Strata Logging Service
SCTP EMAIL Fields
Table of Contents
Expand All
|
Collapse All
Strata Logging Service Docs
SCTP EMAIL Fields
Example SCTP log in EMAIL:
TimeReceived=2021-02-23T02:45:00.000000Z DeviceSN=xxxxxxxxxxxxx LogType=SCTP Subtype= ConfigVersion= TimeGenerated=2021-02-23T02:45:00.000000Z SourceIP=xxxxxxxxxxxx DestinationIP=xxx.xx.x.xx NATSource=xxx.xx.x.xx NATDestination=xxx.xx.x.xx Rule=allow-business-apps SourceUser="paloaltonetwork\xxxxx" DestinationUser=paloaltonetworkxxxxx Application=panorama VirtualLocation=vsys1 FromZone=corporate ToZone=untrust InboundInterface=ethernet1/1 OutboundInterface=ethernet1/2 LogSetting=test SessionID=391582 RepeatCount=1 SourcePort=3033 DestinationPort=5496 NATSourcePort=26714 NATDestinationPort=15054 Protocol=tcp Action=alert DGHierarchyLevel1=12 DGHierarchyLevel2=0 DGHierarchyLevel3=0 DGHierarchyLevel4=0 VirtualSystemName= DeviceName=PA-5220 SequenceNo=6711379990526573312 EndpointAssociationID=2086888838 PayloadProtocolID=-1 VendorSeverity=Critical SctpChunkType=9 SCTPEventType=Kerberos single sign-on failed EventCode=3 VerificationTag1=0x3bae3042 VerificationTag2=0x1911015e SctpCauseCode=0 DiamAppID=-1 DiameterCommandCode=-1 DiamAvpCode=0 StreamID=0 AssocationEndReason= MapAppCode=0 SccpCallingSSN=0 SccpCallingGt= SctpFilter= ChunksTotal=0 ChunksSent=0 ChunksReceived=0 PacketsTotal=0 PacketsSent=0 PacketsReceived=0 RuleUUID= ContainerID= ContainerNameSpace= ContainerName= SourceEDL= DestinationEDL= SourceDynamicAddressGroup= DestinationDynamicAddressGroup= TimeGeneratedHighResolution=2019-07-25T23:30:12.000000Z
The following table identifies the SCTP field names that the Log Forwarding app
uses when you forward logs using the EMAIL log format.
|
EMAIL Name
|
Query Name
|
|---|---|
|
Action
| |
|
Application
| |
|
AssocationEndReason
| |
|
ChunksReceived
| |
|
ChunksSent
| |
|
ChunksTotal
| |
|
ConfigVersion
| |
|
ContainerID
| |
|
ContentVersion
| |
|
RepeatCount
| |
|
CortexDataLakeTenantID
| |
|
DestinationDeviceClass
| |
|
DestinationDeviceMac
| |
|
DestinationDeviceModel
| |
|
DestinationDeviceOS
| |
|
DestinationDeviceVendor
| |
|
DestinationDynamicAddressGroup
| |
|
DestinationEDL
| |
|
DestinationIP
| |
|
DestinationLocation
| |
|
DestinationPort
| |
|
DestinationUser
| |
|
DestinationUserDomain
| |
|
DestinationUserName
| |
|
DestinationUserUUID
| |
|
DestinationUUID
| |
|
DGHierarchyLevel1
| |
|
DGHierarchyLevel2
| |
|
DGHierarchyLevel3
| |
|
DGHierarchyLevel4
| |
|
DiamAppID
| |
|
DiamAvpCode
| |
|
DiameterCommandCode
| |
|
EndpointAssociationID
| |
|
EventCode
| |
|
SCTPEventType
| |
|
FromZone
| |
|
InboundInterface
| |
|
InboundInterfaceDetailsPort
| |
|
InboundInterfaceDetailsSlot
| |
|
InboundInterfaceDetailsType
| |
|
InboundInterfaceDetailsUnit
| |
|
CaptivePortal
| |
|
IsClienttoServer
| |
|
IsContainer
| |
|
IsDecryptMirror
| |
|
IsDecryptedPayloadForward
| |
|
IsDecryptedLog
| |
|
IsDuplicateLog
| |
|
LogExported
| |
|
LogForwarded
| |
|
IsIPV6
| |
|
IsInspectionBeforeSession
| |
|
IsMptcpOn
| |
|
NAT
| |
|
IsNonStandardDestinationPort
| |
|
IsPacketCapture
| |
|
IsPhishing
| |
|
IsPrismaNetwork
| |
|
IsPrismaUsers
| |
|
IsProxy
| |
|
IsReconExcluded
| |
|
IsServertoClient
| |
|
IsSourceXForwarded
| |
|
IsSystemReturn
| |
|
IsTransaction
| |
|
IsTunnelInspected
| |
|
IsURLDenied
| |
|
LogSetting
| |
|
LogSource
| |
|
LogSourceGroupID
| |
|
DeviceSN
| |
|
DeviceName
| |
|
LogSourceTimeZoneOffset
| |
|
TimeReceived
| |
|
LogType
| |
|
MapAppCode
| |
|
NATDestination
| |
|
NATDestinationPort
| |
|
NATSource
| |
|
NATSourcePort
| |
|
OutboundInterface
| |
|
OutboundInterfaceDetailsPort
| |
|
OutboundInterfaceDetailsSlot
| |
|
OutboundInterfaceDetailsType
| |
|
OutboundInterfaceDetailsUnit
| |
|
PacketsReceived
| |
|
PacketsSent
| |
|
PacketsTotal
| |
|
PanoramaSN
| |
|
PayloadProtocolID
| |
|
PlatformType
| |
|
ContainerName
| |
|
ContainerNameSpace
| |
|
Protocol
| |
|
Rule
| |
|
RuleUUID
| |
|
SccpCallingGt
| |
|
SccpCallingSSN
| |
|
SctpCauseCode
| |
|
SctpChunkType
| |
|
SctpFilter
| |
|
SequenceNo
| |
|
SessionOwnerMidx
| |
|
SessionEndReason
| |
|
SessionID
| |
|
SessionTracker
| |
|
Severity
| |
|
SourceDeviceClass
| |
|
SourceDeviceMac
| |
|
SourceDeviceModel
| |
|
SourceDeviceOS
| |
|
SourceDeviceVendor
| |
|
SourceDynamicAddressGroup
| |
|
SourceEDL
| |
|
SourceIP
| |
|
SourceLocation
| |
|
SourcePort
| |
|
SourceUser
| |
|
SourceUserDomain
| |
|
SourceUserName
| |
|
SourceUserUUID
| |
|
SourceUUID
| |
|
StreamID
| |
|
Subtype
| |
|
TimeGenerated
| |
|
TimeGeneratedHighResolution
| |
|
ToZone
| |
|
Tunnel
| |
|
VendorName
| |
|
VendorSeverity
| |
|
VerificationTag1
| |
|
VerificationTag2
| |
|
VirtualLocation
| |
|
VirtualSystemID
| |
|
VirtualSystemName
|