SCTP EMAIL Fields
Focus
Focus
Strata Logging Service

SCTP EMAIL Fields

Table of Contents

SCTP EMAIL Fields

Example SCTP log in EMAIL:
TimeReceived=2021-02-23T02:45:00.000000Z DeviceSN=xxxxxxxxxxxxx LogType=SCTP Subtype= ConfigVersion= TimeGenerated=2021-02-23T02:45:00.000000Z SourceIP=xxxxxxxxxxxx DestinationIP=xxx.xx.x.xx NATSource=xxx.xx.x.xx NATDestination=xxx.xx.x.xx Rule=allow-business-apps SourceUser="paloaltonetwork\xxxxx" DestinationUser=paloaltonetworkxxxxx Application=panorama VirtualLocation=vsys1 FromZone=corporate ToZone=untrust InboundInterface=ethernet1/1 OutboundInterface=ethernet1/2 LogSetting=test SessionID=391582 RepeatCount=1 SourcePort=3033 DestinationPort=5496 NATSourcePort=26714 NATDestinationPort=15054 Protocol=tcp Action=alert DGHierarchyLevel1=12 DGHierarchyLevel2=0 DGHierarchyLevel3=0 DGHierarchyLevel4=0 VirtualSystemName= DeviceName=PA-5220 SequenceNo=6711379990526573312 EndpointAssociationID=2086888838 PayloadProtocolID=-1 VendorSeverity=Critical SctpChunkType=9 SCTPEventType=Kerberos single sign-on failed EventCode=3 VerificationTag1=0x3bae3042 VerificationTag2=0x1911015e SctpCauseCode=0 DiamAppID=-1 DiameterCommandCode=-1 DiamAvpCode=0 StreamID=0 AssocationEndReason= MapAppCode=0 SccpCallingSSN=0 SccpCallingGt= SctpFilter= ChunksTotal=0 ChunksSent=0 ChunksReceived=0 PacketsTotal=0 PacketsSent=0 PacketsReceived=0 RuleUUID= ContainerID= ContainerNameSpace= ContainerName= SourceEDL= DestinationEDL= SourceDynamicAddressGroup= DestinationDynamicAddressGroup= TimeGeneratedHighResolution=2019-07-25T23:30:12.000000Z
The following table identifies the SCTP field names that the Log Forwarding app uses when you forward logs using the EMAIL log format.
EMAIL Name
Query Name
Action
Application
AssocationEndReason
ChunksReceived
ChunksSent
ChunksTotal
ConfigVersion
ContainerID
ContentVersion
RepeatCount
CortexDataLakeTenantID
DestinationDeviceClass
DestinationDeviceMac
DestinationDeviceModel
DestinationDeviceOS
DestinationDeviceVendor
DestinationDynamicAddressGroup
DestinationEDL
DestinationIP
DestinationLocation
DestinationPort
DestinationUser
DestinationUserDomain
DestinationUserName
DestinationUserUUID
DestinationUUID
DGHierarchyLevel1
DGHierarchyLevel2
DGHierarchyLevel3
DGHierarchyLevel4
DiamAppID
DiamAvpCode
DiameterCommandCode
EndpointAssociationID
EventCode
SCTPEventType
FromZone
InboundInterface
InboundInterfaceDetailsPort
InboundInterfaceDetailsSlot
InboundInterfaceDetailsType
InboundInterfaceDetailsUnit
CaptivePortal
IsClienttoServer
IsContainer
IsDecryptMirror
IsDecryptedPayloadForward
IsDecryptedLog
IsDuplicateLog
LogExported
LogForwarded
IsIPV6
IsInspectionBeforeSession
IsMptcpOn
NAT
IsNonStandardDestinationPort
IsPacketCapture
IsPhishing
IsPrismaNetwork
IsPrismaUsers
IsProxy
IsReconExcluded
IsServertoClient
IsSourceXForwarded
IsSystemReturn
IsTransaction
IsTunnelInspected
IsURLDenied
LogSetting
LogSource
LogSourceGroupID
DeviceSN
DeviceName
LogSourceTimeZoneOffset
TimeReceived
LogType
MapAppCode
NATDestination
NATDestinationPort
NATSource
NATSourcePort
OutboundInterface
OutboundInterfaceDetailsPort
OutboundInterfaceDetailsSlot
OutboundInterfaceDetailsType
OutboundInterfaceDetailsUnit
PacketsReceived
PacketsSent
PacketsTotal
PanoramaSN
PayloadProtocolID
PlatformType
ContainerName
ContainerNameSpace
Protocol
Rule
RuleUUID
SccpCallingGt
SccpCallingSSN
SctpCauseCode
SctpChunkType
SctpFilter
SequenceNo
SessionOwnerMidx
SessionEndReason
SessionID
SessionTracker
Severity
SourceDeviceClass
SourceDeviceMac
SourceDeviceModel
SourceDeviceOS
SourceDeviceVendor
SourceDynamicAddressGroup
SourceEDL
SourceIP
SourceLocation
SourcePort
SourceUser
SourceUserDomain
SourceUserName
SourceUserUUID
SourceUUID
StreamID
Subtype
TimeGenerated
TimeGeneratedHighResolution
ToZone
Tunnel
VendorName
VendorSeverity
VerificationTag1
VerificationTag2
VirtualLocation
VirtualSystemID
VirtualSystemName