Strata Logging Service
SCTP EMAIL Fields
Table of Contents
Expand All
|
Collapse All
Strata Logging Service Docs
SCTP EMAIL Fields
Example SCTP log in EMAIL:
TimeReceived=2021-02-23T02:45:00.000000Z DeviceSN=xxxxxxxxxxxxx LogType=SCTP Subtype= ConfigVersion= TimeGenerated=2021-02-23T02:45:00.000000Z SourceIP=xxxxxxxxxxxx DestinationIP=xxx.xx.x.xx NATSource=xxx.xx.x.xx NATDestination=xxx.xx.x.xx Rule=allow-business-apps SourceUser="paloaltonetwork\xxxxx" DestinationUser=paloaltonetworkxxxxx Application=panorama VirtualLocation=vsys1 FromZone=corporate ToZone=untrust InboundInterface=ethernet1/1 OutboundInterface=ethernet1/2 LogSetting=test SessionID=391582 RepeatCount=1 SourcePort=3033 DestinationPort=5496 NATSourcePort=26714 NATDestinationPort=15054 Protocol=tcp Action=alert DGHierarchyLevel1=12 DGHierarchyLevel2=0 DGHierarchyLevel3=0 DGHierarchyLevel4=0 VirtualSystemName= DeviceName=PA-5220 SequenceNo=6711379990526573312 EndpointAssociationID=2086888838 PayloadProtocolID=-1 VendorSeverity=Critical SctpChunkType=9 SCTPEventType=Kerberos single sign-on failed EventCode=3 VerificationTag1=0x3bae3042 VerificationTag2=0x1911015e SctpCauseCode=0 DiamAppID=-1 DiameterCommandCode=-1 DiamAvpCode=0 StreamID=0 AssocationEndReason= MapAppCode=0 SccpCallingSSN=0 SccpCallingGt= SctpFilter= ChunksTotal=0 ChunksSent=0 ChunksReceived=0 PacketsTotal=0 PacketsSent=0 PacketsReceived=0 RuleUUID= ContainerID= ContainerNameSpace= ContainerName= SourceEDL= DestinationEDL= SourceDynamicAddressGroup= DestinationDynamicAddressGroup= TimeGeneratedHighResolution=2019-07-25T23:30:12.000000Z
The following table identifies the SCTP field names that the Log Forwarding app
uses when you forward logs using the EMAIL log format.
EMAIL Name
|
Query Name
|
---|---|
Action
| |
Application
| |
AssocationEndReason
| |
ChunksReceived
| |
ChunksSent
| |
ChunksTotal
| |
ConfigVersion
| |
ContainerID
| |
ContentVersion
| |
RepeatCount
| |
CortexDataLakeTenantID
| |
DestinationDeviceClass
| |
DestinationDeviceMac
| |
DestinationDeviceModel
| |
DestinationDeviceOS
| |
DestinationDeviceVendor
| |
DestinationDynamicAddressGroup
| |
DestinationEDL
| |
DestinationIP
| |
DestinationLocation
| |
DestinationPort
| |
DestinationUser
| |
DestinationUserDomain
| |
DestinationUserName
| |
DestinationUserUUID
| |
DestinationUUID
| |
DGHierarchyLevel1
| |
DGHierarchyLevel2
| |
DGHierarchyLevel3
| |
DGHierarchyLevel4
| |
DiamAppID
| |
DiamAvpCode
| |
DiameterCommandCode
| |
EndpointAssociationID
| |
EventCode
| |
SCTPEventType
| |
FromZone
| |
InboundInterface
| |
InboundInterfaceDetailsPort
| |
InboundInterfaceDetailsSlot
| |
InboundInterfaceDetailsType
| |
InboundInterfaceDetailsUnit
| |
CaptivePortal
| |
IsClienttoServer
| |
IsContainer
| |
IsDecryptMirror
| |
IsDecryptedPayloadForward
| |
IsDecryptedLog
| |
IsDuplicateLog
| |
LogExported
| |
LogForwarded
| |
IsIPV6
| |
IsInspectionBeforeSession
| |
IsMptcpOn
| |
NAT
| |
IsNonStandardDestinationPort
| |
IsPacketCapture
| |
IsPhishing
| |
IsPrismaNetwork
| |
IsPrismaUsers
| |
IsProxy
| |
IsReconExcluded
| |
IsServertoClient
| |
IsSourceXForwarded
| |
IsSystemReturn
| |
IsTransaction
| |
IsTunnelInspected
| |
IsURLDenied
| |
LogSetting
| |
LogSource
| |
LogSourceGroupID
| |
DeviceSN
| |
DeviceName
| |
LogSourceTimeZoneOffset
| |
TimeReceived
| |
LogType
| |
MapAppCode
| |
NATDestination
| |
NATDestinationPort
| |
NATSource
| |
NATSourcePort
| |
OutboundInterface
| |
OutboundInterfaceDetailsPort
| |
OutboundInterfaceDetailsSlot
| |
OutboundInterfaceDetailsType
| |
OutboundInterfaceDetailsUnit
| |
PacketsReceived
| |
PacketsSent
| |
PacketsTotal
| |
PanoramaSN
| |
PayloadProtocolID
| |
PlatformType
| |
ContainerName
| |
ContainerNameSpace
| |
Protocol
| |
Rule
| |
RuleUUID
| |
SccpCallingGt
| |
SccpCallingSSN
| |
SctpCauseCode
| |
SctpChunkType
| |
SctpFilter
| |
SequenceNo
| |
SessionOwnerMidx
| |
SessionEndReason
| |
SessionID
| |
SessionTracker
| |
Severity
| |
SourceDeviceClass
| |
SourceDeviceMac
| |
SourceDeviceModel
| |
SourceDeviceOS
| |
SourceDeviceVendor
| |
SourceDynamicAddressGroup
| |
SourceEDL
| |
SourceIP
| |
SourceLocation
| |
SourcePort
| |
SourceUser
| |
SourceUserDomain
| |
SourceUserName
| |
SourceUserUUID
| |
SourceUUID
| |
StreamID
| |
Subtype
| |
TimeGenerated
| |
TimeGeneratedHighResolution
| |
ToZone
| |
Tunnel
| |
VendorName
| |
VendorSeverity
| |
VerificationTag1
| |
VerificationTag2
| |
VirtualLocation
| |
VirtualSystemID
| |
VirtualSystemName
|