Skip to content

Latest commit

 

History

History
35 lines (28 loc) · 829 Bytes

1b0609f0-44bd-4333-bf67-dcbfe20cf855.md

File metadata and controls

35 lines (28 loc) · 829 Bytes

Mappings: Palo Alto Traps - Custom Parser

Input Requirements

Input Value
Vendor Palo Alto
Product Traps
Log Format JSON
Event ID Regex Pattern traps-.*

Record Output

Output Value
Vendor Palo Alto Networks
Product Next Generation Firewall
Record Type Endpoint

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action action
description description
device_hostname firewall_name
file_basename file_name
file_hash_sha256 sha_256_hash
file_path file_path
normalizedAction action This is a lookup field. More info to come in the catalog later...
srcDevice_ip device_ip
threat_name threat_name
user_authDomain source_user_domain
user_username source_user