---
title: "sase.paloalto"
canonical: "https://docs.devo.com/space/latest/245596181/sase.paloalto"
format: markdown
---
> Macro (toc)

## Introduction

Tags beginning with `sase.paloalto` identify events generated by Prisma SASE belonging to [Paloalto](https://www.paloaltonetworks.com/).

## Valid tags and data tables

The full tag must have at least 4 levels. The first two are fixed as** **`sase.paloalto`. The third level identifies the product module, the fourth indicates the type of events sent and the rest of them indicate the event subtypes.

These are the valid tags and corresponding data tables that will receive the parsers' data:

| **Product / Service** | **Tags** | **Data tables** |
| --- | --- | --- |
| Prisma SASE | `sase.paloalto.prisma_access.threat.leef` | `sase.paloalto.prisma_access` |
| `sase.paloalto.prisma_access.traffic.leef` |
| `sase.paloalto.prisma_access.globalprotect.leef` |
| `sase.paloalto.prisma_access.globalprotect.leef` | `sase.paloalto.prisma_access.globalprotect` |
| `sase.paloalto.prisma_access.threat.leef` | `sase.paloalto.prisma_access.threat` |
| `sase.paloalto.prisma_access.traffic.leef` | `sase.paloalto.prisma_access.traffic` |
| `sase.paloalto.prisma_cloud.audit` | `sase.paloalto.prisma_cloud.audit` |
| `sase.paloalto.prisma_cloud.cwp` | `sase.paloalto.prisma_cloud.cwp` |
| `sase.paloalto.prisma_saas.activity_monitoring` | `sase.paloalto.prisma_saas.activity_monitoring` |
| `sase.paloalto.prisma_saas.admin_audit` | `sase.paloalto.prisma_saas.admin_audit` |
| `sase.paloalto.prisma_saas.incident` | `sase.paloalto.prisma_saas.incident` |
| `sase.paloalto.prisma_saas.invalid` | `sase.paloalto.prisma_saas.invalid` |
| `sase.paloalto.prisma_saas.other` | `sase.paloalto.prisma_saas.other` |
| `sase.paloalto.prisma_saas.policy_violation` | `sase.paloalto.prisma_saas.policy_violation` |
| `sase.paloalto.prisma_saas.remediation` | `sase.paloalto.prisma_saas.remediation` |

For more information, read more [About Devo tags](https://docs.devo.com/space/latest/95126204).

## Table structure

These are the fields displayed in these tables:

> Macro (rw-ui-tabs-macro)
> 
> > Macro (rw-tab)
> 
> - [sase.paloalto.prisma_access](https://docs.devo.com/space/latest/245596181#sase.paloalto.prisma_access)
> - [sase.paloalto.prisma_access.globalprotect](https://docs.devo.com/space/latest/245596181#sase.paloalto.prisma_access.globalprotect)
> - [sase.paloalto.prisma_access.threat](https://docs.devo.com/space/latest/245596181#sase.paloalto.prisma_access.threat)
> - [sase.paloalto.prisma_access.traffic](https://docs.devo.com/space/latest/245596181#sase.paloalto.prisma_access.traffic)
> 
> ### sase.paloalto.prisma_access
> 
> | **Field** | **Type** | **Source field name** | ***Extra***** fields** |
> | --- | --- | --- | --- |
> | *eventdate* | `timestamp` |  |  |
> | *subtype* | `str` | *vsubtype* |  |
> | *hostname* | `str` |  |  |
> | *leefVer* | `str` |  |  |
> | *vendor* | `str` |  |  |
> | *product* | `str` |  |  |
> | *version* | `str` |  |  |
> | *eventID* | `str` |  |  |
> | *log_time* | `timestamp` |  |  |
> | *log_source_id* | `str` |  |  |
> | *log_type__value* | `str` |  |  |
> | *sub_type__value* | `str` |  |  |
> | *config_version__value* | `str` |  |  |
> | *time_generated* | `timestamp` |  |  |
> | *source_ip__value* | `ip4` |  |  |
> | *dest_ip__value* | `ip4` |  |  |
> | *nat_source__value* | `ip4` |  |  |
> | *nat_dest__value* | `ip4` |  |  |
> | *rule_matched* | `str` |  |  |
> | *source_user* | `str` |  |  |
> | *dest_user* | `str` |  |  |
> | *app* | `str` |  |  |
> | *vsys* | `str` |  |  |
> | *from_zone* | `str` |  |  |
> | *to_zone* | `str` |  |  |
> | *inbound_if__value* | `str` |  |  |
