dst target.ip
NAT 源 IP (natsrc) sourceTranslatedAddress principa.nat_ip
NAT 目标 IP (natdst) destinationTranslatedAddress target.nat_ip
规则(规则) cs1 security_result.rule_name
源用户 (srcuser) suser principal.user.userid
目标用户 (dstuser) duser target.user.userid
应用(应用) 应用 network.application_protocol
虚拟系统 (vsys) cs3 vsys intermediary.asset.attribute.labels.key/value
来源可用区(从) cs4 from

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目标可用区(到) cs5

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

入站接口 (inbound_if) deviceInboundInterface inbound_if

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

出站接口 (outbound_if) deviceOutboundInterface outbound_if

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

日志操作 (logset) cs6 logset additional.fields.key 和 additional.fields.value.string_value
记录的时间 (time_received) PanOSTimeReceivedManagementPlane -
会话 ID (sessionid) cn1 network.session_id
重复次数 (repeatcnt) PanOSCountOfRepeats/RepeatCount repeatcnt additional.fields.key 和 additional.fields.value.string_value
来源端口 (sport) spt principal.port
目标端口 (dport) dpt target.port
NAT 源端口 (natsport) sourceTranslatedPort principal.nat_port
NAT 目标端口 (natdport) destinationTranslatedPort target.nat_port
标志 (flags) flexString1 标志 additional.fields.key 和 additional.fields.value.string_value
IP 协议 (proto) proto network.ip_protocol
操作(操作) act security_result.action_details

security_result.action

隧道 (tunnel) PanOSTunnel 隧道 additional.fields.key 和 additional.fields.value.string_value
源虚拟机的 UUID (src_uuid) PanOSSourceUUID principal.asset.product_object_id
目标虚拟机的 UUID (dst_uuid) PanOSDestinationUUID target.asset.product_object_id
规则的 UUID (rule_uuid) PanOSRuleUUID security_result.rule_id
客户端到防火墙的阶段 (hs_stage_c2f) PanOSClientToFirewall hs_stage_c2f additional.fields.key 和 additional.fields.value.string_value
防火墙到服务器的阶段 (hs_stage_f2s) PanOSFirewallToServer hs_stage_f2s additional.fields.key 和 additional.fields.value.string_value
TLS 版本 (tls_version) PanOSTLSVersion network.tls.version
密钥交换算法 (tls_keyxchg) PanOSTLSKeyExchange tls_keyxchg additional.fields.key 和 additional.fields.value.string_value
加密算法 (tls_enc) PanOSTLSEncryptionAlgorithm tls_enc additional.fields.key 和 additional.fields.value.string_value
哈希算法 (tls_auth) PanOSTLSAuth tls_auth additional.fields.key 和 additional.fields.value.string_value
政策名称 (policy_name) PanOSPolicyName policy_name additional.fields.key 和 additional.fields.value.string_value
椭圆曲线 (ec_curve) PanOSEllipticCurve network.tls.curve
错误索引 (err_index) PanOSErrorIndex err_index additional.fields.key 和 additional.fields.value.string_value
根状态 (root_status) PanOSRootStatus root_status additional.fields.key 和 additional.fields.value.string_value
链状态 (chain_status) PanOSChainStatus chain_status additional.fields.key 和 additional.fields.value.string_value
代理类型 (proxy_type) PanOSProxyType proxy_type additional.fields.key 和 additional.fields.value.string_value
证书序列号 (cert_serial) PanOSCertificateSerial network.tls.server.certificate.serial
证书指纹(指纹) PanOSFingerprint network.tls.server.certificate.md5/sha1/sha256
证书开始日期 (notbefore) PanOSTimeNotBefore network.tls.server.certificate.not_before
证书结束日期 (notafter) PanOSTimeNotAfter network.tls.server.certificate.not_after
证书版本 (cert_ver) PanOSCertificateVersion network.tls.server.certificate.version
证书大小 (cert_size) PanOSCertificateSize cert_size additional.fields.key 和 additional.fields.value.string_value
通用名称长度 (cn_len) PanOSCommonNameLength cn_len additional.fields.key 和 additional.fields.value.string_value
颁发机构通用名称长度 (issuer_len) PanOSIssuerNameLength issuer_len additional.fields.key 和 additional.fields.value.string_value
根通用名称长度 (rootcn_len) PanOSRootCNLength rootcn_len additional.fields.key 和 additional.fields.value.string_value
SNI 长度 (sni_len) PanOSSNILength sni_len additional.fields.key 和 additional.fields.value.string_value
证书标志 (cert_flags) PanOSCertificateFlags cert_flags additional.fields.key 和 additional.fields.value.string_value
正文通用名称 (cn) PanOSCommonName cn additional.fields.key 和 additional.fields.value.string_value
颁发机构通用名称 (issuer_cn) PanOSIssuerCommonName network.tls.server.certificate.issuer
根通用名称 (root_cn) PanOSRootCommonName root_cn additional.fields.key 和 additional.fields.value.string_value
服务器名称指示

(sni)

network.tls.client.server_name
错误(错误) PanOSErrorMessage 错误 additional.fields.key 和 additional.fields.value.string_value
容器 ID (container_id) PanOSContainerID container_id intermediary.resource.product_object_id
POD 命名空间 (pod_namespace) PanOSContainerNameSpace pod_namespace

target.resource.attribute.labels.key/value

additional.fields.key 和 additional.fields.value.string_value

POD 名称 (pod_name) PanOSContainerName pod_name target.resource.name
来源外部动态列表 (src_edl) PanOSSourceEDL src_edl

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目标外部动态列表 (dst_edl) PanOSDestinationEDL dst_edl

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

源动态地址组 (src_dag) PanOSSourceDynamicAddressGroup principal.group.group_display_name
目标动态地址组 (dst_dag) PanOSDestinationDynamicAddressGroup target.group.group_display_name
高分辨率时间戳 (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key 和 additional.fields.value.string_value
来源设备类别 (src_category) PanOSSourceDeviceCategory src_category principal.asset.category
源设备配置文件 (src_profile) PanOSSourceDeviceProfile src_profile

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

源设备型号 (src_model) PanOSSourceDeviceModel src_model principal.asset.hardware.model
源设备供应商 (src_vendor) PanOSSourceDeviceVendor src_vendor principal.asset.hardware.manufacturer
源设备操作系统系列 (src_osfamily) PanOSSourceDeviceOSFamily principal.platform
源设备操作系统版本 (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
来源主机名 (src_host) PanOSSourceDeviceHost principal.hostname
源 MAC 地址 (src_mac) PanOSSourceDeviceMac principal.mac
目标设备类别 (dst_category) PanOSDestinationDeviceCategory dst_category target.asset.category
目标设备配置文件 (dst_profile) PanOSDestinationDeviceProfile dst_profile

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

目标设备型号 (dst_model) PanOSDestinationDeviceModel dst_model target.asset.hardware.model
目标设备供应商 (dst_vendor) PanOSDestinationDeviceVendor dst_vendor target.asset.hardware.manufacturer
目标设备操作系统系列 (dst_osfamily) PanOSDestinationDeviceOSFamily dst_osfamily target.platform
目标设备操作系统版本 (dst_osversion) PanOSDestinationDeviceOSVersion target.platform_version
目标主机名 (dst_host) PanOSDestinationDeviceHost target.hostname
目标 MAC 地址 (dst_mac) PanOSDestinationDeviceMac target.mac
序列号 (seqno) PanOSLogTypeSeqNo metadata.product_log_id
操作标志 (actionflags) PanOSActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_1) DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_2) DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_3) DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_4) DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虚拟系统名称 (vsys_name) intermediary.asset.attribute.labels.key/value
设备名称 (device_name) intermediary.hostname
虚拟系统 ID (vsys_id) intermediary.resource.product_object_id
应用子类别 (subcategory_of_app) subcategory_of_app additional.fields.key 和 additional.fields.value.string_value
应用类别 (category_of_app) category_of_app additional.fields.key 和 additional.fields.value.string_value
应用技术 (technology_of_app) technology_of_app additional.fields.key 和 additional.fields.value.string_value
应用风险 (risk_of_app) security_result.severity
应用特征 (characteristic_of_app) characteristic_of_app additional.fields.key 和 additional.fields.value.string_value
应用容器 (container_of_app) container_of_app additional.fields.key 和 additional.fields.value.string_value
应用 SaaS (is_saas_of_app) is_saas_of_app additional.fields.key 和 additional.fields.value.string_value
应用受制裁状态 (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key 和 additional.fields.value.string_value
严重程度(严重程度) number-of-severity(header) security_result.severity 和 security_result.severity_details

隧道

下表列出了隧道日志类型的日志字段及其对应的 UDM 字段。

CSV 字段 CEF 字段 LEEF 字段 Google Security Operations 标签键 UDM 字段
接收时间(receive_time 或 cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp(如果缺少“生成时间”)

序列号(序列) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
类型(类型) type(标头) metadata.product_event_type
威胁/内容类型(子类型) 子类型(标头) 子类型 metadata.product_event_type
生成时间(time_generated 或 cef-formatted-time_generated) metadata.event_timestamp
来源地址 (src) src src principal.ip
目的地地址 (dst) dst dst target.ip
NAT 源 IP (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
NAT 目标 IP (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
规则名称(规则) cs1 RuleName security_result.rule_name
源用户 (srcuser) suser SourceUser / usrName principal.user.userid
目标用户 (dstuser) duser DestinationUser target.user.userid
应用(应用) 应用 应用 network.application_protocol
虚拟系统 (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
来源可用区(从) cs4 SourceZone from

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目标可用区(到) cs5 DestinationZone

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

入站接口 (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

出站接口 (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

日志操作 (logset) cs6 LogForwardingProfile logset additional.fields.key 和 additional.fields.value.string_value
会话 ID (sessionid) cn1 SessionID network.session_id
重复次数 (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key 和 additional.fields.value.string_value
来源端口 (sport) spt srcPort principal.port
目标端口 (dport) dpt dstPort target.port
NAT 源端口 (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
NAT 目标端口 (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
标志 (flags) flexString1 标志 标志 additional.fields.key 和 additional.fields.value.string_value
IP 协议 (proto) proto proto network.ip_protocol
操作(操作) act 操作 security_result.action_details

security_result.action

严重程度(严重程度) number-of-severity(header) security_result.severity 和 security_result.severity_details
序列号 (seqno) externalId 序列 metadata.product_log_id
操作标志 (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
来源位置 (srcloc) principal.location.country_or_region
目的地位置 (dstloc) target.location.country_or_region
设备组层次结构 (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虚拟系统名称 (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
设备名称 (device_name) dvchost DeviceName intermediary.hostname
隧道 ID (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key 和 additional.fields.value.string_value
监控标记 (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key 和 additional.fields.value.string_value
父会话 ID (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
父开始时间 (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key 和 additional.fields.value.string_value
隧道类型(隧道) cs2 TunnelType 隧道 additional.fields.key 和 additional.fields.value.string_value
字节(字节) flexNumber1 totalBytes 字节 additional.fields.key 和 additional.fields.value.string_value
发送的字节数 (bytes_sent) srcBytes network.sent_bytes
接收的字节数 (bytes_received) out dstBytes network.received_bytes
数据包(数据包) cn2 totalPackets 数据包 additional.fields.key 和 additional.fields.value.string_value
发送的数据包数 (pkts_sent) PanOSPacketsSent srcPackets pkts_sent network.sent_packets
接收的数据包数量 (pkts_received) PanOSPacketsReceived dstPackets pkts_received network.received_packets
最大封装 (max_encap) flexNumber2 MaximumEncapsulation max_encap additional.fields.key 和 additional.fields.value.string_value
未知协议 (unknown_proto) cfp1 UnknownProtocol unknown_proto additional.fields.key 和 additional.fields.value.string_value
严格检查 (strict_check) cfp2 StrictChecking strict_check additional.fields.key 和 additional.fields.value.string_value
隧道 fragment (tunnel_fragment) PanOSTunnelFragment TunnelFragment tunnel_fragment additional.fields.key 和 additional.fields.value.string_value
创建的会话数 (sessions_created) cfp3 SessionsCreated sessions_created additional.fields.key 和 additional.fields.value.string_value
关闭的会话数 (sessions_closed) cfp4 SessionsClosed sessions_closed additional.fields.key 和 additional.fields.value.string_value
会话结束原因 (session_end_reason) 原因 SessionEndReason security_result.summary
操作来源 (action_source) ActionSource action_source additional.fields.key 和 additional.fields.value.string_value
开始时间(开始) startTime 开始 additional.fields.key 和 additional.fields.value.string_value
已用时间(已用) cn3 ElapsedTime 已用时间 network.session_duration.seconds
隧道检查规则 (tunnel_insp_rule) PanOSTunneInspectionRule security_result.rule_name = "Tunnel Inspection Rule: %{PanOSTunnelInspectionRule}"
远程用户 IP (remote_user_ip) PanOSRmtUserIP principal.ip
远程用户 ID (remote_user_id) PanOSRmtUserID remote_user_id principal.user.userid
安全规则 UUID (rule_uuid) PanOSRuleUUID security_result.rule_id
PCAP ID (pcap_id) PanOSPcapID pcap_id additional.fields.key 和 additional.fields.value.string_value
动态用户组名称 (dynusergroup_name) PanDynamicUsrgrp principal.group.group_display_name
来源外部动态列表 (src_edl) PanOSSourceEDL src_edl

