26 - LOG_ID_TRAFFIC_HTTP_TRANSACTION
Message ID: 26
Message Description: LOG_ID_TRAFFIC_HTTP_TRANSACTION
Message Meaning: HTTP transaction
Type: Traffic
Category: http-transaction
Severity: Notice
Log Field Name |
Description |
Data Type |
Length |
---|---|---|---|
wanout |
WAN outgoing traffic in bytes |
uint64 |
20 |
wanin |
WAN incoming traffic in bytes |
uint64 |
20 |
vd |
Virtual domain name |
string |
32 |
utmaction |
Security action performed by UTM |
string |
32 |
user |
User name |
string |
256 |
url |
URL |
string |
512 |
tz |
Time zone |
string |
5 |
type |
Log type |
string |
16 |
transid |
|
uint32 |
10 |
tranport |
NAT Destination Port |
uint16 |
5 |
tranip |
NAT Destination IP |
ip |
39 |
time |
Time |
string |
8 |
subtype |
Subtype of the traffic |
string |
20 |
statuscode |
|
string |
8 |
sslaction |
Action taken by ssl-ssh-profile |
string |
26 |
srcuuid |
UUID of the Source Address Object |
string |
37 |
srcport |
Source protocol port number |
uint16 |
5 |
srcip |
Source IP address |
ip |
39 |
sessionid |
Session ID |
uint32 |
10 |
sentbyte |
Sent Bytes |
uint64 |
20 |
scheme |
|
string |
16 |
resptype |
|
string |
16 |
resptime |
|
uint64 |
16 |
resplength |
|
uint64 |
16 |
respfinishtime |
|
uint64 |
16 |
reqtime |
|
uint64 |
16 |
reqlength |
|
uint64 |
16 |
referralurl |
|
string |
512 |
rcvdbyte |
Received Bytes |
uint64 |
20 |
poluuid |
UUID of the Firewall Policy |
string |
37 |
policytype |
Policy type |
string |
24 |
policyid |
Firewall Policy ID |
uint32 |
10 |
logid |
Log ID |
string |
10 |
level |
Log Level |
string |
11 |
lanout |
LAN outgoing traffic in bytes |
uint64 |
20 |
lanin |
LAN incoming traffic in bytes |
uint64 |
20 |
httpmethod |
|
string |
20 |
hostname |
|
string |
256 |
group |
User group name |
string |
512 |
fwdsrv |
|
string |
64 |
eventtime |
Epoch time in nanoseconds |
uint64 |
20 |
emsconnection |
|
string |
8 |
duration |
Duration of the session |
uint32 |
10 |
dstuuid |
UUID of the Destination Address Object |
string |
37 |
dstport |
Destination Protocol Port Number |
uint16 |
5 |
dstip |
Destination IP Address |
ip |
39 |
devid |
Device Serial Number |
string |
16 |
date |
Date |
string |
10 |
countweb |
Number of Web Filter logs associated with the session |
uint32 |
10 |
countwaf |
Number of WAF logs associated with the session |
uint32 |
10 |
countvpatch |
|
uint32 |
10 |
countssl |
|
uint32 |
10 |
countssh |
Number of SSH logs associated with the session |
uint32 |
10 |
countsctpf |
|
uint32 |
10 |
countips |
Number of IPS logs associated with the session |
uint32 |
10 |
counticap |
|
uint32 |
10 |
countff |
|
uint32 |
10 |
countemail |
Number of Email logs associated with the session |
uint32 |
10 |
countdns |
Number of DNS Query logs associated with the session |
uint32 |
10 |
countdlp |
Number of DLP logs associated with the session |
uint32 |
10 |
countcifs |
|
uint32 |
10 |
countcasb |
|
uint32 |
10 |
countav |
Number of AV logs associated with the session |
uint32 |
10 |
countapp |
Number of App Ctrl logs associated with the session |
uint32 |
10 |
clientdevicetags |
|
string |
512 |
clientdeviceowner |
|
string |
80 |
clientdeviceid |
|
string |
80 |
authserver |
Remote Authentication server |
string |
64 |
apprisk |
Application Risk Level |
string |
16 |
applist |
Application Control profile (name) |
string |
64 |
appid |
Application ID |
uint32 |
10 |
appcat |
Application category |
string |
64 |
appact |
The security action from app control |
string |
16 |
app |
Application Name |
string |
96 |
agent |
User agent - eg. agent="Mozilla/5.0" |
string |
1024 |
action |
The status of the session: deny - Session was denied accept - Allowed Forward session start - Session starts (log message was created when the session was created) dns - DNS query return error ip-conn - Failed connection attempts close - Local-traffic session allowed timeout - Allowed session was timeout client-rst - Session reset by client server-rst - Session reset by server |
string |
16 |