Collect Palo Alto Prisma Cloud logs
This document describes how you can collect Palo Alto Prisma Cloud logs by setting up a Google Security Operations feed.
For more information, see Data ingestion to Google Security Operations .
An ingestion label identifies the parser which normalizes raw log data
to structured UDM format. The information in this document applies to the parser
with the PAN_PRISMA_CLOUD 
ingestion label.
Configure Palo Alto Prisma Cloud
- Sign in to the Palo Alto Prisma Cloud Consolewith an administrator account.
- In the Settingsmenu, click Access Keys.
- Click Add Newand enter a Name.
-  Click Create. The Access Key IDand Secret Keyvalues appear. 
-  Save the Access Key IDand Secret Keyvalues. These values are required when you configure the Google Security Operations feed. 
Set up feeds
To configure a feed, follow these steps:
- Go to SIEM Settings > Feeds.
- Click Add New Feed.
- On the next page, click Configure a single feed.
- In the Feed namefield, enter a name for the feed; for example, Palo Alto Prisma Cloud Logs.
- Select Third party APIas the Source Type.
- Select Palo Alto Prisma Cloudas the Log Type.
- Click Next.
- Configure the following mandatory input parameters: - Username: specify the access key ID that you obtained previously.
- Password:specify the secret key that you obtained previously.
- API hostname: specify the API hostname.
 
- Click Nextand then click Submit.
Field mapping reference
This parser code extracts fields from JSON formatted PAN PRISMA CLOUD logs, performs data transformations and mappings to structure the data into the Chronicle UDM schema. It handles various log message structures, including nested objects and arrays, to normalize diverse security events and contextual information for analysis within Chronicle.
UDM Mapping Table
| Log Field | UDM Mapping | Logic | 
|---|---|---|
|   
accountName | read_only_udm.target.resource.attribute.cloud.project.id | Directly mapped from accountNamefield. | 
|   
accountId | read_only_udm.target.hostname | Directly mapped from accountIdfield. | 
|   
accountId | read_only_udm.target.asset.hostname | Directly mapped from accountIdfield. | 
|   
accountId | read_only_udm.principal.cloud.project.id | Directly mapped from accountIdfield in theaggregatedAlertsarray. | 
|   
action | read_only_udm.security_result.description | Directly mapped from actionfield after removing JSON part. | 
|   
alertId | read_only_udm.metadata.product_log_id | Directly mapped from alertIdfield. | 
|   
alertRules.0.allowAutoRemediate | read_only_udm.security_result.detection_fields.allowAutoRemediate_0 | Directly mapped from alertRules.0.allowAutoRemediatefield. | 
|   
alertRules.0.enabled | read_only_udm.security_result.detection_fields.enabled_0 | Directly mapped from alertRules.0.enabledfield. | 
|   
alertRules.0.name | read_only_udm.security_result.detection_fields.name_0 | Directly mapped from alertRules.0.namefield. | 
|   
alertRules.0.notifyOnDismissed | read_only_udm.security_result.detection_fields.notifyOnDismissed_0 | Directly mapped from alertRules.0.notifyOnDismissedfield. | 
|   
alertRules.0.notifyOnOpen | read_only_udm.security_result.detection_fields.notifyOnOpen_0 | Directly mapped from alertRules.0.notifyOnOpenfield. | 
|   
alertRules.0.notifyOnResolved | read_only_udm.security_result.detection_fields.notifyOnResolved_0 | Directly mapped from alertRules.0.notifyOnResolvedfield. | 
|   
alertRules.0.notifyOnSnoozed | read_only_udm.security_result.detection_fields.notifyOnSnoozed_0 | Directly mapped from alertRules.0.notifyOnSnoozedfield. | 
|   
