收集 Secure Web Proxy 日志

解析器版本: 2.0

支持:

本文档介绍了如何使用 Cloud Storage 将 Secure Web Proxy 导出并注入到 Google Security Operations 中。解析器会从 JSON 日志中提取字段,并将其转换为统一数据模型 (UDM)。它会初始化 UDM 字段、解析 JSON 载荷、提取网络信息、安全详细信息和资源属性,并根据正文和目标信息是否存在来设置事件类型。

准备工作

请确保满足以下前提条件:

  • Google SecOps 实例。
  • Secure Web Proxy 在您的 Google Cloud 环境中处于活跃状态并已配置。
  • 对具有特权访问权限,并且具有访问安全 Web 代理日志的适当权限。 Google Cloud

创建 Cloud Storage 存储桶

  1. 登录 Google Cloud 控制台
  2. 进入 Cloud Storage 存储分区 页面。

    进入“存储分区”

  3. 点击创建

  4. 创建存储桶 页面上,输入您的存储桶信息。完成以下每个步骤后,点击继续 以继续执行下一步:

    1. 开始使用 部分中,执行以下操作:

      1. 输入符合存储桶名称要求的唯一名称;例如 gcp-swp-logs
      2. 如需启用分层命名空间,请点击展开箭头以展开优化文件导向型和数据密集型工作负载 部分,然后选择在此存储桶上启用分层命名空间

      3. 如需添加存储桶标签,请点击展开箭头以展开标签 部分。

      4. 点击添加标签,并为标签指定键和值。

    2. 选择数据存储位置 部分中,执行以下操作:

      1. 选择位置类型
      2. 使用位置类型菜单选择一个位置 ,用于永久存储存储桶中的对象数据。

      3. 如需设置跨存储桶复制,请展开设置跨存储桶复制 部分。

    3. 为数据选择一个存储类别 部分中,为存储桶选择默认存储类别 ,或者选择 Autoclass 对存储桶数据进行自动存储类别管理。

    4. 选择如何控制对对象的访问权限 部分中,选择 强制执行禁止公开访问 ,然后为存储桶对象选择访问权限控制模型

    5. 选择如何保护对象数据 部分中,执行以下操作:

      1. 数据保护 下,选择您要为存储桶设置的任何选项。
      2. 如需选择对象数据的加密方式,请点击标有数据加密 的 展开箭头,然后选择数据加密方法
  5. 点击创建

配置 Secure Web Proxy 日志导出

  1. 登录 Google Cloud 控制台
  2. 依次前往日志记录 > 日志路由器
  3. 点击创建接收器
  4. 提供以下配置参数:

    • 接收器名称:输入有意义的名称;例如 SWP-Export-Sink
    • 接收器目标位置:选择 Cloud Storage 存储空间,然后输入存储桶的 URI;例如 gs://gcp-swp-logs/
    • 日志过滤器
    logName="projects/<your-project-id>/logs/networkservices.googleapis.com/gateway_requests"
    
  5. 点击创建

配置 Cloud Storage 的权限

  1. 前往 IAM 和管理 > IAM
  2. 找到 Cloud Logging 服务帐号。
  3. 授予对存储桶的 roles/storage.admin

设置 Feed

如需配置 Feed,请按以下步骤操作:

  1. 依次前往 SIEM 设置 > Feed
  2. 点击 Add New Feed (添加新 Feed)。
  3. 在下一页上,点击 Configure a single feed (配置单个 Feed)。
  4. Feed 名称 字段中,输入 Feed 的名称;例如 Google Cloud SWP Logs
  5. 选择 Google Cloud Storage V2 作为来源类型
  6. 选择 GCP Secure Web Proxy 作为日志类型
  7. 点击 Chronicle 服务账号 字段旁边的 Get Service Account (获取服务账号)。
  8. 点击下一步
  9. 为以下输入参数指定值:

    • 存储分区 URI:Cloud Storage 存储桶网址;例如 gs://gcp-swp-logs/。此网址必须以尾部正斜杠 (/) 结尾。
    • 来源删除选项:根据您的偏好选择删除选项。

