cef0.paloAltoNetworks
Introduction
The tags beginning with cef0.paloAltoNetworks
identify events in CEF format generated by Palo Alto.
Tag structure
Events in CEF format don’t have a specific tag structure, as explained in Technologies supported in CEF syslog format. They are always sent to a table with the structure cef0.deviceVendor.deviceProduct.
In this case, the valid data tables are:
Tags | Data tables |
---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
How is the data sent to Devo?
Learn more about CEF syslog format and how Devo tags these events in Technologies supported in CEF syslog format.
Table structure
These are the fields displayed in this table:
cef0.paloAltoNetworks.cortexXdr
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
| Â | Â |
hostname |
| Â | Â |
priorityCode |
| Â | Â |
cefTag |
| Â | Â |
cefVersion |
| Â | Â |
embDeviceVendor |
| Â | Â |
embDeviceProduct |
| Â | Â |
deviceVersion |
| Â | Â |
signatureID |
| Â | Â |
name |
| Â | Â |
severity |
| Â | Â |
_cefVer |
| Â | Â |
act |
| Â | Â |
app |
| Â | Â |
cat |
| Â | Â |
cs1Label |
| Â | Â |
cs1 |
| Â | Â |
cs2Label |
| Â | Â |
cs2 |
| Â | Â |
cs3Label |
| Â | Â |
cs3 |
| Â | Â |
cs4Label |
| Â | Â |
cs4 |
| Â | Â |
cs5Label |
| Â | Â |
cs5 |
| Â | Â |
cs6Label |
| Â | Â |
cs6 |
| Â | Â |
dst |
| Â | Â |
dpt |
| Â | Â |
end |
| Â | Â |
deviceFacility |
| Â | Â |
externalId |
| Â | Â |
fileHash |
| Â | Â |
filePath |
| Â | Â |
request |
| Â | Â |
shost |
| Â | Â |
src |
| Â | Â |
spt |
| Â | Â |
suser |
| Â | Â |
CSPaccountname |
| Â | Â |
cgoSha256 |
| Â | Â |
incident |
| Â | Â |
initiatorPath |
| Â | Â |
initiatorSha256 |
| Â | Â |
osParentCmd |
| Â | Â |
osParentName |
| Â | Â |
osParentSha256 |
| Â | Â |
osParentSignature |
| Â | Â |
osParentSigner |
| Â | Â |
targetprocesscmd |
| Â | Â |
targetprocessname |
| Â | Â |
targetprocesssha256 |
| Â | Â |
targetprocesssignature |
| Â | Â |
tenantCDLid |
| Â | Â |
tenantname |
| Â | Â |
hostchain |
|  | ✓ |
tag |
| cefTag | ✓ |
rawMessage |
|  | ✓ |
cef0.paloAltoNetworks.cortexXdrAgent
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
| Â | Â |
hostname |
| Â | Â |
priorityCode |
| Â | Â |
cefTag |
| Â | Â |
cefVersion |
| Â | Â |
embDeviceVendor |
| Â | Â |
embDeviceProduct |
| Â | Â |
deviceVersion |
| Â | Â |
signatureID |
| Â | Â |
name |
| Â | Â |
severity |
| Â | Â |
dvchost |
| Â | Â |
shost |
| Â | Â |
cat |
| Â | Â |
end |
| Â | Â |
rt |
| Â | Â |
cs1Label |
| Â | Â |
cs1 |
| Â | Â |
cs2Label |
| Â | Â |
cs2 |
| Â | Â |
cs3Label |
| Â | Â |
cs3 |
| Â | Â |
cs4Label |
| Â | Â |
cs4 |
| Â | Â |
msg |
| Â | Â |
tenantname |
| Â | Â |
tenantCDLid |
| Â | Â |
CSPaccountname |
| Â | Â |
hostchain |
|  | ✓ |
tag |
| cefTag | ✓ |
rawMessage |
|  | ✓ |
cef0.paloAltoNetworks.cortexXsoar
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
| Â | Â |
machine |
| Â | Â |
priority_code |
| Â | Â |
cef_tag |
| Â | Â |
