Strata Logging Service
IPtag CEF Fields
Table of Contents
Expand All
|
Collapse All
IPtag CEF Fields
Example IPtag log in CEF:
Mar 1 21:20:15 xxx.xx.x.xx 1042 <14>1 2021-03-01T21:20:15.116Z stream-logfwd20-587718190-03011312-b28y-harness-x4nx logforwarder - panwlogs - CEF:0|Palo Alto Networks|LF|2.0|IPTAG|iptag|3|ProfileToken=xxxxx dtz=UTC rt=Mar 01 2021 21:20:13 deviceExternalId=xxxxxxxxxxxxx PanOSTenantID=xxxxxxxxxxxxx PanOSIsDuplicateLog=false PanOSIsPrismaNetworks=false PanOSIsPrismaUsers=false PanOSLogExported=false PanOSLogForwarded=true PanOSLogSetting= PanOSLogSource=firewall PanOSLogSourceTimeZoneOffset= PanOSRuleMatched= PanOSRuleMatchedUUID= PanOSConfigVersion= start=Mar 01 2021 21:20:13 cs3=vsys1 cs3Label=VirtualLocation src=xxx.xx.x.xx dst=xxx.xx.x.xx PanOSTagName= PanOSEventID=Unregister cnt=1 PanOSMappingTimeout=10 PanOSMappingDataSource=XMLAPI PanOSMappingDataSourceType=XML-API PanOSMappingDataSourceSubType=Unknown externalId=xxxxxxxxxxxxx PanOSDGHierarchyLevel1=18 PanOSDGHierarchyLevel2=0 PanOSDGHierarchyLevel3=0 PanOSDGHierarchyLevel4=0 PanOSVirtualSystemName= dvchost=PA-VM cn2=1 cn2Label=VirtualSystemID PanOSIPSubnetRange= PanOSTimeGeneratedHighResolution=Jul 25 2019 23:30:12
The following table identifies the IPtag field names that the Log Forwarding app
uses when you forward logs using the CEF log format.
CEF Name
|
Field Details
|
---|---|
PanOSConfigVersion
| Query Name: config_version.valueHeader Type: Custom |
cnt
| Query Name: count_of_repeatsHeader Type: Predefined |
PanOSTenantID
| Query Name: customer_idHeader Type: Custom |
PanOSDGHierarchyLevel1
| Query Name: dg_hier_level_1Header Type: Custom |
PanOSDGHierarchyLevel2
| Query Name: dg_hier_level_2Header Type: Custom |
PanOSDGHierarchyLevel3
| Query Name: dg_hier_level_3Header Type: Custom |
PanOSDGHierarchyLevel4
| Query Name: dg_hier_level_4Header Type: Custom |
PanOSEventID
| Query Name: event_id.valueHeader Type: Custom |
PanOSIPSubnetRange
| Query Name: ip_subnet_rangeHeader Type: Custom |
PanOSIsDuplicateLog
| Query Name: is_dup_logHeader Type: Custom |
PanOSLogExported
| Query Name: is_exportedHeader Type: Custom |
PanOSLogForwarded
| Query Name: is_forwardedHeader Type: Custom |
PanOSIsPrismaNetworks
| Query Name: is_prisma_branchHeader Type: Custom |
PanOSIsPrismaUsers
| Query Name: is_prisma_mobileHeader Type: Custom |
PanOSLogSetting
| Query Name: log_setHeader Type: Custom |
PanOSLogSource
| Query Name: log_sourceHeader Type: Custom |
LogSourceGroupID
| Query Name: log_source_group_idHeader Type: Custom |
deviceExternalId
| |
dvchost
| |
PanOSLogSourceTimeZoneOffset
| Query Name: log_source_tz_offsetHeader Type: Custom |
rt
| Query Name: log_timeHeader Type: Predefined |
Device Event Class ID
| Query Name: log_type.valueHeader Type: Custom |
PanOSMappingDataSource
| Query Name: mapping_data_source_nameHeader Type: Custom |
PanOSMappingDataSourceSubType
| Query Name: mapping_data_source_sub_type.valueHeader Type: Custom |
PanOSMappingDataSourceType
| Query Name: mapping_data_source_type.valueHeader Type: Custom |
PanOSMappingTimeout
| Query Name: mapping_timeoutHeader Type: Custom |
PanOSPanoramaSN
| Query Name: panorama_serialHeader Type: Custom |
PlatformType
| Query Name: platform_typeHeader Type: Custom |
PanOSRuleMatched
| Query Name: rule_matchedHeader Type: Custom |
PanOSRuleMatchedUUID
| Query Name: rule_matched_uuidHeader Type: Custom |
externalId
| |
src and dst, or c6a2 and c6a3
| Query Name: source_ip.valueHeader Type: PredefinedLabel: || c6a2Label && c6a3LabelLabel Text: || Source IPv6 Address && Destination IPv6 Address |
Name
| Query Name: sub_type.valueHeader Type: Custom |
PanOSTagName
| Query Name: tag_nameHeader Type: Custom |
start
| Query Name: time_generatedHeader Type: Predefined |
PanOSTimeGeneratedHighResolution
| Query Name: time_generated_high_resHeader Type: Custom |
Device Vendor
| Query Name: vendor_nameHeader Type: Custom |
cs3
| Query Name: vsysHeader Type: PredefinedLabel: cs3LabelLabel Text: VirtualLocationMax Length: 4000 |
cn2
| |
PanOSVirtualSystemName
| Query Name: vsys_nameHeader Type: Custom |