Secure Access Activity Data
Field Name
|
Type |
General Field
|
Description
|
Example
|
Products
|
act
|
The action
|
|
|
||
application
|
The name of the requested application
|
|
|
||
authType
|
The authentication method
|
|
Trend Vision One Zero Trust Secure Access Internet Access
|
||
clientIp
|
|
The endpoint internet protocol (IP)
|
10.64.23.45 |
|
|
clientProtocol
|
The client protocol
|
HTTP/1.1 |
Trend Vision One Zero Trust Secure Access Internet Access
|
||
clientTls
|
The transport layer security (TLS) of the client
|
TLS 1.2 |
Trend Vision One Zero Trust Secure Access Internet Access
|
||
cloudAppCat
|
The category of the event in Cloud Reputation Service
|
|
Trend Vision One Zero Trust Secure Access Internet Access
|
||
companyName
|
The company name
|
Trend Micro |
Trend Vision OneZero Trust Secure Access Private Access
|
||
contentEncoding
|
The content encoding of the request or the response
|
gzip |
Trend Vision One Zero Trust Secure Access Internet Access
|
||
detectionType
|
The traffic detection type
|
|
|
||
deviceGUID
|
The globally unique identifier (GUID) of a non-endpoint object such as a network appliance
|
11111111-1111-1111-1111-111111111111 |
|
||
dpt
|
Port
|
The service destination port of the private application server (dstport)
|
443 |
|
|
dst
|
|
The destination IP (dstaddr)
|
10.10.10.10 |
|
|
duration
|
The time it took the scanner to complete the scan (in milliseconds)
|
1599465660123 |
Trend Vision One Zero Trust Secure Access Internet Access
|
||
e2eLatency
|
The end-to-end traffic latency time (in milliseconds)
|
10000 |
Trend Vision One Zero Trust Secure Access Internet Access
|
||
endpointGuid
|
EndpointID
|
The device GUID
|
|
|
|
endpointHostName
|
EndpointName
|
The hostname of the device on which the event was detected
|
|
|
|
eventName
|
The name of the log event
|
|
|
||
eventSubName
|
The Zero Trust Secure Access - Internet Access cloud app action or the Palo Alto Networks
firewall log sub-type
|
|
|
||
eventTime
|
The time the agent or product detected the event |
1657135700000
|
|
||
failedHTTPSInspection
|
Whether the hypertext transfer protocol secure (HTTPS) traffic inspection failed
|
true |
Trend Vision One Zero Trust Secure Access Internet Access
|
||
fileHash
|
FileSHA1
|
The secure hash algorithm 1 (SHA-1) of the file that violated the policy
|
1e15bf99022a9164708cebb3eace8fd61ad45cba
|
|
|
fileHashSha256
|
FileSHA2
|
The SHA-256 of the file that violated the policy
|
ba9edecdd09de1307714564c24409bd25508e22fe11c768053a08f173f263e93
|
|
|
fileName
|
|
The name of file that violated the policy
|
word.doc |
|
|
fileSize
|
The size of file that violated the policy
|
12134
|
|
||
fileType
|
The type of file that violated the policy
|
Microsoft Word |
|
||
filterRiskLevel
|
The top level risk level of the event
|
|
Security Analytics Engine
|
||
groupId
|
The group ID for the management scope filter
|
11111111-1111-1111-1111-111111111111 |
Security Analytics Engine
|
||
isPrivateApp
|
Whether the requested application is private
|
|
Trend Vision One Zero Trust Secure Access Internet Access
|
||
isRetroScan
|
Whether the event matches the Security Analytics Engine filter
|
true |
Security Analytics Engine
|
||
logReceivedTime
|
The time when the Extended Detection and Response (XDR) log was received
|
1656324260000 |
Security Analytics Engine
|
||
malName
|
The name of the detected malware
|
Trend Vision One Zero Trust Secure Access Internet Access
|
|||
mimeType
|
The mime type or content type of the response body
|
Text/HTML |
|
||
objectId
|
