Skip to content

Latest commit

 

History

History
42 lines (35 loc) · 1.1 KB

52351529-dfdd-4f70-8d0f-1321cf55a61f.md

File metadata and controls

42 lines (35 loc) · 1.1 KB

Mappings: Palo Alto Threat Vulnerability - Custom Parser

Input Requirements

Input Value
Vendor Palo Alto
Product Firewall
Log Format JSON
Event ID Regex Pattern threat-vulnerability

Record Output

Output Value
Vendor Palo Alto Networks
Product Next Generation Firewall
Record Type Network

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action action
application application
device_hostname firewall_name
dstDevice_ip dest_ip
dstPort dest_port
http_url http_url
ipProtocol protocol
normalizedSeverity pan_severity This is a lookup field. More info to come in the catalog later...
resource flags
severity pan_severity
srcDevice_ip source_ip
srcPort source_port
success action This is a lookup field. More info to come in the catalog later...
threat_category category
threat_name threat_name
threat_ruleType None The static text intrusion is populated in this schema field.
threat_signalName threat_name
user_username source_user