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目标外部动态列表 (dst_edl) PanOSDestinationEDL dst_edl

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

高分辨率时间戳(high_res 时间戳) PanOSTimeGeneratedHighResolution additional.fields.key 和 additional.fields.value.string_value
切片区分符 (nssai_sd) nssai_sd additional.fields.key 和 additional.fields.value.string_value
切片服务类型 (nssai_sd) nssai_sd1 additional.fields.key 和 additional.fields.value.string_value
PDU 会话 ID (pdu_session_id) pdu_session_id additional.fields.key 和 additional.fields.value.string_value
应用子类别 (subcategory_of_app) subcategory_of_app additional.fields.key 和 additional.fields.value.string_value
应用类别 (category_of_app) category_of_app additional.fields.key 和 additional.fields.value.string_value
应用技术 (technology_of_app) technology_of_app additional.fields.key 和 additional.fields.value.string_value
应用风险 (risk_of_app) risk_of_app additional.fields.key 和 additional.fields.value.string_value
应用特征 (characteristic_of_app) characteristic_of_app additional.fields.key 和 additional.fields.value.string_value
应用容器 (container_of_app) container_of_app additional.fields.key 和 additional.fields.value.string_value
应用 SaaS (is_saas_of_app) is_saas_of_app additional.fields.key 和 additional.fields.value.string_value
隧道应用 (tunneled_app) additional.fields.key 和 additional.fields.value.string_value
已分流(已分流) additional.fields.key 和 additional.fields.value.string_value
流量类型 (flow_type) additional.fields.key 和 additional.fields.value.string_value
集群名称 (cluster_name)

principal.resource.name

应用受制裁状态 (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key 和 additional.fields.value.string_value

身份验证

下表列出了身份验证日志类型的日志字段及其对应的 UDM 字段。

CSV 字段 CEF 字段 LEEF 字段 Google Security Operations 标签键 UDM 字段
接收时间(receive_time 或 cef-formatted-receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp(如果缺少“生成时间”)

序列号(序列) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
类型(类型) type(标头) metadata.product_event_type
威胁/内容类型(子类型) 子类型(标头) 子类型 metadata.product_event_type
生成时间(time_generated 或 cef-formatted-time_generated) metadata.event_timestamp
虚拟系统 (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
来源 IP (ip) src src principal.ip
用户 (user) duser usrName target.user.userid
规范化用户 (normalize_user) cs2 NormalizeUser target.user.user_display_name
对象(对象) fname ObjectName object target.resource.name
身份验证政策 (authpolicy) cs4 AuthPolicy authpolicy additional.fields.key 和 additional.fields.value.string_value
重复次数 (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key 和 additional.fields.value.string_value
身份验证 ID (authid) cn2 AuthenticationID authid additional.fields.key 和 additional.fields.value.string_value
供应商 (vendor) flexString2 供应商 供应商 additional.fields.key 和 additional.fields.value.string_value
日志操作 (logset) cs6 LogForwardingProfile logset additional.fields.key 和 additional.fields.value.string_value
服务器配置文件 (serverprofile) cs1 ServerProfile serverprofile additional.fields.key 和 additional.fields.value.string_value
说明(降序) PanOSDesc AdditionalAuthInfo security_result.description
客户端类型 (clienttype) cs5 ClientType clienttype additional.fields.key 和 additional.fields.value.string_value
事件类型(事件) 消息 消息 extensions.auth.auth_details
Factor Number (factorno) cn1 FactorNumber factorno additional.fields.key 和 additional.fields.value.string_value
序列号 (seqno) externalId 序列 metadata.product_log_id
操作标志 (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虚拟系统名称 (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
设备名称 (device_name) dvchost DeviceName intermediary.hostname
虚拟系统 ID (vsys_id) intermediary.resource.product_object_id
身份验证协议 (authproto) authproto additional.fields.key 和 additional.fields.value.string_value
规则的 UUID (rule_uuid) PanOSRuleUUID/RuleUUID security_result.rule_id
高分辨率时间戳 (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key 和 additional.fields.value.string_value
来源设备类别 (src_category) PanOSSourceDeviceCategory src_category principal.asset.category
源设备配置文件 (src_profile) PanOSSourceDeviceProfile src_profile

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

源设备型号 (src_model) PanOSSourceDeviceModel src_model principal.asset.hardware.model
源设备供应商 (src_vendor) PanOSSourceDeviceVendor src_vendor principal.asset.hardware.manufacturer
源设备操作系统系列 (src_osfamily) PanOSSourceDeviceOSFamily

principal.asset.platform_software.platform

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

源设备操作系统版本 (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
来源主机名 (src_host) PanOSSourceHostname principal.hostname
源 MAC 地址 (src_mac) PanOSSourceMac principal.asset.mac
地区(区域) PanOSTrafficOriginRegion principal.location.country_or_region
用户代理 (user_agent) PanOSHTTPUserAgent network.http.user_agent
会话 ID(sessionid) PanOSTrafficSessionID network.session_id
严重程度(严重程度) number-of-severity(header) security_result.severity 和 security_result.severity_details
集群名称 (cluster_name) principal.resource.name

网址

下表列出了网址日志类型的日志字段及其对应的 UDM 字段。

CSV 字段 CEF 字段 LEEF 字段 Google Security Operations 标签键 UDM 字段
接收时间(采用 CEF 格式的 receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp(如果缺少“生成时间”)

序列号(序列) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
类型(类型) type(标头) metadata.product_event_type
威胁/内容类型(子类型) 子类型(标头) 子类型 metadata.product_event_type
生成时间 metadata.event_timestamp
来源地址 (src) src src principal.ip
目的地地址 (dst) dst dst target.ip
NAT 源 IP (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
NAT 目标 IP (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
规则(规则) cs1 RuleName security_result.rule_name
源用户 (srcuser) suser SourceUser principal.user.userid
目标用户 (dstuser) duser DestinationUser target.user.userid
应用(应用) 应用 应用 network.application_protocol
虚拟系统 (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
来源可用区(从) cs4 SourceZone from

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目标可用区(到) cs5 DestinationZone

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

入站接口 (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

出站接口 (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

日志操作 (logset) cs6 LogForwardingProfile logset additional.fields.key 和 additional.fields.value.string_value
记录的时间 time_logged additional.fields.key 和 additional.fields.value.string_value
会话 ID (sessionid) cn1 SessionID network.session_id
重复次数 (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key 和 additional.fields.value.string_value
来源端口 (sport) spt srcPort principal.port
目标端口 (dport) dpt dstPort target.port
NAT 源端口 (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
NAT 目标端口 (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
标志 (flags) flexString1 标志 标志 additional.fields.key 和 additional.fields.value.string_value
IP 协议 (proto) proto proto network.ip_protocol
操作(操作) act 操作 security_result.action_details

security_result.action

网址/文件名(其他) 其他 target.file.names

target.url

威胁/内容名称 (threatid) ThreatID security_result.threat_id
类别(category) cs2 URLCategory category security_result.category_details
严重程度(严重程度) number-of-severity(标头) 严重程度 security_result.severity

security_result.severity_details

方向(direction) flexString2 方向 network.direction
序列号 (seqno) externalId 序列 metadata.product_log_id
操作标志 (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
来源国家/地区 (srcloc) SourceLocation principal.location.country_or_region
目的地国家/地区 (dstloc) DestinationLocation target.location.country_or_region
contenttype (contenttype) requestContext ContentType contenttype additional.fields.key 和 additional.fields.value.string_value
pcap_id (pcap_id) fileId PCAP_ID pcap_id additional.fields.key 和 additional.fields.value.string_value
filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
云 (cloud) Cloud additional.fields.key 和 additional.fields.value.string_value
url_idx (url_idx) URLIndex url_idx additional.fields.key 和 additional.fields.value.string_value
user_agent (user_agent) requestClientApplication UserAgent network.http.user_agent
filetype (filetype) target.file.mime_type
xff (xff) PanOSXForwarderfor identSrc xff principal.ip
referer (referer) PanOSReferer Referer network.http.referral_url
发送者(发送者) network.email.from
主题(主题) 主题 network.email.subject
收件人(收件人) network.email.to
reportid (reportid) reportid additional.fields.key 和 additional.fields.value.string_value
DG 层次结构级别 1 (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
DG 层次结构级别 2 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
DG 层次结构级别 3 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
DG 层次结构级别 4 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虚拟系统名称 (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
设备名称 (device_name) dvchost DeviceName intermediary.hostname
file_url (file_url) target.url
源虚拟机的 UUID (src_uuid) SrcUUID principal.asset.product_object_id
目标虚拟机的 UUID (dst_uuid) DstUUID target.asset.product_object_id
http_method (http_method) requestMethod RequestMethod network.http.method
隧道 ID/IMSI (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key 和 additional.fields.value.string_value
监控标记/IMEI (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key 和 additional.fields.value.string_value
父会话 ID (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
父会话开始时间 (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key 和 additional.fields.value.string_value
隧道 (tunnel) PanOSTunnelType TunnelType 隧道 additional.fields.key 和 additional.fields.value.string_value
thr_category (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
contentver(contentver) PanOSContentVer ContentVer contentver additional.fields.key 和 additional.fields.value.string_value
sig_flags (sig_flags) sig_flags additional.fields.key 和 additional.fields.value.string_value
SCTP 关联 ID (assoc_id) PanOSAssocID assoc_id additional.fields.key 和 additional.fields.value.string_value
载荷协议 ID (ppid) PanOSPPID ppid additional.fields.key 和 additional.fields.value.string_value
http_headers (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
网址类别列表 (url_category_list) PanOSURLCatList url_category_list additional.fields.key 和 additional.fields.value.string_value
规则的 UUID (rule_uuid) PanOSRuleUUID rule_uuid security_result.rule_id
HTTP/2 连接 (http2_connection) PanOSHTTP2Con http2_connection network.application_protocol_version
dynusergroup_name (dynusergroup_name) PanDynamicUsrgrp dynusergroup_name additional.fields.key 和 additional.fields.value.string_value
XFF 地址 (xff_ip) PanXFFIP principal.ip
来源设备类别 (src_category) PanSrcDeviceCat src_category principal.asset.category
源设备配置文件 (src_profile) PanSrcDeviceProf src_profile

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

源设备型号 (src_model) PanSrcDeviceModel src_model principal.asset.hardware.model
源设备供应商 (src_vendor) PanSrcDeviceVendor src_vendor principal.asset.hardware.manufacturer
源设备操作系统系列 (src_osfamily) PanSrcDeviceOS principal.platform
源设备操作系统版本 (src_osversion) PanSrcDeviceOSv principal.platform_version
来源主机名 (src_host) PanSrcHostname src_host principal.hostname
源 MAC 地址 (src_mac) PanSrcMac principal.mac
目标设备类别 (dst_category) PanDstDeviceCat dst_category target.asset.category
目标设备配置文件 (dst_profile) PanDstDeviceProf dst_profile

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

目标设备型号 (dst_model) PanDstDeviceModel dst_model target.asset.hardware.model
目标设备供应商 (dst_vendor) PanDstDeviceVendor dst_vendor target.asset.hardware.manufacturer
目标设备操作系统系列 (dst_osfamily) PanDstDeviceOS target.platform
目标设备操作系统版本 (dst_osversion) PanDstDeviceOSv target.platform_version
目标主机名 (dst_host) PanPODNamespace target.hostname
目标 MAC 地址 (dst_mac) PanDstMac target.mac
容器 ID (container_id) PanContainerName container_id intermediary.resource.product_object_id
POD 命名空间 (pod_namespace) PanPODNamespace pod_namespace target.resource.attribute.labels.key/value
POD 名称 (pod_name) PanPODName pod_name target.resource.name
来源外部动态列表 (src_edl) PanSrcEDL src_edl

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目标外部动态列表 (dst_edl) PanDstEDL dst_edl

