URL EMAIL Fields

Example URL log in EMAIL:
TimeReceived=2021-02-22T04:52:19.000000Z DeviceSN=xxxxxxxxxxxxx LogType=THREAT Subtype=url ConfigVersion=10.0 TimeGenerated=2021-02-22T04:51:55.000000Z SourceAddress=xxx.xx.x.xx DestinationAddress=xxx.xx.x.xx NATSource=xxx.xx.x.xx NATDestination= Rule=deny-time-wasters SourceUser="xxxxx\xxxxx o\"'\"test" DestinationUser="paloaltonetwork\xxxxx" Application=rhapsody VirtualLocation=vsys1 FromZone=ethernet4Zone-test2 ToZone=untrust InboundInterface=unknown OutboundInterface=ethernet1/3 LogSetting=rs-logging SessionID=837029 RepeatCount=1 SourcePort=21038 DestinationPort=24789 NATSourcePort=27050 NATDestinationPort=432 Protocol=tcp Action=reset-client URL=? URLCategory=travel VendorSeverity=Informational DirectionOfAttack=server to client SequenceNo=2638701702 SourceLocation=US DestinationLocation=dallas ContentType=application/foo PacketID=0 URLCounter=1 UserAgent= X-Forwarded-For= Referer= DGHierarchyLevel1=11 DGHierarchyLevel2=0 DGHierarchyLevel3=0 DGHierarchyLevel4=0 VirtualSystemName= DeviceName=xxxxx SourceUUID= DestinationUUID= HTTPMethod=post IMSI=36 IMEI=xxxxx ParentSessionID=6142 ParentStarttime=2021-02-22T04:51:49.000000Z Tunnel=VXLAN InlineMLVerdict=overflow ContentVersion=50222 SigFlags=2 HTTPHeaders= URLCategoryList=travel,​11008,​47022 RuleUUID=2fb8efd4-2f01-421d-a113-097992777432 HTTP2Connection=837029 DynamicUserGroupName= X-Forwarded-ForIP= SourceDeviceCategory=A-Phone SourceDeviceProfile=a-profile SourceDeviceModel=720P/60 SourceDeviceVendor=Samsung SourceDeviceOSFamily=M4500 SourceDeviceOSVersion=Android v8 SourceDeviceHost=pan-123 SourceDeviceMac=264989591511 DestinationDeviceCategory=A-Phone DestinationDeviceProfile=a-profile DestinationDeviceModel=iPhone DestinationDeviceVendor=Apple DestinationDeviceOSFamily=9 DestinationDeviceOSVersion=iOS 9 DestinationDeviceHost=pan-233 DestinationDeviceMac=743514319696 ContainerID=1873cc5c-0d31 ContainerNameSpace=pns_default ContainerName=pan-dp-77754f4 SourceEDL= DestinationEDL= HostID=1010101010 EndpointSerialNumber=xxxxxxxxxxxxxx SourceDynamicAddressGroup= DestinationDynamicAddressGroup= TimeGeneratedHighResolution=2021-02-22T04:51:55.231000Z NSSAINetworkSliceType=38
The following table identifies the URL field names that the Log Forwarding app uses when you forward logs using the EMAIL log format.
EMAIL Name
Query Name
Action
Application
app
ApplicationCategory
ApplicationSubcategory
CloudHostname
CloudReportID
ConfigVersion
ContainerID
ApplicationContainer
ContentType
ContentVersion
RepeatCount
CortexDataLakeTenantID
DestinationDeviceCategory
DestinationDeviceClass
DestinationDeviceHost
DestinationDeviceMac
DestinationDeviceModel
DestinationDeviceOS
DestinationDeviceOSFamily
DestinationDeviceOSVersion
DestinationDeviceProfile
DestinationDeviceVendor
DestinationDynamicAddressGroup
DestinationEDL
DestinationAddress
DestinationLocation
DestinationPort
DestinationUser
DestinationUserDomain
DestinationUserName
DestinationUserUUID
DestinationUUID
DGHierarchyLevel1
DGHierarchyLevel2
DGHierarchyLevel3
DGHierarchyLevel4
DirectionOfAttack
DynamicUserGroupName
EndpointSerialNumber
FileURL
FromZone
HostID
HTTP2Connection
HTTPHeaders
HTTPMethod
InboundInterface
InboundInterfaceDetailsPort
InboundInterfaceDetailsSlot
InboundInterfaceDetailsType
InboundInterfaceDetailsUnit
InlineMLVerdict
CaptivePortal
IsClienttoServer
IsContainer
IsDecryptMirror
IsDecrypted
IsDuplicateLog
IsEncrypted
LogExported
LogForwarded
IsIPV6
IsMptcpOn
NAT
IsNonStandardDestinationPort
IsPacketCapture
IsPhishing
IsPrismaNetwork
IsPrismaUsers
IsProxy
IsReconExcluded
IsSaaSApplication
IsServertoClient
IsSourceXForwarded
IsSystemReturn
IsTransaction
IsTunnelInspected
IsURLDenied
Location
LogSetting
LogSource
DeviceSN
DeviceName
LogSourceTimeZoneOffset
TimeReceived
LogType
IMEI
NATDestination
NATDestinationPort
NATSource
NATSourcePort
NonStandardDestinationPort
NSSAINetworkSliceType
OutboundInterface
OutboundInterfaceDetailsPort
OutboundInterfaceDetailsSlot
OutboundInterfaceDetailsType
OutboundInterfaceDetailsUnit
ParentSessionID
ParentStarttime
Packet
PacketID
ContainerName
ContainerNameSpace
Protocol
Referer
HTTPRefererFQDN
HTTPRefererPort
HTTPRefererProtocol
HTTPRefererURLPath
ApplicationRisk
Rule
RuleUUID
SanctionedStateofApp
SequenceNo
SessionID
Severity
SigFlags
SourceDeviceCategory
SourceDeviceClass
SourceDeviceHost
SourceDeviceMac
SourceDeviceModel
SourceDeviceOS
SourceDeviceOSFamily
SourceDeviceOSVersion
SourceDeviceProfile
SourceDeviceVendor
SourceDynamicAddressGroup
SourceEDL
SourceAddress
SourceLocation
SourcePort
SourceUser
SourceUserDomain
SourceUserName
SourceUserUUID
SourceUUID
Subtype
ApplicationTechnology
TimeGenerated
TimeGeneratedHighResolution
ToZone
Tunnel
TunneledApplication
IMSI
URL
uri
URLCategory
URLCategoryList
URLDomain
URLCounter
UserAgent
Users
VendorName
VendorSeverity
VirtualLocation
VirtualSystemID
VirtualSystemName
X-Forwarded-For
xff
X-Forwarded-ForIP

Recommended For You