Strata Logging Service
Traffic EMAIL Fields
Table of Contents
Expand All
|
Collapse All
Strata Logging Service Docs
Traffic EMAIL Fields
Example Traffic log in EMAIL:
TimeReceived=2021-01-22T21:43:39.000000Z DeviceSN=xxxxxxxxxxxxx LogType=TRAFFIC Subtype=end ConfigVersion=10.0 TimeGenerated=2021-01-22T21:43:23.000000Z SourceAddress=xxx.xx.x.xx DestinationAddress=xxx.xx.x.xx NATSource=xxx.xx.x.xx NATDestination=xxx.xx.x.xx Rule=allow-business-apps SourceUser="paloaltonetwork\xxxxx" DestinationUser= Application=infoblox-grid VirtualLocation=vsys1 FromZone=ethernet4Zone-test1 ToZone=untrust InboundInterface=unknown OutboundInterface=unknown LogSetting=rs-logging SessionID=952362 RepeatCount=1 SourcePort=5547 DestinationPort=6564 NATSourcePort=8940 NATDestinationPort=16125 Protocol=tcp Action=deny Bytes=652430 BytesSent=231247 BytesReceived=421183 PacketsTotal=2058 SessionStartTime=2021-01-22T21:42:53.000000Z SessionDuration=58 URLCategory=1 SequenceNo=20397927 SourceLocation=BR DestinationLocation=CN PacketsSent=1086 PacketsReceived=972 SessionEndReason=unknown VirtualSystemName= DeviceName=xxxxx ActionSource=unknown SourceUUID= DestinationUUID= IMSI=0 IMEI= ParentSessionID=0 ParentStarttime=2021-01-22T21:42:44.000000Z Tunnel=N/A EndpointAssociationID=7349874591868649490 ChunksTotal=3424 ChunksSent=3119 ChunksReceived=305 RuleUUID=ec14df0b-c845-4435-87a2-d207730f5ae8 HTTP2Connection=547970 LinkChangeCount=0 SDWANPolicyName= LinkSwitches= SDWANCluster= SDWANDeviceType= SDWANClusterType= SDWANSite= DynamicUserGroupName=dynug-3 X-Forwarded-ForIP=xxx.xx.x.xx SourceDeviceCategory=X-Phone SourceDeviceProfile=x-profile SourceDeviceModel=Redmi SourceDeviceVendor=Xiaomi SourceDeviceOSFamily=5 Plus SourceDeviceOSVersion=Android v8.2 SourceDeviceHost=pan-603 SourceDeviceMac=645701225660 DestinationDeviceCategory=X-Phone DestinationDeviceProfile=x-profile DestinationDeviceModel=MI DestinationDeviceVendor=Xiaomi DestinationDeviceOSFamily=A1 DestinationDeviceOSVersion=Android v9.1 DestinationDeviceHost=pan-622 DestinationDeviceMac=207974153661 ContainerID=1873cc5c-0d31 ContainerNameSpace=pns_default ContainerName=pan-dp-77754f4 SourceEDL= DestinationEDL= GPHostID=6060606060 EndpointSerialNumber=xxxxxxxxxxxxxx SourceDynamicAddressGroup= aqua_dag DestinationDynamicAddressGroup= HASessionOwner=session_owner-2 TimeGeneratedHighResolution=2021-01-22T21:43:23.795000Z NSSAINetworkSliceType=a7 NSSAINetworkSliceDifferentiator=5700
The following table identifies the Traffic field names that the Log Forwarding app
uses when you forward logs using the EMAIL log format.
