PAN OS Attribute Reference
Focus
Focus
Device Security

PAN OS Attribute Reference

Table of Contents

PAN OS Attribute Reference

This reference lists the attributes that Device Security collects from PAN OS, their names as stored in Device Security, and the Device Security fields they map to.
When Device Security integrates with PAN-OS, it gains better visibility into your Palo Alto Networks firewall infrastructure. The attributes in this reference cover firewall device records and network interface data learned from PAN-OS.
The third-party attribute name in Device Security refers to the attribute name as it appears in the Assets Inventory table and in Query Engine. This follows the format of third-party-name.attribute-name. When viewing the attribute name in the Assets Inventory table column selector or on a Device Details page, where the third-party name can be found as a header for the attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the Query Builder and in the Assets Inventory table, but under Device DetailsAttributesIntegration Specific AttributesMicrosoft Defender, the attribute would appear as macAddress.

System Attributes

Device Security collects system attributes from PAN OS. The following table lists each PAN OS attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
PAN OS Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
devicename
panos.devicename
Device Name
Devicename
hostname
panos.hostname
hostname
Name of the device
ip-address
panos.ip_address
IP Address
IP address
mac-address
panos.mac_address
MAC Address; id
MAC address
model
panos.model
Model
Model of the device
sw-version
panos.sw_version
OS Version
Sw version
serial
panos.serial
Serial Number
Serial number of the device
advanced-routing
panos.advanced_routing
—
Advanced routing
app-version
panos.app_version
—
App version
av-version
panos.av_version
—
Av version
cloud-mode
panos.cloud_mode
—
Cloud mode
default-gateway
panos.default_gateway
—
Default gateway
device-certificate-status
panos.device_certificate_status
—
Device certificate status
family
panos.family
—
Family
operational-mode
panos.operational_mode
—
Operational mode
platform-family
panos.platform_family
—
Platform family
public-ip-address
panos.public_ip_address
—
Public IP address
threat-version
panos.threat_version
—
Threat version
vm-cap-tier
panos.vm_cap_tier
—
Vm cap tier
vm-cores
panos.vm_cores
—
Vm cores
vm-cpuid
panos.vm_cpuid
—
VM CPU ID
vm-license
panos.vm_license
—
Vm license
vm-mac-base
panos.vm_mac_base
—
Vm MAC base
vm-mode
panos.vm_mode
—
Vm mode

Interface All Attributes

Device Security collects interface all attributes from PAN OS. The following table lists each PAN OS attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
PAN OS Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
mac_address
panos.mac_address
id; MAC Address
MAC address
ip_address
panos.ip_address
IP Address
IP address
interface_list
panos.interface_list
third_party_learned_network_interfaces
Interface list
* Only some attributes map to a Device Security Common Attribute.