Events
Focus
Focus
Strata Logging Service

Events

Table of Contents

Events

Endpoint Events logs record security-relevant activities detected by the Prisma Access Browser and SASE agent on managed endpoints. Use these logs to monitor user behavior, content access, application usage, device posture, and policy enforcement actions across your managed browser environment.
Following are the supported log formats:
EVENTS Field
(Display Name)
Description
application.​account_inventory_id
(APPLICATION - ACCOUNT INVENTORY ID)
The inventory ID for the application account associated with the event.
application.​app_category
(APPLICATION - APP CATEGORY)
The application's main category.
EMAIL field name: ApplicationAppCategory
HTTPS field name: ApplicationAppCategory
LEEF field name: ApplicationAppCategory
application.​app_sub_category
(APPLICATION - APP SUBCATEGORY)
The application's sub-category.
EMAIL field name: ApplicationAppSubcategory
HTTPS field name: ApplicationAppSubcategory
LEEF field name: ApplicationAppSubcategory
application.​application_account.​channel_id
(APPLICATION ACCOUNT CHANNEL ID)
The channel identifier in the application account.
EMAIL field name: ApplicationAccountChannelId
HTTPS field name: ApplicationAccountChannelId
application.​application_account.​displayed_value
(APPLICATION ACCOUNT DISPLAY VALUE)
The value displayed to represent the account.
application.​application_account.​domain
(APPLICATION ACCOUNT DOMAIN)
The domain associated with the application account.
EMAIL field name: ApplicationAccountDomain
HTTPS field name: ApplicationAccountDomain
LEEF field name: ApplicationAccountDomain
application.​application_account.​region
(APPLICATION ACCOUNT REGION)
The geographic region associated with the application account.
EMAIL field name: ApplicationAccountRegion
HTTPS field name: ApplicationAccountRegion
LEEF field name: ApplicationAccountRegion
application.​application_account.​tenant_id
(APPLICATION ACCOUNT TENANT ID)
The tenant identifier associated with the application account.
EMAIL field name: ApplicationAccountTenantId
HTTPS field name: ApplicationAccountTenantId
application.​application_account.​workspace_name
(APPLICATION ACCOUNT WORKSPACE NAME)
The workspace name associated with the application account.
application.​application_account_identifier
(APPLICATION ACCOUNT ID)
Unique identifier for the application account.
EMAIL field name: ApplicationAccountId
HTTPS field name: ApplicationAccountId
LEEF field name: ApplicationAccountId
application.​classification
(APPLICATION - CLASSIFICATION)
The classification of the application.
EMAIL field name: ApplicationClassification
HTTPS field name: ApplicationClassification
LEEF field name: ApplicationClassification
application.​credential_type
(APPLICATION - CREDENTIAL TYPE)
The credential type for the application account.
EMAIL field name: ApplicationCredentialType
HTTPS field name: ApplicationCredentialType
LEEF field name: ApplicationCredentialType
application.​external_id
(APPLICATION - EXTERNAL ID)
External identifier for the application.
EMAIL field name: ApplicationExternalID
HTTPS field name: ApplicationExternalID
LEEF field name: ApplicationExternalID
application.​external_name
(APPLICATION - EXTERNAL NAME)
External name for the application.
EMAIL field name: ApplicationExternalName
HTTPS field name: ApplicationExternalName
LEEF field name: ApplicationExternalName
application.​id
(APPLICATION - ID)
Enumeration integer assigned to the application field value.
CEF field name: PanOSApplicationID
EMAIL field name: ApplicationID
HTTPS field name: ApplicationID
LEEF field name: ApplicationID
application.​identity_provider_url
(APPLICATION IDENTITY PROVIDER URL)
Enumeration integer assigned to the application field value.
application.​is_gen_ai
(IS GEN AI)
Whether the application is a Generative AI application.
CEF field name: PanOSIsGenAi
EMAIL field name: IsGenAi
HTTPS field name: IsGenAi
LEEF field name: IsGenAi
application.​local_desktop.​file_description
(APPLICATION - LOCAL DESKTOP FILE DESCRIPTION)
The file description of the local desktop application.
application.​local_desktop.​icon_id
(APPLICATION - LOCAL DESKTOP ICON ID)
Icon identifier for the local desktop application.
application.​local_desktop.​original_file_name
(APPLICATION - LOCAL DESKTOP ORIGINAL FILE NAME)
The original file name of the local desktop application.
application.​local_desktop.​parent_process_path
(APPLICATION - LOCAL DESKTOP PARENT PROCESS PATH)
The path of the parent process for the local desktop application.
application.​local_desktop.​process_path
(APPLICATION - LOCAL DESKTOP PROCESS PATH)
The path to the local desktop application's executable.
application.​local_desktop.​product_name
(APPLICATION - LOCAL DESKTOP PRODUCT NAME)
The product name of the local desktop application.
application.​local_desktop.​thumbprint
(APPLICATION - LOCAL DESKTOP THUMBPRINT)
Digital thumbprint of the local desktop application.
application.​local_desktop.​window_title
(APPLICATION - LOCAL DESKTOP WINDOW TITLE)
The window title of the local desktop application.
application.​login_id
(APPLICATION LOGIN ID)
Identifier for the application login session.
CEF field name: PanOSApplicationLoginId
EMAIL field name: ApplicationLoginId
HTTPS field name: ApplicationLoginId
LEEF field name: ApplicationLoginId
application.​login_method
(APPLICATION LOGIN METHOD)
Method used to log in to the application (e.g., SSO, password).
EMAIL field name: ApplicationLoginMethod
HTTPS field name: ApplicationLoginMethod
LEEF field name: ApplicationLoginMethod
application.​name
(APPLICATION - NAME)
The name of the application associated with the event.
CEF field name: PanOSApplicationName
EMAIL field name: ApplicationName
HTTPS field name: ApplicationName
LEEF field name: ApplicationName
application.​protected_account
(APPLICATION - PROTECTED ACCOUNT)
The protected account associated with the application.
EMAIL field name: ApplicationProtectedAccount
HTTPS field name: ApplicationProtectedAccount
application.​reputation
(APPLICATION REPUTATION)
The reputation of the application.
EMAIL field name: ApplicationReputation
HTTPS field name: ApplicationReputation
LEEF field name: ApplicationReputation
application.​reputation_risk
(APPLICATION REPUTATION RISK)
The reputation risk level of the application.
EMAIL field name: ApplicationReputationRisk
HTTPS field name: ApplicationReputationRisk
LEEF field name: ApplicationReputationRisk
application.​risk_of_app
(APPLICATION - RISK OF APP)
The risk level of the application.
EMAIL field name: ApplicationRiskOfApp
HTTPS field name: ApplicationRiskOfApp
LEEF field name: ApplicationRiskOfApp
application.​service_provider_url
(APPLICATION SERVICE PROVIDER URL)
The URL of the service provider associated with the application.
application.​source
(APPLICATION - SOURCE)
The source from which the application was identified.
CEF field name: PanOSApplicationSource
EMAIL field name: ApplicationSource
HTTPS field name: ApplicationSource
LEEF field name: ApplicationSource
application.​tags
(APPLICATION - TAGS)
List of tags associated with the application.
CEF field name: PanOSApplicationTags
EMAIL field name: ApplicationTags
HTTPS field name: ApplicationTags
LEEF field name: ApplicationTags
application.​use_cases
(APPLICATION USECASES)
Use cases the application is associated with.
CEF field name: PanOSApplicationUsecases
EMAIL field name: ApplicationUsecases
HTTPS field name: ApplicationUsecases
LEEF field name: ApplicationUsecases
application.​username
(APPLICATION - USERNAME)
The username associated with the application account.
CEF field name: PanOSApplicationUsername
EMAIL field name: ApplicationUsername
HTTPS field name: ApplicationUsername
LEEF field name: ApplicationUsername
application.​webauthn.​authenticator
(APPLICATION - WEBAUTHN AUTHENTICATOR)
The type of WebAuthn authenticator used for authentication.
application.​webauthn.​authenticator_attachment
(APPLICATION - WEBAUTHN AUTHENTICATOR ATTACHMENT)
The attachment type of the WebAuthn authenticator.
application.​webauthn.​credential_id
(APPLICATION - WEBAUTHN CREDENTIAL ID)
The credential ID used in the WebAuthn flow.
application.​webauthn.​error.​message
(APPLICATION - WEBAUTHN ERROR MESSAGE)
The error message from the WebAuthn flow.
application.​webauthn.​error.​name
(APPLICATION - WEBAUTHN ERROR NAME)
The error name from the WebAuthn flow.
application.​webauthn.​relying_party_id
(APPLICATION - WEBAUTHN RELYING PARTY ID)
The relying party ID for the WebAuthn flow.
application.​webauthn.​user_handle
(APPLICATION - WEBAUTHN USER HANDLE)
The user handle for the WebAuthn flow.
auth.​sso_provider
(AUTH - SSO PROVIDER)
The SSO provider used for authentication.
