DNS Security (Resolver and SDWAN and Panos 12.1 or later) EMAIL Fields
Focus
Focus
Strata Logging Service

DNS Security (Resolver and SDWAN and Panos 12.1 or later) EMAIL Fields

Table of Contents

DNS Security (Resolver and SDWAN and Panos 12.1 or later) EMAIL Fields

The following table identifies the DNS Security (Resolver and SDWAN and Panos 12.1 or later) field names that the Log Forwarding app uses when you forward logs using the EMAIL log format.
EMAIL Name
Query Name
Action
Application
ApplicationCategory
ApplicationSubcategory
CloudHostname
ConfigVersion
ContainerID
ApplicationContainer
ContentVersion
RepeatCount
CortexDataLakeTenantId
DestinationDeviceCategory
DestinationDeviceClass
DestinationDeviceHost
DestinationDeviceMac
DestinationDeviceModel
DestinationDeviceOS
DestinationDeviceOSFamily
DestinationDeviceOSVersion
DestinationDeviceProfile
DestinationDeviceVendor
DestinationDynamicAddressGroup
DestinationEDL
DestinationIP
DestinationLocation
DestinationPort
DestinationUserInfoDomain
DestinationUserInfoName
DestinationUserInfoUUID
DestinationUUID
DGHierarchyLevel1
DGHierarchyLevel2
DGHierarchyLevel3
DGHierarchyLevel4
DirectionOfAttack
DNSRequestName
DNSRdata
DNSResponseCode
DNSResponseFlags
DNSResponseTTL
DNSResponseType
DomainEDL
DestinationUser
ToZone
DynamicUserGroupName
EndpointSerialNumber
FlowSources
DNSResponseName
FromZone
ThreatID
HostID
HTTP2Connection
HTTPMethod
InboundInterface
InboundInterfaceDetailsPort
InboundInterfaceDetailsSlot
InboundInterfaceDetailsType
InboundInterfaceDetailsUnit
CaptivePortal
IsClienttoServer
IsContainer
IsDecryptMirror
IsDecrypted
IsDuplicateLog
IsEncrypted
LogExported
LogForwarded
IsIPV6
IsMptcpOn
NAT
IsNonStandardDestinationPort
IsPacketCapture
IsPhishing
IsPrismaNetwork
IsPrismaUsers
IsProxy
IsReconExcluded
IsSaaSApplication
IsServertoClient
IsSourceXForwarded
IsSystemReturn
IsTransaction
IsTunnelInspected
IsURLDenied
K8SClusterID
LocalDeepLearningAnalyzed
Location
LogSetting
LogSource
LogSourceGroupID
DeviceSN
DeviceName
LogSourceTimeZoneOffset
TimeReceived
LogType
IMEI
NATDestination
NATDestinationPort
NATSource
NATSourcePort
NonStandardDestinationPort
NSSAINetworkSliceType
EgressInterface
OutboundInterfaceDetailsPort
OutboundInterfaceDetailsSlot
OutboundInterfaceDetailsType
OutboundInterfaceDetailsUnit
PanoramaSN
ParentSessionID
ParentStarttime
PartialHash
PayloadProtocolID
PlatformType
ContainerName
ContainerNameSpace
Protocol
DNSRequestType
ReportID
ApplicationRisk
SecurityRule
RuleUUID
SanctionedStateOfApp
SequenceNo
SessionID
Severity
SigFlags
SourceDeviceCategory
SourceDeviceClass
SourceDeviceHost
SourceDeviceMac
SourceDeviceModel
SourceDeviceOS
SourceDeviceOSFamily
SourceDeviceOSVersion
SourceDeviceProfile
SourceDeviceVendor
SourceDynamicAddressGroup
SourceEDL
SourceIP
SourceLocation
SourcePort
SourceUser
SourceUserInfoDomain
SourceUserInfoName
SourceUserInfoUUID
SourceUUID
SubType
ApplicationTechnology
DNSCategory
DNSThreatName
TimeGenerated
TimeGeneratedHighResolution
SessionDuration
TSGID
Tunnel
TunneledApplication
IMSI
URLCategory
URLDomain
URLCounter
Users
VendorName
VendorSeverity
Verdict
VirtualLocation
VirtualSystemID
VirtualSystemName
X-Forwarded-ForIP