Skip to main content
Skip table of contents

Decryption Event Messages

Vendor Documentation

Classification

Rule NameRule TypeClassificationCommon Event
Decryption Event MessagesBase RuleInformationSession Information

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm SchemaData TypeSchema Description
N/A N/AN/AdeviceVendor
N/A  N/AN/AdeviceProduct
N/A  N/AN/AVersion
N/A<vmid>Text/StringLogType
N/A <command>Text/StringSubType
N/A <severity>NumberdeviceSeverity
ProfileToken N/AN/A N/A
dtz N/AN/A N/A
rt N/AN/ATime the log was received in Cortex Data Lake. This string contains a timestamp value that is the number of microseconds since the Unix epoch.
PanOSDeviceSNN/A N/AID that uniquely identifies the source of the log. That is, the serial number of the firewall that generated the log.
PanOSConfigVersionN/A N/AVersion number of the firewall operating system that wrote this log record, in major.minor format.
startN/AN/ATime when the log was generated on the firewall's data plane. This string contains a timestamp value that is the number of microseconds since the Unix epoch.
src<sip>IP AddressOriginal source IP address.
dst<dip>IP AddressOriginal destination IP address.
sourceTranslatedAddress<snatip>IP AddressIf source NAT was performed, the post-NAT source IP address.
destinationTranslatedAddress<dnatip>IP AddressIf destination NAT was performed, the post-NAT destination IP address.
cs1N/A N/AName of the security policy rule that the network traffic matched.
cs1LabelN/AN/A N/A
susername<login>Text/StringThe username that initiated the network traffic.
dusername<account>Text/StringThe username to which the network traffic was destined.
appN/A N/AApplication associated with the network traffic.
cs3N/AN/AString representation of the unique identifier for a virtual system on a Palo Alto Networks firewall.
cs3LabelN/A N/A N/A
cs4 N/AN/AThe networking zone from which the traffic originated.
cs4Label N/AN/A N/A
cs5 N/AN/ANetworking zone to which the traffic was sent.
cs5Label N/AN/A N/A
deviceInboundInterface<sinterface>Text/StringInterface from which the network traffic was sourced.
deviceOutboundInterface<dinterface>Text/StringInterface to which the network traffic was destined.
cs6 N/AN/ALog forwarding profile name that was applied to the session. This name was defined by the firewall's administrator.
cs6Label N/AN/A N/A
PanOSTimeReceivedManagementPlaneN/A N/ATime the log was received in the management plane in format YYYY-MM-DDTHH:MM:SS[.DDDDDD]Z.
cn1 N/AN/AIdentifies the firewall's internal identifier for a specific network session.
cn1LabelN/A N/A N/A
cnt N/AN/ANumber of sessions with same Source IP, Destination IP, Application, and Content/Threat Type seen for the summary interval.
spt<sport>NumberSource port utilized by the session.
dpt<dport>NumberNetwork traffic's destination port. If this value is 0, then the app is using its standard port.
sourceTranslatedPort<snatport>NumberPost-NAT source port.
destinationTranslatedPort<dnatport>NumberPost-NAT destination port.
proto<protname>Text/StringIP protocol associated with the session.
act<action>Text/StringIdentifies the action that the firewall took for the network traffic.
PanOSTunnel N/AN/AType of tunnel.
PanOSSourceUUIDN/A N/AIdentifies the source universal unique identifier for a guest virtual machine in the VMware NSX environment.
PanOSDestinationUUIDN/A N/AIdentifies the destination universal unique identifier for a guest virtual machine in the VMware NSX environment.
PanOSRuleUUIDN/A N/AUnique identifier for the security policy rule that the network traffic matched.
PanOSClientToFirewallN/A N/AThe direction of the SSL/TLS connection is from the client to the firewall.
PanOSFirewallToClientN/AN/AThe direction of the SSL/TLS connection is from the firewall to the client.
PanOSTLSVersionN/A N/AVersion of TLS used for the encrypted session represented as major.minor.patch.build.
