edr.paloalto
Introduction
The tags beginning with edr.paloalto
identify events generated by Palo Alto Cortex XDR services.
Tag structure
The full tag must have 3 levels. The first two are fixed as edr.paloalto
. The third level identifies the type of event sent.
Therefore, the valid tags and tables include:
Product / Services | Tags | Data tables |
---|---|---|
Palo Alto Cortex XDR |
|
|
|
| |
Palo Alto Networks Traps |
|
|
How is the data sent to Devo?
You can send your events to Devo using the Devo Relay and configuring the following rules. Learn how to configure rules for your relay in Defining a relay rule.
Relay rule 1 - edr.paloalto.cortex_xdr events
After setting up your relay, define a new rule using the following configuration:
Source port |
|
---|---|
Source data |
|
Target message |
|
Target tag |
|
Stop processing | ✓ |
Send without syslog tag | ✓ |
Relay rule 2 - edr.paloalto.cortex_xdr_agent events
After setting up your relay, define a new rule using the following configuration:
Source port |
|
---|---|
Source data |
|
Target message |
|
Target tag |
|
Stop processing | ✓ |
Send without syslog tag | ✓ |
Table structure
These are the fields displayed in these tables:
edr.paloalto.cortex_xdr
Field | Type | Extra fields |
---|---|---|
eventdate |
| Â |
hostname |
| Â |
cefTag |
| Â |
cefVersion |
| Â |
embDeviceVendor |
| Â |
embDeviceProduct |
| Â |
deviceVersion |
| Â |
signatureID |
| Â |
name |
| Â |
severity |
| Â |
act |
| Â |
app |
| Â |
cat |
| Â |
cs1Label |
| Â |
cs1 |
| Â |
cs2Label |
| Â |
cs2 |
| Â |
cs3Label |
| Â |
cs3 |
| Â |
cs4Label |
| Â |
cs4 |
| Â |
cs5Label |
| Â |
cs5 |
| Â |
cs6Label |
| Â |
cs6 |
| Â |
dpt |
| Â |
dst |
| Â |
end |
| Â |
deviceFacility |
| Â |
externalId |
| Â |
fileHash |
| Â |
filePath |
| Â |
msg |
| Â |
request |
| Â |
shost |
| Â |
spt |
| Â |
src |
| Â |
suser |
| Â |
cgoSha256 |
| Â |
tenantname |
| Â |
tenantCDLid |
| Â |
targetprocessname |
| Â |
targetprocesscmd |
| Â |
targetprocesssha256 |
| Â |
targetprocesssignature |
| Â |
mitreTactic |
| Â |
mitreTechnique |
| Â |
initiatorSha256 |
| Â |
initiatorPath |
| Â |
osParentName |
| Â |
osParentCmd |
| Â |
osParentSha256 |
| Â |
osParentSigner |
| Â |
osParentSignature |
| Â |
CSPaccountname |
| Â |
incident |
| Â |
hostchain |
|  ✓ |
tag |
|  ✓ |
rawMessage |
| Â |
edr.paloalto.cortex_xdr_agent
Field | Type | Extra fields |
---|---|---|
eventdate |
| Â |
hostname |
| Â |
cefTag |
| Â |
cefVersion |
| Â |
embDeviceVendor |
| Â |
embDeviceProduct |
| Â |
deviceVersion |
| Â |
signatureID |
| Â |
name |
| Â |
severity |
| Â |
cat |
| Â |
cs1Label |
| Â |
cs1 |
| Â |
cs2Label |
| Â |
cs2 |
| Â |
cs3Label |
| Â |
cs3 |
| Â |
cs4Label |
| Â |
cs4 |
| Â |
dvchost |
| Â |
end |
| Â |
msg |
| Â |
rt |
| Â |
shost |
| Â |
tenantname |
| Â |
tenantCDLid |
| Â |
CSPaccountname |
| Â |
hostchain |
|  ✓ |
tag |
|  ✓ |
rawMessage |
|  ✓ |
edr.paloalto.traps
Field | Type | Extra fields |
---|---|---|
eventdate |
| Â |
cefTag |
| Â |
cefVersion |
| Â |
embDeviceVendor |
| Â |
embDeviceProduct |
| Â |
deviceVersion |
| Â |
signatureID |
| Â |
name |
| Â |
severity |
| Â |
eventId |
| Â |
msg |
| Â |
art |
| Â |
deviceSeverity |
| Â |
rt |
| Â |
dhost |
| Â |
duser |
| Â |
fileHash |
| Â |
cs2 |
| Â |
cs3 |
| Â |
cs5 |
| Â |
cs2Label |
| Â |
cs3Label |
| Â |
cs5Label |
| Â |
ahost |
| Â |
agt |
| Â |
agentZoneURI |
| Â |
amac |
| Â |
av |
| Â |
atz |
| Â |
at |
| Â |
dvchost |
| Â |
dvc |
| Â |
deviceZoneURI |
| Â |
dtz |
| Â |
deviceProcessName |
| Â |
_cefVer |
| Â |
aid |
| Â |
rawMessage |
| ✓ |
hostchain |
| ✓ |