Log - Distributed Secure Internet GateWay API References (1.5.0)
Download OpenAPI specification:Download
Get specific cell-group's security logs.
Get Traffic Logs
Get traffic logs.
Authorizations:
path Parameters
cell_group_id required | string |
query Parameters
receiveTimeFrom | string ^[0-9]{4}-(0[1-9]{1}|1[0-2]{1})-(0[1-9]|[1-2][0-9]|3[0-1])T(0[0-9]|1[0-9]|2[0-3]):(0[0-9]|[1-5][0-9]):(0[0-9]|[1-5][0-9])Z$ The start time for search. |
receiveTimeTo | string ^[0-9]{4}-(0[1-9]{1}|1[0-2]{1})-(0[1-9]|[1-2][0-9]|3[0-1])T(0[0-9]|1[0-9]|2[0-3]):(0[0-9]|[1-5][0-9]):(0[0-9]|[1-5][0-9])Z$ The end time for search. |
offset | integer [ 0 .. 10000000 ] Default: 0 The offset for the displaying rows. |
limit | integer [ 0 .. 5000 ] Default: 1 The limit for the displaying rows. |
sort | string Default: "timestamp:desc" The query for sort (specify like key1:desc,key2:asc). |
filterType | string Default: "exact" Enum: "exact" "partial" "regexp" Specify filter type of query string for logs keys. |
action | string |
actionFlags | string |
actionSource | string |
application | string |
bytes | string |
bytesReceived | string |
bytesSent | string |
category | string |
configVersion | string |
cpadding | string |
destinationAddress | string |
destinationCountry | string |
destinationPort | string |
destinationUser | string |
destinationVmUuid | string |
destinationZone | string |
deviceName | string |
dgHierarchyLevel1 | string |
dgHierarchyLevel2 | string |
dgHierarchyLevel3 | string |
dgHierarchyLevel4 | string |
domain | string |
elapsedTimeSec | string |
flags | string |
generateTime | string |
inboundInterface | string |
ipProtocol | string |
logAction | string |
monitorTagImei | string |
natDestinationIp | string |
natDestinationPort | string |
natSourceIp | string |
natSourcePort | string |
outboundInterface | string |
packets | string |
packetsReceived | string |
packetsSent | string |
parentSessionId | string |
parentSessionStartTime | string |
receiveTime | string |
repeatCount | string |
rule | string |
sctpAssociationId | string |
sctpChunks | string |
sctpChunksReceived | string |
sctpChunksSent | string |
sequenceNumber | string |
serial | string |
sessionEndReason | string |
sessionId | string |
sourceAddress | string |
sourceCountry | string |
sourcePort | string |
sourceUser | string |
sourceVmUuid | string |
sourceZone | string |
startTime | string |
threatContentType | string |
timeLogged | string |
tpadding | string |
tunnel | string |
tunnelIdImsi | string |
type | string |
virtualSystem | string |
virtualSystemName | string |
uuidForRule | string |
http2Connection | string |
linkChangeCount | string |
policyId | string |
linkSwitches | string |
sdwanCluster | string |
sdwanDeviceType | string |
sdwanClusterType | string |
sdwanSite | string |
dynusergroupName | string |
header Parameters
X-Auth-Token required | string The keystone token. |
Responses
OK
Bad Request
Unauthorized
Forbidden
Not Found
Internal Server Error
Response samples
- 200
- 400
- 401
- 403
- 404
- 500
{- "trafficLogs": [
- {
- "action": "allow",
- "actionFlags": "0x0",
- "actionSource": "from-policy",
- "application": "web-browsing",
- "bytes": "1201356",
- "bytesReceived": "255081",
- "bytesSent": "946275",
- "category": "shopping",
- "configVersion": "2049",
- "cpadding": "0",
- "destinationAddress": "203.0.113.4",
- "destinationCountry": "Japan",
- "destinationPort": "443",
- "destinationUser": "",
- "destinationVmUuid": "",
- "destinationZone": "Untrust",
- "deviceName": "35c439-utm",
- "dgHierarchyLevel1": "0",
- "dgHierarchyLevel2": "0",
