Skip to main content
Skip table of contents

SCTP Messages

Vendor Documentation

Classification

Rule NameRule TypeClassificationCommon Event
SCTP MessagesBase RuleNetwork TrafficGeneral Network Traffic
Traffic AllowedSub RuleNetwork AllowTraffic Allowed by Network Firewall
Traffic DeniedSub RuleNetwork DenyTraffic Denied by Network Firewall

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
 N/AN/A N/AdeviceVendor
 N/A N/AN/AdeviceProduct
 N/A N/AN/AVersion
 N/A<vmid>Text/StringLogType
N/A  N/AN/ASubType
 N/A<severity>NumberdeviceSeverity
ProfileToken N/AN/A N/A
dtz N/AN/A N/A
rtN/A N/ATime the log was received in Cortex Data Lake. This string contains a timestamp value that is the number of microseconds since the Unix epoch.
deviceExternalId<serialnumber>Text/String/NumberID that uniquely identifies the source of the log. That is, the serial number of the firewall that generated the log.
PanOSCaptivePortal N/AN/AIndicates if user information for the session was captured through Captive Portal.
PanOSContentVersion N/AN/AVersion of the content on the firewall.
PanOSCortexDataLakeTenantIDN/A N/AThe ID that uniquely identifies the Cortex Data Lake instance which received this log record.
PanOSDestinationDeviceClassN/A N/ADestination device class.
PanOSDestinationDeviceMac<dmac>Text/StringDestination device MAC address.
PanOSDestinationDeviceModelN/A N/ADestination device model.
PanOSDestinationDeviceOS N/AN/ADestination device OS type.
PanOSDestinationDeviceVendorN/A N/ADestination device vendor.
PanOSDestinationLocationN/A N/ADestination country or internal region for private addresses.
PanOSDestinationUUIDN/A N/AIdentifies the destination universal unique identifier for a guest virtual machine in the VMware NSX environment.
PanOSDestinationUserDomain<domainimpacted>Text/StringDomain to which the Destination User belongs.
PanOSDestinationUserName<account>Text/StringThe Destination User. That is, the username to which the network traffic was destined.
PanOSDestinationUserUUID N/AN/AUnique identifier assigned to the Destination User.
PanOSInboundInterfaceDetailsPort N/AN/AHardware port or socket from which the network traffic was sourced.
PanOSInboundInterfaceDetailsSlotN/A N/AInterface slot from which the network traffic was sourced.
PanOSInboundInterfaceDetailsType N/AN/AThe type of interface from which the network traffic was sourced.
PanOSInboundInterfaceDetailsUnit N/AN/AInternal use.
PanOSIsClienttoServer N/AN/AIndicates if direction of traffic is from client to server.
PanOSIsContainer N/AN/AIndicates if the session is a container page access (Container Page).
PanOSIsDecryptMirror N/AN/AIndicates whether decrypted traffic was sent out in clear text through a mirror port.
PanOSIsDecryptedLog N/AN/AUnknown field. No information is available at this time.
PanOSIsDecryptedPayloadForward N/AN/AUnknown field. No information is available at this time.
PanOSIsDuplicateLog N/AN/AIndicates whether this log data is available in multiple locations, such as from Cortex Data Lake as well as from an on-premise log collector.
PanOSIsIPV6 N/AN/AIndicates whether IPV6 was used for the session.
PanOSIsInspectrionBeforeSession N/AN/AUnknown field. No information is available at this time.
PanOSIsMptcpOn N/AN/AIndicates whether the option is enabled on the next-generation firewall that allows a client to use multiple paths to connect to a destination host.
PanOSIsNonStandardDestinationPort N/AN/AIndicates if the destination port is non-standard.
PanOSIsPacketCapture N/AN/AIndicates whether the session has a packet capture (PCAP).
PanOSIsPhishing N/AN/AIndicates whether enterprise credentials were submitted by an end user.
PanOSIsPrismaNetwork N/AN/AInternal-use field. If set to 1, the log was generated on a cloud-based firewall. If 0, the firewall was running on-premise.
PanOSIsPrismaUsers N/AN/AInternal use field. If set to 1, the log record was generated using a cloud-based GlobalProtect instance. If 0, GlobalProtect was hosted on-premise.
PanOSIsProxy N/AN/AIndicates whether the SSL session is decrypted (SSL Proxy).
PanOSIsReconExcluded N/AN/AIndicates whether source for the flow is on the firewall allow list and not subject to recon protection.
PanOSIsServertoClient N/AN/AIndicates if direction of traffic is from server to client.
PanOSIsSourceXForwarded N/AN/AIndicates whether the X-Forwarded-For value from a proxy is in the source user field.