cef_version |
| Â | Â |
emb_device_vendor |
| Â | Â |
emb_device_product |
| Â | Â |
device_version |
| Â | Â |
signature_id |
| Â | Â |
name |
| Â | Â |
severity |
| Â | Â |
device_custom_string_1_label |
| Â | Â |
device_custom_string_1 |
| Â | Â |
device_custom_string_2_label |
| Â | Â |
device_custom_string_2 |
| Â | Â |
device_custom_string_3_label |
| Â | Â |
device_custom_string_3 |
| Â | Â |
device_custom_string_4_label |
| Â | Â |
device_custom_string_4 |
| Â | Â |
end |
| Â | Â |
external_id |
| Â | Â |
message |
| Â | Â |
source_username |
| Â | Â |
cs_paccountname |
| Â | Â |
tenant_cd_lid |
| Â | Â |
tenantname |
| Â | Â |
hostchain |
|  | ✓ |
tag |
| cef_tag | ✓ |
rawMessage |
|  | ✓ |
cef0.paloAltoNetworks.lf
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
| Â | Â |
hostname |
| Â | Â |
priorityCode |
| Â | Â |
cefTag |
| Â | Â |
cefVersion |
| Â | Â |
embDeviceVendor |
| Â | Â |
embDeviceProduct |
| Â | Â |
deviceVersion |
| Â | Â |
signatureID |
| Â | Â |
name |
| Â | Â |
severity |
| Â | Â |
_cefVer |
| Â | Â |
act |
| Â | Â |
app |
| Â | Â |
cat |
| Â | Â |
c6a1Label |
| Â | Â |
c6a1 |
| Â | Â |
cn1Label |
| Â | Â |
cn1 |
| Â | Â |
cn2Label |
| Â | Â |
cn2 |
| Â | Â |
cn3Label |
| Â | Â |
cn3 |
| Â | Â |
cnt |
| Â | Â |
cs1Label |
| Â | Â |
cs1 |
| Â | Â |
cs2Label |
| Â | Â |
cs2 |
| Â | Â |
cs3Label |
| Â | Â |
cs3 |
| Â | Â |
cs4Label |
| Â | Â |
cs4 |
| Â | Â |
cs5Label |
| Â | Â |
cs5 |
| Â | Â |
cs6Label |
| Â | Â |
cs6 |
| Â | Â |
destinationServiceName |
| Â | Â |
destinationTranslatedAddress |
| Â | Â |
destinationTranslatedPort |
| Â | Â |
deviceExternalId |
| Â | Â |
deviceInboundInterface |
| Â | Â |
deviceOutboundInterface |
| Â | Â |
dhost |
| Â | Â |
dst |
| Â | Â |
dpt |
| Â | Â |
duser |
| Â | Â |
dvchost |
| Â | Â |
end |
| Â | Â |
externalId |
| Â | Â |
fileId |
| Â | Â |
fname |
| Â | Â |
in |
| Â | Â |
msg |
| Â | Â |
out |
| Â | Â |
proto |
| Â | Â |
reason |
| Â | Â |
requestClientApplication |
| Â | Â |
requestMethod |
| Â | Â |
requestContext |
| Â | Â |
request |
| Â | Â |
rt |
| Â | Â |
dtz |
| Â | Â |
shost |
| Â | Â |
sourceTranslatedAddress |
| Â | Â |
sourceTranslatedPort |
| Â | Â |
src |
| Â | Â |
spt |
| Â | Â |
start |
| Â | Â |
suser |
| Â | Â |
flexString2 |
| Â | Â |
flexString2Label |
| Â | Â |
PanOSAttemptedGateways |
| Â | Â |
PanOSAuthMethod |
| Â | Â |
PanOSBytes |
| Â | Â |
PanOSChunksReceived |
| Â | Â |
PanOSChunksSent |
| Â | Â |
PanOSChunksTotal |
| Â | Â |
PanOSConfigVersion |
| Â | Â |
PanOSConnectionError |
| Â | Â |
PanOSConnectionErrorID |
| Â | Â |
PanOSConnectionMethod |
| Â | Â |
PanOSContainerID |
| Â | Â |
PanOSContainerName |
| Â | Â |
PanOSContainerNameSpace |
| Â | Â |
PanOSContentVersion |
| Â | Â |
PanOSCountOfRepeats |
| Â | Â |
PanOSDescription |
| Â | Â |
PanOSDestinationDeviceCategory |
| Â | Â |
PanOSDestinationDeviceHost |
| Â | Â |
PanOSDestinationDeviceMac |