|
EMAIL Name
|
Query Name
|
|---|---|
|
Action
| |
|
ActionSource
| |
|
AIFwdError
| |
|
AITraffic
| |
|
Application
| |
|
ApplicationCategory
| |
|
ApplicationSubcategory
| |
|
BytesReceived
| |
|
BytesSent
| |
|
Bytes
| |
|
ChunksReceived
| |
|
ChunksSent
| |
|
ChunksTotal
| |
|
ConfigVersion
| |
|
ContainerID
| |
|
ApplicationContainer
| |
|
RepeatCount
| |
|
CortexDataLakeTenantID
| |
|
DestinationDeviceCategory
| |
|
DestinationDeviceClass
| |
|
DestinationDeviceHost
| |
|
DestinationDeviceMac
| |
|
DestinationDeviceModel
| |
|
DestinationDeviceOS
| |
|
DestinationDeviceOSFamily
| |
|
DestinationDeviceOSVersion
| |
|
DestinationDeviceProfile
| |
|
DestinationDeviceVendor
| |
|
DestinationDynamicAddressGroup
| |
|
DestinationEDL
| |
|
DestinationAddress
| |
|
DestinationLocation
| |
|
DestinationPort
| |
|
DestinationUser
| |
|
DestinationUserDomain
| |
|
DestinationUserName
| |
|
DestinationUserUUID
| |
|
DestinationUUID
| |
|
DGHierarchyLevel1
| |
|
DGHierarchyLevel2
| |
|
DGHierarchyLevel3
| |
|
DGHierarchyLevel4
| |
|
DynamicUserGroupName
| |
|
EndpointSerialNumber
| |
|
EndpointAssociationID
| |
|
FlowType
| |
|
FromZone
| |
|
HASessionOwner
| |
|
GPHostID
| |
|
HTTP2Connection
| |
|
InboundInterface
| |
|
InboundInterfaceDetailsPort
| |
|
InboundInterfaceDetailsSlot
| |
|
InboundInterfaceDetailsType
| |
|
InboundInterfaceDetailsUnit
| |
|
CaptivePortal
| |
|
IsClienttoServer
| |
|
IsContainer
| |
|
IsDecryptMirror
| |
|
IsDecrypted
| |
|
IsDecryptedPayloadForward
| |
|
IsDecryptedLog
| |
|
IsDuplicateLog
| |
|
IsEncrypted
| |
|
LogExported
| |
|
LogForwarded
| |
|
IsIPV6
| |
|
IsInspectionBeforeSession
| |
|
IsMptcpOn
| |
|
NAT
| |
|
IsNonStandardDestinationPort
| |
|
IsOffloaded
| |
|
IsPacketCapture
| |
|
IsPhishing
| |
|
IsPrismaNetwork
| |
|
IsPrismaUsers
| |
|
IsProxy
| |
|
IsReconExcluded
| |
|
IsSaaSApplication
| |
|
IsServertoClient
| |
|
IsSourceXForwarded
| |
|
IsSystemReturn
| |
|
IsTransaction
| |
|
IsTunnelInspected
| |
|
IsURLDenied
| |
|
K8SClusterID
| |
|
LinkChangeCount
| |
|
LinkSwitches
| |
|
Location
| |
|
LogSetting
| |
|
LogSource
| |
|
LogSourceGroupID
| |
|
DeviceSN
| |
|
DeviceName
| |
|
LogSourceTimeZoneOffset
| |
|
TimeReceived
| |
|
LogType
| |
|
IMEI
| |
|
NATDestination
| |
|
NATDestinationPort
| |
|
NATSource
| |
|
NATSourcePort
| |
|
NonStandardDestinationPort
| |
|
NSSAINetworkSliceDifferentiator
| |
|
NSSAINetworkSliceType
| |
|
OutboundInterface
| |
|
OutboundInterfaceDetailsPort
| |
|
OutboundInterfaceDetailsSlot
| |
|
OutboundInterfaceDetailsType
| |
|
OutboundInterfaceDetailsUnit
| |
|
PacketsReceived
| |
|
PacketsSent
| |
|
PacketsTotal
| |
|
PanoramaSN
| |
|
ParentSessionID
| |
|
ParentStarttime
| |
|
PlatformType
| |
|
ContainerName
| |
|
ContainerNameSpace
| |
|
SDWANPolicyName
| |
|
Protocol
| |
|
ApplicationRisk
| |
|
Rule
| |
|
RuleUUID
| |
|
SanctionedStateOfApp
| |
|
SDWANFECRatio
| |
|
SDWANCluster
| |
|
SDWANClusterType
| |
|
SDWANDeviceType
| |
|
SDWANSite
| |
|
SequenceNo
| |
|
SessionOwnerMidx
| |
|
SessionEndReason
| |
|
SessionID
| |
|
SessionStartTime
| |
|
SessionTracker
| |
|
SourceDeviceCategory
| |
|
SourceDeviceClass
| |
|
SourceDeviceHost
| |
|
SourceDeviceMac
| |
|
SourceDeviceModel
| |
|
SourceDeviceOS
| |
|
SourceDeviceOSFamily
| |
|
SourceDeviceOSVersion
| |
|
SourceDeviceProfile
| |
|
SourceDeviceVendor
| |
|
SourceDynamicAddressGroup
| |
|
SourceEDL
| |
|
SourceAddress
| |
|
SourceLocation
| |
|
SourcePort
| |
|
SourceUser
| |
|
SourceUserDomain
| |
|
SourceUserName
| |
|
SourceUserUUID
| |
|
SourceUUID
| |
|
Subtype
| |
|
ApplicationTechnology
| |
|
TimeGenerated
| |
|
TimeGeneratedHighResolution
| |
|
ToZone
| |
|
SessionDuration
| |
|
Tunnel
| |
|
TunneledApplication
| |
|
IMSI
| |
|
URLCategory
| |
|
Users
| |
|
VendorName
| |
|
VirtualLocation
| |
|
VirtualSystemID
| |
|
VirtualSystemName
| |
|
X-Forwarded-ForIP
|