UserID CEF Fields
Table of Contents
UserID CEF Fields
Example UserID log in CEF:
Mar 1 21:06:03 xxx.xx.x.xx 1324 <14>1 2021-03-01T21:06:03.844Z stream-logfwd20-587718190-03011255-ut6o-harness-5vlj logforwarder - panwlogs - CEF:0|Palo Alto Networks|LF|2.0|USERID|logout|3|ProfileToken=xxxxx dtz=UTC rt=Mar 01 2021 21:06:02 deviceExternalId=xxxxxxxxxxxxx PanOSConfigVersion= dntdom=paloaltonetwork duser=xxxxx duid= PanOSCortexDataLakeTenantID=xxxxxxxxxxxxx PanOSIsDuplicateLog=false PanOSIsDuplicateUser= PanOSIsPrismaNetworks=false PanOSIsPrismaUsers=false PanOSLogExported=false PanOSLogForwarded=true PanOSLogSource=firewall PanOSLogSourceTimeZoneOffset= PanOSUserGroupFound= start=Mar 01 2021 21:06:02 cs3=vsys1 cs3Label=VirtualLocation src=xxx.xx.x.xx dst=xxx.xx.x.xx duser0=paloaltonetworks\\xxxxx cs4=fake-data-source-169 cs4Label=MappingDataSourceName cat=0 cnt=1 cn3=3531 cn3Label=MappingTimeout spt=21015 dpt=49760 cs5=probing cs5Label=MappingDataSource cs6=netbios_probing cs6Label=MappingDataSourceType externalId=xxxxxxxxxxxxx PanOSDGHierarchyLevel1=12 PanOSDGHierarchyLevel2=0 PanOSDGHierarchyLevel3=0 PanOSDGHierarchyLevel4=0 PanOSVirtualSystemName= dvchost=PA-5220 cn2=1 cn2Label=VirtualSystemID cs1=xxxxx cs1Label=MFAFactorType end=Jul 09 2019 18:15:44 cn1=3 cn1Label=AuthFactorNo PanOSUGFlags=0x100 PanOSUserIdentifiedBySource=xxxxxxxxxxxxxx PanOSTag= PanOSTimeGeneratedHighResolution=Jul 25 2019 23:30:12
The following table identifies the UserID field names that the Log Forwarding app
uses when you forward logs using the CEF log format.
CEF Name
|
Field Details
|
---|---|
end
| Query Name: auth_completion_timeHeader Type: Predefined |
cn1
| |
dntdom
| |
duser
| |
duid
| |
PanOSConfigVersion
| Query Name: config_version.valueHeader Type: Custom |
cnt
| Query Name: count_of_repeatsHeader Type: Predefined |
PanOSCortexDataLakeTenantID
| Query Name: customer_idHeader Type: Custom |
dpt
| Query Name: dest_portHeader Type: Predefined |
PanOSDGHierarchyLevel1
| Query Name: dg_hier_level_1Header Type: Custom |
PanOSDGHierarchyLevel2
| Query Name: dg_hier_level_2Header Type: Custom |
PanOSDGHierarchyLevel3
| Query Name: dg_hier_level_3Header Type: Custom |
PanOSDGHierarchyLevel4
| Query Name: dg_hier_level_4Header Type: Custom |
cat
| |
PanOSIsDuplicateLog
| Query Name: is_dup_logHeader Type: Custom |
PanOSIsDuplicateUser
| Query Name: is_duplicate_userHeader Type: Custom |
PanOSLogExported
| Query Name: is_exportedHeader Type: Custom |
PanOSLogForwarded
| Query Name: is_forwardedHeader Type: Custom |
PanOSIsPrismaNetworks
| Query Name: is_prisma_branchHeader Type: Custom |
PanOSIsPrismaUsers
| Query Name: is_prisma_mobileHeader Type: Custom |
PanOSLogSource
| Query Name: log_sourceHeader Type: Custom |
LogSourceGroupID
| Query Name: log_source_group_idHeader Type: Custom |
deviceExternalId
| |
dvchost
| |
PanOSLogSourceTimeZoneOffset
| Query Name: log_source_tz_offsetHeader Type: Custom |
rt
| Query Name: log_timeHeader Type: Predefined |
Device Event Class ID
| Query Name: log_type.valueHeader Type: Custom |
cs5
| Query Name: mapping_data_source.valueHeader Type: PredefinedLabel: cs5LabelLabel Text: MappingDataSourceMax Length: 4000 |
cs4
| Query Name: mapping_data_source_nameHeader Type: PredefinedLabel: cs4LabelLabel Text: MappingDataSourceNameMax Length: 4000 |
cs6
| Query Name: mapping_data_source_type.valueHeader Type: PredefinedLabel: cs6LabelLabel Text: MappingDataSourceTypeMax Length: 4000 |
cn3
| |
cs1
| Query Name: mfa_factor_typeHeader Type: PredefinedLabel: cs1LabelLabel Text: MFAFactorTypeMax Length: 4000 |
PanOSPanoramaSN
| Query Name: panorama_serialHeader Type: Custom |
externalId
| |
src and dst, or c6a2 and c6a3
| Query Name: source_ip.valueHeader Type: PredefinedLabel: || c6a2Label && c6a3LabelLabel Text: || Source IPv6 Address && Destination IPv6 Address |
spt
| Query Name: source_portHeader Type: Predefined |
Name
| Query Name: sub_type.valueHeader Type: Custom |
PanOSTag
| Query Name: tag_nameHeader Type: Custom |
start
| Query Name: time_generatedHeader Type: Predefined |
PanOSTimeGeneratedHighResolution
| Query Name: time_generated_high_resHeader Type: Custom |
PanOSUGFlags
| Query Name: ug_flagsHeader Type: Custom |
duser
| |
PanOSUserGroupFound
| Query Name: user_group_foundHeader Type: Custom |
PanOSUserIdentifiedBySource
| Query Name: user_identified_by_source_asHeader Type: Custom |
Device Vendor
| Query Name: vendor_nameHeader Type: Custom |
cs3
| Query Name: vsysHeader Type: PredefinedLabel: cs3LabelLabel Text: VirtualLocationMax Length: 4000 |
cn2
| |
PanOSVirtualSystemName
| Query Name: vsys_nameHeader Type: Custom |