- "dgHierarchyLevel3": "0",
- "dgHierarchyLevel4": "0",
- "domain": "1",
- "elapsedTimeSec": "1809",
- "flags": "0x1500070",
- "generateTime": "2021/02/08 09:55:24",
- "inboundInterface": "ethernet1/2",
- "ipProtocol": "tcp",
- "logAction": "Syslog_Forward",
- "monitorTagImei": "",
- "natDestinationIp": "203.0.113.4",
- "natDestinationPort": "443",
- "natSourceIp": "203.0.113.2",
- "natSourcePort": "29013",
- "outboundInterface": "ethernet1/1",
- "packets": "2432",
- "packetsReceived": "864",
- "packetsSent": "1568",
- "parentSessionId": "0",
- "parentSessionStartTime": "",
- "receiveTime": "2021/02/08 09:55:24",
- "repeatCount": "1",
- "rule": "test01",
- "sctpAssociationId": "0",
- "sctpChunks": "0",
- "sctpChunksReceived": "0",
- "sctpChunksSent": "0",
- "sequenceNumber": "13119",
- "serial": "000000000000000",
- "sessionEndReason": "tcp-fin",
- "sessionId": "169882",
- "sourceAddress": "10.0.0.2",
- "sourceCountry": "10.0.0.0-10.255.255.255",
- "sourcePort": "3567",
- "sourceUser": "",
- "sourceVmUuid": "",
- "sourceZone": "Trust",
- "startTime": "2021/02/08 09:24:58",
- "threatContentType": "end",
- "timeLogged": "2021/02/08 09:55:24",
- "tpadding": "0",
- "tunnel": "N/A",
- "tunnelIdImsi": "0",
- "type": "TRAFFIC",
- "virtualSystem": "vsys1",
- "virtualSystemName": "",
- "uuidForRule": "",
- "http2Connection": "",
- "linkChangeCount": "",
- "policyId": "",
- "linkSwitches": "",
- "sdwanCluster": "",
- "sdwanDeviceType": "",
- "sdwanClusterType": "",
- "sdwanSite": "",
- "dynusergroupName": ""
}, - {
- "action": "allow",
- "actionFlags": "0x0",
- "actionSource": "from-policy",
- "application": "ssl",
- "bytes": "5185",
- "bytesReceived": "4523",
- "bytesSent": "662",
- "category": "any",
- "configVersion": "2049",
- "cpadding": "0",
- "destinationAddress": "203.0.113.6",
- "destinationCountry": "United States",
- "destinationPort": "443",
- "destinationUser": "",
- "destinationVmUuid": "",
- "destinationZone": "Untrust",
- "deviceName": "35c439-utm",
- "dgHierarchyLevel1": "0",
- "dgHierarchyLevel2": "0",
- "dgHierarchyLevel3": "0",
- "dgHierarchyLevel4": "0",
- "domain": "1",
- "elapsedTimeSec": "253",
- "flags": "0x1400070",
- "generateTime": "2021/02/08 09:51:08",
- "inboundInterface": "ethernet1/2",
- "ipProtocol": "tcp",
- "logAction": "Syslog_Forward",
- "monitorTagImei": "",
- "natDestinationIp": "203.0.113.6",
- "natDestinationPort": "443",
- "natSourceIp": "203.0.113.2",
- "natSourcePort": "7431",
- "outboundInterface": "ethernet1/1",
- "packets": "16",
- "packetsReceived": "9",
- "packetsSent": "7",
- "parentSessionId": "0",
- "parentSessionStartTime": "",
- "receiveTime": "2021/02/08 09:51:08",
- "repeatCount": "1",
- "rule": "test01",
- "sctpAssociationId": "0",
- "sctpChunks": "0",
- "sctpChunksReceived": "0",
- "sctpChunksSent": "0",
- "sequenceNumber": "13118",
- "serial": "000000000000000",
- "sessionEndReason": "tcp-fin",
- "sessionId": "171933",
- "sourceAddress": "10.0.0.2",
- "sourceCountry": "10.0.0.0-10.255.255.255",
- "sourcePort": "18792",
- "sourceUser": "",
- "sourceVmUuid": "",
- "sourceZone": "Trust",
- "startTime": "2021/02/08 09:46:38",
- "threatContentType": "end",
- "timeLogged": "2021/02/08 09:51:08",
- "tpadding": "0",
- "tunnel": "N/A",
- "tunnelIdImsi": "0",
- "type": "TRAFFIC",
- "virtualSystem": "vsys1",
- "virtualSystemName": "",
- "uuidForRule": "",
- "http2Connection": "",
- "linkChangeCount": "",
- "policyId": "",
- "linkSwitches": "",
- "sdwanCluster": "",
- "sdwanDeviceType": "",
- "sdwanClusterType": "",
- "sdwanSite": "",
- "dynusergroupName": ""
}
]
}
Get Threat Logs
Get threat logs.
