The firewall generates threat logs whenever traffic matches an Advanced IP Defense policy rule. On PAN-OS 12.2.3 and later, these logs include full attribute-level detail with AIPD-specific fields. On PAN-OS 11.1.x through 12.1.x, threat activity from Advanced IP Defense EDLs is recorded in traffic logs with the EDL name in the source or destination EDL column.