Field Name
|
Type
|
General Field
|
Description
|
Example
|
Products
|
act
|
-
|
-
|
The action
|
|
|
app
|
-
|
-
|
The network protocol
|
|
|
application
|
-
|
-
|
The name of the requested application
|
|
|
cnt
|
-
|
-
|
The total number of logs
|
|
|
dOSName
|
-
|
-
|
The destination OS
|
|
|
dUser1
|
-
|
|
The latest sign-in user of the destination
|
|
|
dhost
|
-
|
|
The destination hostname
|
|
|
dmac
|
-
|
-
|
The destination MAC address
|
|
|
dpt
|
-
|
|
The service destination port of the private application server (dstport)
|
|
|
dst
|
-
|
|
The destination IP (dstaddr)
|
|
|
dstLocation
|
-
|
-
|
The destination country
|
|
|
dstZone
|
-
|
-
|
The destination zone of the Palo Alto Networks Next-Generation Firewalls
session
|
|
|
dvchost
|
-
|
-
|
The network device hostname
|
|
|
eventId
|
-
|
-
|
The event ID
|
|
|
eventName
|
-
|
-
|
The log type
|
|
|
eventSubName
|
-
|
-
|
The Zero Trust Secure Access - Internet Access cloud app action or the Palo Alto
Networks Next-Generation Firewalls log sub-type
|
|
|
eventTime
|
-
|
-
|
The time the agent or product detected the event
|
|
|
filterRiskLevel
|
-
|
-
|
The top level filter risk of the event
|
|
|
flowId
|
-
|
-
|
The network analysis flow ID
|
|
|
httpXForwardedFor
|
-
|
-
|
The HTTP X-Forwarded-For header
|
|
|
pname
|
-
|
-
|
The product name
|
|
|
policyName
|
-
|
-
|
The name of the triggered policy
|
|
|
policyTreePath
|
-
|
-
|
The policy tree path (endpoint only)
|
|
|
policyUuid
|
-
|
-
|
The policy UUID
|
|
|
productCode
|
-
|
-
|
The product which sent the log
|
|
|
pver
|
-
|
-
|
The product version
|
|
|
reqDataSize
|
-
|
-
|
The data volume transmitted over the transport layer by the client (in bytes)
|
|
|
respDataSize
|
-
|
-
|
The data volume transmitted over the transport layer by the server (in bytes)
|
|
|
sOSName
|
-
|
-
|
The source OS
|
|
|
sUser1
|
-
|
|
The latest sign-in user of the source
|
|
|
sessionEndReason
|
-
|
-
|
The reason why a session was terminated
|
|
|
sessionStart
|
-
|
-
|
The session start time (in seconds)
|
|
|
shost
|
-
|
|
The source hostname
|
|
|
smac
|
-
|
-
|
The source MAC address
|
|
|
spt
|
-
|
|
The virtual port of the source assigned to the Secure Access Module (srcport)
|
|
|
src
|
-
|
|
The source IP (srcaddr)
|
|
|
srcLocation
|
-
|
-
|
The source country
|
|
|
srcZone
|
-
|
-
|
The source zone of the Palo Alto Networks Next-Generation Firewalls session
|
|
|
tags
|
-
|
|
The detected technique ID based on the alert filter
|
|
|
uuid
|
-
|
-
|
The unique key of the log
|
|
|
vsysName
|
-
|
-
|
The Palo Alto Networks virtual system of the session
|
|
|
Views: