Traffic EMAIL Fields
Focus
Focus
Strata Logging Service

Traffic EMAIL Fields

Table of Contents

Traffic EMAIL Fields

Example Traffic log in EMAIL:
TimeReceived=2021-01-22T21:43:39.000000Z DeviceSN=xxxxxxxxxxxxx LogType=TRAFFIC Subtype=end ConfigVersion=10.0 TimeGenerated=2021-01-22T21:43:23.000000Z SourceAddress=xxx.xx.x.xx DestinationAddress=xxx.xx.x.xx NATSource=xxx.xx.x.xx NATDestination=xxx.xx.x.xx Rule=allow-business-apps SourceUser="paloaltonetwork\xxxxx" DestinationUser= Application=infoblox-grid VirtualLocation=vsys1 FromZone=ethernet4Zone-test1 ToZone=untrust InboundInterface=unknown OutboundInterface=unknown LogSetting=rs-logging SessionID=952362 RepeatCount=1 SourcePort=5547 DestinationPort=6564 NATSourcePort=8940 NATDestinationPort=16125 Protocol=tcp Action=deny Bytes=652430 BytesSent=231247 BytesReceived=421183 PacketsTotal=2058 SessionStartTime=2021-01-22T21:42:53.000000Z SessionDuration=58 URLCategory=1 SequenceNo=20397927 SourceLocation=BR DestinationLocation=CN PacketsSent=1086 PacketsReceived=972 SessionEndReason=unknown VirtualSystemName= DeviceName=xxxxx ActionSource=unknown SourceUUID= DestinationUUID= IMSI=0 IMEI= ParentSessionID=0 ParentStarttime=2021-01-22T21:42:44.000000Z Tunnel=N/A EndpointAssociationID=7349874591868649490 ChunksTotal=3424 ChunksSent=3119 ChunksReceived=305 RuleUUID=ec14df0b-c845-4435-87a2-d207730f5ae8 HTTP2Connection=547970 LinkChangeCount=0 SDWANPolicyName= LinkSwitches= SDWANCluster= SDWANDeviceType= SDWANClusterType= SDWANSite= DynamicUserGroupName=dynug-3 X-Forwarded-ForIP=xxx.xx.x.xx SourceDeviceCategory=X-Phone SourceDeviceProfile=x-profile SourceDeviceModel=Redmi SourceDeviceVendor=Xiaomi SourceDeviceOSFamily=5 Plus SourceDeviceOSVersion=Android v8.2 SourceDeviceHost=pan-603 SourceDeviceMac=645701225660 DestinationDeviceCategory=X-Phone DestinationDeviceProfile=x-profile DestinationDeviceModel=MI DestinationDeviceVendor=Xiaomi DestinationDeviceOSFamily=A1 DestinationDeviceOSVersion=Android v9.1 DestinationDeviceHost=pan-622 DestinationDeviceMac=207974153661 ContainerID=1873cc5c-0d31 ContainerNameSpace=pns_default ContainerName=pan-dp-77754f4 SourceEDL= DestinationEDL= GPHostID=6060606060 EndpointSerialNumber=xxxxxxxxxxxxxx SourceDynamicAddressGroup= aqua_dag DestinationDynamicAddressGroup= HASessionOwner=session_owner-2 TimeGeneratedHighResolution=2021-01-22T21:43:23.795000Z NSSAINetworkSliceType=a7 NSSAINetworkSliceDifferentiator=5700
The following table identifies the Traffic field names that the Log Forwarding app uses when you forward logs using the EMAIL log format.
EMAIL Name
Query Name
Action
ActionSource
AIFwdError
AITraffic
Application
ApplicationCategory
ApplicationSubcategory
BytesReceived
BytesSent
Bytes
ChunksReceived
ChunksSent
ChunksTotal
ConfigVersion
ContainerID
ApplicationContainer
RepeatCount
CortexDataLakeTenantID
DestinationDeviceCategory
DestinationDeviceClass
DestinationDeviceHost
DestinationDeviceMac
DestinationDeviceModel
DestinationDeviceOS
DestinationDeviceOSFamily
DestinationDeviceOSVersion
DestinationDeviceProfile
DestinationDeviceVendor
DestinationDynamicAddressGroup
DestinationEDL
DestinationAddress
DestinationLocation
DestinationPort
DestinationUser
DestinationUserDomain
DestinationUserName
DestinationUserUUID
DestinationUUID
DGHierarchyLevel1
DGHierarchyLevel2
DGHierarchyLevel3
DGHierarchyLevel4
DynamicUserGroupName
EndpointSerialNumber
EndpointAssociationID
FlowType
FromZone
HASessionOwner
GPHostID
HTTP2Connection
InboundInterface
InboundInterfaceDetailsPort
InboundInterfaceDetailsSlot
InboundInterfaceDetailsType
InboundInterfaceDetailsUnit
CaptivePortal
IsClienttoServer
IsContainer
IsDecryptMirror
IsDecrypted
IsDecryptedPayloadForward
IsDecryptedLog
IsDuplicateLog
IsEncrypted
LogExported
LogForwarded
IsIPV6
IsInspectionBeforeSession
IsMptcpOn
NAT
IsNonStandardDestinationPort
IsOffloaded
IsPacketCapture
IsPhishing
IsPrismaNetwork
IsPrismaUsers
IsProxy
IsReconExcluded
IsSaaSApplication
IsServertoClient
IsSourceXForwarded
IsSystemReturn
IsTransaction
IsTunnelInspected
IsURLDenied
K8SClusterID
LinkChangeCount
LinkSwitches
Location
LogSetting
LogSource
LogSourceGroupID
DeviceSN
DeviceName
LogSourceTimeZoneOffset
TimeReceived
LogType
IMEI
NATDestination
NATDestinationPort
NATSource
NATSourcePort
NonStandardDestinationPort
NSSAINetworkSliceDifferentiator
NSSAINetworkSliceType
OutboundInterface
OutboundInterfaceDetailsPort
OutboundInterfaceDetailsSlot
OutboundInterfaceDetailsType
OutboundInterfaceDetailsUnit
PacketsReceived
PacketsSent
PacketsTotal
PanoramaSN
ParentSessionID
ParentStarttime
PlatformType
ContainerName
ContainerNameSpace
SDWANPolicyName
Protocol
ApplicationRisk
Rule
RuleUUID
SanctionedStateOfApp
SDWANFECRatio
SDWANCluster
SDWANClusterType
SDWANDeviceType
SDWANSite
SequenceNo
SessionOwnerMidx
SessionEndReason
SessionID
SessionStartTime
SessionTracker
SourceDeviceCategory
SourceDeviceClass
SourceDeviceHost
SourceDeviceMac
SourceDeviceModel
SourceDeviceOS
SourceDeviceOSFamily
SourceDeviceOSVersion
SourceDeviceProfile
SourceDeviceVendor
SourceDynamicAddressGroup
SourceEDL
SourceAddress
SourceLocation
SourcePort
SourceUser
SourceUserDomain
SourceUserName
SourceUserUUID
SourceUUID
Subtype
ApplicationTechnology
TimeGenerated
TimeGeneratedHighResolution
ToZone
SessionDuration
Tunnel
TunneledApplication
IMSI
URLCategory
Users
VendorName
VirtualLocation
VirtualSystemID
VirtualSystemName
X-Forwarded-ForIP