DNS Security (Resolver and SDWAN and Panos 12.1 or later) HTTPS Fields
Focus
Focus
Strata Logging Service

DNS Security (Resolver and SDWAN and Panos 12.1 or later) HTTPS Fields

Table of Contents

DNS Security (Resolver and SDWAN and Panos 12.1 or later) HTTPS Fields

The following table identifies the DNS Security (Resolver and SDWAN and Panos 12.1 or later) field names that the Log Forwarding app uses when you forward logs using the HTTPS log format.
HTTPS Name
Query Name
Field Type
Action
string
Application
string
ApplicationCategory
string
ApplicationSubcategory
string
CloudHostname
string
ConfigVersion
string
ContainerID
string
ApplicationContainer
string
ContentVersion
string
RepeatCount
int
CortexDataLakeTenantId
string
DestinationDeviceCategory
string
DestinationDeviceClass
string
DestinationDeviceHost
string
DestinationDeviceMac
string
DestinationDeviceModel
string
DestinationDeviceOS
string
DestinationDeviceOSFamily
string
DestinationDeviceOSVersion
string
DestinationDeviceProfile
string
DestinationDeviceVendor
string
DestinationDynamicAddressGroup
string
DestinationEDL
string
DestinationIP
string
DestinationLocation
string
DestinationPort
int
DestinationUserInfoDomain
string
DestinationUserInfoName
string
DestinationUserInfoUUID
long
DestinationUUID
string
DGHierarchyLevel1
int
DGHierarchyLevel2
int
DGHierarchyLevel3
int
DGHierarchyLevel4
int
DirectionOfAttack
string
DNSRequestName
string
DNSRdata
array
DNSResponseCode
string
DNSResponseFlags
string
DNSResponseTTL
string
DNSResponseType
string
DomainEDL
string
DestinationUser
string
ToZone
string
DynamicUserGroupName
string
EndpointSerialNumber
string
FlowSources
string
DNSResponseName
string
FromZone
string
ThreatID
int
HostID
string
HTTP2Connection
int
HTTPMethod
string
InboundInterface
string
InboundInterfaceDetailsPort
int
InboundInterfaceDetailsSlot
int
InboundInterfaceDetailsType
string
InboundInterfaceDetailsUnit
int
CaptivePortal
boolean
IsClienttoServer
boolean
IsContainer
boolean
IsDecryptMirror
boolean
IsDecrypted
boolean
IsDuplicateLog
boolean
IsEncrypted
boolean
LogExported
boolean
LogForwarded
boolean
IsIPV6
boolean
IsMptcpOn
boolean
NAT
boolean
IsNonStandardDestinationPort
boolean
IsPacketCapture
boolean
IsPhishing
boolean
IsPrismaNetwork
boolean
IsPrismaUsers
boolean
IsProxy
boolean
IsReconExcluded
boolean
IsSaaSApplication
boolean
IsServertoClient
boolean
IsSourceXForwarded
boolean
IsSystemReturn
boolean
IsTransaction
boolean
IsTunnelInspected
boolean
IsURLDenied
boolean
K8SClusterID
int
LocalDeepLearningAnalyzed
boolean
Location
string
LogSetting
string
LogSource
string
LogSourceGroupID
string
DeviceSN
string
DeviceName
string
LogSourceTimeZoneOffset
int
TimeReceived
timestamp
LogType
string
IMEI
string
NATDestination
string
NATDestinationPort
int
NATSource
string
NATSourcePort
int
NonStandardDestinationPort
int
NSSAINetworkSliceType
string
EgressInterface
string
OutboundInterfaceDetailsPort
int
OutboundInterfaceDetailsSlot
int
OutboundInterfaceDetailsType
string
OutboundInterfaceDetailsUnit
int
PanoramaSN
string
ParentSessionID
int
ParentStarttime
timestamp
PartialHash
long
PayloadProtocolID
int
PlatformType
string
ContainerName
string
ContainerNameSpace
string
Protocol
string
DNSRequestType
string
ReportID
long
ApplicationRisk
int
SecurityRule
string
RuleUUID
string
SanctionedStateOfApp
boolean
SequenceNo
long
SessionID
int
Severity
string
SigFlags
int
SourceDeviceCategory
string
SourceDeviceClass
string
SourceDeviceHost
string
SourceDeviceMac
string
SourceDeviceModel
string
SourceDeviceOS
string
SourceDeviceOSFamily
string
SourceDeviceOSVersion
string
SourceDeviceProfile
string
SourceDeviceVendor
string
SourceDynamicAddressGroup
string
SourceEDL
string
SourceIP
string
SourceLocation
string
SourcePort
int
SourceUser
string
SourceUserInfoDomain
string
SourceUserInfoName
string
SourceUserInfoUUID
long
SourceUUID
string
SubType
string
ApplicationTechnology
string
DNSCategory
string
DNSThreatName
string
TimeGenerated
timestamp
TimeGeneratedHighResolution
timestamp
SessionDuration
int
TSGID
string
Tunnel
string
TunneledApplication
string
IMSI
long
URLCategory
string
URLDomain
string
URLCounter
int
Users
string
VendorName
string
VendorSeverity
string
Verdict
string
VirtualLocation
string
VirtualSystemID
int
VirtualSystemName
string
X-Forwarded-ForIP
string