alertRules.0.policyScanConfigId | read_only_udm.security_result.detection_fields.policyScanConfigId_0 | Directly mapped from alertRules.0.policyScanConfigIdfield. | 
|   
alertRules.0.scanAll | read_only_udm.security_result.detection_fields.scanAll_0 | Directly mapped from alertRules.0.scanAllfield. | 
|   
alertRules.1.allowAutoRemediate | read_only_udm.security_result.detection_fields.allowAutoRemediate_1 | Directly mapped from alertRules.1.allowAutoRemediatefield. | 
|   
alertRules.1.createdBy | read_only_udm.principal.user.email_addresses | Directly mapped from alertRules.1.createdByfield. | 
|   
alertRules.1.enabled | read_only_udm.security_result.detection_fields.enabled_1 | Directly mapped from alertRules.1.enabledfield. | 
|   
alertRules.1.name | read_only_udm.security_result.detection_fields.name_1 | Directly mapped from alertRules.1.namefield. | 
|   
alertRules.1.notifyOnDismissed | read_only_udm.security_result.detection_fields.notifyOnDismissed_1 | Directly mapped from alertRules.1.notifyOnDismissedfield. | 
|   
alertRules.1.notifyOnOpen | read_only_udm.security_result.detection_fields.notifyOnOpen_1 | Directly mapped from alertRules.1.notifyOnOpenfield. | 
|   
alertRules.1.notifyOnResolved | read_only_udm.security_result.detection_fields.notifyOnResolved_1 | Directly mapped from alertRules.1.notifyOnResolvedfield. | 
|   
alertRules.1.notifyOnSnoozed | read_only_udm.security_result.detection_fields.notifyOnSnoozed_1 | Directly mapped from alertRules.1.notifyOnSnoozedfield. | 
|   
alertRules.1.policyScanConfigId | read_only_udm.security_result.detection_fields.policyScanConfigId_1 | Directly mapped from alertRules.1.policyScanConfigIdfield. | 
|   
alertRules.1.scanAll | read_only_udm.security_result.detection_fields.scanAll_1 | Directly mapped from alertRules.1.scanAllfield. | 
|   
alertRules.2.allowAutoRemediate | read_only_udm.security_result.detection_fields.allowAutoRemediate_2 | Directly mapped from alertRules.2.allowAutoRemediatefield. | 
|   
alertRules.2.createdBy | read_only_udm.principal.user.email_addresses | Directly mapped from alertRules.2.createdByfield. | 
|   
alertRules.2.enabled | read_only_udm.security_result.detection_fields.enabled_2 | Directly mapped from alertRules.2.enabledfield. | 
|   
alertRules.2.name | read_only_udm.security_result.detection_fields.name_2 | Directly mapped from alertRules.2.namefield. | 
|   
alertRules.2.notifyOnDismissed | read_only_udm.security_result.detection_fields.notifyOnDismissed_2 | Directly mapped from alertRules.2.notifyOnDismissedfield. | 
|   
alertRules.2.notifyOnOpen | read_only_udm.security_result.detection_fields.notifyOnOpen_2 | Directly mapped from alertRules.2.notifyOnOpenfield. | 
|   
alertRules.2.notifyOnResolved | read_only_udm.security_result.detection_fields.notifyOnResolved_2 | Directly mapped from alertRules.2.notifyOnResolvedfield. | 
|   
alertRules.2.notifyOnSnoozed | read_only_udm.security_result.detection_fields.notifyOnSnoozed_2 | Directly mapped from alertRules.2.notifyOnSnoozedfield. | 
|   
alertRules.2.policyScanConfigId | read_only_udm.security_result.detection_fields.policyScanConfigId_2 | Directly mapped from alertRules.2.policyScanConfigIdfield. | 
|   
alertRules.2.scanAll | read_only_udm.security_result.detection_fields.scanAll_2 | Directly mapped from alertRules.2.scanAllfield. | 
|   
alertRuleId | read_only_udm.security_result.rule_id | Directly mapped from alertRuleIdfield. | 
|   
alertRuleName | read_only_udm.security_result.rule_name | Directly mapped from alertRuleNamefield. | 
|   
alertStatus | read_only_udm.security_result.detection_fields.event message alertStatus | Directly mapped from alertStatusfield in theevent_data.msg_dataobject. | 
|   
