Skip to main content
Skip table of contents

Host Profile Messages

Vendor Documentation

Classification

Rule NameRule TypeClassificationCommon Event
Host Profile MessagesBase RuleInformationGeneral Profile Detection

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

 N/A N/AN/AdeviceVendor
 N/A N/AN/AdeviceProduct
 N/A N/AN/AVersion
 N/A<vmid>Text/StringLogType
 N/A N/AN/ASubType
 N/A<severity>NumberdeviceSeverity
ProfileToken N/AN/A
dtz N/AN/A
rt N/AN/ATime the log was received in Cortex Data Lake. This string contains a timestamp value that is the number of microseconds since the Unix epoch.
deviceExternalId<serialnumber>Text/String/NumberID that uniquely identifies the source of the log. That is, the serial number of the firewall that generated the log.
PanOSIsDuplicateLog N/AN/AIndicates whether this log data is available in multiple locations, such as from Cortex Data Lake as well as from an on-premise log collector.
PanOSIsPrismaNetworks N/AN/AInternal-use field. If set to 1, the log was generated on a cloud-based firewall. If 0, the firewall was running on-premise.
PanOSIsPrismaUsers N/AN/AInternal use field. If set to 1, the log record was generated using a cloud-based GlobalProtect instance. If 0, GlobalProtect was hosted on-premise.
PanOSLogExported N/AN/AIndicates if this log was exported from the firewall using the firewall's log export function.
PanOSLogForwarded N/AN/AInternal-use field that indicates if the log is being forwarded.
PanOSLogSource N/AN/AIdentifies the origin of the data. That is, the system that produced the data.
PanOSLogSourceTimeZoneOffset N/AN/ATime Zone offset from GMT of the source of the log.
PanOSSourceDeviceClassN/A N/ASource device class.
PanOSSourceDeviceOSN/A N/ASource device OS type.
sntdom<domainorigin>Text/StringDomain to which the Source User belongs.
dntdom<domainimpacted>Text/StringDomain to which the Destination User belongs.
susername<login>Text/StringThe Source User. That is, the username that initiated the network traffic.
dusername<account>Text/StringThe Destination User. That is, the username that initiated the network traffic.
suidN/A N/AUnique identifier assigned to the Source User.
duid N/AN/AUnique identifier assigned to the Source User.
PanOSCortexDataLakeTenantID N/AN/AThe ID that uniquely identifies the Cortex Data Lake instance which received this log record.
PanOSUUID N/AN/AUUID.
PanOSConfigVersion N/AN/AVersion number of the firewall operating system that wrote this log record.
startN/A N/ATime when the log was generated on the firewall's data plane. This string contains a timestamp value that is the number of microseconds since the Unix epoch.
PanOSSourceUser N/AN/AThe username that initiated the network traffic.
cs3 N/AN/AString representation of the unique identifier for a virtual system on a Palo Alto Networks firewall.
cs3Label N/AN/A
shost<sname>Text/StringName of the user’s machine.
dhost<dname>Text/String
cs2N/A N/AThe operating system installed on the user’s machine or device (or on the client system).
cs2Label N/AN/A
src<sip>IP AddressOriginal source IP address.
dst<dip>IP Address
cat<object>Text/StringName of the HIP object or profile.
cnt<quantity>NumberNumber of sessions with same Source IP, Destination IP, Application, and Content/Threat Type seen for the summary interval.
PanOSHipMatchType<objecttype>Text/StringIdentifies whether the hip field represents a HIP object or a HIP profile.
externalId N/AN/AThe log entry identifier, which is incremented sequentially. Each log type has a unique number space.
PanOSDGHierarchyLevel1 N/AN/AA sequence of identification numbers that indicate the device group’s location within a device group hierarchy.
PanOSDGHierarchyLevel2 N/AN/AA sequence of identification numbers that indicate the device group’s location within a device group hierarchy.
PanOSDGHierarchyLevel3N/A N/AA sequence of identification numbers that indicate the device group’s location within a device group hierarchy.
PanOSDGHierarchyLevel4 N/AN/AA sequence of identification numbers that indicate the device group’s location within a device group hierarchy.
PanOSVirtualSystemName N/AN/AThe name of the virtual system associated with the network traffic.
dvchost N/AN/AName of the source of the log. That is, the hostname of the firewall that logged the network traffic.
cn2 N/AN/AA unique identifier for a virtual system on a Palo Alto Networks firewall.
cn2Label N/AN/A
c6a1 N/AN/ASource from which mapping information is collected.
c6a1Label N/AN/A
PanOSHostID N/AN/AUnique identifier GlobalProtect has assigned to the host.
PanOSEndpointSerialNumber N/AN/ASerial number of the host on which GlobalProtect is installed.
PanOSSourceDeviceCategory N/AN/ACategory of the device from which the session originated.
PanOSSourceDeviceProfile N/AN/AProfile of the device from which the session originated.
PanOSSourceDeviceModel N/AN/AModel of the device from which the session originated.
PanOSSourceDeviceVendorN/A N/AVendor of the device from which the session originated.
PanOSSourceDeviceOSFamily N/AN/AOS family of the device from which the session originated.
PanOSSourceDeviceOSVersionN/A N/AOS version of the device from which the session originated.
PanOSSourceDeviceMac<smac>Text/StringMAC Address of the device from which the session originated.
PanOSSourceDeviceHost N/AN/AHostname of the device from which the session originated.
PanOSSource N/AN/ASource.
PanOSTimestampDeviceIdentification N/AN/ATime the device was identified in format YYYY-MM-DDTHH
PanOSTimeGeneratedHighResolution N/AN/ATime the log was generated in data plane with millisec granularity in format YYYY-MM-DDTHH
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.