CEF field name: PanOSAuthSsoProvider
EMAIL field name: AuthSsoProvider
HTTPS field name: AuthSsoProvider
LEEF field name: AuthSsoProvider
batch_id
(BATCH ID)
The event's batch identifier.
CEF field name: PanOSBatchID
EMAIL field name: BatchID
HTTPS field name: BatchID
LEEF field name: BatchID
browser_extension.​app_launch_url
(BROWSER EXTENSION - APP LAUNCH URL)
The launch URL of the browser extension app.
browser_extension.​available_launch_types
(BROWSER EXTENSION - AVAILABLE LAUNCH TYPES)
Available launch types for the browser extension.
browser_extension.​description
(BROWSER EXTENSION - DESCRIPTION)
Description of the browser extension.
EMAIL field name: BrowserExtensionDescription
HTTPS field name: BrowserExtensionDescription
browser_extension.​disabled_reason
(BROWSER EXTENSION - DISABLED REASON)
Reason the browser extension was disabled.
browser_extension.​enabled
(BROWSER EXTENSION - ENABLED)
Whether the browser extension is enabled.
EMAIL field name: BrowserExtensionEnabled
HTTPS field name: BrowserExtensionEnabled
LEEF field name: BrowserExtensionEnabled
browser_extension.​homepage_url
(BROWSER EXTENSION - HOMEPAGE URL)
Homepage URL of the browser extension.
EMAIL field name: BrowserExtensionHomepageURL
HTTPS field name: BrowserExtensionHomepageURL
browser_extension.​host_permissions
(BROWSER EXTENSION - HOST PERMISSIONS)
Host permissions the browser extension requires.
browser_extension.​id
(BROWSER EXTENSION - ID)
Enumeration integer assigned to the browser_extension field value.
CEF field name: PanOSBrowserExtensionID
EMAIL field name: BrowserExtensionID
HTTPS field name: BrowserExtensionID
LEEF field name: BrowserExtensionID
browser_extension.​install_type
(BROWSER EXTENSION - INSTALL TYPE)
How the browser extension was installed (e.g., normal, sideload).
EMAIL field name: BrowserExtensionInstallType
HTTPS field name: BrowserExtensionInstallType
browser_extension.​is_app
(BROWSER EXTENSION - IS APP)
Whether the browser extension is an app.
EMAIL field name: BrowserExtensionIsApp
HTTPS field name: BrowserExtensionIsApp
LEEF field name: BrowserExtensionIsApp
browser_extension.​launch_type
(BROWSER EXTENSION - LAUNCH TYPE)
How the browser extension is launched.
EMAIL field name: BrowserExtensionLaunchType
HTTPS field name: BrowserExtensionLaunchType
browser_extension.​may_disable
(BROWSER EXTENSION - MAY DISABLE)
Whether the browser extension can be disabled.
EMAIL field name: BrowserExtensionMayDisable
HTTPS field name: BrowserExtensionMayDisable
browser_extension.​name
(BROWSER EXTENSION - NAME)
Name of the browser extension.
EMAIL field name: BrowserExtensionName
HTTPS field name: BrowserExtensionName
LEEF field name: BrowserExtensionName
browser_extension.​offline_enabled
(BROWSER EXTENSION - OFFLINE ENABLED)
Whether the browser extension works offline.
browser_extension.​options_url
(BROWSER EXTENSION - OPTIONS URL)
Options page URL of the browser extension.
EMAIL field name: BrowserExtensionOptionsURL
HTTPS field name: BrowserExtensionOptionsURL
browser_extension.​permissions
(BROWSER EXTENSION - PERMISSIONS)
Permissions the browser extension has.
EMAIL field name: BrowserExtensionPermissions
HTTPS field name: BrowserExtensionPermissions
browser_extension.​short_name
(BROWSER EXTENSION - SHORT NAME)
Short name of the browser extension.
EMAIL field name: BrowserExtensionShortName
HTTPS field name: BrowserExtensionShortName
LEEF field name: BrowserExtensionShortName
browser_extension.​type
(BROWSER EXTENSION - TYPE)
Browser extension context.
EMAIL field name: BrowserExtensionType
HTTPS field name: BrowserExtensionType
LEEF field name: BrowserExtensionType
browser_extension.​update_url
(BROWSER EXTENSION - UPDATE URL)
URL from which the browser extension receives updates.
EMAIL field name: BrowserExtensionUpdateURL
HTTPS field name: BrowserExtensionUpdateURL
LEEF field name: BrowserExtensionUpdateURL
browser_extension.​version
(BROWSER EXTENSION - VERSION)
Version of the browser extension.
EMAIL field name: BrowserExtensionVersion
HTTPS field name: BrowserExtensionVersion
LEEF field name: BrowserExtensionVersion
certificate.​created_time
(CERTIFICATE - CREATED TIME)
The creation timestamp of the certificate.
EMAIL field name: CertificateCreatedTime
HTTPS field name: CertificateCreatedTime
LEEF field name: CertificateCreatedTime
certificate.​expiration_time
(CERTIFICATE - EXPIRATION TIME)
The expiration timestamp of the certificate.
EMAIL field name: CertificateExpirationTime
HTTPS field name: CertificateExpirationTime
LEEF field name: CertificateExpirationTime
certificate.​fingerprints
(CERTIFICATE - FINGERPRINTS)
Fingerprints of the certificate.
EMAIL field name: CertificateFingerprints
HTTPS field name: CertificateFingerprints
LEEF field name: CertificateFingerprints
certificate.​issuer
(CERTIFICATE - ISSUER)
The issuing authority of the certificate.
CEF field name: PanOSCertificateIssuer
EMAIL field name: CertificateIssuer
HTTPS field name: CertificateIssuer
LEEF field name: CertificateIssuer
certificate.​serial_number
(CERTIFICATE - SERIAL NUMBER)
The serial number of the certificate.
EMAIL field name: CertificateSerialNumber
HTTPS field name: CertificateSerialNumber
LEEF field name: CertificateSerialNumber
certificate.​subject
(CERTIFICATE - SUBJECT)
The subject of the certificate.
CEF field name: PanOSCertificateSubject
EMAIL field name: CertificateSubject
HTTPS field name: CertificateSubject
LEEF field name: CertificateSubject
classification.​category
(CLASSIFICATION - CATEGORY)
Category of the security classification.
EMAIL field name: ClassificationCategory
HTTPS field name: ClassificationCategory
LEEF field name: ClassificationCategory
classification.​malicious_categories
(CLASSIFICATION - MALICIOUS CATEGORIES)
List of malicious categories identified.
classification.​mitre
(CLASSIFICATION - MITRE)
MITRE ATT&CK framework category associated with the event.
CEF field name: PanOSClassificationMITRE
EMAIL field name: ClassificationMITRE
HTTPS field name: ClassificationMITRE
LEEF field name: ClassificationMITRE
classification.​reputation
(CLASSIFICATION - REPUTATION)
Reputation classification of the entity.
EMAIL field name: ClassificationReputation
HTTPS field name: ClassificationReputation
LEEF field name: ClassificationReputation
classification.​security_compliance
(CLASSIFICATION - SECURITY COMPLIANCE)
Security compliance classification.
classification.​severity
(CLASSIFICATION - SEVERITY )
Severity level of the classification.
EMAIL field name: ClassificationSeverity
HTTPS field name: ClassificationSeverity
LEEF field name: ClassificationSeverity
clipboard.​from_local_desktop_app.​file_description
(CLIPBOARD - FROM LOCAL DESKTOP APP FILE DESCRIPTION)
File description of the application from which clipboard content originates.
clipboard.​from_local_desktop_app.​icon_id
(CLIPBOARD - FROM LOCAL DESKTOP APP ICON ID)
Icon ID of the application from which clipboard content originates.
clipboard.​from_local_desktop_app.​original_file_name
(CLIPBOARD - FROM LOCAL DESKTOP APP ORIGINAL FILE NAME)
Original file name of the application from which clipboard content originates.
clipboard.​from_local_desktop_app.​parent_process_path
(CLIPBOARD - FROM LOCAL DESKTOP APP PARENT PROCESS PATH)
Parent process path of the application from which clipboard content originates.
clipboard.​from_local_desktop_app.​process_path
(CLIPBOARD - FROM LOCAL DESKTOP APP PROCESS PATH)
Process path of the application from which clipboard content originates.
clipboard.​from_local_desktop_app.​product_name
(CLIPBOARD - FROM LOCAL DESKTOP APP PRODUCT NAME)
Product name of the application from which clipboard content originates.
clipboard.​from_local_desktop_app.​thumbprint
(CLIPBOARD - FROM LOCAL DESKTOP APP THUMBPRINT)
Thumbprint of the application from which clipboard content originates.
clipboard.​from_local_desktop_app.​window_title
(CLIPBOARD - FROM LOCAL DESKTOP APP WINDOW TITLE)
Window title of the application from which clipboard content originates.
clipboard.​from_url
(CLIPBOARD - FROM URL)
The URL from which the clipboard content was copied.