> | *outbound_if__value* | `str` |  |  |
> | *log_set* | `str` |  |  |
> | *session_id* | `str` |  |  |
> | *count_of_repeats* | `int4` |  |  |
> | *source_port* | `int4` |  |  |
> | *dest_port* | `int4` |  |  |
> | *nat_source_port* | `int4` |  |  |
> | *nat_dest_port* | `int4` |  |  |
> | *protocol__value* | `str` |  |  |
> | *sequence_no* | `int8` |  |  |
> | *source_location* | `str` |  |  |
> | *dest_location* | `str` |  |  |
> | *dg_hier_level_1* | `int4` |  |  |
> | *dg_hier_level_2* | `int4` |  |  |
> | *dg_hier_level_3* | `int4` |  |  |
> | *dg_hier_level_4* | `int4` |  |  |
> | *vsys_name* | `str` |  |  |
> | *log_source_name* | `str` |  |  |
> | *source_uuid* | `str` |  |  |
> | *dest_uuid* | `str` |  |  |
> | *tunnelid_imsi* | `str` |  |  |
> | *monitor_tag_imei* | `str` |  |  |
> | *parent_session_id* | `str` |  |  |
> | *parent_start_time* | `timestamp` |  |  |
> | *tunnel__value* | `str` |  |  |
> | *rule_matched_uuid* | `str` |  |  |
> | *http2_connection* | `str` |  |  |
> | *dynusergroup_name* | `str` |  |  |
> | *xff_ip__value* | `ip4` |  |  |
> | *source_device_category* | `str` |  |  |
> | *source_device_profile* | `str` |  |  |
> | *source_device_model* | `str` |  |  |
> | *source_device_vendor* | `str` |  |  |
> | *source_device_osfamily* | `str` |  |  |
> | *source_device_osversion* | `str` |  |  |
> | *source_device_host* | `str` |  |  |
> | *source_device_mac* | `str` |  |  |
> | *dest_device_category* | `str` |  |  |
> | *dest_device_profile* | `str` |  |  |
> | *dest_device_model* | `str` |  |  |
> | *dest_device_vendor* | `str` |  |  |
> | *dest_device_osfamily* | `str` |  |  |
> | *dest_device_osversion* | `str` |  |  |
> | *dest_device_host* | `str` |  |  |
> | *dest_device_mac* | `str` |  |  |
> | *container_id* | `str` |  |  |
> | *pod_namespace* | `str` |  |  |
> | *pod_name* | `str` |  |  |
> | *source_edl* | `str` |  |  |
> | *dest_edl* | `str` |  |  |
> | *host_id* | `str` |  |  |
> | *endpoint_serial_number* | `str` |  |  |
> | *source_dynamic_address_group* | `str` |  |  |
> | *dest_dynamic_address_group* | `str` |  |  |
> | *time_generated_high_res* | `timestamp` |  |  |
> | *nssai_network_slice_type__value* | `str` |  |  |
> | *vsys_id* | `str` |  |  |
> | *dev_time_format* | `str` |  |  |
> | *action__value* | `str` |  |  |
> | *file_name* | `str` |  |  |
> | *vendor_severity__value* | `str` |  |  |
> | *direction_of_attack__value* | `str` |  |  |
> | *content_type* | `str` |  |  |
> | *pcap_id* | `str` |  |  |
> | *file_sha_256* | `str` |  |  |
> | *cloud* | `str` |  |  |
> | *url_idx* | `int4` |  |  |
> | *file_type* | `str` |  |  |
> | *sender_of_virus* | `str` |  |  |
> | *subject_of_email* | `str` |  |  |
> | *recipient_of_virus* | `str` |  |  |
> | *report_id* | `str` |  |  |
> | *http_method__value* | `str` |  |  |
> | *threat_category__value* | `str` |  |  |
> | *inline_ml_verdict__value* | `str` |  |  |
> | *content_version* | `str` |  |  |
> | *sig_flags* | `str` |  |  |
> | *domain_edl* | `str` |  |  |
> | *partial_hash* | `str` |  |  |
> | *app_category* | `str` |  |  |
> | *container_of_app* | `str` |  |  |
> | *risk_of_app* | `str` |  |  |
> | *app_sub_category* | `str` |  |  |
> | *technology_of_app* | `str` |  |  |
> | *is_captive_portal* | `str` |  |  |
> | *cloud_hostname* | `str` |  |  |
> | *cloud_reportid* | `str` |  |  |
> | *customer_id* | `str` |  |  |
> | *dest_device_class* | `str` |  |  |
> | *dest_device_os* | `str` |  |  |
> | *dest_user_info__domain* | `str` |  |  |
> | *dest_user_info__name* | `str` |  |  |
> | *dest_user_info__uuid* | `str` |  |  |
> | *file_url* | `str` |  |  |
> | *inbound_if_details__port* | `str` |  |  |
