Skip to main content
Skip table of contents

V 2.0 GlobalProtect Status Messages 1

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 GlobalProtect Status Messages

Base Rule

General Authentication Event

Other Audit

V 2.0 Remote Authentication Success

Sub RuleUser Logon

Authentication Success

V 2.0 Remote Authentication FailureSub RuleUser Logon Failure
Authentication Failure
V 2.0 Remote Session LogoffSub RuleUser LogoffAuthentication Success

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
Type (type)<vmid>Text/StringSpecifies the type of log; value is GLOBALPROTECT.
Threat/Content Type (subtype)<vendorinfo>Number
Event ID (eventid)<action>Text/StringA string showing the name of the event.
Stage (stage)<status>
<tag1>
Text/StringA string showing the stage of the connection (for example, before-login, login, or tunnel).
Source User (srcuser)<domainorigin>
<login>
Text/StringThe username of the user who initiated the session.
Machine Name (machinename)<sname>Text/StringThe name of the user’s machine.
Public IP (public_ip)<sip>IP AddressThe public IP address for the user who initiated the session.
Private IP (private_ip)<snatip>IP AddressThe private IP address for the user who initiated the session.
Serial Number (serialnumber)<serialnumber>Text/StringThe serial number of the user’s machine or device.
Client Version (client_ver)<version>Text/StringThe client’s GlobalProtect app version.
Repeat Count (repeatcnt)<quantity>NumberThe number of sessions with the same source IP address, destination IP address, application, and subtype that GlobalProtect has detected within the last five seconds.
Reason (reason)<reason>Text/StringA string that shows the reason for the quarantine.
Error (error)<responsecode>Text/StringA string showing that error that has occurred in any event.
Description (opaque)<subject>Text/StringAdditional information for any event that has occurred.
Status (status)<result>
<tag2>
Text/StringThe status (success or failure) of the event.
Login Duration (login_duration)<seconds>NumberThe length of time, in seconds, the user is connected to the GlobalProtect gateway from logging in to logging out.
Device Name (device_name)**<objectname>Text/StringThe hostname of the firewall on which the session was logged.
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.