Field Name
|
Type
|
General Field
|
Description
|
Example
|
Products
|
act
|
-
|
-
|
The action
|
|
|
app
|
-
|
-
|
The application layer protocol
|
|
|
application
|
-
|
-
|
The name of the requested application
|
|
|
archFiles
|
-
|
-
|
The file information extracted from detected files
|
|
|
authType
|
-
|
-
|
The authorization type
|
|
|
clientGroup
|
-
|
-
|
The client IP network group
|
|
|
clientHost
|
-
|
-
|
The client IP hostname
|
|
|
clientIp
|
-
|
|
The endpoint IP
|
|
|
clientMAC
|
-
|
-
|
The client MAC address
|
|
|
clientPort
|
-
|
|
The client port
|
|
|
clientProtocol
|
-
|
-
|
The client protocol
|
|
|
clientTls
|
-
|
-
|
The transport layer security of the client
|
|
|
companyName
|
-
|
-
|
The company name
|
|
|
contentEncoding
|
-
|
-
|
The content encoding of the request or the response
|
|
|
detectionType
|
-
|
-
|
The scan type
|
|
|
deviceGUID
|
-
|
-
|
The non-endpoint object such as a network appliance
|
|
|
direction
|
-
|
-
|
The object transfer direction
|
|
|
dnsQueryType
|
-
|
-
|
The record type requested by the DNS protocol
|
|
|
dpt
|
-
|
|
The service destination port of the private application server
|
|
|
dst
|
-
|
|
The destination IP
|
|
|
duration
|
-
|
-
|
The time it took the scanner to complete the scan (in milliseconds)
|
|
|
duser
|
-
|
|
The email recipient
|
|
|
dvc
|
-
|
-
|
The IP address of the Deep Discovery Inspector or Virtual Network Sensor appliance
|
|
|
dvchost
|
-
|
-
|
The host of the deployed Deep Discovery Inspector or Virtual Network Sensor appliance
|
|
|
e2eLatency
|
-
|
-
|
The end-to-end traffic latency time (in milliseconds)
|
|
|
endpointGuid
|
-
|
|
The device GUID
|
|
|
endpointHostName
|
-
|
|
The hostname of the device on which the event was detected
|
|
|
eventId
|
-
|
-
|
The event ID
|
|
|
eventName
|
-
|
-
|
The log type
|
|
|
eventSubName
|
-
|
-
|
The cloud app action caused by user control via Zero Trust Secure Access - Internet
Access
|
|
|
eventTime
|
-
|
-
|
The time the agent detected the event
|
|
|
failedHTTPSInspection
|
-
|
-
|
The HTTPS traffic inspection failure
|
|
|
fileHash
|
-
|
|
The SHA-1 of the file that violated the policy
|
|
|
fileHashSha256
|
-
|
|
The SHA-256 of the file that violated the policy
|
|
|
fileName
|
-
|
|
The name of the file that violated the policy
|
|
|
fileSize
|
-
|
-
|
The size of the file that is violating the policy
|
|
|
fileType
|
-
|
-
|
The type of file which is violating the policy
|
|
|
filterRiskLevel
|
-
|
-
|
The top level filter risk of the event
|
|
|
flowId
|
-
|
-
|
The network analysis flow ID
|
|
|
ftpTrans
|
-
|
-
|
The transaction information of the FTP protocol
|
|
|
hostName
|
-
|
|
The hostname
|
|
|
httpLocation
|
-
|
|
The HTTP location header
|
|
|
httpReferer
|
-
|
|
The HTTP referrer header
|
|
|
httpXForwardedFor
|
-
|
-
|
The HTTP X-Forwarded-For header
|
|
|
httpXForwardedForGroup
|
-
|
-
|
The X-Forwarded-For IP network group
|
|
|
httpXForwardedForHost
|
-
|
-
|
The X-Forwarded-For IP host name
|
|
|
httpXForwardedForIp
|
-
|
|
The X-Forwarded-For IP used by the network appliance
|
|
|
ja3Hash
|
-
|
-
|
The JA3 hash
|
|
|
ja3sHash
|
-
|
-
|
The JA3S hash
|
|
|
mailMsgSubject
|
-
|
|
The email subject
|
|
|
malName
|
-
|
-
|
The name of the detected malware
|
-
|
|
mimeType
|
-
|
-
|
The MIME type or content type of the response body
|
|
|
msgId
|
-
|
|
The service provider message ID
|
|
|
objectId
|
-
|
-
|
The UUID of the Zero Trust Secure Access private access application
|
|
|
objectIps
|
-
|
|
The IP address resolved by the DNS protocol
|
|
|
osName
|
-
|
-
|
The host OS
|
|
|
overSsl
|
-
|
-
|
The SSL protocol connection
|
|
|
pname
|
-
|
-
|
The product name
|
|
|
policyTemplate
|
-
|
-
|
The Data Loss Prevention template name
|
|
|
policyTreePath
|
-
|
-
|
The policy tree path (endpoint only)
|
|
|
policyUuid
|
-
|
-
|
The UUID of the Zero Trust Secure Access private access or risk control rule
|
|
|
principalName
|
-
|
|
The User Principal Name
|
|
|
productCode
|
-
|
-
|
The product which sent the log
|
|
|
profile
|
-
|
-
|