| Â | Â |
PanOSDestinationDeviceModel |
| Â | Â |
PanOSDestinationDeviceOSFamily |
| Â | Â |
PanOSDestinationDeviceOSVersion |
| Â | Â |
PanOSDestinationDeviceProfile |
| Â | Â |
PanOSDestinationDeviceVendor |
| Â | Â |
PanOSDestinationDynamicAddressGroup |
| Â | Â |
PanOSDestinationEDL |
| Â | Â |
PanOSDestinationLocation |
| Â | Â |
PanOSDestinationUUID |
| Â | Â |
PanOSDeviceGroup |
| Â | Â |
PanOSDeviceName |
| Â | Â |
PanOSDeviceSN |
| Â | Â |
PanOSDGHierarchyLevel1 |
| Â | Â |
PanOSDGHierarchyLevel2 |
| Â | Â |
PanOSDGHierarchyLevel3 |
| Â | Â |
PanOSDGHierarchyLevel4 |
| Â | Â |
PanOSDynamicUserGroupName |
| Â | Â |
PanOSEndpointAssociationID |
| Â | Â |
PanOSEndpointDeviceName |
| Â | Â |
PanOSEndpointOSType |
| Â | Â |
PanOSEndpointOSVersion |
| Â | Â |
PanOSEndpointSerialNumber |
| Â | Â |
PanOSEndpointSN |
| Â | Â |
PanOSEventDescription |
| Â | Â |
PanOSEventIDValue |
| Â | Â |
PanOSEventResult |
| Â | Â |
PanOSEventStatus |
| Â | Â |
PanOSEventTime |
| Â | Â |
PanOSGateway |
| Â | Â |
PanOSGatewayPriority |
| Â | Â |
PanOSGatewaySelectionType |
| Â | Â |
PanOSGlobalProtectClientVersion |
| Â | Â |
PanOSGlobalProtectGatewayLocation |
| Â | Â |
PanOSGPHostID |
| Â | Â |
PanOSHASessionOwner |
| Â | Â |
PanOSHipMatchType |
| Â | Â |
PanOSHostID |
| Â | Â |
PanOSHTTP2Connection |
| Â | Â |
PanOSHTTPHeaders |
| Â | Â |
PanOSIMEI |
| Â | Â |
PanOSIMSI |
| Â | Â |
PanOSInlineMLVerdict |
| Â | Â |
PanOSLinkChangeCount |
| Â | Â |
PanOSLinkSwitches |
| Â | Â |
PanOSLoginDuration |
| Â | Â |
PanOSNSSAINetworkSliceDifferentiator |
| Â | Â |
PanOSNSSAINetworkSliceType |
| Â | Â |
PanOSPacketsReceived |
| Â | Â |
PanOSPacketsSent |
| Â | Â |
PanOSParentSessionID |
| Â | Â |
PanOSParentStarttime |
| Â | Â |
PanOSPortal |
| Â | Â |
PanOSPrivateIPv4 |
| Â | Â |
PanOSPrivateIPv6 |
| Â | Â |
PanOSPublicIPv4 |
| Â | Â |
PanOSPublicIPv6 |
| Â | Â |
PanOSQuarantineReason |
| Â | Â |
PanOSReferer |
| Â | Â |
PanOSRuleUUID |
| Â | Â |
PanOSSDWANCluster |
| Â | Â |
PanOSSDWANClusterType |
| Â | Â |
PanOSSDWANDeviceType |
| Â | Â |
PanOSSDWANPolicyName |
| Â | Â |
PanOSSDWANSite |
| Â | Â |
PanOSSequenceNo |
| Â | Â |
PanOSSessionStartTime |
| Â | Â |
PanOSSigFlags |
| Â | Â |
PanOSSource |
| Â | Â |
PanOSSourceDeviceCategory |
| Â | Â |
PanOSSourceDeviceHost |
| Â | Â |
PanOSSourceDeviceMac |
| Â | Â |
PanOSSourceDeviceModel |
| Â | Â |
PanOSSourceDeviceOSFamily |
| Â | Â |
PanOSSourceDeviceOSVersion |
| Â | Â |
PanOSSourceDeviceProfile |
| Â | Â |
PanOSSourceDeviceVendor |
| Â | Â |
PanOSSourceDynamicAddressGroup |
| Â | Â |
PanOSSourceEDL |
| Â | Â |
PanOSSourceLocation |
| Â | Â |
PanOSSourceRegion |
| Â | Â |
PanOSSourceUser |
| Â | Â |
PanOSSourceUserName |
| Â | Â |
PanOSSourceUUID |
| Â | Â |
PanOSSSLResponseTime |
| Â | Â |
PanOSStage |
| Â | Â |
PanOSTag |
| Â | Â |
PanOSTemplate |
| Â | Â |
PanOSThreatID |
| Â | Â |
PanOSThreatCategory |
| Â | Â |