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

主机 ID (hostid) PanGPHostID hostid principal.asset.asset_id
序列号 (serialnumber) PanEPSerial principal.asset.hardware.serial_number
domain_edl (domain_edl) PanDomainEDL domain_edl additional.fields.key 和 additional.fields.value.string_value
源动态地址组 (src_dag) PanSrcDAG principal.group.group_display_name
目标动态地址组 (dst_dag) PanDstDAG target.group.group_display_name
partial_hash(partial_hash) PanPartialHash partial_hash additional.fields.key 和 additional.fields.value.string_value
高分辨率时间戳 (high_res_timestamp) PanTimeHighRes additional.fields.key 和 additional.fields.value.string_value
原因 (reason) PanReasonFilteringAction 原因 security_result.summary
对齐方式(对齐方式) PanJustification 对齐方式 additional.fields.key 和 additional.fields.value.string_value
nssai_sst (nssai_sst) PanASServiceType nssai_sst additional.fields.key 和 additional.fields.value.string_value
应用子类别 (subcategory_of_app) subcategory_of_app additional.fields.key 和 additional.fields.value.string_value
应用类别 (category_of_app) category_of_app additional.fields.key 和 additional.fields.value.string_value
应用的技术 (technology_of_app) technology_of_app additional.fields.key 和 additional.fields.value.string_value
应用风险 (risk_of_app) risk_of_app additional.fields.key 和 additional.fields.value.string_value
应用的特征 (characteristic_of_app) characteristic_of_app additional.fields.key 和 additional.fields.value.string_value
应用容器 (container_of_app) container_of_app additional.fields.key 和 additional.fields.value.string_value
隧道应用 (tunneled_app) tunneled_app additional.fields.key 和 additional.fields.value.string_value
应用的 SaaS (is_saas_of_app) is_saas_of_app additional.fields.key 和 additional.fields.value.string_value
应用的受制裁状态 (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key 和 additional.fields.value.string_value
云报告 ID (cloud_reportid) additional.fields.key 和 additional.fields.value.string_value
集群名称 (cluster_name)

principal.resource.name

流量类型 (flow_type) additional.fields.key 和 additional.fields.value.string_value

数据

下表列出了数据日志类型的日志字段及其对应的 UDM 字段。

CSV 字段 CEF 字段 LEEF 字段 Google Security Operations 标签键 UDM 字段
接收时间(采用 CEF 格式的 receive_time) rt devTime metadata.collected_timestamp,

metadata.event_timestamp(如果缺少“生成时间”)

序列号(序列) deviceExternalId SerialNumber intermediary.asset.hardware.serial_number
类型(类型) type(标头) metadata.product_event_type
威胁/内容类型(子类型) 子类型(标头) 子类型 metadata.product_event_type
生成时间 metadata.event_timestamp
来源地址 (src) src src principal.ip
目的地地址 (dst) dst dst target.ip
NAT 源 IP (natsrc) sourceTranslatedAddress srcPostNAT principal.nat_ip
NAT 目标 IP (natdst) destinationTranslatedAddress dstPostNAT target.nat_ip
规则(规则) cs1 RuleName security_result.rule_name
源用户 (srcuser) suser SourceUser principal.user.userid
目标用户 (dstuser) duser DestinationUser target.user.userid
应用(应用) 应用 应用 network.application_protocol
虚拟系统 (vsys) cs3 VirtualSystem vsys intermediary.asset.attribute.labels.key/value
来源可用区(从) cs4 SourceZone from

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目标可用区(到) cs5 DestinationZone

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

入站接口 (inbound_if) deviceInboundInterface IngressInterface inbound_if

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

出站接口 (outbound_if) deviceOutboundInterface EgressInterface outbound_if

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

日志操作 (logset) cs6 LogForwardingProfile logset additional.fields.key 和 additional.fields.value.string_value
记录的时间 time_logged additional.fields.key 和 additional.fields.value.string_value
会话 ID (sessionid) cn1 SessionID network.session_id
重复次数 (repeatcnt) cnt RepeatCount repeatcnt additional.fields.key 和 additional.fields.value.string_value
来源端口 (sport) spt srcPort principal.port
目标端口 (dport) dpt dstPort target.port
NAT 源端口 (natsport) sourceTranslatedPort srcPostNATPort principal.nat_port
NAT 目标端口 (natdport) destinationTranslatedPort dstPostNATPort target.nat_port
标志 (flags) flexString1 标志 标志 additional.fields.key 和 additional.fields.value.string_value
IP 协议 (proto) proto proto network.ip_protocol
操作(操作) act 操作 security_result.action_details

security_result.action

网址/文件名(其他) 其他 target.file.names

target.url

威胁/内容名称 (threatid) ThreatID security_result.threat_id
类别(category) cs2 URLCategory category security_result.category_details
严重程度(严重程度) number-of-severity(标头) 严重程度 security_result.severity

security_result.severity_details

方向(direction) flexString2 方向 network.direction
序列号 (seqno) externalId 序列 metadata.product_log_id
操作标志 (actionflags) PanOSActionFlags ActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
来源国家/地区 (srcloc) SourceLocation principal.location.country_or_region
目的地国家/地区 (dstloc) DestinationLocation target.location.country_or_region
contenttype (contenttype) ContentType contenttype additional.fields.key 和 additional.fields.value.string_value
pcap_id (pcap_id) fileId PCAP_ID pcap_id additional.fields.key 和 additional.fields.value.string_value
filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
云 (cloud) Cloud additional.fields.key 和 additional.fields.value.string_value
url_idx (url_idx) URLIndex url_idx additional.fields.key 和 additional.fields.value.string_value
user_agent (user_agent) network.http.user_agent
filetype (filetype) target.file.mime_type
xff (xff) xff principal.ip
referer (referer) network.http.referral_url
发送者(发送者) network.email.from
主题(主题) 主题 network.email.subject
收件人(收件人) network.email.to
reportid (reportid) reportid additional.fields.key 和 additional.fields.value.string_value
DG 层次结构级别 1 (dg_hier_level_1) PanOSDGl1 DeviceGroupHierarchyL1 dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
DG 层次结构级别 2 (dg_hier_level_2) PanOSDGl2 DeviceGroupHierarchyL2 dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
DG 层次结构级别 3 (dg_hier_level_3) PanOSDGl3 DeviceGroupHierarchyL3 dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
DG 层次结构级别 4 (dg_hier_level_4) PanOSDGl4 DeviceGroupHierarchyL4 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虚拟系统名称 (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels.key/value
设备名称 (device_name) dvchost DeviceName intermediary.hostname
file_url (file_url) target.url
源虚拟机的 UUID (src_uuid) SrcUUID principal.asset.product_object_id
目标虚拟机的 UUID (dst_uuid) DstUUID target.asset.product_object_id
http_method (http_method) RequestMethod network.http.method
隧道 ID/IMSI (tunnelid) PanOSTunnelID TunnelID tunnelid additional.fields.key 和 additional.fields.value.string_value
监控标记/IMEI (monitortag) PanOSMonitorTag MonitorTag monitortag additional.fields.key 和 additional.fields.value.string_value
父会话 ID (parent_session_id) PanOSParentSessionID ParentSessionID parent_session_id network.parent_session_id
父会话开始时间 (parent_start_time) PanOSParentStartTime ParentStartTime parent_start_time additional.fields.key 和 additional.fields.value.string_value
隧道 (tunnel) PanOSTunnelType TunnelType 隧道 additional.fields.key 和 additional.fields.value.string_value
thr_category (thr_category) PanOSThreatCategory ThreatCategory thr_category security_result.detection_fields.key/value
contentver(contentver) PanOSContentVer ContentVer contentver additional.fields.key 和 additional.fields.value.string_value
sig_flags (sig_flags) sig_flags additional.fields.key 和 additional.fields.value.string_value
SCTP 关联 ID (assoc_id) PanOSAssocID assoc_id additional.fields.key 和 additional.fields.value.string_value
载荷协议 ID (ppid) PanOSPPID ppid additional.fields.key 和 additional.fields.value.string_value
http_headers (http_headers) PanOSHTTPHeader http_headers target.url.last_http_response_headers
网址类别列表 (url_category_list) url_category_list additional.fields.key 和 additional.fields.value.string_value
规则的 UUID (rule_uuid) PanOSRuleUUID rule_uuid security_result.rule_id
HTTP/2 连接 (http2_connection) http2_connection network.application_protocol_version
dynusergroup_name (dynusergroup_name) dynusergroup_name

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

XFF 地址 (xff_ip) principal.ip
来源设备类别 (src_category) src_category principal.asset.category
源设备配置文件 (src_profile) src_profile

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

源设备型号 (src_model) src_model principal.asset.hardware.model
源设备供应商 (src_vendor) src_vendor principal.asset.hardware.manufacturer
源设备操作系统系列 (src_osfamily) principal.platform
源设备操作系统版本 (src_osversion) principal.platform_version
来源主机名 (src_host) src_host principal.hostname
源 MAC 地址 (src_mac) principal.mac
目标设备类别 (dst_category) dst_category target.asset.category
目标设备配置文件 (dst_profile) dst_profile

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

目标设备型号 (dst_model) dst_model target.asset.hardware.model
目标设备供应商 (dst_vendor) dst_vendor target.asset.hardware.manufacturer
目标设备操作系统系列 (dst_osfamily) target.platform
目标设备操作系统版本 (dst_osversion) target.platform_version
目标主机名 (dst_host) target.hostname
目标 MAC 地址 (dst_mac) target.mac
容器 ID (container_id) container_id intermediary.resource.product_object_id
POD 命名空间 (pod_namespace) pod_namespace target.resource.attribute.labels.key/value
POD 名称 (pod_name) pod_name target.resource.name
来源外部动态列表 (src_edl) src_edl

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目标外部动态列表 (dst_edl) dst_edl

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

主机 ID (hostid) hostid principal.asset.asset_id
序列号 (serialnumber) principal.asset.hardware.serial_number
domain_edl (domain_edl) domain_edl additional.fields.key 和 additional.fields.value.string_value
源动态地址组 (src_dag) principal.group.group_display_name
目标动态地址组 (dst_dag) target.group.group_display_name
partial_hash(partial_hash) partial_hash additional.fields.key 和 additional.fields.value.string_value
高分辨率时间戳 (high_res_timestamp) additional.fields.key 和 additional.fields.value.string_value
原因 (reason) 原因 security_result.summary
对齐方式(对齐方式) 对齐方式 additional.fields.key 和 additional.fields.value.string_value
nssai_sst (nssai_sst) nssai_sst additional.fields.key 和 additional.fields.value.string_value
应用子类别 (subcategory_of_app) subcategory_of_app additional.fields.key 和 additional.fields.value.string_value
应用类别 (category_of_app) category_of_app additional.fields.key 和 additional.fields.value.string_value
应用的技术 (technology_of_app) technology_of_app additional.fields.key 和 additional.fields.value.string_value
应用风险 (risk_of_app) risk_of_app additional.fields.key 和 additional.fields.value.string_value
应用的特征 (characteristic_of_app) characteristic_of_app additional.fields.key 和 additional.fields.value.string_value
应用容器 (container_of_app) container_of_app additional.fields.key 和 additional.fields.value.string_value
隧道应用 (tunneled_app) tunneled_app additional.fields.key 和 additional.fields.value.string_value
应用的 SaaS (is_saas_of_app) is_saas_of_app additional.fields.key 和 additional.fields.value.string_value
应用的受制裁状态 (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key 和 additional.fields.value.string_value
云报告 ID (cloud_reportid) additional.fields.key 和 additional.fields.value.string_value
集群名称 (cluster_name) principal.resource.name
流量类型 (flow_type) additional.fields.key 和 additional.fields.value.string_value

