Oct 13 01:23:58 gke-standard-cluster-2-pool-1-6ea9f13a-g2z7 498 <142>1 2020-10-13T01:23:58.167Z stream-logfwd20-156653024-10121421-eq28-harness-16kn logforwarder - panwlogs - 1,2020-10-13T01:23:50.000000Z,007051000113358,USERID,login,10.0,2020-10-13T01:23:34.000000Z,vsys1,::c28:7141:ffff:0,"xxxxx\xxxxx o"xxxxxxxxxx"'"xxxxxxxxxx"test",fake-data-source-95,1694498816,16777216,-1694302208,63502,60246,server_session_monitor,exchange_server,551324,-9223372036854775808,0,0,0,0,,PA-VM,1,xxxxx,2050-04-13T10:41:35.000000Z,1,64,xxxxxxxxxxxxxx,,2020-10-13T01:23:35.350000Z
The fields are identified in the default order that they appear in each log
line.
HEADER,
log_time,
log_source_id,
log_type.value,
sub_type.value,
config_version.value,
time_generated,
vsys,
source_ip.value,
user,
mapping_data_source_name,
event_id,
count_of_repeats,
mapping_timeout,
source_port,
dest_port,
mapping_data_source.value,
mapping_data_source_type.value,
sequence_no,
action_flags,
dg_hier_level_1,
dg_hier_level_2,
dg_hier_level_3,
dg_hier_level_4,
vsys_name,
log_source_name,
vsys_id,
mfa_factor_type,
auth_completion_time,
auth_factor_num,
ug_flags,
user_identified_by_source_as,
tag_name,
time_generated_high_res