Strata Logging Service
Authentication CEF Fields
Table of Contents
Expand All
|
Collapse All
Authentication CEF Fields
Example Authentication log in CEF:
Mar 1 21:05:25 xxx.xx.x.xx 2206 <14>1 2021-03-01T21:05:25.508Z stream-logfwd20-587718190-03011255-ut6o-harness-5vlj logforwarder - panwlogs - CEF:0|Palo Alto Networks|LF|2.0|AUTH|Radius|3|ProfileToken=xxxxx dtz=UTC rt=Feb 28 2021 18:20:54 deviceExternalId=xxxxxxxxxxxxx PanOSConfigVersion=10.0 PanOSAuthenticatedUserDomain=paloaltonetwork PanOSAuthenticatedUserName=xxxxx PanOSAuthenticatedUserUUID= PanOSClientTypeName= PanOSCortexDataLakeTenantID=xxxxxxxxxxxxx PanOSIsDuplicateLog=false PanOSIsPrismaNetworks=false PanOSIsPrismaUsers=false PanOSLogExported=false PanOSLogForwarded=true PanOSLogSource=firewall PanOSLogSourceTimeZoneOffset= PanOSRuleMatched= start=Feb 28 2021 18:20:40 cs3=vsys1 cs3Label=VirtualLocation c6a2=::ffff:0 c6a2Label=Source IPv6 Address c6a3=::ffff:0 c6a3Label=Destination IPv6 Address duser=paloaltonetwork\\xxxxx cs2=paloaltonetwork\\xxxxx cs2Label=NormalizeUser fname=Authentication object2 cs4=DC cs4Label=AuthenticationPolicy cnt=33554432 cn2=-5257671089978343424 cn2Label=MFAAuthenticationID PanOSMFAVendor=Symantec VIP cs6=rs-logging cs6Label=LogSetting cs1=deny-attackers cs1Label=AuthServerProfile PanOSAuthenticationDescription=www.something cs5=Unknown cs5Label=ClientType msg=Invalid Certificate cn1=0 cn1Label=AuthFactorNo externalId=xxxxxxxxxxxxx PanOSDGHierarchyLevel1=11 PanOSDGHierarchyLevel2=0 PanOSDGHierarchyLevel3=0 PanOSDGHierarchyLevel4=0 PanOSVirtualSystemName= dvchost=xxxxx PanOSVirtualSystemID=1 PanOSAuthenticationProtocol=EAP-TTLS with PAP PanOSRuleMatchedUUID= PanOSTimeGeneratedHighResolution=Feb 28 2021 18:20:41 PanOSSourceDeviceCategory=src_category_list-1 PanOSSourceDeviceProfile=src_profile_list-1 PanOSSourceDeviceModel=src_model_list-1 PanOSSourceDeviceVendor=src_vendor_list-1 PanOSSourceDeviceOSFamily=src_osfamily_list-0 PanOSSourceDeviceOSVersion=src_osversion_list-2 PanOSSourceDeviceHost=src_host_list-0 PanOSSourceDeviceMac=src_mac_list-2 PanOSAuthCacheServiceRegion= PanOSUserAgentString= PanOSSessionID=
The following table identifies the Authentication field names that the Log Forwarding app
uses when you forward logs using the CEF log format.
