For the complete documentation index, see [llms.txt](https://waf-doc.inext.checkpoint.com/llms.txt). This page is also available as [Markdown](https://waf-doc.inext.checkpoint.com/references/events-logs-schema.md).

When events are sent from CloudGuard WAF agents to be viewed in the cloud application and/or to a Syslog/CEF server, they are sent in a specific field structure.

This page will document the fields being sent. This will allow [filter queries](https://waf-doc.inext.checkpoint.com/references/event-query-language) in the cloud application and log parsing to be done on the Syslog/CEF side (see configuration of [Trigger objects](https://waf-doc.inext.checkpoint.com/setup-instructions/setup-log-triggers) for more info).

## Schema in openAPI format

See below the security logs schema in openAPI format.

28KB

[agents-security-logs-openapi-schema-v1.0.4.json](https://2760087783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEWA4nfgNrSRL8dA6Kap7%2Fuploads%2FEzUeIPcHdpHy9zcCArtw%2Fagents-security-logs-openapi-schema-v1.0.4.json?alt=media&token=6a1c5d87-2000-4697-8d0e-ec61527a47b6)

Download [Open](https://2760087783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEWA4nfgNrSRL8dA6Kap7%2Fuploads%2FEzUeIPcHdpHy9zcCArtw%2Fagents-security-logs-openapi-schema-v1.0.4.json?alt=media&token=6a1c5d87-2000-4697-8d0e-ec61527a47b6)

The definitions per field are relevant even when the logs aren't sent in JSON format.

## Log fields

This table shows the predefined field keywords alongside their view name in the logs table and log cards.

| Field Name in Log View             | Field Name                                            | Description                                                                                                 |
|------------------------------------|------------------------------------------------------|-------------------------------------------------------------------------------------------------------------|
| `Time`                             | `eventtime`                                          | Time of the event in UTC.                                                                                   |
| `Event Name`                       | `eventname`                                         | This field describes the event in text.                                                                      |
| `Severity`                         | `eventseverity`                                     | Info, Low, Medium, High, Critical                                                                             |
| `Priority`                         | `eventpriority`                                     | Low, Medium, High, Urgent                                                                                   |
| `Confidence Level`                 | `eventconfidence`                                   | Low, Medium, High, Very High                                                                                 |
| `Event Reference Id`              | `eventreferenceid`                                  | Some events result in showing the user a reference ID.                                                      |
| `Agent UUID`                       | `agentid`                                           | UUID of the agent creating the log, if applicable.                                                          |
| `Issuing Engine Version`           | `issuingengineversion`                              | The agent's and service's version sending reporting this event.                                             |
| `Security Action`                  | `securityaction`                                    | The action taken by the security practice upon this event.                                                  |
| `Asset Name`                       | `assetname`                                         | The name of the asset, protected by the security practice that found a match and issued this log.           |
| `Asset ID`                         | `assetid`                                           | The object ID of the asset, protected by the security practice that found a match and issued this log.      |
| `Zone Name`                        | `zonename`                                          | The name of the zone, protected by the security practice that found a match and issued this log.            |
| `Zone ID`                          | `zoneid`                                            | The object ID of the zone, protected by the security practice that found a match and issued this log.       |
| `Practice Type`                    | `practicetype`                                      | The type of the security practice that found a match and issued this log.                                   |
| `Practice SubType`                 | `practicesubtype`                                   | The subtype of the security practice that found a match and issued this log.                                |
| `Practice Name`                    | `practicename`                                      | The name of the security practice that found a match and issued this log.                                   |
| `Practice ID`                      | `practiceid`                                        | The object UUID of the security practice that found a match and issued this log.                             |
| `Source IP`                        | `sourceip`                                          | Source IP address of the network traffic that caused the matched event.                                      |
| `Source Port`                      | `sourceport`                                        | Source TCP/UDP Port of the network traffic that caused the matched event.                                   |
| `Source Country`                   | `sourcecountryname`                                 | Source country name of the network traffic that caused the matched event, if applicable.                     |
| `Destination IP`                   | `destinationip`                                     | Destination IP address of the network traffic that caused the matched event.                                 |
| `Destination Port`                 | `destinationport`                                   | Destination TCP/UDP Port of the network traffic that caused the matched event.                               |
| `Destination Country`              | `destinationcountryname`                            | Destination country of the network traffic that caused the matched event, if applicable.                     |
| `IP Protocol`                      | `ipprotocol`                                        | IP Protocol of the network traffic that caused the matched event.                                            |
| `Source Identifier`                | `httpsourceid`                                      | The source identifier as determined from the HTTP traffic according to configuration.                         |
| `HTTP Host`                        | `httphostname`                                      | The source identifier as determined from the HTTP traffic according to configuration.                         |
| `HTTP Method`                      | `httpmethod`                                        | HTTP Method as determined from the HTTP traffic (e.g. GET, POST, etc.).                                     |
| `HTTP URI Path`                    | `httpuripath`                                       | HTTP URI path as determined from the HTTP traffic.                                                           |
| `HTTP URI Query`                   | `httpuriquery`                                      | HTTP URI query as determined from the HTTP traffic.                                                          |
| `HTTP Request Headers`             | `httprequestheaders`                                | HTTP Request Headers (Sent only if relevant additional logging is configured on the trigger object).        |
| `HTTP Request Body`                | `httprequestbody`                                   | HTTP Request Body (Sent only if relevant additional logging is configured on the trigger object).           |
| `Incident Type`                    | `waapincidenttype`                                   | CloudGuard WAF incident types (e.g. LDAP injection, SQL injection, etc.).                                    |
| `Incident Details`                 | `waapincidentdetails`                               | A more granular description of the event caught by CloudGuard WAF.                                         |
| `User Reputation`                  | `waapuserreputation`                                | CloudGuard WAF user reputation for the identified source.                                                   |
| `Matched Location`                 | `matchedlocation`                                   | The location within the HTTP traffic where an indicator, causing this event, was detected.                   |
| `Matched Parameter`                | `matchedparameter`                                   | The parameter name within the HTTP traffic, where an indicator, causing this event, was detected.           |
| `Matched Sample`                   | `matchedsample`                                     | The traffic data where the indicators were detected and created the event.                                   |
| `Match Reason`                     | `matchreason`                                       | An additional elaboration for the reason the event was detected.                                             |
| `Found Indicators`                 | `waapfoundindicators`                               | The detected indicators which created the event.                                                              |
| `Practice Override`                | `waapoverride`                                      | Override configuration for this event.                                                                        |
| `Event Audience (Hidden)`          | `eventaudience`                                     | Constant value of 'Security' for events sent to user.                                                       |
| `Tags (Hidden)`                    | `eventtags`                                         | For future use.
