AI Runtime Security API CEF Fields
Focus
Focus
Strata Logging Service

AI Runtime Security API CEF Fields

Table of Contents

AI Runtime Security API CEF Fields

The following table identifies the AI Runtime Security API field names that the Log Forwarding app uses when you forward logs using the CEF log format.
CEF Name
Field Details
PanOSAction
Query Name: action
Header Type: Custom
PanOSAgentFramework
Query Name: agent_framework
Header Type: Custom
PanOSAgentID
Query Name: agent_id
Header Type: Custom
PanOSAIAppCloudProvider
Header Type: Custom
PanOSAIAppCSPName
Query Name: ai_app_csp_name
Header Type: Custom
PanOSAIAppEnvironment
Query Name: ai_app_environment
Header Type: Custom
PanOSAIAppUserDomain
Query Name: ai_app_user_domain
Header Type: Custom
PanOSAIAppUserGroupID
Header Type: Custom
PanOSAIAppUserGroupName
Header Type: Custom
PanOSAIApplicationUserName
Query Name: ai_app_user_name
Header Type: Custom
PanOSAIApplicationName
Header Type: Custom
PanOSAIIncidentReportID
Header Type: Custom
PanOSAIIncidentSubtype
Header Type: Custom
PanOSAIIncidentType
Query Name: ai_incident_type
Header Type: Custom
PanOSAIModelName
Query Name: ai_model_name
Header Type: Custom
PanOSAISecurityPolicyID
Header Type: Custom
PanOSAISecurityPolicyName
Header Type: Custom
PanOSAISecurityProfileID
Header Type: Custom
PanOSAISecurityProfileName
Header Type: Custom
PanOSAISubtypeDetails
Query Name: ai_subtype_details
Header Type: Custom
PanOSAPIKeyName
Query Name: api_key_name
Header Type: Custom
PanOSAPIRegion
Query Name: api_region
Header Type: Custom
PanOSAppId
Query Name: app_id
Header Type: Custom
PanOSAssetID
Query Name: asset_id
Header Type: Custom
PanOSCompletedTS
Query Name: completed_ts
Header Type: Custom
PanOSContentMasked
Query Name: content_masked
Header Type: Custom
PanOSContentType
Query Name: content_type
Header Type: Custom
PanOSCSPID
Query Name: csp_id
Header Type: Custom
PanOSCortexDataLakeTenantID
Query Name: customer_id
Header Type: Custom
PanOSDetectionServiceFlags
Header Type: Custom
PanOSFinalPromptAction
Header Type: Custom
PanOSFinalPromptVerdict
Header Type: Custom
PanOSFinalResponseAction
Header Type: Custom
PanOSFinalResponseVerdict
Header Type: Custom
PanOSIsCode
Query Name: is_code
Header Type: Custom
PanOSIsPrompt
Query Name: is_prompt
Header Type: Custom
PanOSIsPromptAgentRequested
Header Type: Custom
PanOSIsPromptDLPRequested
Header Type: Custom
PanOSIsPromptMCRequested
Header Type: Custom
PanOSIsPromptPIRequested
Header Type: Custom
PanOSIsPromptTCRequested
Header Type: Custom
PanOSIsPromptTGRequested
Header Type: Custom
PanOSIsPromptURLFRequested
Header Type: Custom
PanOSIsResponse
Query Name: is_response
Header Type: Custom
PanOSIsResponseAgentRequested
Header Type: Custom
PanOSIsResponseCGRequested
Header Type: Custom
PanOSIsResponseDBSRequested
Header Type: Custom
PanOSIsResponseDLPRequested
Header Type: Custom
PanOSIsResponseMCRequested
Header Type: Custom
PanOSIsResponseTCRequested
Header Type: Custom
PanOSIsResponseTGRequested
Header Type: Custom
PanOSIsResponseURLFRequested
Header Type: Custom
PanOSLatency
Query Name: latency
Header Type: Custom
PanOSLogSource
Query Name: log_source
Header Type: Custom
LogSourceGroupID
Header Type: Custom
deviceExternalID
Query Name: log_source_id
Header Type: Predefined
dvchost
Query Name: log_source_name
Header Type: Predefined
PanOSLogSourceTimeZoneOffset
Header Type: Custom
rt
Query Name: log_time
Header Type: Predefined
DeviceEventClassID
Query Name: log_type.​value
Header Type: Custom
PanOSMaxLatencyHit
Query Name: max_latency_hit
Header Type: Custom
PanOSMCPServer
Query Name: mcp_server
Header Type: Custom
PlatformType
Query Name: platform_type
Header Type: Custom
PanOSRequestResponse
Query Name: request_response
Header Type: Custom
PanOSScanID
Query Name: scan_id
Header Type: Custom
PanOSScanStartTime
Query Name: scan_start_time
Header Type: Custom
PanOSScanSUBRequestID
Query Name: scan_sub_req_id
Header Type: Custom
PanOSScanType
Query Name: scan_type
Header Type: Custom
PanOSSessionUrl
Query Name: session_url
Header Type: Custom
Name
Query Name: sub_type.​value
Header Type: Custom
PanOSTextRecords
Query Name: text_records
Header Type: Custom
start
Query Name: time_generated
Header Type: Predefined
PanOSTimeGeneratedHighResolution
Header Type: Custom
PanOSTokens64
Query Name: token_64
Header Type: Custom
PanOSToolName
Query Name: tool_name
Header Type: Custom
PanOSTransactionID
Query Name: transaction_id
Header Type: Custom
PanOSTSGID
Query Name: tsg_id
Header Type: Custom
Device Vendor
Query Name: vendor_name
Header Type: Custom
PanOSVendorSeverity
Header Type: Custom
PanOSVerdict
Query Name: verdict
Header Type: Custom