Parsers and Generated Fields

Tag Fields Created by Parser paloalto-ngfw
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser paloalto-ngfw
Vendor FieldCPS FieldDescription
Vendor.TimeGenerated@timestampEvent timestamp
Vendor.FUTUREUSE2Vendor.ConfigVersion  
Vendor.FUTUREUSE1Vendor.FUTURE_USE_1 
Vendor.FUTUREUSE2Vendor.FUTURE_USE_2 
Vendor.FUTUREUSE3Vendor.FUTURE_USE_3 
Vendor.SubTypeVendor.Subtype 
Vendor.TimeGeneratedVendor.generated_time 
Vendor.ReceiveTimeVendor.receive_time 
Vendor.SerialVendor.serial_number 
Vendor.TypeVendor.type 
Vendor.BytesReceiveddestination.bytesBytes received by destination
Vendor.DestinationCountrydestination.geo.country_nameDestination country
Vendor.DestinationAddressdestination.ipDestination IP address
Vendor.DestinationDeviceMacdestination.mac 
Vendor.NATDestinationdestination.nat.ipNAT destination IP
Vendor.NATDestinationPortdestination.nat.portNAT destination port
Vendor.PacketsReceiveddestination.packetsPackets received by destination
Vendor.DestinationPortdestination.portDestination port number
Vendor.DestinationPort;destination.port 
Vendor.Recipientdestination.user.email 
Vendor.DestinationUserdestination.user.nameDestination username
Vendor.DestinationUser;destination.user.name 
Vendor.Descriptionevent.action 
Vendor.ReceiveTimeevent.createdEvent creation timestamp
Vendor.Descriptionevent.descriptionEvent description details
Vendor.ElapsedTimeevent.duration 
Vendor.SessionDurationevent.duration 
Vendor.Actionevent.outcomeMaps allow to success, deny/drop to failure
Vendor.Statusevent.outcome 
Vendor.Reasonevent.reason 
Vendor.Severityevent.severityMaps severity levels to numeric values
Vendor.StartTimeevent.start 
Vendor.SubTypeevent.typeMaps to allowed/denied based on action
Vendor.FileTypefile.type 
Vendor.HostIDhost.id 
Vendor.MachineNamehost.name 
Vendor.SourceDeviceOShost.os.family 
Vendor.OperatingSystem;host.os.full 
Vendor.SourceDeviceOSVersionhost.os.full 
Vendor.HTTPMethodhttp.request.method 
Vendor.Severitylog.level 
Vendor.Applicationnetwork.applicationApplication identifier
Vendor.Bytesnetwork.bytesTotal bytes transferred
Vendor.XForwardedFornetwork.forwarded_ip 
Vendor.Packetsnetwork.packetsTotal packets transferred
Vendor.IpProtocolnetwork.transport 
Vendor.Protocolnetwork.transportTransport protocol
Vendor.DeviceNameobserver.hostnameDevice hostname
Vendor.ConfigurationPathprocess.command_lineCommand line for config changes
Vendor.Categoryrule.categoryRule category
Vendor.Category;rule.category 
Vendor.Categoryrule.category  
Vendor.RuleNamerule.nameSecurity policy rule name
Vendor.TunnelInspectionRulerule.name 
Vendor.RuleUUIDrule.uuidSecurity policy rule UUID
Vendor.BytesSentsource.bytesBytes sent from source
Vendor.SourceCountrysource.geo.country_nameSource country
Vendor.SourceCountry;source.geo.country_name 
Vendor.Hostsource.ip 
Vendor.IPV6PrivateAddress;source.ip 
Vendor.IPv6SystemAddress;source.ip 
Vendor.PrivateAddress;source.ip 
Vendor.SourceAddresssource.ipSource IP address
Vendor.SourceAddress;source.ip 
Vendor.SourceDeviceMacsource.mac 
Vendor.IPV6PublicAddress;source.nat.ip 
Vendor.NATSourcesource.nat.ipNAT source IP
Vendor.PublicAddress;source.nat.ip 
Vendor.NATSourcePortsource.nat.portNAT source port
Vendor.PacketsSentsource.packetsPackets sent from source
Vendor.SourcePortsource.portSource port number
Vendor.Sendersource.user.email 
Vendor.NormalizeUser;source.user.name 
Vendor.SourceUsersource.user.nameSource username
Vendor.SourceUser;source.user.name 
Vendor.Usersource.user.name 
Vendor.UserBySourcesource.user.name 
Vendor.EncryptionAlgorithmtls.cipherTLS cipher suite
Vendor.CertificateEndDatetls.client.not_after 
Vendor.CertificateStartDatetls.client.not_before 
Vendor.ServerNameIndicationtls.client.server_nameSNI value
Vendor.CertificateSizetls.client.x509.public_key_sizeCertificate key size
Vendor.CertificateSerialNumbertls.client.x509.serial_numberCertificate serial number
Vendor.ChainStatustls.client.x509.serial_number 
Vendor.CertificateVersiontls.client.x509.version_number 
Vendor.EllipticCurvetls.curve 
Vendor.TLSVersiontls.versionTLS protocol version
Vendor.URLFilenameurl.original  
top_ldurl.top_level_domain  
source.user.nameuser.name 
Vendor.Adminuser.name  
Vendor.UserAgentuser_agent.originalUser agent string
Vendor.UserAgentuser_agent.original