Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Table of Contents
minLevel1
maxLevel2
typeflat

Introduction

This union table collects information from a set of tables that contain events from Palo Alto Network's firewalls. 

Source tables

The information displayed is extracted from the following tables:

Expand
titleCheck source tables
  • firewall.paloalto.config

  • firewall.paloalto.correlation

  • firewall.paloalto.globalprotect

  • firewall.paloalto.hipmatch

  • firewall.paloalto.system

  • firewall.paloalto.threat

  • firewall.paloalto.traffic

  • firewall.paloalto.url

  • firewall.paloalto.userid

Table structure

This is the set of columns displayed by this union table, which is the result of the collection of columns present in all source tables: 

Note

Extra columns

Fields marked as Extra in the table below are not shown by default in data tables and need to be explicitly requested in the query. You can find them marked as Extra when you perform a query so they can be easily identified. Learn more about this in Selecting unrevealed columns.

Field

Data type

Extra fields

eventdate

timestamp

-

timestamp

timestamp

-

recvdate

timestamp

-

machine

str

-

logType

str

-

subType

str

-

serial

str

-

srcIp

ip4

-

dstIp

ip4

-

srcNatIp

ip4

-

dstNatIp

ip4

-

rule

str

-

srcUser

str

-

dstUser

str

-

app

str

-

virtSys

str

-

srcZone

str

-

dstZone

str

-

srcIface

str

-

dstIface

str

-

logAction

str

-

session

str

-

repCnt

int4

-

srcPort

int4

-

dstPort

int4

-

srcNatPort

int4

-

Field

Data type

Extra fields

dstNatPort

int4

-

flags

str

-

proto

str

-

action

str

-

category

str

-

seqno

int8

-

actionFlags

str

-

deviceName

str

-

bytes

int8

-

sentBytes

int8

-

recvBytes

int8

-

pkts

int4

-

srcCountry

str

-

dstCountry

str

-

session_end_reason

str

-

url_filename

str

-

threatid

str

-

severity

str

-

direction

str

-

host

str

-

result

str

-

path

str

-

rawMessage

str

-

hostchain

str

tag

str

Field transformations

Even though all source tables have several features in common, they have some particularities that make it necessary to undergo a set of transformations to harmonize them for the union table. The most common transformations comprise changes in the data type or the application of rules when several columns in the source table feed a single column in the union table. You can find below the detailed list of transformations in each source table. 

Rw ui tabs macro
Rw tab
titleTable 1

firewall.paloalto.config

Field in union table

Field in source table

Field transformation

Data type

Extra fields

eventdate

eventdate


timestamp


timestamp

timestamp


timestamp


recvdate

recvdate


timestamp


machine

machine


str


logType

logType


str


subType

subType


str


serial

serial


str


srcIp

-

ip4(null(''))

ip4


dstIp

-

ip4(null(''))

ip4


srcNatIp

-

ip4(null(''))

ip4


dstNatIp

-

ip4(null(''))

ip4


rule

-

null('')

str


srcUser

-

null('')

str


dstUser

-

null('')

str


app

-

null('')

str


virtSys

vsys


str


srcZone

-

null('')

str


dstZone

-

null('')

str


srcIface

-

null('')

str


dstIface

-

null('')

str


logAction

-

null('')

str


session

-

null('')

str


repCnt

-

int4(null(''))

int4


srcPort

-

int4(null(''))

int4


dstPort

-

int4(null(''))

int4


srcNatPort

srcNatPort


int4


dstNatPort

dstNatPort


int4


flags

-

null('')

str


proto

-

null('')

str


action

-

null('')

str


category

-

null('')

str


seqno

seqno


int8


actionFlags

-

null('')

str


deviceName

device_name


str


bytes

-

int8(null(''))

int8


sentBytes

-

int8(null(''))

int8


recvBytes

-

int8(null(''))

int8


pkts

-

int4(null(''))

int4


srcCountry

-

null('')

str


dstCountry

-

null('')

str


session_end_reason

-

null('')

str


url_filename

url_filename


str


threatid

-

null('')

str


severity

-

null('')

str


direction

-

null('')

str


host

host


str


result

result


str


path

path


str


rawMessage

rawMessage


str


hostchain

hostchain


str

tag

tag


str

Rw tab
titleTable 2

firewall.paloalto.correlation

Field in union table

Field in source table

Field transformation

Data type

Extra fields

eventdate

eventdate


timestamp


timestamp

timestamp


timestamp


recvdate

recvdate


timestamp


machine

machine


str


logType

logType


str


subType

subType


str


serial

serial


str


srcIp

srcIp


ip4


dstIp

-

ip4(null(''))

ip4


srcNatIp

-

ip4(null(''))

ip4


dstNatIp

-

ip4(null(''))