PanOSTLSKeyExchange
N/AAlgorithm used to perform the key exchange. Possible values are:
PanOSTLSEncryptionAlgorithm
N/AThe algorithm used to encrypt the session data, such as AES-128-CBC, AES-256-GCM, and so forth.
PanOSTLSAuth
N/ATLS hash algorithm.
PanOSPolicyName<policy>Text/StringThe name of the Decryption policy associated with the session.
PanOSEllipticCurve
N/AThe elliptic cryptography curve that the client and server negotiate and use for connections that use ECDHE cipher suites.
PanOSErrorIndex
N/AThe elliptic cryptography curve that the client and server negotiate and use for connections that use ECDHE cipher suites.
PanOSRootStatus
N/AThe status of the root certificate, for example, trusted, untrusted, or uninspected.
PanOSChainStatus
N/AThe certificate chain verification status. Possible values are:
PanOSProxyType
N/AThe Decryption proxy type, such as Forward for Forward Proxy, Inbound for Inbound Inspection, No Decrypt for undecrypted traffic, Decryption Broker, GlobalProtect, and so forth.
PanOSCertificateSerial
N/AThe certificate's serial number.
PanOSFingerprint
N/AA hash of the certificate in x509 binary format.
PanOSTimeNotBefore
N/ATimestamp date before which the certificate is not yet valid.
PanOSTimeNotAfter
N/ATimestamp date after which the certificate is no longer valid.
PanOSCertificateVersion
N/AThe certificate's version number.
PanOSCertificateSize
N/AThe size of the certificate.
PanOSCommonNameLength
N/AThe length of the common name found on the certificate's domain name before truncation (if any).
PanOSIssuerNameLength
N/AThe length of the issuer's common name before truncation (if any).
PanOSRootCNLength
N/AThe length of the root CA's common name before truncation (if any).
PanOSSNILength
N/AThe length of the server name indication (SNI), which is the hostname of the server that the client is trying to reach. This is the full length of the SNI before any truncation might have occurred.
PanOSCertificateFlags
N/AInternal use only bit field containing raw decryption information as generated at the firewall. The information in this bit field is reflected in other decryption log fields.
PanOSCommonName
N/AThe common name found on the certificate's domain name.
PanOSIssuerCommonName
N/AThe name of the organization that verified the certificate’s contents.
PanOSRootCommonName
N/AThe name of the root certificate authority.
PanOSServerNameIndication
N/AThe hostname of the server that the client is trying to contact.
PanOSErrorMessage
N/AThe error message content.
PanOSContainerID
N/AUnknown field. No information is available at this time.
PanOSContainerNameSpace
N/AContainer namespace.
PanOSContainerName
N/AContainer name.
PanOSSourceEDL
N/AThe name of the external dynamic list that contains the source IP address of the traffic.
PanOSDestinationEDL
N/AThe name of the external dynamic list that contains the destination IP address of the traffic.
PanOSSourceDynamicAddressGroup
N/AThe dynamic address group that Device-ID identifies as the source of the traffic.
PanOSDestinationDynamicAddressGroup
N/AThe dynamic address group that Device-ID identifies as the destination for the traffic.
PanOSTimeGeneratedHighResolution
N/ATime the log was generated in data plane with millisec granularity in format YYYY-MM-DDTHH:MM:SS[.DDDDDD]Z.
PanOSSourceDeviceCategory
N/ACategory of the device from which the session originated.
PanOSSourceDeviceProfile
N/AProfile of the device from which the session originated.
PanOSSourceDeviceModel
N/AModel of the device from which the session originated.
PanOSSourceDeviceVendor
N/AVendor of the device from which the session originated.
PanOSSourceDeviceOSFamily
N/AOS family of the device from which the session originated.
PanOSSourceDeviceOSVersion
N/AOS version of the device from which the session originated.
PanOSSourceDeviceHost<sname>Text/StringHostname of the device from which the session originated.
PanOSSourceDeviceMac<smac>Text/StringMAC Address of the device from which the session originated.
PanOSDestinationDeviceCategory
N/ACategory of the device to which the session was directed.
PanOSDestinationDeviceProfile
N/AProfile of the device to which the session was directed.
