DNS Security CEF Fields
Table of Contents
DNS Security CEF Fields
The following table identifies the DNS Security field names that the Log Forwarding app
uses when you forward logs using the CEF log format.
CEF Name
|
Field Details
|
---|---|
act
| |
PanOSCortexDataLakeTenantID
| Query Name: customer_idHeader Type: Custom |
PanOSDNSResolverIP
| Query Name: dest_ip.valueHeader Type: Custom |
PanOSDNSResponse
| Query Name: dns_responseHeader Type: Custom |
PanOSDNSResponseCode
| Query Name: dns_response_codeHeader Type: Custom |
duser
| |
cs5
| |
request
| |
cs4
| |
PanOSThreatID
| Query Name: gtidHeader Type: Custom |
PanOSLogSource
| Query Name: log_sourceHeader Type: Custom |
LogSourceGroupID
| |
deviceExternalID
| |
rt
| Query Name: log_timeHeader Type: Predefined |
DeviceEventClassID
| Query Name: log_type.valueHeader Type: Custom |
PanOSPanoramaSN
| Query Name: panorama_serialHeader Type: Custom |
PlatformType
| Query Name: platform_typeHeader Type: Custom |
PanOSDNSSecuityVersion
| Query Name: protocolHeader Type: Custom |
PanOSRecordType
| Query Name: record_typeHeader Type: Custom |
src
| Query Name: source_ip.valueHeader Type: Predefined |
suser
| |
Name
| Query Name: sub_type.valueHeader Type: Custom |
cat
| |
start
| Query Name: time_generatedHeader Type: Predefined |
cn3
| Query Name: total_time_elapsedHeader Type: Predefined |
Device Vendor
| Query Name: vendor_nameHeader Type: Custom |
PanOSDNSCategory
| Query Name: verdict.valueHeader Type: Custom |