ip4


rule

-

null('')

str


srcUser

srcUser


str


dstUser

-

null('')

str


app

-

null('')

str


virtSys

vsys


str


srcZone

-

null('')

str


dstZone

-

null('')

str


srcIface

-

null('')

str


dstIface

-

null('')

str


logAction

-

null('')

str


session

-

null('')

str


repCnt

-

int4(null(''))

int4


srcPort

-

int4(null(''))

int4


dstPort

-

int4(null(''))

int4


srcNatPort

srcNatPort


int4


dstNatPort

dstNatPort


int4


flags

-

null('')

str


proto

-

null('')

str


action

-

null('')

str


category

-

null('')

str


seqno

-

int8(null(''))

int8


actionFlags

-

null('')

str


deviceName

device_name


str


bytes

-

int8(null(''))

int8


sentBytes

-

int8(null(''))

int8


recvBytes

-

int8(null(''))

int8


pkts

-

int4(null(''))

int4


srcCountry

-

null('')

str


dstCountry

-

null('')

str


session_end_reason

-

null('')

str


url_filename

url_filename


str


threatid

-

null('')

str


severity

-

null('')

str


direction

-

null('')

str


host

-

null('')

str


result

-

null('')

str


path

-

null('')

str


rawMessage

rawMessage


str


hostchain

hostchain


str

tag

tag


str

Rw tab
titleTable 2

firewall.paloalto.globalprotect

Field in union table

Field in source table

Field transformation

Data type

Extra fields

eventdate

eventdate

 

timestamp

timestamp

createdate

 

timestamp

recvdate

recvdate

 

timestamp

machine

machine

 

str

logType

logType

 

str

subType

subType

 

str

serial

serialnumber

 

str

srcIp

srcIp

 

ip4

dstIp

-

Code Block
ip4(null(''))

ip4

srcNatIp

-

Code Block
ip4(null(''))

ip4

dstNatIp

-

Code Block
ip4(null(''))

ip4

rule

-

Code Block
null('')

str

srcUser

srcUser

 

str

dstUser

-

Code Block
null('')

str

app

-

Code Block
null('')

str

virtSys

vsys

 

str

srcZone

-

Code Block
null('')

str

dstZone

-

Code Block
null('')

str

srcIface

-

Code Block
null('')

str

dstIface

-

Code Block
null('')

str

logAction

-

Code Block
null('')

str

session

-

Code Block
null('')

str

repCnt

repeatcnt

Code Block
int4(repeatcnt)

int4

srcPort

-

Code Block
int4(null(''))

int4

dstPort

-

Code Block
int4(null(''))

int4

srcNatPort

srcNatPort

 

int4

dstNatPort

dstNatPort

 

int4

flags

-

Code Block
null('')

str

proto

-

Code Block
null('')

str

action

-

Code Block
null('')

str

category

-

Code Block
null('')

str

seqno

seqno

 

int8

actionFlags

actionflags

 

str

deviceName

machinename

 

str

bytes

-

Code Block
int8(null(''))

int8

sentBytes

-

Code Block
int8(null(''))

int8

recvBytes

-

Code Block
int8(null(''))

int8

pkts

-

Code Block
int4(null(''))

int4

srcCountry

-

Code Block
null('')

str

dstCountry

-

Code Block
null('')

str

session_end_reason

-

Code Block
null('')

str

url_filename

url_filename

 

str

threatid

-

Code Block
null('')

str

severity

-

Code Block
null('')

str

direction

-

Code Block
null('')

str

host

host

 

str

result

-

Code Block
null('')

str

path

-

Code Block
null('')

str

rawMessage

rawMessage

 

str

hostchain

hostchain

 

str

tag

tag

 

str

Rw tab
titleTable 4

firewall.paloalto.hipmatch

Field in union table

Field in source table

Field transformation

Data type

Extra fields

eventdate

eventdate


timestamp


timestamp

createdate


timestamp


recvdate

recvdate


timestamp


machine

machine


str


logType

logType


str


subType

subType


str


serial

serialNumber


str


srcIp

srcIp


ip4


dstIp

-

ip4(null(''))

ip4


srcNatIp

-

ip4(null(''))

ip4


dstNatIp

-

ip4(null(''))

ip4


rule

-

null('')

str


srcUser

srcUser


str


dstUser

-

null('')

str


app

-

null('')

str


virtSys

vsys


str


srcZone

-

null('')

str


dstZone

-

null('')

str


srcIface

-

null('')

str


dstIface

-

null('')

str


logAction

-

null('')

str


session

-

null('')

str


repCnt

repeatCnt

int4(repeatCnt)

int4


srcPort

-

int4(null(''))

int4


dstPort

-

int4(null(''))