alertTs | read_only_udm.metadata.event_timestamp.seconds | Directly mapped from alertTsfield after converting to UNIX timestamp. | 
|   
alertTs | read_only_udm.metadata.event_timestamp.nanos | Directly mapped from alertTsfield after converting to UNIX timestamp. | 
|   
callbackUrl | read_only_udm.metadata.url_back_to_product | Directly mapped from callbackUrlfield. | 
|   
cloudServiceName | read_only_udm.target.resource.attribute.labels.cloudServiceName | Directly mapped from cloudServiceNamefield. | 
|   
cloudType | read_only_udm.target.resource.attribute.cloud.environment | Mapped from cloudTypefield. IfcloudTypeis "gcp", the value is set to "GOOGLE_CLOUD_PLATFORM". IfcloudTypeis "aws", the value is set to "AMAZON_WEB_SERVICES". | 
|   
complianceMetadata.0.requirementId | read_only_udm.security_result.rule_id | Directly mapped from complianceMetadata.0.requirementIdfield. | 
|   
complianceMetadata.0.requirementName | read_only_udm.security_result.summary | Directly mapped from complianceMetadata.0.requirementNamefield. | 
|   
complianceMetadata.0.standardName | read_only_udm.security_result.rule_name | Directly mapped from complianceMetadata.0.standardNamefield. | 
|   
complianceMetadata.1.requirementId | read_only_udm.security_result.rule_id | Directly mapped from complianceMetadata.1.requirementIdfield. | 
|   
complianceMetadata.1.requirementName | read_only_udm.security_result.summary | Directly mapped from complianceMetadata.1.requirementNamefield. | 
|   
complianceMetadata.1.standardName | read_only_udm.security_result.rule_name | Directly mapped from complianceMetadata.1.standardNamefield. | 
|   
complianceMetadata.2.requirementId | read_only_udm.security_result.rule_id | Directly mapped from complianceMetadata.2.requirementIdfield. | 
|   
complianceMetadata.2.requirementName | read_only_udm.security_result.summary | Directly mapped from complianceMetadata.2.requirementNamefield. | 
|   
complianceMetadata.2.standardName | read_only_udm.security_result.rule_name | Directly mapped from complianceMetadata.2.standardNamefield. | 
|   
complianceMetadata.3.requirementId | read_only_udm.security_result.rule_id | Directly mapped from complianceMetadata.3.requirementIdfield. | 
|   
complianceMetadata.3.requirementName | read_only_udm.security_result.summary | Directly mapped from complianceMetadata.3.requirementNamefield. | 
|   
complianceMetadata.3.standardName | read_only_udm.security_result.rule_name | Directly mapped from complianceMetadata.3.standardNamefield. | 
|   
complianceMetadata.4.requirementId | read_only_udm.security_result.rule_id | Directly mapped from complianceMetadata.4.requirementIdfield. | 
|   
complianceMetadata.4.requirementName | read_only_udm.security_result.summary | Directly mapped from complianceMetadata.4.requirementNamefield. | 
|   
complianceMetadata.4.standardName | read_only_udm.security_result.rule_name | Directly mapped from complianceMetadata.4.standardNamefield. | 
|   
event_data.app | read_only_udm.target.application | Directly mapped from event_data.appfield. | 
|   
event_data.msg_data.account.cloudType | read_only_udm.target.resource.attribute.cloud.environment | Mapped from event_data.msg_data.account.cloudTypefield. If the value is "aws", it is set to "AMAZON_WEB_SERVICES". | 
|   
event_data.msg_data.account.id | read_only_udm.target.cloud.project.id | Directly mapped from event_data.msg_data.account.idfield. | 
|   
event_data.msg_data.account.name | read_only_udm.target.cloud.project.name | Directly mapped from event_data.msg_data.account.namefield. | 
|   
event_data.msg_data.accountIDs | read_only_udm.principal.resource.attribute.labels.event message accountId {index} | Directly mapped from event_data.msg_data.accountIDsarray. | 