CEF field name: PanOSClipboardFromURL
EMAIL field name: ClipboardFromURL
HTTPS field name: ClipboardFromURL
LEEF field name: ClipboardFromURL
clipboard.​search_engine
(CLIPBOARD - SEARCH ENGINE)
The search engine used in the clipboard event.
EMAIL field name: ClipboardSearchEngine
HTTPS field name: ClipboardSearchEngine
LEEF field name: ClipboardSearchEngine
clipboard.​selected_element
(CLIPBOARD - SELECTED ELEMENT)
The UI element from which the clipboard content was selected.
EMAIL field name: ClipboardSelectedElement
HTTPS field name: ClipboardSelectedElement
LEEF field name: ClipboardSelectedElement
content.​categories
(CONTENT - CATEGORIES)
Content categories identified in the event.
CEF field name: PanOSContentCategories
EMAIL field name: ContentCategories
HTTPS field name: ContentCategories
LEEF field name: ContentCategories
content.​length_bytes
(CONTENT - LENGTH BYTES)
Length of the content in bytes.
CEF field name: PanOSContentLengthBytes
EMAIL field name: ContentLengthBytes
HTTPS field name: ContentLengthBytes
LEEF field name: ContentLengthBytes
content.​live_scanning.​detection_id
(CONTENT LIVE SCANNING DETECTION ID)
Detection ID from live content scanning.
content.​live_scanning.​malicious_content_url
(CONTENT LIVE SCANNING MALICIOUS URL)
URL of malicious content detected by live scanning.
content.​live_scanning.​malicious_object
(CONTENT LIVE SCANNING MALICIOUS OBJECT)
Malicious object identified during live scanning.
content.​live_scanning.​scan_method
(CONTENT LIVE SCANNING METHOD)
Method used by the live content scanner.
EMAIL field name: ContentLiveScanningMethod
HTTPS field name: ContentLiveScanningMethod
LEEF field name: ContentLiveScanningMethod
content.​live_scanning.​triggered_by
(CONTENT LIVE SCANNING TRIGGERED BY)
What triggered the live content scan.
content.​mip_matched_label
(CONTENT - MIP MATCHED LABEL)
Microsoft Information Protection label matched in the content.
EMAIL field name: ContentMIPMatchedLabel
HTTPS field name: ContentMIPMatchedLabel
LEEF field name: ContentMIPMatchedLabel
content.​scan_engine
(CONTENT - SCAN ENGINE)
Content scanning engine used.
CEF field name: PanOSContentScanEngine
EMAIL field name: ContentScanEngine
HTTPS field name: ContentScanEngine
LEEF field name: ContentScanEngine
content.​sensitive_data_categories
(CONTENT - SENSITIVE DATA CATEGORIES)
Sensitive data categories found in the content.
content.​source_element_selector
(CONTENT - SOURCE ELEMENT SELECTOR)
CSS/DOM selector of the source element from which content originated.
content.​source_url
(CONTENT - SOURCE URL)
Source URL of the content.
CEF field name: PanOSContentSourceURL
EMAIL field name: ContentSourceURL
HTTPS field name: ContentSourceURL
LEEF field name: ContentSourceURL
content.​trace_id
(CONTENT TRACE ID)
Trace ID for the content scanning operation.
CEF field name: PanOSContentTraceId
EMAIL field name: ContentTraceId
HTTPS field name: ContentTraceId
LEEF field name: ContentTraceId
customer_id
(CORTEX DATA LAKE TENANT ID)
The ID that uniquely identifies the Cortex Data Lake instance which received this log record.
EMAIL field name: CortexDataLakeTenantID
HTTPS field name: CortexDataLakeTenantID
LEEF field name: CortexDataLakeTenantID
device.​agent_id
(DEVICE - AGENT ID)
Unique identifier for the Prisma Access Browser agent.
CEF field name: PanOSDeviceAgentID
EMAIL field name: DeviceAgentID
HTTPS field name: DeviceAgentID
LEEF field name: DeviceAgentID
device.​browser_brand
(DEVICE - BROWSER BRAND)
Browser brand (e.g., Google Chrome, Microsoft Edge).
CEF field name: PanOSDeviceBrowserBrand
EMAIL field name: DeviceBrowserBrand
HTTPS field name: DeviceBrowserBrand
LEEF field name: DeviceBrowserBrand
device.​browser_process_id
(DEVICE - BROWSER PROCESS ID)
Process ID of the browser.
EMAIL field name: DeviceBrowserProcessID
HTTPS field name: DeviceBrowserProcessID
LEEF field name: DeviceBrowserProcessID
device.​browser_type
(DEVICE - BROWSER TYPE)
Type of browser (e.g., Chrome, Edge, Safari).
CEF field name: PanOSDeviceBrowserType
EMAIL field name: DeviceBrowserType
HTTPS field name: DeviceBrowserType
LEEF field name: DeviceBrowserType
device.​browser_version
(DEVICE - BROWSER VERSION)
Version of the browser.
EMAIL field name: DeviceBrowserVersion
HTTPS field name: DeviceBrowserVersion
LEEF field name: DeviceBrowserVersion
device.​cortex_agent_id
(DEVICE - CORTEX AGENT ID)
Cortex agent identifier for the device.
CEF field name: PanOSDeviceCortexAgentID
EMAIL field name: DeviceCortexAgentID
HTTPS field name: DeviceCortexAgentID
LEEF field name: DeviceCortexAgentID
device.​country
(DEVICE - COUNTRY)
Country from which the device is accessing the network.
CEF field name: PanOSDeviceCountry
EMAIL field name: DeviceCountry
HTTPS field name: DeviceCountry
LEEF field name: DeviceCountry
device.​device_uuid
(DEVICE - UUID )
Unique identifier (UUID) for the endpoint device.
CEF field name: PanOSDeviceUUID
EMAIL field name: DeviceUUID
HTTPS field name: DeviceUUID
LEEF field name: DeviceUUID
device.​disk_encryption_status
(DEVICE - DISK ENCRYPTION STATUS)
Endpoint device disk encryption status (enabled/disabled/unknown).
EMAIL field name: DeviceDiskEncryptionStatus
HTTPS field name: DeviceDiskEncryptionStatus
device.​epp_status
(DEVICE - EPP STATUS)
Endpoint device EPP (Endpoint Protection Platform) status.
CEF field name: PanOSDeviceEPPStatus
EMAIL field name: DeviceEPPStatus
HTTPS field name: DeviceEPPStatus
LEEF field name: DeviceEPPStatus
device.​extension_version
(DEVICE - EXTENSION VERSION)
Version of the browser extension installed on the device.
EMAIL field name: DeviceExtensionVersion
HTTPS field name: DeviceExtensionVersion
LEEF field name: DeviceExtensionVersion
device.​firewall_status
(DEVICE - FIREWALL STATUS)
Endpoint device firewall status (enabled/disabled/unknown).
EMAIL field name: DeviceFirewallStatus
HTTPS field name: DeviceFirewallStatus
LEEF field name: DeviceFirewallStatus
device.​geoip_from_city_name
(DEVICE - GEO IP FROM CITY NAME)
City name derived from the device's IP address geolocation.
EMAIL field name: DeviceGeoIPFromCityName
HTTPS field name: DeviceGeoIPFromCityName
LEEF field name: DeviceGeoIPFromCityName
device.​geoip_from_country_name
(DEVICE - GEO IP FROM COUNTRY NAME)
Country name derived from the device's IP address geolocation.
EMAIL field name: DeviceGeoIPFromCountryName
HTTPS field name: DeviceGeoIPFromCountryName
device.​geoip_from_location_latitude
(DEVICE - GEO IP FROM LOCATION LATITUDE)
Latitude derived from the device's IP address geolocation.
device.​geoip_from_location_longitude
(DEVICE - GEO IP FROM LOCATION LONGITUDE)
Longitude derived from the device's IP address geolocation.
device.​groups.​ids
(DEVICE - GROUPS IDS)
Enumeration integer assigned to the device.groups field value.
CEF field name: PanOSDeviceGroupsIDs
EMAIL field name: DeviceGroupsIDs
HTTPS field name: DeviceGroupsIDs
LEEF field name: DeviceGroupsIDs
device.​groups.​names
(DEVICE - GROUPS NAMES)
Device group names the endpoint belongs to.
CEF field name: PanOSDeviceGroupsNames
EMAIL field name: DeviceGroupsNames
HTTPS field name: DeviceGroupsNames
LEEF field name: DeviceGroupsNames
device.​hostname
(DEVICE - HOSTNAME)
Hostname of the endpoint device.
