Mappings: Palo Alto Threat
Legacy Parser Grok Patterns |
---|
PALO_FW_THREAT |
Output | Value |
---|---|
Vendor | Palo Alto Networks |
Product | Next Generation Firewall |
Record Type | Network |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
action | action | |
description | threat_id | |
device_ip | sourceIP | |
dstDevice_ip | destination_ip | |
dstDevice_natIp | nat_destination_ip | |
dstPort | destination_port | |
file_mimeType | file_type | |
http_category | category | |
http_url | url | |
ipProtocol | protocol | |
normalizedSeverity | severity | This is a lookup field. More info to come in the catalog later... |
severity | severity | |
srcDevice_ip | source_ip | |
srcDevice_natIp | nat_source_ip | |
srcPort | source_port | |
success | action | This is a lookup field. More info to come in the catalog later... |
threat_category | category | |
threat_name | threat_id | |
threat_ruleType | None | The static text intrusion is populated in this schema field. |
timestamp | generated_time | We expect the orginal record value of generated_time is in the format yyyy/MM/dd HH:mm:ss |
user_username | source_user |