GlobalProtect

下表列出了 GlobalProtect 日志类型的日志字段及其对应的 UDM 字段。

CSV 字段 CEF 字段 LEEF 字段 Google Security Operations 标签键 UDM 字段
接收时间 (receive_time) rt received_time metadata.event_timestamp
序列号(序列) PanOSDeviceSN intermediary_asset_hardware_serial_number intermediary.asset.hardware.serial_number
类型(类型) type(标头) metadata.product_event_type
威胁/内容类型(子类型) 子类型(标头) 子类型 metadata.product_event_type
生成时间 (time_generated) PanOSLogTimeStamp generated_timestamp metadata.event_timestamp
虚拟系统 (vsys) PanOSVirtualSystem vsys intermediary.asset.attribute.labels.key/value
活动 ID (eventid) PanOSEventID event_id additional.fields.key 和 additional.fields.value.string_value
阶段 (stage) PanOSStage 阶段 additional.fields.key 和 additional.fields.value.string_value
身份验证方法 (auth_method) PanOSAuthMethod extension_auth_auth_details extensions.auth.auth_details
隧道类型 (tunnel_type) PanOSTunnelType 隧道 additional.fields.key 和 additional.fields.value.string_value
源用户 (srcuser) PanOSSourceUserName src_user principal.user.email_address

principal.user.userid

principal.administrative_domain

来源区域 (srcregion) PanOSSourceRegion src_region principal.location.country_or_region
机器名称 (machinename) PanOSEndpointDeviceName machine_name principal.hostname
公共 IP (public_ip) PanOSPublicIPv4 principal.nat_ip
公共 IPv6 (public_ipv6) PanOSPublicIPv6 principal.nat_ip
专用 IP (private_ip) PanOSPrivateIPv4 principal.ip
专用 IPv6 (private_ipv6) PanOSPrivateIPv6 principal.ip
主机 ID (hostid) PanOSHostID hostid principal.asset.asset_id
序列号 (serialnumber) PanOSDeviceSN principal.asset.hardware.serial_number
客户端版本 (client_ver) PanOSGlobalProtectClientVersion client_ver additional.fields.key 和 additional.fields.value.string_value
客户端操作系统 (client_os) PanOSEndpointOSType principal.platform
客户端操作系统版本 (client_os_ver) PanOSEndpointOSVersion principal.platform_version
重复次数 (repeatcnt) PanOSCountOfRepeats repeatcnt additional.fields.key 和 additional.fields.value.string_value
原因 (reason) PanOSQuarantineReason security_result.summary
错误(错误) PanOSConnectionError 错误 security_result.description
说明(不透明) PanOSDescription security_result.description
状态(状态) PanOSEventStatus 状态 additional.fields.key 和 additional.fields.value.string_value
位置(位置) PanOSGPGatewayLocation target.location.country_or_region
登录时长 (login_duration) PanOSLoginDuration network.session_duration
连接方法 (connect_method) PanOSConnectionMethod connect_method additional.fields.key 和 additional.fields.value.string_value
错误代码 (error_code) PanOSConnectionErrorID error_code additional.fields.key 和 additional.fields.value.string_value
传送门(传送门) PanOSPortal 门户 additional.fields.key 和 additional.fields.value.string_value
序列号 (seqno) PanOSSequenceNo metadata.product_log_id
操作标志 (actionflags) PanOSActionFlags actionflags additional.fields.key 和 additional.fields.value.string_value
高分辨率时间戳 (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key 和 additional.fields.value.string_value
网关选择方法 (selection_type) PanOSGatewaySelectionType selection_type additional.fields.key 和 additional.fields.value.string_value
SSL 响应时间 (response_time) PanOSSSLResponseTime response_time additional.fields.key 和 additional.fields.value.string_value
网关优先级 (priority) PanOSGatewayPriority 优先级 additional.fields.key 和 additional.fields.value.string_value
尝试性网关(attempted_gateways) PanOSAttemptedGateways attempted_gateways additional.fields.key 和 additional.fields.value.string_value
网关名称(网关) PanOSAttemptedGateways 网关 target.resource.name
设备组层次结构 (dg_hier_level_1) dg_hier_level_1 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_2) dg_hier_level_2 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_3) dg_hier_level_3 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构 (dg_hier_level_4) dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
虚拟系统名称 (vsys_name) intermediary.asset.attribute.labels.key/value
设备名称 (device_name) intermediary.hostname
虚拟系统 ID (vsys_id) intermediary.resource.product_object_id
严重程度(严重程度) number-of-severity(header) security_result.severity 和 security_result.severity_details
集群名称 (cluster_name) principal.resource.name

相关性

下表列出了关联日志类型的日志字段及其对应的 UDM 字段。

CSV 字段 CEF 字段 LEEF 字段 Google Security Operations 标签键 UDM 字段
生成时间(time_generated 或 cef-formatted-time_generated) startTime generated_timestamp metadata.event_timestamp
来源地址 (src) src principal.ip
源用户 (srcuser) SourceUser / usrName principal.user.userid
虚拟系统 (vsys) VirtualSystem vsys intermediary.asset.attribute.labels.key/value
类别(category) security_result.category_details
严重程度(严重程度) 严重程度 security_result.severity 和 security_result.severity_details
设备组层次结构级别 1 DeviceGroupHierarchyL1 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构级别 2 DeviceGroupHierarchyL2 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构级别 3 DeviceGroupHierarchyL3 additional.fields.key 和 additional.fields.value.string_value
设备组层次结构级别 4 DeviceGroupHierarchyL4 additional.fields.key 和 additional.fields.value.string_value
虚拟系统名称 (vsys_name) vSrcName intermediary.asset.attribute.labels.key/value
设备名称 (device_name) DeviceName intermediary.hostname
虚拟系统 ID (vsys_id) VirtualSystemID intermediary.resource.product_object_id
对象名称 (objectname) ObjectName target.resource.name
对象 ID (object_id) ObjectID target.resource.product_object_id
证据(证据) 消息 security_result.summary

GTP

下表列出了 gtp 日志类型的日志字段及其对应的 UDM 字段。

CSV 字段 CEF 字段 LEEF 字段 Google Security Operations 标签键 UDM 字段
接收时间(receive_time 或 cef-formatted-receive_time) metadata.collected_timestamp,

metadata.event_timestamp(如果缺少“生成时间”)

序列号(序列) intermediary.asset.hardware.serial_number
类型(type) metadata.product_event_type
威胁/内容类型(子类型) metadata.product_event_type
生成时间(time_generated 或 cef-formatted-time_generated) metadata.event_timestamp
来源地址 (src) principal.ip
目的地地址 (dst) target.ip
规则名称(规则) security_result.rule_name
应用(应用) network.application_protocol
虚拟系统 (vsys) vsys intermediary.asset.attribute.labels.key/value
来源可用区(从) from

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

目标可用区(到)

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

入站接口 (inbound_if) inbound_if

principal.labels.key 和 principal.labels.value

additional.fields.key 和 additional.fields.value.string_value

出站接口 (outbound_if) outbound_if

target.labels.key 和 target.labels.value

additional.fields.key 和 additional.fields.value.string_value

日志操作 (logset) logset additional.fields.key 和 additional.fields.value.string_value
会话 ID (sessionid) network.session_id
来源端口 (sport) principal.port
目标端口 (dport) target.port
IP 协议 (proto) network.ip_protocol
操作(操作) security_result.action_details

security_result.action

GTP 事件类型 (event_type) gtp_event_type additional.fields.key 和 additional.fields.value.string_value
MSISDN (msisdn) msisdn additional.fields.key 和 additional.fields.value.string_value
接入点名称 (APN) apn additional.fields.key 和 additional.fields.value.string_value
无线接入技术 (RAT) rat additional.fields.key 和 additional.fields.value.string_value
GTP 消息类型 (msg_type) gtp_msg_type additional.fields.key 和 additional.fields.value.string_value
结束 IP 地址 (end_ip_adr) principal.ip
隧道端点标识符 1 (teid1) teid1 additional.fields.key 和 additional.fields.value.string_value
隧道端点标识符 2 (teid2) teid2 additional.fields.key 和 additional.fields.value.string_value
GTP 接口 (gtp_interface) gtp_interface additional.fields.key 和 additional.fields.value.string_value
GTP 原因 (cause_code) gtp_cause_code additional.fields.key 和 additional.fields.value.string_value
严重程度(严重程度) security_result.severity 和 security_result.severity_details
服务网络 MCC (mcc) mcc additional.fields.key 和 additional.fields.value.string_value
服务网络 MNC (mnc) mnc additional.fields.key 和 additional.fields.value.string_value
区号 (area_code) area_code additional.fields.key 和 additional.fields.value.string_value
小区 ID (cell_id) cell_id additional.fields.key 和 additional.fields.value.string_value
GTP 活动代码 (event_code) event_code additional.fields.key 和 additional.fields.value.string_value
来源位置 (srcloc) principal.location.country_or_region
目的地位置 (dstloc) target.location.country_or_region
隧道 ID/IMSI (imsi) tunnelid additional.fields.key 和 additional.fields.value.string_value
监控标记/IMEI (imei) monitortag additional.fields.key 和 additional.fields.value.string_value
开始时间(开始) 开始 additional.fields.key 和 additional.fields.value.string_value
已用时间(已用) network.session_duration.seconds
隧道检查规则隧道 (tunnel_insp_rule) tunnel_insp_rule security_result.detection_fields.key/value
远程用户 IP (remote_user_ip) principal.ip
远程用户 ID (remote_user_id) remote_user_id principal.user.userid
规则的 UUID (rule_uuid) security_result.rule_id
PCAP ID (pcap_id) pcap_id additional.fields.key 和 additional.fields.value.string_value
高分辨率时间戳 (high_res_timestamp) additional.fields.key 和 additional.fields.value.string_value
切片服务类型 (nsdsai_sst) nsdsai_sst additional.fields.key 和 additional.fields.value.string_value
Slice 区分器 (nsdsai_sd) nsdsai_sd additional.fields.key 和 additional.fields.value.string_value
应用子类别 (subcategory_of_app) subcategory_of_app additional.fields.key 和 additional.fields.value.string_value
应用类别 (category_of_app) category_of_app additional.fields.key 和 additional.fields.value.string_value
应用技术 (technology_of_app) technology_of_app additional.fields.key 和 additional.fields.value.string_value
应用风险 (risk_of_app) risk_of_app additional.fields.key 和 additional.fields.value.string_value
应用特征 (characteristic_of_app) characteristic_of_app additional.fields.key 和 additional.fields.value.string_value
应用容器 (container_of_app) container_of_app additional.fields.key 和 additional.fields.value.string_value
应用 SaaS (is_saas_of_app) is_saas_of_app additional.fields.key 和 additional.fields.value.string_value
应用受制裁状态 (sanctioned_state_of_app) sanctioned_state_of_app additional.fields.key 和 additional.fields.value.string_value

SCTP

CSV 字段 CEF 字段 LEEF 字段 Google Security Operations 标签键 UDM 字段
接收时间(receive_time 或 cef-formatted-receive_time) receive_time 或 cef-formatted-receive_time metadata.collected_timestamp
序列号(序列) serial intermediary.asset.hardware.serial_number
类型(type) 类型 metadata.product_event_type
生成时间(time_generated 或 cef-formatted-time_generated) time_generated 或 cef-formatted-time_generated metadata.event_timestamp
来源地址 (src) src principal.ip
目的地地址 (dst) dst target.ip
规则名称 (rule) 规则 security_result.rule_name
来源可用区(从) 来自 additional.fields.key 和 additional.fields.value.string_value
目标可用区(目的地) additional.fields.key 和 additional.fields.value.string_value
入站接口 (inbound_if) inbound_if additional.fields.key 和 additional.fields.value.string_value
出站接口 (outbound_if) outbound_if additional.fields.key 和 additional.fields.value.string_value
日志操作 (logset) logset additional.fields.key 和 additional.fields.value.string_value
会话 ID (sessionid) sessionid network.session_id
重复次数 (repeatcnt) repeatcnt additional.fields.key 和 additional.fields.value.string_value
来源端口 (sport) 体育 principal.port
目标端口 (dport) dport target.port
IP 协议 (proto) proto network.ip_protocol(枚举)
操作(操作) 操作 security_result.action_details
security_result.action
设备组层次结构(dg_hier_level_1 至 dg_hier_level_4) dg_hier_level_1 到 dg_hier_level_4 additional.fields.key 和 additional.fields.value.string_value
设备名称 (device_name) device_name intermediary.hostname
序列号 (seqno) seqno metadata.product_log_id
SCTP 关联 ID (assoc_id) assoc_id additional.fields.key 和 additional.fields.value.string_value
载荷协议 ID (ppid) ppid additional.fields.key 和 additional.fields.value.string_value
严重程度(严重程度) 和程度上减少 security_result.severity 和 security_result.severity_details
SCTP 分块类型 (sctp_chunk_type) sctp_chunk_type additional.fields.key 和 additional.fields.value.string_value
SCTP 事件类型 (sctp_event_type) sctp_event_type additional.fields.key 和 additional.fields.value.string_value
SCTP 验证标记 1 (verif_tag_1) verif_tag_1 additional.fields.key 和 additional.fields.value.string_value
SCTP 验证代码 2 (verif_tag_2) verif_tag_2 additional.fields.key 和 additional.fields.value.string_value
SCTP 原因代码 (sctp_cause_code) sctp_cause_code additional.fields.key 和 additional.fields.value.string_value
Diameter 应用 ID (diam_app_id) diam_app_id additional.fields.key 和 additional.fields.value.string_value
直径命令代码 (diam_cmd_code) diam_cmd_code additional.fields.key 和 additional.fields.value.string_value
Diameter AVP 代码 (diam_avp_code) diam_avp_code additional.fields.key 和 additional.fields.value.string_value
SCTP 数据流 ID (stream_id) stream_id additional.fields.key 和 additional.fields.value.string_value
SCTP 关联结束原因 (assoc_end_reason) assoc_end_reason additional.fields.key 和 additional.fields.value.string_value
操作码 (op_code) op_code additional.fields.key 和 additional.fields.value.string_value
SCCP 主叫方 SSN (sccp_calling_ssn) sccp_calling_ssn additional.fields.key 和 additional.fields.value.string_value
SCCP 主叫方全局标题 (sccp_calling_gt) sccp_calling_gt additional.fields.key 和 additional.fields.value.string_value
SCTP 过滤器 (sctp_filter) sctp_filter additional.fields.key 和 additional.fields.value.string_value
SCTP 块(块) additional.fields.key 和 additional.fields.value.string_value
发送的 SCTP 数据块数 (chunks_sent) chunks_sent additional.fields.key 和 additional.fields.value.string_value
接收到的 SCTP 数据块 (chunks_received) chunks_received additional.fields.key 和 additional.fields.value.string_value
数据包(数据包) 数据包 additional.fields.key 和 additional.fields.value.string_value
规则的 UUID (rule_uuid) rule_uuid security_result.rule_id
虚拟系统 (vsys) vsys intermediary.asset.attribute.labels.key/value
虚拟系统名称 (vsys_name) vsys_name intermediary.asset.attribute.labels.key/value
发送的数据包数 (pkts_sent) pkts_sent network.sent_packets
接收的数据包数量 (pkts_received) pkts_received network.received_packets

