Strata Logging Service
GlobalProtect EMAIL Fields
Table of Contents
Expand All
|
Collapse All
Strata Logging Service Docs
GlobalProtect EMAIL Fields
Example GlobalProtect log in EMAIL:
TimeReceived=2021-02-23T02:44:27.000000Z DeviceSN=xxxxxxxxxxxxx LogType=GLOBALPROTECT LogSubtype=globalprotect ConfigVersion= SourceUserUUID= TenantID=xxxxxxxxxxxxx VendorName=Palo Alto Networks VirtualSystemName= SourceUserName=xxxxx SourceUserDomain=paloaltonetwork LogSourceTimeZoneOffset= Gateway= DGHierarchyLevel1=20 DGHierarchyLevel2=0 DGHierarchyLevel3=0 DGHierarchyLevel4=0 DeviceName=PA-VM EventID=309 IsDuplicateLog=false IsPrismaNetworks=false IsPrismaUsers=false LogExported=false LogSource=firewall VirtualSystemID=1 TimeGenerated=2021-02-23T02:44:27.000000Z VirtualSystem=vsys1 EventIDValue=satellite-gateway-update-route Stage=connected AuthMethod=RADIUS TunnelType=ipsec SourceUserName0="paloaltonetwork\\xxxxx" SourceRegion=ET EndpointDeviceName=machine_name2 PublicIPv4=xxx.xx.x.xx PublicIPv6=xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx PrivateIPv4=xxx.xx.x.xx PrivateIPv6=xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx HostID=e667947f-d92e-4815-9222-89438203bc2b EndpointSN=serialno_list-1 GlobalProtectClientVersion=3.0.9 EndpointOSType=Intel Mac OS EndpointOSVersion=9.3.5 CountOfRepeats=16777216 QuarantineReason=Malicious Traffic ConnectionError=Client cert not present Description=opaque_list-1 EventStatus=failure GlobalProtectGatewayLocation=San Francisco LoginDuration=1 ConnectionMethod=connect_method_list-1 Portal=portal_list-2 SequenceNo=34401910 TimeGeneratedHighResolution=2019-07-25T23:30:12.000000Z GatewaySelectionType= SSLResponseTime= GatewayPriority= AttemptedGateways=
The following table identifies the GlobalProtect field names that the Log Forwarding app
uses when you forward logs using the EMAIL log format.
EMAIL Name
|
Query Name
|
---|---|
AttemptedGateways
| |
AuthMethod
| |
ConfigVersion
| |
ConnectionMethod
| |
ConnectionErrorID
| |
ConnectionError
| |
CountOfRepeats
| |
TenantID
| |
DGHierarchyLevel1
| |
DGHierarchyLevel2
| |
DGHierarchyLevel3
| |
DGHierarchyLevel4
| |
EndpointDeviceName
| |
GlobalProtectClientVersion
| |
EndpointOSType
| |
EndpointOSVersion
| |
EndpointSN
| |
EventIDValue
| |
Gateway
| |
GatewayPriority
| |
GatewaySelectionType
| |
GlobalProtectGatewayLocation
| |
HostID
| |
IsDuplicateLog
| |
LogExported
| |
LogForwarded
| |
IsPrismaNetworks
| |
IsPrismaUsers
| |
LogSource
| |
LogSourceGroupID
| |
DeviceSN
| |
DeviceName
| |
LogSourceTimeZoneOffset
| |
TimeReceived
| |
LogType
| |
LoginDuration
| |
Description
| |
PanoramaSN
| |
PlatformType
| |
Portal
| |
PrivateIPv4
| |
PrivateIPv6
| |
ProjectName
| |
PublicIPv4
| |
PublicIPv6
| |
QuarantineReason
| |
SequenceNo
| |
SourceRegion
| |
SourceUserName
| |
SourceUserDomain
| |
SourceUserName
| |
SourceUserUUID
| |
SSLResponseTime
| |
Stage
| |
EventStatus
| |
LogSubtype
| |
TimeGenerated
| |
TimeGeneratedHighResolution
| |
TunnelType
| |
VendorName
| |
VirtualSystem
| |
VirtualSystemID
| |
VirtualSystemName
|