CEF Name
|
Field Details
|
---|---|
PanOSAuthenticationDescription
| Query Name: auth_descriptionHeader Type: Custom |
msg
| |
cn1
| |
cs4
| Query Name: auth_policyHeader Type: PredefinedLabel: cs4LabelLabel Text: AuthenticationPolicyMax Length: 4000 |
PanOSAuthenticationProtocol
| Query Name: auth_protoHeader Type: Custom |
cs1
| Query Name: auth_server_profileHeader Type: PredefinedLabel: cs1LabelLabel Text: AuthServerProfileMax Length: 4000 |
PanOSAuthenticatedUserDomain
| Query Name: authenticated_user_info.domainHeader Type: Custom |
PanOSAuthenticatedUserName
| Query Name: authenticated_user_info.nameHeader Type: Custom |
PanOSAuthenticatedUserUUID
| Query Name: authenticated_user_info.uuidHeader Type: Custom |
cs5
| Query Name: client_typeHeader Type: PredefinedLabel: cs5LabelLabel Text: ClientTypeMax Length: 4000 |
PanOSClientTypeName
| Query Name: client_type_name.valueHeader Type: Custom |
PanOSConfigVersion
| Query Name: config_version.valueHeader Type: Custom |
cnt
| Query Name: count_of_repeatsHeader Type: Predefined |
PanOSCortexDataLakeTenantID
| Query Name: customer_idHeader Type: Custom |
PanOSDGHierarchyLevel1
| Query Name: dg_hier_level_1Header Type: Custom |
PanOSDGHierarchyLevel2
| Query Name: dg_hier_level_2Header Type: Custom |
PanOSDGHierarchyLevel3
| Query Name: dg_hier_level_3Header Type: Custom |
PanOSDGHierarchyLevel4
| Query Name: dg_hier_level_4Header Type: Custom |
PanOSIsDuplicateLog
| Query Name: is_dup_logHeader Type: Custom |
PanOSLogExported
| Query Name: is_exportedHeader Type: Custom |
PanOSLogForwarded
| Query Name: is_forwardedHeader Type: Custom |
PanOSIsPrismaNetworks
| Query Name: is_prisma_branchHeader Type: Custom |
PanOSIsPrismaUsers
| Query Name: is_prisma_mobileHeader Type: Custom |
PanOSLocation
| Query Name: locationHeader Type: Custom |
cs6
| |
PanOSLogSource
| Query Name: log_sourceHeader Type: Custom |
LogSourceGroupID
| |
deviceExternalId
| |
dvchost
| |
PanOSLogSourceTimeZoneOffset
| Query Name: log_source_tz_offsetHeader Type: Custom |
rt
| Query Name: log_timeHeader Type: Predefined |
DeviceEventClassId
| Query Name: log_type.valueHeader Type: Custom |
cn2
| |
PanOSMFAVendor
| Query Name: mfa_vendorHeader Type: Custom |
cs2
| Query Name: normalize_userHeader Type: PredefinedLabel: cs2LabelLabel Text: NormalizeUserMax Length: 4000 |
fname
| |
PanOSPanoramaSN
| Query Name: panorama_serialHeader Type: Custom |
PlatformType
| Query Name: platform_typeHeader Type: Custom |
PanOSRuleMatched
| Query Name: rule_matchedHeader Type: Custom |
PanOSRuleMatchedUUID
| Query Name: rule_matched_uuidHeader Type: Custom |
externalId
| |
PanOSAuthCacheServiceRegion
| Query Name: service_regionHeader Type: Custom |
PanOSSessionID
| Query Name: session_idHeader Type: Custom |
PanOSSourceDeviceCategory
| Query Name: source_device_categoryHeader Type: Custom |
PanOSSourceDeviceHost
| Query Name: source_device_hostHeader Type: Custom |
PanOSSourceDeviceMac
| Query Name: source_device_macHeader Type: Custom |
PanOSSourceDeviceModel
| Query Name: source_device_modelHeader Type: Custom |
PanOSSourceDeviceOSFamily
| Query Name: source_device_osfamilyHeader Type: Custom |
PanOSSourceDeviceOSVersion
| Query Name: source_device_osversionHeader Type: Custom |
PanOSSourceDeviceProfile
| Query Name: source_device_profileHeader Type: Custom |
PanOSSourceDeviceVendor
| Query Name: source_device_vendorHeader Type: Custom |
src and dst, or c6a2 and c6a3
| Query Name: source_ip.valueHeader Type: PredefinedLabel: || c6a2Label && c6a3LabelLabel Text: || Source IPv6 Address && Destination IPv6 Address |
Name
| Query Name: sub_type.valueHeader Type: Custom |
start
| Query Name: time_generatedHeader Type: Predefined |
PanOSTimeGeneratedHighResolution
| Query Name: time_generated_high_resHeader Type: Custom |
duser
| |
PanOSUserAgentString
| Query Name: user_agentHeader Type: Custom |
Device Vendor
| Query Name: vendor_nameHeader Type: Custom |
cs3
| Query Name: vsysHeader Type: PredefinedLabel: cs3LabelLabel Text: VirtualLocationMax Length: 4000 |
PanOSVirtualSystemID
| Query Name: vsys_idHeader Type: Custom |
PanOSVirtualSystemName
| Query Name: vsys_nameHeader Type: Custom |