UserID EMAIL Fields
Focus
Focus
Strata Logging Service

UserID EMAIL Fields

Table of Contents

UserID EMAIL Fields

Example UserID log in EMAIL:
TimeReceived=2021-02-23T02:43:57.000000Z DeviceSN=xxxxxxxxxxxxx LogType=USERID Subtype=logout ConfigVersion= TimeGenerated=2021-02-23T02:43:57.000000Z VirtualLocation=vsys1 SourceIP=xxxxxxxxxxxx User="paloaltonetworks\xxxxx" MappingDataSourceName=fake-data-source-169 EventID=0 CountofRepeats=1 MappingTimeout=3531 SourcePort=21015 DestinationPort=49760 MappingDataSource=probing MappingDataSourceType=netbios_probing SequenceNo=6711379990526558750 DGHierarchyLevel1=12 DGHierarchyLevel2=0 DGHierarchyLevel3=0 DGHierarchyLevel4=0 VirtualSystemName= DeviceName=PA-5220 VirtualSystemID=1 MFAFactorType=xxxxx AuthCompletionTime=2019-07-09T18:15:44.000000Z AuthFactorNo=3 UGFlags=0x100 UserIdentifiedBySource=xxxxxxxxxxxxxx Tag= TimeGeneratedHighResolution=2019-07-25T23:30:12.000000Z
The following table identifies the UserID field names that the Log Forwarding app uses when you forward logs using the EMAIL log format.
EMAIL Name
Query Name
AuthCompletionTime
AuthFactorNo
AuthenticatedUserDomain
AuthenticatedUserName
AuthenticatedUserUUID
ConfigVersion
CountofRepeats
CortexDataLakeTenantID
DestinationPort
DGHierarchyLevel1
DGHierarchyLevel2
DGHierarchyLevel3
DGHierarchyLevel4
EventID
IsDuplicateLog
IsDuplicateUser
LogExported
LogForwarded
IsPrismaNetworks
IsPrismaUsers
LogSource
LogSourceGroupID
DeviceSN
DeviceName
LogSourceTimeZoneOffset
TimeReceived
LogType
MappingDataSource
MappingDataSourceName
MappingDataSourceType
MappingTimeout
MFAFactorType
PanoramaSN
PlatformType
SequenceNo
SourceIP
SourcePort
Subtype
Tag
TimeGenerated
TimeGeneratedHighResolution
UGFlags
User
UserGroupFound
UserIdentifiedBySource
VendorName
VirtualLocation
VirtualSystemID
VirtualSystemName