View Advanced IP Defense Logs
Focus
Focus
Advanced IP Defense

View Advanced IP Defense Logs

Table of Contents

View Advanced IP Defense Logs

Browse and search Advanced IP Defense threat logs to investigate IP-based threats and validate policy rule effectiveness.
Where Can I Use This?What Do I Need?
  • PAN-OS 12.2.3 and later
  • Strata Cloud Manager
  • PAN-OS 11.1.x and later (EDL-based)
  • Advanced IP Defense license
  • Log forwarding configured (for Strata Cloud Manager log access)
Advanced IP Defense generates threat logs whenever traffic matches a policy rule. You can browse, search, and filter these logs to investigate specific IP-based threats, identify patterns in attacker behavior, and validate that your policy rules are working as intended. Logs are accessible directly on the firewall and through Strata Cloud Manager when log forwarding to Strata Logging Service is configured.
All Advanced IP Defense threat logs share a single unified threat ID and threat category ID, which are delivered through content package updates. Each log entry contains session details (source and destination IP, zone, port, and protocol), the matched IP attributes and their categories, the policy action taken (Allow, Alert, Block, or Deny), the log severity level defined in the policy rule, and the Advanced IP Defense profile name. On PAN-OS 12.2.3 and later, logs include the full set of matched attributes for the IP, providing granular visibility into why the traffic was flagged. On PAN-OS 11.1.x through 12.1.x, logs record the EDL name and the matched IP address.
The Activity Insights threat view in Strata Cloud Manager includes Advanced IP Defense alongside other cloud-delivered security services, allowing you to correlate IP-based threats with DNS, URL, and file-based detections across the same sessions. The threat insights page handles multiple threat categories for IP attributions, so a single IP that matches attributes from several categories (such as both Malware C2 and Direct-to-IP) displays all relevant categories in the log detail. You can also search for a specific IP through IOC Search to view its associated categories and subcategories on the IP Overview page.
On PAN-OS 11.1.x through 12.1.x, Advanced IP Defense threat activity is logged as traffic log entries when EDL-based security rules match. The EDL name appears in the source EDL or destination EDL columns. These logs don't include IP attribute detail but do provide visibility into blocked threats from the predefined Advanced IP Defense External Dynamic Lists.

View Advanced IP Defense Logs in Strata Cloud Manager

View and filter Advanced IP Defense threat logs in Strata Cloud Manager to investigate IP-based threats and track policy rule matches.
Strata Cloud Manager provides a centralized log viewer for Advanced IP Defense threat logs forwarded through Strata Logging Service. You can filter logs by IP attributes, categories, policy actions, and time range to investigate specific threats and assess the effectiveness of your Advanced IP Defense policy rules.
  1. Log in to Strata Cloud Manager.
  2. Access the log viewer.
    Select Incidents and AlertsLog Viewer.
  3. Filter for Advanced IP Defense threat logs.
    In the log viewer, filter the log type to Threat and filter by the Advanced IP Defense threat category. You can further narrow results by:
    • IP attribute category or subcategory
    • Policy action (Allow, Alert, Block, or Deny)
    • Source or destination IP address
    • Source or destination zone
    • Time range
  4. Review the log details for a specific entry.
    Click a log entry to view the full session details, including the matched IP attributes, the Advanced IP Defense profile and rule that triggered the log, the policy action taken, and the log severity level. For IPs that match multiple attribute categories, all matched categories are displayed in the log detail.
  5. (Optional) Search for a specific IP address in IOC Search.
    From the log entry, you can pivot to IOC Search to view the full set of categories and subcategories associated with a specific IP address on the IP Overview page. This provides additional threat intelligence context beyond the attributes that matched your policy rules.

View Advanced IP Defense Logs in PAN-OS and Panorama

View and filter Advanced IP Defense threat logs on the firewall to investigate IP-based threats and track policy rule matches.
The firewall generates threat logs whenever traffic matches an Advanced IP Defense policy rule. On PAN-OS 12.2.3 and later, these logs include full attribute-level detail with AIPD-specific fields. On PAN-OS 11.1.x through 12.1.x, threat activity from Advanced IP Defense EDLs is recorded in traffic logs with the EDL name in the source or destination EDL column.
  1. Log in to the PAN-OS web interface.
  2. Select MonitorLogsThreat.
  3. Filter for Advanced IP Defense log entries.
    Use the following filter expressions to isolate Advanced IP Defense entries:
    • ( subtype eq aipd )
    • ( name-of-threatid eq AdvIPD )
    The log list displays Advanced IP Defense-specific columns including AIPD Category (Attributes), AIPD Profile, AIPD Rule, AIPD Match Field, and AIPD DNS Seen (Direct-to-IP Detection).
    Threat log list — AIPD entries
  4. Click a log entry to view the full details.
    The Detailed Log View shows the following Advanced IP Defense-specific fields under the Details section:
    • Threat Typeaipd
    • Threat ID/NameAdvIPD
    • Categoryaipd-security
    • Severity—The log severity configured in the matched rule
    • AIPD Profile—The profile that triggered the detection
    • AIPD Match Field—Whether the source or destination IP was inspected (src_ip or dst_ip)
    • AIPD Category (Attributes)—The matched categories and their specific attributes, formatted as Category(attribute1,attribute2,...)
    • AIPD Rule—The specific rule within the profile that matched
    • AIPD DNS Seen (Direct-to-IP Detection)—Whether the connection had a prior DNS resolution
    Detailed Log View — AIPD fields
  5. (Optional) Configure log forwarding to Strata Logging Service.
    To access Advanced IP Defense logs in Strata Cloud Manager and enable Activity Insights visibility, configure log forwarding to send threat logs to Strata Logging Service. Select ObjectsLog Forwarding and create or edit a log forwarding profile to include threat logs.