The name of the triggered Threat Protection template or Data Loss Prevention profile
triggered
|
-
|
|
pver
|
-
|
-
|
The product version
|
|
|
reqAppVersion
|
-
|
-
|
The client application version number
|
|
|
reqDataSize
|
-
|
-
|
The data volume transmitted over the transport layer by the client (in bytes)
|
|
|
reqScannedBytes
|
-
|
-
|
The data volume transmitted by the client (in bytes)
|
|
|
request
|
-
|
|
The destination URL that the user is accessing
|
|
|
requestBase
|
-
|
|
The URL domain
|
|
|
requestClientApplication
|
-
|
-
|
The HTTP user agent
|
|
|
requestDate
|
-
|
-
|
The HTTP date header
|
|
|
requestHeaders
|
-
|
-
|
The list of HTTP headers without sensitive information
|
|
|
requestMethod
|
-
|
-
|
The network protocol request method
|
|
|
requestMimeType
|
-
|
-
|
The type of request content
|
|
|
requestSize
|
-
|
-
|
The request length
|
|
|
requests
|
-
|
|
The URLs of the request
|
|
|
resolvedUrlGroup
|
-
|
-
|
The IP address FQDN network group
|
|
|
resolvedUrlIp
|
-
|
|
The IP address of the FQDN
|
|
|
resolvedUrlPort
|
-
|
|
The HTTP server port
|
|
|
respAppVersion
|
-
|
-
|
The server application version number
|
|
|
respArchFiles
|
-
|
-
|
The file information extracted from files detected in response direction
|
|
|
respCode
|
-
|
-
|
The network protocol response code
|
|
|
respDataSize
|
-
|
-
|
The data volume transmitted over the transport layer by the server (in bytes)
|
|
|
respDate
|
-
|
-
|
The HTTP response date header
|
|
|
respFileHash
|
-
|
|
The SHA-1 of the file detected in the response direction
|
|
|
respFileHashSha256
|
-
|
|
The SHA-256 of the file detected in the response direction
|
|
|
respFileType
|
-
|
-
|
The file type detected in the response direction
|
|
|
respHeaders
|
-
|
-
|
The list of HTTP response headers without sensitive information
|
|
|
respMethod
|
-
|
-
|
The response method
|
|
|
respScannedBytes
|
-
|
-
|
The data volume transmitted by the server (in bytes)
|
|
|
responseSize
|
-
|
-
|
The response length
|
|
|
ruleName
|
-
|
-
|
The name of the triggered cloud access rule
|
|
|
ruleUuid
|
-
|
-
|
The risk assessment and control design that is defined by Zero Trust Secure Access
risk control rules
|
|
|
sender
|
-
|
-
|
The roaming users or the Trend Micro Web Security gateway where the web traffic passed
|
|
|
serverGroup
|
-
|
-
|
The server IP network group
|
|
|
serverHost
|
-
|
-
|
The server IP hostname
|
|
|
serverIp
|
-
|
|
The server IP address
|
|
|
serverMAC
|
-
|
-
|
The server MAC address
|
|
|
serverPort
|
-
|
|
The server port
|
|
|
serverProtocol
|
-
|
-
|
The version of the HTTP protocol between the Service Gateway and server or website
|
|
|
serverRespTime
|
-
|
-
|
The time the server took to respond to the request (in milliseconds)
|
|
|
serverTls
|
-
|
-
|
The TLS version between the Service Gateway and server or website
|
|
|
sessionStart
|
-
|
-
|
The session start time (in seconds)
|
|
|
src
|
-
|
|
The source IP
|
|
|
sslCertCommonName
|
-
|
-
|
The certificate common name
|
|
|
sslCertFingerprint
|
-
|
-
|
The certificate fingerprint
|
|
|
sslCertIssuer
|
-
|
-
|
The issuer of the certificate
|
|
|
sslCertSANs
|
-
|
-
|
The Subject Alternative Name of the certificate
|
|
|
sslCertSerialNumber
|
-
|
-
|
The certificate serial number
|
|
|
sslCertValidFrom
|
-
|
-
|
The certificate validity start time
|
|
|
sslCertValidUntil
|
-
|
-
|
The certificate validity end time
|
|
|
status
|
-
|
-
|
The network analysis flow session status
|
|
|
suid
|
-
|
|
The user name or IP address (IPv4)
|
|
|
suser
|
-
|
|
The email sender
|
|
|
tags
|
-
|
|
The detected technique ID based on the alert filter
|
|
|
tlsJA3Fingerprint
|
-
|
-
|
The JA3 fingerprint
|
-
|
|
tlsJA3SFingerprint
|
-
|
-
|
The raw JA3S
|
|
|
tlsSelectedCipher
|
-
|
-
|
The selected cipher of the TLS protocol
|
|
|
trafficType
|
-
|
-
|
The traffic type
|
|
|
userDepartment
|
-
|
-
|
The user department request method
|
|
|
userDomain
|
-
|
|
The Active Directory domain or the domain of the Trend Micro Anti-Spam administrator
portal user
name
|
|
|
uuid
|
-
|
-
|
The unique key of the log
|
|
|
Views: