Authentication HTTPS Fields
Focus
Focus
Strata Logging Service

Authentication HTTPS Fields

Table of Contents

Authentication HTTPS Fields

The following table identifies the Authentication field names that the Log Forwarding app uses when you forward logs using the HTTPS log format.
HTTPS Name
Query Name
Field Type
AuthenticationDescription
string
AuthEvent
string
AuthFactorNo
int
AuthenticationPolicy
string
AuthenticationProtocol
int
AuthServerProfile
string
AuthenticatedUserDomain
string
AuthenticatedUserName
string
AuthenticatedUserUUID
long
ClientType
int
ClientTypeName
string
ConfigVersion
string
RepeatCount
int
CortexDataLakeTenantID
string
DGHierarchyLevel1
int
DGHierarchyLevel2
int
DGHierarchyLevel3
int
DGHierarchyLevel4
int
IsDuplicateLog
boolean
LogExported
boolean
LogForwarded
boolean
IsPrismaNetworks
boolean
IsPrismaUsers
boolean
Location
string
LogSetting
string
LogSource
string
LogSourceGroupID
string
DeviceSN
string
DeviceName
string
LogSourceTimeZoneOffset
int
TimeReceived
timestamp
LogType
string
MFAAuthenticationID
long
MFAVendor
string
NormalizeUser
string
Object
string
PanoramaSN
string
PlatformType
string
Rule
string
RuleUUID
string
SequenceNo
long
AuthCacheServiceRegion
string
SessionID
int
SourceDeviceCategory
string
SourceDeviceHost
string
SourceDeviceMac
string
SourceDeviceModel
string
SourceDeviceOSFamily
string
SourceDeviceOSVersion
string
SourceDeviceProfile
string
SourceDeviceVendor
string
SourceIP
ip
Subtype
string
TimeGenerated
timestamp
TimeGeneratedHighResolution
timestamp_high_res
User
string
UserAgentString
string
VendorName
string
VirtualLocation
string
VirtualSystemID
int
VirtualSystemName
string