PanOSTimeGeneratedHighResolution |
| Â | Â |
PanOSTimestampDeviceIdentification |
| Â | Â |
PanOSTunnel |
| Â | Â |
PanOSTunnelType |
| Â | Â |
PanOSUGFlags |
| Â | Â |
PanOSURLCategoryList |
| Â | Â |
PanOSURLCounter |
| Â | Â |
PanOSUserIdentifiedBySource |
| Â | Â |
PanOSVirtualSystem |
| Â | Â |
PanOSVirtualSystemID |
| Â | Â |
PanOSVirtualSystemName |
| Â | Â |
PanOSXForwardedFor |
| Â | Â |
PanOSXForwardedForIP |
| Â | Â |
hostchain |
|  | ✓ |
tag |
| cefTag | ✓ |
rawMessage |
|  | ✓ |
cef0.paloAltoNetworks.paloAltoNetworksCortexXsoar
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
| Â | Â |
hostname |
| Â | Â |
priorityCode |
| Â | Â |
cefTag |
| Â | Â |
cefVersion |
| Â | Â |
embDeviceVendor |
| Â | Â |
embDeviceProduct |
| Â | Â |
deviceVersion |
| Â | Â |
signatureID |
| Â | Â |
name |
| Â | Â |
severity |
| Â | Â |
_cefVer |
| Â | Â |
cs1Label |
| Â | Â |
cs1 |
| Â | Â |
cs2Label |
| Â | Â |
cs2 |
| Â | Â |
suser |
| Â | Â |
startTime |
| Â | Â |
hostchain |
|  | ✓ |
tag |
| cefTag | ✓ |
rawMessage |
|  | ✓ |
cef0.paloAltoNetworks.panOs
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
| Â | Â |
hostname |
| Â | Â |
priorityCode |
| Â | Â |
cefTag |
| Â | Â |
cefVersion |
| Â | Â |
embDeviceVendor |
| Â | Â |
embDeviceProduct |
| Â | Â |
deviceVersion |
| Â | Â |
signatureID |
| Â | Â |
name |
| Â | Â |
severity |
| Â | Â |
_cefVer |
| Â | Â |
act |
| Â | Â |
app |
| Â | Â |
cat |
| Â | Â |
cn1Label |
| Â | Â |
cn1 |
| Â | Â |
cn2Label |
| Â | Â |
cn2 |
| Â | Â |
cn3Label |
| Â | Â |
cn3 |
| Â | Â |
cnt |
| Â | Â |
cs1Label |
| Â | Â |
cs1 |
| Â | Â |
cs2Label |
| Â | Â |
cs2 |
| Â | Â |
cs3Label |
| Â | Â |
cs3 |
| Â | Â |
cs4Label |
| Â | Â |
cs4 |
| Â | Â |
cs5Label |
| Â | Â |
cs5 |
| Â | Â |
cs6Label |
| Â | Â |
cs6 |
| Â | Â |
destinationTranslatedAddress |
| Â | Â |
destinationTranslatedPort |
| Â | Â |
deviceExternalId |
| Â | Â |
deviceInboundInterface |
| Â | Â |
deviceOutboundInterface |
| Â | Â |
dst |
| Â | Â |
duser |
| Â | Â |
dvchost |
| Â | Â |
dvc |
| Â | Â |
externalId |
| Â | Â |
filePath |
| Â | Â |
fileType |
| Â | Â |
fname |
| Â | Â |
in |
| Â | Â |
msg |
| Â | Â |
out |
| Â | Â |
proto |
| Â | Â |
request |
| Â | Â |
rt |
| Â | Â |
sourceTranslatedAddress |
| Â | Â |
sourceTranslatedPort |
| Â | Â |
spt |
| Â | Â |
src |
| Â | Â |
start |
| Â | Â |
suser |
| Â | Â |
agt |
| Â | Â |
ahost |
| Â | Â |
aid |
| Â | Â |
arcSightEventPath |
| Â | Â |
art |
| Â | Â |
assetCriticality |
| Â | Â |
at |
| Â | Â |
atz |
| Â | Â |
av |
| Â | Â |
catdt |
| Â | Â |
categoryBehavior |
| Â | Â |
categoryDeviceGroup |
| Â | Â |
categoryObject |
| Â | Â |
categoryOutcome |
| Â | Â |
customerID |
| Â | Â |
customerURI |
| Â | Â |
destinationAssetId |
| Â | Â |
destinationGeoCountryCode |
| Â | Â |
destinationGeoLocationInfo |
| Â | Â |
destinationGeoPostalCode |
| Â | Â |
destinationGeoRegionCode |
| Â | Â |
destinationZoneExternalID |
