Parsers and Generated Fields

Tag Fields Created by Parser paloalto-ngfw
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser paloalto-ngfw
Source FieldLogScale Repository Field
Vendor.CertificateEndDateafter
Vendor.CertificateStartDatebefore
Vendor.BytesReceiveddestination.bytes
Vendor.DestinationAddressdestination.ip
Vendor.DestinationDeviceMacdestination.mac
Vendor.NATDestinationdestination.nat.ip
Vendor.NATDestinationPortdestination.nat.port
Vendor.PacketsReceiveddestination.packets
Vendor.DestinationPortdestination.port
Vendor.Recipientdestination.user.email
Vendor.DestinationUserdestination.user.name
Vendor.Descriptionevent.action
Vendor.ReceiveTimeevent.created
Vendor.ElapsedTimeevent.duration
Vendor.SessionDurationevent.duration
Vendor.Statusevent.outcome
Vendor.Reasonevent.reason
Vendor.StartTimeevent.start
Vendor.FileTypefile.type
Vendor.HostIDhost.id
Vendor.DeviceMacAddresshost.mac[0]
Vendor.MachineNamehost.name
Vendor.SourceDeviceOShost.os.family
Vendor.OperatingSystemhost.os.full
Vendor.SourceDeviceOSVersionhost.os.full
Vendor.HTTPMethodhttp.request.method
Vendor.XForwardedForip
Vendor.Severitylog.level
Vendor.IssuerCommonNamename
Vendor.ServerNameIndicationname
Vendor.SubjectCommonNamename
Vendor.Applicationnetwork.application
Vendor.Bytesnetwork.bytes
Vendor.Packetsnetwork.packets
Vendor.IpProtocolnetwork.transport
Vendor.Protocolnetwork.transport
Vendor.CertificateVersionnumber
Vendor.ChainStatusnumber
Vendor.TunnelInspectionRulerule.name
Vendor.RuleUUIDrule.uuid
Vendor.CertificateSizesize
Vendor.BytesSentsource.bytes
Vendor.IPV6PrivateAddresssource.ip
Vendor.IPv6SystemAddresssource.ip
Vendor.PrivateAddresssource.ip
Vendor.SourceAddresssource.ip
Vendor.SourceDeviceMacsource.mac
Vendor.IPV6PublicAddresssource.nat.ip
Vendor.NATSourcesource.nat.ip
Vendor.PublicAddresssource.nat.ip
Vendor.NATSourcePortsource.nat.port
Vendor.PacketsSentsource.packets
Vendor.SourcePortsource.port
Vendor.Sendersource.user.email
Vendor.NormalizeUsersource.user.name
Vendor.SourceUsersource.user.name
Vendor.Usersource.user.name
Vendor.UserBySourcesource.user.name
Vendor.EncryptionAlgorithmtls.cipher
Vendor.EllipticCurvetls.curve