Palo Alto Networks · Schema

AuditLog

An audit management log entry recording an administrative action.

Cloud SecurityCybersecurityFirewallNetwork SecuritySASESOARThreat IntelligenceXDR

Properties

Name Type Description
timestamp integer Action timestamp as Unix epoch milliseconds.
actor_primary_username string Username of the administrator who performed the action.
actor_email string
actor_type string
sub_type string Action subtype (e.g., Login, Logout, Policy Update).
result string
reason string Failure reason if result is FAIL.
ip string Source IP address of the action.
description string
View JSON Schema on GitHub