/
firewall.paloalto.all

firewall.paloalto.all

Introduction

This union table collects information from a set of tables that contain events from Palo Alto Network's firewalls. 

Source tables

The information displayed is extracted from the following tables: 

  • firewall.paloalto.traffic
  • firewall.paloalto.system
  • firewall.paloalto.config
  • firewall.paloalto.threat
  • firewall.paloalto.url
  • firewall.paloalto.userid
  • firewall.paloalto.correlation
  • firewall.paloalto.hipmatch

Table structure

This is the set of columns displayed by this union table, which is the result of the collection of columns present in all source tables: 

Extra columns

Fields marked as Extra in the table below are not shown by default in data tables and need to be explicitly requested in the query. You can find them marked as Extra when you perform a query so they can be easily identified. Learn more about this in Selecting unrevealed columns.

Field

Data type

Extra fields

eventdate

timestamp


timestamp

timestamp


recvdate

timestamp


machine

str


logType

str


subType

str


serial

str


srcIp

ip4


dstIp

ip4


srcNatIp

ip4


dstNatIp

ip4


rule

str


srcUser

str


dstUser

str


app

str


virtSys

str


srcZone

str


dstZone

str


srcIface

str


dstIface

str


logAction

str


session

str


repCnt

int4


srcPort

int4


dstPort

int4


srcNatPort

int4


dstNatPort

int4


Field

Data type

Extra fields

flags

str


proto

str


action

str


category

str


seqno

int8


actionFlags

str


deviceName

str


bytes

int8


sentBytes

int8


recvBytes

int8


pkts

int4


srcCountry

str


dstCountry

str


session_end_reason

str


url_filename

str


threatid

str


severity

str


direction

str


host

str


result

str


path

str


rawMessage

str


hostchain

str

tag

str

Field transformations

Even though all source tables have several features in common, they have some particularities that make it necessary to undergo a set of transformations to harmonize them for the union table. The most common transformations comprise changes in the data type or the application of rules when several columns in the source table feed a single column in the union table. You can find below the detailed list of transformations in each source table. 

Related content

firewall.paloalto.all
firewall.paloalto.all
More like this
firewall.paloalto
firewall.paloalto
More like this
firewall.all.ips
firewall.all.ips
More like this
firewall.all.cpu
firewall.all.cpu
More like this
firewall.all.traffic
firewall.all.traffic
More like this
firewall.paloalto
firewall.paloalto
More like this