|   
event_data.msg_data.aggregatedAlerts.0.category | read_only_udm.security_result.category_details | Directly mapped from event_data.msg_data.aggregatedAlerts.0.categoryfield. | 
|   
event_data.msg_data.aggregatedAlerts.0.command | read_only_udm.principal.process.command_line | Directly mapped from event_data.msg_data.aggregatedAlerts.0.commandfield. | 
|   
event_data.msg_data.aggregatedAlerts.0.collections | read_only_udm.target.resource.attribute.labels.Collection {index} | Directly mapped from event_data.msg_data.aggregatedAlerts.0.collectionsarray. | 
|   
event_data.msg_data.aggregatedAlerts.0.complianceIssues.0.category | read_only_udm.security_result.category_details | Directly mapped from event_data.msg_data.aggregatedAlerts.0.complianceIssues.0.categoryfield. | 
|   
event_data.msg_data.aggregatedAlerts.0.complianceIssues.0.description | read_only_udm.security_result.description | Directly mapped from event_data.msg_data.aggregatedAlerts.0.complianceIssues.0.descriptionfield. | 
|   
event_data.msg_data.aggregatedAlerts.0.complianceIssues.0.severity | read_only_udm.security_result.severity | Directly mapped from event_data.msg_data.aggregatedAlerts.0.complianceIssues.0.severityfield after converting to uppercase. | 
|   
event_data.msg_data.aggregatedAlerts.0.complianceIssues.0.title | read_only_udm.security_result.action_details | Directly mapped from event_data.msg_data.aggregatedAlerts.0.complianceIssues.0.titlefield. | 
|   
event_data.msg_data.aggregatedAlerts.0.container | read_only_udm.target.resource.name | Directly mapped from event_data.msg_data.aggregatedAlerts.0.containerfield. | 
|   
event_data.msg_data.aggregatedAlerts.0.containerID | read_only_udm.target.resource.product_object_id | Directly mapped from event_data.msg_data.aggregatedAlerts.0.containerIDfield. | 
|   
event_data.msg_data.aggregatedAlerts.0.fqdn | read_only_udm.principal.domain.name | Directly mapped from event_data.msg_data.aggregatedAlerts.0.fqdnfield. | 
|   
event_data.msg_data.aggregatedAlerts.0.host | read_only_udm.principal.hostname | Directly mapped from event_data.msg_data.aggregatedAlerts.0.hostfield. | 
|   
event_data.msg_data.aggregatedAlerts.0.host | read_only_udm.principal.asset.hostname | Directly mapped from event_data.msg_data.aggregatedAlerts.0.hostfield. | 
|   
event_data.msg_data.aggregatedAlerts.0.image | read_only_udm.target.resource.attribute.labels.image | Directly mapped from event_data.msg_data.aggregatedAlerts.0.imagefield. | 
|   
event_data.msg_data.aggregatedAlerts.0.imageID | read_only_udm.target.resource.attribute.labels.imageID | Directly mapped from event_data.msg_data.aggregatedAlerts.0.imageIDfield. | 
|   
event_data.msg_data.aggregatedAlerts.0.labels.controller-uid | read_only_udm.target.user.product_object_id | Directly mapped from event_data.msg_data.aggregatedAlerts.0.labels.controller-uidfield. | 
|   
event_data.msg_data.aggregatedAlerts.0.labels.io.kubernetes.pod.name | read_only_udm.target.hostname | Directly mapped from event_data.msg_data.aggregatedAlerts.0.labels.io.kubernetes.pod.namefield. | 
|   
event_data.msg_data.aggregatedAlerts.0.labels.io.kubernetes.pod.uid | read_only_udm.target.resource.product_object_id | Directly mapped from event_data.msg_data.aggregatedAlerts.0.labels.io.kubernetes.pod.uidfield. | 
|   
event_data.msg_data.aggregatedAlerts.0.msg_data | read_only_udm.security_result.description | Directly mapped from event_data.msg_data.aggregatedAlerts.0.msg_datafield. | 
|   
event_data.msg_data.aggregatedAlerts.0.rule | read_only_udm.security_result.rule_name | Directly mapped from event_data.msg_data.aggregatedAlerts.0.rulefield. | 
