Strata Logging Service
UserID EMAIL Fields
Table of Contents
Expand All
|
Collapse All
Strata Logging Service Docs
UserID EMAIL Fields
Example UserID log in EMAIL:
TimeReceived=2021-02-23T02:43:57.000000Z DeviceSN=xxxxxxxxxxxxx LogType=USERID Subtype=logout ConfigVersion= TimeGenerated=2021-02-23T02:43:57.000000Z VirtualLocation=vsys1 SourceIP=xxxxxxxxxxxx User="paloaltonetworks\xxxxx" MappingDataSourceName=fake-data-source-169 EventID=0 CountofRepeats=1 MappingTimeout=3531 SourcePort=21015 DestinationPort=49760 MappingDataSource=probing MappingDataSourceType=netbios_probing SequenceNo=6711379990526558750 DGHierarchyLevel1=12 DGHierarchyLevel2=0 DGHierarchyLevel3=0 DGHierarchyLevel4=0 VirtualSystemName= DeviceName=PA-5220 VirtualSystemID=1 MFAFactorType=xxxxx AuthCompletionTime=2019-07-09T18:15:44.000000Z AuthFactorNo=3 UGFlags=0x100 UserIdentifiedBySource=xxxxxxxxxxxxxx Tag= TimeGeneratedHighResolution=2019-07-25T23:30:12.000000Z
The following table identifies the UserID field names that the Log Forwarding app
uses when you forward logs using the EMAIL log format.
|
EMAIL Name
|
Query Name
|
|---|---|
|
AuthCompletionTime
| |
|
AuthFactorNo
| |
|
AuthenticatedUserDomain
| |
|
AuthenticatedUserName
| |
|
AuthenticatedUserUUID
| |
|
ConfigVersion
| |
|
CountofRepeats
| |
|
CortexDataLakeTenantID
| |
|
DestinationPort
| |
|
DGHierarchyLevel1
| |
|
DGHierarchyLevel2
| |
|
DGHierarchyLevel3
| |
|
DGHierarchyLevel4
| |
|
EventID
| |
|
IsDuplicateLog
| |
|
IsDuplicateUser
| |
|
LogExported
| |
|
LogForwarded
| |
|
IsPrismaNetworks
| |
|
IsPrismaUsers
| |
|
LogSource
| |
|
LogSourceGroupID
| |
|
DeviceSN
| |
|
DeviceName
| |
|
LogSourceTimeZoneOffset
| |
|
TimeReceived
| |
|
LogType
| |
|
MappingDataSource
| |
|
MappingDataSourceName
| |
|
MappingDataSourceType
| |
|
MappingTimeout
| |
|
MFAFactorType
| |
|
PanoramaSN
| |
|
PlatformType
| |
|
SequenceNo
| |
|
SourceIP
| |
|
SourcePort
| |
|
Subtype
| |
|
Tag
| |
|
TimeGenerated
| |
|
TimeGeneratedHighResolution
| |
|
UGFlags
| |
|
User
| |
|
UserGroupFound
| |
|
UserIdentifiedBySource
| |
|
VendorName
| |
|
VirtualLocation
| |
|
VirtualSystemID
| |
|
VirtualSystemName
|