> | *inbound_if_details__slot* | `str` |  |  |
> | *inbound_if_details__type__value* | `str` |  |  |
> | *inbound_if_details__unit* | `str` |  |  |
> | *is_client_to_server* | `str` |  |  |
> | *is_container* | `str` |  |  |
> | *is_decrypted* | `str` |  |  |
> | *is_decrypt_mirror* | `str` |  |  |
> | *is_dup_log* | `str` |  |  |
> | *is_encrypted* | `str` |  |  |
> | *is_ipv6* | `str` |  |  |
> | *is_mptcp_on* | `str` |  |  |
> | *is_non_std_dest_port* | `str` |  |  |
> | *is_packet_capture* | `str` |  |  |
> | *is_phishing* | `str` |  |  |
> | *is_prisma_branch* | `str` |  |  |
> | *is_prisma_mobile* | `str` |  |  |
> | *is_proxy* | `str` |  |  |
> | *is_recon_excluded* | `str` |  |  |
> | *is_saas_app* | `str` |  |  |
> | *is_server_to_client* | `str` |  |  |
> | *is_source_x_fwded* | `str` |  |  |
> | *is_sym_return* | `str` |  |  |
> | *is_transaction* | `str` |  |  |
> | *is_tunnel_inspected* | `str` |  |  |
> | *is_url_denied* | `str` |  |  |
> | *location* | `str` |  |  |
> | *is_exported* | `str` |  |  |
> | *is_forwarded* | `str` |  |  |
> | *log_source* | `str` |  |  |
> | *log_source_tz_offset* | `str` |  |  |
> | *is_nat* | `str` |  |  |
> | *non_standard_dest_port* | `str` |  |  |
> | *outbound_if_details__port* | `str` |  |  |
> | *outbound_if_details__slot* | `str` |  |  |
> | *outbound_if_details__type__value* | `str` |  |  |
> | *outbound_if_details__unit* | `str` |  |  |
> | *pcap* | `str` |  |  |
> | *payload_protocol_id* | `str` |  |  |
> | *sanctioned_state_of_app* | `str` |  |  |
> | *source_device_class* | `str` |  |  |
> | *source_device_os* | `str` |  |  |
> | *source_user_info__domain* | `str` |  |  |
> | *source_user_info__name* | `str` |  |  |
> | *source_user_info__uuid* | `str` |  |  |
> | *threat_name* | `str` |  |  |
> | *threat_name_firewall* | `str` |  |  |
> | *tunneled_app* | `str` |  |  |
> | *url_domain* | `str` |  |  |
> | *users* | `str` |  |  |
> | *verdict__value* | `str` |  |  |
> | *severity* | `str` |  |  |
> | *bytes_total* | `int8` |  |  |
> | *bytes_sent* | `int8` |  |  |
> | *bytes_received* | `int8` |  |  |
> | *packets_total* | `int8` |  |  |
> | *session_start_time* | `timestamp` |  |  |
> | *total_time_elapsed* | `int8` |  |  |
> | *url_category__value* | `str` |  |  |
> | *packets_sent* | `int8` |  |  |
> | *packets_received* | `int8` |  |  |
> | *session_end_reason__value* | `str` |  |  |
> | *action_source__value* | `str` |  |  |
> | *ep_assoc_id* | `str` |  |  |
> | *chunks_total* | `int8` |  |  |
> | *chunks_sent* | `int8` |  |  |
> | *chunks_received* | `int8` |  |  |
> | *link_change_count* | `int8` |  |  |
> | *policy_id* | `str` |  |  |
> | *link_switches* | `str` |  |  |
> | *sdwan_cluster* | `str` |  |  |
> | *sdwan_device_type* | `str` |  |  |
> | *sdwan_cluster_type* | `str` |  |  |
> | *sdwan_site* | `str` |  |  |
> | *ha_session_owner* | `str` |  |  |
> | *nssai_network_slice_differentiator__value* | `str` |  |  |
> | *stage* | `str` |  |  |
> | *auth_method* | `str` |  |  |
> | *tunnel* | `str` |  |  |
> | *source_region* | `str` |  |  |
> | *endpoint_device_name* | `str` |  |  |
> | *public_ip__value* | `str` |  |  |
> | *public_ipv6__value* | `str` |  |  |
> | *private_ip__value* | `str` |  |  |
> | *private_ipv6__value* | `str` |  |  |
> | *endpoint_gp_version* | `str` |  |  |
> | *endpoint_os_type* | `str` |  |  |
> | *endpoint_os_version* | `str` |  |  |
> | *quarantine_reason* | `str` |  |  |
> | *connection_error__value* | `str` |  |  |
> | *opaque* | `str` |  |  |
> | *status__value* | `str` |  |  |
> | *gpg_location* | `str` |  |  |
> | *login_duration* | `str` |  |  |
> | *connect_method* | `str` |  |  |
> | *connection_error__id* | `str` |  |  |
> | *portal* | `str` |  |  |