|   
event_data.msg_data.aggregatedAlerts.0.startupProcess | read_only_udm.principal.application | Directly mapped from event_data.msg_data.aggregatedAlerts.0.startupProcessfield. | 
|   
event_data.msg_data.aggregatedAlerts.0.time | read_only_udm.metadata.event_timestamp.seconds | Directly mapped from event_data.msg_data.aggregatedAlerts.0.timefield after converting to UNIX timestamp. | 
|   
event_data.msg_data.aggregatedAlerts.0.time | read_only_udm.metadata.event_timestamp.nanos | Directly mapped from event_data.msg_data.aggregatedAlerts.0.timefield after converting to UNIX timestamp. | 
|   
event_data.msg_data.aggregatedAlerts.0.type | read_only_udm.security_result.category_details | Directly mapped from event_data.msg_data.aggregatedAlerts.0.typefield. | 
|   
event_data.msg_data.aggregatedAlerts.0.user | read_only_udm.principal.user.userid | Directly mapped from event_data.msg_data.aggregatedAlerts.0.userfield. | 
|   
event_data.msg_data.alertId | read_only_udm.security_result.detection_fields.event message alertId | Directly mapped from event_data.msg_data.alertIdfield. | 
|   
event_data.msg_data.alertRuleId | read_only_udm.security_result.rule_id | Directly mapped from event_data.msg_data.alertRuleIdfield. | 
|   
event_data.msg_data.alertRuleName | read_only_udm.security_result.rule_name | Directly mapped from event_data.msg_data.alertRuleNamefield. | 
|   
event_data.msg_data.alertStatus | read_only_udm.security_result.detection_fields.event message alertStatus | Directly mapped from event_data.msg_data.alertStatusfield. | 
|   
event_data.msg_data.alertTs | read_only_udm.metadata.event_timestamp.seconds | Directly mapped from event_data.msg_data.alertTsfield after converting to UNIX timestamp. | 
|   
event_data.msg_data.alertTs | read_only_udm.metadata.event_timestamp.nanos | Directly mapped from event_data.msg_data.alertTsfield after converting to UNIX timestamp. | 
|   
event_data.msg_data.category | read_only_udm.security_result.category_details | Directly mapped from event_data.msg_data.categoryfield. | 
|   
event_data.msg_data.collections | read_only_udm.target.resource.attribute.labels.Collection {index} | Directly mapped from event_data.msg_data.collectionsarray. | 
|   
event_data.msg_data.command | read_only_udm.principal.process.command_line | Directly mapped from event_data.msg_data.commandfield. | 
|   
event_data.msg_data.complianceIssues.0.category | read_only_udm.security_result.category_details | Directly mapped from event_data.msg_data.complianceIssues.0.categoryfield. | 
|   
event_data.msg_data.complianceIssues.0.description | read_only_udm.security_result.description | Directly mapped from event_data.msg_data.complianceIssues.0.descriptionfield. | 
|   
event_data.msg_data.complianceIssues.0.severity | read_only_udm.security_result.severity | Directly mapped from event_data.msg_data.complianceIssues.0.severityfield after converting to uppercase. | 
|   
event_data.msg_data.complianceIssues.0.title | read_only_udm.security_result.action_details | Directly mapped from event_data.msg_data.complianceIssues.0.titlefield. | 
|   
event_data.msg_data.container | read_only_udm.target.resource.name | Directly mapped from event_data.msg_data.containerfield. | 
|   
event_data.msg_data.containerID | read_only_udm.target.resource.product_object_id | Directly mapped from event_data.msg_data.containerIDfield. | 
|   
event_data.msg_data.dropped | read_only_udm.security_result.detection_fields.dropped | Directly mapped from event_data.msg_data.droppedfield after converting to string. | 
|   
event_data.msg_data.fqdn | read_only_udm.principal.domain.name | Directly mapped from event_data.msg_data.fqdnfield. | 
