Mappings: Palo Alto Traps - Custom Parser
Input | Value |
---|---|
Vendor | Palo Alto |
Product | Traps |
Log Format | JSON |
Event ID Regex Pattern | traps-.* |
Output | Value |
---|---|
Vendor | Palo Alto Networks |
Product | Next Generation Firewall |
Record Type | Endpoint |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
action | action | |
description | description | |
device_hostname | firewall_name | |
file_basename | file_name | |
file_hash_sha256 | sha_256_hash | |
file_path | file_path | |
normalizedAction | action | This is a lookup field. More info to come in the catalog later... |
srcDevice_ip | device_ip | |
threat_name | threat_name | |
user_authDomain | source_user_domain | |
user_username | source_user |