<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Connecting Firewalls to Azure Log Analytics / Sentinel CEF map log fields in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/connecting-firewalls-to-azure-log-analytics-sentinel-cef-map-log/m-p/343011#M2431</link>
    <description>&lt;P&gt;Hi, how can we achieve creating additional fields for logs being processed in "CommonSecurityLog" (&lt;A href="https://docs.microsoft.com/en-us/azure/azure-monitor/reference/tables/commonsecuritylog" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/azure/azure-monitor/reference/tables/commonsecuritylog&lt;/A&gt;) when sending in logs using the described log connector from Azure Sentinel using Syslog? At the moment incoming data gets mapped to fields like "DeviceCustomString1" or "DeviceCustomString1Label" using CEF. Is it possible creating additional/custom fields in "CommonSecurityLog"?!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We try connecting Palo Alto Networks firewalling infrastructure to Azure Log Analytics / Sentinel exactly following the guide (Azure Sentinel workspaces &amp;gt; Azure Sentinel | Data connectors &amp;gt; Palo Alto Networks) in Sentinel but we see a lot of incoming data being mapped to fields like "DeviceCustomString1" which don't have a characteristic name. (e.g. "Session ID" -&amp;gt; "DeviceCustomString1", Rule Name -&amp;gt; "DeviceCustomString2"). The real field names get stored in the label fields like "DeviceCustomString2Label".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks and really appreciate your help on that!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Snap 2020-08-10 at 13.57.21p.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27235iB2CF719147E3A38E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Snap 2020-08-10 at 13.57.21p.png" alt="Snap 2020-08-10 at 13.57.21p.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Snap 2020-08-10 at 13.56.27.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27236iFDAFC7B41E3C1344/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Snap 2020-08-10 at 13.56.27.png" alt="Snap 2020-08-10 at 13.56.27.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 10 Aug 2020 12:25:14 GMT</pubDate>
    <dc:creator>pschoenegger-gm</dc:creator>
    <dc:date>2020-08-10T12:25:14Z</dc:date>
    <item>
      <title>Connecting Firewalls to Azure Log Analytics / Sentinel CEF map log fields</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/connecting-firewalls-to-azure-log-analytics-sentinel-cef-map-log/m-p/343011#M2431</link>
      <description>&lt;P&gt;Hi, how can we achieve creating additional fields for logs being processed in "CommonSecurityLog" (&lt;A href="https://docs.microsoft.com/en-us/azure/azure-monitor/reference/tables/commonsecuritylog" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/azure/azure-monitor/reference/tables/commonsecuritylog&lt;/A&gt;) when sending in logs using the described log connector from Azure Sentinel using Syslog? At the moment incoming data gets mapped to fields like "DeviceCustomString1" or "DeviceCustomString1Label" using CEF. Is it possible creating additional/custom fields in "CommonSecurityLog"?!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We try connecting Palo Alto Networks firewalling infrastructure to Azure Log Analytics / Sentinel exactly following the guide (Azure Sentinel workspaces &amp;gt; Azure Sentinel | Data connectors &amp;gt; Palo Alto Networks) in Sentinel but we see a lot of incoming data being mapped to fields like "DeviceCustomString1" which don't have a characteristic name. (e.g. "Session ID" -&amp;gt; "DeviceCustomString1", Rule Name -&amp;gt; "DeviceCustomString2"). The real field names get stored in the label fields like "DeviceCustomString2Label".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks and really appreciate your help on that!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Snap 2020-08-10 at 13.57.21p.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27235iB2CF719147E3A38E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Snap 2020-08-10 at 13.57.21p.png" alt="Snap 2020-08-10 at 13.57.21p.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Snap 2020-08-10 at 13.56.27.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27236iFDAFC7B41E3C1344/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Snap 2020-08-10 at 13.56.27.png" alt="Snap 2020-08-10 at 13.56.27.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 12:25:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/connecting-firewalls-to-azure-log-analytics-sentinel-cef-map-log/m-p/343011#M2431</guid>
      <dc:creator>pschoenegger-gm</dc:creator>
      <dc:date>2020-08-10T12:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting Firewalls to Azure Log Analytics / Sentinel CEF map log fiel</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/connecting-firewalls-to-azure-log-analytics-sentinel-cef-map-log/m-p/344194#M2440</link>
      <description>&lt;P&gt;For better or worse, this is how CEF works. You can create a better view for your analyst or rule writer in Azure Sentinel by using KQL functions as describe in&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/t5/azure-sentinel/using-kql-functions-to-speed-up-analysis-in-azure-sentinel/ba-p/712381" target="_blank" rel="noopener"&gt;Using KQL functions to speed up analysis in Azure Sentinel&lt;/A&gt;&amp;nbsp;that will rename the relevant fields to your liking.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 13:11:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/connecting-firewalls-to-azure-log-analytics-sentinel-cef-map-log/m-p/344194#M2440</guid>
      <dc:creator>Shezaf</dc:creator>
      <dc:date>2020-08-17T13:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting Firewalls to Azure Log Analytics / Sentinel CEF map log fiel</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/connecting-firewalls-to-azure-log-analytics-sentinel-cef-map-log/m-p/345101#M2443</link>
      <description>&lt;P&gt;Many thanks for your help on renaming relevant fields! That's great!&lt;/P&gt;</description>
      <pubDate>Sun, 23 Aug 2020 13:29:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/connecting-firewalls-to-azure-log-analytics-sentinel-cef-map-log/m-p/345101#M2443</guid>
      <dc:creator>pschoenegger-gm</dc:creator>
      <dc:date>2020-08-23T13:29:53Z</dc:date>
    </item>
  </channel>
</rss>