审核

CSV 字段 CEF 字段 LEEF 字段 Google Security Operations 标签键 UDM 字段
生成时间 metadata.event_timestamp
威胁/内容类型(子类型) metadata.product_event_type
事件 ID principal.application
对象 principal.user.userid
CLI 命令 principal.process.command_line
严重程度 security_result.severity
序列号 intermediary.asset.hardware.serial_number

字段映射参考信息:日志类型到 UDM 事件类型

下表列出了 Palo Alto Networks 防火墙日志类型及其对应的 UDM 事件类型。

日志类型 UDM 事件类型
流量 NETWORK_CONNECTION
威胁 NETWORK_CONNECTION
网址过滤 NETWORK_CONNECTION
WildFire NETWORK_CONNECTION

WildFire 提交日志是威胁日志类型的一个子类型,使用相同的 syslog 格式。

数据过滤 NETWORK_CONNECTION
隧道 NETWORK_CONNECTION
GTP NETWORK_CONNECTION
配置 SETTING_MODIFICATION/SETTING_CREATION/SETTING_DELETION/SETTING_UNCATEGORIZED

“Command (cmd)”字段的值决定了 UDM 事件类型映射。 如果 cmd 字段值为 add 或 clone,则设置 SETTING_CREATION。

如果 cmd 字段值为 delete,则设置 SETTING_DELETION。

如果 cmd 字段值为 edit、move、rename、set 或 commit,则设置 SETTING_MODIFICATION。

如果 cmd 字段值不包含任何值,则设置 SETTING_UNCATEGORIZED。

系统

如果子类型值为“dhcp”,则设置 NETWORK_DHCP。

如果子类型值为“auth”,则设置 USER_LOGIN。

如果说明值为“logged in”,则设置 USER_LOGIN。

如果说明值为“logged out”,则设置 USER_LOGOUT。

对于子类型的其他值,系统会设置 GENERIC_EVENT。

HIP 匹配 NETWORK_CONNECTION
IP 代码 GENERIC_EVENT
User-ID USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED

如果子类型值为“login”,则设置 USER_LOGIN。

如果子类型值为“logout”,则设置 USER_LOGOUT。

如果子类型不包含任何值,则设置为 USER_UNCATEGORIZED。

解密 NETWORK_CONNECTION
Authentication GENERIC_EVENT
SCTP NETWORK_CONNECTION
审核 GENERIC_EVENT

UDM 映射 Delta

UDM 映射增量参考信息:Palo Alto Networks 防火墙

下表列出了 Palo Alto Networks Firewall 的旧版 UDM 映射与 Palo Alto Networks Firewall 的新版 UDM 映射之间的差值。

UDM Event Type Delta

Log type Old UDM Event Type New UDM Event Type
WildFire NETWORK_CONNECTION SCAN_UNCATEGORIZED
Data Filtering NETWORK_CONNECTION NETWORK_UNCATEGORIZED
Authentication STATUS_UPDATE STATUS_UNCATEGORIZED

UDM Field Mapping Delta

Log Type Old UDM Mapping CSV Log Field CEF Log Field LEEF Log Field New UDM Mapping
System intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
System about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
System about.labels.key/value additional.fields.key/value.string_value Object (object) fname Filename target.resource.name
System Description (opaque) msg msg metadata.description
System principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
System intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
Config intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
Config about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
Config principal.process.command_line Configuration Path (path) msg ConfigurationPath principal.process.command_line
Config principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
Config intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
Config principal.asset.attribute.labels.key/value Device Group (dg_id) PanOSFWDeviceGroup target.asset.attribute.labels
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Threat/Wildfire target.file.full_path target.url target.hostname URL/Filename (misc) request Miscellaneous target.file.names target.url
Threat/Wildfire about.file.sha1/md5/sha256 File Digest (filedigest) fileHash FileDigest target.file.sha1/md5/sha256
Threat/Wildfire about.file.mime_type File Type (filetype) fileType FileType target.file.mime_type
Threat/Wildfire principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Threat/Wildfire principal.user.product_object_id Source VM UUID (src_uuid) PanOSSrcUUID SrcUUID principal.asset.product_object_id
Threat/Wildfire target.user.product_object_id Destination VM UUID (dst_uuid) PanOSDstUUID DstUUID target.asset.product_object_id
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value HTTP Headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
Threat/Wildfire principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
Threat/Wildfire principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
Threat/Wildfire principal.asset.software.version Source Device OS Version (src_osversion) PanSrcDeviceOSv principal.platform_version
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
Threat/Wildfire target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
Threat/Wildfire target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
Threat/Wildfire metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Threat/Wildfire about.labels.key/value additional.fields.key/value.string_value Reason (reason) PanReasonFilteringAction security_result.summary
Traffic about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value Packets Sent (pkts_sent) PanOSPacketsSent srcPackets network.sent_packets
Traffic about.labels.key/value additional.fields.key/value.string_value Packets Received (pkts_received) PanOSPacketsReceived dstPackets network.received_packets
Traffic principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
Traffic principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
Traffic principal.asset.platform_software.platform(enum) principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
Traffic target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
Traffic target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
Traffic about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
Traffic about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
Traffic about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
Traffic about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
Traffic metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
User-ID about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
User-ID principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
User-ID principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID intermediary.resource.product_object_id
User-ID principal.user.userid principal.administrative_domain principal.user.email_addresses User by Source (userbysource) PanOSUserBySource target.user.userid target.user.email_addresses
User-ID metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
HIP Match intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
HIP Match about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
HIP Match about.labels.key/value additional.fields.key/value.string_value HIP (matchname) cat HIP target.resource.attribute.labels
HIP Match about.labels.key/value additional.fields.key/value.string_value HIP Type (matchtype) Device Event Class ID (Header) HIPType target.resource.attribute.labels
HIP Match principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName target.asset.attribute.labels
HIP Match intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
HIP Match principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
HIP Match principal.asset.product_object_id Host ID (hostid) PanOSHostID principal.asset.asset_id
HIP Match metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
IP-Tag intermediary.asset.hardware.serial_number Serial Number (serial) deviceExternalId SerialNumber target.asset.hardware.serial_number
IP-Tag about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem target.asset.attribute.labels
IP-Tag principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOsVsysName vSrcName target.asset.attribute.labels
IP-Tag intermediary.hostname Device Name (device_name) dvchost DeviceName target.hostname
IP-Tag principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) cn2 VirtualSystemID target.resource.product_object_id
IP-Tag metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Decryption target.application Application (app) app network.application_protocol
Decryption about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 intermediary.asset.attribute.labels
Decryption principal.asset.asset_id Source VM UUID (src_uuid) PanOSSourceUUID principal.asset.product_object_id
Decryption target.asset.asset_id Destination VM UUID (dst_uuid) PanOSDestinationUUID target.asset.product_object_id
Decryption about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanOSContainerID intermediary.resource.product_object_id
Decryption about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanOSContainerNameSpace target.resource.attribute.labels additional.fields.key/value.string_value
Decryption about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanOSContainerName target.resource.name
Decryption metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanOSSourceDeviceCategory principal.asset.category
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanOSSourceDeviceModel principal.asset.hardware.model
Decryption principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanOSSourceDeviceVendor principal.asset.hardware.manufacturer
Decryption principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanOSSourceDeviceOSFamily principal.platform
Decryption principal.asset.software.version Source Device OS Version (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanOSDestinationDeviceCategory target.asset.category
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanOSDestinationDeviceModel target.asset.hardware.model
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanOSDestinationDeviceVendor target.asset.hardware.manufacturer
Decryption target.labels.key/value additional.fields.key/value.string_value Destination Device OS Family (dst_osfamily) PanOSDestinationDeviceOSFamily target.platform
Decryption target.asset.software.version Destination Device OS Version (dst_osversion) PanOSDestinationDeviceOSVersion target.platform_version
Decryption principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) intermediary.asset.attribute.labels
Decryption principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
Tunnel about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Tunnel principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Tunnel about.labels.key/value additional.fields.key/value.string_value Packets Sent (pkts_sent) PanOSPacketsSent srcPackets network.sent_packets
Tunnel about.labels.key/value additional.fields.key/value.string_value Packets Received (pkts_received) PanOSPacketsReceived dstPackets network.received_packets
Tunnel target.ip Remote User IP (remote_user_ip) PanOSRmtUserIP principal.ip
Tunnel target.labels.key/value additional.fields.key/value.string_value Remote User ID (remote_user_id) PanOSRmtUserID principal.user.userid
Tunnel metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Authentication about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Authentication target.user.user_display_name Normalize User (normalize_user) cs2 NormalizeUser target.user.user_display_name
Authentication about.labels.key/value additional.fields.key/value.string_value Object (object) fname ObjectName target.resource.name
Authentication about.labels.key/value additional.fields.key/value.string_value Authentication Policy (authpolicy) cs4 AuthPolicy additional.fields.key/value.string_value
Authentication principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Authentication principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
Authentication metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res _timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanOSSourceDeviceCategory principal.asset.category
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanOSSourceDeviceModel principal.asset.hardware.model
Authentication principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanOSSourceDeviceVendor principal.asset.hardware.manufacturer
Authentication principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanOSSourceDeviceOSFamily principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value
Authentication principal.asset.software.version Source Device OS Version (src_osversion) PanOSSourceDeviceOSVersion principal.platform_version
URL about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
URL target.file.full_path target.url URL/Filename (misc) Miscellaneous target.file.names target.url
URL about.labels.key/value additional.fields.key/value.string_value Category (category) cs2 URLCategory security_result.category_details
URL about.file.sha1/md5/sha256 filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
URL about.file.mime_type filetype (filetype) target.file.mime_type
URL about.labels.key/value additional.fields.key/value.string_value xff (xff) PanOSXForwarderfor identSrc principal.ip
URL principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
URL about.url file_url (file_url) target.url
URL principal.asset.asset_id Source VM UUID (src_uuid) SrcUUID principal.asset.product_object_id
URL target.asset.asset_id Destination VM UUID (dst_uuid) DstUUID target.asset.product_object_id
URL about.labels.key/value additional.fields.key/value.string_value http_headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
URL about.labels.key/value additional.fields.key/value.string_value UUID for rule (rule_uuid) PanOSRuleUUID security_result.rule_id
URL about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) PanOSHTTP2Con network.application_protocol_version
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) PanSrcDeviceCat principal.asset.category
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) PanSrcDeviceModel principal.asset.hardware.model
URL principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) PanSrcDeviceVendor principal.asset.hardware.manufacturer
URL principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) PanSrcDeviceOS principal.platform
URL principal.asset.software.version Source Device OS Version (src_osversion) PanSrcDeviceOSv principal.platform_version
URL principal.labels.key/value additional.fields.key/value.string_value Source Hostname (src_host) PanSrcHostname principal.hostname
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) PanDstDeviceCat target.asset.category
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) PanDstDeviceModel target.asset.hardware.model
URL target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) PanDstDeviceVendor target.asset.hardware.manufacturer
URL target.asset.platform_software.platform target.labels.key/value Destination Device OS Family (dst_osfamily) PanDstDeviceOS target.platform
URL target.asset.software.version Destination Device OS Version (dst_osversion) PanDstDeviceOSv target.platform_version
URL about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) PanContainerName intermediary.resource.product_object_id
URL about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) PanPODNamespace target.resource.attribute.labels
URL about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) PanPODName target.resource.name
URL about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) PanGPHostID principal.asset.asset_id
URL metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Res Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
URL about.labels.key/value additional.fields.key/value.string_value Reason (reason) PanReasonFilteringAction security_result.summary
Data about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) cs3 VirtualSystem intermediary.asset.attribute.labels
Data target.file.full_path target.url URL/Filename (misc) Miscellaneous target.file.names target.url
Data about.labels.key/value additional.fields.key/value.string_value Category (category) cs2 URLCategory security_result.category_details
Data about.file.sha1/md5/sha256 filedigest (filedigest) FileDigest target.file.sha1/md5/sha256
Data about.file.mime_type filetype (filetype) target.file.mime_type
Data about.labels.key/value additional.fields.key/value.string_value xff (xff) principal.ip
Data principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) PanOSVsysName vSrcName intermediary.asset.attribute.labels
Data about.url file_url (file_url) target.url
Data principal.asset.asset_id Source VM UUID (src_uuid) SrcUUID principal.asset.product_object_id
Data target.asset.asset_id Destination VM UUID (dst_uuid) DstUUID target.asset.product_object_id
Data about.labels.key/value additional.fields.key/value.string_value http_headers (http_headers) PanOSHTTPHeader target.url.last_http_response_headers
Data about.labels.key/value additional.fields.key/value.string_value UUID for rule (rule_uuid) PanOSRuleUUID security_result.rule_id
Data about.labels.key/value additional.fields.key/value.string_value HTTP/2 Connection (http2_connection) network.application_protocol_version
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Category (src_category) principal.asset.category
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Model (src_model) principal.asset.hardware.model
Data principal.labels.key/value additional.fields.key/value.string_value Source Device Vendor (src_vendor) principal.asset.hardware.manufacturer
Data principal.asset.platform_software.platform principal.labels.key/value additional.fields.key/value.string_value Source Device OS Family (src_osfamily) principal.platform
Data principal.asset.software.version Source Device OS Version (src_osversion) principal.platform_version
Data principal.labels.key/value additional.fields.key/value.string_value Source Hostname (src_host) principal.hostname
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Category (dst_category) target.asset.category
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Model (dst_model) target.asset.hardware.model
Data target.labels.key/value additional.fields.key/value.string_value Destination Device Vendor (dst_vendor) target.asset.hardware.manufacturer
Data target.asset.platform_software.platform target.labels.key/value Destination Device OS Family (dst_osfamily) target.platform
Data target.asset.software.version Destination Device OS Version (dst_osversion) target.platform_version
Data about.labels.key/value additional.fields.key/value.string_value Container ID (container_id) intermediary.resource.product_object_id
Data about.labels.key/value additional.fields.key/value.string_value POD Namespace (pod_namespace) target.resource.attribute.labels
Data about.labels.key/value additional.fields.key/value.string_value POD Name (pod_name) target.resource.name
Data about.labels.key/value additional.fields.key/value.string_value Host ID (hostid) principal.asset.asset_id
Data metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Res Timestamp (high_res_timestamp) additional.fields.key/value.string_value
Data about.labels.key/value additional.fields.key/value.string_value Reason (reason) security_result.summary
GlobalProtect about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) PanOSVirtualSystem intermediary.asset.attribute.labels
GlobalProtect principal.user.email_address principal.user.userid principal.administrative_domain Source User (srcuser) PanOSSourceUserName target.user.email_address target.user.userid
GlobalProtect principal.asset.platform_software.platform(enum) Client OS (client_os) PanOSEndpointOSType principal.platform
GlobalProtect principal.asset.platform_software.platform_version Client OS Version (client_os_ver) PanOSEndpointOSVersion principal.platform_version
GlobalProtect metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) PanOSTimeGeneratedHighResolution additional.fields.key/value.string_value
GlobalProtect about.labels.key/value additional.fields.key/value.string_value Gateway Name (gateway) PanOSAttemptedGateways target.resource.name
GlobalProtect principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) intermediary.asset.attribute.labels
GlobalProtect target.hostname Device Name (device_name) intermediary.hostname
GlobalProtect principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) intermediary.resource.product_object_id
CORRELATION about.labels.key/value additional.fields.key/value.string_value Virtual System (vsys) VirtualSystem intermediary.asset.attribute.labels
CORRELATION principal.resource.name principal.resource.resource_type=VIRTUAL_MACHINE Virtual System Name (vsys_name) vSrcName intermediary.asset.attribute.labels
CORRELATION principal.resource.resource_type=VIRTUAL_MACHINE and principal.resource.product_object_id Virtual System ID (vsys_id) VirtualSystemID intermediary.resource.product_object_id
GTP additional.fields.key/value.string_value Virtual System (vsys) intermediary.asset.attribute.labels
GTP target.ip Remote User IP (remote_user_ip) principal.ip
GTP additional.fields.key/value.string_value Remote User ID (remote_user_id) principal.user.userid
GTP metadata.collected_timestamp, metadata.event_timestamp (if "Generate Time" is absent) High Resolution Timestamp (high_res_timestamp) additional.fields.key/value.string_value