PanOSDestinationDeviceModel
N/AModel of the device to which the session was directed.
PanOSDestinationDeviceVendor
N/AVendor of the device to which the session was directed.
PanOSDestinationDeviceOSFamily
N/AOS family of the device to which the session was directed.
PanOSDestinationDeviceOSVersion
N/AOS version of the device to which the session was directed.
PanOSDestinationDeviceHost<dname>Text/StringHostname of the device to which the session was directed.
PanOSDestinationDeviceMac<dmac>Text/StringMAC Address of the device to which the session was directed.
externalId
N/AThe log entry identifier, which is incremented sequentially. Each log type has a unique number space.
PanOSApplicationCategory
N/AIdentifies the high-level family of the application.
PanOSApplicationSubcategory
N/AIdentifies the application's subcategory. The subcategory is related to the application's category, which is identified in category_of_app.
PanOSApplicationCharacteristics
N/AIdentifies the behaviorial characteristic of the application associated with the network traffic.
PanOSApplicationContainer
N/AIdentifies the managing application or parent of the application associated with this network traffic.
PanOSCpadding
N/AFor internal use only.
PanOSCortexDataLakeTenantID
N/AThe ID that uniquely identifies the Cortex Data Lake instance which received this log record.
PanOSDestinationDeviceClass
N/ADestination device class.
PanOSDestinationDeviceOS
N/ADestination device OS type.
PanOSDestinationLocation
N/ADestination country or internal region for private addresses.
dntdom<domainimpacted>Text/StringDomain to which the Destination User belongs.
duid
N/AUnique identifier assigned to the Destination User.
PanOSDGHierarchyLevel1
N/AA sequence of identification numbers that indicate the device group’s location within a device group hierarchy.
PanOSDGHierarchyLevel2
N/AA sequence of identification numbers that indicate the device group’s location within a device group hierarchy.
PanOSDGHierarchyLevel3
N/AA sequence of identification numbers that indicate the device group’s location within a device group hierarchy.
PanOSDGHierarchyLevel4
N/AA sequence of identification numbers that indicate the device group’s location within a device group hierarchy.
PanOSDomain
N/AThe subject common name; that is, the name of the server that the certificate protects.
PanOSInboundInterfaceDetailsPort
N/AHardware port or socket from which the network traffic was sourced.
PanOSInboundInterfaceDetailsSlot
N/AInterface slot from which the network traffic was sourced.
PanOSInboundInterfaceDetailsType
N/AThe type of interface from which the network traffic was sourced.
PanOSInboundInterfaceDetailsUnit
N/AInternal use.
PanOSCaptivePortal
N/AIndicates if user information for the session was captured through Captive Portal.
PanOSIsCertECDSA
N/AThe certificate key exchange algorithm used for the session is ECDSA.
PanOSIsCertRSA
N/AThe certificate key exchange algorithm used for the session is RSA.
PanOSIsCertCNTruncated
N/AIndicates whether the common name found on the certificate has been truncated due to buffer limits.
PanOSIsClienttoServer
N/AIndicates if direction of traffic is from client to server.
PanOSIsContainer
N/AIndicates if the session is a container page access (Container Page).
PanOSIsDecryptMirror
N/AIndicates whether decrypted traffic was sent out in clear text through a mirror port.
PanOSIsDecrypted
N/AFlag that indicates that the session is decrypted.
PanOSIsDuplicateLog
N/AIndicates whether this log data is available in multiple locations, such as from Cortex Data Lake as well as from an on-premise log collector.
PanOSIsEncrypted
N/AFlag that indicates that the session is encrypted.
PanOSLogExported
N/AIndicates if this log was exported from the firewall using the firewall's log export function.
PanOSIsForwarded
N/AInternal-use field that indicates if the log is being forwarded.
PanOSIsIPV6
N/AIndicates whether IPV6 was used for the session.
PanOSIsIssuerCNTruncated
N/AIndicates whether the common name used by the certificate's issuer has been truncated due to buffer limits.
