SD-WAN Traffic CEF Fields
Focus
Focus
Strata Logging Service

SD-WAN Traffic CEF Fields

Table of Contents

SD-WAN Traffic CEF Fields

The following table identifies the SD-WAN Traffic field names that the Log Forwarding app uses when you forward logs using the CEF log format.
CEF Name
Field Details
act
Query Name: action.​value
Header Type: Predefined
app
Query Name: app
Header Type: Predefined
PanOSApplicationCategory
Query Name: app_category
Header Type: Custom
PanOSApplicationSubcategory
Query Name: app_sub_category
Header Type: Custom
Predefined
Query Name: bytes_received
Header Type: Custom
Predefined
Query Name: bytes_sent
Header Type: Custom
PanOSApplicationCharacteristics
Header Type: Custom
PanOSApplicationContainer
Query Name: container_of_app
Header Type: Custom
PanOSCortexDataLakeTenantID
Query Name: customer_id
Header Type: Custom
PanOSDestinationIP
Query Name: dest_ip.​value
Header Type: Custom
dpt
Query Name: dest_port
Header Type: Predefined
PanOSDestinationUserDomain
Header Type: Custom
PanOSDestinationUserName
Header Type: Custom
PanOSDestinationUserUUID
Header Type: Custom
cs4
Query Name: from_zone
Header Type: Predefined
deviceInboundInterface
Header Type: Predefined
Custom
Header Type: Custom
PanOSIsIPV6
Query Name: is_ipv6
Header Type: Custom
PanOSIsSaaSApplication
Query Name: is_saas_app
Header Type: Custom
PanOSLogSource
Query Name: log_source
Header Type: Custom
LogSourceGroupID
Header Type: Custom
deviceExternalID
Query Name: log_source_id
Header Type: Predefined
dvchost
Query Name: log_source_name
Header Type: Predefined
PanOSLogSourceTimeZoneOffset
Header Type: Custom
rt
Query Name: log_time
Header Type: Predefined
DeviceEventClassID
Query Name: log_type.​value
Header Type: Custom
deviceOutboundInterface
Header Type: Predefined
Custom
Query Name: packets_received
Header Type: Custom
Custom
Query Name: packets_sent
Header Type: Custom
PanOSPathValue
Query Name: path.​value
Header Type: Custom
PanOSPathLabel
Query Name: path_label
Header Type: Custom
PlatformType
Query Name: platform_type
Header Type: Custom
PanOSSDWANElementId
Header Type: Custom
PanOSSDWANElementName
Header Type: Custom
PanOSSDWANSiteId
Header Type: Custom
PanOsSDWANSiteName
Header Type: Custom
PanOSSDWANTenantId
Header Type: Custom
proto
Query Name: protocol.​value
Header Type: Predefined
PanOSApplicationRisk
Query Name: risk_of_app
Header Type: Custom
cs1
Query Name: rule_matched
Header Type: Predefined
PanOSRuleUUID
Query Name: rule_matched_uuid
Header Type: Custom
PanOSSanctionedStateOfApp
Header Type: Custom
reason
Header Type: Predefined
cn1
Query Name: session_id
Header Type: Predefined
Custom
Query Name: session_start_time
Header Type: Custom
PanOSSourceDeviceCategory
Header Type: Custom
PanOSSourceDeviceClass
Header Type: Custom
PanOSSourceDeviceHost
Query Name: source_device_host
Header Type: Custom
PanOSSourceDeviceMac
Query Name: source_device_mac
Header Type: Custom
PanOSSourceDeviceModel
Header Type: Custom
PanOSSourceDeviceOS
Query Name: source_device_os
Header Type: Custom
PanOSSourceDeviceOSFamily
Header Type: Custom
PanOSSourceDeviceOSVersion
Header Type: Custom
PanOSSourceDeviceProfile
Header Type: Custom
PanOSSourceDeviceVendor
Header Type: Custom
src
Query Name: source_ip.​value
Header Type: Predefined
spt
Query Name: source_port
Header Type: Predefined
suser
Query Name: source_user
Header Type: Predefined
PanOSSourceUserDomain
Header Type: Custom
PanOSSourceUserName
Header Type: Custom
PanOSSourceUserUUID
Header Type: Custom
Name
Query Name: sub_type.​value
Header Type: Custom
PanOSApplicationTechnology
Query Name: technology_of_app
Header Type: Custom
start
Query Name: time_generated
Header Type: Predefined
PanOSTimeGeneratedHighResolution
Header Type: Custom
cs5
Query Name: to_zone
Header Type: Predefined
Predefined
Query Name: total_time_elapsed
Header Type: Custom
PanOSTrafficClass
Query Name: traffic_class
Header Type: Custom
PanOSTSGID
Query Name: tsg_id
Header Type: Custom
cs2
Header Type: Predefined
Device Vendor
Query Name: vendor_name
Header Type: Custom