Decryption HTTPS Fields
Focus
Focus
Strata Logging Service

Decryption HTTPS Fields

Table of Contents

Decryption HTTPS Fields

The following table identifies the Decryption field names that the Log Forwarding app uses when you forward logs using the HTTPS log format.
HTTPS Name
Query Name
Field Type
Action
string
Application
string
ApplicationCategory
string
ApplicationSubcategory
string
CertificateFlags
int
CertificateSerial
string
CertificateSize
int
CertificateVersion
string
ChainStatus
string
ApplicationCharacteristics
array
ClientFlagResumeSession
string
ClientTLSAuth
string
ClientTLSCipher
string
ClientTLSEllipticCurve
string
ClientTLSEncryptionAlgorithm
string
ClientTLSKeyExchange
string
ClientTLSVersion
string
ClientToFirewall
string
CommonName
string
CommonNameLength
int
ConfigVersion
string
ContainerID
string
ApplicationContainer
string
RepeatCount
int
Cpadding
int
CortexDataLakeTenantID
string
DecryptionStatus
string
DecryptionStatusReason
string
DestinationDeviceCategory
string
DestinationDeviceClass
string
DestinationDeviceHost
string
DestinationDeviceMac
string
DestinationDeviceModel
string
DestinationDeviceOS
string
DestinationDeviceOSFamily
string
DestinationDeviceOSVersion
string
DestinationDeviceProfile
string
DestinationDeviceVendor
string
DestinationDynamicAddressGroup
string
DestinationEDL
string
DestinationAddress
ip
DestinationLocation
string
DestinationPort
int
DestinationUser
string
DestinationUserInfoDomain
string
DestinationUserInfoName
string
DestinationUserInfoUUID
long
DestinationUUID
string
DGHierarchyLevel1
int
DGHierarchyLevel2
int
DGHierarchyLevel3
int
DGHierarchyLevel4
int
Domain
int
DestinationDeviceID
string
EllipticCurve
string
ErrorIndex
string
ErrorMessage
string
F2CCertName
string
Fingerprint
string
FirewallToClient
string
FromZone
string
InboundInterface
string
InboundInterfaceDetailsPort
int
InboundInterfaceDetailsSlot
int
InboundInterfaceDetailsType
string
InboundInterfaceDetailsUnit
int
CaptivePortal
boolean
IsCertECDSA
boolean
IsCertRSA
boolean
IsCertCNTruncated
boolean
IsClienttoServer
boolean
IsContainer
boolean
IsDecryptMirror
boolean
IsDecrypted
boolean
IsDuplicateLog
boolean
IsEncrypted
boolean
LogExported
boolean
IsForwarded
boolean
IsIPV6
boolean
IsIssuerCNTruncated
boolean
IsMptcpOn
boolean
IsNAT
boolean
IsNonStandardDestinationPort
boolean
PacketCapture
boolean
IsPhishing
boolean
IsPrismaNetwork
boolean
IsPrismaUsers
boolean
IsProxy
boolean
IsReconExcluded
boolean
IsResumeSession
boolean
IsRootCNTruncated
boolean
IsSaaSApplication
boolean
IsServertoClient
boolean
IsSNITruncated
boolean
IsSourceXForwarded
boolean
IsSystemReturn
boolean
IsTransaction
boolean
IsTunnelInspected
boolean
IsURLDenied
boolean
IssuerCommonName
string
IssuerNameLength
int
K8SClusterID
int
LogSetting
string
LogSource
string
LogSourceGroupID
string
DeviceSN
string
DeviceName
string
LogSourceTimeZoneOffset
int
TimeReceived
timestamp
LogType
string
NATDestination
ip
NATDestinationPort
int
NATSource
ip
NATSourcePort
int
TimeNotAfter
timestamp
TimeNotBefore
timestamp
OutboundInterface
string
OutboundInterfaceDetailsPort
int
OutboundInterfaceDetailsSlot
int
OutboundInterfaceDetailsType
string
OutboundInterfaceDetailsUnit
int
Padding
int
Padding3
int
PanoramaSN
string
PlatformType
string
ContainerName
string
ContainerNameSpace
string
PolicyName
string
Protocol
string
ProxyType
string
ApplicationRisk
int
RootCommonName
string
RootCNLength
int
RootStatus
string
Rule
string
RuleUUID
string
SanctionedStateOfApp
boolean
SequenceNo
long
ServerCertSignatureAlgorithm
string
ServerCertStatus
string
ServerFlagResumeSession
string
ServerTLSCipher
string
SessionID
int
ServerNameIndication
string
SNILength
int
SourceDeviceCategory
string
SourceDeviceClass
string
SourceDeviceHost
string
SourceDeviceMac
string
SourceDeviceModel
string
SourceDeviceOS
string
SourceDeviceOSFamily
string
SourceDeviceOSVersion
string
SourceDeviceProfile
string
SourceDeviceVendor
string
SourceDynamicAddressGroup
string
SourceEDL
string
SourceAddress
ip
SourceLocation
string
SourcePort
int
SourceUser
string
SourceUserInfoDomain
string
SourceUserInfoName
string
SourceUserInfoUUID
long
SourceUUID
string
SourceDeviceID
string
Subtype
string
ApplicationTechnology
string
TimeGenerated
timestamp
TimeGeneratedHighResolution
timestamp_high_res
TimeReceivedManagementPlane
string
TLSAuth
string
TLSEncryptionAlgorithm
string
TLSKeyExchange
string
TLSVersion
string
ToZone
string
Tpadding
int
TSGID
string
Tunnel
string
TunneledApplication
string
VendorName
string
Vpadding
int
VirtualLocation
string
VirtualSystemID
int
VirtualSystemName
string