|   
event_data.msg_data.firstSeen | read_only_udm.security_result.first_discovered_time.seconds | Directly mapped from event_data.msg_data.firstSeenfield after converting to UNIX timestamp. | 
|   
event_data.msg_data.firstSeen | read_only_udm.security_result.first_discovered_time.nanos | Directly mapped from event_data.msg_data.firstSeenfield after converting to UNIX timestamp. | 
|   
event_data.msg_data.host | read_only_udm.principal.hostname | Directly mapped from event_data.msg_data.hostfield. | 
|   
event_data.msg_data.host | read_only_udm.principal.asset.hostname | Directly mapped from event_data.msg_data.hostfield. | 
|   
event_data.msg_data.image | read_only_udm.target.resource.attribute.labels.image | Directly mapped from event_data.msg_data.imagefield. | 
|   
event_data.msg_data.imageID | read_only_udm.target.resource.attribute.labels.imageID | Directly mapped from event_data.msg_data.imageIDfield. | 
|   
event_data.msg_data.labels.controller-uid | read_only_udm.target.user.product_object_id | Directly mapped from event_data.msg_data.labels.controller-uidfield. | 
|   
event_data.msg_data.labels.io.kubernetes.pod.name | read_only_udm.target.hostname | Directly mapped from event_data.msg_data.labels.io.kubernetes.pod.namefield. | 
|   
event_data.msg_data.labels.io.kubernetes.pod.uid | read_only_udm.target.resource.product_object_id | Directly mapped from event_data.msg_data.labels.io.kubernetes.pod.uidfield. | 
|   
event_data.msg_data.lastSeen | read_only_udm.security_result.last_discovered_time.seconds | Directly mapped from event_data.msg_data.lastSeenfield after converting to UNIX timestamp. | 
|   
event_data.msg_data.lastSeen | read_only_udm.security_result.last_discovered_time.nanos | Directly mapped from event_data.msg_data.lastSeenfield after converting to UNIX timestamp. | 
|   
event_data.msg_data.metadata.cveCritical | read_only_udm.security_result.detection_fields.event_data metadata cveCritical | Directly mapped from event_data.msg_data.metadata.cveCriticalfield. | 
|   
event_data.msg_data.metadata.cveHigh | read_only_udm.security_result.detection_fields.event_data metadata cveHigh | Directly mapped from event_data.msg_data.metadata.cveHighfield. | 
|   
event_data.msg_data.metadata.cveLow | read_only_udm.security_result.detection_fields.event_data metadata cveLow | Directly mapped from event_data.msg_data.metadata.cveLowfield. | 
|   
event_data.msg_data.metadata.cveMedium | read_only_udm.security_result.detection_fields.event_data metadata cveMedium | Directly mapped from event_data.msg_data.metadata.cveMediumfield. | 
|   
event_data.msg_data.metadata.source | read_only_udm.principal.hostname | Directly mapped from event_data.msg_data.metadata.sourcefield. | 
|   
event_data.msg_data.metadata.source | read_only_udm.principal.asset.hostname | Directly mapped from event_data.msg_data.metadata.sourcefield. | 
|   
event_data.msg_data.msg_data | read_only_udm.security_result.description | Directly mapped from event_data.msg_data.msg_datafield. | 
|   
event_data.msg_data.policy.description | read_only_udm.security_result.description | Directly mapped from event_data.msg_data.policy.descriptionfield. | 
|   
event_data.msg_data.policy.id | read_only_udm.security_result.detection_fields.policy_id | Directly mapped from event_data.msg_data.policy.idfield. | 
|   
event_data.msg_data.policy.name | read_only_udm.security_result.summary | Directly mapped from event_data.msg_data.policy.namefield. | 
|   
event_data.msg_data.policy.policyTs | read_only_udm.additional.fields.policy_ts | Directly mapped from event_data.msg_data.policy.policyTsfield. | 
|   
