Skip to content

Latest commit

 

History

History
42 lines (35 loc) · 1.22 KB

91e59967-bf60-4f76-90d8-4c277010ebf1.md

File metadata and controls

42 lines (35 loc) · 1.22 KB

Mappings: Palo Alto Threat

Input Requirements

Legacy Parser Grok Patterns
PALO_FW_THREAT

Record Output

Output Value
Vendor Palo Alto Networks
Product Next Generation Firewall
Record Type Network

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action action
description threat_id
device_ip sourceIP
dstDevice_ip destination_ip
dstDevice_natIp nat_destination_ip
dstPort destination_port
file_mimeType file_type
http_category category
http_url url
ipProtocol protocol
normalizedSeverity severity This is a lookup field. More info to come in the catalog later...
severity severity
srcDevice_ip source_ip
srcDevice_natIp nat_source_ip
srcPort source_port
success action This is a lookup field. More info to come in the catalog later...
threat_category category
threat_name threat_id
threat_ruleType None The static text intrusion is populated in this schema field.
timestamp generated_time We expect the orginal record value of generated_time is in the format yyyy/MM/dd HH:mm:ss
user_username source_user