Strata Logging Service
UserID EMAIL Fields
Table of Contents
Expand All
|
Collapse All
Strata Logging Service Docs
UserID EMAIL Fields
Example UserID log in EMAIL:
TimeReceived=2021-02-23T02:43:57.000000Z DeviceSN=xxxxxxxxxxxxx LogType=USERID Subtype=logout ConfigVersion= TimeGenerated=2021-02-23T02:43:57.000000Z VirtualLocation=vsys1 SourceIP=xxxxxxxxxxxx User="paloaltonetworks\xxxxx" MappingDataSourceName=fake-data-source-169 EventID=0 CountofRepeats=1 MappingTimeout=3531 SourcePort=21015 DestinationPort=49760 MappingDataSource=probing MappingDataSourceType=netbios_probing SequenceNo=6711379990526558750 DGHierarchyLevel1=12 DGHierarchyLevel2=0 DGHierarchyLevel3=0 DGHierarchyLevel4=0 VirtualSystemName= DeviceName=PA-5220 VirtualSystemID=1 MFAFactorType=xxxxx AuthCompletionTime=2019-07-09T18:15:44.000000Z AuthFactorNo=3 UGFlags=0x100 UserIdentifiedBySource=xxxxxxxxxxxxxx Tag= TimeGeneratedHighResolution=2019-07-25T23:30:12.000000Z
The following table identifies the UserID field names that the Log Forwarding app
uses when you forward logs using the EMAIL log format.
EMAIL Name
|
Query Name
|
---|---|
AuthCompletionTime
| |
AuthFactorNo
| |
AuthenticatedUserDomain
| |
AuthenticatedUserName
| |
AuthenticatedUserUUID
| |
ConfigVersion
| |
CountofRepeats
| |
CortexDataLakeTenantID
| |
DestinationPort
| |
DGHierarchyLevel1
| |
DGHierarchyLevel2
| |
DGHierarchyLevel3
| |
DGHierarchyLevel4
| |
EventID
| |
IsDuplicateLog
| |
IsDuplicateUser
| |
LogExported
| |
LogForwarded
| |
IsPrismaNetworks
| |
IsPrismaUsers
| |
LogSource
| |
LogSourceGroupID
| |
DeviceSN
| |
DeviceName
| |
LogSourceTimeZoneOffset
| |
TimeReceived
| |
LogType
| |
MappingDataSource
| |
MappingDataSourceName
| |
MappingDataSourceType
| |
MappingTimeout
| |
MFAFactorType
| |
PanoramaSN
| |
PlatformType
| |
SequenceNo
| |
SourceIP
| |
SourcePort
| |
Subtype
| |
Tag
| |
TimeGenerated
| |
TimeGeneratedHighResolution
| |
UGFlags
| |
User
| |
UserGroupFound
| |
UserIdentifiedBySource
| |
VendorName
| |
VirtualLocation
| |
VirtualSystemID
| |
VirtualSystemName
|