Authorizations:
path Parameters
cell_group_id required | string |
query Parameters
receiveTimeFrom | string ^[0-9]{4}-(0[1-9]{1}|1[0-2]{1})-(0[1-9]|[1-2][0-9]|3[0-1])T(0[0-9]|1[0-9]|2[0-3]):(0[0-9]|[1-5][0-9]):(0[0-9]|[1-5][0-9])Z$ The start time for search. |
receiveTimeTo | string ^[0-9]{4}-(0[1-9]{1}|1[0-2]{1})-(0[1-9]|[1-2][0-9]|3[0-1])T(0[0-9]|1[0-9]|2[0-3]):(0[0-9]|[1-5][0-9]):(0[0-9]|[1-5][0-9])Z$ The end time for search. |
offset | integer [ 0 .. 10000000 ] Default: 0 The offset for the displaying rows. |
limit | integer [ 0 .. 5000 ] Default: 1 The limit for the displaying rows. |
sort | string Default: "timestamp:desc" The query for sort (specify like key1:desc,key2:asc). |
filterType | string Default: "exact" Enum: "exact" "partial" "regexp" Specify filter type of query string for logs keys. |
action | string |
actionFlags | string |
application | string |
category | string |
cloud | string |
configVersion | string |
contenttype | string |
contentver | string |
cpadding | string |
destinationAddress | string |
destinationCountry | string |
destinationPort | string |
destinationUser | string |
destinationVmUuid | string |
destinationZone | string |
deviceName | string |
dgHierarchyLevel1 | string |
dgHierarchyLevel2 | string |
dgHierarchyLevel3 | string |
dgHierarchyLevel4 | string |
direction | string |
domain | string |
fileUrl | string |
filedigest | string |
filetype | string |
flags | string |
generateTime | string |
httpHeaders | string |
httpMethod | string |
inboundInterface | string |
ipProtocol | string |
logAction | string |
monitorTagImei | string |
natDestinationIp | string |
natDestinationPort | string |
natSourceIp | string |
natSourcePort | string |
outboundInterface | string |
parentSessionId | string |
parentSessionStartTime | string |
payloadProtocolId | string |
pcapId | string |
receiveTime | string |
recipient | string |
referer | string |
repeatCount | string |
reportid | string |
rule | string |
sctpAssociationId | string |
sender | string |
sequenceNumber | string |
serial | string |
sessionId | string |
severity | string |
sigFlags | string |
sourceAddress | string |
sourceCountry | string |
sourcePort | string |
sourceUser | string |
sourceVmUuid | string |
sourceZone | string |
subject | string |
thrCategory | string |
threatContentName | string |
threatContentType | string |
timeLogged | string |
tunnel | string |
tunnelIdImsi | string |
type | string |
urlFilename | string |
urlIdx | string |
userAgent | string |
virtualSystemName | string |
virtualSystem | string |
xff | string |
urlCategoryList | string |
uuidForRule | string |
http2Connection | string |
dynusergroupName | string |
header Parameters
X-Auth-Token required | string The keystone token. |
Responses
OK
Bad Request
Unauthorized
Forbidden
Not Found