CEF field name: PanOSDeviceHostname
EMAIL field name: DeviceHostname
HTTPS field name: DeviceHostname
LEEF field name: DeviceHostname
device.​ip_address
(DEVICE - IP ADDRESS)
IP address of the endpoint device.
CEF field name: PanOSDeviceIPAddress
EMAIL field name: DeviceIPAddress
HTTPS field name: DeviceIPAddress
LEEF field name: DeviceIPAddress
device.​is_process_privileged_elevated
(DEVICE - IS PROCESS PRIVILEGED ELEVATED)
Whether the browser process is running with elevated privileges.
device.​is_running_in_vm
(DEVICE - IS RUNNING IN VM)
Whether the device is running in a virtual machine.
CEF field name: PanOSDeviceIsRunningInVm
EMAIL field name: DeviceIsRunningInVm
HTTPS field name: DeviceIsRunningInVm
LEEF field name: DeviceIsRunningInVm
device.​is_system_install
(DEVICE - IS SYSTEM INSTALL)
Whether the browser is installed as a system-level application.
EMAIL field name: DeviceIsSystemInstall
HTTPS field name: DeviceIsSystemInstall
LEEF field name: DeviceIsSystemInstall
device.​is_user_admin
(DEVICE - IS USER ADMIN)
Whether the current user has administrator privileges on the device.
CEF field name: PanOSDeviceIsUserAdmin
EMAIL field name: DeviceIsUserAdmin
HTTPS field name: DeviceIsUserAdmin
LEEF field name: DeviceIsUserAdmin
device.​local_ips
(DEVICE - LOCAL IPS)
List of local IP addresses assigned to the endpoint device.
CEF field name: PanOSDeviceLocalIps
EMAIL field name: DeviceLocalIps
HTTPS field name: DeviceLocalIps
LEEF field name: DeviceLocalIps
device.​mac_addresses
(DEVICE - MAC ADDRESSES)
MAC addresses of the endpoint device's network interfaces.
CEF field name: PanOSMACAddresses
EMAIL field name: DeviceMACAddresses
HTTPS field name: DeviceMACAddresses
LEEF field name: DeviceMACAddresses
device.​model
(DEVICE - MODEL)
Hardware model of the endpoint device.
CEF field name: PanOSDeviceModel
EMAIL field name: DeviceModel
HTTPS field name: DeviceModel
LEEF field name: DeviceModel
device.​os.​android.​build
(DEVICE - OS ANDROID BUILD)
Endpoint device Android build version (if relevant).
EMAIL field name: DeviceOSAndroidBuild
HTTPS field name: DeviceOSAndroidBuild
LEEF field name: DeviceOSAndroidBuild
device.​os.​android.​patch
(DEVICE - OS ANDROID PATCH)
Endpoint device Android patch version (if relevant).
EMAIL field name: DeviceOSAndroidPatch
HTTPS field name: DeviceOSAndroidPatch
LEEF field name: DeviceOSAndroidPatch
device.​os.​android.​release
(DEVICE - OS ANDROID RELEASE)
Endpoint device Android release version (if relevant).
EMAIL field name: DeviceOSAndroidRelease
HTTPS field name: DeviceOSAndroidRelease
LEEF field name: DeviceOSAndroidRelease
device.​os.​android.​sdk
(DEVICE - OS ANDROID SDK)
Endpoint device Android SDK version (if relevant).
CEF field name: PanOSDeviceOSAndroidSDK
EMAIL field name: DeviceOSAndroidSDK
HTTPS field name: DeviceOSAndroidSDK
LEEF field name: DeviceOSAndroidSDK
device.​os.​chrome_os.​build
(DEVICE - OS CHROME OS BUILD)
Endpoint device ChromeOS build version (if relevant).
EMAIL field name: DeviceOsChromeOsBuild
HTTPS field name: DeviceOsChromeOsBuild
LEEF field name: DeviceOsChromeOsBuild
device.​os.​chrome_os.​major
(DEVICE - OS CHROME OS MAJOR)
Endpoint device ChromeOS major version (if relevant).
EMAIL field name: DeviceOsChromeOsMajor
HTTPS field name: DeviceOsChromeOsMajor
LEEF field name: DeviceOsChromeOsMajor
device.​os.​chrome_os.​minor
(DEVICE - OS CHROME OS MINOR)
Endpoint device ChromeOS minor version (if relevant).
EMAIL field name: DeviceOsChromeOsMinor
HTTPS field name: DeviceOsChromeOsMinor
LEEF field name: DeviceOsChromeOsMinor
device.​os.​ios.​major
(DEVICE - OS IOS MAJOR)
Endpoint device iOS major version (if relevant).
CEF field name: PanOSDeviceOSiOSMajor
EMAIL field name: DeviceOSiOSMajor
HTTPS field name: DeviceOSiOSMajor
LEEF field name: DeviceOSiOSMajor
device.​os.​ios.​minor
(DEVICE - OS IOS MINOR)
Endpoint device iOS minor version (if relevant).
CEF field name: PanOSDeviceOSiOSMinor
EMAIL field name: DeviceOSiOSMinor
HTTPS field name: DeviceOSiOSMinor
LEEF field name: DeviceOSiOSMinor
device.​os.​ios.​patch
(DEVICE - OS IOS PATCH)
Endpoint device iOS patch version (if relevant).
CEF field name: PanOSDeviceOSiOSPatch
EMAIL field name: DeviceOSiOSPatch
HTTPS field name: DeviceOSiOSPatch
LEEF field name: DeviceOSiOSPatch
device.​os.​linux.​id
(DEVICE - OS LINUX ID)
Enumeration integer assigned to the device.os.linux field value.
CEF field name: PanOSDeviceOsLinuxId
EMAIL field name: DeviceOsLinuxId
HTTPS field name: DeviceOsLinuxId
LEEF field name: DeviceOsLinuxId
device.​os.​linux.​id_like
(DEVICE - OS LINUX ID LIKE)
Enumeration integer assigned to the device.os.linux field value.
CEF field name: PanOSDeviceOsLinuxIdLike
EMAIL field name: DeviceOsLinuxIdLike
HTTPS field name: DeviceOsLinuxIdLike
LEEF field name: DeviceOsLinuxIdLike
device.​os.​linux.​name
(DEVICE - OS LINUX NAME)
Endpoint device Linux distribution name (if relevant).
CEF field name: PanOSDeviceOsLinuxName
EMAIL field name: DeviceOsLinuxName
HTTPS field name: DeviceOsLinuxName
LEEF field name: DeviceOsLinuxName
device.​os.​linux.​pretty_name
(DEVICE - OS LINUX PRETTY NAME)
Endpoint device Linux pretty name/display name (if relevant).
EMAIL field name: DeviceOsLinuxPrettyName
HTTPS field name: DeviceOsLinuxPrettyName
LEEF field name: DeviceOsLinuxPrettyName
device.​os.​linux.​version
(DEVICE - OS LINUX VERSION)
Endpoint device Linux version (if relevant).
EMAIL field name: DeviceOsLinuxVersion
HTTPS field name: DeviceOsLinuxVersion
LEEF field name: DeviceOsLinuxVersion
device.​os.​linux.​version_id
(DEVICE - OS LINUX VERSION ID)
Endpoint device Linux version ID (if relevant).
EMAIL field name: DeviceOsLinuxVersionId
HTTPS field name: DeviceOsLinuxVersionId
LEEF field name: DeviceOsLinuxVersionId
device.​os.​macos.​bugfix
(DEVICE - OS MACOS BUGFIX)
Endpoint device macOS bugfix version (if relevant).
CEF field name: PanOSDeviceOSmacOSBugfix
EMAIL field name: DeviceOSmacOSBugfix
HTTPS field name: DeviceOSmacOSBugfix
LEEF field name: DeviceOSmacOSBugfix
device.​os.​macos.​build
(DEVICE - OS MACOS BUILD)
Endpoint device macOS build version (if relevant).
CEF field name: PanOSDeviceOSmacOSBuild
EMAIL field name: DeviceOSmacOSBuild
HTTPS field name: DeviceOSmacOSBuild
LEEF field name: DeviceOSmacOSBuild
device.​os.​macos.​integrity_info.​gatekeeper_enabled
(DEVICE - OS MACOS INTEGRITY INFO GATEKEEPER ENABLED)
Whether Gatekeeper is enabled on the device.
device.​os.​macos.​integrity_info.​sip_enabled
(DEVICE - OS MACOS INTEGRITY INFO SIP ENABLED)
Whether SIP (System Integrity Protection) is enabled on the device.
device.​os.​macos.​major
(DEVICE - OS MACOS MAJOR)
Endpoint device macOS major version (if relevant).
