diff --git a/uncoder-core/app/translator/mappings/platforms/palo_alto_cortex/default.yml b/uncoder-core/app/translator/mappings/platforms/palo_alto_cortex/default.yml index 6e5ca29a..f9fb63bd 100644 --- a/uncoder-core/app/translator/mappings/platforms/palo_alto_cortex/default.yml +++ b/uncoder-core/app/translator/mappings/platforms/palo_alto_cortex/default.yml @@ -41,5 +41,7 @@ field_mapping: dst-hostname: xdm.target.host.hostname icmp.type: xdm.network.icmp.type icmp.code: xdm.network.icmp.code - URL: xdm.target.url - QueryName: xdm.target.url + c-uri: xdm.network.http.url + c-uri-query: xdm.network.http.url + QueryName: xdm.network.dns.dns_question.name + Application: xdm.network.application_protocol diff --git a/uncoder-core/app/translator/mappings/platforms/palo_alto_cortex/firewall.yml b/uncoder-core/app/translator/mappings/platforms/palo_alto_cortex/firewall.yml index c6a9e9bf..fc18e036 100644 --- a/uncoder-core/app/translator/mappings/platforms/palo_alto_cortex/firewall.yml +++ b/uncoder-core/app/translator/mappings/platforms/palo_alto_cortex/firewall.yml @@ -51,4 +51,6 @@ field_mapping: ParentIntegrityLevel: causality_actor_process_integrity_level ParentLogonId: causality_actor_process_logon_id ParentProduct: causality_actor_process_signature_product - ParentCompany: causality_actor_process_signature_vendor \ No newline at end of file + ParentCompany: causality_actor_process_signature_vendor + Application: xdm.network.application_protocol + application: xdm.network.application_protocol \ No newline at end of file diff --git a/uncoder-core/app/translator/mappings/platforms/qradar/default.yml b/uncoder-core/app/translator/mappings/platforms/qradar/default.yml index f54c98a6..6a74486f 100644 --- a/uncoder-core/app/translator/mappings/platforms/qradar/default.yml +++ b/uncoder-core/app/translator/mappings/platforms/qradar/default.yml @@ -13,6 +13,7 @@ field_mapping: - DstPort - DestinationPort dst-hostname: DstHost + src-hostname: SrcHost src-port: SourcePort src-ip: - sourceip @@ -24,4 +25,7 @@ field_mapping: - destination_ip User: userName CommandLine: Command - Protocol: IPProtocol \ No newline at end of file + Protocol: IPProtocol + Application: + - Application + - application \ No newline at end of file diff --git a/uncoder-core/app/translator/mappings/platforms/qradar/dns.yml b/uncoder-core/app/translator/mappings/platforms/qradar/dns.yml index 3e3f6aec..dbd1ab9a 100644 --- a/uncoder-core/app/translator/mappings/platforms/qradar/dns.yml +++ b/uncoder-core/app/translator/mappings/platforms/qradar/dns.yml @@ -9,7 +9,7 @@ default_log_source: devicetype: 185 field_mapping: - dns-query: dns-query + dns-query: URL parent-domain: parent-domain dns-answer: dns-answer - dns-record: dns-record \ No newline at end of file + dns-record: URL \ No newline at end of file diff --git a/uncoder-core/app/translator/mappings/platforms/qradar/firewall.yml b/uncoder-core/app/translator/mappings/platforms/qradar/firewall.yml index 518a229c..34866616 100644 --- a/uncoder-core/app/translator/mappings/platforms/qradar/firewall.yml +++ b/uncoder-core/app/translator/mappings/platforms/qradar/firewall.yml @@ -9,7 +9,24 @@ default_log_source: devicetype: 4 field_mapping: - src-ip: sourceip - src-port: sourceport - dst-ip: destinationip - dst-port: sestinationport \ No newline at end of file + src-ip: + - sourceip + - SrcHost + - LocalHost + - Source + - NetworkView + src-port: + - sourceport + - SrcPort + - LocalPort + dst-ip: + - destinationip + - DstHost + - RemoteHost + - Destination + dst-port: + - destinationport + - DstPort + - RemotePort + Protocol: IPProtocol + Application: Application \ No newline at end of file diff --git a/uncoder-core/app/translator/mappings/platforms/qradar/proxy.yml b/uncoder-core/app/translator/mappings/platforms/qradar/proxy.yml index a8a79b2e..7cf88611 100644 --- a/uncoder-core/app/translator/mappings/platforms/qradar/proxy.yml +++ b/uncoder-core/app/translator/mappings/platforms/qradar/proxy.yml @@ -9,8 +9,10 @@ default_log_source: devicetype: 46 field_mapping: - c-uri: URL - c-useragent: c-useragent + c-uri: + - URL + - XForceCategoryByURL + c-useragent: User Agent cs-method: cs-method cs-bytes: Bytes Sent cs-cookie-vars: cs-cookie-vars