PAN OS Attribute Reference
Focus
Focus
Device Security

PAN OS Attribute Reference

Table of Contents

PAN OS Attribute Reference

This reference lists the attributes that Device Security collects from PAN OS, their names as stored in Device Security, and the Device Security fields they map to.
When Device Security integrates with PAN-OS, it gains better visibility into your Palo Alto Networks firewall infrastructure. The attributes in this reference cover firewall device records and network interface data learned from PAN-OS.
The third-party attribute name in Device Security refers to the attribute name as it appears in the Assets Inventory table and in Query Engine. This follows the format of third-party-name.attribute-name. When viewing the attribute name in the Assets Inventory table column selector or on a Device Details page, where the third-party name can be found as a header for the attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the Query Builder and in the Assets Inventory table, but under Device DetailsAttributesIntegration Specific AttributesMicrosoft Defender, the attribute would appear as macAddress.

Show System Info Attributes

Device Security collects show system info attributes from PAN OS. The following table lists each PAN OS attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
PAN OS Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
devicename
panos.devicename
Device Name
Devicename
hostname
panos.hostname
hostname
Name of the device
ip-address
panos.ip_address
IP Address
Ip-address
mac-address
panos.mac_address
MAC; id
Mac-address
model
panos.model
Model
Model of the device
sw-version
panos.sw_version
OS Version
Sw-version
serial
panos.serial
Serial Number
Serial number of the device
advanced-routing
panos.advanced_routing
Advanced-routing
app-version
panos.app_version
App-version
av-version
panos.av_version
Av-version
cloud-mode
panos.cloud_mode
Cloud-mode
default-gateway
panos.default_gateway
Default-gateway
device-certificate-status
panos.device_certificate_status
Device-certificate-status
family
panos.family
Family
operational-mode
panos.operational_mode
Operational-mode
platform-family
panos.platform_family
Platform-family
public-ip-address
panos.public_ip_address
Public-ip-address
threat-version
panos.threat_version
Threat-version
vm-cap-tier
panos.vm_cap_tier
Vm-cap-tier
vm-cores
panos.vm_cores
Vm-cores
vm-cpuid
panos.vm_cpuid
Vm-cpuid
vm-license
panos.vm_license
Vm-license
vm-mac-base
panos.vm_mac_base
Vm-mac-base
vm-mode
panos.vm_mode
Vm-mode

Show Interface All Attributes

Device Security collects show interface all attributes from PAN OS. The following table lists each PAN OS attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
PAN OS Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
mac_address
panos.mac_address
id; MAC
Mac address
ip_address
panos.ip_address
IP Address
IP address
interface_list
panos.interface_list
third_party_learned_network_interfaces
Interface list
* Only some attributes map to a Device Security Common Attribute.