CEF field name: PanOSDeviceOSmacOSMajor
EMAIL field name: DeviceOSmacOSMajor
HTTPS field name: DeviceOSmacOSMajor
LEEF field name: DeviceOSmacOSMajor
device.​os.​macos.​minor
(DEVICE - OS MACOS MINOR)
Endpoint device macOS minor version (if relevant).
CEF field name: PanOSDeviceOSmacOSMinor
EMAIL field name: DeviceOSmacOSMinor
HTTPS field name: DeviceOSmacOSMinor
LEEF field name: DeviceOSmacOSMinor
device.​os.​macos.​server
(DEVICE - OS MACOS SERVER)
Endpoint device macOS server (if relevant).
CEF field name: PanOSDeviceOSmacOSServer
EMAIL field name: DeviceOSmacOSServer
HTTPS field name: DeviceOSmacOSServer
LEEF field name: DeviceOSmacOSServer
device.​os.​type
(DEVICE - OS TYPE)
Endpoint device operating system.
CEF field name: PanOSDeviceOSType
EMAIL field name: DeviceOSType
HTTPS field name: DeviceOSType
LEEF field name: DeviceOSType
device.​os.​windows.​build
(DEVICE - OS WINDOWS BUILD)
Endpoint device Windows build version (if relevant).
EMAIL field name: DeviceOSWindowsBuild
HTTPS field name: DeviceOSWindowsBuild
LEEF field name: DeviceOSWindowsBuild
device.​os.​windows.​integrity_info.​drivers_signing_enforced
(DEVICE - OS WINDOWS INTEGRITY INFO DRIVERS SIGNING ENFORCED)
Whether driver signing is enforced on the device.
device.​os.​windows.​integrity_info.​kernel_debugger_not_present
(DEVICE - OS WINDOWS INTEGRITY INFO KERNEL DEBUGGER NOT PRESENT)
Whether a kernel debugger is absent on the device.
device.​os.​windows.​integrity_info.​secure_boot_enabled
(DEVICE - OS WINDOWS INTEGRITY INFO SECURE BOOT ENABLED)
Whether Secure Boot is enabled on the device.
device.​os.​windows.​major
(DEVICE - OS WINDOWS MAJOR)
Endpoint device Windows major version (if relevant).
EMAIL field name: DeviceOSWindowsMajor
HTTPS field name: DeviceOSWindowsMajor
LEEF field name: DeviceOSWindowsMajor
device.​os.​windows.​minor
(DEVICE - OS WINDOWS MINOR)
Endpoint device Windows minor version (if relevant).
EMAIL field name: DeviceOSWindowsMinor
HTTPS field name: DeviceOSWindowsMinor
LEEF field name: DeviceOSWindowsMinor
device.​os.​windows.​patch
(DEVICE - OS WINDOWS PATCH)
Endpoint device Windows patch version (if relevant).
EMAIL field name: DeviceOSWindowsPatch
HTTPS field name: DeviceOSWindowsPatch
LEEF field name: DeviceOSWindowsPatch
device.​os.​windows.​product
(DEVICE - OS WINDOWS PRODUCT)
Endpoint device Windows product name (if relevant).
EMAIL field name: DeviceOSWindowsProduct
HTTPS field name: DeviceOSWindowsProduct
LEEF field name: DeviceOSWindowsProduct
device.​os_display_name
(DEVICE - OS DISPLAY NAME)
Endpoint device operating system display name.
CEF field name: PanOSDeviceOSDisplayName
EMAIL field name: DeviceOSDisplayName
HTTPS field name: DeviceOSDisplayName
LEEF field name: DeviceOSDisplayName
device.​pabl_version
(DEVICE - PABL VERSION)
PABL (PAB Local Extender) version.
CEF field name: PanOSDevicePablVersion
EMAIL field name: DevicePablVersion
HTTPS field name: DevicePablVersion
LEEF field name: DevicePablVersion
device.​public_ip
(DEVICE - PUBLIC IP)
Public IP address of the device.
CEF field name: PanOSDevicePublicIp
EMAIL field name: DevicePublicIp
HTTPS field name: DevicePublicIp
LEEF field name: DevicePublicIp
device.​raw_universal_id
(DEVICE - RAW UNIVERSAL ID)
Unique endpoint device identifier.
EMAIL field name: DeviceRawUniversalID
HTTPS field name: DeviceRawUniversalID
LEEF field name: DeviceRawUniversalID
device.​screen_lock_status
(DEVICE - SCREEN LOCK STATUS)
Endpoint device screen lock status (enabled/disabled/unknown).
EMAIL field name: DeviceScreenLockStatus
HTTPS field name: DeviceScreenLockStatus
LEEF field name: DeviceScreenLockStatus
device.​serial_number
(DEVICE - SERIAL NUMBER)
Endpoint device manufacturer serial number.
CEF field name: PanOSDeviceSerialNumber
EMAIL field name: DeviceSerialNumber
HTTPS field name: DeviceSerialNumber
LEEF field name: DeviceSerialNumber
device.​type
(DEVICE - TYPE)
Device context.
CEF field name: PanOSDeviceType
EMAIL field name: DeviceType
HTTPS field name: DeviceType
LEEF field name: DeviceType
device.​user_agent
(DEVICE - USER AGENT)
Browser user agent.
CEF field name: PanOSDeviceUserAgent
EMAIL field name: DeviceUserAgent
HTTPS field name: DeviceUserAgent
LEEF field name: DeviceUserAgent
dlp.​detected_classifiers
(DLP - DETECTED CLASSIFIERS)
List of classifiers that were detected in the content.
EMAIL field name: DlpDetectedClassifiers
HTTPS field name: DlpDetectedClassifiers
LEEF field name: DlpDetectedClassifiers
dlp.​detected_classifiers_confidence
(DLP - DETECTED CLASSIFIERS CONFIDENCE)
List of the confidence levels of the classifiers detected in the content.
dlp.​detected_classifiers_occurrences
(DLP - DETECTED CLASSIFIERS OCCURRENCES)
List of the occurrence counts of the classifiers detected in the content.
dlp.​matched_classifiers
(DLP - MATCHED CLASSIFIERS)
List of classifiers that were matched in the content.
EMAIL field name: DlpMatchedClassifiers
HTTPS field name: DlpMatchedClassifiers
LEEF field name: DlpMatchedClassifiers
dlp.​matched_classifiers_confidence
(DLP - MATCHED CLASSIFIERS CONFIDENCE)
List of the confidence levels of the classifiers matched in the content.
dlp.​matched_classifiers_occurrences
(DLP - MATCHED CLASSIFIERS OCCURRENCES)
List of the occurrence counts of the classifiers matched in the content.
dlp.​matched_data_profiles
(DLP - MATCHED DATA PROFILES)
List of data profile names that were matched in the content.
EMAIL field name: DlpMatchedDataProfiles
HTTPS field name: DlpMatchedDataProfiles
LEEF field name: DlpMatchedDataProfiles
dlp.​parent_data_profile
(DLP - PARENT DATA PROFILE)
The parent data profile name that was matched in the content.
EMAIL field name: DlpParentDataProfile
HTTPS field name: DlpParentDataProfile
LEEF field name: DlpParentDataProfile
extension_risk.​initiator
(EXTENSION RISK - INITIATOR)
Initiator of the extension event (User/Policy/Automatic).
EMAIL field name: ExtensionRiskInitiator
HTTPS field name: ExtensionRiskInitiator
LEEF field name: ExtensionRiskInitiator
extension_risk.​risk
(EXTENSION RISK - RISK)
Extension risk level (Low/Medium/High/Malicious/Unknown).
CEF field name: PanOSExtensionRiskRisk
EMAIL field name: ExtensionRiskRisk
HTTPS field name: ExtensionRiskRisk
LEEF field name: ExtensionRiskRisk
extension_risk.​trigger
(EXTENSION RISK - TRIGGER)
Trigger for the extension action (ID/Permissions/Risk).
EMAIL field name: ExtensionRiskTrigger
HTTPS field name: ExtensionRiskTrigger
LEEF field name: ExtensionRiskTrigger
file.​extension
(FILE - EXTENSION)
The event's file type (specific file extension).
CEF field name: PanOSFileExtension
EMAIL field name: FileExtension
HTTPS field name: FileExtension
LEEF field name: FileExtension
file.​is_encrypted
(FILE - IS ENCRYPTED)
The event's file encryption status.
CEF field name: PanOSFileIsEncrypted
EMAIL field name: FileIsEncrypted
HTTPS field name: FileIsEncrypted
LEEF field name: FileIsEncrypted
file.​local_path
(FILE - LOCAL PATH)
The endpoint device path on disk from which the file was selected.
CEF field name: PanOSFileLocalPath
EMAIL field name: FileLocalPath
HTTPS field name: FileLocalPath
LEEF field name: FileLocalPath
file.​mime_type
(FILE - MIME TYPE)
The event's file MIME type (e.g., HTML, JPEG, MPEG).
