The firewall generates threat logs locally whenever traffic matches an Advanced IP Defense policy rule. On PAN-OS 12.2 and later, these logs include full attribute-level detail. On PAN-OS 11.1.x through 12.1.x, threat activity from Advanced IP Defense EDLs is recorded in traffic logs with the EDL name in the source or destination EDL column.