PanOSIsMptcpOn
N/AIndicates whether the option is enabled on the next-generation firewall that allows a client to use multiple paths to connect to a destination host.
PanOSIsNAT
N/AIndicates if the firewall is performing network address translation (NAT) for the logged traffic.
PanOSIsNonStandardDestinationPort
N/AIndicates if the destination port is non-standard.
PanOSPacketCapture
N/AIndicates whether the session has a packet capture (PCAP).
PanOSIsPhishing
N/AIndicates whether enterprise credentials were submitted by an end user.
PanOSIsPrismaNetwork
N/AInternal-use field. If set to 1, the log was generated on a cloud-based firewall. If 0, the firewall was running on-premise.
PanOSIsPrismaUsers
N/AInternal use field. If set to 1, the log record was generated using a cloud-based GlobalProtect instance. If 0, GlobalProtect was hosted on-premise.
PanOSIsProxy
N/AIndicates whether the SSL session is decrypted (SSL Proxy).
PanOSIsReconExcluded
N/AIndicates whether source for the flow is on the firewall allow list and not subject to recon protection.
PanOSIsResumeSession
N/AIndicates that the decryption session was previously interrupted and is now resuming.
PanOSIsRootCNTruncated
N/AIndicates whether the common name used for the root CA has been truncated due to buffer limits.
PanOSIsSaaSApplication
N/AInternal use field. Indicates whether the application associated with this network traffic is a SAAS application.
PanOSIsServertoClient
N/AIndicates if direction of traffic is from server to client.
PanOSIsSNITruncated
N/AIndicates whether the server name indication (SNI), which is the hostname of the server that the client is trying to reach, has been truncated due to buffer limits.
PanOSIsSourceXForwarded
N/AIndicates whether the X-Forwarded-For value from a proxy is in the source user field.
PanOSIsSystemReturn
N/AIndicates whether symmetric return was used to forward traffic for this session.
PanOSIsTransaction
N/AIndicates whether the log corresponds to a transaction within an HTTP proxy session (Proxy Transaction).
PanOSIsTunnelInspected N/A N/AIndicates whether the payload for the outer tunnel was inspected.
PanOSIsURLDeniedN/A N/AIndicates whether the session was denied due to a URL filtering rule.
PanOSLogSourceN/A N/AIdentifies the origin of the data. That is, the system that produced the data.
PanOSDeviceNameN/A  N/AName of the source of the log. That is, the hostname of the firewall that logged the network traffic.
PanOSLogSourceTimeZoneOffsetN/A N/ATime Zone offset from GMT of the source of the log.
PanOSOutboundInterfaceDetailsPortN/A N/AHardware port or socket to which the network traffic was sent.
PanOSOutboundInterfaceDetailsSlotN/A  N/AInterface slot to which the network traffic was sent.
PanOSOutboundInterfaceDetailsTypeN/A N/AThe type of interface to which the network traffic was sent.
PanOSOutboundInterfaceDetailsUnitN/A N/AInternal use.
PanOSPaddingN/A N/AFor internal use only.
PanOSPadding3N/A  N/AFor internal use only.
PanOSApplicationRiskN/A N/AIndicates how risky the application is from a network security perspective.
PanOSSanctionedStateOfAppN/A N/AIndicates whether the application has been flagged as sanctioned by the firewall administrator.
PanOSSourceDeviceClassN/A N/ASource device class.
PanOSSourceDeviceOSN/AN/ASource device OS type.
PanOSSourceLocationN/AN/ASource country or internal region for private addresses.
sntdom<domainorigin>Text/StringDomain to which the Source User belongs.
suidN/AN/AUnique identifier assigned to the Source User.
PanOSApplicationTechnologyN/AN/AThe networking technology used by the identified application.
PanOSTpaddingN/AN/AFor internal use only.
PanOSTunneledApplicationN/AN/AFor internal use only.
PanOSVpaddingN/AN/AFor internal use only.
PanOSVirtualSystemIDN/A N/AA unique identifier for a virtual system on a Palo Alto Networks firewall.
PanOSVirtualSystemNameN/AN/AThe name of the virtual system associated with the network traffic.
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.