event_data.msg_data.policy.policyType | read_only_udm.security_result.threat_name | Directly mapped from event_data.msg_data.policy.policyTypefield. | 
|   
event_data.msg_data.policy.recommendation | read_only_udm.security_result.action_details | Directly mapped from event_data.msg_data.policy.recommendationfield. | 
|   
event_data.msg_data.policy.severity | read_only_udm.security_result.severity | Directly mapped from event_data.msg_data.policy.severityfield after converting to uppercase. | 
|   
event_data.msg_data.reason | read_only_udm.security_result.detection_fields.event message reason | Directly mapped from event_data.msg_data.reasonfield. | 
|   
event_data.msg_data.region | read_only_udm.target.cloud.availability_zone | Directly mapped from event_data.msg_data.regionfield. | 
|   
event_data.msg_data.resource.resourceId | read_only_udm.target.resource.product_object_id | Directly mapped from event_data.msg_data.resource.resourceIdfield. | 
|   
event_data.msg_data.resource.resourceName | read_only_udm.target.resource.name | Directly mapped from event_data.msg_data.resource.resourceNamefield. | 
|   
event_data.msg_data.resource.resourceTs | read_only_udm.target.resource.attribute.creation_time.seconds | Directly mapped from event_data.msg_data.resource.resourceTsfield after converting to UNIX timestamp. | 
|   
event_data.msg_data.resource.resourceTs | read_only_udm.target.resource.attribute.creation_time.nanos | Directly mapped from event_data.msg_data.resource.resourceTsfield after converting to UNIX timestamp. | 
|   
event_data.msg_data.rule | read_only_udm.security_result.rule_name | Directly mapped from event_data.msg_data.rulefield. | 
|   
event_data.msg_data.service | read_only_udm.security_result.detection_fields.event message service | Directly mapped from event_data.msg_data.servicefield. | 
|   
event_data.msg_data.startupProcess | read_only_udm.principal.application | Directly mapped from event_data.msg_data.startupProcessfield. | 
|   
event_data.msg_data.time | read_only_udm.metadata.event_timestamp.seconds | Directly mapped from event_data.msg_data.timefield after converting to UNIX timestamp. | 
|   
event_data.msg_data.time | read_only_udm.metadata.event_timestamp.nanos | Directly mapped from event_data.msg_data.timefield after converting to UNIX timestamp. | 
|   
event_data.msg_data.type | read_only_udm.security_result.category_details | Directly mapped from event_data.msg_data.typefield. | 
|   
event_data.sentTs | read_only_udm.metadata.event_timestamp.seconds | Directly mapped from event_data.sentTsfield after converting to UNIX timestamp. | 
|   
event_data.sentTs | read_only_udm.metadata.event_timestamp.nanos | Directly mapped from event_data.sentTsfield after converting to UNIX timestamp. | 
|   
event_data.type | read_only_udm.security_result.category_details | Directly mapped from event_data.typefield. | 
|   
ipAddress | read_only_udm.principal.ip | Directly mapped from ipAddressfield after extracting IP address using grok. | 
|   
ipAddress | read_only_udm.principal.asset.ip | Directly mapped from ipAddressfield after extracting IP address using grok. | 
|   
ipAddress | read_only_udm.additional.fields.ipAddress | Directly mapped from ipAddressfield if it is not a valid IP address. | 
|   
json_action.0.policy_id | read_only_udm.target.resource.attribute.labels.Policy Id 0 | Directly mapped from json_action.0.policy_idfield. | 
|   
json_action.0.resource_name | read_only_udm.target.resource.attribute.labels.Resource Name 0 | Directly mapped from json_action.0.resource_namefield. | 
|   
json_action.1.policy_id | read_only_udm.target.resource.attribute.labels.Policy Id 1 | Directly mapped from json_action.1.policy_idfield. | 