Internal Server Error
Response samples
- 200
- 400
- 401
- 403
- 404
- 500
{- "threatLogs": [
- {
- "action": "block-url",
- "actionFlags": "0x2000000000000000",
- "application": "web-browsing",
- "category": "block-list",
- "cloud": "",
- "configVersion": "2049",
- "contenttype": "",
- "contentver": "AppThreat-0-0",
- "cpadding": "0",
- "destinationAddress": "203.0.113.3",
- "destinationCountry": "Japan",
- "destinationPort": "443",
- "destinationUser": "",
- "destinationVmUuid": "",
- "destinationZone": "Untrust",
- "deviceName": "35c439-utm",
- "dgHierarchyLevel1": "0",
- "dgHierarchyLevel2": "0",
- "dgHierarchyLevel3": "0",
- "dgHierarchyLevel4": "0",
- "direction": "client-to-server",
- "domain": "1",
- "fileUrl": "",
- "filedigest": "",
- "filetype": "",
- "flags": "0x1503000",
- "generateTime": "2021/02/09 01:40:23",
- "httpHeaders": "",
- "httpMethod": "get",
- "inboundInterface": "ethernet1/2",
- "ipProtocol": "tcp",
- "logAction": "Syslog_Forward",
- "monitorTagImei": "",
- "natDestinationIp": "203.0.113.3",
- "natDestinationPort": "443",
- "natSourceIp": "203.0.113.2",
- "natSourcePort": "33009",
- "outboundInterface": "ethernet1/1",
- "parentSessionId": "0",
- "parentSessionStartTime": "",
- "payloadProtocolId": "4294967295",
- "pcapId": "0",
- "receiveTime": "2021/02/09 01:40:23",
- "recipient": "",
- "referer": "",
- "repeatCount": "1",
- "reportid": "0",
- "rule": "test01",
- "sctpAssociationId": "0",
- "sender": "",
- "sequenceNumber": "7954",
- "serial": "000000000000000",
- "sessionId": "241551",
- "severity": "informational",
- "sigFlags": "0x0",
- "sourceAddress": "10.0.0.2",
- "sourceCountry": "10.0.0.0-10.255.255.255",
- "sourcePort": "17626",
- "sourceUser": "",
- "sourceVmUuid": "",
- "sourceZone": "Trust",
- "subject": "",
- "thrCategory": "unknown",
- "threatContentName": "(9999)",
- "threatContentType": "url",
- "timeLogged": "2021/02/09 01:40:23",
- "tunnel": "N/A",
- "tunnelIdImsi": "0",
- "type": "THREAT",
- "urlFilename": "www.ntt.com/",
- "urlIdx": "1",
- "userAgent": "",
- "virtualSystem": "vsys1",
- "virtualSystemName": "",
- "xff": "",
- "urlCategoryList": "block-allow_filter,computer-and-internet-info,low-risk",
- "uuidForRule": "c4b90ef9-3c0d-4883-91d0-691fd76b68fe",
- "http2Connection": "0",
- "dynusergroupName": ""
}, - {
- "action": "alert",
- "actionFlags": "0x2000000000000000",
- "application": "google-base",
- "category": "search-engines",
- "cloud": "",
- "configVersion": "2049",
- "contenttype": "text/html",
- "contentver": "AppThreat-0-0",
- "cpadding": "0",
- "destinationAddress": "203.0.113.1",
- "destinationCountry": "United States",
- "destinationPort": "443",
- "destinationUser": "",
- "destinationVmUuid": "",
- "destinationZone": "Untrust",
- "deviceName": "35c439-utm",
- "dgHierarchyLevel1": "0",