> | *gateway_selection_type* | `str` |  |  |
> | *ssl_response_time* | `str` |  |  |
> | *gateway_priority__value* | `str` |  |  |
> | *attempted_gateways* | `str` |  |  |
> | *gateway* | `str` |  |  |
> | *hostchain* | `str` |  | **✓** |
> | *tag* | `str` |  | **✓** |
> | *rawMessage* | `str` |  | **✓** |
> 
> ### sase.paloalto.prisma_access.globalprotect
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *leefVer* | `str` |  |
> | *vendor* | `str` |  |
> | *product* | `str` |  |
> | *version* | `str` |  |
> | *eventID* | `str` |  |
> | *log_time* | `timestamp` |  |
> | *log_source_id* | `str` |  |
> | *log_type__value* | `str` |  |
> | *sub_type__value* | `str` |  |
> | *config_version__value* | `str` |  |
> | *time_generated* | `timestamp` |  |
> | *vsys* | `str` |  |
> | *stage* | `str` |  |
> | *auth_method* | `str` |  |
> | *tunnel* | `str` |  |
> | *source_user* | `str` |  |
> | *source_region* | `str` |  |
> | *endpoint_device_name* | `str` |  |
> | *public_ip__value* | `str` |  |
> | *public_ipv6__value* | `str` |  |
> | *private_ip__value* | `str` |  |
> | *private_ipv6__value* | `str` |  |
> | *host_id* | `str` |  |
> | *endpoint_serial_number* | `str` |  |
> | *endpoint_gp_version* | `str` |  |
> | *endpoint_os_type* | `str` |  |
> | *endpoint_os_version* | `str` |  |
> | *count_of_repeats* | `int4` |  |
> | *quarantine_reason* | `str` |  |
> | *connection_error__value* | `str` |  |
> | *opaque* | `str` |  |
> | *status__value* | `str` |  |
> | *gpg_location* | `str` |  |
> | *login_duration* | `str` |  |
> | *connect_method* | `str` |  |
> | *connection_error__id* | `str` |  |
> | *portal* | `str` |  |
> | *sequence_no* | `int8` |  |
> | *time_generated_high_res* | `timestamp` |  |
> | *gateway_selection_type* | `str` |  |
> | *ssl_response_time* | `str` |  |
> | *gateway_priority__value* | `str` |  |
> | *attempted_gateways* | `str` |  |
> | *gateway* | `str` |  |
> | *dg_hier_level_1* | `int4` |  |
> | *dg_hier_level_2* | `int4` |  |
> | *dg_hier_level_3* | `int4` |  |
> | *dg_hier_level_4* | `int4` |  |
> | *vsys_name* | `str` |  |
> | *log_source_name* | `str` |  |
> | *vsys_id* | `str` |  |
> | *dev_time_format* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### sase.paloalto.prisma_access.threat
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *leefVer* | `str` |  |
> | *vendor* | `str` |  |
> | *product* | `str` |  |
> | *version* | `str` |  |
> | *eventID* | `str` |  |
> | *log_time* | `timestamp` |  |
> | *log_source_id* | `str` |  |
> | *log_type__value* | `str` |  |
> | *sub_type__value* | `str` |  |
> | *config_version__value* | `str` |  |
> | *time_generated* | `timestamp` |  |
> | *source_ip__value* | `ip4` |  |
> | *dest_ip__value* | `ip4` |  |
> | *nat_source__value* | `ip4` |  |
> | *nat_dest__value* | `ip4` |  |
> | *rule_matched* | `str` |  |
> | *source_user* | `str` |  |
> | *dest_user* | `str` |  |
> | *app* | `str` |  |
> | *vsys* | `str` |  |
> | *from_zone* | `str` |  |
> | *to_zone* | `str` |  |
> | *inbound_if__value* | `str` |  |
> | *outbound_if__value* | `str` |  |
> | *log_set* | `str` |  |
> | *session_id* | `str` |  |
> | *count_of_repeats* | `int4` |  |
> | *source_port* | `int4` |  |
> | *dest_port* | `int4` |  |
> | *nat_source_port* | `int4` |  |
> | *nat_dest_port* | `int4` |  |
> | *protocol__value* | `str` |  |
> | *action__value* | `str` |  |
> | *file_name* | `str` |  |
> | *vendor_severity__value* | `str` |  |
> | *direction_of_attack__value* | `str` |  |
> | *sequence_no* | `int8` |  |
> | *source_location* | `str` |  |
> | *dest_location* | `str` |  |
> | *content_type* | `str` |  |
> | *pcap_id* | `str` |  |
> | *file_sha_256* | `str` |  |
> | *cloud* | `str` |  |
> | *url_idx* | `int4` |  |
> | *file_type* | `str` |  |
> | *sender_of_virus* | `str` |  |
> | *subject_of_email* | `str` |  |
> | *recipient_of_virus* | `str` |  |
> | *report_id* | `str` |  |
> | *dg_hier_level_1* | `int4` |  |
> | *dg_hier_level_2* | `int4` |  |
> | *dg_hier_level_3* | `int4` |  |
> | *dg_hier_level_4* | `int4` |  |
> | *vsys_name* | `str` |  |
> | *log_source_name* | `str` |  |
> | *source_uuid* | `str` |  |
> | *dest_uuid* | `str` |  |
> | *http_method__value* | `str` |  |
> | *tunnelid_imsi* | `str` |  |
> | *monitor_tag_imei* | `str` |  |
> | *parent_session_id* | `str` |  |
> | *parent_start_time* | `timestamp` |  |
> | *tunnel__value* | `str` |  |
> | *threat_category__value* | `str` |  |
> | *inline_ml_verdict__value* | `str` |  |
> | *content_version* | `str` |  |
> | *sig_flags* | `str` |  |
> | *rule_matched_uuid* | `str` |  |
> | *http2_connection* | `str` |  |
> | *dynusergroup_name* | `str` |  |
> | *xff_ip__value* | `ip4` |  |
> | *source_device_category* | `str` |  |
> | *source_device_profile* | `str` |  |
> | *source_device_model* | `str` |  |
> | *source_device_vendor* | `str` |  |
> | *source_device_osfamily* | `str` |  |
> | *source_device_osversion* | `str` |  |
> | *source_device_host* | `str` |  |
> | *source_device_mac* | `str` |  |
> | *dest_device_category* | `str` |  |
> | *dest_device_profile* | `str` |  |
> | *dest_device_model* | `str` |  |
> | *dest_device_vendor* | `str` |  |
> | *dest_device_osfamily* | `str` |  |
> | *dest_device_osversion* | `str` |  |
> | *dest_device_host* | `str` |  |
> | *dest_device_mac* | `str` |  |
> | *container_id* | `str` |  |
> | *pod_namespace* | `str` |  |
> | *pod_name* | `str` |  |
> | *source_edl* | `str` |  |
> | *dest_edl* | `str` |  |
> | *host_id* | `str` |  |
> | *endpoint_serial_number* | `str` |  |
> | *domain_edl* | `str` |  |
> | *source_dynamic_address_group* | `str` |  |
> | *dest_dynamic_address_group* | `str` |  |
> | *partial_hash* | `str` |  |
> | *time_generated_high_res* | `timestamp` |  |
> | *nssai_network_slice_type__value* | `str` |  |
> | *dev_time_format* | `str` |  |
> | *url_category__value* | `str` |  |
> | *app_category* | `str` |  |
> | *container_of_app* | `str` |  |
> | *risk_of_app* | `str` |  |
> | *app_sub_category* | `str` |  |
> | *technology_of_app* | `str` |  |
> | *is_captive_portal* | `str` |  |
> | *cloud_hostname* | `str` |  |
> | *cloud_reportid* | `str` |  |
> | *customer_id* | `str` |  |
> | *dest_device_class* | `str` |  |
> | *dest_device_os* | `str` |  |
> | *dest_user_info__domain* | `str` |  |
> | *dest_user_info__name* | `str` |  |
> | *dest_user_info__uuid* | `str` |  |
> | *file_url* | `str` |  |
> | *inbound_if_details__port* | `str` |  |
> | *inbound_if_details__slot* | `str` |  |
> | *inbound_if_details__type__value* | `str` |  |
> | *inbound_if_details__unit* | `str` |  |
> | *is_client_to_server* | `str` |  |
> | *is_container* | `str` |  |
> | *is_decrypted* | `str` |  |
> | *is_decrypt_mirror* | `str` |  |
> | *is_dup_log* | `str` |  |
> | *is_encrypted* | `str` |  |
> | *is_ipv6* | `str` |  |
> | *is_mptcp_on* | `str` |  |
> | *is_non_std_dest_port* | `str` |  |
> | *is_packet_capture* | `str` |  |
> | *is_phishing* | `str` |  |
> | *is_prisma_branch* | `str` |  |
> | *is_prisma_mobile* | `str` |  |
> | *is_proxy* | `str` |  |
> | *is_recon_excluded* | `str` |  |
> | *is_saas_app* | `str` |  |
> | *is_server_to_client* | `str` |  |
> | *is_source_x_fwded* | `str` |  |
> | *is_sym_return* | `str` |  |
> | *is_transaction* | `str` |  |
> | *is_tunnel_inspected* | `str` |  |
> | *is_url_denied* | `str` |  |
> | *location* | `str` |  |
> | *is_exported* | `str` |  |