The universally unique identifier (UUID) of Trend Vision One Zero Trust Secure Access Private Access
|
|
Trend Vision OneZero Trust Secure Access Private Access
|
||
originEventSourceType
|
The source type of the original event which matches the Security Analytics Engine
filter
|
EVENT_SOURCE_NETWORK_ACTIVITY |
Security Analytics Engine
|
||
originUUID
|
The UUID of the original event which matches the Security Analytics Engine filter
|
11111111-1111-1111-1111-111111111111 |
Security Analytics Engine
|
||
osName
|
The host operating system (OS) name
|
|
|
||
pname
|
The product name
|
|
|
||
policyTemplate
|
The Data Loss Prevention template names
|
Australia, New Zealand: Healthcare Template, Germany: Banking and Financial Information |
Trend Vision One Zero Trust Secure Access Internet Access
|
||
policyTreePath
|
The policy tree path (endpoint only)
|
policyname1/policyname2/policyname3 |
Security Analytics Engine
|
||
policyUuid
|
The policy UUID
|
|
|
||
principalName
|
UserAccount
|
The User Principal Name
|
sample_email@trendmicro.com |
|
|
productCode
|
The internal product code
|
|
|
||
profile
|
The name of the triggered Threat Protection template or Data Loss Prevention profile
|
Trend Vision One Zero Trust Secure Access Internet Access
|
|||
pver
|
The product version
|
1
|
|
||
request
|
URL
|
The destination uniform resource locator (URL) that the user is accessing
|
|
|
|
requestBase
|
|
The URL domain
|
|
|
|
requestMethod
|
The network protocol request method
|
POST |
|
||
requestMimeType
|
The type of request content
|
application/json; charset=utf-8 |
|
||
requestSize
|
The request length
|
1324 |
Trend Vision One Zero Trust Secure Access Internet Access
|
||
responseSize
|
The response length
|
1324 |
Trend Vision One Zero Trust Secure Access Internet Access
|
||
ruleName
|
The name of the triggered cloud access rule
|
|
|
||
ruleUuid
|
The risk assessment and control design that is defined by Zero Trust Secure Access
risk control rules
|
11111111-1111-1111-1111-111111111111 |
Trend Vision OneZero Trust Secure Access Private Access
|
||
sender
|
The Zero Trust Internet Access gateway location
|
|
Trend Vision One Zero Trust Secure Access Internet Access
|
||
serverProtocol
|
The version of the HTTP protocol between the Service Gateway and server or website
|
HTTP/1.1 |
|
||
serverRespTime
|
The time the server took to respond to the request (in milliseconds)
|
1599465660123 |
Trend Vision One Zero Trust Secure Access Internet Access
|
||
serverTls
|
The TLS version between the Service Gateway and server or website
|
TLS 1.2 |
|
||
sessionEnd
|
The session end time (in seconds)
|
1575462989 |
|
||
sessionStart
|
Session start time (in seconds)
|
1575462989 |
|
||
spt
|
Port
|
The virtual port assigned to the Secure Access Module (srcport)
|
57763 |
|
|
src
|
|
Source IP (srcaddr)
|
100.100.100.100 |
|
|
suid
|
UserAccount
|
The user name or IP address (IPv4)
|
|
|
|
tags
|
Technique
|
The detected technique ID based on the alert filter
|
|
Security Analytics Engine
|
|
tlsJA3Fingerprint
|
JA3 fingerprint
|
|
|||
trafficType
|
The Zero Trust Internet Access gateway service mode
|
|
Trend Vision One Zero Trust Secure Access Internet Access
|
||
userDepartment
|
The user department request method
|
Sales |
Trend Vision One Zero Trust Secure Access Internet Access
|
||
userDomain
|
|
The Microsoft Entra ID domain or the domain of the Trend Micro Anti-Spam administrator portal user name
|
trendmicro.com |
|
|
uuid
|
The unique key of the log
|
11111111-1111-1111-1111-111111111111 |
Security Analytics Engine
|