- "dgHierarchyLevel2": "0",
- "dgHierarchyLevel3": "0",
- "dgHierarchyLevel4": "0",
- "direction": "client-to-server",
- "domain": "1",
- "fileUrl": "",
- "filedigest": "",
- "filetype": "",
- "flags": "0x140b000",
- "generateTime": "2021/02/09 01:39:23",
- "httpHeaders": "",
- "httpMethod": "post",
- "inboundInterface": "ethernet1/2",
- "ipProtocol": "tcp",
- "logAction": "Syslog_Forward",
- "monitorTagImei": "",
- "natDestinationIp": "203.0.113.1",
- "natDestinationPort": "443",
- "natSourceIp": "203.0.113.2",
- "natSourcePort": "37890",
- "outboundInterface": "ethernet1/1",
- "parentSessionId": "0",
- "parentSessionStartTime": "",
- "payloadProtocolId": "4294967295",
- "pcapId": "0",
- "receiveTime": "2021/02/08 09:46:41",
- "recipient": "",
- "referer": "",
- "repeatCount": "1",
- "reportid": "0",
- "rule": "test01",
- "sctpAssociationId": "0",
- "sender": "",
- "sequenceNumber": "7512",
- "serial": "000000000000000",
- "sessionId": "171844",
- "severity": "informational",
- "sigFlags": "0x0",
- "sourceAddress": "10.0.0.2",
- "sourceCountry": "10.0.0.0-10.255.255.255",
- "sourcePort": "7605",
- "sourceUser": "",
- "sourceVmUuid": "",
- "sourceZone": "Trust",
- "subject": "",
- "thrCategory": "unknown",
- "threatContentName": "(9999)",
- "threatContentType": "url",
- "timeLogged": "2021/02/09 01:39:23",
- "tunnel": "N/A",
- "tunnelIdImsi": "0",
- "type": "THREAT",
- "urlFilename": "www.google.co.jp/",
- "urlIdx": "3",
- "userAgent": "",
- "virtualSystem": "vsys1",
- "virtualSystemName": "",
- "xff": "",
- "urlCategoryList": "block-allow_filter,computer-and-internet-info,low-risk",
- "uuidForRule": "c4b90ef9-3c0d-4883-91d0-691fd76b68fe",
- "http2Connection": "0",
- "dynusergroupName": ""
}
]
}
Get Authentication Logs
Get authentication logs.
Authorizations:
path Parameters
cell_group_id required | string |
query Parameters
receiveTimeFrom | string ^[0-9]{4}-(0[1-9]{1}|1[0-2]{1})-(0[1-9]|[1-2][0-9]|3[0-1])T(0[0-9]|1[0-9]|2[0-3]):(0[0-9]|[1-5][0-9]):(0[0-9]|[1-5][0-9])Z$ The start time for search. |
receiveTimeTo | string ^[0-9]{4}-(0[1-9]{1}|1[0-2]{1})-(0[1-9]|[1-2][0-9]|3[0-1])T(0[0-9]|1[0-9]|2[0-3]):(0[0-9]|[1-5][0-9]):(0[0-9]|[1-5][0-9])Z$ The end time for search. |
offset | integer [ 0 .. 10000000 ] Default: 0 The offset for the displaying rows. |
limit | integer [ 0 .. 5000 ] Default: 1 The limit for the displaying rows. |
sort | string Default: "timestamp:desc" The query for sort (specify like key1:desc,key2:asc). |
filterType | string Default: "exact" Enum: "exact" "partial" "regexp" Specify filter type of query string for logs keys. |
domain | string |
receiveTime | string |
serial | string |
type | string |
threatContentType | string |
configVersion | string |
generateTime | string |
virtualSystem | string |
sourceIp | string |
user | string |
normalizeUser | string |
object | string |
authenticationPolicy | string |
repeatCount | string |
authenticationId | string |
vendor | string |
logAction | string |
serverprofile | string |
desc | string |
clientType | string |
eventType | string |
factorNumber | string |
sequenceNumber | string |
actionFlags | string |
dgHierarchyLevel1 | string |
dgHierarchyLevel2 | string |
dgHierarchyLevel3 | string |
dgHierarchyLevel4 | string |
virtualSystemName | string |
deviceName | string |
virtualSystemId | string |
authproto | string |
uuidForRule | string |
header Parameters
X-Auth-Token required | string The keystone token. |
Responses
OK
Bad Request
Unauthorized
Forbidden
Not Found
Internal Server Error
Response samples
- 200
- 400
- 401
- 403
- 404
- 500
{- "authenticationLogs": [
- {
- "domain": "1",
- "receiveTime": "2021/12/01 09:27:51",
- "serial": "007054000162134",
- "type": "AUTH",
- "threatContentType": "Unknown",
- "configVersion": "2305",
- "generateTime": "2021/12/01 09:27:51",
- "virtualSystem": "vsys1",
- "sourceIp": "10.100.10.42",
- "user": "",
- "normalizeUser": "",
- "object": "auth_seq_test",
- "authenticationPolicy": "auth-policy-test",
- "repeatCount": "1",
- "authenticationId": "6997317030235887792",
- "vendor": "",
- "logAction": "",
- "serverprofile": "",
- "desc": "No user activity after prompted for credentials from AUTH-PORTAL.",
- "clientType": "Authentication Portal",
- "eventType": "Authentication Timeout",
- "factorNumber": "1",
- "sequenceNumber": "9584",
- "actionFlags": "0x0",
- "dgHierarchyLevel1": "0",
- "dgHierarchyLevel2": "0",
- "dgHierarchyLevel3": "0",
- "dgHierarchyLevel4": "0",
- "virtualSystemName": "",
- "deviceName": "b8deb3-utm",
- "virtualSystemId": "1",
- "authproto": "",
- "uuidForRule": ""
}, - {
- "domain": "1",
- "receiveTime": "2021/12/01 09:04:04",
- "serial": "007054000162134",
- "type": "AUTH",
- "threatContentType": "Unknown",
- "configVersion": "2305",
- "generateTime": "2021/12/01 09:04:04",
- "virtualSystem": "vsys1",
- "sourceIp": "10.100.10.42",
- "user": "",
- "normalizeUser": "",
- "object": "auth_seq_test",
- "authenticationPolicy": "auth-policy-test",
- "repeatCount": "1",
- "authenticationId": "6997317030235887790",
- "vendor": "",
- "logAction": "",
- "serverprofile": "",
- "desc": "No user activity after prompted for credentials from AUTH-PORTAL.",
- "clientType": "Authentication Portal",
- "eventType": "Authentication Timeout",
- "factorNumber": "1",
- "sequenceNumber": "9583",
- "actionFlags": "0x0",
- "dgHierarchyLevel1": "0",
- "dgHierarchyLevel2": "0",
- "dgHierarchyLevel3": "0",
- "dgHierarchyLevel4": "0",
- "virtualSystemName": "",
- "deviceName": "b8deb3-utm",
- "virtualSystemId": "1",
- "authproto": "",
- "uuidForRule": ""
}
]
}
Get User-ID Logs
Get User-ID logs.
Authorizations:
path Parameters
cell_group_id required | string |
query Parameters
receiveTimeFrom | string ^[0-9]{4}-(0[1-9]{1}|1[0-2]{1})-(0[1-9]|[1-2][0-9]|3[0-1])T(0[0-9]|1[0-9]|2[0-3]):(0[0-9]|[1-5][0-9]):(0[0-9]|[1-5][0-9])Z$ The start time for search. |
receiveTimeTo | string ^[0-9]{4}-(0[1-9]{1}|1[0-2]{1})-(0[1-9]|[1-2][0-9]|3[0-1])T(0[0-9]|1[0-9]|2[0-3]):(0[0-9]|[1-5][0-9]):(0[0-9]|[1-5][0-9])Z$ The end time for search. |
offset | integer [ 0 .. 10000000 ] Default: 0 The offset for the displaying rows. |
limit | integer [ 0 .. 5000 ] Default: 1 The limit for the displaying rows. |
sort | string Default: "timestamp:desc" The query for sort (specify like key1:desc,key2:asc). |
filterType | string Default: "exact" Enum: "exact" "partial" "regexp" Specify filter type of query string for logs keys. |
domain | string |
receiveTime | string |
serial | string |
type | string |
threatContentType | string |
configVersion | string |
generateTime | string |
virtualSystem | string |
sourceIp | string |
user | string |
dataSourceName | string |
eventId | string |
repeatCount | string |
timeout | string |
beginport | string |
endport | string |
dataSource | string |
dataSourceType | string |
sequenceNumber | string |
actionFlags | string |
dgHierarchyLevel1 | string |
dgHierarchyLevel2 | string |
dgHierarchyLevel3 | string |
dgHierarchyLevel4 | string |
virtualSystemName | string |
deviceName | string |
virtualSystemId | string |
factorType | string |
factorCompletionTime | string |
factorNumber | string |
ugflags | string |
userbysource | string |
header Parameters
X-Auth-Token required | string The keystone token. |
Responses
OK
Bad Request
Unauthorized
Forbidden
Not Found
Internal Server Error
Response samples
- 200
- 400
- 401
- 403
- 404
- 500
{- "userIdLogs": [
- {
- "domain": "1",
- "receiveTime": "2021/11/26 02:29:45",
- "serial": "007054000162134",
- "type": "USERID",
- "threatContentType": "login",
- "configVersion": "2305",
- "generateTime": "2021/11/26 02:29:45",
- "virtualSystem": "vsys1",
- "sourceIp": "fe80::d0dd:a902:cdcf:2139",
- "user": "ad-test.example.com\\ouuser01",
- "dataSourceName": "ad-test",
- "eventId": "0",
- "repeatCount": "1",
- "timeout": "300",
- "beginport": "0",
- "endport": "0",
- "dataSource": "agent",
- "dataSourceType": "",
- "sequenceNumber": "105244",
- "actionFlags": "0x0",
- "dgHierarchyLevel1": "0",
- "dgHierarchyLevel2": "0",
- "dgHierarchyLevel3": "0",
- "dgHierarchyLevel4": "0",
- "virtualSystemName": "",
- "deviceName": "b8deb3-utm",
- "virtualSystemId": "1",
- "factorType": "",
- "factorCompletionTime": "2021/11/26 02:29:41",
- "factorNumber": "1",
- "ugflags": "0x0",
- "userbysource": "ad-test.example.com\\ouuser01"
}, - {
- "domain": "1",
- "receiveTime": "2021/11/26 02:24:58",
- "serial": "007054000162134",
- "type": "USERID",
- "threatContentType": "login",
- "configVersion": "2305",
- "generateTime": "2021/11/26 02:24:58",
- "virtualSystem": "vsys1",
- "sourceIp": "172.16.200.1",
- "user": "ad-test\\ouuser01",
- "dataSourceName": "ad-test",
- "eventId": "0",
- "repeatCount": "1",
- "timeout": "300",
- "beginport": "0",
- "endport": "0",
- "dataSource": "agent",
- "dataSourceType": "",
- "sequenceNumber": "105243",
- "actionFlags": "0x0",
- "dgHierarchyLevel1": "0",
- "dgHierarchyLevel2": "0",
- "dgHierarchyLevel3": "0",
- "dgHierarchyLevel4": "0",
- "virtualSystemName": "",
- "deviceName": "b8deb3-utm",
- "virtualSystemId": "1",
- "factorType": "",
- "factorCompletionTime": "2021/11/26 02:24:55",
- "factorNumber": "1",
- "ugflags": "0x0",
- "userbysource": "ad-test\\ouuser01"
}
]
}