> | *is_forwarded* | `str` |  |
> | *log_source* | `str` |  |
> | *log_source_tz_offset* | `str` |  |
> | *is_nat* | `str` |  |
> | *non_standard_dest_port* | `str` |  |
> | *outbound_if_details__port* | `str` |  |
> | *outbound_if_details__slot* | `str` |  |
> | *outbound_if_details__type__value* | `str` |  |
> | *outbound_if_details__unit* | `str` |  |
> | *pcap* | `str` |  |
> | *payload_protocol_id* | `str` |  |
> | *sanctioned_state_of_app* | `str` |  |
> | *source_device_class* | `str` |  |
> | *source_device_os* | `str` |  |
> | *source_user_info__domain* | `str` |  |
> | *source_user_info__name* | `str` |  |
> | *source_user_info__uuid* | `str` |  |
> | *threat_name* | `str` |  |
> | *threat_name_firewall* | `str` |  |
> | *tunneled_app* | `str` |  |
> | *url_domain* | `str` |  |
> | *users* | `str` |  |
> | *verdict__value* | `str` |  |
> | *vsys_id* | `str` |  |
> | *severity* | `str` |  |
> | *hostchain* | `str` | ** ✓** |
> | *tag* | `str` | ** ✓** |
> | *rawMessage* | `str` | ** ✓** |
> 
> ### sase.paloalto.prisma_access.traffic
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *leefVer* | `str` |  |
> | *vendor* | `str` |  |
> | *product* | `str` |  |
> | *version* | `str` |  |
> | *eventID* | `str` |  |
> | *log_time* | `timestamp` |  |
> | *log_source_id* | `str` |  |
> | *log_type__value* | `str` |  |
> | *sub_type__value* | `str` |  |
> | *config_version__value* | `str` |  |
> | *time_generated* | `timestamp` |  |
> | *source_ip__value* | `ip4` |  |
> | *dest_ip__value* | `ip4` |  |
> | *nat_source__value* | `ip4` |  |
> | *nat_dest__value* | `ip4` |  |
> | *rule_matched* | `str` |  |
> | *source_user* | `str` |  |
> | *dest_user* | `str` |  |
> | *app* | `str` |  |
> | *vsys* | `str` |  |
> | *from_zone* | `str` |  |
> | *to_zone* | `str` |  |
> | *inbound_if__value* | `str` |  |
> | *outbound_if__value* | `str` |  |
> | *log_set* | `str` |  |
> | *session_id* | `str` |  |
> | *count_of_repeats* | `int4` |  |
> | *source_port* | `int4` |  |
> | *dest_port* | `int4` |  |
> | *nat_source_port* | `int4` |  |
> | *nat_dest_port* | `int4` |  |
> | *protocol__value* | `str` |  |
> | *bytes_total* | `int8` |  |
> | *bytes_sent* | `int8` |  |
> | *bytes_received* | `int8` |  |
> | *packets_total* | `int8` |  |
> | *session_start_time* | `timestamp` |  |
> | *total_time_elapsed* | `int8` |  |
> | *url_category__value* | `str` |  |
> | *sequence_no* | `int8` |  |
> | *source_location* | `str` |  |
> | *dest_location* | `str` |  |
> | *packets_sent* | `int8` |  |
> | *packets_received* | `int8` |  |
> | *session_end_reason__value* | `str` |  |
> | *dg_hier_level_1* | `int4` |  |
> | *dg_hier_level_2* | `int4` |  |
> | *dg_hier_level_3* | `int4` |  |
> | *dg_hier_level_4* | `int4` |  |
> | *vsys_name* | `str` |  |
> | *log_source_name* | `str` |  |
> | *action_source__value* | `str` |  |
> | *source_uuid* | `str` |  |
> | *dest_uuid* | `str` |  |
> | *tunnelid_imsi* | `str` |  |
> | *monitor_tag_imei* | `str` |  |
> | *parent_session_id* | `str` |  |
> | *parent_start_time* | `timestamp` |  |
> | *tunnel__value* | `str` |  |
> | *ep_assoc_id* | `str` |  |
> | *chunks_total* | `int8` |  |
> | *chunks_sent* | `int8` |  |
> | *chunks_received* | `int8` |  |
> | *rule_matched_uuid* | `str` |  |
> | *http2_connection* | `str` |  |
> | *link_change_count* | `int8` |  |
> | *policy_id* | `str` |  |
> | *link_switches* | `str` |  |
> | *sdwan_cluster* | `str` |  |
> | *sdwan_device_type* | `str` |  |
> | *sdwan_cluster_type* | `str` |  |
> | *sdwan_site* | `str` |  |
> | *dynusergroup_name* | `str` |  |
> | *xff_ip__value* | `ip4` |  |
> | *source_device_category* | `str` |  |
> | *source_device_profile* | `str` |  |