| Â | Â |
destinationZoneID |
| Â | Â |
destinationZoneURI |
| Â | Â |
deviceAssetId |
| Â | Â |
deviceFacility |
| Â | Â |
deviceSeverity |
| Â | Â |
deviceZoneID |
| Â | Â |
deviceZoneURI |
| Â | Â |
dlat |
| Â | Â |
dlong |
| Â | Â |
dpt |
| Â | Â |
dtz |
| Â | Â |
eventAnnotationAuditTrail |
| Â | Â |
eventAnnotationEndTime |
| Â | Â |
eventAnnotationEventId |
| Â | Â |
eventAnnotationFlags |
| Â | Â |
eventAnnotationManagerReceiptTime |
| Â | Â |
eventAnnotationModificationTime |
| Â | Â |
eventAnnotationStageID |
| Â | Â |
eventAnnotationStageUpdateTime |
| Â | Â |
eventAnnotationStageURI |
| Â | Â |
eventAnnotationVersion |
| Â | Â |
eventId |
| Â | Â |
flexNumber1 |
| Â | Â |
flexNumber1Label |
| Â | Â |
flexString1 |
| Â | Â |
flexString1Label |
| Â | Â |
flexString2 |
| Â | Â |
flexString2Label |
| Â | Â |
generatorID |
| Â | Â |
locality |
| Â | Â |
modelConfidence |
| Â | Â |
mrt |
| Â | Â |
priority |
| Â | Â |
relevance |
| Â | Â |
slat |
| Â | Â |
slong |
| Â | Â |
sourceAssetId |
| Â | Â |
sourceGeoCountryCode |
| Â | Â |
sourceGeoLocationInfo |
| Â | Â |
sourceGeoPostalCode |
| Â | Â |
sourceGeoRegionCode |
| Â | Â |
sourceTranslatedZoneExternalID |
| Â | Â |
sourceTranslatedZoneID |
| Â | Â |
sourceTranslatedZoneURI |
| Â | Â |
sourceZoneExternalID |
| Â | Â |
sourceZoneID |
| Â | Â |
sourceZoneURI |
| Â | Â |
type |
| Â | Â |
tag |
| cefTag | ✓ |
rawMessage |
|  | ✓ |
hostchain |
|  | ✓ |
cef0.paloaltonetworks.panwiot
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
| Â | Â |
hostname |
| Â | Â |
priority_code |
| Â | Â |
cef_tag |
| Â | Â |
cef_version |
| Â | Â |
emb_device_vendor |
| Â | Â |
emb_device_product |
| Â | Â |
device_version |
| Â | Â |
signature_id |
| Â | Â |
name |
| Â | Â |
severity |
| Â | Â |
device_custom_string_1_label |
| Â | Â |
device_custom_string_1 |
| Â | Â |
device_custom_string_2_label |
| Â | Â |
device_custom_string_2 |
| Â | Â |
device_custom_string_3_label |
| Â | Â |
device_custom_string_3 |
| Â | Â |
device_custom_string_4_label |
| Â | Â |
device_custom_string_4 |
| Â | Â |
device_hostname |
| Â | Â |
device_ip |
| Â | Â |
device_mac |
| Â | Â |
device_custom_string_10 |
| Â | Â |
device_custom_string_10_label |
| Â | Â |
device_custom_string_15 |
| Â | Â |
device_custom_string_15_label |
| Â | Â |
device_custom_string_16 |
| Â | Â |
device_custom_string_16_label |
| Â | Â |
device_custom_string_17 |
| Â | Â |
device_custom_string_17_label |
| Â | Â |
device_custom_string_22 |
| Â | Â |
device_custom_string_22_label |
| Â | Â |
device_custom_string_44 |
| Â | Â |
device_custom_string_44_label |
| Â | Â |
device_custom_string_7 |
| Â | Â |
device_custom_string_7_label |
| Â | Â |
device_custom_string_8 |
| Â | Â |
device_custom_string_8_label |
| Â | Â |
device_custom_string_9 |
| Â | Â |
device_custom_string_9_label |
| Â | Â |
hostchain |
|  | ✓ |
tag |
| cef_tag | ✓ |
rawMessage |
|  | ✓ |