Directory sync CEF Fields
Focus
Focus
Strata Logging Service

Directory sync CEF Fields

Table of Contents

Directory sync CEF Fields

The following table identifies the Directory sync field names that the Log Forwarding app uses when you forward logs using the CEF log format.
CEF Name
Field Details
PanOSCIETimeReceived
Query Name: cie_log_time
Header Type: Custom
PanOSClientApplicationId
Header Type: Custom
PanOSCount
Query Name: count
Header Type: Custom
PanOSCountSummaryApplication
Header Type: Custom
PanOSCountSummaryComputer
Header Type: Custom
PanOSCountSummaryContainer
Header Type: Custom
PanOSCountSummaryGroup
Header Type: Custom
PanOSCountSummaryOU
Header Type: Custom
PanOSCountSummar RoleAssignment
Header Type: Custom
PanOSCountSummaryUser
Header Type: Custom
PanOSCortexDataLakeTenantID
Query Name: customer_id
Header Type: Custom
PanOSDirectoryId
Query Name: directory_id
Header Type: Custom
PanOSDirectoryName
Query Name: directory_name
Header Type: Custom
PanOSDirectoryType
Query Name: directory_type
Header Type: Custom
PanOSEventCategory
Query Name: event_category
Header Type: Custom
PanOSEventSequenceId
Query Name: event_sequence_id
Header Type: Custom
PanOSEventState
Query Name: event_state
Header Type: Custom
PanOSEventType
Query Name: event_type
Header Type: Custom
PanOSFailureReasonCode
Header Type: Custom
PanOSFlattenedMembershipCountCIE
Header Type: Custom
PanOSFlattenedMembershipCountCIEPreviousSync
Header Type: Custom
PanOSFlattenedMembershipCountIDP
Header Type: Custom
PanOSImmediateMembershipCountCIE
Header Type: Custom
PanOSImmediateMembershipCountCIEPreviousSync
Header Type: Custom
PanOSImmediateMembershipCountIDP
Header Type: Custom
PanOSLogSource
Query Name: log_source
Header Type: Custom
LogSourceGroupID
Header Type: Custom
deviceExternalID
Query Name: log_source_id
Header Type: Predefined
dvchost
Query Name: log_source_name
Header Type: Predefined
PanOSLogSourceTimeZoneOffset
Header Type: Custom
rt
Query Name: log_time
Header Type: Predefined
DeviceEventClassID
Query Name: log_type.​value
Header Type: Custom
PanOSPlatformType
Query Name: platform_type
Header Type: Custom
PanOSRecommendedAction
Query Name: recommended_action
Header Type: Custom
PanOSSourceType
Query Name: source_id
Header Type: Custom
PanOSSourceType
Query Name: source_type
Header Type: Custom
Name
Query Name: sub_type.​value
Header Type: Custom
PanOSSyncJobId
Query Name: sync_job_id
Header Type: Custom
PanOSSyncType
Query Name: sync_type
Header Type: Custom
PanOSTargetId
Query Name: target_id
Header Type: Custom
PanOSTargetType
Query Name: target_type
Header Type: Custom
start
Query Name: time_generated
Header Type: Predefined
PanOSTimeGeneratedHighResolution
Header Type: Custom
PanOSTSGID
Query Name: tsg_id
Header Type: Custom
Device Vendor
Query Name: vendor_name
Header Type: Custom