> | *source_device_model* | `str` |  |
> | *source_device_vendor* | `str` |  |
> | *source_device_osfamily* | `str` |  |
> | *source_device_osversion* | `str` |  |
> | *source_device_host* | `str` |  |
> | *source_device_mac* | `str` |  |
> | *dest_device_category* | `str` |  |
> | *dest_device_profile* | `str` |  |
> | *dest_device_model* | `str` |  |
> | *dest_device_vendor* | `str` |  |
> | *dest_device_osfamily* | `str` |  |
> | *dest_device_osversion* | `str` |  |
> | *dest_device_host* | `str` |  |
> | *dest_device_mac* | `str` |  |
> | *container_id* | `str` |  |
> | *pod_namespace* | `str` |  |
> | *pod_name* | `str` |  |
> | *source_edl* | `str` |  |
> | *dest_edl* | `str` |  |
> | *host_id* | `str` |  |
> | *endpoint_serial_number* | `str` |  |
> | *source_dynamic_address_group* | `str` |  |
> | *dest_dynamic_address_group* | `str` |  |
> | *ha_session_owner* | `str` |  |
> | *time_generated_high_res* | `timestamp` |  |
> | *nssai_network_slice_type__value* | `str` |  |
> | *nssai_network_slice_differentiator__value* | `str` |  |
> | *dev_time_format* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> > Macro (rw-tab)
> 
> - [sase.paloalto.prisma_cloud.audit](https://docs.devo.com/space/latest/245596181#sase.paloalto.prisma_cloud.audit)
> - [sase.paloalto.prisma_cloud.cwp](https://docs.devo.com/space/latest/245596181#sase.paloalto.prisma_cloud.cwp)
> - [sase.paloalto.prisma_saas.activity_monitoring](https://docs.devo.com/space/latest/245596181#sase.paloalto.prisma_saas.activity_monitoring)
> 
> ### sase.paloalto.prisma_cloud.audit
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *timestamp* | `timestamp` |  |
> | *user* | `str` |  |
> | *ipAddress* | `ip4` |  |
> | *resourceType* | `str` |  |
> | *resourceName* | `str` |  |
> | *action* | `str` |  |
> | *result* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### sase.paloalto.prisma_cloud.cwp
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *type* | `str` |  |
> | *time_str* | `str` |  |
> | *container* | `str` |  |
> | *image* | `str` |  |
> | *host* | `str` |  |
> | *fqdn* | `str` |  |
> | *function* | `str` |  |
> | *region* | `str` |  |
> | *runtime* | `str` |  |
> | *appID* | `str` |  |
> | *rule* | `str` |  |
> | *message* | `str` |  |
> | *aggregated* | `str` |  |
> | *rest* | `str` |  |
> | *forensics* | `str` |  |
> | *accountID* | `str` |  |
> | *cluster2* | `str` |  |
> | *collections* | `[str]` |  |
> | *complianceIssues* | `[json]` |  |
> | *vulnerabilities* | `[json]` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### sase.paloalto.prisma_saas.activity_monitoring
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *log_type* | `str` |  |
> | *item_type* | `str` |  |
> | *item_name* | `str` |  |
> | *user* | `str` |  |
> | *source_ip* | `str` |  |
> | *location* | `str` |  |
> | *action* | `str` |  |
> | *target_name* | `str` |  |
> | *target_type* | `str` |  |
> | *severity* | `float8` |  |
> | *serial* | `str` |  |
> | *cloud_app_instance* | `str` |  |
> | *timestamp* | `timestamp` |  |
> | *message* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> > Macro (rw-tab)
> 
> - [sase.paloalto.prisma_saas.admin_audit](https://docs.devo.com/space/latest/245596181#sase.paloalto.prisma_saas.admin_audit)
> - [sase.paloalto.prisma_saas.incident](https://docs.devo.com/space/latest/245596181#sase.paloalto.prisma_saas.incident)
> - [sase.paloalto.prisma_saas.invalid](https://docs.devo.com/space/latest/245596181#sase.paloalto.prisma_saas.invalid)
> 
> ### sase.paloalto.prisma_saas.admin_audit
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *log_type* | `str` |  |
> | *admin_id* | `str` |  |
> | *admin_role* | `str` |  |