CEF field name: PanOSFileMimeType
EMAIL field name: FileMimeType
HTTPS field name: FileMimeType
LEEF field name: FileMimeType
file.​name
(FILE - NAME)
The event's file name.
CEF field name: PanOSFileName
EMAIL field name: FileName
HTTPS field name: FileName
LEEF field name: FileName
file.​operation
(FILE - OPERATION)
File handling operation (e.g., download, upload).
CEF field name: PanOSFileOperation
EMAIL field name: FileOperation
HTTPS field name: FileOperation
LEEF field name: FileOperation
file.​origin_download_url
(FILE - ORIGIN DOWNLOAD URL)
The event's file source URL.
EMAIL field name: FileOriginDownloadURL
HTTPS field name: FileOriginDownloadURL
LEEF field name: FileOriginDownloadURL
file.​sha256
(FILE - SHA256)
The event's file SHA-256 hash.
CEF field name: PanOSFileSHA256
EMAIL field name: FileSHA256
HTTPS field name: FileSHA256
LEEF field name: FileSHA256
file.​url
(FILE - URL)
The event's associated URL when handling files.
CEF field name: PanOSFileURL
EMAIL field name: FileURL
HTTPS field name: FileURL
LEEF field name: FileURL
gen_ai_prompt.​embedded_gen_ai
(GEN AI PROMPT - EMBEDDED GEN AI)
The embedded GenAI application where the prompt was sent (Gemini/Claude/ChatGPT/Copilot/Perplexity).
EMAIL field name: GenAiPromptEmbeddedGenAi
HTTPS field name: GenAiPromptEmbeddedGenAi
LEEF field name: GenAiPromptEmbeddedGenAi
gen_ai_prompt.​included_files
(GEN AI PROMPT - INCLUDED FILES)
The files that were sent to the GenAI application.
EMAIL field name: GenAiPromptIncludedFiles
HTTPS field name: GenAiPromptIncludedFiles
LEEF field name: GenAiPromptIncludedFiles
gen_ai_prompt.​is_prompt_collected
(GEN AI PROMPT - IS PROMPT COLLECTED)
Whether the prompt was collected.
gen_ai_prompt.​prompt
(GEN AI PROMPT - PROMPT)
The prompt that was sent to the GenAI application.
CEF field name: PanOSGenAiPromptPrompt
EMAIL field name: GenAiPromptPrompt
HTTPS field name: GenAiPromptPrompt
LEEF field name: GenAiPromptPrompt
id
(ID)
The event's unique identifier.
CEF field name: PanOSID
EMAIL field name: ID
HTTPS field name: ID
LEEF field name: ID
log_source
(LOG SOURCE)
Identifies the origin of the data - the system that produced the data.
CEF field name: PanOSLogSource
EMAIL field name: LogSource
HTTPS field name: LogSource
LEEF field name: LogSource
log_source_group_id
(LOG SOURCE GROUP ID)
ID that uniquely identifies the logSourceGroupId of the log. That is, the log_source_id of the group.
CEF field name: PanOSLogSourceGroupID
EMAIL field name: LogSourceGroupID
HTTPS field name: LogSourceGroupID
LEEF field name: LogSourceGroupID
log_source_id
(DEVICE SN)
ID that uniquely identifies the source of the log - serial number of the firewall that generated the log.
CEF field name: deviceExternalID
EMAIL field name: DeviceSN
HTTPS field name: DeviceSN
LEEF field name: DeviceSN
log_source_name
(DEVICE NAME)
Name of the source of the log - hostname of the firewall that logged the network traffic.
CEF field name: dvchost
EMAIL field name: DeviceName
HTTPS field name: DeviceName
LEEF field name: DeviceName
log_time
(TIME RECEIVED)
Time the log was received in Cortex Data Lake. This is populated by the platform.
CEF field name: rt
EMAIL field name: TimeReceived
HTTPS field name: TimeReceived
LEEF field name: TimeReceived
log_type.​value
(LOG TYPE)
Identifies the log type.
CEF field name: Device Event Class ID
EMAIL field name: LogType
HTTPS field name: LogType
LEEF field name: cat
misc
(MISCELLANEOUS)
miscellaneous field for events.
CEF field name: PanOSMiscellaneous
EMAIL field name: Miscellaneous
HTTPS field name: Miscellaneous
LEEF field name: Miscellaneous
network.​classifications
(NETWORK - CLASSIFICATIONS)
Web classification of the website associated with the event.
EMAIL field name: NetworkClassifications
HTTPS field name: NetworkClassifications
LEEF field name: NetworkClassifications
network.​frame_url
(NETWORK - FRAME URL)
The URL of the frame within the website (iframe scenario).
CEF field name: PanOSNetworkFrameURL
EMAIL field name: NetworkFrameURL
HTTPS field name: NetworkFrameURL
LEEF field name: NetworkFrameURL
network.​http.​method
(NETWORK - HTTP METHOD)
HTTP method (GET, POST, etc.).
CEF field name: PanOSNetworkHTTPMethod
EMAIL field name: NetworkHTTPMethod
HTTPS field name: NetworkHTTPMethod
LEEF field name: NetworkHTTPMethod
network.​http.​status
(NETWORK - HTTP STATUS)
HTTP status code (200, 404, etc.).
CEF field name: PanOSNetworkHTTPStatus
EMAIL field name: NetworkHTTPStatus
HTTPS field name: NetworkHTTPStatus
LEEF field name: NetworkHTTPStatus
network.​protocol
(NETWORK - PROTOCOL)
Protocol used.
CEF field name: PanOSNetworkProtocol
EMAIL field name: NetworkProtocol
HTTPS field name: NetworkProtocol
LEEF field name: NetworkProtocol
network.​query_params
(NETWORK - QUERY PARAMS)
The query parameters associated with the URL associated with the event.
CEF field name: PanOSNetworkQueryParams
EMAIL field name: NetworkQueryParams
HTTPS field name: NetworkQueryParams
LEEF field name: NetworkQueryParams
network.​redirect_destination_url
(NETWORK - REDIRECT DESTINATION URL)
The destination URL the user was redirected to.
network.​remote_connection_protocol
(NETWORK - REMOTE CONNECTION PROTOCOL)
The underlying protocol for remote application connection (e.g., SSH, RDP, VNC).
network.​tab_url
(NETWORK - TAB URL )
The event's associated tab URL.
CEF field name: PanOSNetworkTabURL
EMAIL field name: NetworkTabURL
HTTPS field name: NetworkTabURL
LEEF field name: NetworkTabURL
network.​tunneled_through_pa
(NETWORK - TUNNELED THROUGH PA)
Indicates if the connection was tunneled through Prisma Access.
EMAIL field name: NetworkTunneledThroughPa
HTTPS field name: NetworkTunneledThroughPa
LEEF field name: NetworkTunneledThroughPa
network.​url
(NETWORK - URL)
The event's associated URL on which the rule was enforced.
CEF field name: PanOSNetworkURL
EMAIL field name: NetworkURL
HTTPS field name: NetworkURL
LEEF field name: NetworkURL
network.​web_risk_level
(NETWORK - WEB RISK LEVEL)
The risk level of the URL.
CEF field name: PanOSNetworkWebRiskLevel
EMAIL field name: NetworkWebRiskLevel
HTTPS field name: NetworkWebRiskLevel
LEEF field name: NetworkWebRiskLevel
network.​web_scan_engine
(NETWORK - WEB SCAN ENGINE)
The scan engine used for web classification.
EMAIL field name: NetworkWebScanEngine
HTTPS field name: NetworkWebScanEngine
LEEF field name: NetworkWebScanEngine
network.​web_scan_engines
(NETWORK - WEB SCAN ENGINES)
The scan engines used for web classification.
EMAIL field name: NetworkWebScanEngines
HTTPS field name: NetworkWebScanEngines
LEEF field name: NetworkWebScanEngines
page.​capture.​is_secure_screenshot
(PAGE - CAPTURE IS SECURE SCREENSHOT)
Whether the screenshot was captured by the secure screenshot capability.
page.​capture.​triggered_by_url
(PAGE - CAPTURE TRIGGERED BY URL)
Whether the screenshot was triggered by the webpage.
EMAIL field name: PageCaptureTriggeredByURL
HTTPS field name: PageCaptureTriggeredByURL
LEEF field name: PageCaptureTriggeredByURL
page.​devtools.​block_reason
(PAGE - DEVTOOLS BLOCK REASON)
The reason DevTools access was blocked (e.g., data masking, typing guard, watermark).
EMAIL field name: PageDevtoolsBlockReason
HTTPS field name: PageDevtoolsBlockReason
LEEF field name: PageDevtoolsBlockReason
page.​title
(PAGE - TITLE)
The title of the page/tab.
