DNS Security (Resolver and SDWAN and Panos 12.1 or later) LEEF Fields
Focus
Focus
Strata Logging Service

DNS Security (Resolver and SDWAN and Panos 12.1 or later) LEEF Fields

Table of Contents

DNS Security (Resolver and SDWAN and Panos 12.1 or later) LEEF Fields

The following table identifies the DNS Security (Resolver and SDWAN and Panos 12.1 or later) field names that the Log Forwarding app uses when you forward logs using the LEEF log format.
When you create a syslog forwarding profile , you can optionally create a profile token that the Log Forwarding app uses when it sends logs to the syslog server. If you configure a profile token, it appears in the log line immediately after the log type information (for example, TRAFFIC, THREAT, HIPMATCH, and so forth). The token will appear on a parameter called profileToken.
LEEF Name
Query Name
Field Type
Action
Custom
Application
Custom
ApplicationCategory
Custom
ApplicationSubcategory
Custom
CloudHostname
Custom
ConfigVersion
Custom
ContainerID
Custom
ApplicationContainer
Custom
ContentVersion
Custom
RepeatCount
Custom
CortexDataLakeTenantId
Custom
DestinationDeviceCategory
Custom
DestinationDeviceClass
Custom
DestinationDeviceHost
Custom
DestinationDeviceMac
Custom
DestinationDeviceModel
Custom
DestinationDeviceOS
Custom
DestinationDeviceOSFamily
Custom
DestinationDeviceOSVersion
Custom
DestinationDeviceProfile
Custom
DestinationDeviceVendor
Custom
DestinationDynamicAddressGroup
Custom
DestinationEDL
Custom
DestinationIP
Custom
DestinationLocation
Custom
dstPort
Predefined
DestinationUserInfoDomain
Custom
DestinationUserInfoName
Custom
DestinationUserInfoUUID
Custom
DestinationUUID
Custom
DGHierarchyLevel1
Custom
DGHierarchyLevel2
Custom
DGHierarchyLevel3
Custom
DGHierarchyLevel4
Custom
DirectionOfAttack
Custom
DNSRequestName
Custom
DNSRdata
Custom
DNSResponseCode
Custom
DNSResponseFlags
Custom
DNSResponseTTL
Custom
DNSResponseType
Custom
DomainEDL
Custom
DestinationUser
Custom
ToZone
Custom
DynamicUserGroupName
Custom
EndpointSerialNumber
Custom
FlowSources
Custom
url
Predefined
FromZone
Custom
ThreatID
Custom
HostID
Custom
HTTP2Connection
Custom
HTTPMethod
Custom
InboundInterface
Custom
InboundInterfaceDetailsPort
Custom
InboundInterfaceDetailsSlot
Custom
InboundInterfaceDetailsType
Custom
InboundInterfaceDetailsUnit
Custom
CaptivePortal
Custom
IsClienttoServer
Custom
IsContainer
Custom
IsDecryptMirror
Custom
IsDecrypted
Custom
IsDuplicateLog
Custom
IsEncrypted
Custom
LogExported
Custom
LogForwarded
Custom
IsIPV6
Custom
IsMptcpOn
Custom
NAT
Custom
IsNonStandardDestinationPort
Custom
IsPacketCapture
Custom
IsPhishing
Custom
IsPrismaNetwork
Custom
IsPrismaUsers
Custom
IsProxy
Custom
IsReconExcluded
Custom
IsSaaSApplication
Custom
IsServertoClient
Custom
IsSourceXForwarded
Custom
IsSystemReturn
Custom
IsTransaction
Custom
IsTunnelInspected
Custom
IsURLDenied
Custom
K8SClusterID
Custom
LocalDeepLearningAnalyzed
Custom
Location
Custom
LogSetting
Custom
LogSource
Custom
LogSourceGroupID
Custom
DeviceSN
Custom
DeviceName
Custom
LogSourceTimeZoneOffset
Custom
TimeReceived
Custom
cat
Predefined
IMEI
Custom
dstPostNAT
Predefined
dstPostNATPort
Predefined
srcPostNAT
Predefined
srcPostNATPort
Predefined
NonStandardDestinationPort
Custom
NSSAINetworkSliceType
Custom
EgressInterface
Custom
OutboundInterfaceDetailsPort
Custom
OutboundInterfaceDetailsSlot
Custom
OutboundInterfaceDetailsType
Custom
OutboundInterfaceDetailsUnit
Custom
PanoramaSN
Custom
ParentSessionID
Custom
ParentStarttime
Custom
PartialHash
Custom
PayloadProtocolID
Custom
PlatformType
Custom
ContainerName
Custom
ContainerNameSpace
Custom
proto
Predefined
DNSRequestType
Custom
ReportID
Custom
ApplicationRisk
Custom
SecurityRule
Custom
RuleUUID
Custom
SanctionedStateOfApp
Custom
SequenceNo
Custom
SessionID
Custom
Severity
Custom
SigFlags
Custom
SourceDeviceCategory
Custom
SourceDeviceClass
Custom
SourceDeviceHost
Custom
SourceDeviceMac
Custom
SourceDeviceModel
Custom
SourceDeviceOS
Custom
SourceDeviceOSFamily
Custom
SourceDeviceOSVersion
Custom
SourceDeviceProfile
Custom
SourceDeviceVendor
Custom
SourceDynamicAddressGroup
Custom
SourceEDL
Custom
src
Predefined
SourceLocation
Custom
srcPort
Predefined
UsrName
Custom
SourceUserInfoDomain
Custom
SourceUserInfoName
Custom
SourceUserInfoUUID
Custom
SourceUUID
Custom
SubType
Custom
ApplicationTechnology
Custom
DNSCategory
Custom
DNSThreatName
Custom
devTime
Predefined
TimeGeneratedHighResolution
Custom
SessionDuration
Custom
TSGID
Custom
Tunnel
Custom
TunneledApplication
Custom
IMSI
Custom
URLCategory
Custom
URLDomain
Custom
URLCounter
Custom
Users
Custom
Vendor
Header
VendorSeverity
Custom
Verdict
Custom
VirtualLocation
Custom
VirtualSystemID
Custom
VirtualSystemName
Custom
X-Forwarded-ForIP
Custom