int4


srcNatPort

srcNatPort


int4


dstNatPort

dstNatPort


int4


flags

-

null('')

str


proto

-

null('')

str


action

-

null('')

str


category

-

null('')

str


seqno

seqno


int8


actionFlags

actionflags


str


deviceName

device_name


str


bytes

-

int8(null(''))

int8


sentBytes

-

int8(null(''))

int8


recvBytes

-

int8(null(''))

int8


pkts

-

int4(null(''))

int4


srcCountry

-

null('')

str


dstCountry

-

null('')

str


session_end_reason

-

null('')

str


url_filename

url_filename


str


threatid

-

null('')

str


severity

-

null('')

str


direction

-

null('')

str


host

host


str


result

-

null('')

str


path

-

null('')

str


rawMessage

rawMessage


str


hostchain

hostchain


str

tag

tag


str

Rw tab
titleTable 5

firewall.paloalto.system

Field in union table

Field in source table

Field transformation

Data type

Extra fields

eventdate

eventdate


timestamp


timestamp

timestamp


timestamp


recvdate

recvdate


timestamp


machine

machine


str


logType

logType


str


subType

subType


str


serial

serial


str


srcIp

-

1ip4(null(''))

ip4


dstIp

-

1ip4(null(''))

ip4


srcNatIp

-

1ip4(null(''))

ip4


dstNatIp

-

1ip4(null(''))

ip4


rule

-

null('')

str


srcUser

-

null('')

str


dstUser

-

null('')

str


app

-

null('')

str


virtSys

-

null('')

str


srcZone

-

null('')

str


dstZone

-

null('')

str


srcIface

-

null('')

str


dstIface

-

null('')

str


logAction

-

null('')

str


session

-

null('')

str


repCnt

-

int4(null(''))

int4


srcPort

-

int4(null(''))

int4


dstPort

-

int4(null(''))

int4


srcNatPort

srcNatPort


int4


dstNatPort

dstNatPort


int4


flags

-

null('')

str


proto

-

null('')

str


action

-

null('')

str


category

-

null('')

str


seqno

seqno


int8


actionFlags

-

null('')

str


deviceName

device_name


str


bytes

-

int8(null(''))

int8


sentBytes

-

int8(null(''))

int8


recvBytes

-

int8(null(''))

int8


pkts

-

int4(null(''))

int4


srcCountry

-

null('')

str


dstCountry

-

null('')

str


session_end_reason

-

null('')

str


url_filename

url_filename


str


threatid

-

null('')

str


severity

-

null('')

str


direction

-

null('')

str


host

-

null('')

str


result

-

null('')

str


path

-

null('')

str


rawMessage

rawMessage


str


hostchain

hostchain


str

tag

tag


str

Rw tab
titleTable 6

firewall.paloalto.threat

Field in union table

Field in source table

Field transformation

Data type

Extra fields

eventdate

eventdate


timestamp


timestamp

timestamp


timestamp


recvdate

recvdate


timestamp


machine

machine


str


logType

logType


str


subType

subType


str


serial

serial


str


srcIp

srcIp


ip4


dstIp

dstIp


ip4


srcNatIp

srcNatIp


ip4


dstNatIp

dstNatIp


ip4


rule

rule


str


srcUser

srcUser


str


dstUser

dstUser


str


app

app


str


virtSys

virtSys


str


srcZone

srcZone


str


dstZone

dstZone


str


srcIface

srcIface


str


dstIface

dstIface


str


logAction

logAction


str


session

session


str


repCnt

repCnt


int4


srcPort

srcPort


int4


dstPort

dstPort


int4


srcNatPort

srcNatPort


int4


dstNatPort

dstNatPort


int4


flags

flags


str


proto

proto


str


action

action


str


category

category


str


seqno

seqno


int8


actionFlags

actionflags


str


deviceName

deviceName


str


bytes

-

int8(null(''))

int8


sentBytes

-

int8(null(''))

int8


recvBytes

-

int8(null(''))

int8


pkts

-

int4(null(''))

int4


srcCountry

srcloc


str


dstCountry

dstloc


str


session_end_reason

-

null('')

str


url_filename

url_filename


str


threatid

threatid


str


severity

severity


str


direction

direction


str


host

-

null('')

str


result

-

null('')

str


path

-

null('')