CEF field name: PanOSPageTitle
EMAIL field name: PageTitle
HTTPS field name: PageTitle
LEEF field name: PageTitle
password_manager.​import.​count
(PASSWORD MANAGER - IMPORT COUNT)
Number of logins imported.
EMAIL field name: PasswordManagerImportCount
HTTPS field name: PasswordManagerImportCount
password_manager.​import.​source
(PASSWORD MANAGER - IMPORT SOURCE)
Import source (csv/system).
EMAIL field name: PasswordManagerImportSource
HTTPS field name: PasswordManagerImportSource
password_manager.​login.​changes
(PASSWORD MANAGER - LOGIN CHANGES)
Login changes.
EMAIL field name: PasswordManagerLoginChanges
HTTPS field name: PasswordManagerLoginChanges
password_manager.​login.​is_managed
(PASSWORD MANAGER - LOGIN IS MANAGED)
Whether the login is managed.
password_manager.​login.​method
(PASSWORD MANAGER - LOGIN METHOD)
Login method.
EMAIL field name: PasswordManagerLoginMethod
HTTPS field name: PasswordManagerLoginMethod
password_manager.​login.​name
(PASSWORD MANAGER - LOGIN NAME)
Password manager login name.
EMAIL field name: PasswordManagerLoginName
HTTPS field name: PasswordManagerLoginName
LEEF field name: PasswordManagerLoginName
password_manager.​login.​retrieved_method
(PASSWORD MANAGER - LOGIN RETRIEVED METHOD)
How the login was retrieved (autofill/manual).
password_manager.​login.​risks
(PASSWORD MANAGER - LOGIN RISKS)
Password manager login risks.
EMAIL field name: PasswordManagerLoginRisks
HTTPS field name: PasswordManagerLoginRisks
LEEF field name: PasswordManagerLoginRisks
password_manager.​login.​sharing.​target.​groups
(PASSWORD MANAGER - LOGIN SHARING TARGET GROUPS)
Password manager login sharing target groups.
password_manager.​login.​sharing.​target.​users
(PASSWORD MANAGER - LOGIN SHARING TARGET USERS)
Password manager login sharing target users.
password_manager.​login.​urls
(PASSWORD MANAGER - LOGIN URLS)
Password manager login URLs.
EMAIL field name: PasswordManagerLoginUrls
HTTPS field name: PasswordManagerLoginUrls
LEEF field name: PasswordManagerLoginUrls
password_manager.​login.​user
(PASSWORD MANAGER - LOGIN USER)
Password manager login user.
EMAIL field name: PasswordManagerLoginUser
HTTPS field name: PasswordManagerLoginUser
LEEF field name: PasswordManagerLoginUser
pincode.​failed_attempts
(PINCODE - FAILED ATTEMPTS)
Number of PIN code failed attempts.
EMAIL field name: PincodeFailedAttempts
HTTPS field name: PincodeFailedAttempts
LEEF field name: PincodeFailedAttempts
pincode.​registration_time
(PINCODE - REGISTRATION TIME)
Timestamp of the last failed attempt in which a PIN code was entered.
EMAIL field name: PincodeRegistrationTime
HTTPS field name: PincodeRegistrationTime
LEEF field name: PincodeRegistrationTime
platform_type
(PLATFORM TYPE)
Identifies the platform that generated the log.
CEF field name: PlatformType
EMAIL field name: PlatformType
HTTPS field name: PlatformType
LEEF field name: PlatformType
policy.​action
(POLICY - ACTION)
Policy resolution on the endpoint activity.
CEF field name: PanOSPolicyAction
EMAIL field name: PolicyAction
HTTPS field name: PolicyAction
LEEF field name: PolicyAction
policy.​block_reason
(POLICY - BLOCK REASON)
Reason the action was blocked.
CEF field name: PanOSPolicyBlockReason
EMAIL field name: PolicyBlockReason
HTTPS field name: PolicyBlockReason
LEEF field name: PolicyBlockReason
policy.​bypass_allowed
(POLICY - BYPASS ALLOWED)
Whether the user is allowed to proceed to the HTTP site.
CEF field name: PanOSPolicyBypassAllowed
EMAIL field name: PolicyBypassAllowed
HTTPS field name: PolicyBypassAllowed
LEEF field name: PolicyBypassAllowed
policy.​bypass_reason
(POLICY - BYPASS REASON)
End-user reason to bypass a block (one of a defined list of options).
CEF field name: PanOSPolicyBypassReason
EMAIL field name: PolicyBypassReason
HTTPS field name: PolicyBypassReason
LEEF field name: PolicyBypassReason
policy.​bypass_request_id
(POLICY - BYPASS REQUEST ID)
Policy bypass request ID.
EMAIL field name: PolicyBypassRequestId
HTTPS field name: PolicyBypassRequestId
LEEF field name: PolicyBypassRequestId
policy.​defined_action
(POLICY - DEFINED ACTION)
The action defined in the matched rule (allow/block/prompt).
CEF field name: PanOSPolicyDefinedAction
EMAIL field name: PolicyDefinedAction
HTTPS field name: PolicyDefinedAction
LEEF field name: PolicyDefinedAction
policy.​evidence.​full_session_recording
(POLICY - EVIDENCE FULL SESSION RECORDING)
Whether policy evidence includes a full session recording.
policy.​evidence.​full_session_recording_id
(POLICY - EVIDENCE FULL SESSION RECORDING ID)
Policy evidence full session recording ID.
policy.​evidence.​full_session_recording_status
(POLICY - EVIDENCE FULL SESSION RECORDING STATUS)
Status of the full session recording (live/finalized/partial).
policy.​evidence.​screenshot
(POLICY - EVIDENCE SCREENSHOT)
Whether policy evidence includes a screenshot.
EMAIL field name: PolicyEvidenceScreenshot
HTTPS field name: PolicyEvidenceScreenshot
LEEF field name: PolicyEvidenceScreenshot
policy.​evidence.​types
(POLICY - EVIDENCE TYPES)
Evidence types (fullSessionRecordingEvidence/screenshotEvidence/eventRecordingEvidence).
CEF field name: PanOSPolicyEvidenceTypes
EMAIL field name: PolicyEvidenceTypes
HTTPS field name: PolicyEvidenceTypes
LEEF field name: PolicyEvidenceTypes
policy.​failure_reason
(POLICY - FAILURE REASON)
Reason the action was blocked due to a failure.
CEF field name: PanOSPolicyFailureReason
EMAIL field name: PolicyFailureReason
HTTPS field name: PolicyFailureReason
LEEF field name: PolicyFailureReason
policy.​is_historical
(POLICY - IS HISTORICAL)
Whether the event originated from the History Collection Module.
CEF field name: PanOSPolicyIsHistorical
EMAIL field name: PolicyIsHistorical
HTTPS field name: PolicyIsHistorical
LEEF field name: PolicyIsHistorical
policy.​is_monitor
(POLICY - IS MONITOR)
Whether the event was generated by a monitoring rule.
CEF field name: PanOSPolicyIsMonitor
EMAIL field name: PolicyIsMonitor
HTTPS field name: PolicyIsMonitor
LEEF field name: PolicyIsMonitor
policy.​is_recording_exist
(POLICY - IS RECORDING EXIST)
Whether a policy recording exists.
EMAIL field name: PolicyIsRecordingExist
HTTPS field name: PolicyIsRecordingExist
LEEF field name: PolicyIsRecordingExist
policy.​is_session_recorded
(POLICY - IS SESSION RECORDED)
Whether the event has a video recording.
EMAIL field name: PolicyIsSessionRecorded
HTTPS field name: PolicyIsSessionRecorded
LEEF field name: PolicyIsSessionRecorded
policy.​is_wec_enabled
(POLICY - IS WEC ENABLED)
Whether policy WEC is enabled.
CEF field name: PanOSPolicyIsWecEnabled
EMAIL field name: PolicyIsWecEnabled
HTTPS field name: PolicyIsWecEnabled
LEEF field name: PolicyIsWecEnabled
policy.​rule_description
(POLICY - RULE DESCRIPTION)
Textual description of the rule that generated the event.
EMAIL field name: PolicyRuleDescription
HTTPS field name: PolicyRuleDescription
LEEF field name: PolicyRuleDescription
policy.​rule_id
(POLICY - RULE ID)
ID of the rule that generated the event.
CEF field name: PanOSPolicyRuleID
EMAIL field name: PolicyRuleID
HTTPS field name: PolicyRuleID
LEEF field name: PolicyRuleID
policy.​rule_log_level
(POLICY - RULE LOG LEVEL)
Policy rule log level.
CEF field name: PanOSPolicyRuleLogLevel
EMAIL field name: PolicyRuleLogLevel
HTTPS field name: PolicyRuleLogLevel
LEEF field name: PolicyRuleLogLevel
policy.​should_log_query_params
(POLICY - SHOULD LOG QUERY PARAMS)
Whether the policy should log query parameters.
