creating additional/custom fields in "CommonSecurityLog" currently stored as e.g. "DeviceCustomString1"

Peter Schönegger 21 Reputation points
2020-08-10T13:07:15.697+00:00

Hi,

how can we achieve creating additional fields for logs being processed in "CommonSecurityLog" (https://learn.microsoft.com/en-us/azure/azure-monitor/reference/tables/commonsecuritylog)? At the moment incoming data gets mapped to fields like "DeviceCustomString1" or "DeviceCustomString1Label" using CEF. Is it possible creating additional/custom fields in "CommonSecurityLog"?!

We try connecting Palo Alto Networks firewalling infrastructure to Azure Log Analytics / Sentinel exactly following the guide in Sentinel but we see a lot of incoming data being mapped to fields like "DeviceCustomString1" which don't have a characteristic name. (e.g. "Session ID" -> "DeviceCustomString1", Rule Name -> "DeviceCustomString2"). The real field names get stored in the label fields like "DeviceCustomString2Label".

Many thanks and really appreciate your help on that!!

16826-ok-snap-2020-08-10-at-135627.png

16793-ok-snap-2020-08-10-at-135721p.png

Microsoft Security | Microsoft Sentinel
{count} votes

Accepted answer
  1. Saurabh Sharma 23,851 Reputation points Microsoft Employee Moderator
    2020-08-12T17:51:30.067+00:00

    @Peter Schönegger I have received confirmation from PG team that they are currently not supporting adding custom fields to table. Palo Alto recommended configuration sends this fields the those fields, other extra fields will be sent to "AdditionalExtensions" field. Also, they are already aware of the importance of this requirement for many customers so they are working to provide a solution in the up coming year.

    ----------

    Please do not forget to "Accept the answer" wherever the information provided helps you to help others in the community.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.