Skip to main content
Skip table of contents

Authentication Event

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event
Authentication EventBase RuleOther AuditGeneral Authentication Event

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

 N/A N/AN/AdeviceVendor
N/A N/A N/AdeviceProduct
N/A  N/AN/AVersion
 N/A<vmid>Text/StringLogType
N/A  N/AN/ASubType
 N/A<severity>NumberdeviceSeverity
ProfileToken N/AN/A N/A
dtzN/A N/A N/A
rt N/AN/ATime the log was received in Cortex Data Lake. This string contains a timestamp value that is the number of microseconds since the Unix epoch.
deviceExternalId<serialnumber>Text/String/NumberID that uniquely identifies the source of the log. That is, the serial number of the firewall that generated the log.
PanOSConfigVersionN/A N/AVersion number of the firewall operating system that wrote this log record.
PanOSAuthenticatedUserDomain<domainorigin>Text/StringDomain to which the user who is being authenticated belongs.
PanOSAuthenticatedUserName<login>Text/StringName of the user who is being authenticated.
PanOSAuthenticatedUserUUID N/AN/AUnique identifier assigned to the user who is being authenticated.
PanOSClientTypeName N/AN/AType of client used to complete authentication.
PanOSCortexDataLakeTenantIDN/AN/AThe ID that uniquely identifies the Cortex Data Lake instance which received this log record.
PanOSIsDuplicateLogN/AN/AIndicates whether this log data is available in multiple locations, such as from the Logging Service and also from an on-premise log collector.
PanOSIsPrismaNetworksN/AN/AInternal-use field. If set to 1, the log was generated on a cloud-based firewall. If 0, the firewall was running on-premise.
PanOSIsPrismaUsersN/AN/AInternal use field. If set to 1, the log record was generated using a cloud-based GlobalProtect instance. If 0, GlobalProtect was hosted on-premise.
PanOSLogExportedN/AN/AIndicates if this log was exported from the firewall using the firewall's log export function.
PanOSLogForwardedN/AN/AInternal-use field that indicates if the log is being forwarded.
PanOSLogSourceN/AN/AIdentifies the origin of the data. That is, the system that produced the data.
PanOSLogSourceTimeZoneOffsetN/AN/ATime Zone offset from GMT of the source of the log.
PanOSRuleN/AN/AName of the security policy rule that the network traffic matched.
startN/AN/ATime when the log was generated on the firewall's data plane. This string contains a timestamp value that is the number of microseconds since the Unix epoch.
cs3N/AN/AString representation of the unique identifier for a virtual system on a Palo Alto Networks firewall.
cs3LabelN/AN/A N/A
c6a2<sip>IP AddressSource IPv6 Address
c6a2Label N/AN/A N/A
c6a3<dip>IP AddressDestination IPv6 Address
c6a3Label N/AN/A N/A
dusernameN/A N/AEnd user being authenticated.
cs2N/A N/ANormalized version of the username being authenticated (such as appending a domain name to the username).
cs2LabelN/A N/A N/A
fname N/AN/AName of the object associated with the system event.
cs4<policy>Text/StringPolicy invoked for authentication before allowing access to a protected resource.
cs4LabelN/AN/A N/A
cntN/AN/ANumber of sessions with same Source IP, Destination IP, Application, and Content/Threat Type seen for the summary interval.
cn2N/AN/AUnique ID given across primary authentication and additional (multi-factor) authentication.
cn2LabelN/AN/A N/A
PanOSMFAVendorN/AN/AVendor providing additional factor authentication.
cs6N/AN/ALog forwarding profile name that was applied to the session. This name was defined by the firewall's administrator.
cs6LabelN/AN/A N/A
cs1N/AN/AAuthentication server used for authentication.
cs1LabelN/AN/A N/A
PanOSAuthenticationDescription N/AN/AAdditional authentication information.
cs5N/A N/AType of client used to complete authentication (such as authentication portal).
cs5LabelN/A N/A N/A
msg<result>Text/StringThe authentication event that caused the firewall to create this log record.
cn1N/A N/AIndicates the use of primary authentication (1) or additional factors (2, 3).
cn1Label N/AN/A N/A
externalIdN/A N/AThe log entry identifier, which is incremented sequentially. Each log type has a unique number space.
PanOSDGHierarchyLevel1N/A N/AA sequence of identification numbers that indicate the device group’s location within a device group hierarchy.
PanOSDGHierarchyLevel2N/A N/AA sequence of identification numbers that indicate the device group’s location within a device group hierarchy.
PanOSDGHierarchyLevel3 N/AN/AA sequence of identification numbers that indicate the device group’s location within a device group hierarchy.
PanOSDGHierarchyLevel4N/A N/AA sequence of identification numbers that indicate the device group’s location within a device group hierarchy.
PanOSVirtualSystemNameN/A N/AThe name of the virtual system associated with the network traffic.
dvchostN/A N/AName of the source of the log. That is, the hostname of the firewall that logged the network traffic.
PanOSVirtualSystemIDN/A N/AA unique identifier for a virtual system on a Palo Alto Networks firewall.
PanOSAuthenticationProtocol<protname>Text/StringIndicates the authentication protocol used by the server. For example, PEAP with GTC.
PanOSRuleUUID N/AN/AUnique identifier for the security policy rule that the network traffic matched.
PanOSTimeGeneratedHighResolution N/AN/ATime the log was generated in data plane with millisec granularity in format YYYY-MM-DDTHH
PanOSSourceDeviceCategoryN/A N/ACategory of the device from which the session originated.
PanOSSourceDeviceProfileN/A N/AProfile of the device from which the session originated.
PanOSSourceDeviceModel N/AN/AModel of the device from which the session originated.
PanOSSourceDeviceVendorN/A N/AVendor of the device from which the session originated.
PanOSSourceDeviceOSFamilyN/A N/AOS family of the device from which the session originated.
PanOSSourceDeviceOSVersion N/AN/AOS version of the device from which the session originated.
PanOSSourceDeviceHost<sname>Text/StringHostname of the device from which the session originated.
PanOSSourceDeviceMac<smac>Text/StringMAC Address of the device from which the session originated.
PanOSAuthCacheServiceRegionN/A N/ARegion where the service is deployed.
PanOSUserAgentString<useragent>Text/StringThe User Agent field specifies the web browser that the user used to access the URL.
PanOSSessionID<session>Text/StringIdentifies the firewall's internal identifier for a specific network session.
src<sip>IP AddressOriginal source IP address.
dst<dip>IP AddressOriginal destination IP address.
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.