str


rawMessage

rawMessage


str


hostchain

hostchain


str

tag

tag


str

Rw tab
titleTable 7

firewall.paloalto.traffic

Field in union table

Field in source table

Field transformation

Data type

Extra fields

eventdate

eventdate

timestamp


timestamp

timestamp

timestamp


recvdate

recvdate

timestamp


machine

machine

str


logType

logType

str


subType

subType

str


serial

serial

str


srcIp

srcIp

ip4


dstIp

dstIp

ip4


srcNatIp

srcNatIp

ip4


dstNatIp

dstNatIp

ip4


rule

rule

str


srcUser

srcUser

str


dstUser

dstUser

str


app

app

str


virtSys

virtSys

str


srcZone

srcZone

str


dstZone

dstZone

str


srcIface

srcIface

str


dstIface

dstIface

str


logAction

logAction

str


session

session

str


repCnt

repCnt

int4


srcPort

srcPort

int4


dstPort

dstPort

int4


srcNatPort

srcNatPort

int4


dstNatPort

dstNatPort

int4


flags

flags

str


proto

proto

str


action

action

str


category

category

str


seqno

seqno

int8


actionFlags

actionFlags

str


deviceName

device_name

str


bytes

bytes

int8


sentBytes

sentBytes

int8


recvBytes

recvBytes

int8


pkts

pkts

int4(pkts)

int4


srcCountry

srcCountry

str


dstCountry

dstCountry

str


session_end_reason

session_end_reason

str


url_filename

url_filename

str


threatid

-

null('')

str


severity

-

null('')

str


direction

-

null('')

str


host

-

null('')

str


result

-

null('')

str


path

-

null('')

str


rawMessage

rawMessage

str


hostchain

hostchain

str

tag

tag

str

Rw tab
titleTable 8

firewall.paloalto.url

Field in union table

Field in source table

Field transformation

Data type

Extra fields

eventdate

eventdate


timestamp


timestamp

timestamp


timestamp


recvdate

recvdate


timestamp


machine

machine


str


logType

logType


str


subType

subType


str


serial

serial


str


srcIp

srcIp


ip4


dstIp

dstIp


ip4


srcNatIp

srcNatIp


ip4


dstNatIp

dstNatIp


ip4


rule

rule


str


srcUser

srcUser


str


dstUser

dstUser


str


app

app


str


virtSys

virtSys


str


srcZone

srcZone


str


dstZone

dstZone


str


srcIface

srcIface


str


dstIface

dstIface


str


logAction

logAction


str


session

session


str


repCnt

repCnt


int4


srcPort

srcPort


int4


dstPort

dstPort


int4


srcNatPort

srcNatPort


int4


dstNatPort

dstNatPort


int4


flags

flags


str


proto

proto


str


action

action


str


category

category


str


seqno

seqno


int8


actionFlags

actionflags


str


deviceName

deviceName


str


bytes

-

int8(null(''))

int8


sentBytes

-

int8(null(''))

int8


recvBytes

-

int8(null(''))

int8


pkts

-

int4(null(''))

int4


srcCountry

srcloc


str


dstCountry

dstloc


str


session_end_reason

-

null('')

str


url_filename

url_filename


str


threatid

threatid


str


severity

severity


str


direction

direction


str


host

-

null('')

str


result

-

null('')

str


path

-

null('')

str


rawMessage

rawMessage


str


hostchain

hostchain


str

tag

tag


str

Rw tab
titleTable 9

firewall.paloalto.userid

Field in union table

Field in source table

Field transformation

Data type

Extra fields

eventdate

eventdate


timestamp


timestamp

timestamp


timestamp


recvdate

recvdate


timestamp


machine

machine


str


logType

logType


str


subType

subType


str


serial

serial


str


srcIp

srcIp


ip4


dstIp

-

ip4(null(''))

ip4


srcNatIp

-

ip4(null(''))

ip4


dstNatIp

-

ip4(null(''))

ip4


rule

-

null('')

str


srcUser

srcUser


str


dstUser

-

null('')

str


app

-

null('')

str


virtSys

virtSys


str


srcZone

-

null('')

str


dstZone

-

null('')

str


srcIface

-

null('')

str


dstIface

-

null('')

str


logAction

-

null('')

str


session

-

null('')

str


repCnt

-

int4(null(''))

int4


srcPort

srcPort


int4


dstPort

dstPort


int4


srcNatPort

srcNatPort


int4


dstNatPort

dstNatPort


int4


flags

-

null('')

str


proto

-

null('')

str


action

-

null('')

str


category

-

null('')

str


seqno

seqno


int8


actionFlags

actionFlags


str


deviceName

device_name


str


bytes

-

int8(null(''))

int8


sentBytes

-

int8(null(''))

int8


recvBytes

-

int8(null(''))

int8


pkts

-

int4(null(''))

int4


srcCountry

-

null('')

str


dstCountry

-

null('')

str


session_end_reason

-

null('')

str


url_filename

url_filename


str


threatid

-

null('')

str


severity

-

null('')

str


direction

-

null('')

str


host

-

null('')

str


result

-

null('')

str


path

-

null('')

str


rawMessage

rawMessage


str


hostchain

hostchain


str

tag

tag


str