System CEF Fields
Table of Contents
System CEF Fields
Example System log in CEF:
Feb 28 08:30:27 xxx.xx.x.xx 1442 <14>1 2021-02-28T08:30:27.339Z stream-logfwd20-587718190-02280003-lvod-harness-mjdh logforwarder - panwlogs - CEF:0|Palo Alto Networks|LF|2.0|SYSTEM|wildfire-appliance|1|ProfileToken=xxxxx dtz=UTC rt=Feb 28 2021 08:30:26 deviceExternalId=xxxxxxxxxxxxx PanOSConfigVersion=0.0 PanOSAgentContentVersion= PanOSAgentDataCollectionStatus= PanOSAgentID= PanOSAgentIsolationStatus= PanOSAgentStatus= PanOSAgentTimeZoneOffset= PanOSAgentVersion= PanOSEndpointCPUArchitecture= PanOSEndpointDeviceDomain= PanOSEndpointDeviceName= PanOSEndpointIPaddress= PanOSEndpointOSType= PanOSEndpointOSVersion= PanOSEndpointUserDomain= PanOSEndpointUserName=xxxxx PanOSEndpointUserUUID= PanOSIsDuplicateLog=false PanOSIsPrismaNetwork=false PanOSIsPrismaUsers=false cat= PanOSLogExported=false PanOSLogForwarded=true PanOSLogSource=firewall PanOSLogSourceTimeZoneOffset= PanOSSeverity=Informational PanOSTenantID=xxxxxxxxxxxxx PanOSVDIEndpoint= PanOSVirtualSystemID=0 PanOSEventTime=Feb 28 2021 08:30:17 cs3= cs3Label=VirtualLocation act= fname= msg=gRPC connection to f0d7d88a-0391-4899-a2e4-0938c4309e17.fei.lcaas-qa.us.paloaltonetworks.com:443 is established, xxx.xx.x.xx:48558 -> xxx.xx.x.xx:443 time: 2021-02-28 00:30:17 externalId=xxxxxxxxxxxxx PanOSDGHierarchyLevel1=0 PanOSDGHierarchyLevel2=0 PanOSDGHierarchyLevel3=0 PanOSDGHierarchyLevel4=0 PanOSVirtualSystemName= dvchost=xxxxx PanOSDeviceGroup= PanOSTemplate= PanOSTimeGeneratedHighResolution=Feb 28 2021 08:30:17
The following table identifies the System field names that the Log Forwarding app
uses when you forward logs using the CEF log format.
CEF Name
|
Field Details
|
---|---|
PanOSAgentContentVersion
| Query Name: agent_content_versionHeader Type: Custom |
PanOSAgentDataCollectionStatus
| Query Name: agent_data_collection_status.valueHeader Type: Custom |
PanOSAgentID
| Query Name: agent_idHeader Type: Custom |
PanOSAgentIsolationStatus
| Query Name: agent_isolation_statusHeader Type: Custom |
PanOSAgentStatus
| Query Name: agent_protection_statusHeader Type: Custom |
PanOSAgentVersion
| Query Name: agent_versionHeader Type: Custom |
PanOSConfigVersion
| Query Name: config_version.valueHeader Type: Custom |
PanOSTenantID
| Query Name: customer_idHeader Type: Custom |
PanOSDeviceGroup
| Query Name: device_group.valueHeader Type: Custom |
PanOSDGHierarchyLevel1
| Query Name: dg_hier_level_1Header Type: Custom |
PanOSDGHierarchyLevel2
| Query Name: dg_hier_level_2Header Type: Custom |
PanOSDGHierarchyLevel3
| Query Name: dg_hier_level_3Header Type: Custom |
PanOSDGHierarchyLevel4
| Query Name: dg_hier_level_4Header Type: Custom |
PanOSEndpointCPUArchitecture
| Query Name: endpoint_cpu_architecture.valueHeader Type: Custom |
PanOSEndpointDeviceDomain
| Query Name: endpoint_device_domainHeader Type: Custom |
PanOSEndpointDeviceName
| Query Name: endpoint_device_nameHeader Type: Custom |
PanOSEndpointIPaddress
| Query Name: endpoint_ip.valueHeader Type: Custom |
PanOSVDIEndpoint
| Query Name: endpoint_is_vdiHeader Type: Custom |
PanOSEndpointOSType
| Query Name: endpoint_os_type.valueHeader Type: Custom |
PanOSEndpointOSVersion
| Query Name: endpoint_os_versionHeader Type: Custom |
PanOSAgentTimeZoneOffset
| Query Name: endpoint_tz_offsetHeader Type: Custom |
PanOSEndpointUserDomain
| Query Name: endpoint_user.domainHeader Type: Custom |
PanOSEndpointUserName
| Query Name: endpoint_user.nameHeader Type: Custom |
PanOSEndpointUserUUID
| Query Name: endpoint_user.uuidHeader Type: Custom |
fname
| |
msg
| |
act
| |
PanOSEventTime
| Query Name: event_timeHeader Type: Custom |
PanOSIsDuplicateLog
| Query Name: is_dup_logHeader Type: Custom |
PanOSLogExported
| Query Name: is_exportedHeader Type: Custom |
PanOSLogForwarded
| Query Name: is_forwardedHeader Type: Custom |
PanOSIsPrismaNetwork
| Query Name: is_prisma_branchHeader Type: Custom |
PanOSIsPrismaUsers
| Query Name: is_prisma_mobileHeader Type: Custom |
cat
| |
PanOSLogSource
| Query Name: log_sourceHeader Type: Custom |
LogSourceGroupID
| Query Name: log_source_group_idHeader Type: Custom |
deviceExternalId
| |
dvchost
| |
PanOSLogSourceTimeZoneOffset
| Query Name: log_source_tz_offsetHeader Type: Custom |
rt
| Query Name: log_timeHeader Type: Predefined |
Device Event Class ID
| Query Name: log_type.valueHeader Type: Custom |
PanOSPanoramaSN
| Query Name: panorama_serialHeader Type: Custom |
externalId
| |
PanOSSeverity
| Query Name: severityHeader Type: Custom |
Name
| Query Name: sub_type.valueHeader Type: Custom |
PanOSTemplate
| Query Name: template.valueHeader Type: Custom |
PanOSTimeGeneratedHighResolution
| Query Name: time_generated_high_resHeader Type: Custom |
Device Vendor
| Query Name: vendor_nameHeader Type: Custom |
PanOSVendorSeverity
| Query Name: vendor_severity.valueHeader Type: Custom |
cs3
| Query Name: vsysHeader Type: PredefinedLabel: cs3LabelLabel Text: VirtualLocationMax Length: 4000 |
PanOSVirtualSystemID
| Query Name: vsys_idHeader Type: Custom |
PanOSVirtualSystemName
| Query Name: vsys_nameHeader Type: Custom |