> | *ip* | `str` |  |
> | *event_type* | `str` |  |
> | *item_type* | `str` |  |
> | *item_name* | `str` |  |
> | *field* | `str` |  |
> | *action* | `str` |  |
> | *resource_value_old* | `str` |  |
> | *resource_value_new* | `str` |  |
> | *timestamp* | `timestamp` |  |
> | *serial* | `str` |  |
> | *message* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### sase.paloalto.prisma_saas.incident
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *log_type* | `str` |  |
> | *item_type* | `str` |  |
> | *item_name* | `str` |  |
> | *item_unique_id* | `str` |  |
> | *asset_id* | `str` |  |
> | *item_owner* | `str` |  |
> | *container_name* | `str` |  |
> | *item_creator* | `str` |  |
> | *exposure* | `str` |  |
> | *occurrences_by_rule* | `int8` |  |
> | *severity* | `float8` |  |
> | *serial* | `str` |  |
> | *cloud_app_instance* | `str` |  |
> | *timestamp* | `timestamp` |  |
> | *asset_create_time* | `timestamp` |  |
> | *asset_create_time_str* | `str` |  |
> | *incident_id* | `str` |  |
> | *policy_rule_name* | `str` |  |
> | *incident_category* | `str` |  |
> | *incident_owner* | `str` |  |
> | *item_owner_email* | `str` |  |
> | *item_creator_email* | `str` |  |
> | *collaborators* | `str` |  |
> | *datetime_edited* | `str` |  |
> | *item_cloud_url* | `str` |  |
> | *item_owner_group* | `str` |  |
> | *item_sha256* | `str` |  |
> | *item_size* | `int4` |  |
> | *item_verdict* | `str` |  |
> | *message* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### sase.paloalto.prisma_saas.invalid
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *message* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> > Macro (rw-tab)
> 
> - [sase.paloalto.prisma_saas.other](https://docs.devo.com/space/latest/245596181#sase.paloalto.prisma_saas.other)
> - [sase.paloalto.prisma_saas.policy_violation](https://docs.devo.com/space/latest/245596181#sase.paloalto.prisma_saas.policy_violation)
> - [sase.paloalto.prisma_saas.remediation](https://docs.devo.com/space/latest/245596181#sase.paloalto.prisma_saas.remediation)
> 
> ### sase.paloalto.prisma_saas.other
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *log_type* | `str` |  |
> | *timestamp* | `timestamp` |  |
> | *item_type* | `str` |  |
> | *item_name* | `str` |  |
> | *serial* | `str` |  |
> | *message* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### sase.paloalto.prisma_saas.policy_violation
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *log_type* | `str` |  |
> | *severity* | `float8` |  |
> | *item_type* | `str` |  |
> | *item_name* | `str` |  |
> | *item_owner* | `str` |  |
> | *item_creator* | `str` |  |
> | *action_taken* | `str` |  |
> | *action_taken_by* | `str` |  |
> | *asset_id* | `str` |  |
> | *serial* | `str` |  |
> | *cloud_app_instance* | `str` |  |
> | *timestamp* | `timestamp` |  |
> | *policy_rule_name* | `str` |  |
> | *incident_id* | `str` |  |
> | *item_owner_email* | `str` |  |
> | *item_creator_email* | `str` |  |
> | *message* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### sase.paloalto.prisma_saas.remediation
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *log_type* | `str` |  |
> | *item_type* | `str` |  |
> | *item_name* | `str` |  |
> | *asset_id* | `str` |  |
> | *item_owner* | `str` |  |
> | *item_creator* | `str` |  |
> | *container_name* | `str` |  |
> | *action_taken* | `str` |  |
> | *action_taken_by* | `str` |  |
> | *serial* | `str` |  |
> | *cloud_app_instance* | `str` |  |
> | *timestamp* | `timestamp` |  |
> | *incident_id* | `str` |  |
> | *policy_rule_name* | `str` |  |
> | *item_owner_email* | `str` |  |
> | *item_creator_email* | `str` |  |
> | *message* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |