Prisma Access Agent Log Event Details
Focus
Focus
Prisma Access Agent

Prisma Access Agent Log Event Details

Table of Contents
Review detailed descriptions of Prisma Access Agent events to help understand Prisma Access Agent logs.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access (Managed by Panorama)
  • Strata Logging Service
  • Minimum Required Prisma Access Version: 5.1 Preferred or Innovation
  • Prisma Access license with the Mobile User subscription
  • Prisma Access Agent version: 25.1.0.14
  • macOS 14 and later or Windows 10 version 2024 and later desktop devices
  • Contact your Palo Alto Networks account representative to activate the Prisma Access Agent feature
To help you understand an event that has occurred, you can review descriptions of log events that are related to the Prisma Access Agent.
The event IDs in the following table correspond to the values in the Event ID Value (event_id.value) field in the log viewer. You can create log queries based on the values the event_id.value field.
The following event IDs are used in the agent log subtype.
Event IDDescription
gateway-authIndicates the gateway authentication stage. See Event Status for results.
gateway-config-releaseIndicates a gateway event for configuration release, such as remove ip-user mapping or remove tunnel.
gateway-connectedIndicates a gateway event for a Prisma Access Agent successful connection for tunnel mode.
gateway-getconfigIndicates a gateway event for generating Prisma Access Agent configuration, such as split-tunnel, virtual IP, or tunnel information.
gateway-hip-checkIndicates a gateway event to confirm whether a Prisma Access Agent HIP report was updated or not, and to refresh ip-user mapping.
gateway-hip-reportIndicates a gateway event to confirm whether a HIP report was received from a Prisma Access Agent, to update ip-user mapping, and to enforce HIP policy.
gateway-logoutIndicates a gateway event for a Prisma Access Agent logout.
gateway-preloginIndicates a gateway event. As a part of the event, the Prisma Access Agent does the following:
  • Certificate: Validates whether a client certificate is valid.
  • SAML: Generates a SAML request and sends it back to a Prisma Access Agent.
gateway-registerIndicates Prisma Access Agent user information, such as username, domain-name, computer name, hostid, serial number, public ip, or login time is added on the gateway.
gateway-setup-ipsecIndicates a gateway event for setting up the IPSec tunnel.
gateway-switch-to-sslIndicates a gateway tunnel switch from IPSec to SSL when the IPSec tunnel was not successful.