Palo Alto Networks Firewall Strata 日志记录服务

概览

Palo Alto Networks® Strata Logging Service 为本地、虚拟(私有云和公有云)防火墙、Prisma Access 以及 Cortex XDR 等云交付服务提供基于云的集中式日志存储和聚合。Strata Logging Service 安全、弹性且容错,可确保您的日志记录数据保持最新,并在您需要时可用。它提供可伸缩的日志记录基础架构,让您无需规划和部署日志收集器即可满足日志保留需求。如果您已有本地日志收集器,新的 Strata Logging Service 可以补充您现有的设置。您可以利用基于云的 Strata Logging Service 增强现有的日志收集基础架构,以便随着业务增长扩大运营能力,或满足新地点的容量需求。借助此服务,Palo Alto Networks 会负责日志记录基础架构的持续维护和监控,以便您可以专注于自己的业务。

  • 验证 Strata Logging Service 解析器支持的日志格式和 PAN-OS 版本。下表列出了 Strata Logging Service 解析器支持的日志格式和相应的 PAN-OS 版本:

    日志格式 PAN-OS 版本
    JSON 12.1
  • 验证 Google SecOps 解析器支持的 Palo Alto Networks 防火墙日志类型。 Google SecOps 解析器支持以下 Palo Alto Networks 防火墙日志类型:

    • 流量
    • 威胁
    • 隧道检查
    • 系统
    • HIP 匹配
    • IP-Tag
    • User-ID
    • 解密
    • 身份验证
    • 网址过滤
    • GlobalProtect

Strata Logging Service 部署

开始将日志发送到 Strata Logging Service:

如需开始向 Strata Logging 服务发送日志,请按以下步骤操作:

  1. 安装受支持的 PAN-OS® 版本
  2. 激活 Strata Logging Service - 激活 Strata Logging Service 包括预配防火墙安全连接到 Strata Logging Service 所需的证书。
  3. 将防火墙载入 Strata Logging Service(无论是否使用 Panorama)

如需了解详细的初始配置步骤,请参阅文档

转发来自 Strata Logging 服务的日志

为了满足您的长期存储、报告和监控或法律法规遵从需求,您可以将 Strata Logging Service 配置为将日志转发到 HTTPS 服务器或以下 SIEM:

  1. Exabeam
  2. Google Chronicle
  3. Microsoft Sentinel
  4. Splunk HTTP Event Collector (HEC)

使用 HTTPS 转发方法通过 Strata Logging Service 转发日志,如需了解详细信息,请参阅此文档

支持的日志格式

Palo Alto Networks Strata Logging Service 防火墙解析器支持 JSON 格式的日志。

支持的示例日志

  • JSON

    {"source": "Palo Alto Networks FLS LF", "host": "dummy-loghost", "time": "1730265996460", "event": {"TimeReceived": "2024-10-30T05:25:50.000000Z", "DeviceSN": "no-serial", "LogType": "TRAFFIC", "Subtype": "end", "ConfigVersion": "10.2", "TimeGenerated": "2024-10-30T05:25:40.000000Z", "SourceAddress": "198.51.100.6", "DestinationAddress": "198.51.100.6", "NATSource": "", "NATDestination": "", "Rule": "egress-dns-ping-traceroute", "SourceUser": null, "DestinationUser": null, "Application": "dns-base", "VirtualLocation": "vsys1", "FromZone": "VA8280-RN", "ToZone": "inter-fw", "InboundInterface": "tunnel.101", "OutboundInterface": "tunnel.4005", "LogSetting": "Cortex Data Lake", "SessionID": 754194, "RepeatCount": 1, "SourcePort": 53578, "DestinationPort": 53, "NATSourcePort": 0, "NATDestinationPort": 0, "Protocol": "udp", "Action": "allow", "Bytes": 214, "BytesSent": 72, "BytesReceived": 142, "PacketsTotal": 2, "SessionStartTime": "2024-10-30T05:25:10.000000Z", "SessionDuration": 0, "URLCategory": "any", "SequenceNo": 7382192512716388639, "SourceLocation": "198.51.100.6-198.51.255.255", "DestinationLocation": "198.51.100.6-198.51.255.255", "PacketsSent": 1, "PacketsReceived": 1, "SessionEndReason": "aged-out", "DGHierarchyLevel1": 65537, "DGHierarchyLevel2": 65538, "DGHierarchyLevel3": 65541, "DGHierarchyLevel4": 0, "VirtualSystemName": "", "DeviceName": "VA8280-RN", "ActionSource": "from-policy", "SourceUUID": null, "DestinationUUID": null, "IMSI": 0, "IMEI": null, "ParentSessionID": 0, "ParentStarttime": "1970-01-01T00:00:00.000000Z", "Tunnel": "N/A", "EndpointAssociationID": 72057594037927936, "ChunksTotal": 0, "ChunksSent": 0, "ChunksReceived": 0, "RuleUUID": "95cfc3cc-cb00-4758-af1d-de9ab5f07f97", "HTTP2Connection": 0, "LinkChangeCount": 0, "SDWANPolicyName": null, "LinkSwitches": null, "SDWANCluster": null, "SDWANDeviceType": null, "SDWANClusterType": null, "SDWANSite": null, "DynamicUserGroupName": null, "X-Forwarded-ForIP": null, "SourceDeviceCategory": null, "SourceDeviceProfile": null, "SourceDeviceModel": null, "SourceDeviceVendor": null, "SourceDeviceOSFamily": null, "SourceDeviceOSVersion": null, "SourceDeviceHost": null, "SourceDeviceMac": null, "DestinationDeviceCategory": null, "DestinationDeviceProfile": null, "DestinationDeviceModel": null, "DestinationDeviceVendor": null, "DestinationDeviceOSFamily": null, "DestinationDeviceOSVersion": null, "DestinationDeviceHost": null, "DestinationDeviceMac": null, "ContainerID": null, "ContainerNameSpace": null, "ContainerName": null, "SourceEDL": null, "DestinationEDL": null, "GPHostID": null, "EndpointSerialNumber": null, "SourceDynamicAddressGroup": null, "DestinationDynamicAddressGroup": null, "HASessionOwner": null, "TimeGeneratedHighResolution": "2024-10-30T05:25:41.009000Z", "NSSAINetworkSliceType": null, "NSSAINetworkSliceDifferentiator": null}}"
    

字段映射参考信息:日志字段到 UDM 字段

本部分介绍解析器如何将 Palo Alto Networks Strata Logging Service 防火墙日志字段映射到 Google UDM 事件字段(针对每种日志类型)。

如需了解每种日志类型的映射参考信息,请参阅以下部分:

系统

下表列出了“系统”日志类型的日志字段及其对应的 UDM 字段。

Log field UDM mapping
AgentContentVersion additional.fields.key/value.string_value
AgentDataCollectionStatus target.resource.attribute.labels
AgentID target.resource.attribute.labels
AgentIsolationStatus target.resource.attribute.labels
AgentStatus target.resource.attribute.labels
AgentVersion target.asset.software.version
ConfigVersion additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DeviceGroup target.group.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EndpointCPUArchitecture target.asset.hardware.cpu_platform
EndpointDeviceDomain target.asset.administrative_domain
EndpointDeviceName target.asset.hostname
EndpointIPaddress target.asset.ip
VDIEndpoint target.asset.attribute.labels
EndpointOSType additional.fields.key/value.string_value
EndpointOSVersion target.platform_version
AgentTimeZoneOffset additional.fields.key/value.string_value
EndpointUserDomain additional.fields.key/value.string_value
EndpointUserName target.user.user_display_name
EndpointUserUUID target.user.userid
EventComponent additional.fields.key/value.string_value
EventDescription metadata.description
EventName additional.fields.key/value.string_value
EventTime metadata.event_timestamp
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogCategory security_result.category_details
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
LogSourceID target.resource.attribute.labels
LogSourceName observer.asset.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
LogTime metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Severity security_result.severity
Subtype metadata.product_event_type
Template target.resource.attribute.labels
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

