V 2.0 General SDWAN Messages
Vendor Documentation
Classification
Rule Name | Rule Type | Common Event | Classification |
---|---|---|---|
V 2.0 General SDWAN Messages | Base Rule | General System Message | Information |
Mapping with LogRhythm Schema
Device Key in Log Message | LogRhythm Schema | Data Type | Schema Description |
---|---|---|---|
FUTURE_USE | N/A | N/A | N/A |
Receive Time (receive_time or cef-formatted-receive_time) | N/A | N/A | Time the log was received at the management plane |
Serial Number (serial) | N/A | N/A | Serial number of the firewall that generated the log |
Type (type) | <vmid> | Test/String | Specifies the type of log; the value is SYSTEM. |
Content/Threat Type (subtype) | <vendorinfo> | Test/String | A subtype of the system log; refers to the system daemon generating the log |
FUTURE_USE | N/A | N/A | N/A |
Generated Time (time_generated or cef-formatted-time_generated) | N/A | N/A | Time the log was generated on the data plane. |
Virtual System (vsys) | N/A | N/A | Virtual System associated with the session. |
Event ID (eventid) | <action> | Test/String | The string showing the name of the event. |
Object (object) | <object> | Test/String | Name of the object associated with the system event. |
FUTURE_USE | N/A | N/A | N/A |
FUTURE_USE | N/A | N/A | N/A |
Module (module) | N/A | N/A | This field is valid only when the value of the Subtype field is general. It provides additional information about the sub-system generating the log; values are general, management, auth, ha, upgrade, and chassis. |
Severity (severity) | <severity> | Test/String | Severity associated with the event; values are informational, low, medium, high, critical. |
Description (opaque) | <subject> | Test/String | Detailed description of the event, up to a maximum of 512 bytes. |
Sequence Number (seqno) | N/A | N/A | A 64-bit log entry identifier incremented sequentially; each log type has a unique number space |
Action Flags (actionflags) | N/A | N/A | A bit field indicating if the log was forwarded to Panorama |
Device Group Hierarchy Level 1 | N/A | N/A | A sequence of identification numbers that indicate the device group’s location within a device group hierarchy. The firewall (or virtual system) generating the log includes the identification number of each ancestor in its device group hierarchy. The shared device group (level 0) is not included in this structure |
Device Group Hierarchy Level 2 | N/A | N/A | |
Device Group Hierarchy Level 3 | N/A | N/A | |
Device Group Hierarchy Level 4 | N/A | N/A | |
Virtual System Name (vsys_name) | N/A | N/A | The name of the virtual system associated with the session; is only valid on firewalls enabled for multiple virtual systems |
Device Name (device_name) | <objectname> | Text/String | The hostname of the firewall on which the session was logged. |
FUTURE_USE* | N/A | N/A | N/A |
FUTURE_USE* | N/A | N/A | N/A |
High Resolution Timestamp (high_res_timestamp)* | N/A | N/A | Time in milliseconds the log was received at the management plane. The High-Resolution Timestamp is supported for logs received from managed firewalls running PAN-OS 10.1 and later releases. Logs received from managed firewalls running PAN-OS 9.1 and earlier releases display a 1969-12-31T16:00:00:000-8:00 timestamp regardless of when the log was received. |