Application Security
Focus
Focus
Strata Logging Service

Application Security

Table of Contents

Application Security

The Application Security logs contain information to help you monitor and investigate threats found in your Application network traffic.
See the following for information related to supported log formats:
APPLICATION SECURITY Field
(Display Name)
Description
action.​value
(ACTION)
Identifies the action that the app-sec policy took on the request.
CEF field name: act
EMAIL field name: Action
HTTPS field name: Action
LEEF field name: Action
app
(APPLICATION)
AppID associated with the application.
CEF field name: app
EMAIL field name: Application
HTTPS field name: Application
LEEF field name: Application
customer_id
(CORTEX DATA LAKE TENANT ID)
The ID that uniquely identifies the Cortex Data Lake instance which received this log record.
EMAIL field name: CortexDataLakeTenantID
HTTPS field name: CortexDataLakeTenantID
LEEF field name: CortexDataLakeTenantID
dest_ip.​value
(DESTINATION ADDRESS)
Original destination IP address.
CEF field name: dst
EMAIL field name: DestinationAddress
HTTPS field name: DestinationAddress
LEEF field name: dst
dest_port
(DESTINATION PORT)
Network traffic's destination port. If this value is 0, then the app is using its standard port.
CEF field name: dpt
EMAIL field name: DestinationPort
HTTPS field name: DestinationPort
LEEF field name: dstPort
fqdn_app_name
(FQDN APPLICATION NAME)
App name defined in the app definition, corresponding to the fqdn in the request.
CEF field name: PanOSFQDNApplicationName
EMAIL field name: FQDNApplicationName
HTTPS field name: FQDNApplicationName
LEEF field name: FQDNApplicationName
internal_source_ip.​value
(INTERNAL SOURCE ADDRESS)
Internal source IP address.
EMAIL field name: InternalSourceAddress
HTTPS field name: InternalSourceAddress
LEEF field name: InternalSourceAddress
log_source
(LOG SOURCE)
Identifies the origin of the data - the system that produced the data.
CEF field name: PanOSLogSource
EMAIL field name: LogSource
HTTPS field name: LogSource
LEEF field name: LogSource
log_source_group_id
(LOG SOURCE GROUP ID)
ID that uniquely identifies the logSourceGroupId of the log. That is, the log_source_id of the group.
CEF field name: LogSourceGroupID
EMAIL field name: LogSourceGroupID
HTTPS field name: LogSourceGroupID
LEEF field name: LogSourceGroupID
log_source_id
(DEVICE SN)
ID that uniquely identifies the source of the log - serial number of the firewall that generated the log.
If the log is generated by Prisma Access, the serial number is not displayed.
CEF field name: deviceExternalId
EMAIL field name: DeviceSN
HTTPS field name: DeviceSN
LEEF field name: DeviceSN
log_source_name
(DEVICE NAME)
Name of the source of the log - hostname of the firewall that logged the network traffic.
CEF field name: dvchost
EMAIL field name: DeviceName
HTTPS field name: DeviceName
LEEF field name: DeviceName
log_source_tz_offset
(LOG SOURCE TIMEZONE OFFSET)
Time Zone offset from GMT of the source of the log.
EMAIL field name: LogSourceTimeZoneOffset
HTTPS field name: LogSourceTimeZoneOffset
LEEF field name: LogSourceTimeZoneOffset
log_time
(TIME RECEIVED)
Time the log was received in Strata Logging Service. This string contains a timestamp value that is the number of microseconds since the Unix epoch.
CEF field name: rt
EMAIL field name: TimeReceived
HTTPS field name: TimeReceived
LEEF field name: ReceiveTime
log_type.​value
(LOG TYPE)
Identifies the log type.
CEF field name: Device Event Class ID
EMAIL field name: LogType
HTTPS field name: LogType
LEEF field name: cat
platform_type
(PLATFORM TYPE)
Identifies the platform that generated the log.
CEF field name: PlatformType
EMAIL field name: PlatformType
HTTPS field name: PlatformType
LEEF field name: PlatformType
policy_rule_additional_details
(APPLICATION SECURITY POLICY RULE ADDITIONAL DETAILS)
Policy rule additional details.
policy_rule_name
(APPLICATION SECURITY POLICY RULE NAME)
App-sec policy rule name.
policy_rule_type.​value
(APPLICATION SECURITY POLICY RULE TYPE)
Type of the policy rule.
response_code
(HTTP RESPONSE CODE)
HTTP response code.
CEF field name: PanOSHTTPResponseCode
EMAIL field name: HTTPResponseCode
HTTPS field name: HTTPResponseCode
LEEF field name: HTTPResponseCode
session_id
(SESSION ID)
Identifies the firewall's internal identifier for a specific network session.
CEF field name: cn1
EMAIL field name: SessionID
HTTPS field name: SessionID
LEEF field name: SessionID
source_ip.​value
(SOURCE ADDRESS)
Original source IP address.
CEF field name: src
EMAIL field name: SourceAddress
HTTPS field name: SourceAddress
LEEF field name: src
source_port
(SOURCE PORT)
Source port utilized by the session.
CEF field name: spt
EMAIL field name: SourcePort
HTTPS field name: SourcePort
LEEF field name: srcPort
source_user
(SOURCE USER)
The username that initiated the network traffic.
CEF field name: suser
EMAIL field name: SourceUser
HTTPS field name: SourceUser
LEEF field name: usrName
sub_type.​value
(SUBTYPE)
Identifies the log subtype.
CEF field name: Name
EMAIL field name: Subtype
HTTPS field name: Subtype
LEEF field name: Subtype
time_generated
(TIME GENERATED)
Time when the log was generated on the firewall's data plane. This string contains a timestamp value that is the number of microseconds since the Unix epoch.
CEF field name: start
EMAIL field name: TimeGenerated
HTTPS field name: TimeGenerated
LEEF field name: devTime
time_generated_high_res
(TIME GENERATED HIGH RESOLUTION)
Time the log was generated in data plane with millisec granularity in format YYYY-MM-DDTHH:MM:SS[.DDDDDD]Z.
EMAIL field name: TimeGeneratedHighResolution
HTTPS field name: TimeGeneratedHighResolution
trace_id
(TRACE ID)
Trace ID associated with the http request.
CEF field name: PanOSTraceID
EMAIL field name: TraceID
HTTPS field name: TraceID
LEEF field name: TraceID
tsg_id
(TSG ID)
The ID that uniquely identifiers a Tenant Sevice Group (TSG) that this log record should be associated with.
CEF field name: PanOSTSGID
EMAIL field name: TSGID
HTTPS field name: TSGID
LEEF field name: TSGID
url
(URL)
URL in the request.
CEF field name: PanOSURL
EMAIL field name: URL
HTTPS field name: URL
LEEF field name: URL
vendor_name
(VENDOR NAME)
Identifies the vendor that produced the data.
CEF field name: Device Vendor
EMAIL field name: VendorName
HTTPS field name: VendorName
LEEF field name: Vendor