威胁

下表列出了威胁日志类型的日志字段及其对应的 UDM 字段。

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
ApplianceOrCloud additional.fields.key/value.string_value
CloudHostname additional.fields.key/value.string_value
CloudReportID security_result.detection_fields.key/value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DirectionOfAttack security_result.detection_fields.key/value
DomainEDL additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
FileName target.file.names
FileHash target.file.sha1
FileType additional.fields.key/value.string_value
FileURL target.url
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HostID principal.asset.asset_id
HTTP2Connection network.application_protocol_version
HTTPMethod network.http.method
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
LocalDeepLearningAnalyzed additional.fields.key/value.string_value
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
PartialHash additional.fields.key/value.string_value
PayloadProtocolID additional.fields.key/value.string_value
Packet additional.fields.key/value.string_value
PacketID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
RecipientEmail target.user.email_addresses
ReportID security_result.detection_fields.key/value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SenderEmail principal.user.email_addresses
SequenceNo metadata.product_log_id
SessionID network.session_id
Severity security_result.severity
SigFlags additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
EmailSubject network.email.subject
ApplicationTechnology additional.fields.key/value.string_value
ThreatCategory security_result.detection_fields.key/value.key/value
ThreatID security_result.threat_id
ThreatName security_result.threat_name
ThreatNameFirewall additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLDomain target.domain.name
URLCounter additional.fields.key/value.string_value
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
Verdict additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-ForIP principal.ip

流量

下表列出了流量日志类型的日志字段及其对应的 UDM 字段。

Log field UDM mapping
Action security_result.action
ActionSource additional.fields.key/value.string_value
AIFwdError additional.fields.key/value.string_value
AITraffic additional.fields.key/value.string_value
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
BytesReceived network.received_bytes
BytesSent network.sent_bytes
Bytes additional.fields.key/value.string_value
ChunksReceived additional.fields.key/value.string_value
ChunksSent additional.fields.key/value.string_value
ChunksTotal additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
EndpointAssociationID additional.fields.key/value.string_value
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HASessionOwner additional.fields.key/value.string_value
GPHostID additional.fields.key/value.string_value
HTTP2Connection network.application_protocol_version
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsOffloaded additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
LinkChangeCount additional.fields.key/value.string_value
LinkSwitches additional.fields.key/value.string_value
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
SDWANPolicyName additional.fields.key/value.string_value
Protocol network.ip_protocol
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SDWANFECRatio additional.fields.key/value.string_value
SDWANCluster additional.fields.key/value.string_value
SDWANClusterType additional.fields.key/value.string_value
SDWANDeviceType additional.fields.key/value.string_value
SDWANSite additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionStartTime additional.fields.key/value.string_value
SessionTracker additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
SessionDuration network.session_duration
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLCategory target.url_metadata.categories
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-ForIP principal.ip

User-ID

下表列出了 User-ID 日志类型的日志字段及其对应的 UDM 字段。

Log field UDM mapping
AuthFactorNo security_result.detection_fields.key/value
AuthenticatedUserDomain target.user.administrative_domain
AuthenticatedUserName target.user.userid
AuthenticatedUserUUID target.user.product_object_id
ConfigVersion additional.fields.key/value.string_value
CountofRepeats additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationPort target.port
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EventID additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsDuplicateUser additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MappingDataSource additional.fields.key/value.string_value
MappingDataSourceName additional.fields.key/value.string_value
MappingDataSourceType additional.fields.key/value.string_value
MappingTimeout additional.fields.key/value.string_value
MFAFactorType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SourceIP principal.ip
SourcePort principal.port
Subtype metadata.product_event_type
Tag additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
UGFlags additional.fields.key/value.string_value
User target.user.userid
UserGroupFound additional.fields.key/value.string_value
UserIdentifiedBySource additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

HIP 匹配

下表列出了 HIP 匹配日志类型的日志字段及其对应的 UDM 字段。

Log field UDM mapping
ConfigVersion additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EndpointDeviceName principal.asset.hostname
EndpointOSType additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
HipMatchName target.resource.attribute.labels
HipMatchType target.resource.attribute.labels
HostID principal.asset.asset_id
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType metadata.product_event_type
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Source additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceIP principal.ip
SourceIPv6 principal.ip
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
TimestampDeviceIdentification principal.asset.first_seen_time
UUID additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

IP 代码

下表列出了 IP 标记日志类型的日志字段及其对应的 UDM 字段。

Log field UDM mapping
ConfigVersion additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
TenantID metadata.product_deployment_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
EventID additional.fields.key/value.string_value
IPSubnetRange network.ip_subnet_range
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSetting target.resource.attribute.labels
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MappingDataSource additional.fields.key/value.string_value
MappingDataSourceSubType additional.fields.key/value.string_value
MappingDataSourceType additional.fields.key/value.string_value
MappingTimeout additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
RuleMatched security_result.rule_name
RuleMatchedUUID security_result.rule_id
SequenceNo metadata.product_log_id
SourceIP principal.ip
Subtype metadata.product_event_type
TagName additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation target.asset.attribute.labels
VirtualSystemID target.resource.product_object_id
VirtualSystemName target.asset.attribute.labels

解密

下表列出了“解密”日志类型的日志字段及其对应的 UDM 字段。

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
CertificateFlags additional.fields.key/value.string_value
CertificateSerial network.tls.server.certificate.serial
CertificateSize additional.fields.key/value.string_value
CertificateVersion network.tls.server.certificate.version
ChainStatus additional.fields.key/value.string_value
ApplicationCharacteristics additional.fields.key/value.string_value
ClientToFirewall additional.fields.key/value.string_value
CommonName additional.fields.key/value.string_value
CommonNameLength additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
Cpadding additional.fields.key/value.string_value
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
Domain target.hostname
EllipticCurve network.tls.curve
ErrorIndex additional.fields.key/value.string_value
ErrorMessage additional.fields.key/value.string_value
Fingerprint network.tls.server.certificate.md5/sha1/sha256
FirewallToClient additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsCertECDSA additional.fields.key/value.string_value
IsCertRSA additional.fields.key/value.string_value
IsCertCNTruncated additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
IsForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsIssuerCNTruncated additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
IsNAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
PacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsResumeSession additional.fields.key/value.string_value
IsRootCNTruncated additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSNITruncated additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
IssuerCommonName network.tls.server.certificate.issuer
IssuerNameLength additional.fields.key/value.string_value
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
TimeNotAfter additional.fields.key/value.string_value
TimeNotBefore additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
Padding additional.fields.key/value.string_value
Padding3 additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
PolicyName additional.fields.key/value.string_value
Protocol network.ip_protocol
ProxyType additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
RootCommonName additional.fields.key/value.string_value
RootCNLength additional.fields.key/value.string_value
RootStatus additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SessionID network.session_id
ServerNameIndication network.tls.client.server_name
SNILength additional.fields.key/value.string_value
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceOS additional.fields.key/value.string_value
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
ApplicationTechnology additional.fields.key/value.string_value
TimeReceivedManagementPlane additional.fields.key/value.string_value
TLSAuth additional.fields.key/value.string_value
TLSEncryptionAlgorithm additional.fields.key/value.string_value
TLSKeyExchange additional.fields.key/value.string_value
TLSVersion network.tls.version
ToZone additional.fields.key/value.string_value
Tpadding additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
Vpadding additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SourceDeviceCategory principal.asset.category
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

隧道

下表列出了隧道日志类型的日志字段及其对应的 UDM 字段。

Log field UDM mapping
AccessPointName additional.fields.key/value.string_value
Action security_result.action
ActionSource additional.fields.key/value.string_value
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
BytesReceived network.received_bytes
BytesSent network.sent_bytes
Bytes additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
LoggingServiceID additional.fields.key/value.string_value
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DynamicUserGroupName additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MobileAreaCode additional.fields.key/value.string_value
MobileBaseStationCode additional.fields.key/value.string_value
MobileCountryCode additional.fields.key/value.string_value
MobileIP additional.fields.key/value.string_value
MobileNetworkCode additional.fields.key/value.string_value
MobileSubscriberISDN additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceDifferentiator additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsDroppedMax additional.fields.key/value.string_value
PacketsDroppedStrict additional.fields.key/value.string_value
PacketsDroppedTunnel additional.fields.key/value.string_value
PacketsDroppedProtocol additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
ProtocolDataUnitsessionID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
RadioAccessTechnology additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionStartTime additional.fields.key/value.string_value
SessionTracker additional.fields.key/value.string_value
Severity security_result.severity
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
StandardPortsOfApp additional.fields.key/value.string_value
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
SessionDuration network.session_duration
Tunnel additional.fields.key/value.string_value
TunnelCauseCode additional.fields.key/value.string_value
TunnelEndpointID1 additional.fields.key/value.string_value
TunnelEndpointID2 additional.fields.key/value.string_value
TunnelEventCode additional.fields.key/value.string_value
TunnelEventType additional.fields.key/value.string_value
TunnelInspectionRule additional.fields.key/value.string_value
TunnelInterface additional.fields.key/value.string_value
TunnelMessageType additional.fields.key/value.string_value
TunnelRemoteIMSIID additional.fields.key/value.string_value
TunnelRemoteUserIP principal.ip
TunnelSessionsClosed additional.fields.key/value.string_value
TunnelSessionsCreated additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URLCategory target.url_metadata.categories
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

身份验证

下表列出了“身份验证”日志类型的日志字段及其对应的 UDM 字段。

Log field UDM mapping
AuthenticationDescription security_result.description
AuthEvent metadata.description
AuthFactorNo security_result.detection_fields.key/value
AuthenticationPolicy security_result.detection_fields.key/value
AuthenticationProtocol additional.fields.key/value.string_value
AuthServerProfile additional.fields.key/value.string_value
AuthenticatedUserDomain target.administrative_domain
AuthenticatedUserName target.user.userid
AuthenticatedUserUUID target.user.product_object_id
ClientType additional.fields.key/value.string_value
ClientTypeName additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
IsPrismaNetworks additional.fields.key/value.string_value
Location target.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogType additional.fields.key/value.string_value
MFAAuthenticationID additional.fields.key/value.string_value
MFAVendor additional.fields.key/value.string_value
NormalizeUser target.user.user_display_name
Object target.resource.name
RuleMatched security_result.rule_name
RuleMatchedUUID security_result.rule_id
AuthCacheServiceRegion additional.fields.key/value.string_value
SessionID network.session_id
SourceDeviceCategory principal.asset.category
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceIP principal.ip
TimeGenerated metadata.event_timestamp
User target.user.userid
UserAgentString network.http.user_agent
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
Subtype metadata.product_event_type
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

网址

下表列出了网址日志类型的日志字段及其对应的 UDM 字段。

Log field UDM mapping
Action security_result.action
Application target.application
ApplicationCategory additional.fields.key/value.string_value
ApplicationSubcategory additional.fields.key/value.string_value
CloudHostname additional.fields.key/value.string_value
CloudReportID security_result.detection_fields.key/value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ApplicationContainer additional.fields.key/value.string_value
ContentType additional.fields.key/value.string_value
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceCategory target.asset.category
DestinationDeviceClass additional.fields.key/value.string_value
DestinationDeviceHost target.asset.hostname
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceOSFamily additional.fields.key/value.string_value
DestinationDeviceOSVersion target.platform_version
DestinationDeviceProfile additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationAddress target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DirectionOfAttack security_result.detection_fields.key/value
DynamicUserGroupName additional.fields.key/value.string_value
EndpointSerialNumber principal.asset.hardware.serial_number
FileURL target.url
FlowType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
HostID principal.asset.asset_id
HTTP2Connection network.application_protocol_version
HTTPHeaders additional.fields.key/value.string_value
HTTPMethod network.http.method
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
InlineMLVerdict additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecrypted additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
IsEncrypted additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsSaaSApplication additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLDenied additional.fields.key/value.string_value
K8SClusterID target.resource.attribute.labels
Location observer.location.country_or_region
LogSetting intermediary.resource.attribute.labels
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
IMEI additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
NonStandardDestinationPort additional.fields.key/value.string_value
NSSAINetworkSliceType additional.fields.key/value.string_value
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
ParentSessionID network.parent_session_id
ParentStarttime additional.fields.key/value.string_value
Packet additional.fields.key/value.string_value
PacketID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
Referer network.http.referral_url
HTTPRefererFQDN additional.fields.key/value.string_value
HTTPRefererPort additional.fields.key/value.string_value
HTTPRefererProtocol additional.fields.key/value.string_value
HTTPRefererURLPath additional.fields.key/value.string_value
ApplicationRisk additional.fields.key/value.string_value
Rule security_result.rule_name
RuleUUID security_result.rule_id
SanctionedStateOfApp additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionID network.session_id
Severity security_result.severity
SigFlags additional.fields.key/value.string_value
SourceDeviceCategory principal.asset.category
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceHost principal.hostname
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceOSFamily additional.fields.key/value.string_value
SourceDeviceOSVersion principal.platform_version
SourceDeviceProfile additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceAddress principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
ApplicationTechnology additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
TunneledApplication additional.fields.key/value.string_value
IMSI additional.fields.key/value.string_value
URL target.url_metadata.URL
URLCategory target.url_metadata.categories
URLCategoryList additional.fields.key/value.string_value
URLDomain target.domain.name
URLCounter additional.fields.key/value.string_value
UserAgent network.http.user_agent
Users additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels
X-Forwarded-For additional.fields.key/value.string_value
X-Forwarded-ForIP principal.ip

