Skip to main content
Skip table of contents

V 2.0 General SDWAN Messages

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 General SDWAN Messages

Base Rule

General System Message

Information

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

FUTURE_USE

N/A

N/A

N/A

Receive Time (receive_time or cef-formatted-receive_time)

N/A

N/A

Time the log was received at the management plane

Serial Number (serial)

N/A

N/A

Serial number of the firewall that generated the log

Type (type)

<vmid>

Test/String

Specifies the type of log; value is SYSTEM.

Content/Threat Type (subtype)

<vendorinfo>

Test/String

Subtype of the system log; refers to the system daemon generating the log

FUTURE_USE

N/A

N/A

N/A

Generated Time (time_generated or cef-formatted-time_generated)

N/A

N/A

Time the log was generated on the dataplane

Virtual System (vsys)

N/A

N/A

Virtual System associated with the session

Event ID (eventid)

<action>

Test/String

String showing the name of the event.

Object (object)

<object>

Test/String

Name of the object associated with the system event.

FUTURE_USE

N/A

N/A

N/A

FUTURE_USE

N/A

N/A

N/A

Module (module)

N/A

N/A

This field is valid only when the value of the Subtype field is general. It provides additional information about the sub-system generating the log; values are general, management, auth, ha, upgrade, chassis.

Severity (severity)

<severity>

Test/String

Severity associated with the event; values are informational, low, medium, high, critical.

Description (opaque)

<subject>

Test/String

Detailed description of the event, up to a maximum of 512 bytes.

Sequence Number (seqno)

N/A

N/A

A 64-bit log entry identifier incremented sequentially; each log type has a unique number space

Action Flags (actionflags)

N/A

N/A

A bit field indicating if the log was forwarded to Panorama

Device Group Hierarchy Level 1

N/A

N/A

A sequence of identification numbers that indicate the device group’s location within a device group hierarchy. The firewall (or virtual system) generating the log includes the identification number of each ancestor in its device group hierarchy. The shared device group (level 0) is not included in this structure

Device Group Hierarchy Level 2

N/A

N/A

Device Group Hierarchy Level 3

N/A

N/A

Device Group Hierarchy Level 4

N/A

N/A

Virtual System Name (vsys_name)

N/A

N/A

The name of the virtual system associated with the session; only valid on firewalls enabled for multiple virtual systems

Device Name (device_name)

N/A

N/A

The hostname of the firewall on which the session was logged

FUTURE_USE*

N/A

N/A

N/A

FUTURE_USE*

N/A

N/A

N/A

High Resolution Timestamp (high_res_timestamp)*

N/A

N/A

Time in milliseconds the log was received at the management plane.
The format for this new field is YYYY-MM-DDThh:ss:sssTZD:
YYYY—Four digit year
MM—Two-digit month
DD—Two-digit day of the month (01 through 31)
T—Indicator for the beginning of the timestamp
hh—Two-digit hour using 24-hour time (00 through 23)
mm—Two-digit minute (00 through 59)
ss—Two-digit second (00 through 60)
sss—One or more digits for millisecond
TZD—Time zone designator (+hh:mm or -hh:mm)

The High Resolution Timestamp is supported for logs received from managed firewalls running PAN-OS 10.1 and later releases. Logs received from managed firewalls running PAN-OS 9.1 and earlier releases display a 1969-12-31T16:00:00:000-8:00 timestamp regardless of when the log was received.

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.