View Advanced IP Defense Logs in PAN-OS and Panorama
Focus
Focus
Advanced IP Defense

View Advanced IP Defense Logs in PAN-OS and Panorama

Table of Contents


View Advanced IP Defense Logs in PAN-OS and Panorama

View and filter Advanced IP Defense threat logs on the firewall to investigate IP-based threats and track policy rule matches.
The firewall generates threat logs whenever traffic matches an Advanced IP Defense policy rule. On PAN-OS 12.2.3 and later, these logs include full attribute-level detail with AIPD-specific fields. On PAN-OS 11.1.x through 12.1.x, threat activity from Advanced IP Defense EDLs is recorded in traffic logs with the EDL name in the source or destination EDL column.
  1. Log in to the PAN-OS web interface.
  2. Select MonitorLogsThreat.
  3. Filter for Advanced IP Defense log entries.
    Use the following filter expressions to isolate Advanced IP Defense entries:
    • ( subtype eq aipd )
    • ( name-of-threatid eq AdvIPD )
    The log list displays Advanced IP Defense-specific columns including AIPD Category (Attributes), AIPD Profile, AIPD Rule, AIPD Match Field, and AIPD DNS Seen (Direct-to-IP Detection).
    Threat log list — AIPD entries
  4. Click a log entry to view the full details.
    The Detailed Log View shows the following Advanced IP Defense-specific fields under the Details section:
    • Threat Typeaipd
    • Threat ID/NameAdvIPD
    • Categoryaipd-security
    • Severity—The log severity configured in the matched rule
    • AIPD Profile—The profile that triggered the detection
    • AIPD Match Field—Whether the source or destination IP was inspected (src_ip or dst_ip)
    • AIPD Category (Attributes)—The matched categories and their specific attributes, formatted as Category(attribute1,attribute2,...)
    • AIPD Rule—The specific rule within the profile that matched
    • AIPD DNS Seen (Direct-to-IP Detection)—Whether the connection had a prior DNS resolution
    Detailed Log View — AIPD fields
  5. (Optional) Configure log forwarding to Strata Logging Service.
    To access Advanced IP Defense logs in Strata Cloud Manager and enable Activity Insights visibility, configure log forwarding to send threat logs to Strata Logging Service. Select ObjectsLog Forwarding and create or edit a log forwarding profile to include threat logs.