HIP Match CEF Fields
Table of Contents
HIP Match CEF Fields
Example HIP Match log in CEF:
Mar 1 21:20:14 xxx.xx.x.xx 1505 <14>1 2021-03-01T21:20:14.889Z stream-logfwd20-587718190-03011312-b28y-harness-x4nx logforwarder - panwlogs - CEF:0|Palo Alto Networks|LF|2.0|HIPMATCH||3|ProfileToken=xxxxx dtz=UTC rt=Mar 01 2021 21:20:13 deviceExternalId=xxxxxxxxxxxxx PanOSIsDuplicateLog=false PanOSIsPrismaNetworks=false PanOSIsPrismaUsers=false PanOSLogExported=false PanOSLogForwarded=true PanOSLogSource=firewall PanOSLogSourceTimeZoneOffset= PanOSSourceDeviceClass= PanOSSourceDeviceOS= sntdom=xxxxx dntdom=xxxxx suser=xxxxx xxxxx duser=xxxxx xxxxx suid= duid= PanOSTenantID=xxxxxxxxxxxxx PanOSUUID= PanOSConfigVersion= start=Mar 01 2021 21:20:13 PanOSSourceUser=xxxxx\\xxxxx xxxxx cs3=vsys1 cs3Label=VirtualLocation shost=machine_name1 dhost=machine_name1 cs2=iOS cs2Label=EndpointOSType src=xxx.xx.x.xx dst=xxx.xx.x.xx cat=match_name1 cnt=1 PanOSHipMatchType=HIP Profile externalId=xxxxxxxxxxxxx PanOSDGHierarchyLevel1=12 PanOSDGHierarchyLevel2=0 PanOSDGHierarchyLevel3=0 PanOSDGHierarchyLevel4=0 PanOSVirtualSystemName= dvchost=PA-5220 cn2=1 cn2Label=VirtualSystemID c6a1=xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx c6a1Label=Device IPv6 Address PanOSHostID=xxxxxxxxxxxxxxe777947f-d92e-4815-9222-89438203bc2b PanOSEndpointSerialNumber=xxxxxxxxxxxxxx PanOSSourceDeviceCategory= PanOSSourceDeviceProfile= PanOSSourceDeviceModel= PanOSSourceDeviceVendor= PanOSSourceDeviceOSFamily= PanOSSourceDeviceOSVersion= PanOSSourceDeviceMac= PanOSSourceDeviceHost= PanOSSource= PanOSTimestampDeviceIdentification=Dec PanOSTimeGeneratedHighResolution=Jul 25 2019 23:30:12
The following table identifies the HIP Match field names that the Log Forwarding app
uses when you forward logs using the CEF log format.
CEF Name
|
Field Details
|
---|---|
PanOSConfigVersion
| Query Name: config_version.valueHeader Type: Custom |
cnt
| Query Name: count_of_repeatsHeader Type: Predefined |
PanOSTenantID
| Query Name: customer_idHeader Type: Custom |
PanOSDGHierarchyLevel1
| Query Name: dg_hier_level_1Header Type: Custom |
PanOSDGHierarchyLevel2
| Query Name: dg_hier_level_2Header Type: Custom |
PanOSDGHierarchyLevel3
| Query Name: dg_hier_level_3Header Type: Custom |
PanOSDGHierarchyLevel4
| Query Name: dg_hier_level_4Header Type: Custom |
shost and dhost
| Query Name: endpoint_device_nameHeader Type: Predefined |
cs2
| Query Name: endpoint_os_typeHeader Type: PredefinedLabel: cs2LabelLabel Text: EndpointOSTypeMax Length: 4000 |
PanOSEndpointSerialNumber
| Query Name: endpoint_serial_numberHeader Type: Custom |
cat
| |
PanOSHipMatchType
| Query Name: hip_match_type.valueHeader Type: Custom |
PanOSHostID
| Query Name: host_idHeader Type: Custom |
PanOSIsDuplicateLog
| Query Name: is_dup_logHeader Type: Custom |
PanOSLogExported
| Query Name: is_exportedHeader Type: Custom |
PanOSLogForwarded
| Query Name: is_forwardedHeader Type: Custom |
PanOSIsPrismaNetworks
| Query Name: is_prisma_branchHeader Type: Custom |
PanOSIsPrismaUsers
| Query Name: is_prisma_mobileHeader Type: Custom |
PanOSLogSource
| Query Name: log_sourceHeader Type: Custom |
LogSourceGroupID
| Query Name: log_source_group_idHeader Type: Custom |
deviceExternalId
| |
dvchost
| |
PanOSLogSourceTimeZoneOffset
| Query Name: log_source_tz_offsetHeader Type: Custom |
rt
| Query Name: log_timeHeader Type: Predefined |
Device Event Class ID
| Query Name: log_type.valueHeader Type: Custom |
PanOSPanoramaSN
| Query Name: panorama_serialHeader Type: Custom |
externalId
| |
PanOSSource
| Query Name: sourceHeader Type: Custom |
PanOSSourceDeviceCategory
| Query Name: source_device_categoryHeader Type: Custom |
PanOSSourceDeviceClass
| Query Name: source_device_classHeader Type: Custom |
PanOSSourceDeviceHost
| Query Name: source_device_hostHeader Type: Custom |
PanOSSourceDeviceMac
| Query Name: source_device_macHeader Type: Custom |
PanOSSourceDeviceModel
| Query Name: source_device_modelHeader Type: Custom |
PanOSSourceDeviceOS
| Query Name: source_device_osHeader Type: Custom |
PanOSSourceDeviceOSFamily
| Query Name: source_device_osfamilyHeader Type: Custom |
PanOSSourceDeviceOSVersion
| Query Name: source_device_osversionHeader Type: Custom |
PanOSSourceDeviceProfile
| Query Name: source_device_profileHeader Type: Custom |
PanOSSourceDeviceVendor
| Query Name: source_device_vendorHeader Type: Custom |
src and dst, or c6a2 and c6a3
| Query Name: source_ip.valueHeader Type: PredefinedLabel: || c6a2Label && c6a3LabelLabel Text: || Source IPv6 Address && Destination IPv6 Address |
c6a1
| Query Name: source_ip_v6.valueHeader Type: PredefinedLabel: c6a1LabelLabel Text: Device IPv6 Address |
PanOSSourceUser
| Query Name: source_userHeader Type: Custom |
sntdom and dntdom
| Query Name: source_user_info.domainHeader Type: Predefined |
suser and duser
| Query Name: source_user_info.nameHeader Type: Predefined |
suid and duid
| Query Name: source_user_info.uuidHeader Type: Predefined |
Name
| Query Name: sub_type.valueHeader Type: Custom |
start
| Query Name: time_generatedHeader Type: Predefined |
PanOSTimeGeneratedHighResolution
| Query Name: time_generated_high_resHeader Type: Custom |
PanOSTimestampDeviceIdentification
| Query Name: timestamp_device_identificationHeader Type: Custom |
PanOSUUID
| Query Name: uuidHeader Type: Custom |
Device Vendor
| Query Name: vendor_nameHeader Type: Custom |
cs3
| Query Name: vsysHeader Type: PredefinedLabel: cs3LabelLabel Text: VirtualLocationMax Length: 4000 |
cn2
| |
PanOSVirtualSystemName
| Query Name: vsys_nameHeader Type: Custom |