PanOSIsSystemReturn N/AN/AIndicates whether symmetric return was used to forward traffic for this session.
PanOSIsTransaction N/AN/AIndicates whether the log corresponds to a transaction within an HTTP proxy session (Proxy Transaction).
PanOSIsTunnelInspected N/AN/AIndicates whether the payload for the outer tunnel was inspected.
PanOSIsURLDenied N/AN/AIndicates whether the session was denied due to a URL filtering rule.
PanOSLogExported N/AN/AIndicates if this log was exported from the firewall using the firewall's log export function.
PanOSLogForwardedN/A N/AInternal-use field that indicates if the log is being forwarded.
PanOSLogSource N/AN/AIdentifies the origin of the data. That is, the system that produced the data.
PanOSLogSourceTimeZoneOffset N/AN/ATime Zone offset from GMT of the source of the log.
PanOSNATN/A N/AIndicates if the firewall is performing network address translation (NAT) for the logged traffic.
PanOSOutboundInterfaceDetailsPortN/A N/AHardware port or socket to which the network traffic was sent.
PanOSOutboundInterfaceDetailsSlotN/A N/AInterface slot to which the network traffic was sent.
PanOSOutboundInterfaceDetailsTypeN/A N/AThe type of interface to which the network traffic was sent.
PanOSOutboundInterfaceDetailsUnit N/AN/AInternal use.
PanOSSessionEndReason<reason>Text/StringThe reason a session terminated.
PanOSSessionOwnerMidx N/AN/AUnknown field. No information is available at this time.
PanOSSessionTrackerN/A N/AUnknown field. No information is available at this time.
PanOSSeverity N/AN/ASeverity as defined by the platform.
PanOSSourceDeviceClass N/AN/ASource device class.
PanOSSourceDeviceMac<smac>Text/StringSource device MAC address.
PanOSSourceDeviceModel N/AN/ASource device model.
PanOSSourceDeviceOS N/AN/ASource device OS type.
PanOSSourceDeviceVendorN/A N/ASource device vendor.
PanOSSourceLocation N/AN/ASource country or internal region for private addresses.
PanOSSourceUUID N/AN/AIdentifies the source universal unique identifier for a guest virtual machine in the VMware NSX environment.
PanOSSourceUserDomain<domainorigin>Text/StringDomain to which the Source User belongs.
PanOSSourceUserName<login>Text/StringThe Source User. That is, the username that initiated the network traffic.
PanOSSourceUserUUID N/AN/AUnique identifier assigned to the Source User.
PanOSTunnelN/A N/AType of tunnel.
PanOSVirtualSystemID N/AN/AA unique identifier for a virtual system on a Palo Alto Networks firewall.
PanOSConfigVersion N/AN/AVersion number of the firewall operating system that wrote this log record.
start N/AN/ATime when the log was generated on the firewall's data plane. This string contains a timestamp value that is the number of microseconds since the Unix epoch.
src<sip>IP AddressOriginal source IP address.
dst<dip>IP AddressOriginal destination IP address.
PanOSNATSource<snatip>IP AddressIf source NAT was performed, the post-NAT source IP address.
PanOSNATDestination<dnatip>IP AddressIf destination NAT performed, the post-NAT destination IP address.
cs1<policy>Text/StringName of the security policy rule that the network traffic matched.
cs1Label N/AN/A
PanOSSourceUser N/AN/AThe username that initiated the network traffic.
PanOSDestinationUser N/AN/AThe username to which the network traffic was destined.
PanOSApplication N/AN/AApplication associated with the network traffic.
cs3 N/AN/AString representation of the unique identifier for a virtual system on a Palo Alto Networks firewall.
cs3Label N/AN/A
cs4 N/AN/AThe networking zone from which the traffic originated.
cs4LabelN/A N/A
cs5 N/AN/ANetworking zone to which the traffic was sent.
cs5Label N/AN/A
PanOSInboundInterface<sinterface>Text/StringInterface from which the network traffic was sourced.
deviceOutboundInterface<dinterface>Text/StringInterface to which the network traffic was destined.
cs6N/A N/ALog forwarding profile name that was applied to the session. This name was defined by the firewall's administrator.
cs6Label N/AN/A
PanOSSessionID<session>NumberIdentifies the firewall's internal identifier for a specific network session.
cnt<quantity>NumberNumber of sessions with same Source IP, Destination IP, Application, and Content/Threat Type seen for the summary interval.
spt<sport>NumberSource port utilized by the session.
dpt<dport>NumberNetwork traffic's destination port. If this value is 0, then the app is using its standard port.
