Skip to content

Latest commit

 

History

History
32 lines (25 loc) · 705 Bytes

b28e6ee8-063a-4a97-975f-aba5a6161c98.md

File metadata and controls

32 lines (25 loc) · 705 Bytes

Mappings: Palo Alto Correlation - Custom Parser

Input Requirements

Input Value
Vendor Palo Alto
Product Firewall
Log Format JSON
Event ID Regex Pattern correlation-.*

Record Output

Output Value
Vendor Palo Alto Networks
Product Next Generation Firewall
Record Type Network

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
device_hostname firewall_name
dstDevice_hostname server_name
logonType server_type
severity severity
srcDevice_ip source_ip
threat_category category
user_authDomain source_user_domain
user_username source_user