Skip to main content
Skip table of contents

V 2.0 : Cloud Firewall Logs

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
V 2.0 : Cloud Firewall LogsBase RuleGeneral Network TrafficNetwork Traffic
V 2.0 : Cloud Traffic AllowedSub RuleTraffic Allowed by Network FirewallNetwork Allow
V 2.0 : Cloud Traffic BlockedSub RuleTraffic Denied by Network FirewallNetwork Deny

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

TimestampN/AN/AThe timestamp of the request transaction in UTC.
Origin IDsN/AN/AThe unique identity of the network tunnel.
Identities<object>Text/StringThe names of the network tunnel.
Identity Type<objecttype>Text/StringThe type of identity that made the request. Should always be "CDFW Tunnel Device".
DirectionN/AN/AThe direction of the packet. It is destined either towards the internet or to the customer's network.
Protocol<protnum>NumberThe actual protocol of the traffic. It could be TCP, UDP, ICMP.
Packet Size<size>NumberThe size of the packet that Umbrella CDFW received.
Source IP<sip>IP AddressThe internal IP address of the user-generated traffic towards the CDFW. If the traffic goes through NAT before it comes to CDFW, it will be the NAT IP address.
Source Port<sport>NumberThe internal port number of the user-generated traffic towards the CDFW.
Destination IP<dip>IP AddressThe destination IP address of the user-generated traffic towards the CDFW.
Destination Port<dport>NumberThe destination port number of the user-generated traffic towards the CDFW.
Data CenterN/AN/AThe name of the Umbrella data center that processed the user-generated traffic.
Rule IDN/AN/AThe ID of the rule that processed the user traffic.
Action<action>
<tag1>
Text/StringThe categories that resulted in the destination being blocked. Available in version 4 and above.
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.