Skip to content

Latest commit

 

History

History
39 lines (32 loc) · 901 Bytes

d6a48aaf-c3e2-4f10-98ce-3821eec55002.md

File metadata and controls

39 lines (32 loc) · 901 Bytes

Mappings: Palo Alto Threat Wildfire - Custom Parser

Input Requirements

Input Value
Vendor Palo Alto
Product Firewall
Log Format JSON
Event ID Regex Pattern threat-wildfire

Record Output

Output Value
Vendor Palo Alto Networks
Product Next Generation Firewall
Record Type Network

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action action
application application
device_hostname firewall_name
dstDevice_ip dest_ip
dstPort dest_port
http_url http_url
ipProtocol protocol
resource flags
severity pan_severity
srcDevice_ip source_ip
srcPort source_port
success action This is a lookup field. More info to come in the catalog later...
threat_category category
threat_name threat_name
user_username source_user