GlobalProtect EMAIL Fields
Focus
Focus
Strata Logging Service

GlobalProtect EMAIL Fields

Table of Contents

GlobalProtect EMAIL Fields

Example GlobalProtect log in EMAIL:
TimeReceived=2021-02-23T02:44:27.000000Z DeviceSN=xxxxxxxxxxxxx LogType=GLOBALPROTECT LogSubtype=globalprotect ConfigVersion= SourceUserUUID= TenantID=xxxxxxxxxxxxx VendorName=Palo Alto Networks VirtualSystemName= SourceUserName=xxxxx SourceUserDomain=paloaltonetwork LogSourceTimeZoneOffset= Gateway= DGHierarchyLevel1=20 DGHierarchyLevel2=0 DGHierarchyLevel3=0 DGHierarchyLevel4=0 DeviceName=PA-VM EventID=309 IsDuplicateLog=false IsPrismaNetworks=false IsPrismaUsers=false LogExported=false LogSource=firewall VirtualSystemID=1 TimeGenerated=2021-02-23T02:44:27.000000Z VirtualSystem=vsys1 EventIDValue=satellite-gateway-update-route Stage=connected AuthMethod=RADIUS TunnelType=ipsec SourceUserName0="paloaltonetwork\\xxxxx" SourceRegion=ET EndpointDeviceName=machine_name2 PublicIPv4=xxx.xx.x.xx PublicIPv6=xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx PrivateIPv4=xxx.xx.x.xx PrivateIPv6=xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx HostID=e667947f-d92e-4815-9222-89438203bc2b EndpointSN=serialno_list-1 GlobalProtectClientVersion=3.0.9 EndpointOSType=Intel Mac OS EndpointOSVersion=9.3.5 CountOfRepeats=16777216 QuarantineReason=Malicious Traffic ConnectionError=Client cert not present Description=opaque_list-1 EventStatus=failure GlobalProtectGatewayLocation=San Francisco LoginDuration=1 ConnectionMethod=connect_method_list-1 Portal=portal_list-2 SequenceNo=34401910 TimeGeneratedHighResolution=2019-07-25T23:30:12.000000Z GatewaySelectionType= SSLResponseTime= GatewayPriority= AttemptedGateways=
The following table identifies the GlobalProtect field names that the Log Forwarding app uses when you forward logs using the EMAIL log format.
EMAIL Name
Query Name
AttemptedGateways
AuthMethod
ConfigVersion
ConnectionMethod
ConnectionErrorID
ConnectionError
CountOfRepeats
TenantID
DGHierarchyLevel1
DGHierarchyLevel2
DGHierarchyLevel3
DGHierarchyLevel4
EndpointDeviceName
GlobalProtectClientVersion
EndpointOSType
EndpointOSVersion
EndpointSN
EventIDValue
Gateway
GatewayPriority
GatewaySelectionType
GlobalProtectGatewayLocation
HostID
IsDuplicateLog
LogExported
LogForwarded
IsPrismaNetworks
IsPrismaUsers
LogSource
LogSourceGroupID
DeviceSN
DeviceName
LogSourceTimeZoneOffset
TimeReceived
LogType
LoginDuration
Description
PanoramaSN
PlatformType
Portal
PrivateIPv4
PrivateIPv6
ProjectName
PublicIPv4
PublicIPv6
QuarantineReason
SequenceNo
SourceRegion
SourceUserName
SourceUserDomain
SourceUserName
SourceUserUUID
SSLResponseTime
Stage
EventStatus
LogSubtype
TimeGenerated
TimeGeneratedHighResolution
TunnelType
VendorName
VirtualSystem
VirtualSystemID
VirtualSystemName