Mappings: Palo Alto Correlation - Custom Parser
Input | Value |
---|---|
Vendor | Palo Alto |
Product | Firewall |
Log Format | JSON |
Event ID Regex Pattern | correlation-.* |
Output | Value |
---|---|
Vendor | Palo Alto Networks |
Product | Next Generation Firewall |
Record Type | Network |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
device_hostname | firewall_name | |
dstDevice_hostname | server_name | |
logonType | server_type | |
severity | severity | |
srcDevice_ip | source_ip | |
threat_category | category | |
user_authDomain | source_user_domain | |
user_username | source_user |