EMAIL field name: PolicyShouldLogQueryParams
HTTPS field name: PolicyShouldLogQueryParams
posture.​block_reason
(POSTURE - BLOCK REASON)
Specific reason a block was triggered due to a posture misalignment.
CEF field name: PanOSPostureBlockReason
EMAIL field name: PostureBlockReason
HTTPS field name: PostureBlockReason
LEEF field name: PostureBlockReason
posture.​block_type
(POSTURE - BLOCK TYPE)
Type of block triggered due to a posture misalignment.
CEF field name: PanOSPostureBlockType
EMAIL field name: PostureBlockType
HTTPS field name: PostureBlockType
LEEF field name: PostureBlockType
posture.​error
(POSTURE - ERROR)
Specific posture check mechanism error.
CEF field name: PanOSPostureError
EMAIL field name: PostureError
HTTPS field name: PostureError
LEEF field name: PostureError
posture.​suspension_type
(POSTURE - SUSPENSION TYPE)
Type of suspension when sign-in is blocked due to suspension (device/user).
EMAIL field name: PostureSuspensionType
HTTPS field name: PostureSuspensionType
LEEF field name: PostureSuspensionType
print.​printer_location
(PRINT - PRINTER LOCATION)
Virtual name of the printer used in the printing activity (if available).
EMAIL field name: PrintPrinterLocation
HTTPS field name: PrintPrinterLocation
LEEF field name: PrintPrinterLocation
print.​printer_name
(PRINT - PRINTER NAME)
Network name of the printer used in the printing activity.
CEF field name: PanOSPrintPrinterName
EMAIL field name: PrintPrinterName
HTTPS field name: PrintPrinterName
LEEF field name: PrintPrinterName
process.​cli_args
(PROESS - CLI ARGS)
Arguments passed to the executable when run via CLI.
CEF field name: PanOSProcessCLIArgs
EMAIL field name: ProcessCLIArgs
HTTPS field name: ProcessCLIArgs
LEEF field name: ProcessCLIArgs
process.​image_path
(PROCESS - IMAGE PATH)
Path on disk of the browser executable.
CEF field name: PanOSProcessImagePath
EMAIL field name: ProcessImagePath
HTTPS field name: ProcessImagePath
LEEF field name: ProcessImagePath
process.​parent_process
(PROCESS - PARENT PROCESS)
Browser process initiator.
EMAIL field name: ProcessParentProcess
HTTPS field name: ProcessParentProcess
LEEF field name: ProcessParentProcess
process.​pid
(PROCESS - PID)
Identifier of the current browser process.
CEF field name: PanOSProcessPID
EMAIL field name: ProcessPID
HTTPS field name: ProcessPID
LEEF field name: ProcessPID
rce_exploit.​sensor
(RCE EXPLOIT - SENSOR)
The detection sensor of the event (WASM_GUARD).
CEF field name: PanOSRceExploitSensor
EMAIL field name: RceExploitSensor
HTTPS field name: RceExploitSensor
LEEF field name: RceExploitSensor
rce_exploit.​url
(RCE EXPLOIT - URL)
The URL of the exploited resource.
CEF field name: PanOSRceExploitUrl
EMAIL field name: RceExploitUrl
HTTPS field name: RceExploitUrl
LEEF field name: RceExploitUrl
state.​device_group_evaluation
(STATE - DEVICE GROUP EVALUATION)
Device group evaluation based on device posture.
EMAIL field name: StateDeviceGroupEvaluation
HTTPS field name: StateDeviceGroupEvaluation
state.​sign_in_rules
(STATE - SIGN IN RULES)
Applicable sign-in rules.
CEF field name: PanOSStateSignInRules
EMAIL field name: StateSignInRules
HTTPS field name: StateSignInRules
LEEF field name: StateSignInRules
sub_tenant_id
(SUBTENANT ID)
Identifies the sub-tenant in which the log was generated
CEF field name: PanOSSubtenantID
EMAIL field name: SubtenantID
HTTPS field name: SubtenantID
LEEF field name: SubtenantID
sub_type.​value
(SUBTYPE)
Identifies the log subtype.
CEF field name: Name
EMAIL field name: Subtype
HTTPS field name: Subtype
LEEF field name: Subtype
tampering.​type
(TAMPERING - TYPE)
Tampering context.
CEF field name: PanOSTamperingType
EMAIL field name: TamperingType
HTTPS field name: TamperingType
LEEF field name: TamperingType
tenant_id
(TENANT ID)
Identifies the tenant in which the log was generated
CEF field name: PanOSTenantID
EMAIL field name: TenantID
HTTPS field name: TenantID
LEEF field name: TenantID
time_generated
(TIME GENERATED)
Time the log was generated on the data plane in format YYYY-MM-DDTHH:MM:SS[.DDDDDD]Z.
CEF field name: start
EMAIL field name: TimeGenerated
HTTPS field name: TimeGenerated
LEEF field name: devTime
time_generated_high_res
(TIME GENERATED HIGH RESOLUTION)
Time the log was generated in data plane with millisec granularity in format YYYY-MM-DDTHH:MM:SS[.DDDDDD]Z.
EMAIL field name: TimeGeneratedHighResolution
HTTPS field name: TimeGeneratedHighResolution
timestamp
(TIMESTAMP)
The event's timestamp.
CEF field name: PanOSTimestamp
EMAIL field name: Timestamp
HTTPS field name: Timestamp
LEEF field name: Timestamp
tsg_id
(TSG ID)
The ID that uniquely identifiers a Tenant Sevice Group (TSG) that this log record should be associated with.
CEF field name: PanOSTSGID
EMAIL field name: TSGID
HTTPS field name: TSGID
LEEF field name: TSGID
type
(TYPE)
The event's type.
CEF field name: PanOSType
EMAIL field name: Type
HTTPS field name: Type
LEEF field name: Type
user.​email
(USER - EMAIL)
Email address of the user that generated the event.
CEF field name: PanOSUserEmail
EMAIL field name: UserEmail
HTTPS field name: UserEmail
LEEF field name: UserEmail
user.​external_id
(USER - EXTERNAL ID)
Unique user identifier (used exclusively by Talon tenants).
CEF field name: PanOSUserExternalID
EMAIL field name: UserExternalID
HTTPS field name: UserExternalID
LEEF field name: UserExternalID
user.​groups.​ids
(USER - GROUPS IDS)
Enumeration integer assigned to the user.groups field value.
CEF field name: PanOSUserGroupsIDs
EMAIL field name: UserGroupsIDs
HTTPS field name: UserGroupsIDs
LEEF field name: UserGroupsIDs
user.​groups.​names
(USER - GROUPS NAMES)
Unique user group names associated with the user that generated the event.
CEF field name: PanOSUserGroupsNames
EMAIL field name: UserGroupsNames
HTTPS field name: UserGroupsNames
LEEF field name: UserGroupsNames
user.​id
(USER ID)
Enumeration integer assigned to the user field value.
CEF field name: PanOSUserID
EMAIL field name: UserID
HTTPS field name: UserID
LEEF field name: UserID
user.​name
(USER - NAME)
Name of the user that generated the event.
CEF field name: PanOSUserName
EMAIL field name: UserName
HTTPS field name: UserName
LEEF field name: UserName
user.​short_username
(USER - SHORT USERNAME)
Shortened version of the username that generated the event.
CEF field name: PanOSUserShortUsername
EMAIL field name: UserShortUsername
HTTPS field name: UserShortUsername
LEEF field name: UserShortUsername
user.​tenant_external_id
(USER - TENANT EXTERNAL ID)
Tenant identifier (used exclusively by Talon tenants).
EMAIL field name: UserTenantExternalID
HTTPS field name: UserTenantExternalID
LEEF field name: UserTenantExternalID
user.​tenant_id
(USER - TENANT ID)
Tenant identifier (used exclusively by Talon tenants).
CEF field name: PanOSUserTenantID
EMAIL field name: UserTenantID
HTTPS field name: UserTenantID
LEEF field name: UserTenantID
user.​tenant_name
(USER - TENANT NAME)
Tenant name (used exclusively by Talon tenants).
CEF field name: PanOSUserTenantName
EMAIL field name: UserTenantName
HTTPS field name: UserTenantName
LEEF field name: UserTenantName
user.​tsg_id
(USER - TSG ID)
Associated TSG_ID of the specific user.
CEF field name: PanOSUserTSGID
EMAIL field name: UserTSGID
HTTPS field name: UserTSGID
LEEF field name: UserTSGID
vendor_name
(VENDOR NAME)
Identifies the vendor that produced the data.
CEF field name: Device Vendor
EMAIL field name: VendorName
HTTPS field name: VendorName
LEEF field name: Vendor