Skip to main content
Skip table of contents

Configuration Messages

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event
Configuration MessagesBase RuleConfigurationConfiguration Modified : System

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

N/AN/AN/AdeviceVendor
N/AN/AN/AdeviceProduct
N/AN/AN/AVersion
N/A<vmid>Text/StringLogType
N/AN/AN/ASubType
N/A<severity>NumberdeviceSeverity
ProfileTokenN/AN/AN/A
dtzN/AN/AN/A
rtN/AN/ATime the log was received in Cortex Data Lake. This is populated by the platform.
deviceExternalId<serialnumber>Text/String/NumberID that uniquely identifies the source of the log. If the source is a firewall, this is its serial number. If the source is TMS, this is the trapsID.
PanOSEventTimeN/AN/ATime when the log was generated on the firewall's data plane. This string contains a timestamp value that is the number of microseconds since the Unix epoch.
dusernameN/AN/AUsername of the administrator performing the configuration.
dntdom<domainorigin>Text/StringDomain to which the admin user belongs.
duid<login>Text/StringThe admin user's unique ID.
PanOSEventDetailsN/AN/AIdentifies the firewall's configuration prior to and immediately after the configuration change.
PanOSIsDuplicateLogN/AN/AIndicates whether this log data is available in multiple locations, such as from Cortex Data Lake as well as from an on-premise log collector.
PanOSIsPrismaNetworkN/AN/AIf set to 1, the log was generated on a cloud-based firewall. If 0, the firewall was running on-premise.
PanOSIsPrismaUsersN/AN/AIf set to 1, the log record was generated using a cloud-based GlobalProtect instance. If 0, GlobalProtect was hosted on-premise.
cat<vendorinfo>Text/StringThe log category.
PanOSLogExportedN/AN/AIndicates if this log was exported from the firewall using the firewall's log export function.
PanOSLogSourceN/AN/AIdentifies the origin of the data. That is, the system that produced the data.
PanOSLogSourceTimeZoneOffsetN/AN/ATime Zone offset from GMT of the source of the log.
PanOSSeverityN/AN/ASeverity as defined by the platform.
PanOSTenantIDN/AN/AThe ID that uniquely identifies the Cortex Data Lake instance which received this log record.
PanOSVirtualSystemIDN/AN/AA unique identifier for a virtual system on a Palo Alto Networks firewall.
src<sip>IP AddressHostname or IP address of the client.
cs3N/AN/AString representation of the unique identifier for a virtual system on a Palo Alto Networks firewall.
cs3LabelN/AN/AN/A
act<command>Text/StringName of the system event.

duser0 or dusername0

<account>Text/StringName of the user who created the configuration change.
destinationServiceName<process>Text/StringClient used by the administrator who is performing the configuration.
PanOSEventResult<result>Text/StringResult of the configuration action.
msg<object>Text/StringThe path of the configuration command issued.
externalIdN/AN/AThe log entry identifier, which is incremented sequentially. Each log type has a unique number space.
PanOSDGHierarchyLevel1N/AN/AA sequence of identification numbers that indicate the device group’s location within a device group hierarchy.
PanOSDGHierarchyLevel2N/AN/AA sequence of identification numbers that indicate the device group’s location within a device group hierarchy.
PanOSDGHierarchyLevel3N/AN/AA sequence of identification numbers that indicate the device group’s location within a device group hierarchy.
PanOSDGHierarchyLevel4N/AN/AA sequence of identification numbers that indicate the device group’s location within a device group hierarchy.
PanOSVirtualSystemNameN/AN/AThe name of the virtual system associated with the network traffic.
dvchostN/AN/AName of the source of the log. If the source is a firewall, this is the device_name value. If the source is TMS, this is either the customer or tenant name.
PanOSEventDescriptionN/AN/ADescription of the system event. If the source is a firewall, this is opaque. If the source is TMS, this is the msgTextEn field.
PanOSTimeGeneratedHighResolutionN/AN/ATime the log was generated in data plane with millisec granularity in format YYYY-MM-DDTHH.
PanOSVendorSeverityN/AN/ASeverity associated with the event.
PanOSTemplateN/AN/AThe ID and name of the template/template stack to which the firewall belonged where the log was generated.
PanOSConfigVersionN/AN/AConfig version converted to string represented as major.minor.patch.build in value and as hex in ID.
PanOSDeviceGroupN/AN/AThe ID and the name of the device group the firewall is in.
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.