PanOSNATSourcePort<snatport>NumberPost-NAT source port.
PanOSNATDestinationPort<dnatport>NumberPost-NAT destination port.
proto<protname>Text/StringIP protocol associated with the session.
act<action>
<tag1>
Text/StringIdentifies the action that the firewall took for the network traffic.
PanOSDGHierarchyLevel1 N/AN/AA sequence of identification numbers that indicate the device group’s location within a device group hierarchy.
PanOSDGHierarchyLevel2 N/AN/AA sequence of identification numbers that indicate the device group’s location within a device group hierarchy.
PanOSDGHierarchyLevel3 N/AN/AA sequence of identification numbers that indicate the device group’s location within a device group hierarchy.
PanOSDGHierarchyLevel4 N/AN/AA sequence of identification numbers that indicate the device group’s location within a device group hierarchy.
PanOSVirtualSystemName N/AN/AThe name of the virtual system associated with the network traffic.
dvchost N/AN/AName of the source of the log. That is, the hostname of the firewall that logged the network traffic.
externalId N/AN/AThe log entry identifier, which is incremented sequentially. Each log type has a unique number space.
PanOSEndpointAssociationID N/AN/AThe ID assigned to the endpoint association used for the SCTP network traffic.
PanOSPayloadProtocolIDN/A N/AThe Payload Protocol Identifier (PPID) associated with the SCTP data chunk.
PanOSSctpChunkType N/AN/AType of information contained in the SCTP data chunk.
PanOSSCTPEventType<subject>Text/StringThe SCTP event notification type set for this message.
PanOSEventCode N/AN/AThe SCTP event notification code set for this message.
PanOSVerificationTag1 N/AN/AThe verification tag set for the SCTP packet.
PanOSVerificationTag2 N/AN/AThe verification tag set for the SCTP packet.
PanOSSctpCauseCode N/AN/AThe error cause code found in the SCTP message.
PanOSDiamAppID N/AN/AThe IANA ID assigned to the Diameter application associated with this network traffic.
PanOSDiameterCommandCode N/AN/AThe Diameter command code used by this network traffic.
PanOSDiamAvpCode N/AN/AThe AVP code used by the Diameter application associated with this network traffic.
PanOSStreamID N/AN/AIdentifies the firewall's internal identifier for the SCTP stream.
PanOSAssocationEndReasonN/A N/AThe reason the session terminated. If the termination had multiple reasons, only the highest priority reason is identified here.
PanOSMapAppCodeN/A N/AMobile Application Part (MAP) operation code used for this network traffic.
PanOSSccpCallingSSNN/A N/AThe subsystem number (SSN) specified in the called party address used for this SCCP protocol message.
PanOSSccpCallingGtN/A N/AThe Global Title (GT) specified in the called party address used for this SCCP protocol message.
PanOSSctpFilterN/A N/AThe SCTP filter that the firewall applied to this network traffic.
PanOSChunksTotalN/A N/AThe total number of SCTP data chunks in the network traffic.
PanOSChunksSentN/A N/AThe total number of SCTP data chunks in the client-to-server network traffic.
PanOSChunksReceived N/AN/AThe total number of SCTP data chunks in the server-to-client network traffic.
PanOSPacketsTotalN/A N/ANumber of total packets (transmit and receive) seen for the session.
PanOSPacketsSent<packetsin>NumberNumber of client-to-server packets for the session.
PanOSPacketsReceived<packetsout>NumberNumber of server-to-client packets for the session.
PanOSRuleUUID N/AN/AUnique identifier for the security policy rule that the network traffic matched.
PanOSContainerID N/AN/AUnknown field. No information is available at this time.
PanOSContainerNameSpaceN/A N/AContainer namespace.
PanOSContainerNameN/A N/AContainer name.
PanOSSourceEDLN/A N/AThe name of the external dynamic list that contains the source IP address of the traffic.
PanOSDestinationEDLN/A N/AThe name of the external dynamic list that contains the destination IP address of the traffic.
PanOSSourceDynamicAddressGroupN/A N/AThe dynamic address group that Device-ID identifies as the source of the traffic.
PanOSDestinationDynamicAddressGroupN/A N/AThe dynamic address group that Device-ID identifies as the destination for the traffic.
PanOSTimeGeneratedHighResolutionN/A N/ATime the log was generated in data plane with millisec granularity in format YYYY-MM-DDTHH:MM:SS[.DDDDDD]Z.
PanOSVendorSeverityN/A N/ASeverity associated with the event.
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.