    • 最长文件存在时间:包含在过去指定天数内修改的文件。默认值为 180 天。

  10. 点击下一步

  11. 最终确定 屏幕中检查新 Feed 配置,然后点击提交

UDM 映射表

日志字段 UDM 映射 逻辑
httpRequest.latency additional.fields[].key: HTTPRequest Latency
additional.fields[].value.string_value: 0.124462s
直接从原始日志字段映射。
httpRequest.protocol network.application_protocol: HTTP
network.application_protocol_version: 2
协议和版本使用 grok 模式从 httpRequest.protocol 字段中提取。
httpRequest.remoteIp target.asset.ip: 1.1.0.1
target.ip: 1.1.0.1
IP 地址使用 grok 模式从 httpRequest.remoteIp 字段中提取。
httpRequest.requestMethod network.http.method: GET 直接从原始日志字段映射。
httpRequest.requestSize network.sent_bytes: 144 直接从原始日志字段映射并转换为整数。
httpRequest.requestUrl target.url: https://github.com/tempuslabs/tempusutils/info/refs?service=git-upload-pack 直接从原始日志字段映射。
httpRequest.responseSize network.received_bytes: 225 直接从原始日志字段映射并转换为整数。
httpRequest.serverIp principal.asset.ip: 1.8.1.4
principal.ip: 1.8.1.4
IP 地址使用 grok 模式从 httpRequest.serverIp 字段中提取。
httpRequest.status network.http.response_code: 401 直接从原始日志字段映射并转换为整数。
httpRequest.userAgent network.http.user_agent: git/2.34.1
network.http.parsed_user_agent: {
family: USER_DEFINED,
device: git,
device_version: 2.34.1
}
直接从原始日志字段映射。parsed_user_agent 字段通过解析 httpRequest.userAgent 字段派生而来。
insertId metadata.product_log_id: 1yh8wczer5o8n 直接从原始日志字段映射。
jsonPayload.@type additional.fields[].key: Log Type
additional.fields[].value.string_value: type.googleapis.com/google.cloud.loadbalancing.type.LoadBalancerLogEntry
直接从原始日志字段映射。
jsonPayload.enforcedGatewaySecurityPolicy.hostname target.asset.hostname: github.com
target.hostname: github.com
直接从原始日志字段映射。
jsonPayload.enforcedGatewaySecurityPolicy.matchedRules[].action security_result.action: ALLOW
security_result.action_details: ALLOWED
security_result.action 基于 jsonPayload.enforcedGatewaySecurityPolicy.matchedRules[].action 的值派生而来。如果操作为 ALLOWED,则 UDM 字段设置为 ALLOW。如果操作为 DENIED,则 UDM 字段设置为 BLOCK
jsonPayload.enforcedGatewaySecurityPolicy.matchedRules[].name security_result.rule_name: projects/671807354785/locations/us-central1/gatewaySecurityPolicies/github-access-gateway-security-policy-5cec30cd/rules/github-access-gateway-security-policy-rule-5cec30cd 直接从原始日志字段映射。
jsonPayload.enforcedGatewaySecurityPolicy.requestWasTlsIntercepted security_result.detection_fields[].key: requestWasTlsIntercepted
security_result.detection_fields[].value: true
直接从原始日志字段映射。
logName additional.fields[].key: Log Name
additional.fields[].value.string_value: projects/rws-w6uza3pn5jzzh6z3hc3d/logs/networkservices.googleapis.com%2Fgateway_requests
直接从原始日志字段映射。
receiveTimestamp metadata.collected_timestamp: {
seconds: 1710189647,
nanos: 661101224
}
使用 RFC 3339 日期格式从原始日志字段解析。
resource.labels.gateway_name security_result.detection_fields[].key: gateway-name
security_result.detection_fields[].value: github-access-gateway-5cec30cd
直接从原始日志字段映射。
resource.labels.gateway_type security_result.detection_fields[].key: gateway-type
security_result.detection_fields[].value: SECURE_WEB_GATEWAY
直接从原始日志字段映射。
resource.labels.location target.resource.attribute.cloud.availability_zone: us-central1 直接从原始日志字段映射。
resource.labels.network_name target.resource.attribute.labels[].key: rc_network_name
target.resource.attribute.labels[].value: projects/rws-w6uza3pn5jzzh6z3hc3d/global/networks/rws-tr-pilot-workspace
直接从原始日志字段映射。
resource.type target.resource.attribute.labels[].key: Resource Type
target.resource.attribute.labels[].value: networkservices.googleapis.com/Gateway
直接从原始日志字段映射。
severity security_result.severity: MEDIUM 从原始日志字段映射。该值会转换为 UDM 严重级别。在本例中,WARNING 映射到 MEDIUM
timestamp metadata.event_timestamp: {
seconds: 1710189639,
nanos: 952848000
}
使用 RFC 3339 日期格式从原始日志字段解析。
(解析器逻辑) metadata.event_type: NETWORK_HTTP 由解析器逻辑根据 has_principalhas_target 和与 http 匹配的协议是否存在来确定。
(解析器逻辑) metadata.log_type: GCP_SWP 基于产品的硬编码值。

更新日志

查看此解析器的更新日志

需要更多帮助?获得社区成员和 Google SecOps 专业人士的解答。