|   
json_action.1.resource_name | read_only_udm.target.resource.attribute.labels.Resource Name 1 | Directly mapped from json_action.1.resource_namefield. | 
|   
policy.policyId | read_only_udm.security_result.rule_id | Directly mapped from policy.policyIdfield. | 
|   
policy.policyType | read_only_udm.security_result.rule_type | Directly mapped from policy.policyTypefield. | 
|   
policy.recommendation | read_only_udm.metadata.description | Directly mapped from policy.recommendationfield. | 
|   
policy.severity | read_only_udm.security_result.severity | Mapped from policy.severityfield. If the value is "info", it is set to "INFORMATIONAL". | 
|   
policyName | read_only_udm.metadata.description | Directly mapped from policyNamefield. | 
|   
reason | read_only_udm.metadata.product_event_type | Directly mapped from reasonfield. | 
|   
resource.accountId | read_only_udm.target.resource.product_object_id | Directly mapped from resource.accountIdfield. | 
|   
resource.cloudServiceName | read_only_udm.target.resource.attribute.labels.cloudServiceName | Directly mapped from resource.cloudServiceNamefield. | 
|   
resource.data.architecture | read_only_udm.principal.asset.hardware.cpu_platform | Directly mapped from resource.data.architecturefield. | 
|   
resource.data.cpuPlatform | read_only_udm.additional.fields.CPU Platform | Directly mapped from resource.data.cpuPlatformfield. | 
|   
resource.data.labelFingerprint | read_only_udm.security_result.detection_fields.labelFingerprint | Directly mapped from resource.data.labelFingerprintfield. | 
|   
resource.data.metadata.items.key | read_only_udm.additional.fields.key | Directly mapped from resource.data.metadata.items.keyfield. | 
|   
resource.data.metadata.items.value | read_only_udm.additional.fields.value.string_value | Directly mapped from resource.data.metadata.items.valuefield. | 
|   
resource.data.networkInterfaces.0.accessConfigs.0.natIP | read_only_udm.target.nat_ip | Directly mapped from resource.data.networkInterfaces.0.accessConfigs.0.natIPfield. | 
|   
resource.data.networkInterfaces.0.networkIP | read_only_udm.target.ip | Directly mapped from resource.data.networkInterfaces.0.networkIPfield. | 
|   
resource.data.networkInterfaces.0.networkIP | read_only_udm.target.asset.ip | Directly mapped from resource.data.networkInterfaces.0.networkIPfield. | 
|   
resource.data.physicalBlockSizeBytes | read_only_udm.principal.resource.attribute.labels.physicalBlockSizeBytes | Directly mapped from resource.data.physicalBlockSizeBytesfield after converting to string. | 
|   
resource.data.selfLink | read_only_udm.about.url | Directly mapped from resource.data.selfLinkfield. | 
|   
resource.data.serviceAccounts.0.email | read_only_udm.principal.user.email_addresses | Directly mapped from resource.data.serviceAccounts.0.emailfield. | 
|   
resource.data.serviceAccounts.0.email | read_only_udm.principal.user.attribute.roles.type | If resource.data.serviceAccounts.0.emailcontains "serviceaccount", the value is set to "SERVICE_ACCOUNT". | 
|   
resource.data.sizeGb | read_only_udm.principal.resource.attribute.labels.sizeGb | Directly mapped from resource.data.sizeGbfield. | 
|   
resource.data.sourceImage | read_only_udm.principal.resource.attribute.labels.sourceImage | Directly mapped from resource.data.sourceImagefield. | 
|   
resource.name | read_only_udm.target.resource.name | Directly mapped from resource.namefield. | 
|   
resource.regionId | read_only_udm.target.location.country_or_region | Directly mapped from `resource | 
Need more help? Get answers from Community members and Google SecOps professionals.