GlobalProtect

下表列出了 GlobalProtect 日志类型的日志字段及其对应的 UDM 字段。

Log field UDM mapping
AttemptedGateways additional.fields.key/value.string_value
AuthMethod extensions.auth.auth_details
ConnectionMethod additional.fields.key/value.string_value
ConnectionErrorID additional.fields.key/value.string_value
ConnectionError additional.fields.key/value.string_value
CountOfRepeats additional.fields.key/value.string_value
EndpointDeviceName principal.asset.hostname
GlobalProtectClientVersion additional.fields.key/value.string_value
EndpointOSType additional.fields.key/value.string_value
EndpointSN principal.asset.hardware.serial_number
EventIDValue additional.fields.key/value.string_value
Gateway target.resource.name
GatewayPriority additional.fields.key/value.string_value
GatewaySelectionType additional.fields.key/value.string_value
GlobalProtectGatewayLocation target.location.country_or_region
HostID principal.asset.asset_id
LogSource intermediary.resource.attribute.labels
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LoginDuration network.session_duration
Description security_result.description
Portal target.hostname
PrivateIPv4 principal.ip
PrivateIPv6 principal.ip
ProjectName additional.fields.key/value.string_value
PublicIPv4 principal.nat_ip
PublicIPv6 principal.nat_ip
QuarantineReason security_result.summary
SequenceNo metadata.product_log_id
SourceRegion principal.location.country_or_region
SourceUserName principal.user.user_display_name
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SSLResponseTime additional.fields.key/value.string_value
Stage additional.fields.key/value.string_value
EventStatus additional.fields.key/value.string_value
LogSubtype metadata.product_event_type
TunnelType additional.fields.key/value.string_value
VirtualSystem intermediary.asset.attribute.labels
VirtualSystemName intermediary.asset.attribute.labels
EndpointOSVersion principal.platform_version
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsPrismaNetworks additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType metadata.product_event_type
PanoramaSN observer.asset.hardware.serial_number
PlatformType additional.fields.key/value.string_value
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VirtualSystemID intermediary.resource.product_object_id

SCTP

下表列出了 SCTP 日志类型的日志字段及其对应的 UDM 字段。

Log field UDM mapping
Action security_result.action
Application target.application
AssocationEndReason additional.fields.key/value.string_value
ChunksReceived additional.fields.key/value.string_value
ChunksSent additional.fields.key/value.string_value
ChunksTotal additional.fields.key/value.string_value
ConfigVersion additional.fields.key/value.string_value
ContainerID intermediary.resource.product_object_id
ContentVersion additional.fields.key/value.string_value
RepeatCount additional.fields.key/value.string_value
CortexDataLakeTenantID metadata.product_deployment_id
DestinationDeviceClass target.asset.category
DestinationDeviceMac target.asset.mac
DestinationDeviceModel target.asset.hardware.model
DestinationDeviceOS additional.fields.key/value.string_value
DestinationDeviceVendor target.asset.hardware.manufacturer
DestinationDynamicAddressGroup target.group.group_display_name
DestinationEDL additional.fields.key/value.string_value
DestinationIP target.ip
DestinationLocation target.location.country_or_region
DestinationPort target.port
DestinationUser target.user.userid
DestinationUserDomain target.administrative_domain
DestinationUserName target.user.user_display_name
DestinationUserUUID target.user.product_object_id
DestinationUUID target.resource.product_object_id
DGHierarchyLevel1 additional.fields.key/value.string_value
DGHierarchyLevel2 additional.fields.key/value.string_value
DGHierarchyLevel3 additional.fields.key/value.string_value
DGHierarchyLevel4 additional.fields.key/value.string_value
DiamAppID additional.fields.key/value.string_value
DiamAvpCode additional.fields.key/value.string_value
DiameterCommandCode additional.fields.key/value.string_value
DiameterRequestFlag additional.fields.key/value.string_value
DeviceName principal.asset.hostname
SCTPEventType additional.fields.key/value.string_value
FromZone additional.fields.key/value.string_value
InboundInterface additional.fields.key/value.string_value
InboundInterfaceDetailsPort additional.fields.key/value.string_value
InboundInterfaceDetailsSlot additional.fields.key/value.string_value
InboundInterfaceDetailsType additional.fields.key/value.string_value
InboundInterfaceDetailsUnit additional.fields.key/value.string_value
CaptivePortal additional.fields.key/value.string_value
IsClienttoServer additional.fields.key/value.string_value
IsContainer additional.fields.key/value.string_value
IsDecryptMirror additional.fields.key/value.string_value
IsDecryptedPayloadForward additional.fields.key/value.string_value
IsDecryptedLog additional.fields.key/value.string_value
IsDuplicateLog additional.fields.key/value.string_value
LogExported additional.fields.key/value.string_value
LogForwarded additional.fields.key/value.string_value
IsIPV6 additional.fields.key/value.string_value
IsInspectionBeforeSession additional.fields.key/value.string_value
IsMptcpOn additional.fields.key/value.string_value
NAT additional.fields.key/value.string_value
IsNonStandardDestinationPort additional.fields.key/value.string_value
IsPacketCapture additional.fields.key/value.string_value
IsPhishing additional.fields.key/value.string_value
IsPrismaNetwork additional.fields.key/value.string_value
IsPrismaUsers additional.fields.key/value.string_value
IsProxy additional.fields.key/value.string_value
IsReconExcluded additional.fields.key/value.string_value
IsServertoClient additional.fields.key/value.string_value
IsSourceXForwarded additional.fields.key/value.string_value
IsSystemReturn additional.fields.key/value.string_value
IsTransaction additional.fields.key/value.string_value
IsTunnelInspected additional.fields.key/value.string_value
IsURLFiltering additional.fields.key/value.string_value
IsWildfire additional.fields.key/value.string_value
LogAction additional.fields.key/value.string_value
LogSourceGroupID intermediary.resource.attribute.labels
DeviceSN intermediary.asset.hardware.serial_number
DeviceName intermediary.hostname
LogSourceTimeZoneOffset additional.fields.key/value.string_value
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
MapAppCode additional.fields.key/value.string_value
NATDestination target.nat_ip
NATDestinationPort target.nat_port
NATSource principal.nat_ip
NATSourcePort principal.nat_port
OutboundInterface additional.fields.key/value.string_value
OutboundInterfaceDetailsPort additional.fields.key/value.string_value
OutboundInterfaceDetailsSlot additional.fields.key/value.string_value
OutboundInterfaceDetailsType additional.fields.key/value.string_value
OutboundInterfaceDetailsUnit additional.fields.key/value.string_value
PacketsReceived network.received_packets
PacketsSent network.sent_packets
PacketsTotal additional.fields.key/value.string_value
PanoramaSN observer.asset.hardware.serial_number
PayloadProtocolID additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
ContainerName target.resource.name
ContainerNameSpace target.resource.attribute.labels
Protocol network.ip_protocol
Rule security_result.rule_name
RuleUUID security_result.rule_id
SccpCallingGt additional.fields.key/value.string_value
SccpCallingSSN additional.fields.key/value.string_value
SctpCauseCode additional.fields.key/value.string_value
SctpChunkType additional.fields.key/value.string_value
SctpFilter additional.fields.key/value.string_value
SequenceNo metadata.product_log_id
SessionOwnerMidx additional.fields.key/value.string_value
SessionEndReason security_result.summary
SessionID network.session_id
SessionTracker additional.fields.key/value.string_value
Severity security_result.severity
SourceDeviceClass additional.fields.key/value.string_value
SourceDeviceMac principal.asset.mac
SourceDeviceModel principal.asset.hardware.model
SourceDeviceOS additional.fields.key/value.string_value
SourceDeviceVendor principal.asset.hardware.manufacturer
SourceDynamicAddressGroup principal.group.group_display_name
SourceEDL additional.fields.key/value.string_value
SourceIP principal.ip
SourceLocation principal.location.country_or_region
SourcePort principal.port
SourceUser principal.user.userid
SourceUserDomain principal.administrative_domain
SourceUserName principal.user.user_display_name
SourceUserUUID principal.user.product_object_id
SourceUUID principal.resource.product_object_id
Subtype metadata.product_event_type
TimeGenerated metadata.event_timestamp
TimeGeneratedHighResolution additional.fields.key/value.string_value
ToZone additional.fields.key/value.string_value
Tunnel additional.fields.key/value.string_value
VendorName additional.fields.key/value.string_value
VendorSeverity security_result.severity_details
VerificationTag1 additional.fields.key/value.string_value
VerificationTag2 additional.fields.key/value.string_value
VirtualLocation intermediary.asset.attribute.labels
VirtualSystemID intermediary.resource.product_object_id
VirtualSystemName intermediary.asset.attribute.labels

审核

下表列出了“审核日志”类型的日志字段及其对应的 UDM 字段。

Log field UDM mapping
EventCategory network.http.method
EventDescription metadata.description
EventDestinationURL target.url
EventDestinationUserUserID target.user.userid
DestinationVendor additional.fields.key/value.string_value
EventDetails additional.fields.key/value.string_value
EventID metadata.product_log_id
EventName additional.fields.key/value.string_value
EventResult security_result.summary
EventSourceUserUserID principal.user.userid
EventTime metadata.event_timestamp
LogSource target.resource.attribute.labels
LogSourceGroupID target.resource.attribute.labels
DeviceSN target.asset.hardware.serial_number
DeviceName target.hostname
TimeReceived metadata.collected_timestamp
LogType additional.fields.key/value.string_value
PlatformType additional.fields.key/value.string_value
Subtype metadata.product_event_type
TSGID additional.fields.key/value.string_value
Vendor additional.fields.key/value.string_value
VendorSeverity security_result.severity_details

字段映射参考信息:日志类型到 UDM 事件类型

下表列出了 Palo Alto Networks Strata Logging Service 防火墙日志类型及其对应的 UDM 事件类型。

日志类型 UDM 事件类型
流量 NETWORK_CONNECTION
威胁 NETWORK_CONNECTION
网址过滤 NETWORK_CONNECTION
隧道 NETWORK_CONNECTION
系统

如果子类型值为“dhcp”,则设置 NETWORK_DHCP。

如果子类型值为“auth”,则设置 USER_LOGIN。

如果说明值为“logged in”,则设置 USER_LOGIN。

如果说明值为“logged out”,则设置 USER_LOGOUT。

对于子类型的其他值,系统会设置 GENERIC_EVENT。

HIP 匹配 NETWORK_CONNECTION
IP 代码 GENERIC_EVENT
User-ID USER_LOGIN/USER_LOGOUT/USER_UNCATEGORIZED

如果子类型值为“login”,则设置 USER_LOGIN。

如果子类型值为“logout”,则设置 USER_LOGOUT。

如果子类型不包含任何值,则设置为 USER_UNCATEGORIZED。

解密 NETWORK_CONNECTION
Authentication STATUS_UNCATEGORIZED
Globalprotect USER_LOGIN/USER_LOGOUT/USER_RESOURCE_ACCESS

如果子类型值为“auth”,则设置 USER_LOGIN。

如果子类型值为“logout”,则设置 USER_LOGOUT。

如果子类型不包含任何值,则设置 USER_RESOURCE_ACCESS。

SCTP NETWORK_CONNECTION
审核 NETWORK_CONNECTION

后续步骤

需要更多帮助?获得社区成员和 Google SecOps 专业人士的解答。